License management method, license management system, and license management program
The described license management method and system enhance the detection and prevention of unauthorized application use by validating licenses and registering authentication data to accurately identify and notify administrators of unauthorized activities.
Patent Information
- Application Number
- JP2023221294
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-27
- Publication Date
- 2025-07-09
AI Technical Summary
Existing license management systems struggle to effectively prevent unauthorized use when user forgery occurs, leading to difficulties in detecting and managing unauthorized access to applications.
A license management method and system that includes a management server device to validate application licenses, register unissued information and authentication data for unauthorized users, and output alerts to detect and prevent unauthorized use.
Enhances the detection and prevention of unauthorized application use by accurately identifying and notifying administrators of unauthorized activities, thereby improving the precision and effectiveness of license management.
Smart Images

Figure 2025103713000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a license management method, a license management system, and a license management program.
Background Art
[0002] Patent Document 1 discloses a management server to which a terminal that performs predetermined file processing and captures an image of a user to transmit the user's image image is connected. The management server includes a file processing management information table in which information indicating permission / non - permission of predetermined file processing is registered for each file for each individual user, and an image image management information table in which the user's image image is registered in association with each user. When a file processing request is received from the terminal, the file processing management information table is referred to determine whether file processing by the user is permitted for the target file of the file processing, and the image image management information table is referred to determine whether the user's image image transmitted from the terminal matches the user's image image registered in the image image management information table. When it is determined that file processing of the target file is permitted for the user who made the file processing request and it is determined that the user's image image transmitted from the terminal matches the user's image image registered in the image image management information table, file processing is permitted for the terminal.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Patent Document 1 discloses a management server that prevents unauthorized access to information assets (files). However, in Patent Document 1, there is a problem that it is difficult to prevent unauthorized use by an unauthorized user when forgery occurs by the unauthorized user at the time of registering the user's image.
[0005] The present disclosure has been devised in view of the above-described conventional circumstances, and aims at a license management method, a license management system, and a license management program for more effectively detecting unauthorized use of an application.
Means for Solving the Problems
[0006] The present disclosure provides a license management method for managing a license of an application executed by a computer, the method including: obtaining the license of the application; performing a first determination to determine whether the license of the application is valid; based on the first determination, when it is determined that the license of the application is not valid, registering unissued information indicating that the license has not been issued to the user who uses the application, and registering authentication information used for authenticating the user; and outputting an alert notifying that the authentication information of the user to whom the license has not been issued has been registered.
[0007] In addition, the present disclosure provides a license management system including a terminal device and a management server device that can communicate with the terminal device and manages licenses for applications used by the terminal device. The terminal device transmits the license acquired at the time of starting the application to the management server device. The management server device executes a first determination to determine whether the license of the application acquired from the terminal device is valid. Based on the first determination, when it is determined that the license of the application is not valid, the management server device registers unissued information indicating that the license has not been issued to the user using the application, and registers authentication information used for authenticating the user, and outputs an alert notifying that the authentication information of the user to whom the license has not been issued has been registered.
[0008] In addition, the present disclosure provides a program for processing, by one or more processors, a license management method for managing licenses of applications performed by a computer. The program realizes steps of acquiring a license of the application, executing a first determination to determine whether the license of the application is valid, based on the first determination, when it is determined that the license of the application is not valid, registering unissued information indicating that the license has not been issued to the user using the application, registering authentication information used for authenticating the user, and outputting an alert notifying that the authentication information of the user to whom the license has not been issued has been registered.
Advantages of the Invention
[0009] According to the present disclosure, unauthorized use of applications can be detected more effectively.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Embodiments for Carrying Out the Invention
[0011] Hereinafter, embodiments specifically disclosing the configuration and operation of the license management method, license management system, and license management program according to the present disclosure will be described in detail with reference to the drawings as appropriate. However, detailed descriptions that are more detailed than necessary may be omitted. For example, detailed descriptions of well-known matters and duplicate descriptions of substantially the same configuration may be omitted. This is to avoid making the following description unnecessarily redundant and to facilitate understanding by those skilled in the art. Note that the accompanying drawings and the following description are provided for those skilled in the art to fully understand the present disclosure, and it is not intended to limit the subject matter described in the claims thereby.
[0012] Referring to FIG. 1, a use case example of the license management system 100 according to the embodiment will be described. FIG. 1 is a diagram showing an example of a use case of the license management system 100 according to the embodiment.
[0013] The license management system 100 manages whether an application is being used properly based on the license of the application used by at least one terminal device P11,..., P21,... and user authentication for using the terminal devices P11,..., P21,.... The license management system 100 includes a management server device AP1, a terminal management server S1, a license issuance device LP1, and at least one terminal device P11,..., P21,.... Note that the license issuance device LP1 is not an essential configuration and may be omitted. Also, the license management system 100 may include an administrative terminal (not shown) used by an administrator and communicably connected to the management server device AP1 or the terminal devices P11,..., P21,.... Here, the administrator refers to a person who manages the license of the application used in the terminal devices P11,..., P21,... or a person who manages the management server device AP1, etc.
[0014] Here, the user authentication method is preferably multi-factor authentication, but is not limited thereto. In the description of this embodiment, as an example, an example of performing user authentication by multi-factor authentication using knowledge information such as the user's ID / PASS and biometric information based on the user's face image will be described. Needless to say, the multi-factor authentication method is not limited to this.
[0015] The management server device AP1 issues a license for using the application to each of the terminal devices P11,... P21,... that use the application, or determines whether the terminal devices P11,... P21,... have a license for using the application at the start of using the application. When the management server device AP1 detects unauthorized use of the application, it notifies (notifies) the administrator who manages the use of the application of the detection of unauthorized use of the application. The management server device AP1 is connected to be able to transmit and receive data to and from the terminal management server S1, the license issuing device LP1, and each of at least one terminal device P11,... P21,... via the network NW.
[0016] Note that the management server device AP1 may be realized by a plurality of computers, that is, two or more management server devices, and the processing executed by the management server device AP1 of the present disclosure may be processed in a shared manner by the plurality of management server devices. For example, when realized by two management server devices, the first management server device may execute license determination processing, and the second management server device may execute biometric information registration processing.
[0017] The terminal management server S1 manages unauthorized use of the terminal devices P11,... P21,... based on the alert notified by the management server device AP1. The terminal management server S1 is connected to be able to transmit and receive data to and from the management server device AP1 via the network NW. The terminal management server S1 may manage history information of unauthorized use based on the alert for each terminal device.
[0018] The license issuing device LP1 issues a license for each of the terminal devices P11, …, P21, … that use the application, for the user who operates each of the terminal devices P11, …, P21, … to use the application. The license issuing device LP1 is connected to be able to transmit and receive data to and from the management server device AP1 via the network NW. Note that the license issuing device LP1 may be omitted when the management server device AP1 executes the license issuing process. In the present embodiment, an example in which the management server device AP1 executes the license issuing process will be described, and hereinafter, the description of the license issuing device LP1 will be omitted.
[0019] The terminal devices P11, … are connected to be able to communicate wired with the management server device AP1 via the network NW and execute data transmission and reception. The terminal devices P21, … are connected to be able to communicate wirelessly with the management server device AP1 via the network NW and execute data transmission and reception. Note that the wireless communication mentioned here is communication provided in accordance with wireless communication standards such as wireless Local Area NetWork (LAN), wireless Wide Area NetWork (WAN), 4G (Fourth Generation Mobile Communication System), 5G (Fifth Generation Mobile Communication System), or Wi-Fi (registered trademark).
[0020] Each of the terminal devices P11, …, P21, … is realized by a Personal Computer (hereinafter referred to as “PC”), a notebook PC, a tablet terminal, a smartphone, or the like. Each of the terminal devices P11, …, P21, … can receive a user operation, is operated by the user, and acquires authentication information used for user authentication. In addition, each of the terminal devices P11, …, P21, … acquires biometric information of the user (for example, a face image, fingerprint, palmprint, vein, or iris) using a camera or sensor built in or externally attached to the device itself.
[0021] Each of the terminal devices P11, …, P21, … includes a communication unit (not shown), a processor (not shown), a memory (not shown), and a display P11D. Each of the terminal devices P11, …, P21, … has an application P11A, an authentication application P11B, and a non-authentication application P11C installed therein, which are executed by a processor (not shown).
[0022] The application P11A is an application managed by the management server device AP1. The application P11A is activated for use by the user when the user is authenticated as a legitimate user through user authentication executed by the authentication application P11B. The application P11A is not activated for use as unavailable when the user is authenticated as an unauthorized user through user authentication executed by the authentication application P11B or the non-authentication application P11C.
[0023] The authentication application P11B registers authentication information of legitimate users and executes user authentication of legitimate users.
[0024] The non-authentication application P11C registers authentication information of unauthorized users and executes user authentication of unauthorized users.
[0025] In this embodiment, for the sake of easy understanding, the application (authentication application P11B) used for registering authentication information of legitimate users and the dummy application (non-authentication application P11C) used for registering authentication information of unauthorized users are shown as different applications. However, these applications may be realized by one application, or may be realized as one or more functions included in the application P11A.
[0026] The display P11D is configured using, for example, a Liquid Crystal Display (hereinafter referred to as "LCD") or an organic Electroluminescence (hereinafter referred to as "EL"). The display P11D displays various screens (see FIG. 8) for registering user authentication information or various screens (see FIG. 10) for authenticating the user, etc.
[0027] The network NW is connected so as to enable data communication between the management server device AP1, the terminal management server S1, the license issuing device LP1, and at least one terminal device P11,... P21,.... Note that the network NW may be an open network or a closed network.
[0028] Next, with reference to FIG. 2, the management server device AP1 will be described. FIG. 2 is a diagram showing an example of the internal structure of the management server device AP1 in the embodiment.
[0029] Note that in FIG. 2, as an example, an example of the internal configuration of the management server device AP1 is shown, but it is not limited thereto. For example, when each of the terminal devices P11,... P21,... can execute the same processing as the management server device AP1, each of the terminal devices P11,... P21,... may include the authentication application 11A shown in FIG. 2 and may be configured to be able to realize various processes executed by the management server device AP1 described hereinafter. Further, when various processes executed by the management server device AP1 of the present disclosure are shared and executed by the management server device AP1 and the terminal device in which the application P11A is used, among the functional blocks in the authentication application 11A, the functional block corresponding to the process executed by the management server device AP1 and the functional block corresponding to the process executed by the terminal device in which the application P11A is used may be included in each device.
[0030] The management server device AP1 includes a communication unit 10, a processor 11, a memory 12, and an output unit 13. Note that the output unit 13 may be realized by a display or the like communicably connected to the management server device AP1.
[0031] The communication unit 10 executes data transmission and reception with the terminal management server S1, the license issuing device LP1, and each of at least one terminal device P11, … P21, … via the network NW. The communication unit 10 outputs the data transmitted from each of the terminal management server S1, the license issuing device LP1, or at least one terminal device P11, … P21, … to the processor 11. Further, the communication unit 10 transmits the data output from the processor 11 to each of the terminal management server S1, the license issuing device LP1, or at least one terminal device P11, … P21, …
[0032] The processor 11 is configured using, for example, a Central Processing Unit (CPU) or a Field Programmable Gate Array (FPGA), and performs various processes and controls in cooperation with the memory 12. Specifically, the processor 11 refers to the programs and data held in the memory 12 and executes the programs to realize the functions of the authentication application 11A.
[0033] The authentication application 11A issues and manages licenses for each of the terminal devices P11, … P21, …. Further, the authentication application 11A determines the usability of the application based on the issued license and executes the management of the application. The authentication application 11A includes a license determination unit 111, a license issuance unit 112, a Media Access Control (hereinafter referred to as “MAC”) address acquisition unit 113, an alert determination unit 114, a registration processing unit 115, an ID / PASS verification unit 116, a biometric information verification unit 117, a license database DB1, and a user database DB2.
[0034] The license determination unit 111 determines whether to issue a license permitting the use of the application to the terminal devices P11, …, P21, … based on the license files transmitted from the terminal devices P11, …, P21, …, or determines whether the licenses of the terminal devices P11, …, P21, … are proper licenses (that is, whether the licenses are not being misused). Further, when the license determination unit 111 determines based on the license file that the license has not been issued and the license issuance conditions are satisfied, it causes the license issuance unit 112 to issue a temporary license for the terminal devices P11, …, P21, …
[0035] The license issuance unit 112 issues a temporary license to the terminal devices P11, …, P21, … for which the license has not been issued. The license issuance unit 112 outputs the issued temporary license to the MAC address acquisition unit 113.
[0036] The MAC address acquisition unit 113 acquires the MAC addresses of the terminal devices P11, …, P21, … that are the targets of license issuance. The MAC address acquisition unit 113 issues a license for the terminal devices P11, …, P21, … by rewriting the temporary MAC address included in the temporary license issued by the license issuance unit 112 with the acquired MAC addresses of the terminal devices P11, …, P21, … The MAC address acquisition unit 113 stores the information of the issued license in the license database DB1 for each vendor. The MAC address acquisition unit 113 feeds back the information of the issued license to the license determination unit 111.
[0037] The alert determination unit 114 generates alert information (for example, the alert notification screens SC1, SC2, SC3, etc. shown in FIGS. 11 to 13) to notify the administrator of the detection of unauthorized use of the application or the detection of unauthorized users based on the license determination result output from the license determination unit 111 or the user authentication result. Further, the alert determination unit 114 determines the type (level) of the alert based on the license determination result and the user authentication result, and generates alert information of the corresponding alert type (level). The alert determination unit 114 outputs the generated alert information to the output unit 13.
[0038] Note that the alert information (for example, the alert notification screens SC1, SC2, SC3, etc. shown in FIGS. 11 to 13) may be transmitted to and displayed on a management terminal (not shown) used by the administrator. In such a case, each of the management server device AP1 or the terminal devices P11,..., P21,... is connected so as to be able to transmit and receive data to and from the management terminal (not shown). When it is determined that unauthorized use of the application has been detected by executing the license determination process, alert information is generated and transmitted to the management terminal (not shown) for output.
[0039] The registration processing unit 115 stores and registers biometric information including feature amounts indicating the individuality of the user from the biometric information of the user transmitted from the terminal devices P11,..., P21,... in the user database DB2.
[0040] The ID / PASS verification unit 116 acquires the user ID and PASS (password) transmitted from the terminal devices P11,..., P21,.... The ID / PASS verification unit 16 verifies the acquired user ID and PASS with the ID and PASS stored in the user database DB2 to determine whether the user ID and PASS match the ID and PASS registered in the user database DB2.
[0041] The biometric information verification unit 117 acquires the biometric information of the user transmitted from the terminal devices P11,... P21,.... The biometric information verification unit 117 verifies the acquired biometric information of the user with the biometric information stored in the user database DB2 to determine whether the biometric information of the user is a legitimate user registered in the user database DB2. The biometric information verification unit 117 transmits the result of the biometric authentication to the corresponding terminal devices P11,... P21,....
[0042] The license database DB1 is a so-called storage, which is configured using a storage medium such as a flash memory, a Hard Disk Drive (hereinafter referred to as "HDD"), or a Solid State Drive (hereinafter referred to as "SSD"). The license database DB1 stores the licenses issued to each of the terminal devices P11,... P21,.... Note that the license database DB1 may be a database configured integrally with the user database DB2. In such a case, the information on the licenses issued to each terminal device may be stored in association with the authentication information of the users registered in each terminal device.
[0043] The user database DB2 is a so-called storage, which is configured using a storage medium such as a flash memory, an HDD, or an SSD. The user database DB2 stores, for each user, the user's ID and PASS and the biometric information in association with each other as the authentication information of the user.
[0044] The memory 12 has, for example, a Random Access Memory (RAM) as a work memory used when each process of the processor 11 is executed, and a Read Only Memory (ROM) that stores the programs and data defining the operation of the processor 11. In the RAM, the data or information generated or acquired by the processor 11 is temporarily stored. In the ROM, the program defining the operation of the processor 11 is written.
[0045] The output unit 13 is configured using, for example, a Liquid Crystal Display (LCD) or an organic Electroluminescence (EL). The output unit 13 outputs the alert notification screens SC1, SC2, and SC3 (see FIGS. 11 to 13) output from the alert determination unit 114.
[0046] Next, with reference to FIG. 3, the license will be described. FIG. 3 is a diagram showing an example of the license database DB1. Note that the license shown in FIG. 3 is an example and is not limited thereto. For example, the file name shown in FIG. 3 is generated including information such as the vendor name, the subject name, and the maximum number of licenses that can be issued, but it goes without saying that it is not limited to this.
[0047] A license is a so-called license file and includes, for example, a file name, an extension, and file contents. The file name includes information such as the vendor name, the subject name, and the maximum number of licenses, which is the maximum number of licenses that can be issued. The file contents include information such as the MAC address of the terminal device, the expiration date of the license, and the license number, which is the issue number of the license. Note that the MAC address may be any information that can identify the terminal device. For example, when the terminal device is realized by a smartphone, the information of the MAC address may be replaced with information such as the device unique number of the smartphone.
[0048] In Use Example 1, the vendor (user) “AAAA” for which the license is to be issued has the subject name “BBBBBB” set, the expiration date is “July 31, 2024”, and the number of licenses that can be issued is set to “300”.
[0049] The license issuance unit 112 issues a temporary license to a vendor (user) with a vendor name of "AAAA" and a subject of "BBBBBB", including a file name of "AAAA-BBBBBB-300.lic" and a file content of "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ, July 31, 2024, lic=1". Here, the file content included in the temporary license includes the temporarily issued MAC address "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ", the expiration date "July 31, 2024", and the current license issuance count "lic=1" for the vendor name "AAAA". Note that the current license issuance count includes the temporarily issued license.
[0050] The MAC address acquisition unit 113 acquires the MAC address "B8:9A:2A:56:DE:DE" of the terminal device for which the license is to be issued. Based on the acquired MAC address, the MAC address acquisition unit 113 rewrites the temporary MAC address "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ" in the file content "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ, July 31, 2024, lic=1" of the temporarily issued license with the acquired MAC address "B8:9A:2A:56:DE:DE". The MAC address acquisition unit 113 stores the license after the MAC address rewrite in the license database DB1 as a regular license corresponding to the terminal device. Also, the MAC address acquisition unit 113 outputs the generated license to the license determination unit 111.
[0051] In Use Case 2, the vendor (user) "CCCC" for which the license is to be issued has a subject of "DDDDDD" set, an expiration date of unlimited ("YYYY / MM / DD"), and the number of licenses that can be issued is set to unlimited ("ZZZZ").
[0052] The license issuing unit 112 issues a temporary license including the file name "CCCC-DDDDDD-ZZZZ.lic" and the file content "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ, YYYY / MM / DD, lic=ZZZZ" to the vendor (user) with the vendor name "CCCC" and the subject "DDDDDD". Here, the file content included in the temporary license includes the temporarily issued MAC address "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ", the expiration date "YYYY / MM / DD", and the current license issuance limit number "lic=ZZZZ" for the vendor name "ZZZZ".
[0053] The MAC address acquisition unit 113 acquires the MAC address "B8:9A:2A:56:DE:DE" of the terminal device to which the license is to be issued. Based on the acquired MAC address, the MAC address acquisition unit 113 rewrites the temporary MAC address "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ" in the file content "mac=ZZ:ZZ:ZZ:ZZ:ZZ:ZZ, YYYY / MM / DD, lic=ZZZZ" of the temporarily issued license to the acquired MAC address "B8:9A:2A:56:DE:DE". The MAC address acquisition unit 113 stores the license after the MAC address rewrite in the license database DB1 as a proper license corresponding to the terminal device. Also, the MAC address acquisition unit 113 outputs the generated license to the license determination unit 111.
[0054] As described above, the authentication application 11A can manage the license issuance to the terminal device by issuing a temporary license including a temporary MAC address to the terminal device with an unissued license, acquiring the MAC address of the terminal device, and then issuing a proper license including the MAC address of this terminal device.
[0055] Next, with reference to FIG. 4, various data used for user authentication will be described. FIG. 4 is a diagram showing an example of a user database DB2. In the present embodiment, as an example, for the purpose of performing multi-factor authentication using an ID / PASS (password) assigned to each user and the biometric information of the user, an example of storing the ID / PASS (password) and the biometric information of the user will be described.
[0056] The user database DB2 stores, for each user, authentication information for authenticating whether a user who uses an application is a legitimate user who has been registered in advance, which is a plurality of pieces of authentication information used for multi-factor authentication.
[0057] For example, the user database DB2 stores the ID "ABC001", the password "8687", and the biometric information "feature quantity 1" as the authentication information of the first user, stores the ID "ABC002", the password "123", and the biometric information "feature quantity 2" as the authentication information of the second user, and stores the ID "ABC003", the password "456", and the biometric information "feature quantity 3" as the authentication information of the third user.
[0058] Next, with reference to FIGS. 5 and 6 respectively, a license management method by the management server device AP1 will be described. FIG. 5 is a flowchart showing an example of the license management procedure of the management server device AP1 in the embodiment. FIG. 6 is a flowchart showing an example of the license determination procedure of the management server device AP1 in the embodiment.
[0059] Here, for the sake of easy understanding, the license management method of the terminal device P11 when the terminal device P11 uses the application P11A will be specifically described, but the same applies to other terminal devices. Also, here, as an example, an example in which the biometric information is the feature quantity of the user's face will be described.
[0060] The terminal device P11 reads and obtains a license file from the application P11A when the application P11A is started. The terminal device P11 transmits the information of the license file to the management server device AP1.
[0061] The license determination unit 111 of the management server device AP1 obtains the license file transmitted from the terminal device P11, and obtains the lic file as the extension from the license file (St11). The license determination unit 111 determines whether there is one license file included in the specified folder (St12). Note that the license file obtained here may be encrypted.
[0062] When the license determination unit 111 determines in the process of step St12 that there is one license file included in the specified folder (St12, YES), the license determination unit 111 decrypts the license file name from the license file (St13).
[0063] On the other hand, when the license determination unit 111 determines in the process of step St12 that there is not one license file included in the specified folder (St12, NO), the license determination unit 111 determines that it is the activation of the application P11A by an unauthorized user, and does not permit the terminal device P11 to use the authentication application P11B for obtaining the biometric information of the user used for the authentication of the license of the application P11A. The license determination unit 111 transmits the non - permission to use the authentication application P11B to the terminal device P11.
[0064] When the terminal device P11 obtains the non - permission to use the authentication application P11B by the management server device AP1, the terminal device P11 starts a non - authentication application P11C, which is a dummy authentication application not used for the authentication of the license of the application P11A, and captures the user's face. The terminal device P11 extracts the feature amount of the user's face from the captured face image of the user, and transmits the extracted feature amount of the user's face as biometric information to the management server device AP1.
[0065] The registration processing unit 115 acquires the biometric information transmitted from the terminal device P11 and stores it in the user database DB2 as biometric information of an unauthorized user. After storing it in the user database DB2, the registration processing unit 115 generates a registration result of the biometric information indicating that the registration of the biometric information has been completed, and transmits it to the terminal device P11 for output (St35). The terminal device P11 generates a registration result screen SC13B (see FIG. 8) based on the registration result of the biometric information transmitted from the management server device AP1, and displays (outputs) it on the display P11D. Note that the registration of the biometric information of an unauthorized user is not essential and may be omitted.
[0066] The registration processing unit 115 outputs an alert indicating that unauthorized use of the application P11A by an unauthorized user has been detected to the license determination unit 111. The license determination unit 111 outputs a control command requesting alert notification to the alert determination unit 114. Based on the control command, the alert determination unit 114 generates an alert notifying the administrator that there has been registration of authentication information by an unauthorized user, outputs it to the output unit 13, and executes alert notification (St36). The license determination unit 111 determines that the license has been used unauthorizedly, and obtains a determination result indicating that unauthorized use of the application P11A has been detected (St14).
[0067] The license determination unit 111 refers to the license database DB1 and determines whether the decrypted license file satisfies all four conditions (St15). The four conditions mentioned here are conditions for determining whether the license has been issued. The license determination unit 111 refers to the license database DB1 and checks whether the decrypted license file satisfies the first condition that it contains the correct MAC address, the second condition that the expiration date of the decrypted license file is within the expiration period, the third condition that the license No (i.e., the number of licenses) contained in the decrypted license file does not exceed the maximum number of licenses, and the fourth condition that the license No contained in the decrypted license file is appropriate.
[0068] In step St15, when the license determination unit 111 determines that the decrypted license file satisfies all four conditions and the MAC address is a temporary MAC address that has been temporarily issued (St15, YES1), it determines that the license has not been issued, enables the issuance of a license to the terminal device P11 that is the source of the license file, and causes the license issuance unit 112 to issue a temporary license (St16).
[0069] The MAC address acquisition unit 113 acquires the MAC address of the terminal device P11 from the terminal device P11 on which the application P11A is operating (St17). The MAC address acquisition unit 113 writes the acquired MAC address to the temporarily issued license file, issues a license for the terminal device P11 (St18). The MAC address acquisition unit 113 updates the license registered in the license database DB1 to the license after writing the MAC address, and ends the license issuance (St19).
[0070] Also, in step St15, when the license determination unit 111 determines that the decrypted license file satisfies all four conditions and the MAC address is not a temporary MAC address that has been temporarily issued (St15, YES2), it executes a license determination process to determine whether the license has been properly issued (St20).
[0071] On the other hand, in step St15, when the license determination unit 111 determines that the decrypted license file does not satisfy all four conditions, that is, when it determines that the decrypted license file does not satisfy at least one of the above four conditions (St15, NO), it determines that the license is being misused and obtains a determination result indicating that the unauthorized use of the application P11A has been detected (St14).
[0072] Here, in the process of step St15, an example of the determination of satisfaction of the first condition will be described, where it is determined that the decoded license file does not satisfy all four conditions (St15, NO).
[0073] For example, when the acquired MAC address is "ZZ:ZZ:ZZ:ZZ:ZZ:11", "YY:YY:YY:YY:YY:YY", etc., the license determination unit 111 determines whether the acquired MAC address is a MAC address registered in the license database DB1 and whether the acquired MAC address matches the temporary MAC address "ZZ:ZZ:ZZ:ZZ:ZZ:ZZ" issued by the license issuing unit 112. If the license determination unit 111 determines that the acquired MAC address is not a MAC address registered in the license database DB1 and does not match the temporary MAC address "ZZ:ZZ:ZZ:ZZ:ZZ:ZZ", it determines that the license is being used illegally and that the license is invalid.
[0074] Also, for example, the license determination unit 111 determines whether the characters, numbers, or symbols used in the acquired MAC address are the same as those used in the MAC address issued by the license issuing unit 112. When the MAC address issued by the license issuing unit 112 is composed of the numbers "0" to "9" and the alphabets "A" to "F", and the acquired MAC address is "YY:11:YY:YY:YY:YY", "11:22:33:44:55:YY", etc., the license determination unit 111 determines that the acquired MAC address is not the MAC issued by the license issuing unit 112. If the license determination unit 111 determines that the acquired MAC address is not the MAC issued by the license issuing unit 112, it determines that the license is being used illegally, that is, the license is invalid.
[0075] Subsequently, the license determination process (step St20) will be described.
[0076] The license determination unit 111 acquires the MAC address of the terminal device P11 from the terminal device P11 on which the application P11A is operating (St21). The license determination unit 111 writes the acquired MAC address to the license file (St22), and determines whether the acquired MAC address matches the MAC address of the license file that has been registered, that is, issued, in the license database DB1 (St23).
[0077] In the process of step St23, if the license determination unit 111 determines that the acquired MAC address matches the MAC address of the issued license file (St23, YES), it acquires the current date and time information from the terminal device P11 on which the software is operating (St24).
[0078] On the other hand, in the process of step St23, if the license determination unit 111 determines that the acquired MAC address does not match the MAC address of the issued license file (St23, NO), it determines that the license is being misused, and obtains a determination result indicating that the unauthorized use of the application P11A has been detected (St25).
[0079] The license determination unit 111 determines whether the acquired current date and time information is within the expiration date of the license file (St26).
[0080] In the process of step St26, if the license determination unit 111 determines that the acquired current date and time information is within the expiration date of the license file (St26, YES), it determines that the license is being properly used, and obtains a determination result indicating that the proper use of the application P11A has been detected (St27).
[0081] On the other hand, in the process of step St26, if the license determination unit 111 determines that the acquired current date and time information is not within the expiration date of the license file (St26, NO), it determines that the license is being misused, and obtains a determination result indicating that unauthorized use of the application P11A has been detected (St25). Note that when the license determination unit 111 determines that the acquired MAC address matches the MAC address of the issued license file and that it is proper outside the expiration date, it may generate a message prompting license update, transmit it to the terminal device P11, and output (display) it.
[0082] As described above, the management server device AP1 in the embodiment can more accurately determine whether the application P11A is being used properly, that is, whether the application P11A has been obtained and used illegally.
[0083] Next, with reference to FIG. 7, the registration process of the user's authentication information will be described. FIG. 7 is a flowchart for explaining an example of the user registration procedure of the management server device AP1 in the embodiment. In FIG. 7, for the sake of easy understanding of the explanation, an example of registering the feature amount of the user's face extracted from the user's face image as biometric information will be described. Also, for the sake of easy understanding of the explanation, the license management method of the terminal device P11 when the terminal device P11 uses the application P11A will be specifically described here, but the same applies to other terminal devices.
[0084] The license determination unit 111 executes the license determination process (step St20) and determines whether the license has been issued and whether the issued license is a proper license use (St31).
[0085] When the license determination unit 111 determines that the license has been issued and the issued license is an appropriate license use (St31, YES), it permits the use of the authentication application P11B for acquiring the user's authentication information on the terminal device P11 (St32). The license determination unit 111 transmits the permission to use the authentication application P11B to the terminal device P11.
[0086] When the terminal device P11 acquires the permission to use the authentication application P11B by the management server device AP1, it activates the regular authentication application P11B and captures the user's face. The terminal device P11 extracts the feature amount of the user's face from the captured face image of the user, and transmits the extracted feature amount of the user's face to the management server device AP1 as biometric information.
[0087] The registration processing unit 115 acquires the biometric information transmitted from the terminal device P11, and stores it in the user database DB2 as the biometric information of the regular user. After storing it in the user database DB2, the registration processing unit 115 generates a registration result of the biometric information indicating that the registration of the biometric information has been completed, and transmits it to the terminal device P11 for output (St33). The terminal device P11 generates a registration result screen SC13A (see FIG. 8) based on the registration result of the biometric information transmitted from the management server device AP1, and displays (outputs) it on the display P11D.
[0088] On the other hand, when the license determination unit 111 determines that the license has been issued and the issued license is not an appropriate license use (St31, NO), it does not permit the use of the authentication application P11B for acquiring the user's biometric information used for authenticating the license of the application P11A on the terminal device P11 (St34). The license determination unit 111 transmits the non - permission to use the authentication application P11B to the terminal device P11.
[0089] When the terminal device P11 obtains the non - permission to use the authentication application P11B by the management server device AP1, it starts a non - authentication application P11C, which is a dummy authentication application that is not used for the license authentication of the application P11A, and captures the user's face. The terminal device P11 extracts the feature amount of the user's face from the captured user face image, and transmits the extracted feature amount of the user's face as biometric information to the management server device AP1.
[0090] The registration processing unit 115 acquires the biometric information transmitted from the terminal device P11 and stores it in the user database DB2 as the biometric information of an unauthorized user. After storing it in the user database DB2, the registration processing unit 115 generates a registration result of the biometric information indicating that the registration of the biometric information is completed, and transmits it to the terminal device P11 for output (St35). The terminal device P11 generates a registration result screen SC13B (see FIG. 8) based on the registration result of the biometric information transmitted from the management server device AP1 and displays (outputs) it on the display P11D. Note that the registration of the biometric information of an unauthorized user is not essential and may be omitted.
[0091] The registration processing unit 115 outputs an alert indicating that unauthorized use of the application P11A by an unauthorized user has been detected to the license determination unit 111. The license determination unit 111 outputs a control command requesting alert notification to the alert determination unit 114. Based on the control command, the alert determination unit 114 generates an alert notifying the administrator that there has been registration of authentication information by an unauthorized user, outputs it to the output unit 13, and executes alert notification (St36).
[0092] As a result, when the license management system 100 according to the embodiment detects unauthorized use of the application P11A, by starting the dummy unauthenticated application P11C instead of the regular authentication application P11B, it is possible to prevent the biometric information (authentication information) of an unauthorized user attempting to pose as a regular user from being registered as the biometric information of the regular user. Therefore, the license management system 100 can more effectively prevent impersonation by unauthorized users and can perform license management of the application P11A with higher precision.
[0093] Also, when the license management system 100 according to the embodiment detects unauthorized use of the application P11A, by accepting the registration process of the biometric information (authentication information) of the unauthorized user in the dummy unauthenticated application P11C, the license of this application P11A can be managed as an illegally registered license. Therefore, the license management system 100 can detect unauthorized use of the application P11A with higher precision.
[0094] Next, with reference to FIG. 8, an example of screen transition of various screens displayed on the terminal device at the time of registering the user's authentication information will be described. FIG. 8 is a diagram for explaining an example of screen transition at the time of user registration. In FIG. 8, for the sake of easy understanding of the explanation, an example of registering the feature amount of the user's face extracted from the user's face image as biometric information will be described. Also, here, for the sake of easy understanding of the explanation, the license management method of the terminal device P11 when the terminal device P11 uses the application P11A will be specifically described, but the same applies to other terminal devices.
[0095] First, an example of screen transition of various screens when using the regular authentication application P11B will be described.
[0096] When the terminal device P11 obtains permission to use the regular authentication application P11B from the management server device AP1, it starts the authentication application P11B and displays a registration screen SC11A that accepts the input of the user ID and password (PW) registered as the user's authentication information. The terminal device P11 transmits the input user ID and password (PW) to the management server device AP1.
[0097] In the example shown in FIG. 8, when the terminal device P11 accepts the input of the user ID "XXX" and the user password (PW) "○○○○" on the registration screen SC11A and the login button BT11A on the registration screen SC11A is pressed (selected) by the user operation, the user ID "XXX" and the user password (PW) "○○○○" are transmitted to the management server device AP1.
[0098] When the login button BT11A on the registration screen SC11A is pressed (selected) by the user operation, the terminal device P11 displays a registration screen SC12A that accepts the input of the user's biometric information registered as the user's authentication information. The terminal device P11 extracts the feature amount of the user's face from the face image obtained by imaging the user's face and transmits it to the management server device AP1.
[0099] In the example shown in FIG. 8, after imaging the user's face, the terminal device P11 displays a registration screen SC12A including the user's face image F11 for obtaining (extracting) the user's biometric information. When the login button BT11A on the registration screen SC12A is pressed (selected), the terminal device P11 extracts the feature amount from the user's face image F11 and transmits it to the management server device AP1.
[0100] When the registration button BT12A on the registration screen SC12A is pressed (selected) by the user operation and the terminal device P11 obtains the registration result from the management server device AP1, it generates a registration result screen SC13A notifying the completion of the registration of the user's authentication information and displays (outputs) it on the display P11D.
[0101] Next, a description will be given of screen transition examples of various screens when using a non-authentication application P11C that is a dummy of the authentication application P11B.
[0102] When the terminal device P11 cannot obtain permission to use the regular authentication application P11B from the management server device AP1, it starts the non-authentication application P11C and displays a dummy registration screen SC11B that accepts input of the ID and password (PW) of an unauthorized user registered as the user's authentication information. The terminal device P11 transmits the input ID and password (PW) of the unauthorized user to the management server device AP1.
[0103] In the example shown in FIG. 8, when the terminal device P11 accepts input of the ID "XXX" of the unauthorized user and the password (PW) "○○○○" of the unauthorized user on the registration screen SC11B, and the login button BT11B on the registration screen SC11B is pressed (selected) by a user operation, the ID "XXX" of the unauthorized user and the password (PW) "○○○○" of the unauthorized user are transmitted to the management server device AP1.
[0104] When the login button BT11B on the registration screen SC11B is pressed (selected) by a user operation, the terminal device P11 displays a dummy registration screen SC12B that accepts input of the biometric information of the unauthorized user registered as the user's authentication information. The terminal device P11 extracts the feature amount of the face of the unauthorized user from the face image obtained by imaging the face of the unauthorized user and transmits it to the management server device AP1.
[0105] In the example shown in FIG. 8, after imaging the face of the unauthorized user, the terminal device P11 displays a dummy registration screen SC12B including the face image F11 of the user for obtaining (extracting) the biometric information of the unauthorized user. When the login button BT11B on the registration screen SC12B is pressed (selected), the terminal device P11 extracts the feature amount from the face image F12 of the unauthorized user and transmits it to the management server device AP1.
[0106] When the registration button BT12B on the registration screen SC12B is pressed (selected) by a user operation and the terminal device P11 obtains a registration result from the management server device AP1, the terminal device P11 generates a registration result screen SC13B that notifies the completion of registration of the authentication information of an unauthorized user, and displays (outputs) it on the display P11D.
[0107] As described above, even when the license management system 100 according to the embodiment determines that the application P11A is being used illegally, it can register the authentication information of the unauthorized user who is attempting to use the application P11A illegally. Therefore, subsequent illegal use of the application P11A can be detected with higher accuracy.
[0108] Also, even when the license management system 100 according to the embodiment determines that the application P11A is being used illegally, by making the various screens displayed when registering the authentication information of an unauthorized user by the unauthenticated application P11C and when registering the authentication information of an authorized user by the authenticated application P11B the same, the license management system 100 can prevent an unauthorized user who attempts to use the application P11A illegally from knowing that the management server device AP1 has detected the illegal use of the application P11A. As a result, the license management system 100 according to the embodiment can detect illegal use of the application P11A by an unauthorized user with higher accuracy and more effectively.
[0109] Next, with reference to FIG. 9, user authentication processing will be described. FIG. 9 is a flowchart for explaining an example of a user authentication procedure of the management server device AP1 in the embodiment. Note that in FIG. 9, for the sake of easy understanding, an example of authenticating a user by multi-factor authentication using the user's ID / PASS and the user's face authentication will be described. Also, for the sake of easy understanding, the license management method of the terminal device P11 when the terminal device P11 uses the application P11A will be specifically described here, but the same applies to other terminal devices.
[0110] The license determination unit 111 executes license determination processing (step St20) and determines whether the license has been issued and whether the issued license is an appropriate license use (St41).
[0111] When the license determination unit 111 determines that the license has been issued and the issued license is an appropriate license use (St41, YES), it permits the use of the authentication application P11B for authenticating the user on the terminal device P11 (St42). The license determination unit 111 transmits the permission to use the authentication application P11B to the terminal device P11.
[0112] When the terminal device P11 obtains the permission to use the authentication application P11B from the management server device AP1, it starts the regular authentication application P11B, obtains the user's authentication information, and transmits it to the management server device AP1.
[0113] The registration processing unit 115 obtains the biometric information transmitted from the terminal device P11. The registration processing unit 115 compares the obtained (input) biometric information with the biometric information of the user registered in the user database DB2 to perform biometric authentication (St43), generates an authentication screen SC21A (see FIG. 10) including the biometric authentication result, and displays (outputs) it on the display P11D (St44).
[0114] On the other hand, when the license determination unit 111 determines that the license has been issued and the issued license is not an appropriate license use (St41, NO), it does not permit the use of the authentication application P11B for obtaining the biometric information of the user used for authenticating the license of the application P11A on the terminal device P11 (St45). The license determination unit 111 transmits the non - permission to use the authentication application P11B to the terminal device P11.
[0115] When the terminal device P11 obtains the non - permission to use the authentication application P11B by the management server device AP1, it starts a non - authentication application P11C, which is a dummy authentication application and not used for the license authentication of the application P11A, to obtain the user's authentication information. The terminal device P11 transmits the obtained user's authentication information to the management server device AP1.
[0116] The registration processing unit 115 acquires the biometric information transmitted from the terminal device P11. The registration processing unit 115 compares the acquired (input) biometric information with the biometric information of the user registered in the user database DB2 to perform biometric authentication (St46), generates an authentication screen SC21B (see FIG. 10) including the biometric authentication result, and displays (outputs) it on the display P11D (St47).
[0117] The registration processing unit 115 outputs an alert indicating that unauthorized use of the application P11A by an unauthorized user has been detected to the license determination unit 111. The license determination unit 111 outputs a control command requesting alert notification to the alert determination unit 114. The alert determination unit 114 generates an alert notifying the administrator that there has been an authentication process by an unauthorized user based on the control command, outputs it to the output unit 13, and executes alert notification (St48).
[0118] Here, when the alert determination unit 114 determines that the user is a user registered as a legitimate user of another terminal device through user authentication, it notifies an alert with the type (level) of the alert lowered by one level, and generates an alert including an instruction to request the installation of the application P11A in a legitimate manner, transmits it to the terminal device P11, and outputs (displays) it.
[0119] As a result, when the license management system 100 according to the embodiment detects unauthorized use of the application P11A, by starting the dummy unauthenticated application P11C instead of the regular authentication application P11B, it is possible to more effectively prevent an unauthorized user who attempts to pose as a legitimate user from being authenticated using the biometric information (authentication information) of the unauthorized user. Therefore, the license management system 100 can more effectively prevent impersonation by unauthorized users and execute license management of the application P11A with higher precision.
[0120] In addition, when the license management system 100 according to the embodiment detects unauthorized use of the application P11A, it can prevent unauthorized use of the application P11A by accepting the authentication process of the biometric information (authentication information) of the unauthorized user with the dummy unauthenticated application P11C.
[0121] Next, with reference to FIG. 10, an example of screen transition of various screens displayed on the terminal device at the time of user authentication will be described. FIG. 10 is a diagram for explaining an example of screen transition at the time of user authentication. In FIG. 10, for the sake of easy understanding of the explanation, an example of performing biometric authentication using the feature amount of the user's face extracted from the user's face image will be described. Also, here, for the sake of easy understanding of the explanation, the license management method of the terminal device P11 when the terminal device P11 uses the application P11A will be specifically described, but the same applies to other terminal devices.
[0122] First, an example of screen transition of various screens when using the regular authentication application P11B will be described.
[0123] When the terminal device P11 obtains permission to use the regular authentication application P11B from the management server device AP1, it starts the authentication application P11B and displays an authentication screen SC21A that accepts the input of the user's ID and password (PW) as the user's authentication information. The terminal device P11 transmits the input user ID and password (PW) to the management server device AP1.
[0124] In the example shown in FIG. 10, when the terminal device P11 accepts the input of the user ID "XXX" and the user password (PW) "○○○○" on the authentication screen SC21A and the login button BT21A on the authentication screen SC21A is pressed (selected) by the user operation, the user ID "XXX" and the user password (PW) "○○○○" are transmitted to the management server device AP1.
[0125] When the login button BT21A on the authentication screen SC21A is pressed (selected) by the user operation, the terminal device P11 extracts the feature amount of the user's face from the face image obtained by imaging the user's face as the user's authentication information and transmits it to the management server device AP1. When the terminal device P11 obtains the authentication result from the management server device AP1, it generates an authentication result screen SC22A that notifies the result of user authentication and displays (outputs) it on the display P11D.
[0126] In the example shown in FIG. 10, the terminal device P11 displays an authentication result screen SC22A including the authentication result "Authentication OK" transmitted from the management server device AP1 and the user's face image F21 used for user authentication.
[0127] Next, an example of screen transition of various screens when using the non-authentication application P11C will be described.
[0128] When the terminal device P11 fails to obtain permission to use the regular authentication application P11B from the management server device AP1, it activates the non-authentication application P11C and displays an authentication screen SC21B that accepts the input of the ID and password (PW) of the unauthorized user as the authentication information of the unauthorized user. The terminal device P11 transmits the input ID and password (PW) of the unauthorized user to the management server device AP1.
[0129] In the example shown in FIG. 10, when the terminal device P11 accepts the input of the ID "XXX" of the unauthorized user and the password (PW) "○○○○" of the unauthorized user on the authentication screen SC21B, and the login button BT21B on the authentication screen SC21B is pressed (selected) by a user operation, the terminal device P11 transmits the ID "XXX" of the unauthorized user and the password (PW) "○○○○" of the unauthorized user to the management server device AP1.
[0130] When the login button BT21B on the authentication screen SC21B is pressed (selected) by a user operation, the terminal device P11 extracts the feature amount of the face of the unauthorized user from the face image obtained by capturing the user's face as the user's authentication information and transmits it to the management server device AP1. When the terminal device P11 obtains the authentication result from the management server device AP1, it generates an authentication result screen SC22B that notifies the result of user authentication and displays (outputs) it on the display P11D.
[0131] In the example shown in FIG. 10, the terminal device P11 displays an authentication result screen SC22B that includes the authentication result "Authentication OK" transmitted from the management server device AP1 and the face image F22 of the unauthorized user used for user authentication.
[0132] As described above, even when it is determined that the application P11A is being misused, the license management system 100 according to the embodiment makes the various screens displayed when an unauthorized user is authenticated by the unauthorized application P11C and when a legitimate user is authenticated by the authorized application P11B the same, so that unauthorized users who attempt to misuse the application P11A are not made aware that the management server device AP1 has detected the unauthorized use of the application P11A. As a result, the license management system 100 according to the embodiment can detect unauthorized use of the application P11A by unauthorized users with higher accuracy and more effectively.
[0133] Next, with reference to FIGS. 11 to 13, an alert notification method will be described. FIG. 11 is a diagram for explaining an example of the alert notification screen SC1. FIG. 12 is a diagram for explaining an example of the alert notification screen SC2. FIG. 13 is a diagram for explaining an example of the alert notification screen SC3. It goes without saying that the alert notification screens SC1 to SC3 are merely examples and are not limited thereto. The alert information described hereinafter may be transmitted to and displayed on a management terminal (not shown) used by the administrator as well as the management server device AP1.
[0134] The alert notification screens SC1 to SC3 are generated by the alert determination unit 114 and output to the output unit 13 and displayed when the license determination unit 111 detects unauthorized use of the application P11A.
[0135] The alert notification screen SC1 shown in FIG. 11 includes PC icons corresponding to each of the 15 terminal devices registered with the same vendor name and a pop-up PU1. On the alert notification screen SC1, the PC icon ART1 corresponding to the terminal device in which unauthorized use has been detected among these 15 PC icons is highlighted in a predetermined color. The pop-up PU1 includes an unauthorized use detection message Msg1 including a message "Improper use event detected" indicating that unauthorized use of the license has been detected, information "Terminal: 001" of the terminal device in which unauthorized use of the license has been detected, and the user ID "ID: 0001" of the user using this terminal device.
[0136] When the confirmation button BT1 of the PC icon ART1 or the pop-up PU1 is pressed (selected) by a user operation (cursor CSR) on the alert notification screen SC1, the management server device AP1 acquires the history information of the license determination result executed on the terminal device in which unauthorized use has been detected and recorded in the terminal management server S1. The management server device AP1 generates and displays an alert notification screen SC2 based on the acquired history information of the license determination result.
[0137] The alert notification screen SC2 shown in FIG. 12 includes a history table TB21 that visualizes the history information of the license determination result executed on the terminal device in which unauthorized use has been detected. The history table TB21 includes, for example, date and time information when the license determination process was executed, event information indicating the authentication result, classification information indicating the classification of the user, or information such as the user ID of the user who manages this terminal management.
[0138] When a region ART21 in which predetermined history information is displayed is pressed (selected) by a user operation (cursor CSR) on the alert notification screen SC2, the management server device AP1 generates a history table TB31 that visualizes the face image of the user who attempted user authentication based on the history information of the license determination result executed on the terminal device in which unauthorized use has been detected, and generates and displays an alert notification screen SC3 including the generated history table TB31.
[0139] In addition, the management server device AP1 analyzes the face images IMG12 and IMG13 of unauthorized users who have misused the terminal device corresponding to "Terminal: 001", and executes the identification process of unauthorized users. The management server device AP1 counts the license determination processes executed by unauthorized users determined to be the same person through the identification process, that is, the number of registrations or authentications of the user's authentication information. Based on the number of times of the license determination process executed by the counted unauthorized users, the management server device AP1 determines the type (level) of the alert corresponding to this terminal device, or determines the main unauthorized user and the secondary unauthorized user among the unauthorized users who misuse this terminal device.
[0140] The management server device AP1 estimates the unauthorized user with the largest number of license determination processes executed by unauthorized users (the unauthorized user corresponding to the face image IMG13) as the main unauthorized user, and highlights each face image IMG13 of this unauthorized user with a frame line. In addition, the management server device AP1 estimates unauthorized users other than the main unauthorized user (the unauthorized user corresponding to the face image IMG12) as secondary unauthorized users, and highlights each face image IMG12 of this unauthorized user with a frame line. Note that in FIG. 13, an example is shown where the frame lines of the face images IMG12 and IMG13 are the same, but in order to distinguish between the main unauthorized user and the secondary unauthorized user, the line type, color, or line thickness of the frame line may be arbitrarily changed.
[0141] The alert notification screen SC3 shown in FIG. 13 includes a history table TB31. The history table TB31 visualizes the face images of users arranged based on the date and time information when user authentication was executed. The face images shown in the history table TB31 shown in FIG. 13 indicate that the face image IMG11 is the face image of a legitimate user, and the face images IMG12 and IMG13 are the face images of unauthorized users, respectively. In addition, the history table TB31 superimposes frame lines on the face images IMG12 and IMG13, visualizing that the users of the face images IMG12 and IMG13 are unauthorized users, respectively.
[0142] As a result, the license management system 100 according to the embodiment can visualize for the administrator which terminal device has detected unauthorized use of the application P11A or the license by generating and outputting the alert notification screens SC1 to SC3.
[0143] In addition, the license management system 100 according to the embodiment can support the management and prevention of unauthorized use by visualizing the history information regarding the use of the application P11A or the license for each terminal device using the history table TB21, or visualizing the face image of the user who has used the application P11A or the license using the history table TB31.
[0144] Further, the license management system 100 according to the embodiment can support the prevention of unauthorized use of the application P11A or the license by multiple unauthorized users by estimating and outputting the main unauthorized user and the secondary unauthorized user based on the number of times of unauthorized use by the unauthorized users.
[0145] (Appendix) Based on the descriptions of the above embodiments, the following technologies are disclosed.
[0146] (Technology 1) A license management method for managing the license of an application P11A performed by a computer (management server device AP1), acquiring the license of the application P11A, executing a first determination to determine whether the license of the application P11A is valid, based on the first determination, when it is determined that the license of the application P11A is not valid, registering unissued information indicating that the license has not been issued to the user who uses the application P11A, and registering authentication information used for authenticating the user, outputting an alert notifying that the authentication information of the user to whom the license has not been issued has been registered. License management method. With this configuration, the management server device AP1 can detect unauthorized use of the application with higher accuracy and notify the administrator. As a result, the management server device AP1 can assist the administrator in managing the license of the application.
[0147] (Technology 2) Send a false registration notice indicating that the authentication information of the user has been registered to the terminal (terminal devices P11,..., P21,...) where the application P11A is used. The license management method according to (Technology 1). With this configuration, the management server device AP1 can notify the administrator of the detection of unauthorized users without being noticed by the unauthorized users. As a result, the management server device AP1 can detect unauthorized use of the application more effectively.
[0148] (Technology 3) Based on the first determination, when it is determined that the license of the application P11A is valid, execute a second determination to determine whether the license of the application P11A is a properly issued license. Based on the second determination, when it is determined that the license of the application P11A is not proper, output an alert notifying that the license is unauthorized. The license management method according to (Technology 1) or (Technology 2). With this configuration, the management server device AP1 can detect unauthorized use of the application with higher accuracy and notify the administrator.
[0149] (Technology 4) Based on the first determination, when it is determined that the license of the application P11A is valid, execute a second determination to determine whether the license of the application P11A is a properly issued license. When it is determined based on the second determination that the license of the application P11A is not proper, execute the registration of the authentication information used for the authentication of the user who uses the application P11A, Output an alert notifying that the authentication information of the user for whom the license has not been issued has been registered, (License management method) described in (Technology 1). With this configuration, the management server device AP1 can notify (inform) the administrator of the detection of an unauthorized user without being noticed by the unauthorized user. As a result, the management server device AP1 can more effectively detect unauthorized use of the application.
[0150] (Technology 5) When it is determined based on the first determination that the license of the application P11A is valid, execute a second determination to determine whether the license of the application P11A is a properly issued license, When it is determined based on the second determination that the license of the application P11A is not proper, omit the registration of the user's authentication information, Send a false registration notice indicating that the user's authentication information has been registered to the terminal (terminal devices P11,..., P21,...) where the application P11A is used, (License management method) described in any one of (Technology 1) to (Technology 4). With this configuration, the management server device AP1 can notify (inform) the administrator of the detection of an unauthorized user without being noticed by the unauthorized user. As a result, the management server device AP1 can more effectively detect unauthorized use of the application.
[0151] (Technology 6) After registering the user's authentication information, obtain the license of the application P11A and the authentication information of the user who uses the application P11A, and based on the first determination, if it is determined that the license of the application P11A is valid, execute a third determination to authenticate the user based on the obtained user authentication information and the registered user authentication information. Based on the third determination, if it is determined that the user is not authenticated, output an alert notifying that the authentication of the user for whom the license has not been issued has been performed. (The license management method according to any one of (Technology 1) to (Technology 5). With this configuration, the management server device AP1 can detect unauthorized use of an application by an unauthorized user with higher accuracy and notify the administrator.
[0152] (Technology 7) After registering the user's authentication information, obtain the license of the application P11A and the authentication information of the user who uses the application P11A. Based on the first determination, if it is determined that the license of the application P11A is valid, execute a third determination to authenticate the user based on the obtained user authentication information and the registered user authentication information. Based on the third determination, if it is determined that the user is not authenticated, the application P11A transmits a false authentication notification indicating that the user's authentication information has been authenticated to the terminal (terminal devices P11,..., P21,...) where the application P11A is used. (The license management method according to any one of (Technology 1) to (Technology 6). With this configuration, the management server device AP1 can notify the administrator of the detection of an unauthorized user without being noticed by the unauthorized user. As a result, the management server device AP1 can more effectively detect unauthorized use of the application.
[0153] (Technology 8) Store the license of the application P11A used in the first terminal (terminal devices P11,..., P21,...) and the authentication information of the first user who uses the application P11A in the first terminal (terminal devices P11,..., P21,...). Obtain the license of the application P11A and the authentication information of the first user who uses the application P11A. Based on the third determination, when it is determined that the authentication information of the first user is obtained from a second terminal (terminal devices P11,..., P21,...) different from the first terminal (terminal devices P11,..., P21,...) and the license of the application P11A has not been issued for the second terminal (terminal devices P11,..., P21,...), generate a message prompting the acquisition of the license of the application P11A in the second terminal (terminal devices P11,..., P21,...) and send it to the second terminal (terminal devices P11,..., P21,...). (The license management method according to any one of (Technique 4) to (Technique 6). With this configuration, the management server device AP1 can recommend the proper use of the application to legitimate users and more effectively suppress the illegal use of the application.
[0154] (Technique 9) Associate and store the terminal (terminal devices P11,..., P21,...) where the application P11A is used, the license of the application P11A used in the terminal (terminal devices P11,..., P21,...), the expiration date of the license, and the authentication information of the user who uses the application P11A in the terminal (terminal devices P11,..., P21,...). In the first determination, when it is determined that the expiration date of the license has passed, send a message prompting the renewal of the license to the terminal (terminal devices P11,..., P21,...). (The license management method according to any one of (Technique 1) to (Technique 8). With this configuration, the management server device AP1 can more effectively suppress the illegal use of the application.
[0155] (Technology 10) Terminal devices P11,…, P21,…, and a license management system 100 including a management server device AP1 that can communicate with the terminal devices P11,…, P21,… and manages licenses of applications used by the terminal devices P11,…, P21,…, the terminal devices P11,…, P21,… send the license acquired at the time of starting the application to the management server device AP1, the management server device AP1 execute a first determination to determine whether the license of the application acquired from the terminal devices P11,…, P21,… is valid, based on the first determination, if it is determined that the license of the application is not valid, execute registration of unissued information indicating that the license has not been issued to the user using the application and registration of authentication information used for authentication of the user, output an alert notifying that the authentication information of the user for whom the license has not been issued has been registered, License management system 100. With this configuration, the license management system 100 can detect unauthorized use of an application with higher accuracy and notify (alert) the administrator. Thereby, the license management system 100 can assist the administrator in managing the licenses of applications.
[0156] (Technology 11) a license management program that processes, by one or more processors 11, a license management method for managing licenses of applications performed by a computer (terminal devices P11,…, P21,…), a step of acquiring a license of the application, a step of executing a first determination to determine whether the license of the application is valid, When it is determined based on the first determination that the license of the application is invalid, perform the steps of registering unissued information indicating that the license has not been issued to the user who uses the application and registering authentication information used for authenticating the user. Output an alert notifying that the authentication information of the user to whom the license has not been issued has been registered, for a license management program. With this configuration, the license management program can detect unauthorized use of an application with higher accuracy and notify the administrator. As a result, the license management program can assist the administrator in managing the license of the application.
[0157] As described above, various embodiments have been described with reference to the accompanying drawings, but the present disclosure is not limited to such examples. It is obvious that those skilled in the art can conceive of various modification examples, correction examples, substitution examples, addition examples, deletion examples, and equivalent examples within the scope described in the claims, and it is understood that these also belong to the technical scope of the present disclosure. Further, within the scope not departing from the gist of the invention, the components in the above-described various embodiments may be arbitrarily combined.
Industrial Applicability
[0158] The present disclosure is useful as a presentation of a license management method, a license management system, and a license management program that can more effectively detect unauthorized use of an application.
Description of Signs
[0159] 10 Communication unit 11 Processor 11A Authentication application 12 Memory 13 Output unit 16 ID / PASS verification unit 100 License management system 111 License determination unit 112 License Issuing Unit 113 MAC Address Acquisition Unit 114 Alert Judgment Unit 115 Registration Processing Unit 116 ID / PASS Verification Unit 117 Biometric Information Verification Unit AP1 Management Server Device DB1 License Database DB2 User Database F11, F12, F21, F22, IMG11, IMG12, IMG13 Facial Images LP1 License Issuing Device Msg1 Unauthorized Use Detection Message P11, P21 Terminal Devices P11A Application P11B Authentication Application P11C Unauthenticated Application P11D Display S1 Terminal Management Server SC1, SC2, SC3 Alert Notification Screens SC11A, SC11B, SC12A, SC12B Registration Screens SC13A, SC13B Registration Result Screens SC21A, SC21B Authentication Screens SC22A, SC22B Authentication Result Screens
Claims
1. A license management method for managing licenses of applications performed by a computer, comprising: acquiring a license of the application; performing a first determination to determine whether the license of the application is valid; based on the first determination, when it is determined that the license of the application is not valid, registering unissued information indicating that the license has not been issued to the user using the application and registering authentication information used for authentication of the user; outputting an alert notifying that the authentication information of the user to whom the license has not been issued has been registered; A license management method.
2. sending a false registration notice indicating that the authentication information of the user has been registered to a terminal on which the application is used; The license management method according to claim 1.
3. based on the first determination, when it is determined that the license of the application is valid, performing a second determination to determine whether the license of the application is a properly issued license; based on the second determination, when it is determined that the license of the application is not proper, outputting an alert notifying that the license is illegal; The license management method according to claim 1.
4. based on the first determination, when it is determined that the license of the application is valid, performing a second determination to determine whether the license of the application is a properly issued license; based on the second determination, when it is determined that the license of the application is not proper, registering authentication information used for authentication of the user using the application; outputting an alert notifying that the authentication information of the user to whom the license has not been issued has been registered; The license management method according to claim 1.
5. based on the first determination, when it is determined that the license of the application is valid, performing a second determination to determine whether the license of the application is a properly issued license; based on the second determination, when it is determined that the license of the application is not proper, omitting the registration of the authentication information of the user; Sending a false registration notification indicating that the authentication information of the user has been registered to the terminal on which the application is used The license management method according to claim 1
6. After registration of the authentication information of the user, the license of the application and the authentication information of the user using the application are acquired, and when it is determined based on the first determination that the license of the application is valid, a third determination for authenticating the user is executed based on the acquired authentication information of the user and the registered authentication information of the user When it is determined based on the third determination that the user is not authenticated, an alert is output notifying that the authentication of the user for whom the license has not been issued has been performed The license management method according to claim 1
7. After registration of the authentication information of the user, the license of the application and the authentication information of the user using the application are acquired When it is determined based on the first determination that the license of the application is valid, a third determination for authenticating the user is executed based on the acquired authentication information of the user and the registered authentication information of the user When it is determined based on the third determination that the user is not authenticated, a false authentication notification indicating that the authentication information of the user has been authenticated is sent to the terminal on which the application is used The license management method according to claim 1
8. Storing the license of the application used on the first terminal and the authentication information of the first user using the application on the first terminal Acquiring the license of the application and the authentication information of the first user using the application When it is determined based on the third determination that the authentication information of the first user is acquired from a second terminal different from the first terminal and for which the license of the application has not been issued, a message prompting acquisition of the license of the application on the second terminal is generated and sent to the second terminal The license management method according to claim 6 or 7
9. Associate and store the terminal on which the application is used, the license of the application used on the terminal, the expiration date of the license, and the authentication information of the user who uses the application on the terminal. In the first determination, if it is determined that the expiration date of the license has passed, send a message prompting the update of the license to the terminal. The license management method according to claim 1.
10. A terminal device, A license management system comprising a management server device that is communicable with the terminal device and manages the license of an application used by the terminal device, The terminal device, Send the license acquired at the startup of the application to the management server device. The management server device, Execute a first determination to determine whether the license of the application acquired from the terminal device is valid. Based on the first determination, if it is determined that the license of the application is not valid, execute the registration of unissued information indicating that the license has not been issued to the user who uses the application and the registration of authentication information used for the authentication of the user. Output an alert notifying that the authentication information of the user to whom the license has not been issued has been registered. License management system.
11. A license management program for processing, by one or more processors, a license management method for managing the license of an application performed by a computer, A step of acquiring the license of the application, A step of executing a first determination to determine whether the license of the application is valid, Based on the first determination, if it is determined that the license of the application is not valid, execute a step of registering unissued information indicating that the license has not been issued to the user who uses the application and a step of registering authentication information used for the authentication of the user. A step of outputting an alert notifying that the authentication information of the user to whom the license has not been issued has been registered, for realizing License management program.
Citation Information
Patent Citations
Management server and terminal management method therefor
JP2012103781A