Portable storage device and information processing system
The portable storage device provides a secure virtualized environment for business operations on non-organization-owned devices, addressing security risks and eliminating the need for costly virtual desktop infrastructure and stable network connections.
Patent Information
- Application Number
- JP2024006092
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-18
- Publication Date
- 2025-07-31
AI Technical Summary
Existing technologies for virtual desktop environments require costly infrastructure and stable network connections, and using personal devices for business operations poses significant security risks due to malware and data leakage.
A portable storage device that includes a host OS program, guest OS program, and management programs to create a virtualized environment, enabling secure business operations on non-organization-owned devices by managing and securing the host and guest OS environments.
Reduces security risks and enables business operations on non-organization-owned devices without the need for a virtual desktop environment or constant network connections, ensuring secure and functional business use.
Smart Images

Figure 2025112044000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a portable storage device and an information processing system.
Background Art
[0002] In organizations such as companies, it is common to provide employees with business devices such as terminals, and employees use the provided business devices to conduct business both inside and outside the office. On the other hand, when conducting business outside the office such as at home, or when the provided business device breaks down, there are cases where employees utilize devices they own or devices at the destination to conduct business.
[0003] When an employee conducts business using a device other than the business device provided by the organization, there is a risk that business data used and generated on the device may be leaked due to malware or external transfer. Therefore, there is a need to prevent information leakage and reduce security risks.
[0004] As one method of reducing security risks, there is a method of virtual desktops that aggregates and manages the functions and data of business devices in a data center such as the cloud and uses the functions and data of business devices via a network. In Patent Document 1, a method for performing charging that accurately reflects input operations performed by a user is proposed in an apparatus that provides a virtual desktop environment.
[0005] Also, as a remote operation device for remotely connecting to and operating a virtual desktop, there is a method of a thin client that does not store business data on the device. In Patent Document 2, a method for providing a memory device capable of constructing a thin client system with complete virus countermeasures by connecting to an external connection terminal of a standard PC and performing fingerprint authentication is proposed.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
[0007] However, the technologies in Patent Documents 1 and 2 require costs for the virtual desktop environment. In addition, a constant network connection is required to connect to the virtual desktop, which can cause response delays in locations with unstable networks, affecting convenience.
[0008] On the other hand, if virtual desktops are not used and employees use their own devices or devices at their workplaces, it is difficult to take measures to sufficiently reduce the security risks of the devices because they are not owned by the organization.
[0009] Therefore, an object of the present invention is to provide a technology that reduces security risks and enables business operations to be performed using business equipment other than that owned by an organization. [Means for solving the problem]
[0010] In order to solve the above problem, one representative portable storage device of the present invention is a portable storage device connected to a terminal device, and stores business programs used by users for business purposes, a host OS program that runs on the terminal device and creates and provides a virtualized environment, a guest OS program that runs in the virtualized environment, a host management program that runs on the host OS program and causes the guest OS program to run in the virtualized environment, a guest management program that causes the business program to run on the guest OS program, and unique data assigned to the virtualized environment. [Effects of the Invention]
[0011] According to the present invention, security risks can be reduced and business can be carried out using equipment other than business equipment owned by the organization.
[0012] Problems, configurations, and effects other than those described above will be clarified by the following description of the embodiments.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Best Mode for Carrying Out the Invention
[0014] Hereinafter, embodiments of the present invention will be described with reference to FIGS. 1 to 16.
[0015] First, the configurations of the portable storage device and the system according to the embodiments of the present invention will be described with reference to FIGS. 1 to 10.
[0016] FIG. 1 is a schematic diagram for explaining an example of the overall configuration of the information processing system in the present embodiment.
[0017] The information processing system 100 includes a management device 10, one or more business terminal devices 11, one or more temporary use terminal devices 12, and one or more portable storage devices 13. The business terminal devices 11 and the temporary use terminal devices 12 communicate with the management device 10 via a network 14.
[0018] The business terminal device 11 is, for example, a terminal device provided by an organization. The business terminal device 11 includes a business program used in business and business data. The user 16 is, for example, an employee of an organization, and performs business using the business terminal device 11.
[0019] The temporary use terminal device 12 is, for example, a terminal device located at various business locations such as home or a business trip destination.
[0020] The portable storage device 13 stores programs and data such as an OS program. The user 16 can perform business using the temporary use terminal device 12 by connecting the portable storage device 13 to the temporary use terminal device 12.
[0021] The management device 10 is a device that manages the business terminal devices 11 and the portable storage devices 13 to be managed. The administrator 15 is an administrator of the business terminal device 11, the portable storage device 13, and the information processing system 100, and can view and edit the data stored in the management device 10.
[0022] FIG. 2 is a block diagram for explaining an example of the configuration of the management device 10.
[0023] The management device 10 includes a processor 21, a memory 22, a communication device 23, an input / output device 24, a storage device 25, an internal signal line 26, a monitor 27, a keyboard 28, and a mouse 29. The processor 21, the memory 22, the communication device 23, the input / output device 24, and the storage device 25 are connected to each other via the internal signal line 26.
[0024] The processor 21 is a device that performs program processing. The storage device 25 is a hard disk, an SSD (Solid State Drive), a non-volatile memory, etc., and is a device that stores programs and data. The memory 22 is a storage device for storing the programs to be executed and temporarily storing data. The input / output device 24 is a device that controls the output to the monitor 27 and the input from the keyboard 28 and the mouse 29. The communication device 23 is a device that performs network communication with other devices.
[0025] Programs and data are stored in the storage device 25. The programs stored in the storage device 25 include a management OS program 201, a business terminal management program 202, and a portable storage device management program 203. The data stored in the storage device 25 includes a management target list data 204, confirmation item setting data 205, operation setting data 206, and storage operation data 207.
[0026] The management OS program 201 on the storage device 25 is loaded into the memory 22 and executed.
[0027] The management OS program 201 controls the input / output device 24 and loads data from the storage device 25 to the memory 22. Further, the management OS program 201 loads the business terminal management program 202 and the portable storage device management program 203 from the storage device 25 into the memory 22 and executes them.
[0028] The business terminal management program 202 communicates with the business terminal device 11 to be managed or the temporary use terminal device 12 to which the portable storage device 13 is connected, and manages the OS of the device to be managed.
[0029] The portable storage device management program 203 communicates with a program running on the temporary use terminal device 12 to which the portable storage device 13 is connected, and transmits and receives data such as confirmation item setting data 205, operation setting data 206, and storage business data 207.
[0030] The management target list data 204 includes information on the OS programs in the business terminal device 11 or portable storage device 13 that are the management targets.
[0031] The confirmation item setting data 205 includes setting information of items that the host management program of the portable storage device 13 checks regarding the security of the host OS program when the temporary use terminal device 12 is started up using the portable storage device 13 .
[0032] The operation setting data 206 includes setting information of items that the host management program of the portable storage device 13 determines regarding the functions and performance of the temporary use terminal device 12 started up using the portable storage device 13 .
[0033] In the stored business data 207, business data corresponding to the portable storage device 13 is stored.
[0034] FIG. 3 is a block diagram illustrating an example of the configuration of business terminal device 11. As shown in FIG.
[0035] The business terminal device 11 includes a startup processing device 30, a processor 31, a memory 32, a communication device 33, an input / output device 34, a storage device 35, an internal signal line 36, a monitor 37, a keyboard 38, and a mouse 39. The startup processing device 30, the processor 31, the memory 32, the communication device 33, the input / output device 34, and the storage device 35 are connected to each other via the internal signal line 36.
[0036] The processor 31 is a device that processes programs. The storage device 35 is a hard disk, SSD (Solid State Drive), non-volatile memory, etc., and is a device that stores programs and data. The memory 32 is a storage device for storing the programs to be executed and temporary data. The input / output device 34 is a device that controls the output to the monitor 37 and the input from the keyboard 38 and the mouse 39. The communication device 33 is a device that performs network communication with other devices.
[0037] Programs and data are stored in the storage device 35. The programs stored in the storage device 35 include the business terminal OS program 301, the business terminal control program 302, and the business program 303. The data stored in the storage device 35 includes the in-terminal business data 304.
[0038] The startup processing device 30 stores the terminal device specific data 300.
[0039] The terminal device specific data 300 has information that can uniquely identify the hardware of the business terminal device 11.
[0040] After the business terminal device 11 is powered on, the startup processing device 30 loads and executes the business terminal OS program 301 on the storage device 35 into the memory 32, with the storage device 35 as the storage device to be started up.
[0041] The business terminal OS program 301 controls the input / output device 34 and loads data from the storage device 35 into the memory 32. Also, the business terminal OS program 301 loads the business terminal control program 302 and the business program 303 from the storage device 35 into the memory 32 and executes them.
[0042] The user 16 can perform business using the business program 303 and save the business data used, created, and edited in the business as the in-terminal business data 304.
[0043] The business terminal OS program 301 and the business terminal control program 302 can use the data of the terminal device specific data 300.
[0044] The business terminal control program 302 of the business terminal device 11 communicates with the business terminal management program 202 of the management device 10, obtains the control content set by the administrator according to the organization's policy, and performs control such as checking and taking measures on the security status of the program operating on the business terminal OS program 301 and the business terminal OS program 301.
[0045] In addition, the business terminal control program 302 sends the information of the program operating on the business terminal OS program 301 and the business terminal OS program 301, and the information of the business terminal device 11 to the business terminal management program 202 of the management device 10 together with the terminal device specific data 300.
[0046] In the business terminal management program 202 of the management device 10, for the management target specified by the acquired terminal device specific data 300, the corresponding management target list data 204 is rewritten. The administrator 15 can check the latest state of the management target by checking the content of the management target list data 204 on the monitor 27 etc. of the management device 10.
[0047] FIG. 4 is a block diagram for explaining an example of the configuration of the temporary use terminal device 12.
[0048] The temporary use terminal device 12 includes a startup processing device 40, a processor 41, a memory 42, a communication device 43, an input / output device 44, a storage device 45, an internal signal line 46, a monitor 47, a keyboard 48, and a mouse 49. The startup processing device 40, the processor 41, the memory 42, the communication device 43, the input / output device 44, and the storage device 45 are connected to each other via the internal signal line 46.
[0049] The processor 41 is a device that processes programs. The storage device 45 is a hard disk, SSD (Solid State Drive), non-volatile memory, etc., and is a device that stores programs and data. The memory 42 is a storage device for storing programs to be executed and temporary data. The input / output device 44 is a device that controls output to the monitor 47, input from the keyboard 48 and mouse 49, and input / output with the portable storage device 13. The communication device 43 is a device that performs network communication with other devices.
[0050] Programs and data are stored in the storage device 45. The programs stored in the storage device 45 include the temporary use terminal OS program 401 and the temporary use terminal program 402. The data stored in the storage device 45 includes the temporary use terminal data 403.
[0051] When the user 16 uses the temporary use terminal device 12 for purposes other than the organization's business, after turning on the power of the temporary use terminal device 12, the startup processing device 40 designates the storage device 45 as the storage device to be started, and loads and executes the temporary use terminal OS program 401 on the storage device 45 into the memory 42.
[0052] The temporary use terminal OS program 401 controls the input / output device 44 and loads data from the storage device 45 into the memory 42. Also, the temporary use terminal OS program 401 loads the temporary use terminal program 402 from the storage device 45 into the memory 42 and executes it.
[0053] When the user 16 uses the temporary use terminal device 12 for purposes other than the organization's business, the user 16 can use the temporary use terminal program 402 and the temporary use terminal data 403 in the storage device 45.
[0054] On the other hand, when the user 16 uses the temporary use terminal device 12 for the organization's business, the portable storage device 13 is connected to the input / output device 44 of the temporary use terminal device 12.
[0055] After the power of the temporary use terminal device 12 is turned on, the startup processing device 40 sets the portable storage device 13 as the storage device to be started, loads the OS program on the portable storage device 13 into the memory 42, and executes it.
[0056] When the user 16 uses the temporary use terminal device 12 for the organization's business, the programs and data in the portable storage device 13 can be used.
[0057] FIG. 5 is a block diagram for explaining an example of the configuration of the portable storage device 13.
[0058] The portable storage device 13 can be connected to the temporary use terminal device 12 to input and output program and data information.
[0059] Programs and data are stored in the portable storage device 13. The programs stored in the portable storage device 13 include a host OS program 501 and a host management program 502. The data stored in the portable storage device 13 includes confirmation item setting data 205, operation setting data 206, and guest OS-specific data 503.
[0060] In addition, the portable storage device 13 has a guest OS storage area 504. Programs and data for the guest OS are stored in the guest OS storage area 504. The programs stored in the guest OS storage area 504 include a guest OS program 511, a business terminal control program 302, a guest management program 512, and a business program 303. The data stored in the guest OS storage area 504 includes in-portable-storage-device business data 513.
[0061] When using the temporary use terminal device 12 for the organization's business, after the power of the temporary use terminal device 12 is turned on, the startup processing device 40 loads the host OS program 501 on the portable storage device 13 into the memory 42 as the storage device to be started and executes it.
[0062] The host OS program 501 loads the host management program 502 into the memory 42 of the temporary use terminal device 12 and executes it.
[0063] The host management program 502 acquires the confirmation item setting data 205 and the operation setting data 206 from the management device 10, and based on these data, checks the security status of the host OS program 501 and the performance and functions of the temporary use terminal device 12.
[0064] Also, the guest OS program operates on virtual hardware created by the virtualization functions of the host OS program 501 and the temporary use terminal device 12. The guest OS specific data 503 has information that can uniquely identify the virtual hardware on which the guest OS program 511 of the portable storage device 13 operates.
[0065] The guest OS program 511 and the business terminal control program 302 can use the data of the guest OS specific data 503.
[0066] The business terminal control program 302 of the portable storage device 13 communicates with the business terminal management program 202 of the management device 10, acquires the control content set by the administrator in accordance with the organization's policies, and performs controls such as checking and taking measures on the security status of the guest OS program 511 and the programs operating on the guest OS program 511.
[0067] Also, the business terminal control program 302 sends the information of the guest OS program 511 and the programs operating on the guest OS program 511 to the business terminal management program 202 of the management device 10 together with the guest OS specific data 503.
[0068] The business terminal management program 202 rewrites the corresponding management target list data 204 for the management target specified by the acquired guest OS specific data 503.
[0069] The administrator 15 can check the latest status of the management target by checking the content of the management target list data 204 using the monitor 27 etc. of the management device 10.
[0070] FIG. 6 is a diagram for explaining an example of the configuration of the management target list data 204.
[0071] The management target list data 204 has fields of a management target ID 601, unique data 602, an OS name 603, an OS version 604, a security measure status 605, and a malware countermeasure enforcement 606.
[0072] The management target ID 601 is a field for describing an identifier unique to a management target such as a business terminal OS in the business terminal device 11 or a guest OS in the portable storage device 13.
[0073] The unique data 602 is a field for describing the unique data of the management target corresponding to the management target ID 601.
[0074] The OS name 603 is a field for describing the OS name of the management target corresponding to the management target ID 601.
[0075] The OS version 604 is a field for describing the version of the OS of the management target corresponding to the management target ID 601.
[0076] The security measure status 605 is a field for describing the status of the security measures of the management target as good (OK) or abnormal (NG) corresponding to the management target ID 601.
[0077] The malware countermeasure enforcement 606 is a field for describing whether to enforce malware countermeasures on the management target as enforce (ON) or not enforce (OFF) corresponding to the management target ID 601.
[0078] The administrator 15 operates the management device 10 before the portable storage device 13 and the information processing system 100 start operating, and registers a list of the OSs of the management targets in the management target list data 204. At that time, the administrator 15 determines whether to enforce malware countermeasures according to the organization's policy, and describes it in the malware countermeasure enforcement 606.
[0079] Also, after the portable storage device 13 and the information processing system 100 start operating, when there are additions, deletions, or changes to the contents of the management target list, the administrator 15 operates the management device 10 to change the contents of the management target list data 204.
[0080] Also, the contents of the management target list data 204 are updated by the business terminal management program 202.
[0081] The contents of the malware countermeasure enforcement 606 in the management target list data 204 are sent to the business terminal control program 302 of the business terminal device 11 or the portable storage device 13 corresponding to the unique data 602 via the business terminal management program 202. As a result, when forcing (ON) whether to enforce malware countermeasures, it is applied to the operation of the business terminal control program 302 to enforce malware countermeasures.
[0082] The business terminal control program 302 of the business terminal device 11 checks the OS name, OS version, and security measure status for the business terminal OS program 301 and programs operating on the business terminal OS program 301, and sends the check results to the business terminal management program 202 together with the terminal device unique data 300.
[0083] Also, the business terminal control program 302 of the portable storage device 13 checks the OS name, OS version, and security measure status for the guest OS program 511 and programs operating on the guest OS program 511, and sends the check results to the business terminal management program 202 together with the unique data 503 for the guest OS.
[0084] The business terminal management program 202 rewrites the management target corresponding to the acquired unique data in the management target list data 204 with the acquired OS name, OS version, and security measure status.
[0085] By checking the content of the management target list data 204 using the monitor 27 etc. of the management device 10, the manager 15 can check the latest status of the business terminal device 11 and the portable storage device 13 that are under management.
[0086] FIG. 7 is a diagram for explaining an example of the configuration of the confirmation item setting data 205.
[0087] The confirmation item setting data 205 has fields for a confirmation item ID 701, a confirmation content 702, and an action content 703.
[0088] The confirmation item ID 701 is a field for describing an identifier that is unique to the item that the host management program 502 checks regarding the security of the host OS program 501 when the temporary use terminal device 12 is started using the portable storage device 13.
[0089] The confirmation content 702 is a field for describing the confirmation content corresponding to the confirmation item ID 701.
[0090] The action content 703 is a field for describing the content of the action that the host management program 502 of the portable storage device 13 performs when it is determined that the conditions are not met corresponding to the confirmation item ID 701. Here, for example, an action of aborting the start of the guest OS program 511 and improving the security of the host OS program 501 is described.
[0091] The manager 15 operates the management device 10 according to the organization's policy before the portable storage device 13 and the information processing system 100 start operating, and registers a list of confirmation items in the confirmation item setting data 205.
[0092] Also, when there are additions, deletions, or changes to the content of the confirmation item list after the portable storage device 13 and the information processing system 100 start operating, the manager 15 operates the management device 10 to change the content of the confirmation item setting data 205.
[0093] The confirmation item setting data 205 is sent to the portable storage device 13 via the portable storage device management program 203 and applied to the operation of the host management program 502.
[0094] FIG. 8 is a diagram for explaining an example of the configuration of the operation setting data 206.
[0095] The operation setting data 206 has fields for a determination item ID 801, a determination item 802, an action execution range 803, and an action content 804.
[0096] The determination item ID 801 is a field that describes an identifier unique to an item for which the host management program 502 determines the functions and performance of the temporary use terminal device 12 started using the portable storage device 13.
[0097] The determination item 802 is a field that describes the determination item corresponding to the determination item ID 801.
[0098] The action execution range 803 is a field that describes the range in which an action is executed based on the result of the determination corresponding to the determination item ID 801.
[0099] The action content 804 is a field that describes the content of the action to be performed by the host management program 502 when the action is to be executed within the range corresponding to the determination item ID 801. Here, for example, actions such as aborting the start of the guest OS program 511 and notifying the user of the situation, or performing settings suitable for the functions and performance of the temporary use terminal device 12 on the host OS program 501 are described.
[0100] The administrator 15 operates the management device 10 before the portable storage device 13 and the information processing system 100 start operating in accordance with the policies of the organization and the characteristics of the guest OS, and registers a list of determination items in the operation setting data 206.
[0101] After the portable storage device 13 and the information processing system 100 are started up, when there are additions, deletions, or changes to the contents of the list of determination items, the administrator 15 operates the management device 10 to change the contents of the operation setting data 206.
[0102] The operation setting data 206 is sent to the portable storage device 13 via the portable storage device management program 203 and applied to the operation of the host management program 502.
[0103] FIG. 9 is a diagram for explaining an example of the configuration of the terminal device specific data 300.
[0104] The terminal device specific data 300 has fields for a specific data name 901 and a specific data value 902.
[0105] The specific data name 901 is a field for describing a name that is unique to the items of the specific data of the business terminal device 11.
[0106] The specific data value 902 is a field for describing the value of the specific data corresponding to the specific data name 901.
[0107] The terminal device specific data 300 of the business terminal device 11 has different values for each piece of hardware of the business terminal device 11. By using the terminal device specific data 300, the business terminal management program 202 of the management device 10 can uniquely identify the business terminal device 11.
[0108] FIG. 10 is a diagram for explaining an example of the configuration of the specific data 503 for the guest OS.
[0109] The specific data 503 for the guest OS has the same configuration as the terminal device specific data 300 and has fields for a specific data name 901 and a specific data value 902.
[0110] The specific data name 901 is a field for describing a name that is unique to the items of the specific data of the business terminal device.
[0111] The inherent data value 902 is a field that describes the value of the inherent data corresponding to the inherent data name 901.
[0112] The inherent data 503 for the guest OS has different values set for each virtual hardware on which the guest OS program 511 of the portable storage device 13 operates. By using the inherent data 503 for the guest OS, the business terminal management program 202 can uniquely identify the virtual hardware on which the guest OS program 511 of the portable storage device 13 operates and the guest OS program 511 operating on the virtual hardware.
[0113] Next, the operations of the portable storage device 13 and the information processing system 100 according to the embodiment of the present invention will be described with reference to FIGS. 11 to 16.
[0114] FIGS. 11 to 12 are flowcharts for explaining an example of the business start operation of the present embodiment.
[0115] In FIGS. 11 to 12, the operations from when the user 16 uses the temporary use terminal device 12 and the portable storage device 13 until starting the business after turning on the power of the temporary use terminal device 12 are explained.
[0116] First, the user 16 connects the portable storage device 13 to the temporary use terminal device 12 and turns on the power of the temporary use terminal device 12. The startup processing device 40 of the temporary use terminal device 12 starts the host OS program 501 on the portable storage device 13 by using the portable storage device 13 as the storage device to be started (S1101).
[0117] Next, the host OS program 501 starts the host management program 502 (S1102).
[0118] The host management program 502 requests the data of the confirmation item setting data 205 and the operation setting data 206 from the portable storage device management program 203 of the management device 10 (S1103).
[0119] The portable memory device management program 203 sends the data of the confirmation item setting data 205 and the operation setting data 206 to the host management program 502 (S1104).
[0120] After the host management program 502 saves the data received in S1104 in the portable memory device 13, it performs a confirmation process to confirm the state of the host OS program 501 according to the content of each item of the confirmation item setting data 205, and determines whether there is a problem with security (S1105). The host management program 502 saves the history (log) of the confirmation process in S1105 in the portable memory device 13.
[0121] As a result of the confirmation process in S1105, if the state of the temporary use terminal device 12 satisfies the content described in the confirmation content 702 and it is determined that there is no problem with security, the process proceeds to S1109..
[0122] As a result of the confirmation process in S1105, if the state of the temporary use terminal device 12 does not satisfy the content described in the confirmation content 702 and it is determined that there is a problem with security, the process proceeds to S1106 and the action described in the action content 703 is executed.
[0123] For example, when the confirmation content 702 of "Is the last update date and time of the host OS program within two weeks?" is not satisfied, the user 16 is notified that the guest OS start is aborted and the host OS program is updated (S1106). The notification in S1106 is performed, for example, by displaying the confirmation content notification screen in FIG. 13 on the monitor 47 of the temporary use terminal device 12 or the like.
[0124] FIG. 13 is a diagram showing an example of a confirmation content notification screen interface.
[0125] The confirmation content notification screen interface has a title display area 1301 and a notification information display area 1302.
[0126] The notification information display area 1302 displays the details of actions, such as starting or stopping the guest OS program 511 or updating the host OS program 501.
[0127] Return to FIG. 11, request the host OS program 501 to handle the action details 703 (S1107), confirm the completion of the response of the host OS program 501 (S1108), and proceed to S1109.
[0128] As a result of the confirmation process in S1105, if it is determined that the state of the temporary use terminal device 12 does not satisfy multiple contents described in the confirmation details 702 and there are multiple security issues, summarize and notify the user 16 of them and perform respective actions.
[0129] The host OS program 501 is operating while the guest OS program 511 is also running. Therefore, if there are vulnerabilities in the host OS program 501 or malware such as a keylogger or screen capture operates, there is a risk of data leakage of the guest OS program 511 or programs operating on the guest OS program 511 by the host OS program 501 or programs operating on the host OS program 501.
[0130] Through the processes from S1103 to S1108, before starting the guest OS program 511, check and take countermeasures to ensure there are no security issues in the host OS program 501, programs operating on the host OS program 501, and data. This can reduce the risk of information leakage by the host OS program 501 or programs operating on the host OS program 501.
[0131] In this embodiment, before the start of the guest OS program 511 from S1103 to S1108, a confirmation process for whether there is a problem with the security of the host OS program 501 and a response when there is a problem with the security of the host OS program 501 are performed. These confirmation processes and responses may be performed after the start of the guest OS program 511, or may be performed more than once at a predetermined timing instead of just once.
[0132] Next, in S1109, the host management program 502 checks the functions of the processor, memory, etc. of the temporary use terminal device 12 and the performance such as the data read / write speed with the portable storage device 13 according to the contents of each item of the operation setting data 206 received in S1104, and determines whether there is a problem with the functions and performance of the temporary use terminal device 12.
[0133] As a result of the confirmation of the functions and performance in S1109, if the content described in the determination item 802 does not match the content described in the action execution range 803 and it is determined that there is no problem with the functions and performance of the temporary use terminal device 12, the process proceeds to S1114.
[0134] On the other hand, as a result of the confirmation of the functions and performance in S1109, if the content described in the determination item 802 matches the content described in the action execution range 803 and it is determined that there is a problem with the functions and performance of the temporary use terminal device 12, the process proceeds to S1110.
[0135] In S1110, it is determined whether there is a description of aborting the start of the guest OS in the corresponding action content 804.
[0136] In S1110, if there is a description of aborting the start of the guest OS in the corresponding action content 804, the host management program 502 determines that there is a problem with the start of the guest OS program 511, does not start the guest OS program 511, and notifies the user 16 (S1111).
[0137] Next, the host management program 502 is terminated (S1112), and this process is terminated.
[0138] The notification in S1111 is made by, for example, displaying the determination content notification screen of FIG.
[0139] FIG. 14 is a diagram showing an example of a determination content notification screen interface.
[0140] The judgment content notification screen interface has a title display area 1401 and a notification information display area 1402 .
[0141] The notification information display area 1402 displays, for example, information that the temporary use terminal device 12 is in an environment that does not support the operation of the guest OS program 511 .
[0142] Returning to Figure 11, if the corresponding action content 804 does not include a description of stopping guest OS startup at S1110, the host management program 502 requests the host OS program 501 to make the settings described in the corresponding action content 804 (S1113) and proceeds to S1114.
[0143] At this time, if multiple contents described in the check item 802 apply to the contents described in the action execution range 803, the host management program 502 makes a setting request to the host OS program 501 according to each action.
[0144] In S1114, the host management program 502 requests the guest OS program 511 to start.
[0145] Next, the host OS program 501 performs the guest OS settings specified by the host management program 502 (S1115).
[0146] Next, the host OS program 501 starts the guest OS program 511 (S1116), and the process proceeds to S1201 in FIG.
[0147] By the processes from S1109 to S1116, before starting the guest OS program 511, the functions such as the processor and memory of the temporary use terminal device 12 and the performance such as the data read / write speed with the portable storage device 13 are confirmed and countermeasures are taken. Thereby, it is possible to prevent providing the user with a business environment that is insufficient in function and performance according to the functions and performance such as the processor and memory of the temporary use terminal device 12 and the data read / write speed.
[0148] Also, by performing the operation setting of the guest OS program 511 that conforms to the configuration of the temporary use terminal device 12, the performance of the guest OS program 511 and the programs operating on the guest OS program 511 can be improved.
[0149] In S1201, the guest OS program 511 requested to start by the S1114 host OS program 501 starts the guest management program 512.
[0150] Next, the guest management program 512 requests the host management program 502 for the data of the confirmation item setting data 205 stored in the portable storage device 13 and the history (log) of the confirmation process stored in the portable storage device 13 in S1105 (S1202).
[0151] The host management program 502 sends the confirmation item setting data 205 and the history (log) data of the confirmation process to the guest management program 512 (S1203).
[0152] Also, the guest management program 512 requests the portable storage device management program 203 of the management device 10 for the data of the confirmation item setting data 205 (S1204).
[0153] The portable storage device management program 203 sends the data of the confirmation item setting data 205 to the guest management program 512 (S1205).
[0154] Then, the guest management program 512 checks whether there is a problem with the state of the host management program 502 by comparing the data of the confirmation item setting data 205 obtained in S1203 with the data of the confirmation item setting data 205 obtained in S1205 to check if there are any differences (S1206).
[0155] As a result of the confirmation in S1206, it is determined whether the data of the confirmation item setting data 205 obtained in S1203 and S1205 are different (S1207). If the data of the confirmation item setting data 205 obtained in S1203 and S1205 are different, it is determined that there is a problem with the state of the host management program 502 because the confirmation process in S1105 has not been performed correctly.
[0156] If there are differences in the data of the confirmation item setting data 205 in S1207, it is determined that there is a problem with the operation or state of the host management program 502, and there is a security risk in the host OS program 501, the programs operating on the host OS program 501, and the data, and a notification is sent to the user 16 (S1208).
[0157] The notification in S1208 is performed, for example, by displaying the status notification screen in FIG. 15 on the monitor 47 of the temporary use terminal device 12 or the like.
[0158] FIG. 15 is a diagram showing a status notification screen interface.
[0159] The status notification screen interface has a title display area 1501 and a notification information display area 1502.
[0160] The notification information display area 1502 displays contents such as that the host management program 502 is not operating normally.
[0161] Returning to FIG. 12, the guest management program 512 requests the guest OS program 511 to end (S1209). After that, the guest management program 512 is terminated (S1210), and this process is terminated.
[0162] In S1207, if the data of the confirmation item setting data 205 obtained in S1203 and S1205 are not different, it is determined that there is no problem with the state of the host management program 502, and the process proceeds to S1211.
[0163] In S1211, the guest management program 512 requests business data from the removable storage device management program 203 of the management device 10.
[0164] The removable storage device management program 203 reads the business data corresponding to the corresponding removable storage device 13 from the storage business data 207 and sends it to the guest management program 512 (S1212).
[0165] The guest management program 512 stores the obtained business data as the business data 513 in the removable storage device (S1213) and starts the business program 303 (S1214).
[0166] The user 16 starts the business using the business program 303 and the business data 513 in the removable storage device (S1215).
[0167] FIG. 16 is a flowchart for explaining an example of the business end operation of the present embodiment.
[0168] In FIG. 16, the operations until the user 16 finishes the business using the temporary use terminal device 12 and the removable storage device 13 and stops the temporary use terminal device 12 and the removable storage device 13 are explained.
[0169] First, the user 16 requests the guest OS program 511 to end (S1601).
[0170] Next, the guest OS program 511 requests the guest management program 512 to end (S1602) and waits until the guest management program 512 ends.
[0171] The guest management program 512 requests the business program 303 to end (S1603), and the business program 303 ends (S1604).
[0172] The guest management program 512 confirms the end of the business program 303 (S1605).
[0173] Next, the guest management program 512 sends the business data in the removable storage device business data 513 to the removable storage device management program 203 (S1606).
[0174] The removable storage device management program 203 stores the acquired business data in the storage business data 207 corresponding to the corresponding removable storage device 13, and returns the storage result to the guest management program 512 (S1607).
[0175] Upon receiving the storage result, the guest management program 512 deletes the business data in the removable storage device business data 513 (S1608).
[0176] After that, the guest management program 512 requests the host management program 502 to end the host OS program after the guest OS program ends (S1609), and ends the guest management program 512 (S1610).
[0177] After the guest OS program 511 confirms that the guest management program 512 has ended (S1611), the guest OS program 511 ends (S1612).
[0178] The host management program 502, in accordance with the request of S1609, after confirming the end of the guest OS program 511 (S1613), requests the host OS program 501 to end (S1614), and ends the host management program 502 (S1615).
[0179] After that, the host OS program ends (S1616), and the temporary use terminal device 12 and the removable storage device 13 stop.
[0180] By the process shown in FIG. 16, before the temporary use terminal device 12 and the portable storage device 13 stop, the business data stored in the portable storage device 13 is deleted. Thereby, the risk of information leakage due to the loss of the portable storage device can be suppressed.
[0181] As described above, when an employee uses a terminal device such as a device owned by the employee or a device at the destination as a temporary use terminal device for business, it is possible to perform business without using the programs and data in the storage device of the device. Therefore, the risk of information leakage caused by the program in the storage device of the device for the business data used in business can be reduced.
[0182] Also, since no change is made to the storage device of the temporary use terminal device, it does not affect the operation of the device other than for business use.
[0183] Furthermore, since a business program operates on the temporary use terminal and business is possible, a virtual desktop environment is not required, no cost is incurred for the virtual desktop environment, and a constant connection to the network is not necessary.
[0184] In addition, the OS program (guest OS program) in which the business program operates can be managed by business terminal device management means using unique data such as a serial number for identifying the device, and security measures can be confirmed and enforced remotely.
[0185] Also, for the host OS program that virtualizes and operates the guest OS program, when the security measure status of the host OS program is insufficient for the content specified by the administrator, the guest OS program and the business program are not started. Therefore, the risk of information leakage due to the host OS program and the programs on the host OS can be reduced.
[0186] Furthermore, it is possible to prevent providing a user with a business environment that is insufficient in terms of functions and performance according to the functions and performance of a processor, memory, etc. of the temporary use terminal device, such as data read / write speed, and to improve the performance of the guest OS program with an operation setting that conforms to the configuration of the temporary use terminal device.
[0187] Furthermore, it is possible to reliably erase business data stored in the portable storage device at the end of business and suppress the risk of information leakage due to loss of the portable storage device.
[0188] Note that the present invention is not limited to the above-described embodiments, and various modifications are possible within the scope of the gist.
[0189] For example, the temporary use terminal device may be not only a device owned by an employee or a device at the destination of movement, but also a device owned by an organization or a device in movement.
[0190] The management device is configured as a single unit, but it may also be configured to operate with one or more management devices.
[0191] Also, although the business terminal management program and the portable storage device management program are configured to operate on the same single management device, they may also be configured to operate on separate management devices.
[0192] Furthermore, when permission is given to make changes to the temporary use terminal device, it may also be configured to save and use programs and data in the portable storage medium in the temporary use terminal device.
[0193] The operating host OS program and guest OS program are each configured as one, but they may also be configured with one or more.
[0194] The portable storage device is configured to be connected to the temporary use terminal device via an input / output device, but it may also be configured to be connected by other means such as via a communication device.
[0195] Although the terminal device specific data is configured to be stored in the startup processing device, the terminal device specific data may be configured to be stored in other components such as a processor and a communication device, or may be configured to be distributed and stored including other components.
[0196] As items to be managed acquired from the business terminal device and the guest OS, the OS name, OS version, and security measure status are configured. However, other items such as the program name, program version, and program setting contents other than the OS may also be targets to be acquired from the management targets.
[0197] As an item of security measures performed on the business terminal device and the guest OS, malware countermeasure enforcement is configured. However, other items such as program update enforcement and external output prohibition enforcement may also be targets of security measures.
[0198] Note that the present invention is not limited to the above-described embodiments and includes various modifications. For example, the above-described embodiments have been described in detail for easy understanding of the present invention, and are not necessarily limited to those having all the configurations described. Also, a part of the configuration of one embodiment can be replaced with the configuration of another embodiment, and the configuration of another embodiment can be added to the configuration of one embodiment. Also, for a part of the configuration of each embodiment, addition, deletion, or replacement of other configurations is possible.
[0199] In addition, each of the above configurations, functions, processing units, processing means, etc. may be realized in hardware by designing a part or all of them, for example, by an integrated circuit. Also, each of the above configurations, functions, etc. may be realized in software by a processor interpreting and executing a program that realizes each function. Information such as a program, table, file, etc. that realizes each function can be placed in a memory, a recording device such as a hard disk or an SSD (Solid State Drive), or a recording medium such as an IC card, an SD card, or a DVD.
Explanation of Reference Numerals
[0200] 10…Management device, 11…Business terminal device, 12…Temporary use terminal device, 13…Portable storage device, 14…Network, 15…Administrator, 16…User, 21…Processor, 22…Memory, 23…Communication device, 24…Input / output device, 25…Storage device, 26…Internal signal line, 27…Monitor, 28…Keyboard, 29…Mouse, 100…Information processing system, 201…Management OS program, 202…Business terminal management program, 203…Portable storage device management program, 204…List of management targets data, 205…Confirmation item setting data, 206…Operation setting data, 207…Storage operation data, 30…Startup processing device, 31…Processor, 32…Memory, 33…Communication device, 34…Input / output device, 35…Storage device, 36…Internal signal line, 37…Monitor, 38…Keyboard, 39…Mouse, 300…Terminal device specific data, 301…Business terminal OS program, 302…Business terminal control program, 303…Business program, 304…Business data within the business terminal, 40…Startup processing device, 41…Processor, 42…Memory, 43…Communication device, 44…Input / output device, 45…Storage device, 46…Internal signal line, 47…Monitor, 48…Keyboard, 49…Mouse, 401…Temporary use terminal OS program, 402…Temporary use terminal program, 403…Temporary use terminal data, 501…Host OS program, 502…Host management program, 503…Guest OS specific data, 504…Guest OS memory area, 511…Guest OS program, 512…Guest management program, 513…Business data within the portable storage device, 601…Management target ID, 602…Specific data, 603…OS name, 604…OS version, 605…Security measure status, 606…Malware countermeasure enforcement, 701…Confirmation item ID, 702…Confirmation content, 703…Action content, 801…Judgment item ID, 802…Judgment item, 803…Action execution range, 804…Action content, 901…Specific data name, 902…Specific data value, 1301…Title display area, 1302…Notification information display area, 1401…Title display area, 1402…Notification information display area, 1501…Title display area, 1502…Notification information display area.
Claims
1. A portable storage device connected to a terminal device, a business program used by a user for business, a host OS program that operates on the terminal device to construct and provide a virtualized environment, a guest OS program that operates in the virtualized environment, a host management program that operates on the host OS program to operate the guest OS program in the virtualized environment, a guest management program that operates the business program on the guest OS program, and unique data assigned to the virtualized environment, wherein the portable storage device stores the above.
2. The portable storage device according to Claim 1, wherein a management device connected to the terminal device identifies the portable storage device using the unique data and manages information including the security state of the portable storage device.
3. The portable storage device according to Claim 2, wherein the host management program obtains confirmation item setting data from the management device, and operates the guest OS program when it is determined that there is no problem with the security of the host OS program based on the confirmation item setting data.
4. The portable storage device according to Claim 3, wherein the host management program requests a measure to improve the security of the host OS program based on the confirmation item setting data when it is determined that there is a problem with the security of the host OS program based on the confirmation item setting data.
5. The portable storage device according to Claim 2, wherein the host management program obtains operation setting data from the management device, and operates the guest OS program when it is determined that there is no problem with the functions and performance of the terminal device based on the operation setting data.
6. The portable storage device according to Claim 5, wherein the host management program requests settings conforming to the functions and performance of the terminal device for the host OS program based on the operation setting data when it is determined that there is a problem with the functions and performance of the terminal device based on the operation setting data.
7. The portable storage device according to Claim 2, The guest management program acquires business data used by the user for work from the management device, stores it in the portable storage device, transmits the business data stored in the portable storage device to the management device before ending the terminal device, and deletes the business data stored in the portable storage device.
8. An information processing system including a terminal device and a portable storage device connected to the terminal device, wherein the portable storage device stores a business program used by the user for work, a host OS program that operates on the terminal device to construct and provide a virtualized environment, a guest OS program that operates in the virtualized environment, a host management program that operates on the host OS program to operate the guest OS program in the virtualized environment, a guest management program that operates the business program on the guest OS program, and unique data assigned to the virtualized environment. An information processing system for storing these.
9. The information processing system according to claim 8, further including a management device connected to the terminal device, wherein the management device includes a storage device, and a control device that uses the unique data to identify the portable storage device and stores and manages information including the security state of the portable storage device in the storage device. An information processing system including these.
10. The information processing system according to claim 9, wherein the management device stores confirmation item setting data corresponding to the portable storage device in the storage device, and the host management program acquires the confirmation item setting data from the management device and operates the guest OS program when it is determined that there is no problem with the security of the host OS program based on the confirmation item setting data.
11. The information processing system according to claim 10, wherein when the host management program determines that there is a problem with the security of the host OS program based on the confirmation item setting data, the host management program requests a measure to improve the security of the host OS program based on the confirmation item setting data.
12. The information processing system according to claim 9, wherein the management device stores operation setting data for confirming the functions and performance of the terminal device in the portable storage device in the storage device. An information processing system in which the host management program acquires the operation setting data from the management device and operates the guest OS program when it is determined that there is no problem with the functions and performance of the terminal device based on the operation setting data.
13. The information processing system according to claim 12, wherein when the host management program determines that there is a problem with the functions and performance of the terminal device based on the operation setting data, the host management program requests the host OS program to make settings conforming to the functions and performance of the terminal device based on the operation setting data.
14. The information processing system according to claim 9, wherein the storage device stores business data used by the user for business, the guest management program acquires the business data from the management device and stores it in the portable storage device, sends the business data stored in the portable storage device to the management device before the terminal device is terminated, and deletes the business data stored in the portable storage device, and the control device stores the sent business data in the storage device.
Citation Information
Patent Citations
JP2013‐196220A
JP2010‐9473A