Operation execution system, operation execution method, and program
The operation execution system addresses security concerns in automating business system operations by using a managed system to securely change and manage account passwords, thereby enhancing overall security.
Patent Information
- Application Number
- JP2025053441
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-03-16
AI Technical Summary
When automating operations on business systems, there is a security risk as users executing scripts or RPA may be able to access and refer to account IDs, which is a concern for companies with strict security requirements.
An operation execution system that includes a management device for managing account information and an operation execution device that executes scripts to change passwords. The system requests temporary and permanent changes to passwords, with the management device determining and performing these changes if conditions are met.
This solution enhances security by reducing the risk of account ID exposure and ensuring that password changes are managed securely, even when automating operations.
Smart Images

Figure 2025094255000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an operation execution system, an operation execution method, and a program.
Background Art
[0002] In recent years, various business systems have been used in enterprises. For example, in banks, various business systems such as accounting systems and information systems are used to conduct banking operations. Since routine operations such as maintenance work are often performed regularly in these business systems, workers in charge need the account IDs of the business systems for these operations.
[0003] On the other hand, a technology is known in which the account IDs of business systems are collectively managed by a server, and the account IDs (and their passwords) are lent to workers in charge in response to applications from the responsible persons.
[0004] By the way, in recent years, technologies for automating operations for various tasks that were originally performed manually have become known. For example, a technology for automating operations in the operation of IT systems is known (Patent Document 1). Also, a technology for automatically executing operations for various tasks that were originally performed manually by executing a program described in a script language (hereinafter also simply referred to as a "script") is known, and it is also sold and distributed as a product. In addition to these, technologies such as RPA (Robotic Process Automation) are also known as technologies for automatically executing operations for various tasks that were originally performed manually.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] Here, when automating an operation for a certain work or the like on a business system, it is necessary to grant the entity executing the operation the execution authority based on the account ID (and its password) of the business system.
[0007] However, in this case, for example, a user of a terminal equipped with a script or RPA that executes the above operation may be able to refer to the account ID, which is a security issue. This is particularly a problem for companies and the like that are subject to strict security requirements.
[0008] One embodiment of the present invention has been made in view of the above points, and an object thereof is to improve the security when automating an operation using an account.
Means for Solving the Problems
[0009] To achieve the above object, an operation execution system according to an embodiment includes a management device that manages account information, and an operation execution device that executes one or more scripts that respectively realize operations for changing the password included in the account information. The operation execution device, by executing the one or more scripts, transmits a request for a temporary change representing a temporary change of the password to the management device, and then, if the temporary change is successful, transmits a request for a permanent change representing a non-temporary change of the password to the management device. The management device has a determination unit that determines whether to perform the temporary change or the permanent change when receiving the request for the temporary change or the request for the permanent change, and a response unit that performs the temporary change or the permanent change and transmits the result of the temporary change or the permanent change to the operation execution device when it is determined to perform the temporary change or the permanent change. The determination unit determines to perform the temporary change or the permanent change when there is no change in the information regarding the one or more scripts.
Effects of the Invention
[0010] It is possible to improve the security when automating the operation of using an account.
Brief Description of the Drawings
[0011]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Modes for Carrying Out the Invention
[0012] Hereinafter, embodiments of the present invention (the present embodiment) will be described in detail. In this embodiment, an operation script execution system 1 that can improve the security when automating an operation of using an account by a script will be described, targeting the case of automating an operation of using an account by a script. Here, the operation script execution system 1 according to the present embodiment enables the use of an account defined by this application and approval based on an application for executing a script, and acquires and uses the account when the script is executed. As a result, the security at the time of executing a script that automates an operation of using an account can be improved.
[0013] However, automating an operation of using an account by a script is just an example. For example, even in the case of automating by RPA or other technologies (for example, machine learning technologies that realize AI (Artificial Intelligence), etc.), the present embodiment is similarly applicable.
[0014] Note that hereinafter, a script for executing a certain predetermined operation is also referred to as an "operation script". The "operation script" includes, for example, codes and commands for operating a computer, the program itself such as an application, or instructions for calling a program. Also, a set of operation scripts composed of one or more operation scripts and realizing one work content by the operations executed by these operation scripts is called a "script group" or a "scenario".
[0015] <Overall Configuration of Operation Script Execution System 1> First, the overall configuration of the operation script execution system 1 according to the present embodiment will be described with reference to FIG. 1. FIG. 1 is a diagram showing an example of the overall configuration of the operation script execution system 1 according to the present embodiment.
[0016] As shown in FIG. 1, the operation script execution system 1 according to the present embodiment includes one or more operation script execution terminals 10, an account management device 20, one or more application terminals 30, one or more approval terminals 40, and one or more target servers 50. These terminals, devices, and servers are communicably connected via a communication network N such as the Internet or a LAN (Local Area Network).
[0017] The target server 50 is various business systems and the like that are the targets of operation scripts. The target server 50 is also called a target. A business system is a computer or computer system that provides various functions and applications used in a company's business activities. Note that the business system may include a computer system called a core system. Examples of business systems include accounting systems, accounting systems, information systems, sales management systems, production management systems, inventory management systems, expense settlement systems, personnel management systems, and the like.
[0018] Here, the accounts of the target server 50 (that is, the account ID such as a user ID and the password corresponding to the account ID) are managed by the account management device 20 as account information.
[0019] In addition, in order to perform an operation on the target server 50 by an operation script, the entity that executes the operation script needs to be granted the authority corresponding to the operation. Such authority is determined by the account ID used when the executing entity logs in to the target server 50. Account IDs include, for example, IDs with administrator privileges such as "root" and "administrator" (so-called "privileged IDs") and other IDs (so-called "general IDs"). Also, even general IDs may have different authorities depending on the account ID.
[0020] The application terminal 30 is a terminal device that performs a workflow application as an application for executing an operation script. Note that, as the application terminal 30, various terminal devices such as a PC (Personal Computer), a smartphone, and a tablet terminal are used, for example.
[0021] The application terminal 30 has an application processing unit 301 as a functional unit. The application processing unit 301 executes a process for performing a workflow application. Note that the application processing unit 301 is realized by a process in which one or more programs installed in the application terminal 30 cause the CPU (Central Processing Unit) to execute.
[0022] The approval terminal 40 is a terminal device that performs approval (workflow approval) for the workflow application applied by the application terminal 30. Note that, as the approval terminal 40, various terminal devices such as a PC, a smartphone, and a tablet terminal are used, for example.
[0023] The approval terminal 40 has an approval processing unit 401 as a functional unit. The approval processing unit 401 executes a process for approving the workflow application. Note that the approval processing unit 401 is executed by a process in which one or more programs installed in the approval terminal 40 cause the CPU to execute.
[0024] The account management device 20 is a computer or a computer system that manages the account information of the operation target server 50 and manages the application information of the workflow.
[0025] The account management device 20 has a workflow processing unit 201, a response unit 202, and a check unit 203 as functional units. The account management device 20 also has a storage unit 204.
[0026] The workflow processing unit 201 executes processes related to workflow applications and approvals. For example, the workflow processing unit 201 stores the application information for which a workflow has been applied in the storage unit 204, or updates the application information according to the workflow approval (that is, updates the application information to "approved"). Here, the application information is information representing the content applied for by the workflow application and its status (for example, "under application", "approved", etc.).
[0027] The response unit 202 sends a response to a request from the operation script execution terminal 10. Examples of requests from the operation script execution terminal 10 include, as will be described later, an account information acquisition request, a temporary registration request for a new password, a formal registration request for a new password, etc.
[0028] The check unit 203 determines whether it is possible to execute the process corresponding to a request from the operation script execution terminal 10 (hereinafter, this determination is also referred to as "validity check"). For example, the check unit 203 performs a validity check on an account information acquisition request to determine whether it is possible to acquire the account information related to the request. Similarly, for example, the check unit 203 performs a validity check on a temporary registration request for a new password to determine whether it is possible to temporarily register the new password related to the request. Similarly, for example, the check unit 203 performs a validity check on a formal registration request for a new password to determine whether it is possible to formally register the new password related to the request. Here, the temporary registration of a new password means temporarily registering the new password as a temporary password in the account information, and the formal registration of a new password means changing the password included in the account information to the new password.
[0029] The storage unit 204 stores various types of information. Examples of the information stored in the storage unit 204 include account information, application information, etc. The details of the account information and the application information will be described later.
[0030] Note that the workflow processing unit 201, the response unit 202, and the check unit 203 are realized by the processing executed by one or more programs installed in the account management device 20 on the CPU. Further, the storage unit 204 can be realized by using a storage device (for example, an auxiliary storage device such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive)) provided in the account management device 20 or a storage device connected to the account management device 20 via a communication network.
[0031] The operation script execution terminal 10 is a terminal device that executes each operation script constituting the scenario. Note that as the operation script execution terminal 10, for example, various terminal devices such as a PC, a smartphone, and a tablet terminal are used.
[0032] The operation script execution terminal 10 includes, as functional units, a startup control unit 101, an execution control unit 102, and a request unit 103. Further, the operation script execution terminal 10 includes a storage unit 104.
[0033] The startup control unit 101 controls the startup of the scenario. Here, the startup control unit 101 controls the startup of the scenario by an arbitrary method. For example, the startup control unit 101 may start the scenario in response to a startup instruction operation from the user, may start the scenario according to a scheduler or the like, or may start the scenario corresponding to the condition when a certain condition is satisfied.
[0034] When the scenario is activated by the activation control unit 101, the execution control unit 102 executes each operation script that constitutes the scenario. As a result, a predetermined operation is performed on the operation target (for example, the operation target server 50) by each operation script that constitutes the scenario. Here, in the present embodiment, at least one operation script among the operation scripts that constitute the scenario includes an instruction statement (hereinafter, also referred to as an "information acquisition instruction statement") for realizing an operation for acquiring account information or the like of a certain operation target server 50, or an instruction statement (hereinafter, also referred to as a "temporary registration instruction statement") for realizing an operation for temporarily registering a new password of a certain operation target server 50 and an instruction statement (hereinafter, also referred to as a "final registration instruction statement") for realizing an operation for finally registering the new password of the operation target server 50.
[0035] In response to an instruction based on a predetermined instruction statement (information acquisition instruction statement, temporary registration instruction statement, or final registration instruction statement) included in the operation script executed by the execution control unit 102, the request unit 103 transmits a request (account information acquisition request, new password temporary registration request, or new password final registration request) corresponding to the instruction to the account management device 20.
[0036] Here, the operation target of the operation script may be not only the operation target server 50 but also various application programs (hereinafter, also referred to as "local apps 60") installed on the operation script execution terminal 10. Examples of the local apps 60 include various utilities such as file compression / decompression software, and document applications such as spreadsheet software and document creation software. By targeting the local apps 60, for example, the operation results for the operation target server 50 can be processed (for example, decompressing compressed files using file compression / decompression software, processing using spreadsheet software, etc.) by the local apps 60.
[0037] The storage unit 104 stores various types of information. Examples of the information stored in the storage unit 104 include information used for executing an operation script (such as an account ID, its password, various parameters, etc.), information indicating the execution result of the operation script and the processing results during the execution, and the like.
[0038] Note that the startup control unit 101, the execution control unit 102, and the request unit 103 are realized by the processing executed by one or more programs installed in the operation script execution terminal 10 on the CPU. Also, the storage unit 104 can be realized using a storage device (such as an auxiliary storage device like an HDD or SSD, various memories, etc.) provided in the operation script execution terminal 10.
[0039] The configuration of the operation script execution system 1 shown in FIG. 1 is an example and is not limited thereto, and other configurations may be used. For example, the application terminal 30 and the approval terminal 40 do not necessarily need to be separated, and the same terminal may function as either the application terminal 30 or the approval terminal 40 by a user logged in to the account management device 20. Also, the application terminal 30 may function as the operation script execution terminal 10. Further, for example, the storage unit 204 of the account management device 20 may be realized by a plurality of storage units or a DB (database).
[0040] <Script group (scenario)> Here, as specific examples of the script group (scenario), the following two scenarios (1) and (2) will be described.
[0041] (1) Scenario name: Performance information acquisition scenario A scenario of acquiring performance information from a certain operation target server 50 (hereinafter referred to as "operation target server A") and another certain operation target server 50 (hereinafter referred to as "operation target server B") and creating a report (2) Scenario name: Password change scenario A scenario of changing the passwords of operation target server A and operation target server B ≪Performance information acquisition scenario≫ An example of a performance information acquisition scenario is shown in FIG. 2. The performance information acquisition scenario shown in FIG. 2 is composed of three operation scripts, namely operation script 1-1, operation script 1-2, and operation script 1-3, and they are executed in the order of operation script 1-1, operation script 1-2, and operation script 1-3.
[0042] First, operation script 1-1 executes the following operations 1-1-1 to 1-1-5 in sequence, for example.
[0043] Operation 1-1-1: An operation to acquire the account information of the target server A Operation 1-1-2: An operation to log in to the target server A Operation 1-1-3: An operation to execute a performance information output command Operation 1-1-4: An operation to compress the execution result of the performance information output command and create a compressed file Operation 1-1-5: An operation to send the compressed file to the operation script execution terminal 10 Note that the above operation 1-1-1 is realized by an information acquisition command sentence.
[0044] Next, operation script 1-2 executes the following operations 1-2-1 to 1-2-6 in sequence, for example.
[0045] Operation 1-2-1: An operation to acquire the account information of the target server B Operation 1-2-2: An operation to log in to the target server B Operation 1-2-3: An operation to acquire a file list using, for example, the dir command or the ls command Operation 1-2-4: An operation to acquire performance monitor information Operation 1-2-5: An operation to compress the file list and the performance monitor information and create a compressed file Operation 1-2-6: An operation to send the compressed file to the operation script execution terminal 10 Note that the above operation 1-2-1 is realized by an information acquisition command sentence.
[0046] Finally, operation scripts 1-3 execute operations 1-3-1 to 1-3-2 below in order, for example.
[0047] Operation 1-3-1: An operation to decompress the compressed file received from operation target server A and the compressed file received from operation target server B Operation 1-3-2: An operation to process the decompressed file with local app 60 (for example, spreadsheet software, etc.) and create a report showing the performance information of operation target server A and operation target server B In this way, in operation script execution terminal 10, by executing each operation script that constitutes the scenario, the work content represented by the scenario (performance information acquisition work in the example shown in FIG. 2) is realized. Also, at this time, the account information necessary for the execution is acquired when each operation script that constitutes the scenario is executed (for example, the above operations 1-1-1 and 1-2-1). For this reason, operation script execution terminal 10 does not hold account information for a long time, and as a result, it is possible to reduce risks such as leakage of account information.
[0048] ≪Password change scenario≫ An example of the password change scenario is shown in FIG. 3. The password change scenario shown in FIG. 3 is composed of operation script 2-1 and operation script 2-2, and is executed in the order of operation script 2-1 and operation script 2-2.
[0049] First, operation script 2-1 executes operations 2-1-1 to 2-1-5 below in order, for example.
[0050] Operation 2-1-1: An operation to acquire the account information of operation target server A Operation 2-1-2: An operation to generate a new password for operation target server A Operation 2-1-3: An operation to temporarily register the new password of operation target server A in account management device 20 Operation 2-1-4: An operation to change the password of operation target server A to the new password Operation 2-1-5: Operation to officially register the new password of the target server A with the account management device 20 Note that the above operation 2-1-1 is realized by an information acquisition command sentence, the above operation 2-1-3 is realized by a temporary registration command sentence, and the above operation 2-1-5 is realized by an official registration command sentence, respectively.
[0051] Then, the operation script 2-2 sequentially executes the following operations 2-2-1 to 2-2-5, for example.
[0052] Operation 2-2-1: Operation to acquire the account information of the target server B Operation 2-2-2: Operation to generate a new password for the target server B Operation 2-2-3: Operation to temporarily register the new password of the target server B with the account management device 20 Operation 2-2-4: Operation to change the password of the target server B to the new password Operation 2-2-5: Operation to officially register the new password of the target server B with the account management device 20 Note that the above operation 2-2-1 is realized by an information acquisition command sentence, the above operation 2-2-3 is realized by a temporary registration command sentence, and the above operation 2-2-5 is realized by an official registration command sentence, respectively.
[0053] In this way, on the operation script execution terminal 10, by executing each operation script that constitutes the scenario, the work content represented by the scenario (password change work in the example shown in FIG. 3) is realized. Also, at this time, when each operation script that constitutes the scenario is executed, the account information necessary for the execution is acquired (for example, the above operations 2-1-1 and 2-2-1). For this reason, the operation script execution terminal 10 no longer holds the account information for a long time, and as a result, it is possible to reduce risks such as leakage of account information. Furthermore, since the new password is automatically generated by the operation script and the password of the operation target server 50 is changed, the password can be changed without human intervention, and as a result, it is possible to reduce the human password leakage risk (for example, the leakage risk due to writing down the changed password as a memo, etc.).
[0054] <Account information> Next, the account information will be described with reference to FIG. 4. FIG. 4 is a diagram showing an example of the account information. Note that one or more pieces of account information are stored in the storage unit 204 of the account management device 20.
[0055] As shown in FIG. 4, the account information includes, as data items (also referred to as information items or attributes), "operation target server", "account ID", "password", and "temporary password", etc.
[0056] In the "operation target server", information for identifying the operation target server 50 (for example, a target name representing the name of the operation target server 50, etc.) is set. In the "account ID", the account ID of the operation target server 50 is set. In the "password", the password corresponding to the account ID (the officially registered password) is set. In the "temporary password", a temporary password corresponding to the account ID is temporarily set. Note that the password (the officially registered password, the temporary password) is encrypted and then set in the account information.
[0057] As described above, the account information is information in which at least information indicating the operation target server 50, an account ID, and a password are associated with each other. Note that the account information may include data items such as a "domain" in which, for example, a domain (or group) to which the account ID belongs is set, in addition to the above data items.
[0058] <Application Information> Next, the application information will be described with reference to FIG. 5. FIG. 5 is a diagram showing an example of the application information. Note that one or more pieces of application information are stored in the storage unit 204 of the account management device 20.
[0059] As shown in FIG. 5, the application information includes, as data items, an "application ID", an "applicant login ID", a "status", an "applicant", an "application name", an "execution terminal name", a "start date and time", and the like.
[0060] An "application ID" is set as information for identifying a workflow. An "applicant login ID" is set as the login ID of the applicant who applied for the workflow (that is, the login ID used when the user operating the application terminal 30 logs in to the account management device 20 (or the workflow processing unit 201 of the account management device 20)). A "status" is set as the status of the workflow, such as "under application" or "approved". Here, "under application" is a status indicating, for example, that the workflow has not been approved. On the other hand, "approved" is a status indicating, for example, that the workflow has been approved.
[0061] For the "Applicant", the name of the applicant who submitted the workflow (e.g., name, etc.) is set. For the "Application Name", the application name specified at the time of submitting the workflow is set. For the "Execution Terminal Name", information indicating the operation script execution terminal 10 specified at the time of submitting the workflow (e.g., the name of the operation script execution terminal 10, IP (Internet Protocol) address, MAC (Media Access Control) address, etc.) is set. Execution of each operation script constituting the scenario is permitted for the operation script execution terminal 10 set in this "Execution Terminal Name". For the "Start Date and Time", the date and time specified at the time of submitting the workflow is set. Execution of each operation script constituting the scenario is permitted after the date and time set in this "Start Date and Time".
[0062] Thus, the application information includes various information specified at the time of submitting the workflow, etc. Note that, for example, the above data items are just examples. For example, when a scenario to be executed on the operation script execution terminal 10 is specified at the time of workflow submission, a "Scenario Name" in which the scenario name, etc. of that scenario is set may be included as a data item. Also, for example, when the period during which execution of the scenario is permitted is specified, in addition to the "Start Date and Time", an "End Date and Time" in which the date and time when execution of each operation script constituting the scenario is no longer permitted is set may be included as a data item. For the "End Date and Time", the date and time specified at the time of submitting the workflow is set, and execution of each operation script constituting the scenario is permitted during the period from the date and time set in the "Start Date and Time" until the date and time set in the "End Date and Time" arrives. Additionally, for example, a "Script Name" in which the script name (file name), etc. of each operation script constituting the scenario is set may be included as a data item. Also, for example, a "Keyword" in which the correct keyword for the keyword described later (hereinafter also referred to as the correct keyword) is set, or the account ID of the operation target server 50 may be included as a data item.
[0063] <Process Flow> Next, the process flow executed by the operation script execution system 1 according to this embodiment will be described.
[0064] ≪Workflow Application and Approval≫ Hereinafter, the process when applying for and approving a workflow will be described with reference to FIG. 6. FIG. 6 is a sequence diagram for explaining an example of the process from workflow application to approval.
[0065] First, the application processing unit 301 of the application terminal 30 displays a workflow application screen (step S101). Here, the workflow application screen is a screen for applying for a workflow. The workflow application screen includes, for example, designation fields for designating at least one of at least "application name", "execution terminal name", and at least one of "start date and time" and "end date and time" among the respective data items included in the application information. A user (applicant) of the application terminal 30 can specify desired values or information in these designation fields. Regarding the "start date and time" and "end date and time", either only one of the "start date and time" or "end date and time" may be specified, or both the "start date and time" and "end date and time" may be specified. When only the "start date and time" is specified, the execution of each operation script is permitted after that start date and time. When only the "end date and time" is specified, the execution of each operation script is permitted from after the approval of the workflow until that end date and time. When both the "start date and time" and "end date and time" are specified, the execution of each operation script is permitted during the period from the start date and time until the end date and time arrives.
[0066] Next, the application processing unit 301 of the application terminal 30 receives a workflow application operation on the workflow application screen (step S102). The applicant can perform a workflow application operation by designating various information (for example, application name, execution terminal name, start date and time, etc.) on the workflow application screen and then pressing an application button or the like. In addition to the above various information, on the workflow application screen, for example, a user (approver) who can approve the workflow can also be designated.
[0067] When the application processing unit 301 of the application terminal 30 receives a workflow application operation, it sends the workflow application to the account management device 20 (step S103). The workflow application includes various information (e.g., application name, execution terminal name, start date and time, etc.) specified by the applicant on the workflow application screen, and information indicating the applicant (e.g., login ID, name, etc.).
[0068] When the workflow processing unit 201 of the account management device 20 receives a workflow application, it creates application information from the various information included in the workflow application (e.g., application name, execution terminal name, start date and time, applicant's login ID, name, etc.) (step S104). That is, the workflow processing unit 201 generates an application ID and then creates application information including this application ID and the above various information. At this time, for example, "application in progress" indicating not approved is set in the "status" of the application information.
[0069] Although the application information is created by the account management device 20, the application information may be created by the application terminal 30.
[0070] Next, the workflow processing unit 201 of the account management device 20 saves the application information in the storage unit 204 (step S105). As a result, for example, application information with a status of "application in progress" is stored in the storage unit 204.
[0071] When performing workflow approval, the approval processing unit 401 of the approval terminal 40 displays a workflow approval screen (step S106). Here, the workflow approval screen is a screen for performing workflow approval. The workflow approval screen lists, for example, the workflows that can be approved by the user (approver) of the approval terminal 40.
[0072] Next, the approval processing unit 401 of the approval terminal 40 receives a workflow approval operation on the workflow approval screen (step S107). The approver can perform a workflow approval operation by specifying or selecting a desired workflow from the list of approvable workflows and then pressing an approval button or the like.
[0073] When the approval processing unit 401 of the approval terminal 40 receives a workflow approval operation, it sends the workflow approval to the account management device 20 (step S108). The workflow approval includes, for example, the application ID of the workflow for which a workflow approval operation has been performed by the approver on the workflow approval screen.
[0074] When the workflow processing unit 201 of the account management device 20 receives a workflow approval, it updates the status of the corresponding application information among the application information stored in the storage unit 204 to approved (step S109). That is, the workflow processing unit 201 updates the status of the application information indicated by the application ID included in the workflow approval to approved among the application information stored in the storage unit 204, for example.
[0075] As described above, a workflow for executing each operation script constituting a scenario on the operation script execution terminal 10 is applied for and approved. Note that applying for and approving application information by a workflow is just an example, and application information may be applied for and approved by other methods. For example, application information may be applied for by being stored in an application folder, and the application information may be approved by being stored in an approval folder within the application folder.
[0076] Also, for example, the account management device 20 may register and update application information based on application information that has been applied for or approved by an external workflow management system that approves workflows. More specifically, when information regarding the workflow is notified from an external workflow management system, or at predetermined timings, cycles, etc., the workflow management system or a database related thereto may be connected, and application information including the status may be registered and updated. At this time, if the status is omitted in the application information, the application information may be treated as having been approved.
[0077] ≪Execution of Scenario Using Account Information≫ Hereinafter, the procedure for executing a scenario in which account information such as the performance information acquisition scenario shown in FIG. 2 is acquired and some work content is realized using the account information will be described with reference to FIG. 7. FIG. 7 is a sequence diagram for explaining an example of the procedure for executing a scenario using account information. Hereinafter, it is assumed that each operation script constituting the scenario performs a predetermined operation on the operation target server 50 using the account information after performing an operation of acquiring the account information of a certain operation target server 50.
[0078] The startup control unit 101 of the operation script execution terminal 10 starts a scenario (for example, the performance information acquisition scenario shown in FIG. 2) (step S201). As a result, the execution control unit 102 of the operation script execution terminal 10 executes the following steps S202 to S208 according to each operation script constituting the scenario. Hereinafter, the case where steps S202 to S208 are executed by a certain operation script will be described.
[0079] First, the execution control unit 102 of the operation script execution terminal 10 instructs the request unit 103 to request the acquisition of the account information of the operation target server 50 by the information acquisition instruction sentence of the operation script (step S202). At this time, the execution control unit 102 instructs the request unit 103 to request the acquisition of account information by specifying, for example, a target name, an account ID, a keyword, etc. Here, the keyword is an arbitrary character string determined in advance and is used for the validity check by the check unit 203. Note that the keyword may also be referred to as a password phrase, etc., and may be a meaningful character string, or may be a random character string without meaning.
[0080] When the request unit 103 of the operation script execution terminal 10 is instructed to request the acquisition of account information, it transmits the account information acquisition request to the account management device 20 (step S203). Here, the account information acquisition request includes the target name, account ID, keyword, etc. specified in the above instruction. In addition to this, various information used for the subsequent validity check (for example, the execution terminal name, the script name (file name) of the operation script, etc.) may also be included.
[0081] When the check unit 203 of the account management device 20 receives the account information acquisition request from the operation script execution terminal 10, it performs a validity check (step S204). Here, in the validity check, for example, one or more of the following conditions 1 to 5 are used to determine whether all of those one or more conditions are satisfied. Note that if all of those one or more conditions are satisfied, it means that the validity check has succeeded, and if not, it means that the validity check has failed.
[0082] Condition 1: The application information stored in the storage unit 204 has been approved. Here, for specifying the application information, an application name, an application ID, an applicant, an applicant login ID, the execution terminal name of the operation script execution terminal 10, a script name, a storage location of the operation script (for example, a file path including a computer name, a URL, etc.) can be used.
[0083] Condition 2: When only the start date and time are specified in the application information, it is after the start date and time. When only the end date and time are specified in the application information, the status is "Approved" and the end date and time have not arrived yet. When both the start date and time and the end date and time are specified in the application information, it is after the start date and time and the end date and time have not arrived yet.
[0084] Condition 3: The name of the execution terminal (one or more of name, IP address, MAC address, etc.) of the operation script execution terminal 10 is correct. That is, the name of the execution terminal included in the application information matches the name of the execution terminal of the operation script execution terminal 10.
[0085] Condition 4: The information regarding the operation script is correct. That is, for example, the application information includes a script name, and the script name included in the application information matches the script name included in the account information acquisition request. In addition to the script name, for example, information such as the storage location of the operation script (e.g., file path including computer name, URL, etc.), the size (capacity) of the operation script, and the hash value may also be used.
[0086] Condition 5: The keyword is correct. That is, for example, the application information includes a correct keyword, and the correct keyword included in the application information matches the keyword included in the account information acquisition request. Note that the correct keyword may not be set in the application information, but may be uniquely determined, for example, in the operation script execution system 1, or may be uniquely determined for the group to which the operation script execution terminal 10 belongs or the group to which the scenario belongs.
[0087] Note that which of the above Conditions 1 to 5 are used for the validity check is preset. During these validity checks, the account management device 20 requests the operation script to send various information of the operation script, or receives and acquires the necessary information from the operation script by itself, and compares it with the information applied in advance.
[0088] If the validity check in step S204 above is successful, the response unit 202 of the account management device 20 acquires the account information related to the account information acquisition request from the storage unit 204 (step S205). That is, the response unit 202 acquires the account information in which the target name and the account ID included in the account information acquisition request are set from the account information stored in the storage unit 204.
[0089] Then, the response unit 202 of the account management device 20 transmits the account information acquired in step S205 above to the operation script execution terminal 10 (step S206).
[0090] If the validity check in step S204 above fails, the response unit 202 of the account management device 20 does not acquire and transmit the account information, but transmits information indicating that the validity check has failed to the operation script execution terminal 10.
[0091] The execution control unit 102 of the operation script execution terminal 10 sets the account ID and password (or only the password if the account ID is already set) included in the account information received from the account management device 20 for the operation script (step S207). Here, since the password included in the account information is encrypted, the execution control unit 102 decrypts the password, for example, on the memory and sets the decrypted password for the operation script. Thereby, for example, the account ID and password used for the execution of the operation script can be concealed from the user of the operation script execution terminal 10. For example, variables for setting the account ID and password are defined in the operation script, and the execution control unit 102 may set the account ID and password for these variables.
[0092] Then, the execution control unit 102 of the operation script execution terminal 10 executes each operation on the operation target server 50 or the local application 60 according to the operation script in which the account ID and password are set in step S207 above (step S208).
[0093] As described above, in the operation script execution system 1 according to the present embodiment, when each operation script constituting the scenario is executed, information necessary for the execution of the operation script (for example, the password corresponding to the account ID, etc.) is acquired. For this reason, the password is held only by the operation script execution terminal 10 when the operation script is executed, and risks such as password leakage can be reduced. Also, for example, even when the password of the operation target server 50 is periodically changed, the latest password can always be acquired, so that execution failure of the operation script due to an incorrect password or the like can be prevented.
[0094] In step S205 of FIG. 7, account information was acquired from the storage unit 204, but this is not limiting. For example, information such as parameters necessary for the execution of the corresponding operation script may be acquired together with the account information. As a result, since the parameters are also transmitted to the operation script execution terminal 10 together with the password in step S206 of FIG. 7, in step S207 of FIG. 7, in addition to the password, the parameters necessary for the execution of the operation script can also be set in the operation script.
[0095] ≪Execution of Scenario for Changing Account Information≫ Hereinafter, the flow in the case of executing a scenario that realizes the work content of acquiring account information such as the password change scenario shown in FIG. 3 and changing the password will be described with reference to FIG. 8. FIG. 8 is a sequence diagram for explaining an example of the flow in the case of executing a scenario for changing the password included in the account information.
[0096] The startup control unit 101 of the operation script execution terminal 10 activates a scenario (for example, the password change scenario shown in FIG. 3) (step S301). As a result, the execution control unit 102 of the operation script execution terminal 10 executes the following steps S302 to S315 according to each operation script constituting the scenario. Hereinafter, the case where steps S302 to S315 are executed by a certain operation script will be described.
[0097] First, the execution control unit 102 of the operation script execution terminal 10 acquires the account information of the operation target server 50 according to the operation script (step S302). Here, the execution control unit 102 may acquire, for example, the account information previously given to the operation script execution terminal 10 from the storage unit 104 or the like, or may acquire the account information by the same processing as steps S202 to S206 in FIG. 7. Note that the password included in the account information acquired in this step is the password to be changed, and hereinafter will be referred to as the "old password".
[0098] Next, the execution control unit 102 of the operation script execution terminal 10 generates a new password according to the operation script (step S303). Here, the execution control unit 102 may generate a new password by any method. For example, the execution control unit 102 may randomly generate a character string of a random length equal to or greater than a certain length (or a character string of a random length equal to or greater than a certain length and less than a certain length), and use that character string as the new password.
[0099] Next, the execution control unit 102 of the operation script execution terminal 10 instructs the request unit 103 to request a temporary registration of the new password generated in step S303 according to the temporary registration command statement of the operation script (step S304). At this time, the execution control unit 102 instructs the request unit 103 to request a temporary registration of the new password by specifying, for example, a target name, an account ID, a new password, a keyword, and the like.
[0100] When the request unit 103 of the operation script execution terminal 10 is instructed to request a temporary registration of a new password, it sends a request for temporary registration of the new password to the account management device 20 (step S305). Here, the request for temporary registration of the new password includes the target name, account ID, new password, keyword, etc. specified in the above instruction. In addition to this, various information used for the later-described validity check (for example, the name of the execution terminal, the name of the operation script (file name), etc.) may also be included.
[0101] When the check unit 203 of the account management device 20 receives a request for temporary registration of a new password from the operation script execution terminal 10, it performs a validity check in the same manner as step S204 in FIG. 7 (step S306). That is, the check unit 203 determines whether or not all of one or more of the above conditions 1 to 5 are satisfied, for example, using one or more of the above conditions.
[0102] If the validity check in step S306 above is successful, the response unit 202 of the account management device 20 temporarily registers the new password included in the request for temporary registration of the new password (step S307). That is, the response unit 202 sets the new password included in the temporary registration request for the "temporary password" of the account information in which the target name and account ID included in the request for temporary registration of the new password are set among the account information stored in the storage unit 204.
[0103] Then, the response unit 202 of the account management device 20 sends a temporary registration completion response indicating that the temporary registration in step S307 above has been completed to the operation script execution terminal 10 (step S308).
[0104] If the validity check in step S306 above fails, the response unit 202 of the account management device 20 does not perform a temporary registration of the new password and sends information indicating that the validity check has failed to the operation script execution terminal 10.
[0105] The execution control unit 102 of the operation script execution terminal 10 transmits a password change request to the operation target server 50 according to the operation script (step S309). Here, the password change request includes the account ID of the operation target server 50, the old password corresponding to the account ID, and the new password generated in step S303 above. As a result, on the operation target server 50, the password corresponding to the account ID is changed from the old password to the new password.
[0106] When the above password change is successful, the operation target server 50 transmits, for example, a password change completion response indicating the completion of the password change to the operation script execution terminal 10 (step S310). If the above password change fails, the operation target server 50 transmits, for example, a password change failure response indicating that the password change has failed to the operation script execution terminal 10.
[0107] When the execution control unit 102 of the operation script execution terminal 10 receives a password change completion response from the operation target server 50, it instructs the request unit 103 to make a main registration request for the new password generated in step S303 according to the main registration instruction statement of the operation script (step S311). At this time, the execution control unit 102 instructs the request unit 103 to make a main registration request for the new password by specifying, for example, the target name, account ID, keyword, etc.
[0108] When the request unit 103 of the operation script execution terminal 10 is instructed to make a main registration request for the new password, it transmits the main registration request for the new password to the account management device 20 (step S312). Here, the main registration request for the new password includes the target name, account ID, keyword, etc. specified in the above instruction. In addition to this, various information used for the later validity check (for example, the execution terminal name, the script name (file name) of the operation script, etc.) may also be included.
[0109] When the check unit 203 of the account management device 20 receives a request for official registration of a new password from the operation script execution terminal 10, it performs a validity check in the same manner as step S306 above (step S313). That is, the check unit 203 determines, for example, whether all of one or more of the above conditions 1 to 5 are satisfied using one or more of the above conditions.
[0110] If the validity check in step S313 above is successful, the response unit 202 of the account management device 20 officially registers the new password of the account information in which the target name and account ID included in the request for official registration of the new password are set (step S314). That is, the response unit 202 sets the password (new password) set for the "temporary password" of the account information in which the target name and account ID included in the request for official registration of the new password are set among the account information stored in the storage unit 204 to "password", and then deletes the password set for the "temporary password".
[0111] Then, the response unit 202 of the account management device 20 transmits an official registration completion response indicating that the official registration in step S314 above has been completed to the operation script execution terminal 10 (step S315).
[0112] As described above, in the operation script execution system 1 according to the present embodiment, the password of the operation target server 50 can be automatically generated and changed, and the password registered in the account management device 20 can be updated with the changed password. As a result, the password can be changed without human intervention, and as a result, it is possible to reduce the risk of human password leakage (for example, the risk of leakage due to leaving the changed password as a memo).
[0113] Also, when updating the password registered in the account management device 20, after temporarily registering the new password, the new password is permanently registered when the password change of the target server 50 is successful. As a result, for example, even when the password change of the target server 50 fails, it is not necessary to roll back the account information registered in the account management device 20. Note that, for example, the temporary password may be deleted when the permanent registration is performed, when the permanent registration is not performed within a predetermined period, when a valid permanent registration application is not made, and the like.
[0114] <Modification Example> Hereinafter, some modification examples of the present embodiment will be described. Note that the modification examples described below may be combined with one or more modification examples as appropriate.
[0115] · Modification Example 1 The keyword used for the validity check in the check unit 203 may be configured by combining some or all of the various types of information described in the validity check conditions 2 to 4. For example, the name of the execution terminal of the operation script execution terminal 10, the hash value of the operation script, etc. may be combined to form a keyword. In particular, by using information related to the operation script execution terminal 10 or the operation script to configure a keyword and comparing it with the previously applied application information, it is possible to confirm whether the operation script is as applied and whether it has been modified or not.
[0116] · Modification Example 2 Regarding the application of an operation script, the login ID and keyword may be described in the operation script itself, or a login file or keyword file, which is another external file where the login ID and keyword are described, may be referenced. By doing so, it becomes unnecessary to edit the operation script to be executed each time, and it is possible to appropriately update only the information corresponding to the application without changing file information such as the update date and time, file size, and hash value of the operation script. Also, by restricting the reference authority of the login file and keyword file more than that of the operation script, security can be further enhanced.
[0117] ·Modification Example 3 In the validity check (step S306, step S13) at the time of a request for temporary registration of a new password or a request for final registration of a new password, a check may be added as to whether the new password satisfies the required conditions. Here, the required conditions are, for example, the number of characters of the password, the type of characters such as alphanumeric characters and symbols used in the password, and the fact that no words are included in a dictionary or the like, which are preset security policies.
[0118] If the new password does not satisfy the required conditions, its registration is prevented, so it is possible to prevent the use of passwords that do not meet the required security strength or inappropriate passwords.
[0119] At this time, furthermore, in the generation of a new password (step S303), a password corresponding to the security policy for the account to be registered may be generated by a function within the account management device 20 or a function provided by an external system. In this case, the operation script may call this password generation function, receive the generated password, and notify the account management device 20 of the password together with the information necessary for the validity check via the operation script or the password generation function.
[0120] ·Modification Example 4 Although the case of changing the password has been described with reference to FIG. 8, it may also be possible to register, change, delete, etc. account information other than the password (for example, attribute information, role, account authority, etc.). For example, using information specified by the user or information generated by some algorithm or the like, it may be possible to temporarily register (temporarily store) or officially register (store) such information as account information, or to change or delete it from the account information.
[0121] The present invention is not limited to the above-described embodiments specifically disclosed, and various modifications, changes, combinations with known technologies, etc. are possible without departing from the scope of the claims.
Explanation of Reference Numerals
[0122] 1 Operation script execution system 10 Operation script execution terminal 20 Account management device 30 Application terminal 40 Approval terminal 50 Target server to be operated 60 Local application 101 Startup control unit 102 Execution control unit 103 Request unit 104 Storage unit 201 Workflow processing unit 202 Response unit 203 Check unit 204 Storage unit 301 Application processing unit 401 Approval processing unit N Communication network
Claims
1. An operation execution system including a management device that manages account information and an operation execution device that executes one or more scripts that respectively realize an operation for changing a password included in the account information, The operation execution device is a request unit that executes the one or more scripts to transmit a request for a temporary change to the management device, the request being a temporary change to the management device, and then transmits a request for a permanent change to the management device, the request being a non-temporary change to the management device, if the temporary change is successful; The management device includes: a determination unit that, when receiving the request for the temporary change or the request for the final change, determines whether or not to perform the temporary change or the final change; a response unit that, when it is determined that the temporary change or the final change is to be made, makes the temporary change or the final change and transmits a result of the temporary change or the final change to the operation execution device, The determination unit is When there is no change in the information relating to the one or more scripts, the operation execution system determines to make the provisional change or the final change.
2. 2 . The operation execution system according to claim 1 , wherein the temporarily changed and the officially changed passwords are information different from information relating to the one or more scripts and are included in information that can be referenced by execution of the one or more scripts.
3. The response unit:
3. The operation execution system according to claim 1, further comprising: a step of: deleting the temporarily changed password if a request for a permanent change is not received within a predetermined period of time after the temporary change has been made.
4. 1. An operation execution method for use in an operation execution system including a management device for managing account information and an operation execution device for executing one or more scripts each realizing an operation for changing a password included in the account information, comprising: The operation execution device, a request procedure for transmitting a temporary change request representing a temporary change of the password to the management device by executing the one or more scripts, and then, if the temporary change is successful, transmitting a permanent change request representing a non-temporary change of the password to the management device; The management device, a determination step of determining whether or not to make the temporary change or the final change when the request for the temporary change or the request for the final change is received; a response step of performing the temporary change or the final change and transmitting a result of the temporary change or the final change to the operation execution device when it is determined that the temporary change or the final change is to be performed; The determination procedure includes: When there is no change in the information relating to the one or more scripts, it is determined that the temporary change or the final change is to be made.
5. A program for causing a computer to function as the operation execution system according to any one of claims 1 to 3.
Citation Information
Patent Citations
Management server
JP2005018234A
Information processing system, and authentication method
JP2016091210A
Operation work automation system, operation work automation method and operation work automation program
JP2014048860A