Access management apparatus, communication apparatus, access management system, access management method, access management program, communication method, and communication program
The access management device enables secure, time-limited communication with the cloud by using cloud-side time and authentication information to prevent unauthorized access, addressing the lack of time-specific communication in existing systems.
Patent Information
- Application Number
- JP2024050664
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-27
- Publication Date
- 2025-10-09
- Estimated Expiration
- 2044-03-27
AI Technical Summary
Existing systems for offloading computational processing to the cloud lack the ability to set specific times for file data communication with the cloud for each user, compromising security against unauthorized access.
An access management device that includes a storage unit for cloud-side time information and authentication information, a gate control unit to permit communication within specified times, and update these settings to enhance security by limiting access to designated times for each user.
This solution allows for secure, time-limited access management, preventing unauthorized access by continuously updating authentication and communication times for each user, thereby enhancing security in cloud-based systems.
Smart Images

Figure 2025150021000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an access management device, a communication device, an access management system, an access management method, an access management program, a communication method, and a communication program. [Background technology]
[0002] The system configuration commonly adopted in systems that offload computational processing to the cloud involves collecting raw data in an on-premises environment, uploading the collected raw data to the cloud, performing calculations using the raw data in the cloud, and then returning the calculation results to the on-premises environment. Raw data is the data collected on-site and is data before any computational processing is performed. In the manufacturing industry in particular, raw data can be used to infer the status of production activities, so it is important to prevent raw data from being leaked to malicious parties. Therefore, when adopting this system configuration, the key point is how to ensure security to prevent unauthorized access to the cloud. Generally, authentication information consisting of multiple character strings (for example, ID and password) is exchanged to determine whether the accessing party is legitimate or not. Patent Document 1 discloses a technique for further strengthening security by registering time information as an access permission condition for a management server. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] International Publication No. 2015-141354 Brochure Summary of the Invention [Problem to be solved by the invention]
[0004] The technology disclosed in Patent Document 1 has a problem in that it is not possible to set the time during which file data can be communicated with the cloud for each user. The present disclosure aims to enable each user to set the time during which file data can be communicated with the cloud. [Means for solving the problem]
[0005] The access management device according to the present disclosure comprises: An access management device that executes file data communication with a target device, a storage unit that stores cloud-side time information indicating a time during which the target device is permitted to communicate file data, and cloud-side authentication information that is authentication information corresponding to the target device; When the time indicated by the cloud-side time information is set as a target time, at the target time, the target device is permitted to communicate file data with the access management device based on the cloud-side authentication information, and the time indicated by the cloud-side time information is updated from the target time to an updated target time, which is the time when the target device will next be permitted to communicate file data with the access management device; a gate control unit that does not permit the target device to communicate file data with the access management device from the end time of the target time until the start time of the updated target time; Equipped with. [Effects of the Invention]
[0006] According to the present disclosure, the gate control unit permits the target device to communicate file data with the access management device based on the cloud-side authentication information during the target time, and updates the time indicated by the cloud-side time information from the target time to the updated target time. The gate control unit also does not permit the target device to communicate file data with the access management device from the end time of the target time to the start time of the updated target time. Here, the target time and the updated target time may be set for each user. The access management device may also be a device constituting a cloud. Therefore, according to the present disclosure, it is possible to set the time during which file data can be communicated with the cloud for each user. [Brief explanation of the drawings]
[0007] [Figure 1] 1 is a diagram showing an example of the configuration of an access management system 90 according to a first embodiment. [Figure 2] 1 is a diagram showing an example of the configuration of an access management system 90 according to a first embodiment. [Figure 3] 1 is a diagram showing an example of the hardware configuration of a device 100 according to a first embodiment. [Figure 4] 6 is a flowchart showing the operation of the access management system 90 during uploading according to the first embodiment. [Figure 5] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 6] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 7] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 8] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 9] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 10] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 11] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 12] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during upload according to the first embodiment. [Figure 13] 6 is a flowchart showing the operation of the access management system 90 during downloading according to the first embodiment. [Figure 14] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 15] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 16] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 17] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 18] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 19] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 20] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 21] FIG. 4 is a diagram for explaining the state and processing of the access management system 90 during downloading according to the first embodiment. [Figure 22] FIG. 10 is a diagram showing an example of the hardware configuration of a device 100 according to a modification of the first embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0008] In the description of the embodiments and the drawings, the same elements and corresponding elements are given the same reference numerals. The description of elements given the same reference numerals will be omitted or simplified as appropriate. Arrows in the drawings mainly indicate the flow of data or the flow of processing. Furthermore, "unit" may be read as "circuit," "step," "procedure," "process," or "circuitry" as appropriate.
[0009] Embodiment 1 Hereinafter, this embodiment will be described in detail with reference to the drawings.
[0010] ***Configuration Description*** 1 shows an example of the configuration of an access management system 90 according to this embodiment and an outline of the operation of the access management system 90 within a specified time period. As shown in FIG. 1, the access management system 90 includes a device 100 and a cloud 200. The access management system 90 may include multiple devices 100. As shown in FIG. 1, the device 100 can communicate file data with the cloud 200 within a specified time period.
[0011] The device 100 is a piece of equipment operated by a user, and specific examples thereof include a PC (Personal Computer), an on-premise server, or a smartphone. The device 100 corresponds to a communication device. Each device 100 corresponds to a target device. The device 100 includes an upload unit 110, a download unit 120, and a storage unit 190. The storage unit 190 stores cloud authentication information 101 and a scheduled transmission / reception time 102 .
[0012] The cloud authentication information 101 is authentication information used when the device 100 accesses the cloud 200. As the cloud authentication information 101, authentication information for the upload unit 110 and authentication information for the download unit 120 may be prepared. Each piece of information may be data in a file format. The cloud authentication information 101 corresponds to the user-side authentication information. The user-side authentication information is authentication information corresponding to the cloud-side authentication information. The cloud-side authentication information is authentication information for authenticating communication between the access management device and the communication device. The access management device is a device that constitutes the cloud 200, and is a device that executes communication of file data with the target device. The communication of file data is at least one of sending file data and receiving file data. File data may also be simply referred to as a file.
[0013] The scheduled transmission / reception time 102 is information indicating the next time when the device 100 is permitted to communicate file data with the cloud 200 . A specific example of the scheduled transmission / reception time 102 is a text file. When the scheduled transmission / reception time 102 is a text file, the time indicated by the scheduled transmission / reception time 102 is, for example, the date and time or time range recorded in the text file for each upload and download. The scheduled transmission / reception time 102 may also be data in a format other than a text file. The time indicated by the scheduled transmission / reception time 102 corresponds to a specified time. As a specific example, the scheduled transmission / reception time 102 indicates at least one of an available upload time and an available download time. The scheduled transmission / reception time 102 may be different for each device 100. Note that the time may be interpreted as a time period as appropriate. The scheduled transmission / reception time 102 corresponds to user-side time information. The user-side time information indicates the time during which the access management device is permitted to transmit file data via the communication device. When the time indicated by the user-side time information is defined as the user-side target time, the user-side target time may be either the upload-enabled time or the download-enabled time. The upload allowed time is the time during which the target device is permitted to upload file data to the access management device, that is, the time during which the device 100 can upload a file to the cloud 200. The downloadable time is the time during which the target device is permitted to download file data from the access management device, that is, the time during which the device 100 can download the file from the cloud 200. The designated time exists for each device 100. The designated time is a general term for the time when uploading is possible and the time when downloading is possible. The time when uploading is possible and the time when downloading is possible do not have to overlap. Data is exchanged between the device 100 and the cloud 200 by the upload unit 110 and the download unit 120 accessing each shared folder provided in the cloud 200. The upload unit 110 and the download unit 120 may be configured integrally.
[0014] When the user-side target time is the upload-allowed time, the upload unit 110 uses the user-side authentication information to request permission to upload file data to the access management device at the user-side target time. When uploading file data to the access management device is permitted, the upload unit 110 uploads the file data to the access management device and determines the next upload time as the updated target time. Thereafter, the upload unit 110 updates the time indicated by the user-side time information from the user-side target time to the determined next upload time and notifies the access management device of the determined next upload time. The next upload time is the time when file data will next be uploaded to the access management device. The updated target time is the time when the communication device will next be permitted to communicate file data to the access management device. When the user-side target time is the upload-enabled time and the upload unit 110 is notified of updated authentication information from the access management device at the user-side target time, the upload unit 110 updates the user-side authentication information to first updated authentication information based on the updated authentication information. Furthermore, at the next upload time, the upload unit 110 uses the first updated authentication information to request permission to upload file data from the access management device. The updated authentication information is authentication information generated by updating the cloud-side authentication information. As a specific example, the upload unit 110 has an upload folder and also has a function of uploading various files to the cloud 200. A program that realizes this function is also called an upload program. The upload folder is a folder that stores files to be uploaded to the cloud 200. A specific example of the uploaded file is a file that indicates data to be processed, calculated, or the like in the cloud 200.
[0015] When the user-side target time is the download-allowed time, the download unit 120 requests permission to download file data from the access management device using the user-side authentication information at the user-side target time. When downloading file data to the access management device is permitted, the download unit 120 downloads the file data from the access management device and determines the next download time as the updated target time. Thereafter, the download unit 120 updates the time indicated by the user-side time information to the next download time determined from the user-side target time and notifies the access management device of the determined next download time. The next download time is the time when file data will next be downloaded from the access management device. When the user-side target time is the downloadable time and the download unit 120 is notified of updated authentication information from the access management device during the user-side target time, the download unit 120 updates the user-side authentication information to second updated authentication information based on the updated authentication information. Furthermore, at the next download time, the download unit 120 requests permission to download file data from the access management device using the second updated authentication information. As a specific example, the download unit 120 has a download folder and also has a function of downloading various files from the cloud 200. A program that realizes this function is also called a download program. The download folder is a folder that stores files downloaded from the cloud 200. A specific example of the downloaded file is a file that indicates the results of processing raw data in the cloud 200.
[0016] The cloud 200 is a device that constitutes a cloud server or a cloud system. As a specific example, the cloud 200 is a device that constitutes AWS (registered trademark, Amazon Web Services). The cloud 200 corresponds to an access management device. The cloud 200 includes a gate control unit 210 , a data processing unit 220 , an upload shared folder unit 230 , a download shared folder unit 240 , and a storage unit 290 . The storage unit 290 stores cloud authentication information 201 and a scheduled transmission / reception time 202 .
[0017] The cloud authentication information 201 is authentication information corresponding to the cloud authentication information 101, and is authentication information used to determine whether or not to permit each device 100 to access the cloud 200. The cloud authentication information 201 may be prepared for each device 100. As the cloud authentication information 201, authentication information for uploading files and authentication information for downloading files may be prepared. Cloud authentication information 201 corresponds to cloud-side authentication information, which is authentication information corresponding to the target device.
[0018] The scheduled transmission / reception time 202 is information corresponding to the scheduled transmission / reception time 102, and indicates, for each device 100, the next time when the device 100 is permitted to communicate file data with the cloud 200. The time indicated by the scheduled transmission / reception time 202 corresponds to the specified time. The scheduled transmission / reception time 202 corresponds to cloud-side time information, which indicates the time during which the target device is permitted to communicate file data.
[0019] When the time indicated by the cloud-side time information is set as the target time, the gate control unit 210 permits the target device to communicate file data with the access management device at the target time based on the cloud-side authentication information, and updates the time indicated by the cloud-side time information from the target time to the updated target time. The updated target time is the time when the target device will next be permitted to communicate file data with the access management device. The updated target time may be a time determined randomly within the target time range. The target time range may be any time range. The target time may be either the upload-enabled time or the download-enabled time. The gate control unit 210 does not permit the target device to communicate file data with the access management device from the end time of the target time to the start time of the updated target time. The updated target time may be the time notified by the target device. When the target time is an upload-allowed time, the gate control unit 210 permits the target device to upload file data to the access management device based on the cloud-side authentication information during the target time, and sets the updated target time as the next time when the target device will be permitted to upload file data to the access management device. Furthermore, the gate control unit 210 does not permit the target device to upload file data to the access management device from the end time of the target time to the start time of the updated target time. When the target time is a download-allowed time, the gate control unit 210 permits the target device to download file data from the access management device based on the cloud-side authentication information during the target time, and sets the updated target time as the time when the target device will next be permitted to download file data from the access management device. Furthermore, the gate control unit 210 does not permit the target device to download file data from the access management device from the end time of the target time until the start time of the updated target time. The gate control unit 210 updates the authentication information indicated by the cloud-side authentication information to updated authentication information at the target time, and notifies the target device of the updated authentication information. Furthermore, the gate control unit 210 permits the target device to communicate file data with the access management device based on the updated authentication information at the post-update target time. As a specific example, the gate control unit 210 controls external access based on the cloud authentication information 201. Furthermore, the gate control unit 210 has a function of controlling the time during which each shared folder in the cloud 200 can be accessed from outside, based on the scheduled transmission / reception time 202. Outside of that time, even if the user or device 100 has access authority to the cloud 200, the gate control unit 210 denies the user or device 100 access to the cloud 200. The functions of the gate control unit 210 are specifically realized by a gate control program.
[0020] The data processing unit 220 executes data processing using the data uploaded to the upload shared folder unit 230, and stores data indicating the execution result of the data processing in the download shared folder unit 240. The data processing unit 220 may execute data processing on a company-by-company or product-by-product basis.
[0021] The upload shared folder section 230 is made up of an upload shared folder that stores files uploaded by the upload section 110 .
[0022] The download shared folder section 240 is made up of a download shared folder that stores files requested by the download section 120 .
[0023] FIG. 2 shows an example of the configuration of the access control system 90 and an outline of the operation of the access control system 90 outside of designated hours. The period outside the designated time is a period that is not within the designated time. For example, the period outside the designated time is a period that is neither an uploadable time nor a downloadable time. Outside the designated time, the gate control unit 210 does not permit access from the device 100. Outside the designated time, the gate control unit 210 does not have to permit only one of the device 100 to upload file data or the device 100 to download file data.
[0024] 3 shows an example of the hardware configuration of the device 100 according to this embodiment. The device 100 is made up of a computer. The device 100 may also be made up of multiple computers.
[0025] As shown in the figure, the device 100 is a computer including hardware such as a processor 11, a memory 12, an auxiliary storage device 13, an input / output IF (Interface) 14, and a communication device 15. These pieces of hardware are appropriately connected via signal lines 19.
[0026] The processor 11 is an integrated circuit (IC) that performs arithmetic processing and controls the hardware of the computer. Specific examples of the processor 11 include a central processing unit (CPU), a digital signal processor (DSP), or a graphics processing unit (GPU). The device 100 may include multiple processors that replace the processor 11. The multiple processors share the role of the processor 11.
[0027] The memory 12 is typically a volatile storage device, specifically a random access memory (RAM). The memory 12 is also called a primary storage device or a main memory. Data stored in the memory 12 is saved in the secondary storage device 13 as needed.
[0028] The auxiliary storage device 13 is typically a non-volatile storage device, and specific examples thereof include a ROM (Read Only Memory), an HDD (Hard Disk Drive), or a flash memory. Data stored in the auxiliary storage device 13 is loaded into the memory 12 as needed. The memory 12 and the auxiliary storage device 13 may be integrated into one unit.
[0029] The input / output IF 14 is a port to which an input device and an output device are connected. A specific example of the input / output IF 14 is a USB (Universal Serial Bus) terminal. Specific examples of the input device are a keyboard and a mouse. A specific example of the output device is a display.
[0030] The communication device 15 is a receiver and a transmitter, and is, for example, a communication chip or a network interface card (NIC).
[0031] Each unit of the device 100 may use the input / output IF 14 and the communication unit 15 as appropriate when communicating with other devices.
[0032] The auxiliary storage device 13 stores a communication program. The communication program is a program that causes a computer to realize the functions of each unit included in the device 100. The communication program is loaded into the memory 12 and executed by the processor 11. The functions of each unit included in the device 100 are realized by software.
[0033] Data used when executing the communication program and data obtained by executing the communication program are stored in a storage device as appropriate. Each part of the device 100 uses a storage device as appropriate. Specific examples of the storage device include at least one of the memory 12, the auxiliary storage device 13, a register in the processor 11, and a cache memory in the processor 11. Note that the terms "data" and "information" may have the same meaning. The storage device may be independent of the computer. The functions of the memory 12 and the auxiliary storage device 13 may be realized by other storage devices.
[0034] The communication program may be recorded on a computer-readable non-volatile recording medium. Specific examples of the non-volatile recording medium include an optical disk and a flash memory. The communication program may be provided as a program product. The hardware configuration of the cloud 200 is the same as the hardware configuration of the device 100. The storage unit 190 and the storage unit 290 are each realized by a storage device. The above explanation regarding the "communication program" also applies to the "access management program."
[0035] ***Explanation of Operation*** The operating procedures of the devices included in the access management system 90 are collectively called an access management method. The programs that realize the operations of the devices included in the access management system 90 are collectively called access management programs. The operation procedure of the device 100 is called a communication method. The programs that realize the operation of the device 100 are collectively called communication programs.
[0036] 4 is a flowchart showing an example of the operation of the access management system 90 during uploading. This operation will be explained using Fig. 4. In explaining this flowchart, the operation of the device 100 will be explained as the operation of the target device, which is the device 100.
[0037] (Step S101) FIG. 5 is a diagram for explaining the state and processing of the access management system 90 in this step. The target device stores an “upload program” for uploading the target file to the cloud 200, as well as preset cloud authentication information 101 and estimated transmission / reception time 102. The cloud 200 stores cloud authentication information 201 corresponding to the cloud authentication information 101 and a scheduled transmission / reception time 202 corresponding to the scheduled transmission / reception time 102. As a specific example, the "cloud authentication information" describes two types of character strings required for accessing the cloud 200. In this example, only when both of the two types of character strings indicated by the "cloud authentication information" match between the target device and the cloud 200, it is determined that "the upload unit 110 has the right to access the shared upload folder." The "scheduled transmission / reception time" indicates the next available time for uploading. In this step, the scheduled transmission / reception time 102 indicates the target time on the user side. The scheduled transmission / reception time 202 indicates the target time.
[0038] (Step S102) FIG. 6 is a diagram illustrating the state and processing of the access management system 90 in this step. The user stores the file to be uploaded to the cloud 200 in the upload folder of the target device. The upload unit 110 and the gate control unit 210 each operate periodically, and execute the process of step S103 when the time on each system reaches the start time of the upload-enabled time indicated by the "scheduled transmission / reception time."
[0039] (Step S103) FIG. 7 is a diagram for explaining the state and processing of the access management system 90 in this step. The upload unit 110 reads the cloud authentication information 101 . The gate control unit 210 removes the access restriction on the upload shared folder unit 230, which is based on the upload allowable time.
[0040] (Step S104) FIG. 8 is a diagram for explaining the state and processing of the access management system 90 in this step. The upload unit 110 accesses the upload shared folder unit 230 based on the read cloud authentication information 101 . If the cloud authentication information 101 and the cloud authentication information 201 match, the gate control unit 210 permits the upload unit 110 to access the upload shared folder unit 230. After that, the process of step S105 is executed. If the cloud authentication information 101 and the cloud authentication information 201 do not match, the gate control unit 210 denies access by the upload unit 110 .
[0041] (Step S105) FIG. 9 is a diagram illustrating the state and processing of the access management system 90 in this step. The upload unit 110 uploads each file in an upload folder provided in the upload unit 110 to the upload shared folder unit 230.
[0042] (Step S106) FIG. 10 is a diagram for explaining the state and processing of the access management system 90 in this step. The upload unit 110 updates the available upload time indicated by the scheduled transmission / reception time 102 and transmits data indicating the updated available upload time to the cloud 200. At this time, the upload unit 110 may automatically update the available upload time, or may update the start time and duration of the available upload time. The updated available upload time corresponds to the next upload time and the target time after update. The gate control unit 210 receives the data indicating the updated available upload time, and updates the scheduled transmission / reception time 202 based on the received data. Here, the upload unit 110 may set the uploadable time as a random time within a certain time range, with the aim of preventing malicious parties from identifying the uploadable time. As a specific example, the upload unit 110 may set the period from 1:00 PM to 5:00 PM, and set the start time of the uploadable time as a random time in 10-minute increments. As a specific example, the upload unit 110 may set the start time of the uploadable time at 2:20 PM at one time and at 4:40 PM at another time.
[0043] (Step S107) FIG. 11 is a diagram for explaining the state and processing of the access management system 90 in this step. The gate control unit 210 operates periodically, and when it detects that the available upload time indicated by the estimated transmission / reception time 202 has been updated, it updates the cloud authentication information 201 and places a "cloud authentication information" file, which is file format data indicating the updated cloud authentication information 201, in the upload shared folder unit 230. Note that placing the "cloud authentication information" file in the upload shared folder unit 230 corresponds to notifying the target device of the updated authentication information. The "cloud authentication information" corresponds to the updated authentication information and also corresponds to the first updated authentication information. The upload unit 110 operates periodically, and when it detects that a "cloud authentication information" file has been placed in the upload shared folder unit 230, it overwrites and updates the cloud authentication information 101 based on the "cloud authentication information" file.
[0044] (Step S108) FIG. 12 is a diagram for explaining the state and processing of the access management system 90 in this step. The gate control unit 210 restricts access to the upload shared folder unit 230 at the end of the upload-enabled time. After that, the process proceeds to step S101. In step S101 after the transition, the "cloud authentication information" and the "scheduled transmission / reception time" have been updated.
[0045] Fig. 13 is a flowchart showing an example of the operation of the access management system 90 at the time of downloading. This operation will be explained using Fig. 13. In explaining this flowchart, the operation of the device 100 will be explained as the operation of the target device, which is the device 100.
[0046] (Step S201) 14 is a diagram for explaining the state and processing of the access control system 90 in this step. This step is similar to step S101. The target device stores a "download program" for downloading the target file from the cloud 200, as well as pre-set cloud authentication information 101 and scheduled transmission / reception time 102. The cloud 200 stores cloud authentication information 201 corresponding to the cloud authentication information 101 and a scheduled transmission / reception time 202 corresponding to the scheduled transmission / reception time 102. The "cloud authentication information" is as described above, and is used to determine whether the download unit 120 has the right to access the shared folder for downloads. The "Scheduled Transmission / Reception Time" field indicates the next available time for downloading.
[0047] (Step S202) FIG. 15 is a diagram for explaining the state and processing of the access management system 90 in this step. The download unit 120 and the gate control unit 210 each operate periodically, and execute the process of step S203 when the time on each system reaches the start time of the downloadable time indicated by the "scheduled transmission / reception time." The data processing unit 220 stores each download file in the download shared folder unit 240 by the start time of the downloadable period. Each download file may be a file corresponding to each uploaded file, or may be a file specified by the user. Note that the data processing unit 220 can operate files in the cloud 200 even when access is restricted.
[0048] (Step S203) FIG. 16 is a diagram illustrating the state and processing of the access management system 90 in this step. The download unit 120 reads the cloud authentication information 101 . The gate control unit 210 removes the access restriction on the download shared folder unit 240, which is based on the downloadable time.
[0049] (Step S204) FIG. 17 is a diagram illustrating the state and processing of the access management system 90 in this step. If the cloud authentication information 101 and the cloud authentication information 201 match, the gate control unit 210 permits the download unit 120 to access the download shared folder unit 240. After that, the process of step S205 is executed. If the cloud authentication information 101 and the cloud authentication information 201 do not match, the gate control unit 210 denies the access by the download unit 120 .
[0050] (Step S205) FIG. 18 is a diagram for explaining the state and processing of the access management system 90 in this step. The download unit 120 downloads each file in the download shared folder unit 240 to a download folder provided in the download unit 120.
[0051] (Step S206) 19 is a diagram for explaining the state and processing of the access management system 90 in this step. This step is similar to step S106. The download unit 120 updates the downloadable time indicated by the scheduled transmission / reception time 102, and transmits data indicating the updated downloadable time to the cloud 200. The updated downloadable time corresponds to the next download time and also corresponds to the post-update target time. The gate control unit 210 receives the data indicating the updated downloadable time, and updates the estimated transmission / reception time 202 based on the received data.
[0052] (Step S207) 20 is a diagram for explaining the state and processing of the access control system 90 in this step. This step is similar to step S107. Gate control unit 210 operates periodically, and when it detects that the downloadable time indicated by estimated transmission / reception time 202 has been updated, it updates cloud authentication information 201 and places a "cloud authentication information" file, which is file format data indicating the updated cloud authentication information 201, in download shared folder unit 240. Note that placing the "cloud authentication information" file in download shared folder unit 240 corresponds to notifying the target device of the updated authentication information. This "cloud authentication information" corresponds to the updated authentication information and also to the second updated authentication information. The download unit 120 operates periodically, and when it detects that a "cloud authentication information" file has been placed in the download shared folder unit 240, it overwrites and updates the cloud authentication information 101 based on the "cloud authentication information" file.
[0053] (Step S208) FIG. 21 is a diagram illustrating the state and processing of the access management system 90 in this step. The gate control unit 210 restricts access to the download shared folder unit 240 at the end of the downloadable time. After that, the process proceeds to step S201. In step S201 after the transition, the "cloud authentication information" and the "scheduled transmission / reception time" have been updated.
[0054] ***Explanation of the effect of the first embodiment*** As described above, according to this embodiment, the gate control unit 210 determines whether the device 100 has the authority to access each shared folder at the time indicated by the "scheduled transmission / reception time" based on the information held by the device 100 as "cloud authentication information." Furthermore, each time file data communication is executed between the device 100 and the cloud 200, the "cloud authentication information" and the "scheduled transmission / reception time" are each updated. Each piece of updated information is shared between the device 100 and the cloud 200. Here, if we ignore the time and computer resources involved, it is possible to identify authentication information consisting of multiple character strings by using a brute force method (a method of exhaustively extracting all possible combinations of character strings and using the extracted combinations for access). On the other hand, in this embodiment, in addition to access control using "authentication information consisting of multiple character strings," the "accessible time" is limited to a very limited time, thereby further enhancing security for the shared area of the cloud 200. The "accessible time" and the "authentication information consisting of multiple character strings" are each changed every time the device 100 accesses the cloud 200. Therefore, according to this embodiment, even if a malicious user obtains the information necessary to access the cloud 200 using a brute force method or another method, the malicious user cannot access the cloud 200 outside of the specified time period. Furthermore, since the authentication information and the time during which the cloud 200 can be accessed are continuously updated, the possibility of rejecting unauthorized access is further increased.
[0055] Furthermore, according to this embodiment, the "cloud authentication information" and the "scheduled transmission / reception time" can be set and updated for each device 100. Therefore, according to this embodiment, security can be further strengthened in the cloud 200 that provides services to a large number of different users.
[0056] ***Other Configurations*** <Variation 1> FIG. 22 shows an example of the hardware configuration of the device 100 according to this modification. The device 100 includes a processing circuit 18 instead of the processor 11 , the processor 11 and memory 12 , the processor 11 and auxiliary storage device 13 , or the processor 11 , memory 12 , and auxiliary storage device 13 . The processing circuitry 18 is hardware that realizes at least some of the components of the device 100 . The processing circuitry 18 may be dedicated hardware or may be a processor that executes a program stored in the memory 12 .
[0057] When processing circuitry 18 is dedicated hardware, processing circuitry 18 may be, for example, a single circuit, a composite circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof. The device 100 may include multiple processing circuits that replace the processing circuit 18. The multiple processing circuits share the role of the processing circuit 18.
[0058] In the device 100, some functions may be realized by dedicated hardware, and the remaining functions may be realized by software or firmware.
[0059] Processing circuitry 18 is illustratively implemented in hardware, software, firmware, or a combination thereof. The processor 11, memory 12, secondary storage device 13, and processing circuit 18 are collectively referred to as "processing circuitry." In other words, the functions of each functional component of device 100 are realized by the processing circuitry. The cloud 200 may also have the same configuration as in this modified example. ***Other embodiments*** Although the first embodiment has been described, it is also possible to combine multiple parts of this embodiment. Alternatively, it is also possible to implement this embodiment in part. In addition, this embodiment may be modified in various ways as needed, and may be implemented in any combination, either as a whole or in part. The above-described embodiments are essentially preferred examples and are not intended to limit the scope of the present disclosure, its applications, and uses. The procedures described using flowcharts and the like may be modified as appropriate.
[0060] Various aspects of the present disclosure are summarized below as appendices.
[0061] (Appendix 1) An access management device that executes file data communication with a target device, a storage unit that stores cloud-side time information indicating a time during which the target device is permitted to communicate file data, and cloud-side authentication information that is authentication information corresponding to the target device; When the time indicated by the cloud-side time information is set as a target time, at the target time, the target device is permitted to communicate file data with the access management device based on the cloud-side authentication information, and the time indicated by the cloud-side time information is updated from the target time to an updated target time, which is the time when the target device will next be permitted to communicate file data with the access management device; a gate control unit that does not permit the target device to communicate file data with the access management device from the end time of the target time to the start time of the updated target time; An access control device comprising:
[0062] (Appendix 2) 2. The access management device according to claim 1, wherein the post-update target time is a time notified by the target device.
[0063] (Appendix 3) 3. The access management device according to claim 1, wherein the post-update target time is a time randomly determined within a target time range.
[0064] (Appendix 4) the target time is either an uploadable time, which is a time during which the target device is permitted to upload file data to the access management device, or a downloadable time, which is a time during which the target device is permitted to download file data from the access management device, When the target time is the uploadable time, the gate control unit During the target time, the target device is permitted to upload file data to the access management device based on the cloud-side authentication information, and the post-update target time is set as the time when the target device will next be permitted to upload file data to the access management device; from the end time of the target time to the start time of the updated target time, not allowing the target device to upload file data to the access management device; When the target time is the downloadable time, the gate control unit During the target time, the target device is permitted to download file data from the access management device based on the cloud-side authentication information, and the post-update target time is set as the time when the target device will next be permitted to download file data from the access management device; 4. An access management device according to any one of claims 1 to 3, wherein the target device is not permitted to download file data from the access management device from the end time of the target time to the start time of the updated target time.
[0065] (Appendix 5) The gate control unit At the target time, updating the authentication information indicated by the cloud-side authentication information to updated authentication information and notifying the target device of the updated authentication information; 5. The access management device according to claim 1, wherein the access management device permits the target device to communicate file data with the access management device based on the updated authentication information during the updated target time.
[0066] (Appendix 6) The access management device according to any one of Supplementary Notes 1 to 5, wherein the access management device is a device that constitutes a cloud system.
[0067] (Appendix 7) A storage unit that stores user-side time information and user-side authentication information. A communication device comprising: the user-side time information indicates a time during which communication of file data by the communication device is permitted in an access management device that executes communication of file data with the communication device, the user-side authentication information is authentication information corresponding to cloud-side authentication information, which is authentication information for authenticating communication between the access management device and the communication device, When the time indicated by the user-side time information is taken as a user-side target time, the user-side target time is either an uploadable time, which is a time during which the communication device is permitted to upload file data to the access management device, or a downloadable time, which is a time during which the communication device is permitted to download file data from the access management device, The communication device further comprises: an upload unit that, when the user-side target time is the upload-allowed time, requests permission to upload file data to the access management device using the user-side authentication information during the user-side target time, and when uploading the file data to the access management device is permitted, uploads the file data to the access management device, determines a next upload time, which is the time when the file data will next be uploaded to the access management device, as an updated target time, which is the time when the communication device will next be permitted to communicate file data to the access management device, updates the time indicated by the user-side time information to the determined next upload time from the user-side target time, and notifies the access management device of the determined next upload time; a download unit that, when the user-side target time is the download-enabled time, requests permission to download file data from the access management device using the user-side authentication information during the user-side target time, and when downloading of the file data to the access management device is permitted, downloads the file data from the access management device, determines a next download time, which is the time when the file data will be downloaded next from the access management device, as the updated target time, updates the time indicated by the user-side time information to the next download time determined from the user-side target time, and notifies the access management device of the determined next download time; A communication device comprising:
[0068] (Appendix 8) When the user-side target time is the uploadable time, the upload unit: When updated authentication information generated by updating the cloud-side authentication information is notified from the access management device during the user-side target time, the user-side authentication information is updated to first updated authentication information based on the updated authentication information; At the next upload time, request permission to upload file data to the access management device using the first updated authentication information; When the user-side target time is the downloadable time, the download unit: When the updated authentication information is notified from the access management device during the user-side target time, the user-side authentication information is updated to second updated authentication information based on the updated authentication information; 8. The communication device according to claim 7, which requests permission to download file data from the access management device using the second updated authentication information at the next download time.
[0069] (Appendix 9) 10. The access management device according to claim 1, An access control system comprising: The target device is a communication device according to Supplementary Note 7 or 8. An access control system comprising: [Explanation of symbols]
[0070] 11 processor, 12 memory, 13 auxiliary storage device, 14 input / output IF, 15 communication device, 18 processing circuit, 19 signal line, 90 access control system, 100 device, 101, 201 cloud authentication information, 102, 202 scheduled transmission / reception time, 110 upload unit, 120 download unit, 190 storage unit, 200 cloud, 210 gate control unit, 220 data processing unit, 230 upload shared folder unit, 240 download shared folder unit, 290 storage unit.
Claims
1. An access management device that executes file data communication with a target device, a storage unit that stores cloud-side time information indicating a time during which the target device is permitted to communicate file data, and cloud-side authentication information that is authentication information corresponding to the target device; When the time indicated by the cloud-side time information is set as a target time, at the target time, the target device is permitted to communicate file data with the access management device based on the cloud-side authentication information, and the time indicated by the cloud-side time information is updated from the target time to an updated target time, which is the time when the target device will next be permitted to communicate file data with the access management device; a gate control unit that does not permit the target device to communicate file data with the access management device from the end time of the target time until the start time of the updated target time; An access control device comprising:
2. The access management device according to claim 1 , wherein the post-update target time is a time notified by the target device.
3. The access management device according to claim 1 or 2, wherein the post-update target time is a time that is randomly determined within a target time range.
4. the target time is either an uploadable time, which is a time during which the target device is permitted to upload file data to the access management device, or a downloadable time, which is a time during which the target device is permitted to download file data from the access management device, When the target time is the uploadable time, the gate control unit During the target time, the target device is permitted to upload file data to the access management device based on the cloud-side authentication information, and the post-update target time is set as the time when the target device will next be permitted to upload file data to the access management device; from the end time of the target time to the start time of the updated target time, not allowing the target device to upload file data to the access management device; When the target time is the downloadable time, the gate control unit During the target time, the target device is permitted to download file data from the access management device based on the cloud-side authentication information, and the post-update target time is set as the time when the target device will next be permitted to download file data from the access management device; 3. The access management device according to claim 1, wherein the target device is not permitted to download file data from the access management device during the period from the end time of the target time to the start time of the updated target time.
5. The gate control unit At the target time, updating the authentication information indicated by the cloud-side authentication information to updated authentication information and notifying the target device of the updated authentication information; The access management device according to claim 1 or 2, wherein, during the post-update target time, communication of file data from the target device to the access management device is permitted based on the post-update authentication information.
6. The access management device according to claim 1 or 2, wherein the access management device is a device that constitutes a cloud system.
7. A storage unit that stores user-side time information and user-side authentication information. A communication device comprising: the user-side time information indicates a time during which communication of file data by the communication device is permitted in an access management device that executes communication of file data with the communication device, the user-side authentication information is authentication information corresponding to cloud-side authentication information, which is authentication information for authenticating communication between the access management device and the communication device, When the time indicated by the user-side time information is taken as a user-side target time, the user-side target time is either an uploadable time, which is a time during which the communication device is permitted to upload file data to the access management device, or a downloadable time, which is a time during which the communication device is permitted to download file data from the access management device, The communication device further comprises: an upload unit that, when the user-side target time is the upload-allowed time, requests permission to upload file data to the access management device using the user-side authentication information during the user-side target time, and when uploading the file data to the access management device is permitted, uploads the file data to the access management device, determines a next upload time, which is the time when the file data will next be uploaded to the access management device, as an updated target time, which is the time when the communication device will next be permitted to communicate file data to the access management device, updates the time indicated by the user-side time information to the determined next upload time from the user-side target time, and notifies the access management device of the determined next upload time; a download unit that, when the user-side target time is the download-enabled time, requests permission to download file data from the access management device using the user-side authentication information during the user-side target time, and when downloading of the file data to the access management device is permitted, downloads the file data from the access management device, determines a next download time, which is the time when the file data will be downloaded next from the access management device, as the updated target time, updates the time indicated by the user-side time information to the next download time determined from the user-side target time, and notifies the access management device of the determined next download time; A communication device comprising:
8. When the user-side target time is the uploadable time, the upload unit: When updated authentication information generated by updating the cloud-side authentication information is notified from the access management device during the user-side target time, the user-side authentication information is updated to first updated authentication information based on the updated authentication information; requesting permission to upload file data from the access management device using the first updated authentication information at the next upload time; When the user-side target time is the downloadable time, the download unit: When the updated authentication information is notified from the access management device during the user-side target time, the user-side authentication information is updated to second updated authentication information based on the updated authentication information; The communication device according to claim 7 , wherein at the next download time, the communication device requests permission to download file data from the access management device using the second updated authentication information.
9. The access management device according to claim 1 or 2 An access control system comprising: The target device is a communication device according to claim 7 or 8. An access control system comprising:
10. An access management method executed by an access management device that is a computer that executes file data communication with a target device and stores cloud-side time information indicating a time during which the target device is permitted to communicate file data, and cloud-side authentication information that is authentication information corresponding to the target device, The access management device When the time indicated by the cloud-side time information is set as a target time, at the target time, the target device is permitted to communicate file data with the access management device based on the cloud-side authentication information, and the time indicated by the cloud-side time information is updated from the target time to an updated target time, which is the time when the target device will next be permitted to communicate file data with the access management device; An access management method in which the target device is not permitted to communicate file data with the access management device from the end time of the target time to the start time of the updated target time.
11. An access management program executed by an access management device that is a computer that executes file data communication with a target device and stores cloud-side time information indicating a time during which the target device is permitted to communicate file data, and cloud-side authentication information that is authentication information corresponding to the target device, When the time indicated by the cloud-side time information is set as a target time, at the target time, the target device is permitted to communicate file data with the access management device based on the cloud-side authentication information, and the time indicated by the cloud-side time information is updated from the target time to an updated target time, which is the time when the target device will next be permitted to communicate file data with the access management device; A gate control process that does not permit the target device to communicate file data with the access management device from the end time of the target time until the start time of the updated target time. an access management program that causes the access management device to execute the above;
12. A communication method executed by a communication device that is a computer that stores user-side time information and user-side authentication information, the user-side time information indicates a time during which communication of file data by the communication device is permitted in an access management device that executes communication of file data with the communication device, the user-side authentication information is authentication information corresponding to cloud-side authentication information, which is authentication information for authenticating communication between the access management device and the communication device, When the time indicated by the user-side time information is taken as a user-side target time, the user-side target time is either an uploadable time, which is a time during which the communication device is permitted to upload file data to the access management device, or a downloadable time, which is a time during which the communication device is permitted to download file data from the access management device, when the user-side target time is the upload-allowed time, the communication device uses the user-side authentication information during the user-side target time to request permission to upload file data to the access management device, and if uploading of the file data to the access management device is permitted, uploads the file data to the access management device, determines a next upload time, which is the time at which the file data will next be uploaded to the access management device, as an updated target time, which is the time at which the communication device will next be permitted to communicate file data to the access management device, updates the time indicated by the user-side time information to the determined next upload time from the user-side target time, and notifies the access management device of the determined next upload time; a communication method in which, when the user-side target time is the downloadable time, the communication device uses the user-side authentication information to request permission to download file data from the access management device during the user-side target time, and if downloading of file data to the access management device is permitted, downloads the file data from the access management device, determines a next download time, which is the time when file data will next be downloaded from the access management device, as the updated target time, updates the time indicated by the user-side time information to the next download time determined from the user-side target time, and notifies the access management device of the determined next download time.
13. A communication program executed by a communication device that is a computer that stores user-side time information and user-side authentication information, the user-side time information indicates a time during which communication of file data by the communication device is permitted in an access management device that executes communication of file data with the communication device, the user-side authentication information is authentication information corresponding to cloud-side authentication information, which is authentication information for authenticating communication between the access management device and the communication device, When the time indicated by the user-side time information is taken as a user-side target time, the user-side target time is either an uploadable time, which is a time during which the communication device is permitted to upload file data to the access management device, or a downloadable time, which is a time during which the communication device is permitted to download file data from the access management device, an upload process of, when the user-side target time is the upload-allowed time, requesting permission to upload file data to the access management device using the user-side authentication information during the user-side target time, and if uploading of the file data to the access management device is permitted, uploading the file data to the access management device, determining a next upload time, which is the time when the file data will next be uploaded to the access management device, as an updated target time, which is the time when communication of file data by the communication device to the access management device will next be permitted, updating the time indicated by the user-side time information to the determined next upload time from the user-side target time, and notifying the access management device of the determined next upload time; a download process that, when the user-side target time is the download-available time, requests permission to download file data from the access management device using the user-side authentication information during the user-side target time, and when downloading of the file data to the access management device is permitted, downloads the file data from the access management device, determines a next download time, which is the time when the file data will be downloaded next from the access management device, as the updated target time, updates the time indicated by the user-side time information to the next download time determined from the user-side target time, and notifies the access management device of the determined next download time; a communication program that causes the communication device to execute the above.
Citation Information
Patent Citations
Password collating system
JP1987031231A
Cash cooperative data acquisition method, proxy server, cash cooperative data acquisition program, and storage medium storing cash cooperative data acquisition program
JP2003108428A
Content delivery system, content delivery server, user terminal, and computer program
JP2006018506A
Data access management method and data access management system
JP2012190076A
Time-based control of access to software assets on user devices
JP2014534518A