Relay apparatus

The relay device addresses the challenge of notifying administrators of impending license expirations by using internal mechanisms to ensure timely display of expiration notices on administrator terminals, overcoming the limitations of email delays and hard-to-notice device locations.

JP2025113546APending Publication Date: 2025-08-04SAXA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024007758
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-23
Publication Date
2025-08-04

AI Technical Summary

Technical Problem

Existing relay devices, such as UTM and GW devices, face challenges in reliably notifying administrators of license expiration dates due to their installation in hard-to-notice locations and the potential delay in email notifications, which can lead to delayed responses.

Method used

A relay device that includes a license period confirmation mechanism, administrator information acquisition, terminal identification, and notification processing units to ensure timely and reliable display of expiration notices on administrator terminals when the license period is nearing expiration.

Benefits of technology

Ensures that license expiration information is reliably notified to administrators at the appropriate time, preventing delays and oversight associated with email notifications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025113546000001_ABST
    Figure 2025113546000001_ABST
Patent Text Reader

Abstract

To provide a relay apparatus that is installed between a WAN and a LAN and reliably notifies information relating to license expiration dates only to an administrator at an appropriate time.SOLUTION: In a UTM (Unified Threat Management) apparatus 130, which serves as a relay apparatus, if the time from the current time until a license expiration date confirmed by a license expiration confirmation unit 131 is a certain period or less, an administrator information acquisition unit 132 acquires an email address of an administrator of the apparatus, and an expiration notification screen creation unit 133 creates an expiration notification screen. A terminal identification information acquisition unit 134 acquires the terminal identification information of a sender terminal apparatus from the email sent from the administrator, and notifies an administrator terminal request detection unit 135 of the information. When the administrator terminal request detection unit detects a request to access a Web page from the administrator, an administrator terminal notification processing unit 136 provides a deadline notification screen to the terminal apparatus specified by the terminal identification information of the administrator.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a relay device that relays between different networks, such as a UTM (Unified Threat Management) device or a GW (Gateway) device. [Background technology]

[0002] UTM devices (unified threat management devices) that integrate multiple different security functions into a single piece of hardware and centralize security management for networks and other devices are increasingly being used by companies and other organizations. UTM devices are primarily installed between a wide area network (WAN), which is the Internet, and a local area network (LAN), and are equivalent to relay devices that monitor, control, and manage communications between the WAN and LAN. GW devices also have the function of relaying between networks with different protocols and are equivalent to relay devices. Such relay devices require activation processing before they can be used.

[0003] Activation refers to the process in which a user who has installed a relay device performs a specific activation operation, which unlocks functional limitations and enables full use of the device. More specifically, when the relay device is activated, it requests authentication from a license server operated by the manufacturer. If authentication is obtained through the license server, the relay device receives the latest software (including signature files and definition files), which are updated periodically or as needed, and becomes operational using this software. The activation operation is often a simple operation, such as pressing and holding a specific button on the relay device. The expiration date of the relay device is determined based on the date of activation and is managed by the license server.

[0004] Patent Document 1 described later discloses an invention such as a method for appropriately managing a license for an information processing apparatus such as an image forming apparatus having a number of functions such as a printing function, a document reading function, a transmission function of read image data, and a facsimile function. Patent Document 1 discloses an invention that enables the license use period of license information to be dynamically extended in order to prevent the license use period from being substantially eroded and shortened regardless of the cause on the user side. Patent Document 1 also discloses that a license information display screen is displayed on the display unit of the image forming apparatus to notify the user of information such as the scheduled license expiration date and time.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] The invention disclosed in Patent Document 1 relates to an information processing apparatus such as an image processing apparatus used by one person or about two to three people. A license information display screen can be displayed on the display unit of the information processing apparatus to notify the user of information such as the scheduled license expiration date and time. However, in the case of a relay apparatus such as the UTM apparatus or GW apparatus described above, a number of terminal apparatuses such as PCs (Personal Computers) are connected through a LAN. For this reason, the relay apparatus is often installed in a place where it is difficult to be noticed by people, and even if information such as the scheduled license expiration date and time is displayed on the display screen of the relay apparatus, it is difficult to notice.

[0007] Therefore, on the license server side that manages the license period of the relay device, the email address of the store that sold the relay device is registered, and when the license period of the relay device is approaching expiration, the store is contacted by email. This enables the store to take action against users who are using a relay device whose license period is approaching expiration. However, in the case of notification by email, the action from the store may be delayed because the email is overlooked or the store is busy.

[0008] Therefore, it is conceivable to notify (inform) information such as the scheduled license expiration date and time of the relay device through the subordinate PCs connected via the LAN. However, even if information such as the scheduled license expiration date and time of the relay device is notified to a PC used by someone other than the administrator involved in the operation of the relay device, no specific action can be taken, resulting in a delay in response. Of course, it is also conceivable to provide information such as the scheduled license expiration date and time of the relay device to the administrator on the user (user) side by email. However, as mentioned above, notification by email may be delayed due to being overlooked or being busy.

[0009] In view of the above, it is an object to ensure that information regarding the license expiration date can be reliably notified to only the administrator at an appropriate timing for a relay device installed between a WAN and a LAN.

Means for Solving the Problem

[0010] To solve the above problems, the relay device according to the invention described in claim 1 is a relay device that relays between a wide area network and a LAN (Local Area Network), a license period confirmation means that makes an inquiry to a license server connected to the wide area network at a predetermined timing and confirms the license period of its own device, When the period from the current time to the expiration date of the license period confirmed by the license period confirmation means is equal to or less than a certain period, an administrator information acquisition means for acquiring the e-mail address of the administrator of the own device, When the period from the current time to the expiration date of the license period confirmed by the license period confirmation means is equal to or less than the certain period, a due date notification screen creation means for forming a due date notification screen, A terminal identification information acquisition means for monitoring a transmitted e-mail from a terminal device connected to the LAN and acquiring the terminal identification information of the transmitting terminal device from the transmitted e-mail whose sender's e-mail address matches the administrator's e-mail address, A manager terminal request detection means for monitoring an access request for a web page from a terminal device connected to the LAN and detecting an access request for a web page whose sender's terminal identification information matches the terminal identification information acquired by the terminal identification information acquisition means, When an access request for a web page that matches the terminal identification information acquired by the terminal identification information acquisition means is detected by the manager terminal request detection means, a manager terminal notification processing means for providing the due date notification screen created by the due date notification screen creation means to the terminal device specified by the terminal identification information characterized by comprising.

[0011] According to the relay device of the invention described in claim 1, assume that the period from the current time to the expiration date of the license period confirmed through the license period confirmation means is equal to or less than a certain period. In this case, the administrator information acquisition means acquires the e-mail address of the administrator of the own device, and the expiration notice screen formation means creates an expiration notice screen. The terminal identification information acquisition means monitors the transmitted e-mails from the subordinate terminal devices, and acquires the terminal identification information of the terminal device used by the administrator from the e-mail with the e-mail address of the administrator as the sender. The administrator terminal notification processing means monitors the access requests for the Web pages from the subordinate terminal devices. When the administrator terminal request detection unit 135 detects an access request for a Web page having the terminal identification information of the administrator, the administrator terminal notification processing means provides the expiration notice screen created by the expiration notice screen formation means to the terminal device specified by the terminal identification information of the administrator.

Effect of the Invention

[0012] According to this invention, regarding the relay device installed between the WAN and the LAN, information regarding the license expiration date can be reliably notified to only the administrator at an appropriate timing.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Embodiments for Carrying Out the Invention

[0014] Hereinafter, with reference to the drawings, an embodiment of the relay device according to the present invention will be described. In the embodiment described below, the wide area network means a WAN (Wide Area Network). The WAN means a network that extends over a wider range compared to a LAN or a MAN (Metropolitan Area Network), and in a broad sense, corresponds to the Internet. Therefore, in the following description, the wide area network is described as a WAN. Also, in the embodiment described below, the LAN is formed, for example, within a company. Therefore, in the following description, the relay device is a GW device or a UTM device that relays between the WAN and the LAN. In the following description, for the sake of simplicity, the case where the relay device is a UTM device will be described as an example.

[0015] [Description of Network System] FIG. 1 is a diagram for explaining a configuration example of the network system according to the embodiment. As shown in FIG. 1, the UTM device 1 is connected to the WAN 4 and the LAN 2 and functions as a relay device that relays between the WAN 4 and the LAN 2. In this embodiment, the LAN 2 is a network formed within a company as described above, and through the LAN 2, a plurality of PCs (Personal Computers) 3(1), 3(2), 3(3), …, 3(n) used by employees are connected to the UTM device 1.

[0016] On the other hand, as shown in Figure 1, a customer management server 5, a license server 6, a remote maintenance server 7, an update server 8, and a dealer PC 9 are connected to the WAN 4. The customer management server 5, the license server 6, the remote maintenance server 7, and the update server 8 are each a server group (cloud system) operated by the manufacturer of the UTM device 1. The server group performs license authentication for the UTM device 1 and appropriately manages the license period. Furthermore, the server group manages whether the UTM device 1 is operating normally at all times during the license period, and also provides the UTM device 1 with the latest software (including signature files and definition files).

[0017] In this embodiment, the software used by the UTM device 1 is used to identify known fraudulent communications and attack patterns, and to prevent fraudulent communications and attacks. For this reason, the software used by the UTM device 1 is sometimes collectively referred to as a signature. This is because, although the word signature originally meant a "signature" or "the directions and precautions written on a medicine container," in the IT (information technology) field it can also mean a set of rules for identifying known fraudulent communications and attack patterns.

[0018] In this specification, the process of enabling the UTM device 1 to receive the latest software, etc., from license authentication is referred to as activation processing. In other words, activation processing is the process of removing functional restrictions on the UTM device 1, enabling all functions to be used, and enabling the UTM device 1 to function properly and effectively.

[0019] In addition, in order to execute this activation process, the person in charge at the store that sells the UTM device 1 needs to register customer management information with the customer management server 5 and set detailed information in the UTM device 1 before installing the UTM device 1 in the user environment. In this case, the store PC 9 is used to register the customer management information. Note that the customer management information includes, for example, the manufacturing number of the UTM device 1, the MAC (Media Access Control) address, customer information, store information, registration date, and the like.

[0020] The customer information includes the customer name, customer identification number, name of the customer's administrator, email address of the customer's administrator, and the like. The administrator of the said customer is the person responsible for the operation of the UTM device 1 and has the responsibility to select, decide on, and contact the store or the like regarding any one of replacement of the UTM device 1, extension of the license period, or removal as the license period expires. Also, the store information includes the store name, person in charge at the store, phone number of the person in charge at the store, email address of the person in charge at the store, and the like.

[0021] [Execution operation of activation process according to user operation] Next, the execution operation of the activation process according to the user operation will be described. By performing this activation process, the start point of the license period is determined and the management of the license period is started.

[0022] FIG. 2 is a block diagram for explaining the operation when activation processing is performed in response to a user operation in the network system of the embodiment. As shown on the left end side of FIG. 2, before the UTM device 1 is installed in the user environment, a person in charge of a sales store that sells the UTM device 1 uses the sales store PC 9 to perform a process of registering customer management information with the customer management server 5 (step S1). Here, "installing the UTM device 1 in the user environment" means that the UTM device 1 can be installed and used at a predetermined location of the introducing company. The person in charge of the sales store connects the UTM device 1 before installation in the user environment to the WAN 4 at a predetermined work location, connects the sales store PC 9 to the UTM device 1, and turns on the power to the UTM device 1 and the sales store PC 9.

[0023] The person in charge of the sales store can access a predetermined web page using the sales store PC 9 and register customer management information by inputting necessary information to the customer management server 5. Also, the person in charge of the sales store issues an instruction through the web page via the sales store PC 9, downloads necessary information, and performs a process of setting it in the UTM device 1. As a result, even if the person in charge of the sales store does not go to the installation location himself / herself, if the installer transports the UTM device 1 to the user's company and installs it, and connects it to the WAN 4 and the LAN 2, the usage environment can be prepared.

[0024] After the UTM device 1 is installed in the user environment in this way, the user turns on the power to the UTM device 1. In this case, the UTM device 1 automatically accesses the remote maintenance server 7 and automatically connects a session (step S2). As a result, the remote maintenance server 7 can monitor the operating state of the UTM device 1 and manage whether it is operating normally and what state it is in. If a malfunction of the UTM device 1 is detected in the remote maintenance server 7, it becomes possible to perform recovery by remote operation or send a manufacturer's engineer to the company where the UTM device 1 is installed to handle it.

[0025] Next, the user manually performs an activation operation on the UTM device 1 (step S3). Specifically, a predetermined button switch provided on the UTM device 1 is, for example, long-pressed for 3 seconds or more. Note that the long-pressing of the button switch is an example of an operation. Therefore, in the UTM device 1, various activation operations such as pressing two button switches simultaneously or tilting and then returning the lever switch can be adopted.

[0026] Upon receiving the activation operation by the user, the UTM device 1 forms an activation request and transmits this to the license server 6 (step S4). The activation request includes, for example, identification information of the UTM device 1 such as the MAC address and manufacturing number of the UTM device 1. Assuming that the license server 6 has received the activation request. In this case, the license server 6 uses the identification information of the UTM device 1 such as the MAC address included in the activation request to confirm with the customer management server 5 whether the UTM device 1 is a legitimate one with proper registration of customer management information (step S5).

[0027] Based on the identification information of the UTM device 1 from the license server 6, the customer management server 5 refers to the customer management information it holds and transmits a result return (confirmation result) to the license server 6 (step S6). The result return is information indicating authentication permission when the customer management information has been appropriately registered with the customer management server 5 and there is customer management information corresponding to the identification information of the UTM device 1. Also, the result return is information indicating non-authentication when the customer management information has not been appropriately registered with the customer management server 5 and there is no customer management information corresponding to the identification information of the UTM device 1.

[0028] The license server 6 forms a result return in response to the result return from the customer management server 5 and performs a process of providing this to the UTM device 1 (step S7). Specifically, when the result return from the customer management server 5 is information indicating non-authenticable, in step S7, a result return indicating non-authenticable is transmitted to the UTM device 1. Also, when the result return from the customer management server 5 is information indicating authentication permission, in step S7, information indicating authentication permission and authentication information (information unique to the UTM device 1 indicating that authentication has been permitted) are provided to the UTM device 1. When the UTM device 1 obtains the authentication information, it holds this in itself. As a result, the UTM device 1 becomes in a state where authentication is obtained and it can receive the provision of the latest software.

[0029] The UTM device 1 periodically forms a signature update check and transmits this to the update server 8 (step S8). The signature update check is for confirming whether there is the latest information necessary for the normal operation of the UTM device 1 such as updated software and definition files, and when authentication information has been obtained in step S7, it includes this. The update server 8 applies the latest signature update or rejects the application of the update (step S9).

[0030] That is, when the signature update check from the UTM device 1 does not include appropriate authentication information, the UTM device 1 is a device for which authentication has not been obtained. For this reason, in step S8, the update server 8 forms information notifying of update rejection and provides this to the UTM device 1. On the other hand, when the signature update check from the UTM device 1 includes appropriate authentication information, the UTM device 1 is a device for which authentication has been obtained. Therefore, in step S8, the update server 8 provides the held latest software to the UTM device 1.

[0031] In this way, in the UTM device 1, when the activation process is properly executed and authentication information is obtained, the latest software that is updated periodically and as needed can be downloaded from the update server 8 and used. As a result, the UTM device 1 can always function properly. Further, in the license server 6, when providing information indicating authentication permission and authentication information in response to the activation request in step S4, the management of the license period is started from that point as the starting point.

[0032] For example, assume that the time when the license server 6 provides the UTM device 1 with information indicating authentication permission and authentication information in response to the activation request is "April 1, 2023". Also assume that the license period of the UTM device 1 is 5 years after the activation process is performed. In this case, the expiration date (license expiration) of the license period is calculated and managed from "April 1, 2023" to "March 31, 2028" which is 5 years later. The UTM device 1 of this embodiment can surely notify the administrator operating the UTM device 1 at an appropriate timing when the license expiration is approaching.

[0033] [Configuration example of UTM device 1] FIG. 3 is a block diagram for explaining a configuration example of the UTM device 1 of the embodiment. The connection end 101T constitutes a connection end with the WAN 4. The communication I / F (Interface) 101 is a part that performs communication processing through the WAN 4. That is, the communication I / F 101 converts a signal addressed to itself transmitted through the WAN 4 into a signal in a form that can be processed by itself and captures it. Also, the communication I / F 101 converts a signal transmitted from itself into a signal in a transmission form and sends it out to the WAN 4 for transmission to the counterpart. Therefore, when communicating with a counterpart connected to the WAN 4, it is performed through the connection end 101T and the communication I / F 101.

[0034] The control unit 102 is a microprocessor configured to include a CPU (Central Processing Unit), a ROM (Read Only Memory), a RAM (Random Access Memory), a non-volatile memory, etc. (not shown), and controls each part of the UTM device 1. In, for example, the non-volatile memory of the control unit 102, the MAC address, the manufacturing number, etc. of the UTM device 1 are stored and held. In addition, as described above, when the activation process is executed and authentication information is provided from the license server 6, this is stored and held. The storage device 103 is a device unit composed of a recording medium and its driver, such as an HDD (Hard Disk Drive) or an SSD (Solid State Drive), and performs recording, reading, changing, deleting, etc. of various data to / from the recording medium. The storage device 103 stores and holds necessary data and programs, and is also used as a work area for temporarily storing intermediate data generated in various processes.

[0035] The operation unit 104 is a part configured with several button switches, etc., receives an operation input from the user, forms an electrical signal corresponding to the operation input, and notifies the control unit 102. Thereby, the control unit 102 controls each part according to the operation input from the user received through the operation unit 104, and the user can execute the desired process in the UTM device 1. Note that the user can start the activation process under the control of the control unit 102 by, for example, long-pressing a predetermined button switch provided on the operation unit 104.

[0036] The address DB (Data Base) 105 stores and retains the MAC addresses and IP addresses of the PCs 3(1), 3(2), 3(3), …, 3(n) under the UTM device 1 connected to the UTM device 1 through the LAN2. Similar to the storage device 103 described above, the address DB 105 is formed in a device unit composed of a recording medium such as an HDD or an SSD and its driver. Incidentally, if there is a free space in the storage device 103, the address DB 105 can also be formed in the free space of the storage device 103. The clock circuit 106 provides the current date, current day of the week, and current time.

[0037] The connection terminal 107T constitutes the connection end with the LAN2. The LAN I / F (Interface) 107 is a part that performs communication processing through the LAN2. That is, the LAN I / F 107 converts a signal addressed to the local device transmitted through the LAN2 into a signal in a form that can be processed by the local device and captures it. Also, the LAN I / F 107 converts a signal transmitted from the local device into a signal in a transmission format and sends it to the LAN2 for transmission to the counterpart. Therefore, when communicating with the PCs 3(1), 3(2), 3(3), …, 3(n) connected to the LAN2, it is performed through the connection terminal 107T and the LAN I / F 107.

[0038] Although not shown in the figure, the security function unit 110 is configured to include, for example, a P2P countermeasure unit, an HP access control unit, a virus countermeasure unit, a mail countermeasure unit, an IPS / IDS unit, and a firewall unit. That is, the security function unit 110 realizes a function of prohibiting P2P connections with parties that have not taken security measures or malicious parties (function as a P2P countermeasure unit). Incidentally, "P2P" means "Peer to Peer" and means that peers communicate directly with each other via the Internet.

[0039] In addition, the security function unit 110 realizes a function of prohibiting access to a homepage corresponding to a category by, for example, selecting a target homepage category in advance (function as an HP access control unit). Further, the security function unit 110 performs verification (virus check) of a response of a web page (function as an anti-virus unit). More specifically, it realizes a function of monitoring communication when browsing a web page and verifying (checking) whether a virus is mixed in an image to be browsed or a file to be downloaded. Also, the security function unit 110 realizes a function of blocking an e-mail with unnecessary advertisements or viruses attached thereto with respect to the received e-mail (function as an e-mail countermeasure unit).

[0040] In addition, the security function unit 110 realizes a function of preventing inappropriate intrusion or notifying inappropriate intrusion (function as an IPS / IDS unit). Here, IPS is an abbreviation of Intrusion Prevention System, and IDS is an abbreviation of Intrusion Detection System. Note that the security function unit 110 can defend against attacks by so-called malware such as worms and Trojan horses. Also, the security function unit 110 determines whether to supply data to LAN2 based on the status of data communication, the software to be used, etc., and realizes a function of defending the own system from attacks and unauthorized access from an external network (function as a firewall unit).

[0041] The proper operation unit 120 is a functional unit for ensuring the proper functioning of the UTM device 1, and includes a maintenance server connection unit 121, an activation request unit 122, and a signature update unit 123. The maintenance server connection unit 121 realizes the function of accessing the remote maintenance server 7 and connecting a session under the control of the control unit 102. Thereby, the remote maintenance server 7 can monitor the operating state of the UTM device 1. In this case, the maintenance server connection unit 121 accesses the remote maintenance server 7 and connects a session using necessary information such as the URL (uniform resource locator) registered in the non-volatile memory of the control unit 102.

[0042] The activation request unit 122 realizes the function of forming an activation request and transmitting this to the license server 6 to execute activation processing under the control of the control unit 102. Also in this case, the activation request unit 122 accesses the license server 6 and transmits an activation request using necessary information such as the URL (uniform resource locator) registered in the non-volatile memory of the control unit 102. As a result of the activation request being made in this way, when receiving the provision of information indicating authentication permission and authentication information from the license server 6, the control unit 102 performs a process of registering at least the authentication information in the non-volatile memory of the control unit 102.

[0043] The signature update unit 123 measures a predetermined period based on the information from the clock circuit 106 under the control of the control unit 102, forms a signature update check at each predetermined timing, and realizes the function of transmitting this to the update server 8. The predetermined timing is, for example, an appropriate timing such as once a day, once every two days, once every three days, or once a week. This timing is predetermined by the manufacturer side of the UTM device 1. Even in this case, the signature update unit 123 accesses the update server 8 using necessary information such as the URL registered in the non-volatile memory of the control unit 102 and transmits the signature update check. Also, when the signature update unit 123 collaborates with the control unit 102 and receives the provision of the latest software (including the signature file and the definition file) from the update server 8, it records this in a predetermined area of the storage device 103 so that it can operate using this.

[0044] When the license expiration date is approaching, the license expiration notification unit 130 forms a license expiration notification screen and realizes the function of notifying the administrator through the administrator's PC of the UTM device 1. The license expiration is notified to the administrator of the UTM device 1 at an appropriate timing and reliably. This prevents inconveniences such as missing an email notification, forgetting to check the email later because one is busy and forgetting that one has received the email, and causing a delay in response as in the case of email notifications.

[0045] [Configuration and Operation of License Expiration Notification Unit 130] FIG. 4 is a block diagram for explaining a configuration example of the license expiration notification unit 130 of the UTM device 1 according to the embodiment. As described with reference to FIG. 1, a server group including a customer management server 5, a license server 6, a remote maintenance server 7, and an update server 8 is provided in the WAN 4. In the following, for simplicity of explanation, as shown in FIG. 4, the customer management server 5 related to license expiration management and the license server 6 are shown, and descriptions of other servers are omitted. Also, as described with reference to FIG. 3 and also shown in FIG. 4, communication between the customer management server 5 and the license server 6 connected to the WAN 4 and the UTM device 1 is performed through the communication I / F 101 of the UTM device 1.

[0046] Furthermore, as described with reference to FIG. 1, PCs 3(1), 3(2), 3(3),..., 3(n) are connected to the UTM device 1 through the LAN 2. In the following, for simplicity of explanation, it is described that the PC 3(1) is an administrator PC used by an administrator, and the other PCs are general employee PCs used by general employees. Also, as described with reference to FIG. 3 and also shown in FIG. 4, communication between the administrator PC 3(1) and the general employee PC 3(2) etc. connected to the LAN 2 and the UTM device 1 is performed through the LAN I / F 107.

[0047] As shown in FIG. 4, the license expiration notification unit 130 includes a license expiration confirmation unit 131, an administrator information acquisition unit 132, a deadline notification screen creation unit 133, a terminal identification information acquisition unit 134, an administrator terminal request detection unit 135, and an administrator terminal notification processing unit 136.

[0048] After the activation process is performed and information indicating authentication permission and authentication information are provided from the license server 6, the license expiration confirmation unit 131 queries the license server 6 for the license information of the own device, for example, at a fixed time every day. In response to the query of the license information, the license expiration date (license expiration period) is returned from the license server 6. The license expiration confirmation unit 131 calculates the remaining days of the license and notifies this to the administrator information acquisition unit 132 and the expiration notice screen creation unit 133. Further, the license expiration confirmation unit 131 notifies the license expiration period acquired from the license server 6 to the expiration notice screen creation unit 133. Note that the remaining days of the license are the number of days from the current date and time acquired from the clock circuit 106 to the license expiration date.

[0049] When the remaining days of the license period from the license expiration confirmation unit 131 are equal to or less than a certain period, the administrator information acquisition unit 132 forms an administrator information query and transmits this to the customer management server 5. The administrator information query includes the MAC address and the manufacturing number stored in the non-volatile memory of the control unit 102. When the customer management server 5 receives the administrator information query from the administrator information acquisition unit 132, it reads out the customer management information corresponding to the MAC address included in the query and transmits this to the UTM device 1.

[0050] The administrator information acquisition unit 132 acquires the administrator's email address from the customer management information from the customer management server 5 and notifies this to the terminal identification information acquisition unit 134. Further, the administrator information acquisition unit 132 extracts the information necessary for forming the expiration notice screen from the customer management information from the customer management server 5 and supplies this to the expiration notice screen creation unit. Here, the information necessary for forming the expiration notice screen is information such as the device SN (Serial Number), the contact information (dealer name), the person in charge, the telephone number, and the email address regarding the inquiry destination.

[0051] When the number of remaining days of the license period from the license expiration confirmation unit 131 is equal to or less than a certain period, the expiration notice screen creation unit 133 creates an expiration notice screen and makes it available for the administrator terminal notification processing unit 136. FIG. 5 is a diagram showing an example of the expiration notice screen created by the expiration notice screen creation unit 133. As shown in FIG. 5, the expiration notice screen has a title display bar indicating that this is the expiration notice screen on the upper end side. In this example, in order to clarify that this is the license expiration notice screen of the UTM device 1, the title "License Expiration Notice Screen" is displayed. Further, as the main information of the license status, it includes the device SN (Serial Number), license expiration date, remaining days (the number of remaining days of the license period), and inquiry destination information.

[0052] The information regarding the device SN and the inquiry destination is the information provided by the administrator information acquisition unit 132. The information regarding the inquiry destination includes the name of the distributor serving as the contact, the name of the person in charge at the distributor, the phone number of the person in charge at the distributor, and the email address of the person in charge at the distributor. Also, the license expiration date and the remaining days (the number of remaining days of the license period) are the information provided by the license expiration confirmation unit 131. With the expiration notice screen shown in FIG. 5, it is possible to clearly notify the administrator that the license expiration date of the UTM device 1 is approaching and that it is necessary to quickly communicate with the distributor side to take some action.

[0053] The terminal identification information acquisition unit 134 monitors the transmitted e-mails sent from each of the PCs 3(1), …, 3(n) connected to the LAN 2. The terminal identification information acquisition unit 134 detects a transmitted e-mail whose sender's e-mail address matches the e-mail address acquired by the administrator information acquisition unit 132. The terminal identification information acquisition unit 134 acquires the terminal identification information of the sender's terminal device from the detected transmitted e-mail and notifies this to the administrator terminal request detection unit 135. In this embodiment, the terminal identification information of the sender's terminal device is the MAC address. That is, the terminal identification information acquisition unit 134 realizes a function of acquiring the MAC address of the administrator PC 3(1) from the e-mail (transmitted e-mail) sent from the administrator PC 3(1) and notifying this to the administrator terminal request detection unit 135.

[0054] The administrator terminal request detection unit 135 monitors the access requests for Web pages sent from each of the PCs 3(1), …, 3(n) connected to the LAN 2. The administrator terminal request detection unit 135 detects an access request for a Web page whose MAC address of the sender's terminal device matches the MAC address from the terminal identification information acquisition unit 134. Assume that the administrator terminal request detection unit 135 has detected an access request for a Web page including the MAC address from the terminal identification information acquisition unit 134. In this case, the administrator terminal request detection unit 135 notifies this to the administrator terminal notification processing unit 136 and waits in a standby state for the transmission of the said access request to the WAN 4. That is, the administrator terminal request detection unit 135 realizes a function of notifying an access request for a Web page from the administrator PC 3(1) to the administrator terminal notification processing unit 136 and waiting in a standby state without transmitting the said access request to the WAN 4.

[0055] When the administrator terminal request detection unit 135 in the administrator terminal notification processing unit 136 detects an access request for a web page including a MAC address that matches the MAC address acquired by the terminal identification information acquisition unit 134, the administrator terminal notification processing unit 136 functions. The administrator terminal notification processing unit 136 provides the expiration notice screen (Fig. 5) created by the expiration notice screen creation unit 133 to the administrator PC 3(1) specified by the MAC address. As a result, when the remaining number of days of the license period of the UTM device 1 becomes equal to or less than a certain number of days, and at the timing when the administrator PC 3(1) sends an access request for a web page, the expiration notice screen can be displayed on the display of the administrator PC 3(1).

[0056] In this way, when the remaining number of days of the license period of the UTM device 1 becomes equal to or less than a certain number of days, the license expiration notice unit 130 can display the expiration notice screen (Fig. 5) at the timing when the administrator is trying to view a web page through the administrator PC 3(1). This prevents oversight such as that which can occur with an email, and also prevents the situation where, even if there is no oversight, one later intends to check the email carefully but forgets to do so.

[0057] When the license expiration notice screen shown in Fig. 5 is displayed on the display of the administrator PC 3(1), the administrator can immediately call the person in charge at the dealership or send an email to start discussions regarding the approaching license expiration. Specifically, discussions can immediately be started regarding specific measures such as whether to replace the UTM device 1 (exchange it), extend the license of the UTM device 1, or stop using and remove the UTM device 1. Of course, it may take time to reach a conclusion, but in any case, discussions with the dealership can be quickly started at the timing when the license expiration of the UTM device 1 is approaching.

[0058] [Operation of the Network System] FIG. 6 and FIG. 7 are sequence diagrams for explaining the operation of the network system centered around the UTM device 1 of the embodiment. The license expiration date confirmation unit 131 of the UTM device 1 periodically makes a license information inquiry to the license server 6 once a day (step S11) and receives a reply of the license expiration date as a result response from the license server 6 (step S12). The license expiration date confirmation unit 131 calculates the remaining license days and notifies this to the administrator information acquisition unit 132 and the expiration notice screen creation unit 133. The license expiration date is notified to the expiration notice screen creation unit 133 for creating the expiration notice screen.

[0059] When the remaining license days of the UTM device 1 are equal to or less than a certain number of days, the administrator information acquisition unit 132 of the UTM device 1 makes a user administrator information inquiry including its own MAC address to the customer management server 5 (step S13). The administrator information acquisition unit 132 acquires the user administrator information provided from the customer management server 5 (step S14). The user administrator information includes information such as the administrator's email address, device SN (Serial Number), information regarding the inquiry destination, reseller name, reseller staff, reseller staff's phone number, and reseller staff's email address. The administrator information acquisition unit 132 notifies the administrator email address to the terminal identification information acquisition unit 134 and notifies the device SN (Serial Number) and the information regarding the inquiry destination to the expiration notice screen creation unit 133.

[0060] When the remaining license days of the UTM device 1 are equal to or less than a certain number of days, the expiration notice screen creation unit 133 of the UTM device 1 creates an expiration notice screen and makes this available for the administrator terminal notification processing unit 136 (step S15). Making it available for the administrator terminal notification processing unit 136 means storing the created expiration notice screen in a memory that can be read by the administrator terminal notification processing unit 136. The memory may be a memory within the expiration notice screen creation unit 133, a memory within the administrator terminal notification processing unit 136, or a predetermined area of the storage device 103.

[0061] On the one hand, the terminal identification information acquisition unit 134 starts monitoring the sent e-mail based on the administrator e-mail address from the administrator information acquisition unit 132 (step S16). After that, it is assumed that the administrator of the UTM device 1 starts the mailer on the administrator PC3(1) he uses (step S17) and sends an e-mail to the intended recipient (step S18). The terminal identification information acquisition unit 134 has started monitoring the sent e-mail in step S16. When the e-mail address of the sender of the sent e-mail matches the administrator e-mail address from the administrator information acquisition unit 132, the terminal identification information acquisition unit 134 identifies the MAC address of the sender included in the sent e-mail (step S19). In step S19, the terminal identification information acquisition unit 134 notifies the administrator terminal request detection unit 135 of the identified MAC address of the sender, that is, the MAC address of the administrator PC3(1). Thereby, the administrator terminal request detection unit 135 starts monitoring the access requests for web pages from the subordinate terminal devices (step S20).

[0062] After that, it is assumed that the administrator of the UTM device 1 starts the browser on the administrator PC3(1) he uses (step S21) and sends an access request for a web page (home page request) (step S22). The administrator terminal request detection unit 135 has started monitoring the access requests for web pages in step S20. When the MAC address included in the access request for the web page matches the MAC address of the administrator PC3(1) from the terminal identification information acquisition unit 134, the administrator terminal request detection unit 135 notifies the MAC address to the administrator terminal notification processing unit 136 (step S23). Also, in step S23, the administrator terminal request detection unit 135 puts the access request for the web page from the administrator PC(1) in a standby state without sending it to the WAN4.

[0063] When the administrator terminal notification processing unit 136 receives the provision of the MAC address from the administrator terminal request detection unit 135, it provides the expiration notification screen created by the expiration notification screen creation unit 133 to the administrator PC 3(1) specified by the MAC address (step S24). As a result, the expiration notification screen described with reference to FIG. 5 is provided to the administrator PC 3(1) (step S25) and is displayed on the display of the administrator PC 3(1) (step S26). The administrator using the administrator PC 3(1) can check the display content of the expiration notification screen (FIG. 5) displayed on the display of the administrator PC 3(1) that he / she uses and can take appropriate measures before the expiration of the license period. That is, the administrator can start discussions with the person in charge at the dealership regarding the use of the UTM device 1 whose expiration is approaching by, for example, calling the person in charge at the dealership or sending an email.

[0064] After that, when the administrator selects the "OK button" displayed at the upper right end of the expiration notification screen displayed on the display of the administrator PC 3(1), information indicating that the "OK button" has been selected is transmitted to the UTM device 1 through the LAN 2 (step S27). When the information indicating that the "OK button" has been selected is transmitted, the administrator terminal request detection unit 135 detects this and sends out a Web page access request (home screen request) from the waiting administrator PC 3(1) to the WAN 4 (step S28). The Web page access request reaches the site that provides the target Web page, and the Web page (home screen) corresponding to the request is provided from the site (step S29). The Web page (home screen) is provided to the requesting administrator PC 3(1) via the UTM device 1 (step S30) and is displayed on the display of the administrator PC 3(1) (step S31).

[0065] In this way, when the administrator sends an access request for a web page at the timing when the administrator is viewing the display using the administrator PC3(1), the expiration notice screen is displayed on the display of the administrator PC3(1). As a result, the administrator can surely view the expiration notice screen through the display of the administrator PC3(1) that the administrator uses at an appropriate timing. Also, the expiration notice screen is not provided to the general employee PCs 3(2), 3(3), …, 3(n) other than the administrator PC3(1). Therefore, it does not affect the operations performed using the general employee PCs 3(2), 3(3), …, 3(n).

[0066] [Effects of the Embodiment] Since the expiration notice screen can be directly provided to the administrator on the user side who uses the UTM device 1, the administrator on the user side can surely grasp the license expiration date of the UTM device 1 and take appropriate measures. That is, the user side of the license of the UTM device 1 can surely know that the license expiration date is approaching, and the risk of operating with an expired license can be reduced. Also, since the expiration notice screen is not provided to the general employee PCs 3(2) to 3(n) used by general employees other than the administrator, it does not interfere with the work of general employees.

[0067] Furthermore, from the perspective of the sales store side of the UTM device 1, the sales store side does not need to substantially manage the license expiration date of the UTM device 1 and only needs to respond when there is an inquiry from the user. Therefore, the burden on the sales store side of the UTM device 1 is reduced. Accordingly, a system can be established to respond quickly and appropriately to inquiries from users.

[0068] [Modification Example] Note that in the above-described embodiment, the administrator information acquisition unit 132 and the expiration notice screen creation unit 133 have been described as functioning when the remaining license days are less than a certain period. In this case, when measures such as an extension are taken for the license period, the display of the expiration notice screen can be prevented from being performed.

[0069] Also, the fixed period is not limited to one. As the fixed period, three types of periods such as three months, one month, and ten days are defined, and the comparison order is determined in advance as three months → one month → ten days. Thus, first, since the first comparison target period is "three months", first, when the license remaining period becomes three months or less, the first deadline notification screen is provided. Next, since the comparison target period becomes "one month", the second deadline notification screen is provided two months after the provision of the first deadline notification screen. Finally, since the comparison target period becomes "ten days", the third deadline notification screen is provided twenty days after the provision of the second deadline notification screen.

[0070] In this way, it is also possible to provide the deadline notification screen by determining a plurality of provision timings. Even in this case, after the license period extension procedure is taken, since the license deadline is extended, the provision of the deadline notification screen is no longer performed. Also, the fixed period is not limited to the above example, and the fixed period for comparison with the license remaining days can be determined as appropriate numbers and appropriate periods such as six months, five months, four months,....

[0071] Also, in the above-described embodiment, the UTM device 1 queries the license server 6 about its own license information every day, but it is not limited to this. For example, until the license remaining days become four months or less, the license server 6 is queried about its own license information at a timing of once a month. If the license remaining days become four months or less, it is also possible to query the license server 6 about its own license information every day. That is, the cycle for querying the license server 6 about its own license information can be determined according to the license remaining days. Of course, the cycle for querying the license server 6 about its own license information can also be determined as an appropriate cycle such as every day, once every two days, once every three days, once a week, once every two weeks, etc.

[0072] In the above-described embodiment, the administrator information acquisition unit 132 acquires customer management information from the customer management server 5. However, this is not the only way. For example, the storage device 103 of the UTM device 1 may also store customer management information similar to that of the customer management server 5, and the customer management information of this storage device 103 may be acquired. However, since the customer management server 5 is appropriately managed by the manufacturer side, the latest and accurate information can be provided in any case when the information of the dealer changes.

[0073] Also, it is considered that the administrator on the user side may change. For this reason, the customer management server 5 periodically sends an email to the administrator on the user side, and when a change occurs to the administrator or when a change occurs to the administrator's information, it guides the user to change the customer management information of the customer management server 5. Thereby, even if a change occurs on the user side, it is possible to respond. Of course, when a change occurs to the administrator or when a change occurs to the administrator's information, for example, when a person in charge of the dealer visits regularly, new information can also be used to change the customer management information of the customer management server 5 through the dealer PC 9.

[0074] Also, when providing the expiration screen through the display of the administrator PC 3(1), it is also possible to emit a warning sound (alarm sound) or emit a message voice such as "The license expiration date of the UTM device 1 is approaching." Of course, it is also possible to display a notification of the arrival of the license expiration date on the display screen of the UTM device 1 or output a notification sound or a notification message from the UTM device 1.

[0075] Also, the expiration notification screen is not limited to that described with reference to FIG. 5. Various expiration notification screens having various display contents for notifying the arrival of the license expiration date of the UTM device 1 can be formed and used. For example, as described above, when the remaining license days are 3 months ago, 1 month ago, and 10 days ago, it is possible to display or emit a message that more strongly urges a response as the remaining days decrease.

[0076] Also, in the above-described embodiment, the MAC address is used as the terminal identification information, but it is not limited to this. Any information included in the transmitted e-mail or the access request for the web page that can individually identify the source terminal device can be used. For example, if the product SN (Serial Number) is included in the transmitted e-mail or the access request for the web page and can be utilized, the product SN (Serial Number) can be used as the terminal identification information. Also, if the IP address is included in the transmitted e-mail or the access request for the web page and can be utilized, the IP address can be used as the terminal identification information. That is, the terminal identification information only needs to be information that can uniquely identify the terminal device under the UTM device 1 connected to the LAN2 and enables the designation of the transmission destination of the expiration notice screen.

[0077] Also, in the above-described embodiment, the customer management server 5, the license server 6, the remote maintenance server 7, and the update server 8 are described as existing, but it is not limited to this. For example, a server having the combined functions of the customer management server 5 and the license server 6 and a server having the combined functions of the remote maintenance server 7 and the update server 8 can also constitute a server group (cloud system) operated by the manufacturer side of the UTM device 1. That is, the number of servers is not the issue. As long as a cloud system operated by the manufacturer side is constructed by one or more servers having the functions of each of the customer management server 5, the license server 6, the remote maintenance server 7, and the update server 8, it is sufficient.

[0078] In addition, in the above-described embodiments, the PCs 3(1), 3(2), 3(3), …, 3(n) connected to the UTM device 1 via the LAN 2 are shown as being wired-connected, but this is not restrictive. A wireless communication terminal connected to the UTM device 1 through an access point connected to the LAN 2 may of course be connected to the UTM device 1.

[0079] Also, in the above-described embodiments, the case where the relay device is the UTM device 1 has been described as an example, but this is not restrictive. The present invention can be applied to various relay devices such as a gateway device that relays between a WAN and a LAN to which a plurality of terminal devices are connected.

[0080] In addition, in the above-described embodiments, the time point when the license server 6 receives an activation request and provides authentication information to the UTM device 1 is defined as the completion time point of the activation process, and the license period is determined based on this reference point. However, this is not restrictive. For example, it is also possible to define the license period based on the time point when the activation process is properly performed and the UTM device 1 first receives the provision of the latest software from the update server 8 as a reference point. In this case, the UTM device 1 notifies the license server 6 that it has received the provision of the latest software, enabling management by the license server 6.

Description of Reference Numerals

[0081] 1…UTM device, 101T…connection terminal, 101…communication I / F, 102…control unit, 103…memory device, 104…operation unit, 105…address DB, 106…clock circuit, 107T…connection terminal, 107…LAN I / F, 110…security function unit, 120…proper operation unit, 121…maintenance server connection unit, 122…activation request unit, 123…signature update unit, 130…license expiration notification unit, 131…license expiration confirmation unit, 132…administrator information acquisition unit, 133…screen creation unit for expiration notification, 134…terminal identification information acquisition unit, 135…administrator terminal request detection unit, 136…administrator terminal notification processing unit, 2…LAN, 3(1)…administrator PC, 3(1), 3(2), 3(3), …, 3(n)…general employee PC, 4…WAN, 5…customer management server, 6…license server, 7…remote maintenance server, 8…update server, 9…dealer PC

Claims

1. A relay device that relays between a wide area network and a LAN (Local Area Network), a license period confirmation means for making an inquiry to a license server connected to the wide area network at a predetermined timing and confirming the license period of the own device; an administrator information acquisition means for acquiring the email address of the administrator of the own device when the period from the current time to the expiration date of the license period confirmed by the license period confirmation means is equal to or less than a certain period; a due date notification screen creation means for forming a due date notification screen when the period from the current time to the expiration date of the license period confirmed by the license period confirmation means is equal to or less than the certain period; a terminal identification information acquisition means for monitoring an outgoing email from a terminal device connected to the LAN and acquiring the terminal identification information of the source terminal device from an outgoing email whose source email address matches the email address of the administrator; an administrator terminal request detection means for monitoring an access request for a web page from a terminal device connected to the LAN and detecting an access request for a web page whose source terminal identification information matches the terminal identification information acquired by the terminal identification information acquisition means; an administrator terminal notification processing means for providing the due date notification screen created by the due date notification screen creation means to the terminal device specified by the terminal identification information when an access request for a web page that matches the terminal identification information acquired by the terminal identification information acquisition means is detected by the administrator terminal request detection means A relay device characterized by comprising the above.

2. The relay device according to claim 1, an access request sending means for sending the access request for the web page detected by the administrator terminal request detection means to the wide area network when a predetermined confirmation response is sent from the terminal device specified by the terminal identification information acquired by the terminal identification information acquisition means after the due date notification screen is provided by the administrator terminal notification processing means A relay device characterized by comprising the above.

3. The relay device according to claim 1, wherein the administrator information acquisition means makes an inquiry to a customer management server connected to the wide area network and acquires the email address of the administrator A relay device characterized by the above.

4. The relay device according to any one of Claims 1 to 3, wherein a plurality of fixed periods having different periods are provided as the fixed period used by the due date notification screen creating means and the administrator information acquiring means, and the due date notification screen creating means and the administrator information acquiring means function when the period from the current time to the expiration date of the license period confirmed by the license period confirmation means is equal to or less than any one of the fixed periods. A relay device characterized by the above.

Citation Information

Patent Citations

  • Information processing apparatus and license management method

    JP2022112276A