Quarantine network system and quarantine server
The quarantine network system improves information security by inspecting client devices for synchronization status with cloud storage, ensuring synchronization before granting network access, thus preventing data loss and maintaining shared systems.
Patent Information
- Application Number
- JP2024071791
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-25
- Publication Date
- 2025-11-07
AI Technical Summary
Existing quarantine network systems fail to maintain synchronization between client devices and cloud storage, leading to potential loss of folders or files and compromising information security, particularly availability, especially in shared systems.
A quarantine network system that includes a quarantine server which inspects client devices for synchronization operation status with cloud storage, determining whether the client device passes or fails quarantine based on predefined criteria, and restricts network access if synchronization fails.
Enhances information security by detecting and preventing synchronization issues early, preventing loss of folders or files and maintaining shared systems by ensuring client devices are synchronized before allowing network access.
Smart Images

Figure 2025167306000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a quarantine network system and a quarantine server. [Background technology]
[0002] Patent Document 1 discloses a quarantine network system that quarantines devices that apply security policies other than those to which general-purpose computers must comply. In this system, a quarantine server identifies the security policy to which the embedded device must comply based on ID information received from the embedded device, and sends an inspection request to the embedded device to inspect whether it complies with the identified security policy. In response to the inspection request, the embedded device obtains inspection information for inspecting whether it complies with the security policy, inspects itself based on the inspection information, and transmits the inspection results to the quarantine server. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-198659 Summary of the Invention [Problem to be solved by the invention]
[0004] Generally, a quarantine network system is known in which a quarantine server is used to inspect, isolate, and treat client devices. When a client device connects to a network, the quarantine server determines whether the client device passes quarantine by inspecting, for example, the application status of operating system (OS) patches on the client device. Specifically, the quarantine server inspects, for example, whether a specific file exists on the client device, and determines that the client device has passed quarantine if the specific file exists. Note that a client device that has failed quarantine is not permitted to connect to the network.
[0005] Meanwhile, in recent years, services known as cloud storage or online storage, such as Microsoft OneDrive (registered trademark) and Google Drive (registered trademark), have become popular. By using cloud storage, synchronization settings can be configured to automatically back up synchronization targets, which are folders or files stored on a client device, to the cloud storage's storage area. This prevents the loss of folders or files, even if a client device fails, for example. Furthermore, synchronization and sharing settings can be configured to synchronize and share synchronization targets among multiple client devices. This allows for the creation of a sharing system involving multiple client devices.
[0006] However, it is not always possible to maintain synchronization between a client device and cloud storage. For example, if a client device becomes out of sync for some reason and the user of the client device fails to notice this, folders or files may be lost. Furthermore, it becomes impossible to maintain a shared system consisting of multiple client devices. As a result, there is a risk of information security, particularly availability, being compromised.
[0007] Therefore, one object of the present invention is to provide a quarantine network system and a quarantine server that can enhance information security.
[0008] The above and other objects and novel features of the present invention will become apparent from the description of this specification and the accompanying drawings. [Means for solving the problem]
[0009] A brief summary of a representative embodiment of the invention disclosed in this application will be given below.
[0010] A quarantine network system according to one embodiment includes a client device and a quarantine server connected to a network, which inspects the client device and determines whether the client device passes or fails quarantine based on the inspection results. The client device is configured for synchronization with cloud storage. The cloud storage is connected to the network and provides the client device with a storage area via the network, and synchronizes and stores synchronization targets, which are pre-defined folders or files, with the client device. Here, when the client device requests connection to the network, the quarantine server obtains the synchronization operation status of the synchronization target from the client device and determines whether the client device passes or fails quarantine based on the obtained synchronization operation status. [Effects of the Invention]
[0011] To briefly explain the effect obtained by a representative embodiment of the invention disclosed in this application, it is possible to improve information security. [Brief explanation of the drawings]
[0012] [Figure 1] 1 is a schematic diagram showing an example of the configuration of an entire network system including a quarantine network system according to a first embodiment. [Figure 2] 2 is a schematic diagram illustrating an example of a hardware configuration of a client device appearing in FIG. 1. [Figure 3] 2 is a diagram illustrating an example of an operational state of synchronization between the client device and the cloud storage in FIG. 1. FIG. [Figure 4] 1, is a schematic diagram showing an example of the configuration of a quarantine target setting table provided in the quarantine server. [Figure 5] 1, is a schematic diagram showing an example of the configuration of a quarantine management table provided in the quarantine server. [Figure 6] 2 is a sequence diagram showing an example of processing contents of the quarantine network system in FIG. 1. FIG. [Figure 7]2 is a block diagram showing a detailed example of the functional configuration of a main part of the client device shown in FIG. 1. FIG. [Figure 8] 2 is a block diagram showing an example of a detailed functional configuration of a main part of the quarantine server shown in FIG. 1. FIG. [Figure 9] 10 is a block diagram showing a detailed example of the functional configuration of a main part of the quarantine server shown in FIG. 1 in the quarantine network system according to the second embodiment. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0013] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In all drawings for explaining the embodiments, the same components are generally designated by the same reference numerals, and repeated description thereof will be omitted.
[0014] (First embodiment) <Quarantine Network System Overview> Fig. 1 is a schematic diagram showing an example of the configuration of an overall network system including a quarantine network system according to a first embodiment. The overall network system shown in Fig. 1 includes an external network 10, an internal network 11, a gateway 12, a business server 13, a quarantine server 14, an authentication server 15, cloud storage 16, an authentication switch SW, and client devices TM10 and TM20. In this specification, the client devices TM10 and TM20 are collectively referred to as client devices TM.
[0015] In this example, a gateway 12, a business server 13, a quarantine server 14, and an authentication server 15 are connected to an internal network 11. The internal network 11, the quarantine server 14, the authentication server 15, the authentication switch SW, and the client device TM constitute a quarantine network system 5.
[0016] The authentication switch SW is connected between the client devices TM10 and TM20 and the internal network 11. In this example, the client device TM10 is connected to port P1 of the authentication switch SW and is used by a user 17a. The client device TM20 is, for example, a tablet device used by a user 17b, and is connected to port Pn of the authentication switch SW via a wireless LAN (Local Area Network) access point WAP. In this specification, the users 17a and 17b are collectively referred to as users 17.
[0017] The authentication switch SW performs network authentication of the client device TM or user 17, and based on the authentication result, controls the relay of frames or packets between the client device TM and the internal network 11. The internal network 11 is, for example, an in-house network, and although not shown, includes a layer 2 (L2) switch, a layer 3 (L3) switch, etc. that are responsible for relaying frames or packets.
[0018] The gateway 12 is a router or the like, and mediates communication between the internal network 11 and the external network 10. The external network 10 is the Internet. A cloud storage 16, in other words, an online storage, is connected to the external network 10. The cloud storage 16 includes, for example, a remote server 25 and a storage 26. The remote server 25 is responsible for controlling communication with the external network 10 and access to the storage 26.
[0019] The client device TM is set up for synchronization with the cloud storage 16. The cloud storage 16 provides the client device TM with a storage area via a network, in this example, the external network 10 and the internal network 11, that is, a storage area in the storage 26. The cloud storage 16 then synchronizes with the client device TM a synchronization target, which is a preset folder or file, and stores it in the storage 26.
[0020] The business server 13 is, for example, a file server, a web server, etc., and provides various services required for business. The quarantine server 14 inspects the client device TM and determines whether the client device TM passes or fails quarantine based on the inspection results. As one of the inspections, the quarantine server 14 inspects the operating status of synchronization between the client device TM and the cloud storage 16, which will be described in detail later. To perform this inspection, the quarantine server 14 stores a quarantine target setting table 21 and a quarantine management table 22 in the memory 20.
[0021] Although detailed description will be omitted, as is generally known, the quarantine server 14 also checks the application status of patches to the OS (Operating System) of the client device TM, the application status of an antivirus program, etc. In addition, the quarantine server 14 also checks the operating status of synchronization in the client device TM.
[0022] The authentication server 15 cooperates with the authentication switch SW to perform network authentication of the client device TM or the user 17. Specifically, although not shown, the authentication server 15 stores an authentication table that defines account information of the client device TM or the user 17 that is permitted network authentication. In response to an authentication judgment request from the authentication switch SW, the authentication server 15 performs authentication judgment based on the authentication table and returns the authentication judgment result to the authentication switch SW. The authentication server 15 is, for example, a RADIUS (Remote Authentication Dial In User Service) server or the like.
[0023] 1, the business server 13, the quarantine server 14, and the authentication server 15 are connected to the internal network 11. However, some or all of these servers may be connected to the external network 10 as cloud servers. In this case, the authentication switch SW may be installed, for example, between the gateway 12 and the internal network 11.
[0024] Fig. 2 is a schematic diagram showing an example of the hardware configuration of the client device TM in Fig. 1. The client device TM shown in Fig. 2 is realized by a computer system including a computer 30, a display 31, a user input interface 32, etc. The computer 30 includes a processor 35 such as a CPU (Central Processing Unit), a memory 36, a communication interface (IF) 37, and a bus 38 connecting these. The memory 36 is configured, for example, by combining volatile memory such as DRAM (Dynamic Random Access Memory) or SRAM (Static Random Access Memory) with non-volatile memory such as flash memory, SSD (Solid State Drive), or HDD (Hard Disk Drive).
[0025] The memory 36 stores a security inspection program 39, the details of which will be described later. The processor 35 executes the security inspection program 39 to obtain the synchronization operation status of each cloud storage 16 in the client device TM. The communication interface 37 is, for example, a wired LAN interface or a wireless LAN interface. In the example of FIG. 1, the client device TM is connected to the authentication switch SW via the communication interface 37.
[0026] The display 31 is, for example, a liquid crystal display, an organic EL (Electro Luminescence) display, or the like, and displays information based on an image signal from the computer 30. The user input interface 32 is, for example, a keyboard, a mouse, or a touch panel, and outputs an input signal based on an operation by the user 17 to the computer 30. Note that the business server 13, the quarantine server 14, and the authentication server 15 shown in FIG. 1 can also be realized using such computers.
[0027] <About syncing with cloud storage> FIG. 3 is a diagram showing an example of the operating state of synchronization between the client device TM and the cloud storage 16 in FIG. 1. Here, the cloud storage 16 is assumed to be Microsoft OneDrive. By using the cloud storage 16, synchronization settings can be configured to automatically back up synchronization targets, which are folders or files stored in the client device TM, to a storage area within the cloud storage 16. For example, when a target file is updated in the client device TM, the target file in the cloud storage 16 is also updated. Therefore, for example, even if the client device TM breaks down, loss of folders or files can be prevented.
[0028] Furthermore, by using the cloud storage 16, synchronization settings and sharing settings can be configured to synchronize and share synchronization targets between multiple client devices TM via the remote server 25. For example, when a target file is updated on one client device TM, the target file on another client device TM that is in a sharing relationship with the client device TM is also automatically and immediately updated via the remote server 25. This improves work efficiency when, for example, a shared system is constructed among multiple client devices TM to perform collaborative work.
[0029] Such synchronization and sharing is performed automatically by software for cloud storage 16. The software for cloud storage 16 manages the synchronization operation status with, for example, four operation statuses as shown in FIG. 3. The four operation statuses are (1) asynchronous state, i.e., not synchronized state, (2) synchronization in progress state, (3) synchronized state, i.e., synchronized state, and (4) online-only available state. An icon is assigned to each operation status. For example, when a file is to be synchronized, an icon representing the file is displayed with an icon representing the operation status added.
[0030] Furthermore, each synchronization operation state is represented by an identifier. In the example shown in Fig. 3, four operation states (1)-(4) are represented by identifiers ST1-ST4, respectively. The identifiers ST1-ST4 representing these operation states can be obtained, for example, from the properties of the folder or file to be synchronized. In this specification, the multiple identifiers ST1-ST4 are collectively referred to as identifier ST. Note that the operation state (4) corresponding to identifier ST4 means that the entity of the folder or file to be synchronized does not exist in the storage area of the client device TM, but exists in the storage area of the cloud storage 16.
[0031] Here, the synchronized state between the client device TM and the cloud storage 16 may not always be maintained depending on, for example, the operating status of the client device TM or the network. For this reason, for example, if the (1) asynchronous state corresponding to the identifier ST1 occurs for some reason and the user 17 using the client device TM fails to notice this, folders or files may be lost. Furthermore, it may become impossible to maintain a shared system consisting of multiple client devices TM. As a result, there is a risk that information security, particularly availability, may be compromised. Therefore, it is beneficial to use the method described below.
[0032] <Details of the Quarantine Target Setting Table and Quarantine Management Table> Fig. 4 is a schematic diagram showing an example of the configuration of the quarantine target setting table 21 provided in the quarantine server 14 in Fig. 1. The contents of the quarantine target setting table 21 are registered in advance by an administrator of the quarantine server 14. As shown in Fig. 4, the quarantine target setting table 21 determines folders or files to be quarantined from among synchronization targets for which synchronization settings with the cloud storage 16 are made. The quarantine target is determined, for example, for each client device TM.
[0033] 4, the quarantine targets for client devices TM10 and TM20 are set to the folder "C:\example1" and the file "C:\example2\example.txt", etc. Also, the quarantine targets for client device TM30 are set to all folders and files to be synchronized by using the wildcard "*".
[0034] In this way, the administrator of the quarantine server 14 can arbitrarily define quarantine targets. However, the administrator may particularly define synchronization targets that require backups or synchronization targets for building a shared system consisting of multiple client devices TM as quarantine targets. The quarantine server 14 checks the synchronization operation status of the quarantine targets for each client device TM based on the quarantine target setting table 21.
[0035] 5 is a schematic diagram showing an example of the configuration of the quarantine management table 22 provided in the quarantine server 14 in FIG. 1. The contents of the quarantine management table 22 are registered in advance by the administrator of the quarantine server 14. As shown in FIG. 5, the quarantine management table 22 defines the correspondence between the synchronous operating status and the pass / fail of the quarantine. In the example shown in FIG. 5, the (1) asynchronous status corresponding to the identifier ST1 is set to fail. The operating statuses corresponding to the remaining identifiers ST2-ST4 are set to pass.
[0036] The quarantine server 14 determines whether the client device TM passes or fails the quarantine based on the quarantine management table 22. In detail, for each client device TM, the quarantine server 14 determines that the client device TM passes the quarantine if the operation status of all the quarantine targets, i.e., folders or files, defined in Fig. 4 pass, that is, if the operation status corresponds to any of the identifiers ST2-ST4.
[0037] On the other hand, for each client device TM, if the operating status of any of the quarantine targets is unsuccessful, that is, if the operating status is the operating status corresponding to identifier ST1, the quarantine server 14 determines that the client device TM has failed the quarantine. For example, when inspecting the client device TM30 in Fig. 4, if any one of all folders and files to be synchronized is in the (1) unsynchronized state, the quarantine for the client device TM30 is determined to have failed.
[0038] 3 may differ for each type of cloud storage 16. For this reason, in FIG. 5, the identifiers ST representing the synchronization operation states may be pre-set to reflect multiple types of cloud storage 16. In this case, the administrator simply registers pass / fail determination information for each pre-set identifier ST. Furthermore, to accommodate new types of cloud storage 16, the quarantine management table 22 may be configured to allow the administrator to register new identifiers ST.
[0039] <Operation of the Quarantine Network System> Fig. 6 is a sequence diagram showing an example of the processing contents of the quarantine network system 5 in Fig. 1. First, as a premise, the authentication switch SW is set in advance to permit network connections to the quarantine server 14 and the cloud storage 16. In addition, the authentication switch SW is set to restrict other network connections, such as connections to the business server 13 and connections to the external network 10 excluding the cloud storage 16.
[0040] Specifically, the authentication switch SW may use, for example, an authentication VLAN (Virtual Local Area Network) function to assign a VLAN that only permits access to the quarantine server 14 and the cloud storage 16 to a client device TM that is not permitted to receive network authentication. In addition, the administrator pre-registers in the quarantine server 14 a quarantine target setting table 21 as shown in Fig. 4 and a quarantine management table 22 as shown in Fig. 5. Under these conditions, the quarantine network system 5 executes the process shown in Fig. 6.
[0041] First, in an initial state, processing is performed to synchronize objects to be synchronized between the client device TM and the cloud storage 16 (step S11). In this state, in step S12, the client device TM transmits a network connection request to the quarantine server 14. In response to this, the quarantine server 14 requests the client device TM to execute the security inspection program 39.
[0042] In step S12, if the security inspection program 39 has not been downloaded to the client device TM, the quarantine server 14 causes it to be downloaded. Specifically, the quarantine server 14 stores the security inspection program 39 in the memory 20. The quarantine server 14 then displays, for example, a link or button on the display 31 of the client device TM, such as a web screen, for downloading the security inspection program 39 from the memory 20 to the client device TM. When the user 17 selects the link or button, the client device TM downloads the security inspection program 39 from the quarantine server 14 to its own memory 36.
[0043] Next, the client device TM starts the security inspection program 39 stored in the memory 36 (step S13). At this time, the client device TM may automatically start the security inspection program 39 after completing the download of the security inspection program 39 in step S12. Furthermore, the download and start of the security inspection program 39 in steps S12 and S13 are performed every time a network connection request is made from the client device TM.
[0044] However, the method is not limited to this, and the quarantine server 14 may, for example, install the security inspection program 39 in the client device TM when it receives the first network connection request from the client device TM. In this case, when it receives the second or subsequent network connection request from the client device TM, the quarantine server 14 may execute the installed security inspection program 39.
[0045] Thereafter, the client device TM, more specifically, the processor 35 of the client device TM executes the security inspection program 39 to perform the processes of the following steps S14-S16, S19-1a, S19-1b, and S19-2.
[0046] In step S14, the client device TM transmits a notification request for quarantine targets to the quarantine server 14. In response to this, the quarantine server 14 refers to the quarantine target setting table 21 to obtain information on quarantine targets for the client device TM, and transmits the obtained information to the client device TM.
[0047] Next, in step S15, the client device TM determines a quarantine target from among the synchronization targets based on the quarantine target information acquired from the quarantine server 14. Then, the client device TM acquires the synchronization operation status of the determined quarantine target. Specifically, the client device TM acquires the synchronization operation status of the quarantine target, more specifically, an identifier ST that represents the operation status, for example, by referencing the properties of the folder or file that is the quarantine target.
[0048] Next, the client device TM transmits a request for determining whether the quarantine is successful or not based on the acquired synchronization operation status for each quarantine target, specifically the identifier ST, to the quarantine server 14 (step S16). In response to this, the quarantine server 14 determines whether the quarantine for the client device TM is successful or not by referring to the quarantine management table 22 using the identifier ST for each quarantine target acquired from the client device TM (step S17).
[0049] Then, the quarantine server 14 transmits the result of the quarantine pass / fail determination to the client device TM (step S18). If the quarantine server 14 determines that the client device TM has failed the quarantine, it notifies the client device TM of the quarantine target, and ultimately the synchronization target, that is the basis for the failure determination. As a specific example, in Fig. 4, the quarantine server 14 receives from the client device TM10 information that the file "C:\example2\example.txt" has identifier ST1, i.e., is in an asynchronous state, and if it determines that the quarantine has failed based on that information, it notifies the client device TM of the information about "C:\example2\example.txt".
[0050] If the quarantine pass / fail judgment result received in step S18 is pass, the client device TM displays a message stating "quarantine passed" on the display 31, for example, on a web screen or on a screen displayed by the security inspection program 39. Then, the client device TM transmits a network authentication request to the authentication switch SW (step S19-1a). Note that, although a detailed explanation will be omitted, a case where the quarantine has passed means, in more detail, that not only the synchronization operation status but also the OS patch application status and antivirus program application status have passed.
[0051] Then, in step S20, for example, the user 17 inputs account information such as a user identifier and password on the web screen of the authentication switch SW or on a screen by the security inspection program 39. The client device TM transmits the input account information to the authentication switch SW. In response, the authentication switch SW queries the authentication server 15 as to whether network authentication based on the received account information is permitted. If the authentication switch SW determines that network authentication is permitted, it removes the network restriction on the client device TM.
[0052] The authentication switch SW also transmits the result of the network authentication to the client device TM (step S19-1b). Note that although the authentication method using a user identifier and a password has been described here, network authentication may also be performed using a digital certificate applied to the authentication server 15, the client device TM, or both.
[0053] On the other hand, if the quarantine pass / fail judgment result received in step S18 is a failure, the client device TM displays a message stating "quarantine has failed and connection to the network is denied" on, for example, a web screen or a screen displayed by the security inspection program 39. Furthermore, the client device TM displays on the screen information about the quarantine target that is the basis for the failure notified in step S18.
[0054] This allows the user 17 of the client device TM to investigate the cause of the problem with the notified quarantine target folder or file, for example by checking the synchronization settings, and take some kind of countermeasure to resynchronize (step S19-2). If the countermeasure results in successful synchronization, for example, the user 17 causes the client device TM to run the security inspection program 39 again. This causes the quarantine network system 5 to return to the processing of step S14.
[0055] <Quarantine Network System Variation [1]> 6, the security inspection program 39 acquires information about the quarantine target based on the quarantine target setting table 21 from the quarantine server 14, and acquires the synchronization operation status of the quarantine target. However, the method is not limited to this, and the security inspection program 39 may acquire the synchronization operation status of all synchronization targets and send the acquired information to the quarantine server 14. In this case, the quarantine server 14 may extract information about the quarantine target from the acquired information based on the quarantine target setting table 21, and determine whether the quarantine has passed or failed based on the extracted information.
[0056] <Quarantine Network System Variation [2]> In a quarantine network, if the quarantine fails, various methods are used, such as the authentication switch method, the personal firewall method, and the authentication DHCP (Dynamic Host Configuration Protocol) method, depending on which point is to be denied free connection to the network. Figure 6 shows an example of the authentication switch method. However, this is not the only method, and other methods may also be used.
[0057] For example, when the personal firewall method is used, the security inspection program 39 controls the personal firewall installed in the client device TM according to the result of the quarantine inspection. When the authentication DHCP method is used, a DHCP server (not shown) assigns an inspection IP address to the client device TM as an initial state. Then, when the DHCP server receives a notification from the quarantine server 14 or the security inspection program 39 that the quarantine inspection has been passed, the DHCP server assigns an IP address with no network restrictions to the client device TM.
[0058] <Quarantine Network System Variation [3]> In the example shown in FIG. 6, network connection is controlled via the authentication switch SW according to the synchronization operation status. However, controlling the network connection is not necessarily required. In other words, the synchronization operation status is usually less likely to have a significant impact on confidentiality and integrity in information security than the patch application status of the OS, etc. Therefore, even if the quarantine server 14 determines that the synchronization operation status is unacceptable, it may not restrict the network connection and may instead notify the client device TM of the unacceptable synchronization operation status as a warning. This allows the user 17 to recognize that there is at least a synchronization problem at an early stage of using the client device TM, and therefore allows them to perform various tasks, including resynchronization, based on that assumption.
[0059] <Security Inspection Program Details> Fig. 7 is a block diagram showing a detailed example of the functional configuration of the main parts of the client device TM in Fig. 1. The client device TM shown in Fig. 7 includes a quarantine target setting unit 40, a status acquisition unit 41, a pass / fail determination request unit 42, a determination result receiving unit 43, and a network authentication request unit 44. Each of these units is realized by the processor 35 of the client device TM executing a security inspection program 39 in the memory 36. In other words, the security inspection program 39 causes the computer 30 to function as the quarantine target setting unit 40, the status acquisition unit 41, the pass / fail determination request unit 42, the determination result receiving unit 43, and the network authentication request unit 44.
[0060] The quarantine target setting unit 40 transmits a notification request for a quarantine target to the quarantine server 14, as shown in step S14 in Fig. 6. In response to this, the quarantine target setting unit 40 acquires information on the quarantine target based on the quarantine target setting table 21 from the quarantine server 14, and determines a quarantine target from among the synchronization targets based on the acquired information on the quarantine target. As shown in step S15 in Fig. 6, the status acquisition unit 41 acquires the synchronization target, more specifically, the operating status of synchronization in the quarantine target determined by the quarantine target setting unit 40, more specifically, an identifier ST that indicates the operating status.
[0061] 6, the pass / fail determination request unit 42 transmits the obtained synchronization application state, i.e., a quarantine pass / fail determination request based on the identifier ST, to the quarantine server 14. In detail, the pass / fail determination request unit 42 transmits the pass / fail determination request including, for example, information specifying the quarantine target and the identifier ST for each quarantine target.
[0062] 6, the determination result receiving unit 43 receives the quarantine pass / fail determination result from the quarantine server 14. As shown in steps S19-1a and S19-1b in FIG. 6, the network authentication request unit 44 transmits a network authentication request to the authentication switch SW when the quarantine pass / fail determination result is pass.
[0063] <Quarantine server details> Fig. 8 is a block diagram showing a detailed example of the functional configuration of the main parts of the quarantine server 14 in Fig. 1. The quarantine server 14 shown in Fig. 8 includes a connection request receiving unit 50, a quarantine target notifying unit 51, a pass / fail determining unit 52, and a memory 20. Each of these units is realized, for example, by a processor of the quarantine server 14 executing a quarantine management program (not shown) stored in the memory 20. However, each of these units is not limited to being implemented by software as described above, and may be realized by hardware such as a field programmable gate array (FPGA) or an application specific integrated circuit (ASIC), or may be realized by a combination of software and hardware.
[0064] The memory 20 stores a quarantine target setting table 21 that determines, for each client device TM, which targets for quarantine from among synchronization targets, as shown in Fig. 4. The memory 20 also stores a quarantine management table 22 that determines the correspondence between the synchronization operation status and the pass / fail of quarantine, as shown in Fig. 5. The memory 20 also stores a security inspection program 39 that causes the client device TM to perform downloads.
[0065] 6, the connection request receiving unit 50 receives a network connection request from the client device TM via the authentication switch SW. In response to the connection request, the connection request receiving unit 50 requests the client device TM to execute the security inspection program 39. At this time, as described in step S12, if the security inspection program 39 has not been downloaded to the client device TM, the connection request receiving unit 50 causes the client device TM to download the security inspection program 39.
[0066] Specifically, the connection request receiving unit 50 causes the client device TM to display, for example, a screen for downloading the security inspection program 39 in the memory 20 to the client device TM, for example, a screen including a link or button to the security inspection program 39. When the user 17 selects the link or the like, the client device TM downloads and executes the security inspection program 39 from the quarantine server 14.
[0067] 6, in response to a request for notification of a quarantine target from a client device TM, the quarantine target notification unit 51 acquires information on the quarantine target for the client device TM by referring to the quarantine target setting table 21. Then, the quarantine target notification unit 51 transmits the acquired information on the quarantine target to the client device TM.
[0068] 6, the pass / fail determination unit 52 acquires the synchronization operation status of the synchronization target, more specifically, the synchronization operation status of the quarantine target, from the client device TM. Then, the pass / fail determination unit 52 determines whether the client device TM passes or fails the quarantine by referring to the quarantine management table 22 using the acquired synchronization operation status. Furthermore, the pass / fail determination unit 52 transmits the pass / fail determination result to the client device TM. At this time, if the pass / fail determination unit 52 determines that the quarantine has failed, it notifies the client device TM of information on the quarantine target that is the basis for this determination.
[0069] <Major Effects of the First Embodiment> As described above, in the method of the first embodiment, assuming that synchronization settings are configured between the client device and cloud storage, the quarantine server obtains the synchronization operation status of the synchronization target from the client device and determines whether the client device passes or fails quarantine based on that information. This improves information security, particularly availability. Specifically, for example, a client device with a problem in the backup environment can be detected early in the client device's use and the user can be prompted to take corrective action, preventing the loss of folders or files. Furthermore, when building a shared system consisting of multiple client devices, a client device with a problem can be detected early in the client device's use and the user can be prompted to take corrective action, thereby maintaining the shared system.
[0070] Furthermore, by detecting synchronization or sharing problems in the early stages of client device use in this manner, various problems that may occur in actual operation when the client device is out of sync or not shared can be prevented in advance. For example, in a shared system, if a user of a client device uses the client device without noticing a sharing problem, there is a risk that collaborative work will proceed based on incorrect information that has not been shared. This situation can be prevented in advance.
[0071] (Second embodiment) <Quarantine server details> 9 is a block diagram showing a detailed example of the functional configuration of the main parts of the quarantine server 14 shown in FIG. 1 in a quarantine network system according to the second embodiment. The quarantine server 14 shown in FIG. 9 differs from the configuration example shown in FIG. 8 in the following three points. The first difference is that the memory 20 stores grace period information 55 registered by the administrator of the quarantine server 14 instead of the quarantine management table 22 shown in FIG. 8. The second difference is that the pass / fail determination unit 52a refers to the grace period information 55. The third difference is that the client device TM acquires information on the last synchronization date and time as the synchronization target, more specifically, as the synchronization operation status of the quarantine target, and transmits this information to the pass / fail determination unit 52a.
[0072] As in the first embodiment, the pass / fail determination unit 52a acquires the synchronization operation status of the synchronization target, more specifically, the synchronization operation status of the quarantine target, from the client device TM, and determines whether the client device TM passes or fails the quarantine based on the acquired synchronization operation status. However, unlike the first embodiment, the acquired synchronization operation status is the last synchronization date and time. The pass / fail determination unit 52a compares the elapsed time from the acquired last synchronization date and time to the current date and time with the grace period based on the grace period information 55. Then, the pass / fail determination unit 52a determines whether the client device TM passes or fails the quarantine based on the comparison result.
[0073] Specifically, if the elapsed time is shorter than the grace period, the pass / fail determination unit 52a determines that the client device TM has passed the quarantine inspection. On the other hand, if the elapsed time is longer than the grace period, the pass / fail determination unit 52a determines that the client device TM has failed the quarantine inspection. Note that the client device TM, more specifically, the status acquisition unit 41 shown in FIG. 7, can acquire the last synchronization date and time as the synchronization operation status from the properties of the folder or file to be synchronized, etc.
[0074] When using the grace period as described above, for example, by setting the grace period to a certain length, pre-synchronization of the synchronization targets as shown in step S11 in Fig. 6 is not necessary. Therefore, the authentication switch SW does not necessarily have to permit network connection to the cloud storage 16 in advance. Furthermore, the authentication switch SW may permit network connection to the cloud storage 16 only when the quarantine server 14 determines that the quarantine has been passed.
[0075] This can prevent free network connection to the cloud storage 16, which may improve information security, such as confidentiality and integrity. However, unlike the method of the first embodiment, the method of the second embodiment may be difficult to guarantee in real time that the synchronization operation status is correct. Therefore, from the viewpoint of information security availability, it is preferable to use the method of the first embodiment.
[0076] <Major Effects of the Second Embodiment> As described above, by using the method of the second embodiment, it is possible to obtain the same effects as those described in the first embodiment. In addition, it is possible to prevent free network connection to cloud storage.
[0077] The invention made by the inventor has been specifically described above based on the embodiments, but the present invention is not limited to the above embodiments and can be modified in various ways without departing from the spirit of the invention. For example, the above-described embodiments have been described in detail to clearly explain the present invention, and the present invention is not necessarily limited to those including all of the described configurations. Furthermore, it is possible to replace part of the configuration of one embodiment with the configuration of another embodiment, or to add the configuration of another embodiment to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace part of the configuration of each embodiment with other configurations.
[0078] For example, the various programs described above may be stored in a non-transitory, tangible, computer-readable recording medium and then supplied to a computer. Examples of such recording media include magnetic recording media such as hard disk drives, optical recording media such as DVDs (Digital Versatile Discs) and Blu-ray Discs, and semiconductor memories such as flash memories. [Explanation of symbols]
[0079] 5: Quarantine network system, 10: External network, 11: Internal network, 14: Quarantine server, 16: Cloud storage, 20, 36: Memory, 21: Quarantine target setting table, 22: Quarantine management table, 30: Computer, 39: Security inspection program, 40: Quarantine target setting unit, 41: Status acquisition unit, 42: Pass / fail judgment request unit, 43: Judgment result receiving unit, 44: Network authentication request unit, 50: Connection request receiving unit, 51: Quarantine target notification unit, 52, 52a: Pass / fail judgment unit, 55: Grace period information, ST: Identifier, SW: Authentication switch, TM: Client device
Claims
1. a client device; a quarantine server connected to a network, inspecting the client device and determining whether the client device passes quarantine based on the inspection result; A quarantine network system having: The client device is configured to synchronize with the cloud storage, The cloud storage provides a storage area to the client device via the network, and synchronizes and stores a synchronization target, which is a preset folder or file, with the client device; the quarantine server acquires the operation status of synchronization in the synchronization target from the client device when the client device requests connection to the network, and determines whether the client device passes quarantine based on the acquired operation status of synchronization; Quarantine network system.
2. 2. The quarantine network system according to claim 1, The quarantine server stores a quarantine management table that defines a correspondence relationship between the operation status of the synchronization and whether the client device has passed or failed the quarantine, and determines whether the client device has passed or failed the quarantine by referring to the quarantine management table using the operation status of the synchronization acquired from the client device. Quarantine network system.
3. 2. The quarantine network system according to claim 1, The quarantine server stores information about a grace period, and when the client device requests connection to the network, acquires information about the last synchronization date and time from the client device as the operation status of the synchronization in the synchronization target, and determines whether the client device passes or fails quarantine based on a comparison result between the elapsed time from the last synchronization date and time to the current date and time and the grace period. Quarantine network system.
4. 2. The quarantine network system according to claim 1, The client device is implemented as a computer, the quarantine server requests the client device to execute a security inspection program when the client device requests connection to the network; The client device executes the security inspection program, a status acquisition unit that acquires an operation status of the synchronization in the synchronization target; a pass / fail determination request unit that transmits a request for a quarantine pass / fail determination based on the acquired operation status of the synchronization to the quarantine server; a judgment result receiving unit that receives a quarantine pass / fail judgment result from the quarantine server; It functions as Quarantine network system.
5. 5. The quarantine network system according to claim 4, the quarantine server stores a quarantine target setting table that determines quarantine targets from among the synchronization targets; the client device executes the security inspection program to acquire information on the quarantine target based on the quarantine target setting table from the quarantine server, and functions as a quarantine target setting unit that determines the quarantine target based on the acquired information on the quarantine target; the status acquisition unit acquires the operation status of the synchronization in the quarantine target defined by the quarantine target setting unit; Quarantine network system.
6. 2. The quarantine network system according to claim 1, When the quarantine server determines that the client device has failed the quarantine, the quarantine server notifies the client device of the information on the synchronization target that is the basis for determining that the client device has failed the quarantine. Quarantine network system.
7. 5. The quarantine network system according to claim 4, an authentication switch connected between the client device and the network, for performing network authentication of the client device; By executing the security inspection program, the client device further functions as a network authentication request unit that transmits a network authentication request to the authentication switch when the quarantine pass / fail judgment result received by the judgment result receiving unit is pass. Quarantine network system.
8. 8. The quarantine network system according to claim 7, the authentication switch is set in advance to permit a network connection to the quarantine server and a network connection to the cloud storage; Quarantine network system.
9. A quarantine server applied to a network system having a client device and a cloud storage that provides a storage area to the client device via a network and stores synchronization targets, which are preset folders or files, in synchronization with the client device, inspects the client device, and determines whether the client device passes quarantine based on the inspection results, a pass / fail determination unit that, when the client device requests connection to the network, acquires an operation status of the synchronization in the synchronization target from the client device, and determines whether the client device passes or fails quarantine based on the acquired operation status of the synchronization; Quarantine server.
10. The quarantine server according to claim 9, a memory for storing a quarantine management table that defines a correspondence between the operational status of the synchronization and whether or not the quarantine has been passed; the pass / fail determination unit determines whether the client device passes quarantine by referring to the quarantine management table using the synchronization operation status acquired from the client device; Quarantine server.
11. The quarantine server according to claim 9, a memory for storing information about the grace period; When the client device requests connection to the network, the pass / fail determination unit acquires information on the last synchronization date and time from the client device as the operation status of the synchronization in the synchronization target, and determines whether the client device passes or fails quarantine based on a comparison result between the elapsed time from the last synchronization date and time to the current date and time and the grace time. Quarantine server.
12. 10. The quarantine server according to claim 9, a connection request receiving unit that receives a connection request from the client device to the network and requests the client device to execute a security inspection program in response to the connection request; The security inspection program configures the client device as follows: a status acquisition unit that acquires an operation status of the synchronization in the synchronization target; a pass / fail determination request unit that transmits a request for a quarantine pass / fail determination based on the acquired operation status of the synchronization to the quarantine server; a judgment result receiving unit that receives a quarantine pass / fail judgment result from the quarantine server; It is a program to function as Quarantine server.
13. The quarantine server according to claim 12, a memory for storing a quarantine target setting table for determining quarantine targets from among the synchronization targets; a quarantine target notification unit that, in response to a notification request for the quarantine target from the client device, acquires information about the quarantine target by referring to the quarantine target setting table and transmits the acquired information about the quarantine target to the client device; Equipped with the security inspection program causes the client device to function as a quarantine target setting unit, the quarantine target setting unit determines the quarantine target from among the synchronization targets by sending a notification request for the quarantine target to the quarantine server and acquiring information on the quarantine target from the quarantine server; the status acquisition unit acquires the operation status of the synchronization in the quarantine target defined by the quarantine target setting unit; Quarantine server.
14. The quarantine server according to claim 9, When the pass / fail determination unit determines that the client device has failed the quarantine inspection, the pass / fail determination unit notifies the client device of information on the synchronization target that is the basis for determining that the client device has failed. Quarantine server.
15. The quarantine server according to claim 12, a memory for storing the security inspection program; the connection request receiving unit, in response to the connection request from the client device, causes the client device to display a screen for downloading the security inspection program stored in the memory to the client device; Quarantine server.
Citation Information
Patent Citations
Quarantine network system and quarantine client
JP2012198659A