Shared server device and access restriction program

The shared server device employs VLAN-IDs to manage access permissions, addressing the challenge of imposing access restrictions without account settings, and achieving flexible and efficient access control in shared server environments.

JP2025086658APending Publication Date: 2025-06-09SAXA +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023200796
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-28
Publication Date
2025-06-09

Smart Images

  • Figure 2025086658000001_ABST
    Figure 2025086658000001_ABST
Patent Text Reader

Abstract

To enable appropriate access restrictions to be applied to the data storage locations formed in a storage device without having to configure account setting, etc., on a client device.SOLUTION: VLAN-ID extraction means 111 extracts a VLAN-ID included in an access request from a hub device. First conversion means converts the extracted VLAN-ID into an account on the basis of an account conversion table. Access control means references an access range setting table on the basis of the converted account to enable access to data storage locations in a data storage location according to the access request, and forms an access response. Second conversion means converts the account used by the access control means into a VLAN-ID on the basis of the account conversion table. Assignment means assigns the VLAN-ID to the formed access response and outputs the response.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an apparatus and a program that can appropriately restrict the use of data storage locations such as folders and files in a storage unit of a shared server apparatus.

Background Art

[0002] Patent Document 1 described later discloses an invention related to a digital image communication system or the like that simplifies the procedure when a user who owns a digital image accesses the digital image while preventing unwanted access from other users to the digital image stored in a server. The home server (100) according to the invention receives an access request to a digital image from any of a parent PC (210), a sibling PC (220), a family TV (310), and an eldest daughter TV (320). In this case, based on the device ID and viewing information transmitted simultaneously with the access request, the viewing restriction information table (140) is referred to. Then, based on the viewing restriction information described in the viewing restriction information table (140), it is determined whether to restrict access to the digital image stored in the image storage unit (120), and access is permitted when not restricted.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] The invention disclosed in Patent Document 1 described above is for solving problems related to sharing of a home server used at home, and performs usage restrictions on a limited number of users such as one family. For this reason, access restrictions are carried out using device IDs and browsing information that is relatively easy to accumulate. That is, the invention disclosed in Patent Document 1 performs usage restrictions on a limited number of users such as one family. For this reason, for example, it is difficult to apply to a system that is used by a relatively large number of people like a server device used in a company, where many projects are active simultaneously, users are fluid, and additions, changes, and deletions of folders or the like to which access restrictions are applied occur.

[0005] Conventionally, access to a shared server is generally managed by restricting folders or the like accessed by an account. However, in the case of a company, there are times when, not only for its own employees but also for visitors such as the person in charge of a business partner, during a meeting or presentation, it is desired to share a folder only at that time. However, it is troublesome to issue an account or make sharing settings each time for that purpose. Also, when a so-called guest account is set up, the guest account is stored in the client device, so there is a possibility that it can be accessed from another location using that account. For example, it is also desired to achieve the ability to access only pre-determined folders from this conference room A without bothering the visitors.

[0006] In view of the above, it is an object to be able to appropriately impose access restrictions on a data storage location formed in the storage unit of a client device without setting an account or the like for the client device.

Means for Solving the Problem

[0007] To solve the above problems, the shared server device according to the invention described in claim 1 A shared server device connected to a hub device that can divide a broadcast domain for each VLAN-ID (Virtual Local Area Network-identification) by setting a VLAN-ID for each LAN (Local Area Network) port. An access range setting table that stores information associating a predetermined account with one or more data storage locations where access is permitted according to the account. An account conversion table that associates the VLAN-ID set for each LAN port of the hub device with the account. Extraction means for extracting the VLAN-ID attached to an access request received from the hub device. First conversion means for converting the VLAN-ID extracted by the extraction means into the account based on the account conversion table. Based on the account converted by the first conversion means, referring to the access range setting table, enabling access to the data storage location corresponding to the access request and where access is permitted, and forming an access response. Second conversion means for converting the account used by the access control means into the VLAN-ID based on the account conversion table. Granting means for attaching and outputting the VLAN-ID converted by the second conversion means to the access response formed by the access control means. Characterized by comprising the above.

[0008] According to the shared server device of the invention described in claim 1, the extraction means extracts the VLAN-ID included in the access request from the hub device. The first conversion means converts the extracted VLAN-ID into an account based on the account conversion table. The access control means refers to the access range setting table based on the converted account, enables access to the data storage location where access is permitted in the data storage location corresponding to the access request, and forms an access response. The second conversion means converts the account used by the access control means into a VLAN-ID based on the account conversion table. The granting means grants the VLAN-ID to the formed access response and outputs it.

Advantages of the Invention

[0009] According to this invention, without performing account settings or the like on the client device, it is possible to appropriately impose access restrictions on the data storage locations formed in the storage unit of the shared server device.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments of an apparatus and a program according to this invention will be described with reference to the drawings. In the embodiments described below, the case of constructing a network system (LAN system) within a company using the apparatus and program according to this invention will be described as an example.

[0012] [Configuration Example of Network System] FIG. 1 is a diagram for explaining a configuration example of a network system according to an embodiment. The sharing server 1 according to this embodiment can restrict accessible folders and files according to the group to which client devices such as PCs (Personal Computers) that receive information from the sharing server 1 belong. Further, the sharing server 1 according to this embodiment performs connection confirmation of client devices, and when it can detect the departure of all client devices belonging to the group, it can organize accessible folders and files.

[0013] In order to implement such a function, in this embodiment, there is no need to take the trouble of assigning an account to the client device and performing settings. The shared server 1 of this embodiment uses the VLAN-ID (Virtual Local Area Network-identification) assigned to an access request or the like by the hub 2 as an account. Thereby, access restrictions on folders and files that can be accessed for each group to which the client device belongs can be performed. In addition, the connection of the client device is checked, and when all the client devices belonging to the group have left, the folders and files that the client devices belonging to that group could access are organized.

[0014] In FIG. 1, the shared server 1 is an application of an embodiment of the shared server device according to the present invention. As shown in FIG. 1, the PC3 brought into Conference Room A is connected to the port PT1 (the first port) of the hub (hub device) 2, and the PC4 brought into Conference Room B is connected to the port PT2 (the second port) of the hub 2. Further, the shared server 1 is connected to the port PT10 (the tenth port) of the hub 2. In this way, the PC3 and the PC4 are connected to the shared server 1 through the hub 2. The PC3 and the PC4 are brought into different conference rooms. For this reason, it is assumed that the PC3 belongs to Group 1, which is a group of client devices connected to the shared server 1, and the PC4 belongs to Group 2, which is a group of client devices connected to the shared server 1.

[0015] In FIG. 1, the hub 2 is a commercially available general-purpose one. However, the hub 2 can set a VLAN-ID for each LAN port and has a function of dividing the broadcast domain. The broadcast domain means the network range to which an Ethernet (registered trademark) broadcast frame reaches. In the case of the example shown in FIG. 1, the hub 2 can treat the range of client devices connected to the port PT1 and the range of client devices connected to the port PT2 as different broadcast domains (different networks). Utilizing this, the shared server 1 performs access restriction on accessible folders and files, connection confirmation of client devices, and organization of folders and files that were accessible by the disconnected client devices.

[0016] Various data are stored and held in the storage device 106 mounted on the shared server 1. For example, as shown in FIG. 1, a plurality of folders are formed, and various files are stored in each folder. The hub 2 of this embodiment assigns (adds) the VLAN-ID set in the LAN port PT1 to an access request from the PC3 belonging to Group 1 brought into Conference Room A. In the shared server 1, the VLAN-ID included in the access request is used as an account, and as shown in FIG. 1, access to folders A, B, D, and E belonging to the access range R1 of Group 1 is enabled, and access to other folders is disabled.

[0017] In addition, the hub 2 of this embodiment assigns the VLAN-ID set in the LAN port PT2 to the access request from the PC 4 belonging to Group 2 brought into Conference Room B. In the shared server 1, the VLAN-ID included in the access request is used as an account, and as shown in FIG. 1, access to the folders E, F, H, and I belonging to the access range R2 of Group 2 is enabled, and access to other folders is disabled. In this way, the shared server 1 can perform access restriction on various data stored and held in the storage device 106 mounted on itself according to the group to which the client device connected to the hub 2 belongs.

[0018] Furthermore, the shared server 1 of this embodiment checks the connection of the client device. As a result, when it is confirmed that all the client devices belonging to the group have left, it has a function of deleting from the storage device 106 the folders and files that can be used only by the client devices belonging to that group. FIG. 2 is a diagram for explaining the connection check of the client device and the folder deletion process performed in the network system of the embodiment. As shown in FIG. 1, when an access request is sent from the PC 3 to the shared server 1 through the hub 2, the shared server 1 extracts and holds the VLAN-ID from the received access request. Thereby, the shared server 1 can recognize that the client device (PC 3) belonging to Group 1 is in a connected state.

[0019] Therefore, as shown by the arrows S1 and S2 in FIG. 2(A), the shared server 1 periodically sends a connection check request and, as shown by the arrows S3 and S4, receives a connection check response to the connection check response. The connection check response includes a VLAN-ID. For this reason, when the same VLAN-ID as the VLAN-ID held in the shared server 1 can be extracted from the received connection check response, it can be determined that the client device (PC 3) belonging to that group is in a connectable state to the shared server 1.

[0020] However, as indicated by arrows S1 and S2 in Fig. 2(B), if the connection confirmation response does not return from PC3 even when the connection confirmation request is periodically sent, it can be determined that PC3 has left the network and is in a state where it cannot access the shared server 1. In the case of this example, as shown in Fig. 1, since only PC3 belongs to Group 1, it can be determined that all the client devices belonging to Group 1 have left.

[0021] When the state shown in Fig. 2(B) occurs, in the shared server 1, as shown in Fig. 2(C), the folders A, B, and D of the storage device 106 for which access was permitted to the client devices belonging to Group 1 are deleted. Since Folder E can also be accessed by the client devices belonging to Group 2, it is not deleted until all the departures of the client devices belonging to Group 2 are confirmed. As a result, the folders that could be used by PC3, which is the only client device belonging to Group 1, can be deleted when PC3 departs, so that the data can be managed with high confidentiality.

[0022] Note that in the case described with reference to Fig. 2, immediately after removing PC3 from the LAN port PT1 of the hub 2, assume that another PC5 is connected to the LAN port PT1. In this case, the session ID assigned to the access request when accessing the shared server 1 is different from that assigned to the access request when accessing the shared server 1 from the removed PC3. For this reason, in the used ID table 103, not only the VLAN-ID included in the access request but also the IP address and the session ID are extracted and stored in association with the VLAN-ID.

[0023] Thus, even if the newly connected PC5 is assigned the same VLAN-ID and IP address as the removed PC3 for an access request from the newly connected PC5 to the shared server 1, the session ID is different. In this case, the access request from the newly connected PC5 can be ignored, and folders and files can be deleted. Also, in this case, even when the IP address included in the access request from the newly connected PC5 is different from that included in the access request from the previously received removed PC3, the access request from the newly connected PC5 can be ignored, and folders and files can be deleted.

[0024] Hereinafter, in the network system of this embodiment, for the hub 2 which is a general-purpose but important component, and the shared server 1 to which one embodiment of the shared server device of the present invention is applied, the configuration example and operation will be specifically described. Note that since PC3 and 4 are existing PCs, detailed descriptions thereof will be omitted.

[0025] [Schematic Configuration of Hub 2] FIG. 3 is a block diagram for explaining a schematic configuration example of the hub 2 used in the network system of the embodiment. The hub 2 of this embodiment is a commercially available hub device, and is a so-called VLAN hub that can configure a VLAN (Virtual Local Area Network). For simplicity of explanation, the hub 2 of this embodiment is assumed to include ten LAN ports PT1 to PT10, and identifier processing units 201(1) to 201(10) are provided corresponding to each LAN port. The hub 2 enables data transmission and reception between devices connected to the LAN ports PT1 to PT10. A case where communication is performed between the PCs connected to the LAN ports PT1 to PT9 and the shared server 1 connected to the LAN port PT10 will be described.

[0026] Each of the identifier processing units 201(1) to 201(10) can set a VLAN-ID, for example, through an operation unit (not shown) or a connected PC. In the hub 2 of this example, the VLAN-ID = 100 is set in the identifier processing unit 201(1). For an access request from the PC3 connected to the LAN port PT1, the VLAN-ID = 100 can be assigned and sent to the shared server 1. Also, an access response with the VLAN-ID = 100 from the shared server 1 can have the VLAN-ID removed and be sent to the PC3 through the LAN port PT1. Similarly, the VLAN-ID = 200 is set in the identifier processing unit 201(2). For an access request from the PC4 connected to the LAN port PT2, the VLAN-ID = 200 can be assigned and sent to the shared server 1. Also, an access response with the VLAN-ID = 200 from the shared server 1 can have the VLAN-ID removed and be sent to the PC4 through the LAN port PT2.

[0027] Note that the VLAN-IDs = 300 to 900 are also set in the identifier processing units 201(4) to 201(9). Therefore, for access requests from the client devices connected to the LAN ports PT3 to PT9, the VLAN-IDs = 300 to 900 can be assigned and sent to the shared server 1. Also, access responses with the VLAN-IDs = 300 to 900 from the shared server 1 can have the VLAN-IDs removed and be sent to the client devices connected to the corresponding LAN ports PT3 to PT9 through the corresponding LAN ports PT3 to PT9. Further, the VLAN-IDs = 100 to 900 are set in the identifier processing unit 201(10) corresponding to the LAN port PT10. As a result, through the LAN port PT10, data from any of the LAN ports PT1 to PT9 can be output and sent to the shared server 1, and also, the access response from the shared server 1 can be output to any of the LAN ports PT1 to PT9.

[0028] In the case of the example shown in FIG. 3, different VLAN-IDs are set for the LAN ports PT1 to PT9, but the present invention is not limited to this. For example, the same VLAN-ID can be set for a plurality of LAN ports, such as setting the VLAN-ID to 100 for the LAN ports PT1 to PT3 and setting the VLAN-ID to 200 for the LAN ports PT4 to PT6. In this case, it can be treated as if the client devices connected to the LAN ports PT1 to PT3 and the client devices connected to the LAN ports PT4 to PT6 are connected to different broadcast domains (different networks).

[0029] As described above, the hub 2 of this embodiment can set a VLAN-ID for each LAN port and can attach the VLAN-ID and transmit an access request or the like from a PC connected to the LAN port to the shared server 1. Conversely, an access response with a VLAN-ID assigned from the shared server 1 can be transmitted only to the client device connected to the LAN port to which the VLAN-ID is assigned.

[0030] [Configuration Example of Shared Server 1] FIG. 4 is a block diagram for explaining a configuration example of the shared server 1 used in the network system of the embodiment. The connection end 101T constitutes a connection end to the hub 2, and the LAN I / F (Interface) 101 is a part that performs communication processing through the LAN. That is, the LAN I / F 101 converts a signal addressed to itself transmitted via the hub 2 into a signal in a format that can be processed by itself and captures this signal. Further, the LAN I / F 101 converts a signal to be transmitted from itself to a target destination via the hub 2 into a signal in a transmission format and transmits this signal.

[0031] The control unit 102 is a microprocessor including a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), a non-volatile memory, etc., which controls each part of the shared server 1. The usage ID table 103, the access range setting table 104, and the account conversion table 105 are created on the recording medium of a storage device composed of a recording medium and its driver, such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive).

[0032] FIG. 5 is a diagram for explaining an example of stored data in the usage ID table 103 of the shared server 1 according to the embodiment. As shown in FIG. 5, the usage ID table 103 stores and holds the VLAN-ID extracted from access requests and the like from client devices such as the PCs 3 and 4 transmitted via the hub 2. That is, the usage ID table 103 stores and holds the VLAN-ID extracted from the transmitted data from the client devices actually connected to the shared server 1 through the hub 2. Note that the same VLAN-ID is assigned to access requests and the like from client devices belonging to the same group, so that the same VLAN-ID is not registered repeatedly in the usage ID table 103.

[0033] FIG. 6 is a diagram for explaining an example of stored data in the access range setting table 104 of the shared server 1 according to the embodiment. In the access range setting table 104, for example, information is registered in advance by an administrator. In this embodiment, as shown in FIG. 6, an account and the folder names of one or more shared folders (the folder names of the shared folders) associated with the account are stored in advance. The accounts are set for each group.

[0034] Specifically, in the access range setting table 104, as described with reference to FIG. 1, an account "group1" is set for group 1 consisting of client devices brought into conference room A and connected to the LAN port PT1 of hub 2. For this account "group1", folder A, folder B, folder C, and folder E are associated. Also, in the access range setting table 104, as described with reference to FIG. 1, an account "group2" is set for group 2 consisting of client devices brought into conference room B and connected to the LAN port PT2 of hub 2. For this account "group2", folder E, folder F, folder H, and folder I are associated.

[0035] FIG. 7 is a diagram for explaining an example of the stored data in the account conversion table 105 of the shared server 1 according to the embodiment. The account conversion table 105 stores and holds the VLAN-ID set for each LAN port of hub 2 in association with the account for each group. As described with reference to FIG. 3, for the LAN port PT1 of hub 2, VLAN-ID = 100 is set. Also, for the LAN port PT2 of hub 2, VLAN-ID = 200 is set.

[0036] And as shown in FIG. 1, since the device connected to LAN port PT1 (VLAN-ID = 100) is PC3 belonging to group 1 installed in conference room A, the account "group1" of group 1 is associated with VLAN-ID = 100. Also, since the device connected to LAN port PT2 (VLAN-ID = 200) is PC4 belonging to group 2 installed in conference room B, the account "group2" of group 2 is associated with VLAN-ID = 200.

[0037] Therefore, based on the VLAN-ID included in the access request, by referring to the account conversion table 105, the account of the group to which the client device of the access request source belongs can be identified. In other words, the VLAN-ID can be converted into an account. By using this identified (converted) account and referring to the access range setting table 104, it becomes possible to determine which folders the client devices PC3 and PC4, which are the source devices, can access.

[0038] Note that each of the used ID table 103, the access range setting table 104, and the account conversion table 105 may be formed on the same recording medium, or may be formed on different recording media of the same storage device. Further, they may be formed on recording media of different storage devices.

[0039] The storage device 106 is a device unit composed of a recording medium and its driver, such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive), and performs recording, reading, modification, deletion, etc. of various data to and from the recording medium. In addition to storing and holding necessary data and programs, the storage device 106 is also used as a work area for temporarily storing intermediate data generated in various processes. As shown in FIGS. 1 and 4, various folders and files are formed in the storage device 106 of the shared server 1 of this embodiment, and access restrictions can be imposed using the VLAN-ID set in the hub 2.

[0040] Note that each of the used ID table 103, the access range setting table 104, and the account conversion table 105 may be formed on the same recording medium, or may be formed on different recording media of the same storage device. Further, they may be formed on recording media of different storage devices. Also, each of the used ID table 103, the access range setting table 104, and the account conversion table 105 can also be formed on the recording medium of the storage device 106.

[0041] The shared folder control unit 110 is a part that realizes access control using VLAN - IDs, and includes a VLAN - ID extraction unit 111, an account conversion unit 112, an access control unit per account 113, a VLAN - ID conversion unit 114, and a VLAN - ID assignment unit 115. The VLAN - ID extraction unit 111 performs a process of extracting a VLAN - ID from an access request addressed to the local device received through the connection terminal 101T and the LAN I / F 101. Also, the VLAN - ID extraction unit 111 performs a process of recording the extracted VLAN - ID in the usage ID table 103. The account conversion unit 112 performs a process of referring to the account conversion table 105 based on the VLAN - ID extracted by the VLAN - ID extraction unit 111 and extracting the corresponding account. That is, the account conversion unit 112 performs a process of converting the extracted VLAN - ID into an account.

[0042] The access control unit per account 113 uses the account extracted by the account conversion unit 112 to refer to the access range setting table 104 and enables access to the folders and files to which access is permitted by the extracted account. Also, the access control unit per account 113 forms an access response by accessing the folders and files to which access is permitted in response to an access request from the client device, referring to the target data, etc., and performs a process of outputting this. The VLAN - ID conversion unit 114 performs a process of referring to the account conversion table 105 using the account used by the access control unit per account 113 and extracting the corresponding VLAN - ID. That is, the VLAN - ID conversion unit 114 performs a process opposite to that of the account conversion unit 112, and performs a process of converting the account used by the access control unit per account 113 into a VLAN - ID.

[0043] The VLAN-ID assigning unit 115 performs a process of assigning the VLAN-ID extracted by the VLAN-ID conversion unit 114 to the access response formed by the per-account access control unit 113 and replying to the client device. As a result, when an access request is transmitted from PC3, the use of folders within the access range R1 of group 1 in the storage device 106 is enabled, and an access response is formed. The access response is replied to PC3 of group 1 specified by the VLAN-ID among the client devices connected to the hub 2. Similarly, when an access request is transmitted from PC4, the use of folders within the access range R2 of group 2 in the storage device 106 is enabled, and an access response is formed. The access response is replied to PC4 of group 2 specified by the VLAN-ID among the client devices connected to the hub 2. In this way, access restriction can be performed according to the VLAN-ID.

[0044] When all the client devices in the group to which the client device connected to the shared server 1 belongs have left, the departure handling unit 120 performs a process of deleting the folders and files that can be used by the group from the storage device 106. The departure handling unit 120 includes a connection confirmation transmission processing unit 121, a connection response reception processing unit 122, and a storage location deletion unit 123. The connection confirmation transmission processing unit 121 periodically forms a connection confirmation request and transmits it to each of the client devices connected to itself through the LANI / F101 and the connection terminal 101T. Specifically, the connection confirmation request is an ARP (Address Resolution Protocol) request. The ARP request requests the client devices connected to the shared server 1 to notify the MAC (Media Access Control) address.

[0045] Upon receiving the connection confirmation request, the client device forms and sends a connection confirmation response. Specifically, the connection confirmation response is an ARP reply. Although the ARP reply notifies the MAC address of the client device that is the source, since it is sent to the shared server 1 through the hub 2, it will be given a VLAN-ID corresponding to the LAN port. The connection response reception processing unit 122 extracts the VLAN-ID from the connection confirmation response received through the connection end 101T and the LANI / F101, and matches it with the stored data in the usage ID table 103. Thereby, the VLAN-ID of the group from which all client devices have left is identified, and the identified VLAN-ID is notified to the storage location deletion unit 123.

[0046] That is, assume that all client devices connected to the LAN port with VLAN-ID = 100, whether it is the LAN port PT1 or other LAN ports, have left. In this case, no connection confirmation response with the VLAN-ID "100" will be sent. In this case, it can be determined that all client devices with the VLAN-ID "100" have left. Thus, the connection response reception processing unit 122 performs the process of identifying the VLAN-ID of the group consisting of the client devices that have left and notifying this to the storage location deletion unit 123.

[0047] When the storage location deletion unit 123 is notified of the VLAN-ID from the connection response reception processing unit 122, it refers to the account conversion table 105 to identify the corresponding account. The storage location deletion unit 123 refers to the access range setting table 104 based on the identified account, and identifies the folders and files that can be accessed by the group having the account. The storage location deletion unit 123 performs a deletion process so that the identified folders and files cannot be used. The deletion process may move the target folders and files to the so-called trash can to make them unusable, or may physically delete them from the recording medium of the storage device 106.

[0048] In this way, the shared server 1 can perform access restrictions on folders and files for each group of client devices that can be grouped by VLAN-ID, using the VLAN-ID assigned to each LAN port by the hub 2. Also, when all of the client devices that can be grouped by VLAN-ID have left (when the connection to the shared server 1 is lost), the folders and files accessible to the group of client devices that can be grouped can be deleted. Through these measures, the sharing of data stored in the storage device 106 can be appropriately realized, and the confidentiality of the shared data can be highly managed.

[0049] [Summary of the Operations of the Shared Server 1] Next, the access restriction process and the connection confirmation process performed in the shared server 1 of this embodiment described with reference to FIGS. 4 to 7 will be summarized with reference to the flowcharts.

[0050] <Access Restriction Process> FIG. 8 is a flowchart for explaining the process when an access request to the shared server of the embodiment is received. The process of the flowchart shown in FIG. 8 is a process executed by the control unit 102 when the power of the shared server 1 is turned on. When the control unit 102 receives an access request addressed to itself through the connection terminal 101T and the LAN I / F 101, it controls each part of the shared folder access restriction control unit 110 to perform an access restriction process on the folders created in the storage device 106.

[0051] First, the VLAN-ID extraction unit 111 functions to perform a process of extracting the VLAN-ID assigned by the hub 2 from the received access request (packet data) (step S101). Next, the account conversion unit 112 functions to refer to the account conversion table 105 based on the VLAN-ID extracted in step S101 and convert the VLAN-ID into an account (step S102). After that, the per-account access control unit 113 functions to refer to the access range setting table 104 based on the account converted in step S102 and enable access only to the folders associated with the account (step S103). That is, access to folders not associated with the account is disabled, and the available folders are restricted.

[0052] The per-account access control unit 113 generates an access response (packet data) based on the data obtained by accessing the folder to which access is permitted in response to the access request (step S104). After that, the VLAN-ID conversion unit 114 functions to refer to the account conversion table 105 based on the account used for access restriction by the per-account access control unit 113 and convert the account into a VLAN-ID (step S105). Next, the VLAN-ID assignment unit 115 functions to assign (add) the obtained VLAN-ID to the access response formed in step S104 and transmit this through the LANI / F101 and the connection terminal (step S106). In this way, in the shared server 1, access restrictions can be imposed on folders and files for each assumed group by using the VLAN-ID.

[0053] <Connection confirmation process> FIG. 9 is a flowchart for explaining the connection confirmation process of the shared server according to the embodiment. The process of the flowchart shown in FIG. 9 is a process that is periodically executed, for example, every two hours, every three hours, or at 5:00 p.m. from Monday to Friday, based on a predetermined time point. Of course, the examples given here are examples of periodicity, and it may be performed periodically at various timings. Therefore, for example, it can be performed periodically at predetermined timings such as at the start of business every day, at predetermined times in the morning and afternoon every day, and at predetermined times on Monday, Wednesday, and Friday. The process shown in FIG. 9 is also a process executed in the control unit 102.

[0054] When the predetermined timing arrives, the control unit 102 controls each part of the disconnection response unit 120 to perform a connection confirmation process and delete unnecessary folders and files. First, the connection confirmation transmission processing unit 121 functions to form a connection confirmation request (ARP request) and transmit it to each of the client devices connected to the own device through the LANI / F101 and the connection terminal 101T (step S201). Next, the connection response reception processing unit 122 functions to receive a connection confirmation response (ARP reply) transmitted from the client device that has received the connection confirmation request transmitted in step S101 through the connection terminal 101T and the LANI / F101 (step S202).

[0055] After this, the connection response reception processing unit 122 extracts and aggregates the VLAN-ID attached to the connection confirmation response, and executes a process of comparing it with the stored data in the used ID table 103 (step S203). Then, according to the result of the comparison process in step S203, a VLAN-ID that exists in the used ID table 103 but does not exist in the received connection confirmation response is specified, and this is notified to the storage location deletion unit (step S204). The VLAN-ID specified here is for a group of client devices that were previously connected to the shared server 1 but are not currently connected.

[0056] Next, the storage location deletion unit 123 deletes the folders associated with the account corresponding to the specified VLAN-ID (step S205). That is, the storage location deletion unit 123 uses the account conversion table to specify the account corresponding to the specified VLAN-ID. Based on this specified account, the storage location deletion unit 123 refers to the access range setting table to specify the corresponding folders and files, and deletes the specified folders and files from the storage medium of the storage device 106. Therefore, as shown in FIG. 5, when "100" and "200" are registered as VLAN-IDs in the usage ID table 103, even if a connection confirmation request is sent and no connection confirmation response with the VLAN-ID of "100" is returned. In this case, it can be determined that the PC3 connected to the LAN port PT1 of the hub 2 has disconnected (been removed from the LAN port PT1).

[0057] Therefore, the process of step S205 is that the storage location deletion unit 123 specifies the account "group1" corresponding to the VLAN-ID "100" and deletes the folders A, B, and D associated with the account "group1". Note that the folders associated with the account "group1" corresponding to the VLAN-ID "100" are folders A, B, D, and E, and it is confirmed whether each of them is associated with other accounts. As a result, only the folders that can be confirmed not to be associated with other accounts are deleted.

[0058] Therefore, as shown in FIGS. 1 and 4, since the folder E is associated not only with the account "group1" but also with the account "group2", it is not deleted if the PC3 disconnects but the PC4 does not. In the case of this example, since no connection confirmation response with the VLAN-ID of "100" has been returned, the VLAN-ID "100" is also deleted from the usage ID table 103.

[0059] [Effects of the Embodiment] The shared server 1 of the above-described embodiment can restrict the folders that can be accessed according to the accounts associated with (linked to) the VLAN-IDs. That is, in the case of the example shown in FIG. 1, there is no need to go through the trouble of issuing accounts and performing sharing settings in advance for PC3 brought into Conference Room A and PC4 brought into Conference Room B as in the prior art. Considering the connection to the LAN port of hub 2 with the VLAN-ID set, if the access range setting table 104 and the account conversion table 105 are created in advance, it becomes possible to perform control to restrict the folders that can be accessed.

[0060] Specifically, as shown in FIG. 1, PC3 brought into Conference Room A is connected to the LAN port PT1 of hub 2 with the VLAN-ID set to "100". Just by this, PC3 can be made accessible only to folders A, B, D, and E stored in the storage device 106 of the shared server 1, and inaccessible to other folders. Similarly, as shown in FIG. 1, PC4 brought into Conference Room B is connected to the LAN port PT2 of hub 2 with the VLAN-ID set to "200". Just by this, PC4 can be made accessible only to folders E, F, H, and I stored in the storage device 106 of the shared server 1, and inaccessible to other folders.

[0061] Also, the shared server 1 of this embodiment can delete the folders restricted by access according to the VLAN-ID when there is no client device that sends an access request including the VLAN-ID. Thereby, for the folders targeted for access restriction, they will be deleted when there is no client device using them, so they can be protected from unauthorized use.

[0062] [Modification Example] In the above-described embodiment, different VLAN-IDs are set for each LAN port of the hub 2, such that the VLAN-ID = 100 is set for the LAN port PT1 of the hub 2 and the VLAN-ID = 200 is set for the LAN port PT2. However, this is not the only way. For example, the same VLAN-ID can be set for different LAN ports, such that the VLAN-ID = 100 is set for the LAN ports PT1, PT2, and PT3, and the VLAN-ID = 200 is set for the LAN ports PT4, PT5, and PT6.

[0063] Also, in the above-described embodiment, only one hub 2 was used, but the present invention can also be provided when multiple hubs are used. The key is to use the VLAN-ID set for each LAN port of the hub, and ensure that only the folder associated with the account corresponding to the VLAN-ID can be accessed for access requests from client devices with the same VLAN-ID assigned. For this reason, assume that hub 2(2) is connected to hub 2(1), the VLAN-ID of the LAN port PT1 of hub 2(1) is set to "100", and the VLAN-ID of the LAN port PT1 of hub 2(2) is set to "100". In this case, the PC3(1) connected to the LAN port PT1 of hub 2(1) and the PC3(2) connected to the LAN port PT1 of hub 2(2) can only access the folder associated with the account corresponding to the VLAN-ID.

[0064] In the above-described embodiment, it was described that folders A to I are formed in the storage device 106 of the shared server 1, but this is not the only way. Files not stored in the folder can also be subject to access restrictions and deletion processing.

[0065] [Others] As can be understood from the description of the above embodiments, the functions of the access range setting table and the account conversion table in the claims are realized by the access range setting table 104 and the account conversion table 105 of the shared server 1 in the embodiments. Also, the functions of the extraction means, the first conversion means, and the access control means in the claims are realized by the VLAN-ID extraction unit 111, the account conversion unit 112, and the per-account access control unit 113 of the shared server 1 in the embodiments. Further, the functions of the second conversion means and the granting means in the claims are realized by the VLAN-ID conversion unit 114 and the VLAN-ID granting unit 115 of the shared server 1 in the embodiments.

[0066] Also, the function of the storage means for storing and holding the VLAN-ID in the claims is realized by the used ID table 103 of the shared server 1 in the embodiments. The functions of the connection confirmation request transmission processing means, the connection response reception processing means, and the storage location deletion means in the claims are realized by the connection confirmation transmission processing unit 121, the connection response reception processing unit 122, and the storage location deletion unit 123 of the shared server 1 in the embodiments.

[0067] Also, a program for performing the processes shown in the flowcharts of FIGS. 8 and 9 is an application of one embodiment of the access restriction program according to the present invention. Therefore, also, the functions of the respective parts of the shared folder restriction control unit 110 of the shared server 1 shown in FIG. 4 can be realized as the functions of the control unit 102 by a program executed by the control unit 102. That is, the functions of the respective parts of the VLAN-ID extraction unit 111, the account conversion unit 112, the per-account access control unit 113, the VLAN-ID conversion unit 114, and the VLAN-ID granting unit 115 can be realized as the functions of the control unit 102 by a program. Similarly, the connection confirmation transmission processing unit 121, the connection response reception processing unit 122, and the storage location deletion unit 123 constituting the detachment handling unit 120 shown in FIG. 4 can be realized as the functions of the control unit 102 by a program executed by the control unit 102.

Description of Reference Numerals

[0068] 1... Shared server, 101T... Connection terminal, 101... LANI / F, 102... Control unit, 103... User ID table, 104... Access range setting table, 105... Account conversion table, 106... Storage device, R1... Access range of group 1, R2... Access range of group 2, A~I... Folders, 110... Shared folder restriction control unit, 111... VLAN-ID extraction unit, 112... Account conversion unit, 113... Access control unit for each account, 114... VLAN-ID conversion unit, 115... VLAN-ID assignment unit, 120... Disconnection handling unit, 121... Connection confirmation transmission processing unit, 122... Connection response reception processing unit, 123... Storage location deletion unit, 2... Hub, PT1, PT2,..., PT10... LAN ports, 3... PC, 4... PC

Claims

1. A shared server device connected to a hub device capable of dividing a broadcast domain for each VLAN-ID (Virtual Local Area Network-identification) by setting a VLAN-ID for each LAN (Local Area Network) port, an access range setting table that stores information associating a predetermined account with one or more data storage locations where access is permitted according to the account, an account conversion table that associates the VLAN-ID set for each LAN port of the hub device with the account, extraction means for extracting the VLAN-ID attached to an access request received from the hub device, first conversion means for converting the VLAN-ID extracted by the extraction means into the account based on the account conversion table, access control means for referring to the access range setting table based on the account converted by the first conversion means, enabling access to the data storage location corresponding to the access request and permitted for access, and forming an access response, second conversion means for converting the account used by the access control means into the VLAN-ID based on the account conversion table, and imparting means for imparting and outputting the VLAN-ID converted by the second conversion means to the access response formed by the access control means characterized in that it comprises a shared server device.

2. The shared server device according to claim 1, usage ID storage means for storing and holding the VLAN-ID extracted from the access request by the extraction means, connection confirmation request transmission processing means for forming and transmitting a connection confirmation request at predetermined timings, connection response reception processing means for receiving a connection confirmation response transmitted from a client device that has received the connection confirmation request transmitted through the connection confirmation request transmission processing means, extracting the VLAN-ID included in the connection confirmation response, comparing it with the VLAN-ID in the usage ID storage means, and identifying whether the client device that has transmitted the access request has left. Based on the account corresponding to the VLAN-ID corresponding to the client device determined to have disconnected by the connection response receiving processing means, the storage location deletion means refers to the access range setting table and deletes the associated data storage location A shared server device characterized by comprising the same.

3. An access restriction program executed on a computer mounted on a shared server device connected to a hub device capable of dividing a broadcast domain for each VLAN-ID by setting a VLAN-ID (Virtual Local Area Network-identification) for each LAN (Local Area Network) port, The shared server device includes an access range setting table that stores information associating a predetermined account with one or more data storage locations where access is permitted according to the account, and an account conversion table that associates the VLAN-ID set for each LAN port of the hub device with the account. An extraction step of extracting the VLAN-ID attached to the access request received from the hub device; A first conversion step of converting the VLAN-ID extracted in the extraction step into the account based on the account conversion table; Based on the account converted in the first conversion step, referring to the access range setting table, enabling access to the data storage location corresponding to the access request and permitted for access, and forming an access response; A second conversion step of converting the account used in the access control step into the VLAN-ID based on the account conversion table; An attachment step of attaching the VLAN-ID converted in the second conversion step to the access response formed in the access control step and outputting it An access restriction program characterized by having the same.

4. The access restriction program according to claim 3, The shared server device includes usage ID storage means for storing and holding the VLAN-ID extracted from the access request in the extraction step. A connection confirmation request transmission processing step of forming and transmitting a connection confirmation request for connection confirmation at a predetermined timing; A connection response reception processing step of receiving a connection confirmation response transmitted from a client device that has received the connection confirmation request transmitted through the connection confirmation request transmission processing step, extracting the VLAN-ID included in the connection confirmation response, comparing it with the VLAN-ID of the used ID storage means, and specifying whether the client device that has transmitted the access request has left; A storage location deletion step of referring to the access range setting table based on the account corresponding to the VLAN-ID corresponding to the client device determined to have left in the connection response reception processing step and deleting the associated data storage location; An access restriction program, characterized by comprising the above.

Citation Information

Patent Citations

  • Digital image communication system and server, and terminal

    JP2002171503A