Grasping usage status of service providing server device

The management system addresses the challenges of detecting duplicate function usage, lack of access information, and underutilized resources by aggregating usage data from multiple service-providing server devices, enabling improved efficiency and security through accurate tracking and management.

JP2025091913AActive Publication Date: 2025-06-19MOTEX INC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2023207458
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-08
Publication Date
2025-06-19
Estimated Expiration
2043-12-08

AI Technical Summary

Technical Problem

Existing systems fail to accurately detect and address issues such as duplicate function usage across multiple service-providing server devices, lack of access information from certain service-providing server devices, unused authorized service-providing server devices, and low usage of employee accounts, leading to inefficiencies and security concerns.

Method used

A management system that includes terminal devices with function access detection and information transmission capabilities, and a management server that aggregates usage status information from multiple service-providing server devices, enabling accurate tracking of function usage and identifying underutilized resources or unauthorized access.

Benefits of technology

The system effectively grasps the usage status of each function in service-providing server devices, identifies unused or unauthorized access, and takes appropriate measures, thereby improving efficiency and enhancing security and management capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025091913000001_ABST
    Figure 2025091913000001_ABST
Patent Text Reader

Abstract

To provide a technique for grasping the usage status of a service providing server device.SOLUTION: Each of communication means 12 of terminal devices T1, T2, ..., Tm can access functions prepared by service providing server devices SS1, SS2, ..., SSn and use the functions. Function access detection means 14 detects which function of the service providing server devices SS1, SS2, ..., SSn has been accessed and records it as function access information. Function access information transmission means 16 transmits the function access information to a management server device MS. Therefore, function access information acquisition means 24 of the management server device MS acquires the function access information from each of the terminal devices T1, T2, ..., Tm. Function aggregation means 22 of the management server device MS aggregates the acquired function access information for each function and outputs the aggregated information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to grasping the usage status of a service - providing server device.

Background Art

[0002] In enterprises and the like, the opportunity for each employee to access an external service - providing server device such as SaaS from their terminal device is increasing. There are service - providing server devices with various functions, and the service - providing server devices are properly used according to the functions required by the enterprise. Since it can be used by accessing the service - providing server device without installing a program having the function on the terminal device, there is an advantage that the barrier to use is low and it is easy to use.

[0003] Due to such ease of use, there are also employees who use service - providing devices not permitted by the enterprise's information system administrator. Such a situation is not preferable in terms of security and management, so countermeasures have been taken. For example, in Patent Document 1, from an accounting server (a server device that aggregates regular payments to each service - providing server device) and in - house network devices, etc., it is possible to obtain which service - providing server device an employee has accessed, and to check whether there is a device outside the management target among these accessed service - providing server devices. Thereby, access to an unauthorized service - providing server device can be extracted, and countermeasures can be taken.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in Patent Document 1, although it is possible to detect and eliminate access to an unauthorized service - providing server device, it was not possible to detect waste such as duplicate use of the same function in multiple service - providing server devices being used.

[0006] (b) In the prior art described in Patent Document 1, access information is obtained from the service - providing server device. However, depending on the service - providing server device, there are some that do not provide the information necessary to count the frequency of access, etc. For such service - providing server devices, there was a problem that the access situation could not be grasped and no countermeasure could be taken.

[0007] (c) In the prior art described in Patent Document 1, access to an unauthorized service - providing server device is detected and eliminated, but it has not been possible to detect an unused service - providing server device even though it is permitted, and thus efficiency improvement has not been achieved.

[0008] (d) Also, in cases where the use of an account set by a member such as an employee is not used at all or is extremely low in order to use the service of the service - providing server device, it is preferable to take countermeasures such as account suspension. For this purpose, it is necessary to grasp the usage status of the account in each service - providing server device, but there was a problem that this could not be done.

[0009] An object of the present invention is to provide a usage situation grasping technique that solves any one of the problems (a) to (d) above.

Means for Solving the Problems

[0010] Hereinafter, several independent features of the present invention are listed. These features are not essential to be combined and can be arbitrarily combined.

[0011] (1)-(5) A management system according to an embodiment of the present invention is a management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, The terminal device includes function access detection means for detecting which function of each service providing server device has been accessed, and function access information transmission means for transmitting, to the management server device, function access information indicating which function of each service providing server device has been accessed as detected by the function access detection means, The management server device is characterized by including function access information acquisition means for acquiring function access information from each terminal device, and function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each terminal device.

[0012] Therefore, it is possible to accurately grasp the usage status of each function in the service providing server device. Since the function access information in the terminal device is acquired, it is possible to grasp this even if the service providing server device does not provide the usage status of each function.

[0013] (6)(7) A management server device according to the present invention is a management server device that aggregates which functions of a plurality of service providing server devices are being used by a plurality of terminal devices, and includes function access information acquisition means for acquiring, from each of the service providing server devices, function access information indicating which function of each service providing server device has been accessed by each terminal device, and function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each service providing server device.

[0014] Therefore, it is possible to accurately grasp the usage status of each function in the service providing server device.

[0015] (8) The management system according to the present invention includes a terminal device, which also includes a terminal device connected to an external network of the organization. The terminal device is configured such that it cannot be connected to the internal network of the organization unless it is provided with function access detection means and function access information transmission means.

[0016] Therefore, substantially, it is possible to enforce that the terminal device is provided with function access detection means and function access information transmission means, which facilitates management.

[0017] (9) The management system according to the present invention is characterized in that function aggregation means aggregates the usage status of the same or similar functions in different service providing server devices, prohibits the use of the function of the service providing server device with less usage for the same function of a plurality of service providing devices, and proposes to use the same function of other service providing server devices.

[0018] Therefore, it is possible to integrate the function utilization of the service providing server device.

[0019] (10)(11) The management system according to the present invention includes a terminal device, which is provided with communication start detection means for detecting the start of communication in the terminal device, and communication operation determination means for determining the propriety of the operation of the communication whose start has been detected based on the communication operation determination information recorded in the recording unit, and stopping the communication determined to be inappropriate to operate. The management server device includes communication operation determination information setting means for communicating with the terminal device, transmitting the communication operation determination information to the terminal device, and causing the terminal device to record it, and registration means for registering, as the communication operation determination information, to prohibit communication to the function of the service providing device other than the service providing server device determined to be used for the same function of a plurality of service providing server devices.

[0020] Therefore, it is possible to ensure the integration of function utilization.

[0021] (12) The management system according to the present invention is characterized in that the function aggregation means identifies the users of the terminal devices that use the management functions of the service providing devices, and identifies the users as administrators when receiving services from the service providing devices.

[0022] Therefore, the administrator can be appropriately determined.

[0023] (13) The management system according to the present invention is characterized in that the function aggregation means identifies whether multi-factor authentication is performed when using each service providing device.

[0024] Therefore, it is possible to grasp whether multi-factor authentication is executed.

[0025] (14)-(18) The management system according to the present invention is a management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, The terminal device includes access detection means for detecting which of the service providing server devices has been accessed, and access information transmission means for transmitting, to the management server device, access information indicating which of the service providing server devices has been accessed, detected by the access detection means. The management server device includes access information acquisition means for acquiring access information from each terminal device, and specifying means for collating the access information acquired from each terminal device with a list of permitted service providing devices, and specifying service providing devices that are not used despite being permitted or service providing devices that are used despite not being permitted.

[0026] Therefore, it is possible to identify service providing devices that are not used despite being permitted or service providing devices that are used despite not being permitted, and take appropriate measures. Since the access information in the terminal device is acquired, it is possible to grasp this even if the service providing server device does not provide access information.

[0027] (19)(20) The management server device according to this invention is a management server device that identifies which of a plurality of service providing server devices a plurality of terminal devices are using. The management server device includes access information acquisition means for acquiring, from each of the service providing server devices, access information indicating which of the service providing server devices each terminal device has accessed, and identification means for comparing the access information acquired from each service providing server device with a list of permitted service providing devices and identifying a service providing device that is not being used despite being permitted or a service providing device that is being used despite not being permitted.

[0028] Therefore, it is possible to identify a service providing device that is not being used despite being permitted or a service providing device that is being used despite not being permitted, and take appropriate measures.

[0029] (21) The management system according to this invention includes a terminal device that also includes a terminal device connected to an external network of the organization. The terminal device is configured such that it cannot be connected to the internal network of the organization unless it is provided with the function access detection means and the function access information transmission means.

[0030] Therefore, it is possible to substantially enforce that the terminal device is provided with the function access detection means and the function access information transmission means, making management easier.

[0031] (22)(23) The management system according to this invention includes a terminal device that includes communication start detection means for detecting the start of communication in the terminal device, and communication operation determination means for determining the propriety of the operation of the communication for which the start has been detected based on communication operation determination information recorded in a recording unit and stopping the communication determined to be inappropriate to operate. The management server device includes communication operation determination information setting means for communicating with the terminal device, transmitting the communication operation determination information to the terminal device, and causing the terminal device to record it. As the communication operation determination information, there is provided registration means for registering to prohibit communication of the terminal device with a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted.

[0032] Therefore, access to an inappropriate service providing server device can be prohibited.

[0033] (24) The management system according to the present invention is characterized in that the function aggregation means, aggregation means or specifying means of the management server device specifies an access destination in consideration of the operation log of the program or the communication log of the process.

[0034] Therefore, the access destination can be specified more accurately.

[0035] (25)-(29) The management system according to the present invention is a management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, wherein the terminal device includes login ID acquisition means for acquiring the user's terminal login ID or terminal ID used during the login process, access detection means for detecting access to an account of a service providing server device, and access information transmission means for attaching the terminal login ID or terminal ID to information indicating access to the service providing server device detected by the access detection means and transmitting the information as terminal acquired access information to the management server device. The management server device includes: a server account information acquisition means for acquiring, from the service providing server device, account information indicating each account opened in the service providing server device and the server login ID of each account; a terminal acquisition access information acquisition means for acquiring terminal acquisition access information from each terminal device; a history generation means for aggregating the terminal acquisition access information acquired from each terminal device for each user based on the terminal login ID or terminal ID to generate an access history; and an aggregation means for specifying which user each account of the service providing server device belongs to based on the terminal login ID or terminal ID or user information recorded in association with any of these and the server login ID, associating each account with the access history, and aggregating the usage status of each account.

[0036] Therefore, even if the service providing server device does not provide detailed usage status of the accounts, the usage status of each account can be obtained.

[0037] (30)(31) The management server device according to this invention includes: a server account information acquisition means for acquiring, from the service providing server device, each account opened in the service providing server device and account information indicating the usage history of each account; and an aggregation means for aggregating the usage status of each account based on the account information acquired from the service providing server device.

[0038] Therefore, the usage status of each account of the service providing server device can be grasped.

[0039] (32) The management system according to this invention is characterized in that the terminal device, which also includes a terminal device connected to an external network of the organization, is configured so that it cannot be connected to the internal network of the organization unless it is provided with the access detection means and the access information transmission means.

[0040] Therefore, substantially, it is possible to force the terminal device to include function access detection means and function access information transmission means, making management easier.

[0041] (33) The management system according to the present invention is characterized in that the aggregation means identifies accounts that are not used or are rarely used in the service - providing server device, and performs a process for deleting the accounts in the service - providing server device.

[0042] Therefore, it is possible to delete unwanted accounts.

[0043] (34) In the management system according to the present invention, the terminal - acquired access information and the server - acquired access information include IP address information used when the terminal device accessing the Internet accesses the Internet. The aggregation means detects access from a terminal device not managed by the management server device to an account of the service - providing server device based on the difference between the IP address information included in the terminal - acquired access information and the IP address information included in the server - acquired access information.

[0044] Therefore, it is possible to prevent unauthorized access and use from a personal terminal device or the like to a business account of the service - providing server device.

[0045] (35)-(37) The management system according to the present invention is a management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices. The terminal device includes at least one processor and a storage for recording an agent configured to be executed by the at least one processor. The agent detects which function of each service - providing server device has been accessed, and includes an instruction to transmit function access information indicating which function of each service - providing server device has been accessed to the management server device. The management server device includes at least one processor and a storage for recording a management program configured to be executed by the at least one processor. The management program is characterized by including an instruction to acquire function access information from each terminal device and aggregate the usage status of each function in each service providing server device based on the function access information acquired from each terminal device.

[0046] Therefore, it is possible to accurately grasp the usage status of each function in the service providing server device. Since the function access information in the terminal device is acquired, it is possible to grasp this even if the service providing server device does not provide the usage status of each function.

[0047] (38)(39) The management server device according to this invention is a management server device that aggregates which functions of a plurality of service providing server devices are being used by a plurality of terminal devices. It includes at least one processor and a storage for recording a management program configured to be executed by the at least one processor. The management program acquires function access information indicating which function of each service providing server device each terminal device has accessed from each service providing server device, and includes an instruction to aggregate the usage status of each function in each service providing server device based on the function access information acquired from each service providing server device.

[0048] Therefore, it is possible to accurately grasp the usage status of each function in the service providing server device.

[0049] (40)-(42) The management system according to this invention is a management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices. The terminal device includes at least one processor and a storage for recording an agent configured to be executed by the at least one processor. The agent is configured to detect which of the service providing server devices has been accessed, and includes an instruction to transmit access information indicating which of the service providing server devices has been accessed, which has been detected, to the management server device. The management server device includes at least one processor and a storage for recording a management program configured to be executed by the at least one processor. The management program is configured to obtain access information from each terminal device, compare the access information obtained from each terminal device with a list of permitted service providing devices, and identify a service providing device that has not been used despite being permitted or a service providing device that has been used despite not being permitted.

[0050] Therefore, it is possible to identify a service providing device that has not been used despite being permitted or a service providing device that has been used despite not being permitted, and take appropriate measures. Since the access information in the terminal device is obtained, it is possible to grasp this even if the service providing server device does not provide access information.

[0051] (43)(44) The management server device according to the present invention is a management server device that identifies which of a plurality of service providing server devices a plurality of terminal devices are using, and includes at least one processor and a storage that records a management program configured to be executed by the at least one processor. The management program acquires access information indicating which of the service providing server devices each terminal device has accessed from each of the service providing server devices, collates the access information acquired from each service providing server device with a list of permitted service providing devices, and includes an instruction to identify a service providing device that is not being used despite being permitted or a service providing device that is being used despite not being permitted.

[0052] Therefore, it is possible to identify a service providing device that is not being used despite being permitted or a service providing device that is being used despite not being permitted, and take appropriate measures.

[0053] (45)-(47) The management system according to the present invention is a management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices. The terminal device includes at least one processor and a storage that records an agent configured to be executed by the at least one processor. The agent acquires the terminal login ID of the user used during the login process, detects access to the account of the service providing server device, attaches the terminal login ID to the information indicating access to the detected service providing server device, and includes an instruction to transmit it as terminal acquired access information to the management server device. The management server device includes at least one processor and a storage for recording a management program configured to be executed by the at least one processor. The management program acquires account information indicating each account opened in the service providing server device and the server login ID of each account from the service providing server device, acquires terminal acquisition access information from each terminal device, aggregates the terminal acquisition access information acquired from each terminal device for each user based on the terminal login ID to generate an access history, and is characterized by including an instruction for specifying which user each account of the service providing server device belongs to based on the terminal login ID or user information recorded in association with the terminal login ID and the server login ID, associating each account with the access history, and aggregating the usage status of each account.

[0054] Therefore, even if the service providing server device does not provide detailed usage status of accounts, the usage status of each account can be obtained.

[0055] (48)(49) The management server device according to this invention includes at least one processor and a storage for recording a management program configured to be executed by the at least one processor. The management program acquires each account opened in the service providing server device and account information indicating the usage history of each account from the service providing server device, and includes an instruction for aggregating the usage status of each account based on the account information acquired from the service providing server device.

[0056] Therefore, the usage status of each account of the service providing server device can be grasped.

[0057] In the embodiment, "function access detection means" corresponds to step S29.

[0058] In the embodiment, "functional access information transmission means" corresponds to step S35.

[0059] In the embodiment, "functional access information acquisition means" corresponds to step S156.

[0060] In the embodiment, "function aggregation means" corresponds to step S157.

[0061] In the embodiment, "access detection means" corresponds to step S29.

[0062] In the embodiment, "access information transmission means" corresponds to step S35.

[0063] In the embodiment, "access information acquisition means" corresponds to step S156.

[0064] In the embodiment, "specification means" corresponds to step S158.

[0065] In the embodiment, "login ID acquisition means" corresponds to step S20.

[0066] In the embodiment, "server account information acquisition means" corresponds to step S162.

[0067] In the embodiment, "terminal acquired access information acquisition means" corresponds to step S156.

[0068] In the embodiment, "history generation means" corresponds to step S163.

[0069] In the embodiment, "aggregation means" corresponds to step S164.

[0070] The term "device" includes not only what is constituted by a single computer, but also what is constituted by a plurality of computers connected via a network or the like. Therefore, when the means (or a part of the means) of the present invention is distributed among a plurality of computers, these plurality of computers correspond to the device.

[0071] The term "program" includes not only a program directly executable by a CPU, but also a program in source form, a compressed program, an encrypted program, a program that cooperates with an operating system to exhibit its functions, and the like.

Brief Description of the Drawings

[0072]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Figure 17

Figure 18

Figure 19

Figure 20

Figure 21

Figure 22

Figure 23

Figure 24

Figure 25

Figure 26

Figure 27

Figure 28

Figure 29

Figure 30

Figure 31

Figure 32

Figure 33

Figure 34

Figure 35

Figure 36

Figure 37

Figure 38

Figure 39

Figure 40

Modes for Carrying Out the Invention

[0073] 1. First Embodiment 1.1 Functional Configuration FIG. 1 shows the functional configuration of a management system according to an embodiment of the present invention. Service providing server devices SS1, SS2 ··· SSn such as SaaS are provided on the Internet. Terminal devices T1, T2 ··· Tm are terminal devices used by members of an enterprise (organization) or the like.

[0074] Each communication means 12 of the terminal devices T1, T2 ··· Tm can access each function prepared by the service providing server devices SS1, SS2 ··· SSn and use the function. The function access detection means 14 detects which function of the service providing server devices SS1, SS2 ··· SSn has been accessed and records it as function access information.

[0075] The function access information transmission means 16 transmits the function access information to the management server device MS. Therefore, the function access information acquisition means 24 of the management server device MS will acquire the function access information from each terminal device T1, T2... Tm. The function aggregation means 22 of the management server device MS aggregates and outputs the acquired function access information for each function.

[0076] As described above, since the function access information is acquired from each terminal device T1, T2... Tm, the access status of each function of each service providing server device can be accurately grasped. In addition, since the usage status in a plurality of service providing server devices SS1 to SSn is aggregated for each function, it can be used for efficiency improvement in terms of functions.

[0077] An example of the processing according to this embodiment will be described with reference to FIG. 27. An agent is installed in the in-house terminal device IT (such as a PC or a smartphone) prepared in the company. Similarly, an agent is also installed in the terminal device OT (such as a PC or a smartphone) that the company approves for use in telecommuting.

[0078] The agents of the terminal devices IT and OT record which function of which SaaS server device the terminal device has accessed. The management server device MS acquires the access status of each terminal device IT and OT from these agents.

[0079] Since the management server device MS aggregates the access status from each terminal device IT and OT, it is possible to know how much each function of each SaaS server device is used even if the SaaS server device does not provide detailed access status.

[0080] 1.2 Hardware Configuration FIG. 2 shows the system configuration of the management system. In this embodiment, as the terminal device T, an in-house terminal device IT and an out-of-house terminal device OT are used.

[0081] The in-house terminal devices IT1, IT2 ··· ITm are connected to the in-house network (intra-organizational network) by wire or wirelessly. A shared server device (not shown) is connected to the in-house network, and data necessary for business operations and the like are recorded thereon. Each of the in-house terminal devices IT1, IT2 ··· ITm can access the shared server device via the in-house network, and can use these data and the like.

[0082] The external terminal devices OT1 ··· OTp can be connected to the in-house network via a VPN over the Internet connected by wire or wirelessly. In the case of telecommuting or the like, it is possible to connect to the in-house network via such a VPN, connect to the shared server device, and conduct business.

[0083] A management server device MS is provided on the Internet. Also, SaaS server devices SS1 ··· SSq that provide various business applications and the like having functions in the cloud are provided.

[0084] Fig. 3 shows the hardware configurations of the terminal devices IT and OT. A memory 32, a display 34, an SSD (which may be a storage device such as a hard disk) 36, a DVD-ROM drive 38, a keyboard / mouse 40, and a communication circuit 42 are connected to the CPU 30. The communication circuit 42 is a circuit for connecting to the in-house network and the Internet.

[0085] An operating system 50, processes P1 ··· Pr, and an agent 52 are recorded on the SSD 36. The processes P1 ··· Pr and the agent 52 cooperate with the operating system 50 to exhibit their functions.

[0086] The operating system 50 and processes P1...Pr are recorded on a DVD-ROM 58 and then installed on the SSD 36 via the DVD-ROM drive 38. Alternatively, they may be installed from an external recording device such as a USB memory. Furthermore, these programs may be downloaded from a server device or a management server device on the Internet and then installed.

[0087] Processes P1...Pr are individual functions of an application program (for example, a process that connects to a SaaS server device SS and obtains a processing result). In other words, a number of processes are gathered together to construct one application program. One process may also construct one application program.

[0088] The agent 52 is downloaded from the management server device MS and installed. It should be noted that the agent 52 may be installed from the DVD-ROM 78.

[0089] 4 shows the hardware configuration of the management server device MS. A memory 62, a communication circuit 64, an SSD (which may be a storage device such as a hard disk) 66, and a DVD-ROM drive 68 are connected to a CPU 60. The communication circuit 64 is a circuit for connecting to the Internet.

[0090] The SSD 66 stores an operating system 70 and a management server program 72. The management server program 72 cooperates with the operating system 70 to fulfill its functions.

[0091] The operating system 70 and the management server program 72 were installed on the SSD 66 via the DVD-ROM drive 68 from what was recorded on the DVD-ROM 78. Also, what was recorded on an external recording device such as a USB memory may be installed. Furthermore, these programs may be downloaded and installed from a server device on the Internet.

[0092] 1.3 Recording process of communication logs in each terminal device Fig. 5 shows a flowchart of the process for recording communication logs. This process is executed by the CPU 60 based on the operating system (hereinafter referred to as OS) 50, the agent 52, and the processes P1···Pr in the terminal devices IT and OT. Hereinafter, the case where the CPU 30 performs processing based on the OS 50 is expressed as "the OS 50 performs processing". The same notation is used for other programs.

[0093] When the process P, which is a browser program or an application (or the programs constituting these), uses the functions of the SaaS server device SS on the Internet, it needs to request the OS 50 to communicate with the SaaS server device and receive the processing result. Therefore, the process P gives a communication command indicating the URL of the SaaS server device as the communication partner and the desired processing content to the OS 50 (step S41).

[0094] In this embodiment, when the OS 50 receives a communication command, it notifies the agent 52 of the content (step S5). Such a function can be realized by a hook function or the like prepared in the OS 50. In the figure, the horizontal dashed line indicates the interaction between programs within the same terminal devices IT and OT.

[0095] The agent 52 records the content of the communication command in association with the usage user information of the terminal devices IT and OT (step S29). Note that which user is using the device can be specified by the user ID when logging in to the terminal devices IT and OT.

[0096] When the agent 52 permits communication, the OS 50 accesses the SaaS server device SS based on the command and requests the desired processing (step S7). In response to this, the SaaS server device SS executes the requested processing and transmits the processing result to the OS 50 of the terminal devices IT and OT (step S101). The OS 50 receives the processing result through communication and provides it to the process P (step S8).

[0097] Hereinafter, the process P uses the processing functions of the SaaS server device SS via the OS 50 as necessary.

[0098] Fig. 6 shows the communication log recorded in step S29. The date and time, user name, program name (process name), URL, etc. are recorded.

[0099] 1.4 Collection and aggregation of communication logs in the management server device Fig. 7 shows a flowchart of the process in which the management server device MS collects and aggregates communication logs from each of the terminal devices IT and OT. The CPU 60 of the management server device MS (hereinafter sometimes abbreviated as the management server device MS) transmits a request for communication logs to each of the terminal devices IT and OT (step S155).

[0100] In response to this, each of the terminal devices IT and OT returns the recorded communication logs to the management server device MS (step S35). The management server device MS receives the communication logs from each of the terminal devices IT and OT (step S156).

[0101] For example, if the above process is executed once a day, the daily communication logs of each terminal device IT and OT can be obtained. In this embodiment, the management server device MS requests communication logs from the terminal devices IT and OT. However, the terminal devices IT and OT may also spontaneously send communication logs to the management server device MS.

[0102] Based on the communication logs for a predetermined period obtained from each terminal device IT and OT, the management server device MS aggregates the usage status for each function of the SaaS server device (step S157). As shown in the communication log of FIG. 6, the URL of the connection destination is recorded. Since this URL differs for each function, aggregation for each function is possible.

[0103] In this embodiment, as shown in FIG. 8, a correspondence table between the functions and URLs of each SaaS server device SS is prepared in advance. Note that depending on the SaaS server device SS, it may not be possible to determine solely based on the URL, and in some cases, it may be possible to determine by looking at the query parameters. In such cases, the function is specified in association with the URL and the query parameters.

[0104] Based on this correspondence table, the management server device MS aggregates how many times each function of each SaaS server device has been used during the aggregation period. FIG. 9 shows the aggregated data of the generated usage status. How each function of each SaaS server device is used is shown. Note that in FIG. 9, only a part of the usage status of the user "TaroMorete" is shown, but the usage status of all other users who use the terminal devices IT and OT is also aggregated. Also, in the communication log shown in FIG. 7, access to servers other than the SaaS server device SS is included, so only access to the SaaS server device SS is selected using the correspondence table of FIG. 8.

[0105] Furthermore, based on the aggregated data in FIG. 9, the management server device MS counts how many times each function of each SaaS server device is used. FIG. 10 shows an example of the count. This makes it possible to identify functions with low usage counts or functions that are not used at all.

[0106] The information system administrator can access the management server device MS from their own terminal device IT, view this information, and consider contract termination for unused functions.

[0107] In addition, based on the usage situation, the management server device MS can also propose integration or the like regarding the function usage of the SaaS server device SS. In this case, the management server device MS records a list of functions that can be exchanged between different SaaS server devices SS as shown in FIG. 11.

[0108] When the management server device MS obtains usage aggregation as shown in FIG. 10, it extracts the functions of the SaaS server device SS that can be exchanged with reference to FIG. 11 and obtains their usage counts (usage times). In the case of FIG. 10, it compares the usage counts (853 times, 347 times, 35 times) of calendar viewing, addition, and deletion of Gagarin's calendar with the usage counts (2 times, 1 time, 0 times) of calendar viewing, addition, and deletion of the web calendar, and proposes aggregating the less frequent calendar functions of the web calendar to Gagarin. The information system administrator can consider contract cancellation with the SaaS server device SS after seeing this.

[0109] As shown in FIG. 11, if it is necessary to exchange as an integral part with other functions as an exchangeable condition, it is preferable to record this in the table as a condition.

[0110] Also, in order to be able to prohibit communication with the SaaS server device SS whose contract has been cancelled, or to be able to prohibit the startup of the process for using the SaaS server device SS, the process control and communication control described in the fourth to sixth embodiments may be used.

[0111] 1.5 Variation Example (Others) (1) In the above embodiment, the agent 52 uses the hook function of the OS 50 to obtain the communication destination of the process P. However, alternatively or in addition to this, the communication destination may be obtained using a communication status list. Also, the communication destination may be obtained using the communication log of the OS 50.

[0112] (2) In the above embodiment, the communication destination of the program operating on the OS 50 is obtained. However, the agent 52 may obtain the operation log (process operation log) of the program, and determine which function of the SaaS server device SS is being used from the page title etc. included in the operation log. For example, if the page title is "Add Calendar", it can be determined that the calendar addition function is being used. To perform this accurately, it is preferable to prepare a correspondence table between the page title displayed when each function of each SaaS server device SS is used and the function.

[0113] In the following embodiments, when referring to the "communication log", it also means "only the communication log" or "not only the communication log but also the process operation log" as described above.

[0114] (3) In the above embodiment, the agents 52 of the terminal devices IT and OT obtain and record access to each function of each SaaS server device SS. However, as shown in FIG. 12, if the service providing server device SS provides an access log (function access information) to each function, the function access information may be obtained from each service providing server device SS.

[0115] Also, for the target service providing server device SS, it may be possible to combine obtaining function access information from the terminal device T and obtaining function access information from the service providing server device.

[0116] Further, it may be possible to obtain functional access information from both the terminal device T and the service - providing server device SS, and to complement any missing information.

[0117] For example, when an operation of "sharing a specific file with a specific user" is performed on the SaaS server device SS, the terminal devices IT and OT do not record "which file?" and "to whom?" However, in the case of the service - providing server device, it is possible to record "which file?" and "to whom?", so by obtaining functional access information from the service - providing server device, these usage situations can also be grasped.

[0118] By doing so, in incident response and the like, events can be accurately traced.

[0119] (4) In the above - described embodiment, the functions used by the service - providing server device SS are aggregated. Among these functions, it may be possible to detect which employees are accessing the administrator functions necessary for receiving the services provided by the service - providing server device SS. As a result, the information system administrator can know which employees are registered as the administrator when receiving the said service.

[0120] As a result, in the case where a problem occurs in service provision, etc., corresponding measures can be taken through the said employee. Also, in some cases, instead of the said employee, the information system administrator can be changed to be the administrator when receiving the said service. Also, it is possible to immediately identify who the administrator of the non - permitted SaaS is.

[0121] Furthermore, when logging in to the service - providing server device SS, it may be determined based on the communication log from the terminal device whether multi - factor authentication such as two - factor authentication is being performed. In the case of multi - factor authentication, for example, at the time of login, it is shown that the authentication process is performed multiple times, such as access to the login screen, access to some multi - factor authentication process, access to some multi - factor authentication process, and access to the screen after successful login. Therefore, the management server device can check the communication log to confirm whether multi - factor authentication is being performed.

[0122] Similarly, when single sign - on is performed, access to the server that manages single sign - on occurs, so this can be confirmed.

[0123] As an in - house rule, when multi - factor authentication is mandatory, the information system administrator can check this and determine, for example, which SaaS services (utilization of the service - providing server device SS) do not perform multi - factor authentication. Also, as an in - house rule, when single sign - on (not performing single sign - on) is mandatory, the information system administrator can check this and determine, for example, which SaaS services perform single sign - on during utilization.

[0124] (5) In the above - described embodiment, the management server device MS is placed on the Internet. However, the management server device MS may be placed on the in - house network. If the management target is only the terminal device IT connected to the in - house network, this may be done. In this case, if the terminal devices connected to the external network (network outside the organization) are also to be management targets, it may be premised that such terminal devices must be connected to the in - house network via a VPN for use.

[0125] (6) In the above-described embodiment, based on the correspondence table in FIG. 8, the management server device MS aggregates how each function of each SaaS server device is used. That is, a URL or the like is sent as function access information from each terminal device.

[0126] However, the correspondence table in FIG. 8 may be recorded in (or configured to be accessible to) each terminal device, and whether each terminal device has accessed a function of each SaaS server device may be recorded, and this may be transmitted as function access information to the management server device MS. The management server device MS aggregates how each function of each SaaS server device is used based on the data from each terminal device.

[0127] (7) The above-described embodiment and its modifications can be implemented in combination with each other. Also, they can be implemented in combination with other embodiments and their modifications.

[0128] 2. Second Embodiment 2.1 Functional Configuration In the first embodiment, the usage status is grasped for each function of the service providing server device SS. In this embodiment, the usage status of each service providing server device SS is grasped, and a service providing server device SS with little or no usage is specified.

[0129] FIG. 13 shows the functional configuration of the management system according to the second embodiment. Service providing server devices SS1, SS2,..., SSn such as SaaS are provided on the Internet. Terminal devices T1, T2,..., Tm are terminal devices used by organizational members such as enterprises.

[0130] Each communication means 12 of the terminal devices T1, T2,..., Tm can access each function provided by the service providing server devices SS1, SS2,..., SSn and use the function. The access detection means 18 detects which of the service providing server devices SS1, SS2,..., SSn has been accessed and records it as access information.

[0131] The access information transmission means 20 transmits access information to the management server device MS. Therefore, the access information acquisition means 28 of the management server device MS will acquire access information from each terminal device T1, T2... Tm. The specifying means 26 of the management server device MS refers to the access information, collates it with the list of service providing devices that permit access, and specifies service providing server devices that are used less or not used at all.

[0132] As described above, since the access information is acquired from each terminal device T1, T2... Tm, even if the service providing server device SS does not provide detailed access information, the usage status of the service providing server device SS can be grasped, and service providing server devices SS that are used less or not used at all can be specified.

[0133] An example of the processing according to this embodiment will be described with reference to FIG. 27. An agent is installed in in-house terminal devices IT (such as PCs and smartphones) prepared by a company. Similarly, an agent is also installed in terminal devices OT (such as PCs and smartphones) that the company permits to be used for telecommuting.

[0134] The agents of the terminal devices IT and OT record which SaaS server device SS the terminal device has accessed. The management server device MS acquires the access status of each terminal device IT and OT from these agents.

[0135] Therefore, the management server device MS can aggregate the access status from each terminal device IT and OT and know how much each SaaS server device is used.

[0136] 2.2 System Configuration · Hardware Configuration The system configuration, the hardware configuration of the terminal device T, and the hardware configuration of the management server device MS are the same as those in FIGS. 2, 3, and 4 in the first embodiment.

[0137] 2.3 Management Process The flowchart of the communication record acquisition of the terminal device in this embodiment is the same as that in FIG. 5. Also, in step S29 of FIG. 5, the communication logs collected by each terminal device T1, T2 ··· Tm are the same as those in FIG. 6.

[0138] FIG. 14 shows a flowchart of the process in which the management server device MS collects and aggregates communication logs from each terminal device IT, OT. The management server device MS sends a request for communication logs to each terminal device IT, OT (step S155).

[0139] Upon receiving this, each terminal device IT, OT returns the recorded communication logs to the management server device MS (step S35). The management server device MS receives the communication logs from each terminal device IT, OT (step S156).

[0140] For example, if the above process is executed once a day, the daily communication logs of each terminal device IT, OT can be obtained. In this embodiment, the management server device MS requests communication logs from the terminal devices IT, OT, but the terminal devices IT, OT may also spontaneously send communication logs to the management server device MS.

[0141] The management server device MS aggregates the usage status for each SaaS server device based on the communication logs for a predetermined period obtained from each terminal device IT, OT (step S158). As shown in the communication log of FIG. 6, the URL of the connection destination is recorded. By looking at this URL, it is possible to aggregate which SaaS server device SS is being accessed.

[0142] In this embodiment, as shown in FIG. 15, a correspondence table between each SaaS server device SS (service) and the URL is prepared in advance. The management server device MS aggregates, based on this correspondence table, how many times each SaaS server device has been used during the aggregation period.

[0143] Figure 16 shows the aggregated data of the generated usage status. It shows how each SaaS server device is being used. Note that in Figure 16, only a part of the usage status of the user "TaroMorete" is shown, but the usage status of all other users who use the terminal devices IT and OT is also aggregated. Also, in the communication log shown in Figure 7, access to servers other than the SaaS server device SS is included, so only the access to the SaaS server device SS is selected using the correspondence table in Figure 15.

[0144] Furthermore, based on the aggregated data in Figure 16, the management server device MS counts how many times each SaaS server device SS is used. Figure 17 shows an example of the counting. The management server device MS cross-checks with the list of SaaS server devices SS that it manages (and that the organization has permitted).

[0145] The management server device MS extracts the usage frequency of the SaaS server devices SS included in the list and selects those that are not being used or have a low usage frequency. This makes it possible to identify SaaS server devices with few usage times or those that are not being used at all among the SaaS server devices contracted by paying usage fees or the like.

[0146] The information system administrator can access the management server device MS from their terminal device IT to view this information and consider contract termination of SaaS server devices that are not being used or have a low usage frequency.

[0147] Also, in order to be able to prohibit communication to the SaaS server device SS whose contract has been cancelled, or to be able to prohibit the start of a process for using the SaaS server device SS, the process control and communication control described in the fourth to sixth embodiments may be used.

[0148] 2.4 Variants (Others) (1) In the above embodiment, the agent 52 uses the hook function of the OS 50 to obtain the communication destination of the process P. However, alternatively or in addition to this, the communication destination may be obtained using a communication status list.

[0149] (2) In the above embodiment, the communication destination of the program operating on the OS 50 is obtained. However, the agent 52 may obtain the operation log of the program and determine which SaaS server device SS is being used from URLs and the like included in the operation log.

[0150] (3) In the above embodiment, the management server device MS extracts unused or low-frequency SaaS server devices SS that it manages (and that the organization has permitted). However, accesses to SaaS server devices SS other than those it manages may be extracted. This allows the system administrator to detect accesses to unmanaged SaaS server devices SS and cancel contracts or re-contract as needed.

[0151] (4) In the above embodiment, the agents 52 of the terminal devices IT and OT obtain and record accesses to each SaaS server device SS. However, if the service-providing server device SS provides an access log (access information), the access information may be obtained from each service-providing server device SS.

[0152] Also, for the target service-providing server device SS, the method of obtaining access information from the terminal device T and the method of obtaining access information from the service-providing server device may be combined.

[0153] Also, access information may be obtained from both the terminal device T and the service-providing server device SS, and any missing information may be supplemented.

[0154] Even if it is a service - providing server device not approved by the information - system administrator for company use, when access logs are provided based on the user's email address or the like, it is possible to grasp access to the service - providing server device not approved by the information - system administrator for company use.

[0155] (5) The above - described embodiments and their modifications can be implemented in combination with each other. Also, they can be implemented in combination with other embodiments and their modifications.

[0156] 3. Third Embodiment 3.1 Functional Configuration In the above - described embodiment, access to the service - providing server device SS or access to each of its functions is acquired and aggregated. In this embodiment, the usage status of the accounts set in the service - providing server device SS is aggregated.

[0157] FIG. 18 shows the functional configuration of the management system according to the third embodiment. Service - providing server devices SS1, SS2 ··· SSn such as SaaS are provided on the Internet. Terminal devices T1, T2 ··· Tm are terminal devices used by organizational members (such as employees) of an organization such as a company.

[0158] Each login - ID acquisition means 11 of the terminal devices T1, T2 ··· Tm acquires a terminal - login ID (information other than the password input at login, such as a user name) when an organizational member uses the terminal device. Each communication means 12 of the terminal devices T1, T2 ··· Tm accesses the service - providing server devices SS1, SS2 ··· SSn and can use the services. The access - detection means 14 detects which of the service - providing server devices SS1, SS2 ··· SSn has been accessed and records it as terminal - acquired access information.

[0159] The access information transmission means 16 transmits access information to the management server device MS. Therefore, the terminal acquisition access information acquisition means 21 of the management server device MS will acquire terminal acquisition access information from each terminal device T1, T2 ··· Tm. The history generation means 23 of the management server device MS aggregates the acquired terminal acquisition access information for each terminal login ID and generates an access history.

[0160] The server account information acquisition means 27 of the management server device MS acquires account information indicating which account has been used from each service providing server device SS1 to SSn.

[0161] The aggregation means 25 associates the two based on the terminal login ID and the server login ID, and determines which access history the account in the server device corresponds to. Thereby, the usage status of each account of each service providing server device can be obtained.

[0162] As described above, the usage status acquired in each terminal device T1, T2 ··· Tm is associated with the account of the service providing server device SS based on the terminal login ID and the server login ID. Therefore, even if the service providing server device SS does not provide detailed access information of the account, the usage status of the account can be grasped.

[0163] An example of the processing according to this embodiment will be described with reference to FIG. 27. An agent is installed on in-house terminal devices IT (such as PCs and smartphones) prepared in a company. Similarly, an agent is also installed on terminal devices OT (such as PCs and smartphones) that the company has approved for use in telecommuting.

[0164] The agents of the terminal devices IT and OT record which SaaS server device SS the terminal device has accessed. The management server device MS acquires the access status of each terminal device IT and OT from these agents. This access status also includes the frequency of access to the SaaS server device SS, etc.

[0165] On the other hand, the management server device MS acquires account information from the SaaS server device SS (see F in the figure). This account information does not record the details of account usage (such as usage frequency, etc.).

[0166] Therefore, the management server device MS associates the account of the SaaS server device SS with the login ID of the terminal device. Thereby, the usage details for each account of the SaaS server device SS can be obtained.

[0167] 3.2 System Configuration - Hardware Configuration The system configuration, the hardware configuration of the terminal device T, and the hardware configuration of the management server device MS are the same as those in FIGS. 2, 3, and 4 in the first embodiment.

[0168] 3.3 Communication Log Recording Process in Each Terminal Device FIG. 19 shows a flowchart of the process for recording communication logs. This process is executed by the CPU 60 based on the operating system (hereinafter referred to as OS) 50, the agent 52, and the processes P1 ··· Pr in the terminal devices IT and OT. Hereinafter, the case where the CPU 30 performs processing based on the OS 50 is expressed as "the OS 50 performs processing". The same notation is used for other programs.

[0169] Employees who use the IT and OT terminal devices perform a login process after starting up the IT and OT terminal devices. That is, the agent 52 requests the input of a login ID (user ID) and a password, and does not permit the use of the IT and OT terminal devices unless these match a pre-registered combination (step S20). An employee whose use is permitted can use the programs of the IT and OT terminal devices.

[0170] When the process P, which is a browser program or an application (or a program that constitutes these), uses the functions of the SaaS server device SS on the Internet, it needs to request the OS 50 to communicate with the SaaS server device and receive the processing result. Therefore, the process P gives a communication command indicating the URL of the SaaS server device that is the communication partner to the OS 50 and indicating the desired processing content (step S41).

[0171] In this embodiment, when the OS 50 receives a communication command, it notifies the agent 52 of the content (step S5). Such a function can be realized by a hook function or the like prepared in the OS 50.

[0172] The agent 52 records the content of the communication command in association with the user information for using the IT and OT terminal devices (step S29). Note that which user is using it can be specified by the user ID when logging in to the IT and OT terminal devices.

[0173] When the agent 52 permits communication, the OS 50 accesses the SaaS server device SS based on the command and requests the desired processing (step S7). In response to this, the SaaS server device SS executes the requested processing and transmits the processing result to the OS 50 of the IT and OT terminal devices (step S101). The OS 50 receives the processing result by communication and gives it to the process P (step S8).

[0174] Hereinafter, the process P uses the processing functions of the SaaS server device SS via the OS 50 as necessary.

[0175] Figure 6 shows the communication log recorded in step S29. The date and time, terminal login ID (login username), program name (process name), URL, etc. are recorded.

[0176] 3.4 Collection and Aggregation of Communication Logs in the Management Server Device Figure 20 shows a flowchart of the process in which the management server device MS collects and aggregates communication logs from each terminal device IT, OT. The management server device MS sends a request for communication logs to each terminal device IT, OT (step S155).

[0177] Upon receiving this, each terminal device IT, OT returns the recorded communication logs to the management server device MS (step S35). The management server device MS receives the communication logs from each terminal device IT, OT (step S156).

[0178] For example, if the above process is executed once a day, the daily communication logs of each terminal device IT, OT can be obtained. In this embodiment, the management server device MS requests communication logs from the terminal devices IT, OT, but the terminal devices IT, OT may also spontaneously send communication logs to the management server device MS.

[0179] Based on the communication logs received from each terminal device IT, OT, the management server MS aggregates and records the access history of each SaaS server device SS for each login ID of each terminal device IT, OT (step S157).

[0180] The aggregated access history is shown in Figure 22. For each SaaS server device SS, the number of times and the time used by the users of each terminal login ID are aggregated. Note that it may be aggregated daily or aggregated over a predetermined period (such as one week).

[0181] FIG. 21 shows a flowchart of a process in which the management server device MS collects communication logs from each of the SaaS server devices SS1 to SSn and associates them with the aggregation results shown in FIG. 22.

[0182] The management server device MS sends a request for access information to each of the SaaS server devices SS1 to SSn (step S161). In response to this, each of the SaaS server devices SS1 to SSn returns the access information to the management server device MS (step S45). The management server device MS receives the access information from each of the SaaS server devices SS1 to SSn and records it (steps S162, S163).

[0183] As shown in FIG. 23, the access information from each of the SaaS server devices SS1 to SSn records the SaaS account (ID when accessing the SaaS server device) and the last access date and time of each account. Thus, the access information obtained from the SaaS server devices SS1 to SSn does not show the details of the usage status of each account. On the other hand, as shown in FIG. 22, according to the communication logs collected and aggregated from each of the terminal devices IT and OT, the usage history for each terminal login ID can be known in detail, but it is not known which account it belongs to.

[0184] Therefore, in this embodiment, the SaaS account and the terminal login ID are associated with each other. As a result, the detailed usage status of each SaaS account can be grasped.

[0185] However, the same employee does not necessarily use the same terminal login ID and SaaS account (account ID). In many cases, the terminal login ID is determined as a rule in the company, and it is often stipulated to use only the surname or the full name (surname first). In contrast, for the ID of the SaaS account, in most cases, the email address given by the company is used regardless of whether it is stipulated as a rule in the company. It is normal to use only the surname or the full name (surname first) before the @ of the email address given by the company. Therefore, if the part before the @ of the terminal login ID and the SaaS account matches, the two can be associated with each other.

[0186] In addition, in the association, the association may be performed by referring to the employee information (such as email address, full name, etc.) determined by the terminal login ID. Also, even if it is not an exact match, if the similarity is determined and is above a predetermined similarity, the association may be performed.

[0187] By performing the above association, as shown in FIG. 24, the details of the usage status for each account of each SaaS server device can be obtained.

[0188] The information system administrator can access the management server device MS from his / her own terminal device IT to view this information, and consider terminating the contract of accounts that are not being used or have a low usage frequency (number of uses · usage time).

[0189] Also, in the management server device MS in advance, accounts with a usage frequency lower than a predetermined frequency can be extracted, and a request for contract cancellation of the corresponding accounts can be automatically sent to the SaaS server device.

[0190] As described above, the usage status of each account can be grasped, and corresponding countermeasures can be taken accordingly.

[0191] 3.4 Variants (Others) (1) In the above-described embodiment, the management server device MS obtains the usage status of each account based on the usage information of the SaaS server device SS in the terminal devices IT and OT and the access information in the SaaS server device SS.

[0192] However, it may be used to find an act of accessing the SaaS server device SS using a business account from the employee-owned terminal device XT. The processing in this case will be described with reference to FIG. 27.

[0193] Now, the act to be detected is an act of accessing and using the business account of the SaaS server device SS by the privately-owned terminal device XT (without an agent installed) (see (7) in the figure).

[0194] The management server device MS acquires an access log from the SaaS server device SS (see F in the figure). This access log records the IP address information used when the accessing terminal device accesses the Internet. Also, the management server device MS acquires communication logs from the terminal devices IT and OT to the SaaS server device SS. This communication log records the IP address information used when the terminal device accesses the Internet.

[0195] The management server device MS matches the access log and the communication log to identify an IP address that is in the access log but does not appear in the communication log. This IP address is the IP address of the privately-used terminal device XT that accessed the SaaS server device. In this way, unauthorized access can be identified.

[0196] Also, by identifying the account information used in relation to the IP address, and further the terminal login ID corresponding to this account information, the employee who made unauthorized use can be identified.

[0197] When performing the above processing, the terminal devices IT and OT record the access to the SaaS server device as a communication log. This communication log includes the IP addresses of the terminal devices IT and OT. The management server device MS acquires the communication logs from each terminal device IT and OT and aggregates them as shown in FIG. 25.

[0198] In FIG. 25, the second and third rows are the aggregation of accesses from the user "furutani" to the SaaS server device "Gagarin".

[0199] The second row records the IP address information 122.213.111.96 used by the terminal device when accessing the Internet. This means an access from an in-house terminal device IT. The third row records that access was made from the IP address 189.563.256.88 of the terminal device. This means an access from an external terminal device OT.

[0200] Similarly, the fourth and fifth rows show that the user "tanaka" accessed the SaaS server device "Gagarin" from the terminal device IT with the IP address 122.213.111.87 and the terminal device OT with the IP address 141.313.222.35.

[0201] On the other hand, the management server device MS acquires access information from the SaaS server device. This access information includes the IP address information used by the terminal device accessing the SaaS account when accessing the Internet. The management server device MS aggregates this as shown in FIG. 26.

[0202] The management server device MS compares the aggregated data in FIG. 25 (communication logs obtained from the terminals) with the aggregated data in FIG. 26 (access logs obtained from the SaaS server device). Through this comparison, it is determined whether there is an IP address in the aggregated data of FIG. 26 that is not present in the aggregated data of FIG. 25. If access to the SaaS server device is only from the terminal devices IT and OT with agents, the IP addresses in both aggregated data should match. A difference occurs when a business SaaS account is used from a personal terminal device XT without an agent as shown in (7) of FIG. 27.

[0203] Here, the IP address "163.564.222.89" in the 6th row of FIG. 26 can be found. This can be determined to be an unauthorized account by the personal terminal device XT. Also, by associating the SaaS account with the terminal login ID, it is possible to identify which employee made this unauthorized use.

[0204] The information system administrator can access the management server device MS from their own terminal device IT, view this information, detect unauthorized use, and take corresponding measures.

[0205] (2) In the above embodiment, in the terminal device, the agent performs the login process. However, a program other than the agent may perform the login process, and the agent may obtain the information at the time of login.

[0206] (3) In the above embodiment, the agent 52 uses the hook function of the OS 50 to obtain the communication destination of the process P. However, instead of or in addition to this, the communication destination may be obtained using a communication status list.

[0207] (4) In the above embodiment, the communication destination of the program operating on the OS 50 is acquired. However, the agent 52 may acquire the operation log of the program and determine which SaaS server device SS is being used from URLs and the like included in the operation log.

[0208] (5) In the above embodiment, the agents 52 of the terminal devices IT and OT acquire and record details of access to each SaaS server device SS. However, if the service - providing server device SS seems to be providing details of account access, the access information of the account may be acquired from each service - providing server device SS. In this case, the user may be identified from the account ID (which is often an email address).

[0209] (6) The above embodiment and its modification examples can be implemented in combination with each other. Also, they can be implemented in combination with other embodiments and their modification examples.

[0210] 4. Fourth Embodiment 4.1 Functional Configuration FIG. 28 shows the functional configuration of the management system according to the fourth embodiment. Terminal devices T1, T2 ··· Tn and a management server device MS capable of communicating with these are provided.

[0211] The process operation determination information setting means 22 of the server device S transmits process operation determination information to each of the terminal devices T1, T2 ··· Tn. Also, the communication operation determination information setting means 24 transmits communication operation determination information to the terminal devices T1, T2 ··· Tn. These determination information are recorded in the recording unit 6 of the terminal devices T1, T2 ··· Tn.

[0212] The communication start detection means 14 of the terminal devices T1, T2 ··· Tn (hereinafter referred to as terminal device T) detects the start of communication 18 in the terminal device T. The communication operation determination means 12 refers to the recorded communication operation determination information 10 for the communication 18 whose start has been detected and determines the propriety of that communication 18.

[0213] When it is determined that communication 18 is appropriate, communication 18 is made to be performed. On the other hand, when it is determined that the start of communication 18 is inappropriate, the communication operation determination means 12 stops the communication 18. Therefore, the start of inappropriate communication 18 is prevented. Note that the stop of communication, in this embodiment, is a concept that includes not only the case of stopping the communication that has already been started but also the case of not starting the communication for which start has been requested but has not yet been started.

[0214] The process start detection means 2 of the terminal device T detects the start of the process 16 in the terminal device T. The process operation determination means 4 refers to the recorded process information determination information 8 for the process 16 for which start has been detected, and determines the propriety of the start.

[0215] When it is determined that the start of the process 16 is appropriate, the process 16 is started as it is. On the other hand, when it is determined that the start of the process 16 is inappropriate, the process operation determination means 4 stops the process 16. Therefore, the start of inappropriate process 16 is prevented. Note that the stop of the process, in this embodiment, is a concept that includes not only the case of stopping the process that has already been started but also the case of not starting the process for which start has been requested but has not yet been started.

[0216] As described above, the determination information from the management server device MS is recorded in each terminal device T, and based on this, in each terminal device T, inappropriate processes and communications are excluded. Therefore, inappropriate processes and communications can be determined and excluded on the terminal device T side. Also, since the above management process can be performed by recording the determination information in each terminal device T, even if the terminal device T is connected to an external network, appropriate management can be performed.

[0217] 4.2 System Configuration and Hardware Configuration The system configuration of the management system is the same as that of FIG. 2 in each of the above embodiments. As the terminal devices T, in-house terminal devices IT and external terminal devices OT are used.

[0218] The in-house terminal devices IT1, IT2... ITm are connected to the in-house network by wire or wirelessly. A shared server device (not shown) is connected to the in-house network, and data necessary for business and the like are recorded thereon. Each of the in-house terminal devices IT1, IT2... ITm can access the shared server device via the in-house network and use these data and the like.

[0219] The external terminal devices OT1... OTp can be connected to the in-house network via a VPN over the Internet connected by wire or wirelessly. In the case of telecommuting or the like, it is possible to connect to the in-house network via such a VPN, connect to the shared server device, and perform business.

[0220] A management server device MS is provided on the Internet. Also, SaaS server devices SS1... SSq that provide business applications and the like in the cloud are provided.

[0221] The hardware configurations of the terminal devices IT and OT are the same as those of FIG. 3. Also, the hardware configuration of the management server device MS is the same as that of FIG. 4.

[0222] 4.3 Process and Communication Management Processing FIGS. 29 and 31 show flowcharts of process and communication management processing. FIG. 29 is a flowchart of process management processing. These processes are executed by the CPU 30 based on the operating system (hereinafter referred to as OS) 50, agent 52, and processes P1... Pr in the terminal devices IT and OT, and are executed by the CPU 60 based on the management server program 72 in the management server device MS. Hereinafter, when it is said that the OS 50 performs a process, it means that the CPU 30 performs the process based on the OS 50. The same applies to other programs.

[0223] In this embodiment, when the OS 50 receives a process startup command using the hook function or the like prepared in the OS 50, the OS 50 notifies the agent 52 that there has been a startup command (step S1). As for the case where the OS 50 receives a process startup command, there are cases such as when the user tries to start by double-clicking on the application icon, or when another process tries to start the said process.

[0224] When the agent 52 of the terminal devices IT and OT receives notice from the OS 50 of the terminal devices IT and OT that there has been a process startup command, the agent 52 reads out the process operation determination information 56 from the SSD 36 (step S21). In the figure, the horizontal broken line indicates the communication between programs within the same terminal devices IT and OT. Subsequently, for the process with the startup command, the agent 52 refers to this process operation determination information 56 and determines whether the startup is appropriate (step S23).

[0225] FIG. 30 shows the process operation determination information 56. In this embodiment, the permission list of processes permitted to start is the process operation determination information 56. The agent 52 determines whether the process with the startup command is in this permission list. If it is in the list, it is determined that it is appropriate to start, and if it is not in the list, it is determined that it is not appropriate to start.

[0226] The agent 52 notifies the OS 50 whether the startup of the process with the startup command is appropriate (step S23). The OS 50 receives this notification. If it is a notification that the startup is appropriate, the OS 50 starts the said process (step S3).

[0227] On the other hand, if it is a notification that the startup is inappropriate, the OS 50 does not start the said process.

[0228] In the above manner, it is possible to prevent a process from being started unless it is permitted in the process permission list. Note that, as will be described later, the administrator can control the management server device MS, and the process permission list can be rewritten from the management server device MS. Therefore, in each terminal device IT and OT, it is possible to manage so that the device cannot operate unless it is a process designated by the administrator.

[0229] FIG. 31 shows a flowchart of communication management processing. The above is the processing when the running process P attempts to communicate with the SaaS server device SS on the Internet. In the figure, the horizontal dashed line indicates the interaction between programs within the same terminal devices IT and OT. The horizontal solid line indicates the communication between the terminal devices IT and OT and the SaaS server device SS.

[0230] When the process P of the terminal devices IT and OT uses the functions of the SaaS server device SS on the Internet, it is necessary to request the OS 50 to communicate with the SaaS server device SS and receive the processing result. Therefore, the process P gives a communication command indicating the URL of the SaaS server device as the communication partner and the desired processing content to the OS 50 (step S41).

[0231] In this embodiment, when the OS 50 receives a communication command, the OS 50 notifies the agent 52 that there is a communication command by using a hook function or the like prepared in the OS 50 (step S5).

[0232] When the agent 52 of the terminal devices IT and OT receives a notice from the OS 50 of the terminal devices IT and OT that there is a communication command, it reads the communication operation determination information 54 from the SSD 36 (step S25). Subsequently, with reference to this communication operation determination information 54, it determines the propriety of the communication for which the command was given (step S26).

[0233] Figure 32 shows communication operation determination information 54. In this embodiment, the permission URL list of the SaaS server device SS that permits communication is used as the communication operation determination information 54. The agent 52 determines whether the URL of the SaaS server device SS indicated by the communication command is in this permission URL list. If it is in the list, it is determined that it is appropriate to communicate with this SaaS server device SS, and if it is not in the list, it is determined that it is not appropriate to communicate.

[0234] In addition, when it has the same URL as the URL shown in the permission URL list and the URL at a lower level is the communication destination, it is determined to be a permitted URL. For example, if www.xxx.jp is described in the permission URL list, it is determined that any of www.xxx.jp / yyy, www.xxx.jp / zzz, and www.xxx.jp / yyy / kkk is a permitted URL for the communication destination. Note that communication may not be permitted unless it exactly matches the URL described in the permission URL list.

[0235] The agent 52 notifies the OS 50 of whether communication with the SaaS server device SS for which the communication command was issued is appropriate (step S26). The OS 50 receives this notification.

[0236] If it is a notification that communication with the said SaaS server device SS is appropriate, the OS 50 communicates with the SaaS server device SS and requests a desired process (step S7). In response to this, the SaaS server device SS executes the requested process and transmits the process result to the OSs 50 of the terminal devices IT and OT (step S101). The OS 50 receives the process result by communication and gives it to the process P (step S8).

[0237] Hereinafter, the process P can utilize the processing function of the SaaS server device SS via the OS 50 as necessary.

[0238] On the other hand, if the OS 50 receives a notification in step S6 that the communication with the SaaS server device SS is inappropriate, it will not communicate with the SaaS server device SS that is the target of the communication command.

[0239] As described above, it is possible to prevent communication unless it is with the SaaS server device SS permitted in the communication permission list. Note that, as will be described later, this communication permission list can be rewritten from the management server device MS under the control of the administrator. Therefore, in each terminal device IT and OT, it is possible to manage so that communication cannot be performed unless it is with the SaaS management server device SS designated by the administrator.

[0240] In this embodiment, the agent 52 is installed not only in the terminal device IT assumed to be used by connecting to the in-house network, but also in the terminal device OT used for telecommuting etc. (not assumed to be used by connecting to the in-house network). Therefore, for these external terminal devices OT, process management and communication management can be performed in the same way as for the internal terminal device IT. In that case, no additional device is required.

[0241] When connecting an external terminal device OT to the in-house network, it is connected to the in-house network using a VPN. Thereby, it is possible to connect to the in-house network from the outside while ensuring security. However, in order to connect to the SaaS server device SS, connection to the in-house network is not essential. This is because the external terminal device OT is also managed by the agent 52. Therefore, the burden on the VPN is not unnecessarily increased.

[0242] 4.4 Agent Introduction Process As described in the above embodiment, if the agent 52 is introduced in each terminal device IT and OT, the above-described process management and communication management can be performed. Conversely, if the agent 52 is not installed in the terminal devices IT and OT to be managed, the above management cannot be performed.

[0243] In this embodiment, in order to ensure that the agent 52 is installed on the terminal devices IT and OT to be managed, the following is done.

[0244] When lending terminal devices IT and OT to members of an organization such as employees in an organization such as a company, the agent 52 is installed in advance. This can ensure the introduction of the agent 52 in the terminal devices IT and OT.

[0245] In addition, the administrator records the MAC addresses of the terminal devices IT and OT on which these agents 52 are installed in network devices such as routers on the corporate internal network. The router is configured not to allow connection to the corporate internal network for terminal devices IT and OT other than those with the MAC addresses recorded.

[0246] Therefore, terminal devices without the agent 52 installed, rather than the terminal devices IT and OT lent from the organization, cannot connect to the corporate internal network. For this reason, it becomes difficult to perform operations on such terminal devices.

[0247] When using a terminal device other than the lent terminal device for work, it is necessary to install the agent 52 and then contact the administrator to have the MAC address set in the router so that it can be connected to the corporate internal network.

[0248] In this way, a state where the agent 52 is substantially installed can be formed in the terminal devices used for work.

[0249] Note that the management server device MS may collect the MAC addresses of the terminal devices IT and OT on which the agent 52 is installed, and based on this, the management server device MS may set the MAC addresses in the router. This can save the administrator's effort.

[0250] 4.5 Update of Process Operation Judgment Information and Communication Operation Judgment Information In the above description, it has been explained that process management and communication management are performed based on the process operation determination information (the process permission list in the above description) and the communication operation determination information (the communication permission list in the above description) recorded in the terminal devices IT and OT.

[0251] These determination information are those recorded in the management server device MS and are downloaded by each of the terminal devices IT and OT and recorded in each of the terminal devices IT and OT.

[0252] Also, the administrator can access the management server device MS using their own terminal device IT, update the determination information, and cause it to be recorded in each of the terminal devices IT and OT. Thereby, it is possible to respond to newly permitted processes and communications, and newly prohibited processes and communications.

[0253] 4.6 Variation Example (Others) (1) In the above embodiment, both the propriety of process startup and the propriety of communication are determined to control the operation. However, only the propriety of process startup or only the propriety of communication may be determined to control the operation.

[0254] (2) In the above embodiment, in steps S21 and S25, the determination information is acquired each time. However, these determination information may be acquired from the SSD 36 only once at startup, held in the memory 32, and referred to.

[0255] (3) In the above embodiment, in the management of process startup, using a hook function or the like, the OS 50 that has received the startup command of the process P does not immediately start the process P, and only the processes determined to be appropriate by the agent 52 are started.

[0256] However, the agent 52 may be controlled as follows using a process list indicating the currently running processes.

[0257] The processing flowchart in this case is shown in FIG. 33.

[0258] When there is a process start command, the OS 50 of the IT and OT terminal devices starts the process (step S11). At this time, the OS 50 adds the started process to the process list indicating the currently operating processes.

[0259] The agent 52 of the IT and OT terminal devices constantly (at a predetermined time interval) monitors the process list updated by the OS 50 (step S31). The agent 52 acquires the process operation determination information 56 (the process permission list in FIG. 30) and determines whether the start of the process newly appeared (that is, newly started) in the process list is appropriate.

[0260] If the started process is in the process permission list, it is determined that the start of the process is appropriate, and if it is not in the process permission list, it is determined that the start of the process is inappropriate (step S33).

[0261] When the agent 52 determines that the start of the process is inappropriate, it notifies the OS 50 to forcibly terminate the process (step S34). The OS 50 that has received the forced termination instruction forcibly terminates the process (step S13).

[0262] On the other hand, when the agent 52 determines that the start of the process is appropriate, it does not give an instruction to forcibly terminate the operation of the started process as it is.

[0263] As described above, the management of process start can be performed using the process list managed by the OS 50. In this example, although an inappropriate process will be started once, it is forcibly terminated in a short time, so an effect equivalent to that of not being substantially permitted to start can be obtained.

[0264] Note that in the above, a process list indicating the currently running processes is used. However, instead of this, similar processing may be performed using an event log. The event log is a log that records when the OS 50 starts a new process. By monitoring this event log, the agent 52 can know when a new process is started and can execute the processing from step S32 in FIG. 33 and below.

[0265] As described above, the case of using a process list and the case of using an event log have been explained. Since the process list indicates the currently operating processes, unnecessary processing for processes that have already ended can be eliminated.

[0266] (4) In the above embodiment, in communication management, using a hook function or the like, the OS 50 that has received a communication command does not immediately perform communication, and only communication that the agent 52 determines to be appropriate is permitted.

[0267] However, the agent 52 may control using a communication status list indicating the currently running communication as follows.

[0268] The processing flowchart in this case is shown in FIG. 34. When the OS 50 receives a communication command from the process P, it communicates with the SaaS server device SS specified in the communication command and requests the specified processing (step S15). At this time, the OS 50 adds the communication with this SaaS server device SS to the communication status list indicating the current communication status.

[0269] The agent 52 that constantly monitors (monitors at predetermined time intervals) the communication status list acquires the above communication newly added to the communication status list (step S27). The agent 52 determines whether the communication with the above SaaS server device SS is appropriate based on the communication operation determination information 54 (communication permission list).

[0270] If it is determined that the communication is not in the communication permission list and is inappropriate, the agent 52 notifies the OS 50 of an instruction to forcibly terminate the communication (step S30). In response to this, the OS 50 forcibly terminates the communication (step S17).

[0271] On the other hand, if it is determined that the communication is in the communication permission list and is appropriate, the agent 52 does not give an instruction to forcibly terminate to the OS 5050. Therefore, the OS 50 receives the result from the SaaS server device SS and transmits this to the process P (step S18).

[0272] (5) In the above embodiment, the management server device MS is placed on the Internet. However, the management server device MS may be placed on the in-house network. If the devices to be managed are only the terminal devices IT connected to the in-house network, this may be done. In this case, if terminal devices connected to an external network (organization-external network) are also to be managed, it may be premised that such terminal devices are always connected to the in-house network via a VPN and used.

[0273] (6) In the above embodiment, a process permission list (white list) for permitting startup is used as the process operation determination information 56. However, a process list (black list) for not permitting startup may be used instead.

[0274] Similarly, for the communication operation determination information 54, instead of a permission URL list (white list) for permitting communication, a non-permission URL list (black list) for not permitting communication may be used.

[0275] (8) In the above embodiment, the communication with the SaaS server device SS is managed. However, the communication with other devices on the Internet, such as a normal web server device, may be managed.

[0276] (9) In the above-described embodiment, a white list or a black list of communication destination URLs is used as communication operation determination information. That is, it is configured to determine suitability based on the communication destination and construct communication operation determination information.

[0277] However, it may be configured to determine suitability based on communication conditions (such as communication speed, communication method (wireless or wired, etc.), security status such as SSL, communication capabilities of the server device of the communication partner, etc.) and construct communication operation determination information.

[0278] (10) In the above-described embodiment, in the permitted URL list of FIG. 32, protocols such as http: / / , https: / / , and ftp are not specified. However, these may be specified.

[0279] Also, it may be configured to specify by domain or IP, and if necessary, specify a port number.

[0280] (11) In the above-described embodiment, the permission list permits or prohibits the activation of each process, and the URL list permits or prohibits the connection to each communication destination.

[0281] However, when the administrator permits a specific SaaS service for an employee, a plurality of processes necessary to receive the service must be registered in the permission list, and a plurality of communication destinations must be registered in the URL list, which is cumbersome.

[0282] Therefore, it may be configured to record set information that combines a plurality of processes and a plurality of communication destinations necessary to receive each service provision in a maintenance server device provided on the Internet. The administrator can access this maintenance server device and obtain the set information that combines a plurality of processes and a plurality of communication destinations necessary for each service. Therefore, the setting of the permission list and the URL list is easy.

[0283] Also, in the maintenance server device, if there are changes in the necessary processes and communication destinations in each service, the set information is updated. As a result, even if there are changes in the processes and communication destinations of each service, the administrator can easily respond by obtaining the set information from the maintenance server device. Also, the maintenance server device may update the process and communication destination for the management server device (delete the old process and communication destination and add the new process and communication destination). Also, the management server device may access the maintenance server device to obtain and update the set information.

[0284] In the above, the update of the necessary processes and communication destinations in each service has been described. The same applies when newly registering the necessary processes and communication destinations for each service.

[0285] (12) The above-described embodiments and modifications can be implemented in combination with each other. Also, these embodiments and modifications can be implemented in combination with other embodiments and their modifications.

[0286] 5. Fifth Embodiment 5.1 Functional Configuration FIG. 35 shows the functional configuration of the management system according to the fifth embodiment. The startup management and communication management of the basic processes in this embodiment are the same as those in the first embodiment. However, it is different in that when the communication stop process is performed, the process operation determination information is updated so as to prohibit the startup of the process that was about to perform the communication hereafter.

[0287] The communication operation determination means 12 refers to the communication operation determination information 10 and determines the propriety of the communication. If it is determined that it is inappropriate, the communication 18 is stopped. At this time, the communication operation determination means 12 transmits the fact that the communication has been stopped and the process that was about to perform the communication to the process operation determination information setting means 22 of the management server device MS.

[0288] The process operation determination information setting means 22 receives this, updates the process operation determination information so as to prohibit the start of the process, and transmits it to the terminal device T. As a result, the start of the process will be prohibited hereafter.

[0289] As described above, for the process attempting inappropriate communication, the process operation determination information is updated to prohibit the start, so that the start of the process can be prohibited hereafter. 5.2 System configuration and hardware configuration The system configuration and hardware configuration are the same as those in FIGS. 2 to 4 in the first embodiment.

[0290] 5.3 Process and communication management processing The process management processing is the same as that in FIG. 29 in the fourth embodiment. However, in this embodiment, a list of processes not permitted to start (start blacklist) is used as the process operation determination information. Therefore, the agent 52 approves the start of a process that is not listed in this list of non-permitted processes. Also, for a process listed in the start blacklist, the start is not approved.

[0291] The flowchart of the communication management processing is also the same as that in FIG. 31 in the fourth embodiment. Also in this embodiment, a list of URLs permitted for communication (communication whitelist) is used as the communication operation determination information, in the same way as in the fourth embodiment.

[0292] In this embodiment, as described above, the appropriateness of the start of the process is determined by the start blacklist. Therefore, it is possible to install and start a newly supplied process (for example, a process provided by the SaaS server device SS that has not been used in the terminal devices IT and OT so far) in the terminal devices IT and OT.

[0293] If this process attempts to communicate with an unauthorized destination, the communication will be prohibited by the communication whitelist. Therefore, there are no particular issues regarding communication. However, since the operation of the process itself is not prohibited, the process will be started multiple times, unnecessarily consuming the processing power of the terminal devices IT and OT.

[0294] Therefore, in this embodiment, the start of a process that attempts to perform inappropriate communication is prohibited.

[0295] In step S26 of FIG. 31, the agent 52 refers to a list of URLs that permit communication (communication whitelist) to determine whether the communication to be performed by the process P is appropriate. This is the same as in the fourth embodiment.

[0296] However, when the agent 52 determines that the communication is inappropriate, it performs the processing as shown in FIG. 36. The agent 52 requests the management server device MS to prohibit the start of the process P that attempts to perform the communication determined to be inappropriate.

[0297] In response to this, the management server program 72 of the management server device MS adds and updates the process P to the startup blacklist (process operation determination information 76) (step S151). Further, the management server program 72 transmits the rewritten startup blacklist (process operation determination information 76) to the agents 52 of each terminal device IT and OT (step S152).

[0298] The agents 52 of each terminal device IT and OT that have received the startup blacklist rewrite the startup blacklist (process operation determination information 56) based on this (step S123).

[0299] As described above, subsequent startups of the process P that attempts to perform inappropriate communication will be prohibited in each terminal device IT and OT.

[0300] 5.4 Modification Example (Others) (1) In the above embodiment, a list of URLs that do not permit communication (communication blacklist) is used as communication operation determination information. However, a list of URLs that permit communication (communication whitelist) may be used as communication operation determination information instead.

[0301] (2) In the above embodiment, the management server program instructs all terminal devices IT and OT to rewrite the process operation determination information in step S152.

[0302] However, it may be instructed to rewrite the process operation determination information only for the terminal devices IT and OT in which a process attempting an inappropriate communication operation has started (in this case, the agent 52 itself may rewrite the process operation determination information of the relevant terminal devices IT and OT without going through the management server device MS).

[0303] Alternatively, it may be rewritten for all of the terminal devices IT and OT belonging to the same department (or terminal devices in a predetermined relationship) as the terminal devices IT and OT in which the process has started.

[0304] (3) In the above embodiment, the agent 52 requests the management server device MS to update the process operation determination information in step S122.

[0305] However, the agent 52 may forcibly terminate the process P that attempts to perform inappropriate communication without making such a request. Also, after forcibly terminating it, it may request an update of the process operation determination information in step S122.

[0306] (4) The above embodiment and the modification example can be implemented in combination with each other. Also, these embodiments and modification examples can be implemented in combination with other embodiments and their modification examples.

[0307] 6. Sixth Embodiment 6.1 Functional Configuration Figure 37 shows the functional configuration of the management system according to the sixth embodiment. The startup management and communication management of the basic processes in this embodiment are the same as those in the fourth embodiment. However, the communication destination of the process permitted to start is different in that the communication operation determination information is updated so as to permit communication.

[0308] The communication operation determination means 12 refers to the communication operation determination information 10 and determines the propriety of communication. If it is determined that the communication is inappropriate, a determination is made as to whether to stop the communication or permit the communication based on the setting information recorded in association with the process P attempting to perform the communication.

[0309] If it is specified in the setting information that the communication is to be stopped, the current communication is stopped. If it is specified in the setting information that the communication is to be permitted, the current communication is permitted and a communication operation determination information update command is transmitted to the management server device MS. The communication operation determination information setting means 24 of the management server device MS receives this and updates the communication operation determination information so as to permit the communication and transmits it to the terminal device T.

[0310] The terminal device T receives this and rewrites the communication operation determination information 10. Therefore, hereafter, the communication will be permitted.

[0311] Therefore, by setting the setting information, communication can be automatically permitted for a predetermined process.

[0312] 6.2 System Configuration and Hardware Configuration The system configuration and hardware configuration are the same as FIGS. 2 to 4 in the first embodiment.

[0313] 6.3 Process and Communication Management Processing The process management process is the same as that in FIG. 29 of the fourth embodiment. However, also in this embodiment, as process operation determination information, a list of processes permitted to start (start white list) is used. Therefore, the agent 52 approves the start of any process listed in this list of permitted processes. Also, for processes not listed in the start white list, the start is not approved.

[0314] The flowchart of the communication management process is shown in FIGS. 38 and 39. Also in this embodiment, as in the fourth embodiment, a list of URLs permitted for communication (communication white list) is used as communication operation determination information.

[0315] In the fourth embodiment, communication to URLs not listed in the communication white list is prohibited. However, the following problems may have occurred.

[0316] When the startup of a dedicated application (process) for connecting to the SaaS server device SS and using its functions is approved, the SaaS server device SS may provide a new URL as a connection destination for providing new functions. In this case, since the new URL is not listed in the communication white list, according to the fourth embodiment, the communication will be rejected.

[0317] In this way, in order to use new functions of the SaaS server device, etc., the administrator has to rewrite the communication operation determination information, which is cumbersome.

[0318] In this embodiment, in order to handle the above situation, for some processes, the communication operation determination information is automatically updated so as to permit communication to a new communication destination URL. This will be described below.

[0319] The process P gives a communication command indicating the URL of the SaaS server device that is the communication partner to the OS 50 and indicating the desired processing content (step S41).

[0320] When the agent 52 of the IT and OT terminal devices receives a communication command from the OS 50 of the IT and OT terminal devices (step S5), it reads the communication operation determination information 54 from the SSD 36 (step S25). Subsequently, with reference to this communication operation determination information 54, it determines the appropriateness of the communication for which the command was given (step S26). In this embodiment, as in the fourth embodiment, a list of URLs permitting communication (communication whitelist) is used as the communication operation determination information 54.

[0321] If the agent 52 determines that communication is appropriate, it notifies the OS 50 of the communication permission in step S124 of FIG. 39.

[0322] On the other hand, if it determines that communication is not appropriate, instead of immediately notifying the OS 50 of the communication non - permission, it refers to the setting information to determine permission / non - permission.

[0323] The agent 52 reads the setting information recorded in association with the process attempting to communicate from the SSD 36. In this embodiment, the setting information is included in the communication operation determination information 54. An example of the setting information is shown in FIG. 40. For each process, whether to automatically permit the communication destination is recorded.

[0324] The agent 52 refers to this setting information and determines the presence or absence of automatic permission for the communication destination for the process for which communication is to be performed (step S123). If there is no automatic permission, it transmits a communication non - permission notice to the OS 50 in step S124.

[0325] If there is automatic permission, it transmits a communication permission notice to the OS 50 in step S125. Therefore, even a URL not listed in the communication whitelist may be permitted to communicate.

[0326] Furthermore, the agent 52 requests the management server program to update the communication whitelist (communication operation determination information 54) for the URL so that the communication is determined to be appropriate (step S126).

[0327] Upon receiving this, the management server program adds and updates the URL to the communication whitelist (step S153). Furthermore, the management server program transmits this to the agents 52 of each terminal device IT and OT (step S154).

[0328] Upon receiving the updated communication whitelist, the agents 52 of each terminal device IT and OT record and rewrite this in the SSD 36 (step S127).

[0329] As described above, by setting the setting information, the communication destination can be automatically permitted for a predetermined process.

[0330] Note that the communication destination is not uniformly automatically permitted for all processes because it is dangerous if it is not a process recognized as safe by the administrator. The administrator can set the setting information in each terminal device IT and OT via the management server device MS and determine which processes to permit the communication destination automatically.

[0331] 6.4 Variation (Others) (1) In the above embodiment, the management server program instructs all terminal devices IT and OT to rewrite the communication operation determination information in step S154.

[0332] However, it may be instructed to rewrite the communication operation determination information only for the terminal devices IT and OT that have requested the communication permission setting (in this case, the agent 52 itself may rewrite the communication operation determination information of the terminal devices IT and OT without passing through the management server device MS).

[0333] In addition, for all of the IT and OT terminal devices belonging to the same department (or terminal devices in a predetermined relationship) as the IT and OT terminal devices that have requested communication permission settings, they may be rewritten.

[0334] (2) In the above embodiment, in step S126, the communication operation determination information is updated. However, the communication operation determination information may not be updated, and only a communication permission notification may be given to the OS 50 (step S125).

[0335] (3) In the above embodiment, the setting information is part of the communication operation determination information. However, setting information may be provided separately from the communication operation determination information.

[0336] (4) The above embodiment and the modification example can be implemented in combination with each other. Further, these embodiment and modification example can also be implemented in combination with other embodiments and their modification examples.

Claims

1. A management system comprising a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, wherein the terminal device includes function access detection means for detecting which function of each service providing server device has been accessed, function access information transmission means for transmitting, to the management server device, function access information indicating which function of each service providing server device has been accessed, detected by the function access detection means, and the management server device includes function access information acquisition means for acquiring function access information from each terminal device, and function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each terminal device. The management system is characterized by this.

2. A management server device that constitutes a management system together with a terminal device, function access information acquisition means for acquiring, from each terminal device, function access information indicating which function of each service providing server device has been accessed by each terminal device, function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each terminal device, and the management server device is provided with this.

3. A management server program for realizing, by a computer, a management server device that constitutes a management system together with a terminal device, the computer being caused to function as function access information acquisition means for acquiring, from each terminal device, function access information indicating which function of each service providing server device has been accessed by each terminal device, and a management server program for causing it to function as function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each terminal device.

4. A terminal device that constitutes a management system together with a management server device, function access detection means for detecting which function of each service providing server device has been accessed; function access information transmission means for transmitting, to the management server device, function access information indicating which function of each service providing server device has been accessed, detected by the function access detection means, so that the management server device can aggregate the usage status of each function in each service providing server device; A terminal device comprising the above.

5. A terminal program for realizing, by a computer, a terminal device that constitutes a management system together with a management server device, the computer being caused to function as: function access detection means for detecting which function of each service providing server device has been accessed; function access information transmission means for transmitting, to the management server device, function access information indicating which function of each service providing server device has been accessed, detected by the function access detection means, so that the management server device can aggregate the usage status of each function in each service providing server device.

6. A management server device that aggregates which functions of a plurality of service providing server devices are being used by a plurality of terminal devices, function access information acquisition means for acquiring, from each of the service providing server devices, function access information indicating which function of each service providing server device has been accessed by each terminal device; function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each service providing server device; A management server device comprising the above.

7. A management server program for realizing, by a computer, a management server device that aggregates which functions of a plurality of service providing server devices are being used by a plurality of terminal devices, the program causing the computer to function access information acquisition means for acquiring, from each of the service providing server devices, function access information indicating which function of each of the service providing server devices each terminal device has accessed; A management server program for causing the computer to function as function aggregation means for aggregating the usage status of each function in each service providing server device based on the function access information acquired from each service providing server device.

8. In the system, management server device, management server program, terminal device, or terminal program according to any one of Claims 1 to 5, the terminal device includes terminal devices connected to an external network of the organization, A system, management server device, management server program, terminal device, or terminal program configured such that the terminal device cannot be connected to an internal network of the organization unless it is provided with the function access detection means and the function access information transmission means.

9. In the system, management server device, management server program, terminal device, or terminal program according to any one of Claims 1 to 7, the function aggregation means aggregates the usage status of the same or similar functions in different service providing server devices, A system, management server device, management server program, terminal device, or terminal program, characterized in that for the same function of a plurality of service providing devices, the use of the function of the service providing server device with less use is prohibited, and a proposal is made to use the same function of other service providing server devices.

10. In the system, management server device, or terminal device according to Claim 9, the terminal device communication start detection means for detecting the start of communication in the terminal device; Communication operation determination means for determining the propriety of the operation of the detected communication based on the communication operation determination information recorded in the recording unit, and stopping the communication determined to be inappropriate for operation, The management server device, Communication operation determination information setting means for communicating with the terminal device, transmitting the communication operation determination information to the terminal device, and causing the terminal device to record it, A system, server device, or terminal device comprising registration means for registering, as the communication operation determination information, to prohibit communication to the function of a service providing device other than the service providing server device determined to be used for the same function of a plurality of service providing server devices.

11. In the management server program of claim 9, the computer further Communication operation determination information setting means for communicating with the terminal device, transmitting the communication operation determination information to the terminal device, and causing the terminal device to record it, A management server program for functioning as registration means for registering, as the communication operation determination information, to prohibit communication to the function in the terminal device of a service providing device other than the service providing server device determined to be used for the same function of a plurality of service providing server devices.

12. In any one of the systems, management server devices, management server programs, terminal devices, or terminal programs of claims 1 to 7, The function aggregation means identifies the user of the terminal device using the management function of the service providing device, and identifies the user as an administrator when receiving the service by the service providing device. A system, management server device, server program, terminal device, or terminal program characterized by this.

13. In any one of the systems, management server devices, management server programs, terminal devices, or terminal programs of claims 1 to 7, The function aggregation means is a system, a management server device, a management server program, a terminal device, or a terminal program, characterized by specifying whether multi-factor authentication is performed when each service providing device is used.

14. A management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, The terminal device, Access detection means for detecting which of each service providing server device is accessed, Access information transmission means for transmitting, to the management server device, access information indicating which of each service providing server device is accessed, detected by the access detection means. The management server device, Access information acquisition means for acquiring access information from each terminal device, A management system characterized by comprising: specific means for collating the access information acquired from each terminal device with a list of permitted service providing devices, and specifying a service providing device that is not used despite being permitted, or a service providing device that is used despite not being permitted.

15. A management server device that constitutes a management system together with a terminal device, Access information acquisition means for acquiring, from each terminal device, access information indicating which of each service providing server device is accessed by each terminal device, A management server device characterized by comprising: specific means for collating the access information acquired from each terminal device with a list of permitted service providing devices, and specifying a service providing device that is not used despite being permitted, or a service providing device that is used despite not being permitted.

16. A management server program for realizing, by a computer, a management server device that constitutes a management system together with a terminal device, the computer being Access information acquisition means for acquiring, from each terminal device, access information indicating to which of the service providing server devices each terminal device has accessed. A management server program for causing the access information acquired from each terminal device to be collated with a list of permitted service providing devices, and functioning as specifying means for specifying a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted.

17. A terminal device that constitutes a management system together with a management server device, Access detection means for detecting to which of the service providing server devices access has been made, In the management server device, access information indicating to which of the service providing server devices access has been made, detected by the access detection means, is transmitted to the management server device so that the access information acquired from each terminal device can be collated with a list of permitted service providing devices, and a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted, can be specified. Access information transmission means. A terminal device provided with the above.

18. A management server program for realizing, by a computer, a terminal device that constitutes a management system together with a management server device, the computer being Access detection means for detecting to which of the service providing server devices access has been made, In the management server device, access information indicating to which of the service providing server devices access has been made, detected by the access detection means, is caused to function as access information transmission means for transmitting the access information to the management server device so that the access information acquired from each terminal device can be collated with a list of permitted service providing devices, and a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted, can be specified. Terminal program.

19. A management server device that identifies which of a plurality of service providing server devices a plurality of terminal devices are using, access information acquisition means for acquiring, from each of the service providing server devices, access information indicating which of the service providing server devices each terminal device has accessed; specifying means for collating the access information acquired from each service providing server device with a list of permitted service providing devices, and specifying a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted; A management server device characterized by comprising:

20. A management server program for realizing, by a computer, a management server device that identifies which of a plurality of service providing server devices a plurality of terminal devices are using, the computer being caused to function as: access information acquisition means for acquiring, from each of the service providing server devices, access information indicating which of the service providing server devices each terminal device has accessed; A management server program for causing the computer to function as specifying means for collating the access information acquired from each service providing server device with a list of permitted service providing devices, and specifying a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted.

21. In the system, server device, terminal device, server program, or terminal program according to any one of claims 14 to 18, the terminal device includes a terminal device connected to an external network of the organization, A system, server device, terminal device, server program, or terminal program, wherein the terminal device is configured not to be connectable to an internal network of the organization unless it is provided with the access detection means and the access information transmission means.

22. In the system according to claim 14, the management server device according to claim 15, or the terminal device according to claim 17, the terminal device comprises communication start detection means for detecting the start of communication in the terminal device, and communication operation determination means for determining the propriety of the operation of the communication for which start has been detected based on communication operation determination information recorded in a recording unit, and stopping the communication determined to be inappropriate for operation. The management server device communicates with the terminal device, and has communication operation determination information setting means for transmitting the communication operation determination information to the terminal device to cause the terminal device to record it, and a registration means for registering, as the communication operation determination information, to prohibit communication of the terminal device with a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted. A system, server device, or terminal device.

23. In the management server program according to claim 20, the computer further communicates with the terminal device, and has communication operation determination information setting means for transmitting the communication operation determination information to the terminal device to cause the terminal device to record it, and functions as registration means for registering, as the communication operation determination information, to prohibit communication of the terminal device with a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted. A management server program characterized by this.

24. In any of the systems, management server devices, management server programs, terminal devices, or terminal programs according to claims 1 to 7 and 14 to 20, the function aggregation means, aggregation means, or specifying means of the management server device specifies an access destination in consideration of a program operation log or a process communication log. A system, management server device, management server program, terminal device, or terminal program characterized by this.

25. A management system comprising a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, wherein the terminal device comprises a login ID acquisition means for acquiring a user's terminal login ID or terminal ID used during login processing, an access detection means for detecting access to an account of a service providing server device, and an access information transmission means for attaching the terminal login ID or terminal ID to information indicating access to the service providing server device detected by the access detection means, and transmitting the information as terminal acquisition access information to the management server device. The management server device comprises a server account information acquisition means for acquiring account information indicating each account opened in the service providing server device and the server login ID of each account from the service providing server device, a terminal acquisition access information acquisition means for acquiring terminal acquisition access information from each terminal device, a history generation means for aggregating the terminal acquisition access information acquired from each terminal device for each user based on the terminal login ID or terminal ID to generate an access history, and an aggregation means for identifying which user each account of the service providing server device belongs to based on the terminal login ID or terminal ID or user information recorded in association with any of them and the server login ID, associating each account with the access history, and aggregating the usage status of each account. A management system characterized by comprising the above.

26. A management server device constituting a management system together with a terminal device, comprises a server account information acquisition means for acquiring account information indicating each account opened in the service providing server device and the server login ID of each account from the service providing server device, Terminal acquisition access information acquisition means for acquiring, from each terminal device, terminal acquisition access information in which a user's terminal login ID is attached to information indicating that an account of a service providing server device has been accessed; History generation means for generating an access history by aggregating, for each user, the terminal acquisition access information acquired from each terminal device based on the terminal login ID or terminal ID; Aggregation means for identifying which user each account of the service providing server device belongs to based on the terminal login ID or terminal ID or user information recorded in association with any of these and the server login ID, associating each account with the access history, and aggregating the usage status of each account; A management server device comprising the above.

27. A management server program for realizing, by a computer, a management server device that constitutes a management system together with a terminal device, the computer being caused to: Server account information acquisition means for acquiring, from the service providing server device, account information indicating each account opened in the service providing server device and the server login ID of each account; Terminal acquisition access information acquisition means for acquiring, from each terminal device, terminal acquisition access information in which a user's terminal login ID is attached to information indicating that an account of a service providing server device has been accessed; History generation means for generating an access history by aggregating, for each user, the terminal acquisition access information acquired from each terminal device based on the terminal login ID or terminal ID; A management server program for causing the computer to function as aggregation means for identifying which user each account of the service providing server device belongs to based on the terminal login ID or terminal ID or user information recorded in association with any of these and the server login ID, associating each account with the access history, and aggregating the usage status of each account.

28. A terminal device that constitutes a management system together with a management server device, a login ID acquisition means for acquiring the terminal login ID or terminal ID of the user used in the login process, an access detection means for detecting access to the account of the service providing server device, the management server device aggregates the terminal acquisition access information acquired from each terminal device for each user based on the terminal login ID or terminal ID to generate an access history, and associates the access history with the account of the service providing server device. An access information transmission means for attaching the terminal login ID or terminal ID to the information indicating access to the service providing server device detected by the access detection means and transmitting it to the management server device as terminal acquisition access information, A terminal device comprising.

29. A terminal program for realizing, by a computer, a terminal device that constitutes a management system together with a management server device, the computer being a login ID acquisition means for acquiring the terminal login ID or terminal ID of the user used in the login process, an access detection means for detecting access to the account of the service providing server device, the management server device aggregates the terminal acquisition access information acquired from each terminal device for each user based on the terminal login ID or terminal ID to generate an access history, and associates the access history with the account of the service providing server device. A terminal program for functioning as an access information transmission means for attaching the terminal login ID or terminal ID to the information indicating access to the service providing server device detected by the access detection means and transmitting it to the management server device as terminal acquisition access information.

30. Server account information acquisition means for acquiring account information indicating each account opened in the service providing server device and the usage history of each account from the service providing server device, Aggregation means for aggregating the usage status of each account based on the account information acquired from the service providing server device, A management server device comprising:

31. A management server program for realizing the management server device by a computer, the computer being Server account information acquisition means for acquiring account information indicating each account opened in the service providing server device and the usage history of each account from the service providing server device, A management server program for causing the computer to function as aggregation means for aggregating the usage status of each account based on the account information acquired from the service providing server device.

32. In any one of the systems, management server devices, management server programs, terminal devices, or terminal programs according to claims 25 to 29, The terminal device includes a terminal device connected to an external network of the organization, A system, management server device, management server program, terminal device, or terminal program configured such that the terminal device cannot be connected to the internal network unless it includes the access detection means and the access information transmission means.

33. In any one of the systems, management server devices, management server programs, terminal devices, or terminal programs according to claims 25 to 31, The aggregation means identifies an account that is not used or is used less frequently in the service providing server device, and performs a process for deleting the account in the service providing server device. A system, management server device, management server program, terminal device, or terminal program

34. In any of the systems, management server devices, management server programs, terminal devices, or terminal programs according to claims 25 to 29, the terminal acquisition access information and the server acquisition access information include IP address information used when the terminal device that performed the access accessed the Internet, the aggregation means detects access to the account of the service providing server device from a terminal device not managed by the management server device based on the difference between the IP address information included in the terminal acquisition access information and the IP address information included in the server acquisition access information. A system, management server device, management server program, terminal device, or terminal program characterized by this.

35. A management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, the terminal device includes at least one processor, and a storage for recording an agent configured to be executed by the at least one processor, the agent detects which function of each service providing server device has been accessed, and includes an instruction to transmit function access information indicating which function of each service providing server device has been accessed, which has been detected, to the management server device, the management server device includes at least one processor, and a storage for recording a management program configured to be executed by the at least one processor, the management program acquires function access information from each terminal device, and includes an instruction to aggregate the usage status of each function in each service providing server device based on the function access information acquired from each terminal device. A management system characterized by this.

36. A management server device capable of communicating with a terminal device, at least one processor, and a storage for recording a management program configured to be executed by the at least one processor, wherein the management program, acquires function access information from each terminal device, and includes an instruction to aggregate the usage status of each function in each service providing server device based on the function access information acquired from each terminal device. A management server device characterized by this.

37. A non - transitory recording medium recording a management program for realizing, by a computer, a management server device capable of communicating with a terminal device, wherein the management program, acquires function access information from each terminal device, and includes an instruction to aggregate the usage status of each function in each service providing server device based on the function access information acquired from each terminal device. A non - transitory recording medium recording a management program characterized by this.

38. A management server device that aggregates which functions of a plurality of service providing server devices are being used by a plurality of terminal devices, at least one processor, and a storage for recording a management program configured to be executed by the at least one processor, wherein the management program, acquires function access information indicating which functions of each service providing server device each terminal device has accessed from each of the service providing server devices, and includes an instruction to aggregate the usage status of each function in each service providing server device based on the function access information acquired from each service providing server device. A management server device.

39. A non-transitory recording medium recording a management program for realizing, by a computer, a management server device that aggregates which functions of a plurality of service providing server devices are being used by a plurality of terminal devices, The management program, acquires function access information indicating which functions of each service providing server device each terminal device has accessed from each of the service providing server devices, and is a non-transitory recording medium recording a management program including an instruction to aggregate the usage status of each function in each service providing server device based on the function access information acquired from each service providing server device.

40. A management system including a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, The terminal device, includes at least one processor, and a storage for recording an agent configured to be executed by the at least one processor, The agent, detects which of the service providing server devices it has accessed, and includes an instruction to transmit access information indicating which of the service providing server devices has been accessed, as detected, to the management server device, The management server device, includes at least one processor, and a storage for recording a management program configured to be executed by the at least one processor, The management program, acquires access information from each terminal device, and is characterized by including an instruction to collate the access information acquired from each terminal device with a list of permitted service providing devices and identify a service providing device that is not being used despite being permitted or a service providing device that is being used despite not being permitted.

41. A management server device that constitutes a management system together with a terminal device, at least one processor, and a storage for recording a management program configured to be executed by the at least one processor, wherein the management program acquires access information indicating to which of the service providing server devices each terminal device has accessed from each of the terminal devices, collates the access information acquired from each terminal device with a list of service providing devices that are permitted, and includes an instruction to identify a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted. A management server device characterized by this.

42. A non - transitory recording medium recording a management program for realizing, by a computer, a management server device that constitutes a management system together with a terminal device, wherein the management program acquires access information indicating to which of the service providing server devices each terminal device has accessed from each of the terminal devices, collates the access information acquired from each terminal device with a list of service providing devices that are permitted, and records a management program including an instruction to identify a service providing device that is not being used despite being permitted, or a service providing device that is being used despite not being permitted. A non - transitory recording medium.

43. A management server device for identifying which of a plurality of service providing server devices a plurality of terminal devices are using, at least one processor, and a storage for recording a management program configured to be executed by the at least one processor, wherein the management program Obtain access information indicating which service - providing server device each terminal device has accessed from each of the service - providing server devices. A management server device, characterized in that it comprises an instruction for collating the access information obtained from each service - providing server device with a list of permitted service - providing devices, and identifying a service - providing device that is not being used despite being permitted, or a service - providing device that is being used despite not being permitted.

44. A non - transitory recording medium storing a management program for realizing, by a computer, a management server device that identifies which of a plurality of service - providing server devices a plurality of terminal devices are using, The management program, obtains access information indicating which service - providing server device each terminal device has accessed from each of the service - providing server devices, A non - transitory recording medium storing a management program that collates the access information obtained from each service - providing server device with a list of permitted service - providing devices, and includes an instruction for identifying a service - providing device that is not being used despite being permitted, or a service - providing device that is being used despite not being permitted.

45. A management system comprising a plurality of terminal devices to be managed and a management server device capable of communicating with the plurality of terminal devices, The terminal device, comprises at least one processor, and a storage for recording an agent configured to be executed by the at least one processor, The agent, obtains the terminal login ID of the user used during the login process, detects access to an account of a service - providing server device, Attach the terminal login ID to the information indicating access to the detected service - providing server device, and include an instruction to transmit it as terminal - acquired access information to the management server device. The management server device includes at least one processor, and a storage for recording a management program configured to be executed by the at least one processor. The management program acquires account information indicating each account opened on the service - providing server device and the server login ID of each account from the service - providing server device, acquires terminal - acquired access information from each terminal device, aggregates the terminal - acquired access information acquired from each terminal device for each user based on the terminal login ID to generate an access history, identifies which user each account on the service - providing server device belongs to based on the terminal login ID or user information recorded in association with the terminal login ID and the server login ID, associates each account with the access history, and includes an instruction to aggregate the usage status of each account. A management system characterized by the above is provided.

46. A management server device that constitutes a management system together with a terminal device, includes at least one processor, and a storage for recording a management program configured to be executed by the at least one processor. The management program acquires account information indicating each account opened on the service - providing server device and the server login ID of each account from the service - providing server device, acquires, from each terminal device, terminal - acquired access information in which the user's terminal login ID is attached to the information indicating access to an account on the service - providing server device. Aggregate the terminal acquisition access information obtained from each terminal device for each user based on the terminal login ID to generate an access history, Based on the terminal login ID or user information recorded in association with the terminal login ID and the server login ID, identify which user each account of the service providing server device belongs to, associate each account with the access history, and aggregate the usage status of each account. A management server device having an instruction for this.

47. A non-transitory recording medium recording a management program for realizing a management server device constituting a management system together with a terminal device, The program is, Obtain account information indicating each account opened in the service providing server device and the server login ID of each account from the service providing server device, Obtain terminal acquisition access information with the user's terminal login ID attached to information indicating access to an account of the service providing server device from each terminal device, Aggregate the terminal acquisition access information obtained from each terminal device for each user based on the terminal login ID to generate an access history, Based on the terminal login ID or user information recorded in association with the terminal login ID and the server login ID, identify which user each account of the service providing server device belongs to, associate each account with the access history, and aggregate the usage status of each account. A non-transitory recording medium recording a management server program having an instruction for this.

48. At least one processor, A storage for recording a management program configured to be executed by the at least one processor, The management program is, Obtain account information indicating each account opened in the service-providing server device and the usage history of each such account from the service-providing server device, A management server device comprising an instruction to aggregate the usage status of each account based on the account information obtained from the service-providing server device.

49. A non-transitory recording medium recording a management program for realizing the management server device by a computer, wherein the management program, obtains account information indicating each account opened in the service-providing server device and the usage history of each such account from the service-providing server device, and is a non-transitory recording medium recording a management program comprising an instruction to aggregate the usage status of each account based on the account information obtained from the service-providing server device.

Citation Information

Patent Citations

  • Image processing device, control method, and program

    JP2018019240A

  • System, method, and program

    JP2020022063A

  • Information processor, method for processing information, and program

    JP2021092892A

  • Information processing device and program

    JP2023032359A

  • Information processing device and program

    JP2023033078A