Management system, control device, management method and program
The management system addresses the issue of restricted access by allowing general users to access privileged IDs based on location and time, enhancing user convenience and security by dynamically managing access permissions.
Patent Information
- Application Number
- JP2025148321
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-11-18
AI Technical Summary
Existing systems restrict access to important functions and data to administrators only, reducing user convenience and failing to prevent unnecessary access by users with access rights due to device state and location conditions.
A management system that allows controlled access to privileged IDs based on terminal location and usage determination time, enabling general users to access important functions while reducing security risks by authenticating and managing access permissions dynamically.
Enhances user convenience while reducing security risks by allowing controlled access to privileged IDs based on location and time conditions, thus improving device management security.
Smart Images

Figure 2025170434000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a management system, a control device, a management method, and a program. [Background technology]
[0002] An information processing device (computer) generally has a function for setting access authority (hereinafter simply referred to as authority) to data, etc. stored in the information processing device according to a user ID (identifier). Furthermore, generally, in order to protect important functions, data, etc., access authority to important functions, data, etc. is limited to an administrator of the information processing device, etc. In other words, in order to protect important functions, data, etc., a predetermined user (an administrator of the information processing device, etc.) is granted stronger authority than users other than the predetermined user (hereinafter referred to as general users).
[0003] Patent document 1 describes a technology for restricting access to controlled data stored internally in a device to users with special authorizations based on the life cycle state of the device and the location and / or time of the device. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2016-058035 Summary of the Invention [Problem to be solved by the invention]
[0005] The disclosures of the above prior art documents are incorporated herein by reference. The following analysis is made from the perspective of the present invention.
[0006] As described above, by restricting access rights to important functions, data, etc. to an administrator of the information processing device, it is possible to protect the important functions, data, etc. However, there are cases where general users need to temporarily access the important functions, data, etc.
[0007] Here, in the technology described in Patent Document 1, if access to the controlled data is restricted to users with special authority (such as an administrator), users other than the administrator are not permitted to access the controlled data. Therefore, in the technology described in Patent Document 1, if access to the controlled data is restricted to users with special authority, convenience for users other than the administrator may be reduced.
[0008] Furthermore, with the technology described in Patent Document 1, if the state (lifecycle state) of a device that stores control-target data internally, the device's location and / or time satisfy predetermined conditions, a user with access rights can access the control-target data. Therefore, the technology described in Patent Document 1 cannot prevent a user with access rights from accessing the control-target data unnecessarily.
[0009] Therefore, an object of the present invention is to provide a management system, a control device, a management method, and a program that contribute to reducing the security risk of devices to be managed while improving user convenience. [Means for solving the problem]
[0010] According to a first aspect of the present invention, there is provided a management system. The management system includes a managed device that can be operated using a first ID with predetermined authority, a control device that controls the managed device, and a terminal that acquires terminal location information indicating the location of the terminal and transmits the terminal location information to the control device. The control device includes an ID usage management unit that requests the managed device to authenticate the terminal, and if the managed device authenticates the terminal, determines whether to permit the terminal to use the first ID based on the terminal location information and a usage determination time.
[0011] According to a second aspect of the present invention, there is provided a control device that controls a managed device that can be operated using a first ID with predetermined authority. The control device further includes an ID usage management unit that requests the managed device to authenticate the terminal, and, if the managed device authenticates the terminal, determines whether to permit the terminal to use the first ID based on terminal location information indicating the location of the terminal and a usage determination time.
[0012] According to a third aspect of the present invention, there is provided a management method. The management method includes a step of acquiring terminal location information indicating the location of a terminal. The management method further includes a step of requesting authentication of the terminal from a managed device that can be operated using a first ID with predetermined authority. The management method further includes a step of determining, when the terminal is authenticated, whether to permit the terminal to use the first ID based on the terminal location information and a usage determination time. It should be noted that this method is tied to a specific machine, that is, a control device that controls the managed device.
[0013] According to a fourth aspect of the present invention, there is provided a program. The program causes a computer that controls a control device to receive, from a terminal, terminal location information indicating the location of the terminal. The program also causes the computer to request authentication of the terminal from a managed device that can be operated using a first ID with predetermined authority. If the terminal is authenticated, the program also causes the computer to determine, based on the terminal location information and a usage determination time, whether to permit the terminal to use the first ID. These programs can be recorded on a computer-readable storage medium. The storage medium can be a non-transient medium such as a semiconductor memory, a hard disk, a magnetic recording medium, or an optical recording medium. The present invention can also be embodied as a computer program product. [Effects of the Invention]
[0014] According to each aspect of the present invention, a management system, a control device, a management method, and a program are provided that contribute to reducing security risks of managed devices while improving user convenience. [Brief explanation of the drawings]
[0015] [Figure 1] FIG. 1 is a diagram for explaining an overview of an embodiment. [Figure 2] 1 is a block diagram showing an example of the overall configuration of a management system 1. FIG. [Figure 3] FIG. 10 is a diagram showing an example of a usage application information table 105. [Figure 4] FIG. 10 is a diagram showing an example of a managed server table 106. [Figure 5] FIG. 10 is a diagram showing an example of a work user table 107. [Figure 6] 10 is a flowchart showing an example of the operation of the management server 100. [Figure 7]10 is a flowchart showing an example of the operation of the management server 100. [Figure 8] 10 is a flowchart showing an example of the operation of the management server 100. [Figure 9] 10 is a flowchart showing an example of the operation of the management system 1. [Figure 10] 10 is a flowchart showing an example of the operation of the management system 1. [Figure 11] 4 is a flowchart showing an example of the operation of the control device 300. [Figure 12] 4 is a flowchart showing an example of the operation of the control device 300. DETAILED DESCRIPTION OF THE INVENTION
[0016] First, an overview of one embodiment will be described using FIG. 1. Note that the reference numerals in this overview are added to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, the connection lines between blocks in each block diagram include both bidirectional and unidirectional ones. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Furthermore, although not explicitly shown in the circuit diagrams, block diagrams, internal configuration diagrams, connection diagrams, etc. shown in this disclosure, input ports and output ports exist at the input and output ends of each connection line. The same applies to input / output interfaces.
[0017] As described above, there is a demand for a management system that contributes to reducing security risks of managed devices while improving user convenience.
[0018] Therefore, as an example, a management system 1000 shown in Fig. 1 is provided. The management system 1000 includes a management target device 1010, a control device 1020, and a terminal 1030.
[0019] The managed device 1010 can be operated using a first ID that has a predetermined authority. The terminal 1030 acquires terminal location information that indicates the location of the terminal 1030 itself, and transmits the terminal location information to the control device 1020.
[0020] The control device 1020 controls the managed device 1010. Furthermore, the control device 1020 includes an ID usage management unit 1021. The ID usage management unit 1021 requests the managed device 1010 to authenticate the terminal 1030. When the managed device 1010 authenticates the terminal 1030, the ID usage management unit 1021 determines whether or not to permit the terminal 1030 to use the first ID in the managed device 1010, based on the terminal location information received from the terminal 1030 and a time to be determined. In the following description, the time to be determined is referred to as the usage determination time.
[0021] Here, it is assumed that the first ID is a user ID (hereinafter referred to as a privileged ID) having stronger authority than the user ID of a general user. Furthermore, it is assumed that the time to be determined is the time of determination. In this case, for the terminal 1030 authenticated by the managed device 1010, the control device 1020 determines whether or not to permit the terminal 1030 to use the privileged ID in the managed device 1010 based on the location of the terminal 1030 and the time of determination. Therefore, the control device 1020 permits the terminal 1030 authenticated by the managed device 1010, which is present at a location that satisfies a predetermined condition at a time that satisfies a predetermined condition, to use the privileged ID in the managed device 1010.
[0022] That is, in the management system 1000, the control device 1020 permits an external device (i.e., terminal 1030) different from the managed device 1010 to use the privileged ID of the managed device 1010. Furthermore, in the management system 1000, even a general user can use the privileged ID of the managed device 1010 if predetermined conditions are met. Therefore, the management system 1000 contributes to improving convenience for users who use the managed device 1010.
[0023] Meanwhile, the control device 1020 causes the managed device 1010 to authenticate the terminal 1030. Furthermore, the control device 1020 determines whether or not to permit the terminal 1030 to use the privileged ID of the managed device 1010, based on the location and time of the terminal 1030. In other words, the control device 1020 restricts the terminals 1030 that can use the privileged ID of the managed device 1010, as well as the locations and times at which they can be used. Therefore, the management system 1000 contributes to reducing the security risk of the managed device 1010.
[0024] Therefore, the management system 1000 contributes to reducing security risks of the managed device 1010 while improving user convenience.
[0025] [First embodiment] The first embodiment will be described in detail with reference to the drawings. In the following description, the managed device will be referred to as a managed server. However, this does not mean that the managed device is limited to a server.
[0026] Fig. 2 is a block diagram showing an example of the overall configuration of a management system 1 according to this embodiment. The management system 1 includes a management server 100, a terminal 200, and a control device 300. Although Fig. 2 shows one terminal 200, this does not mean that the management system 1 is limited to being configured to include one terminal 200. Of course, the management system 1 may include two or more terminals 200.
[0027] The control device 300 is connected to managed servers (managed devices) (301a, 301b). In the following description, the managed servers (310a, 310b) will be referred to as managed servers 310 when there is no need to distinguish between them. Although FIG. 2 shows two managed servers (301a, 301b), this does not mean that the number of managed servers 310 is limited to two. It goes without saying that the management system 1 may be configured to include one or three or more managed servers 310.
[0028] The control device 300 and the managed server 310 are arranged in a managed server network (first network) 400. In the management system 1 according to this embodiment, the managed server network 400 is assumed to be a LAN (Local Area Network). In other words, in the management system 1 according to this embodiment, the control device 300 and the managed server 310 are assumed to be arranged in a LAN. When the terminal 200 exists in the managed server network 400, it is assumed that it can connect to the control device 300 and the managed server 310 via the managed server network 400.
[0029] Furthermore, the terminal 200 can be connected to the management server 100 via a second network different from the managed server network 400. For example, the second network may be the Internet. Alternatively, the second network may be a LAN different from the managed server network 400.
[0030] The management server 100 is configured to include a usage application management unit 103, a management server control unit 104, and a management server storage unit 101. Furthermore, the management server 100 is equipped with a communication means (not shown). It goes without saying that the management server 100 may be configured to include hardware and / or software not shown.
[0031] Terminal 200 is an information processing device (computer) used by an operator. For example, terminal 200 may be a smartphone, a tablet terminal, or the like. Terminal 200 is configured to include an ID management relay unit 201 and a location information acquisition unit 202. Furthermore, terminal 200 is equipped with a communication means (not shown). Note that terminal 200 may, of course, be configured to include hardware and / or software not shown.
[0032] The control device 300 is an information processing device (computer) that controls the managed server 310. The control device 300 includes an ID usage management unit 301. The control device 300 also includes a communication means (not shown). Of course, the control device 300 may also include hardware and / or software (not shown).
[0033] The managed server 310 is an information processing device (computer). Specifically, the managed server 310 is an information processing device (computer) that can be connected using at least one of a first ID having a predetermined authority and a second ID different from the first ID. In the following description, the first ID is assumed to be a privileged ID.
[0034] The management server 100 will be described in detail below.
[0035] The management server storage unit 101 stores information necessary to operate the management server 100. The management server storage unit 101 stores an ID management database 102. The management server storage unit 101 is realized by a magnetic disk device, an optical disk device, or a semiconductor memory.
[0036] The ID management database 102 will be described in more detail below.
[0037] The ID management database 102 stores information that associates information for identifying the managed server 310 with usage application information. In the following description, the table that associates information for identifying the managed server 310 with usage application information is referred to as a usage application information table 105.
[0038] The information for identifying the managed server 310 may be a number assigned to each managed server 310, and the details are not important as long as it is information that can identify the managed server 310. In the following explanation, the information for identifying the managed server 310 will be referred to as the managed server ID.
[0039] The use application information includes a privileged ID (first ID), information indicating the authority corresponding to the privileged ID, a use start time, and a use end time.
[0040] The information indicating the authority corresponding to the privileged ID is information indicating the authority that can be used using the privileged ID on the managed server 310. In the following description, among the information indicating the authority corresponding to the privileged ID, the information included in the usage application information is referred to as the authority to be applied for.
[0041] The usage start time is the time when the user plans to start using the managed server 310. On the other hand, the usage end time is the time when the user plans to end using the managed server 310. In other words, the user requests to use the managed server 310 from the usage start time to the usage end time.
[0042] Fig. 3 is a diagram showing an example of the usage application information table 105. Specifically, Fig. 3 shows a table in which a managed server ID, a work user ID, a privilege ID, an authority to be applied for, a usage start time, and a usage end time are associated with each other.
[0043] Furthermore, the ID management database 102 stores a managed server ID, server connection information, authentication information corresponding to a second ID, registered location information, and a distance threshold in association with each other. In the following description, the second ID will be referred to as a connected user ID. The connected user ID is a user ID linked to a privileged ID and is a user ID for connecting to the managed server 310. In the following description, a table that associates a managed server ID, server connection information, connected user authentication information corresponding to a connected user ID (second ID), registered location information, and a distance threshold will be referred to as a managed server table 106. In the following description, authentication information corresponding to a connected user ID will be referred to as connected user authentication information. The connected user authentication information is information including a connected user ID and a password corresponding to the connected user ID.
[0044] The server connection information is information required to connect to the managed server 310. For example, the server connection information may include a host name and a port number corresponding to the managed server 310. Furthermore, for example, the server connection information may include an IP address and a port number corresponding to the managed server 310.
[0045] The registered location information is information indicating a location that has been applied for use by a user and registered. For example, the registered location information may be information indicating a location where a user of the terminal 200 plans to work using a privileged ID.
[0046] The distance threshold is a distance that is used as a threshold for determining whether the difference between the location of the terminal 200 and the location for which use has been applied in advance is within a predetermined range.
[0047] Fig. 4 is a diagram showing an example of the managed server table 106. Specifically, Fig. 4 shows a table in which managed server IDs, host names, port numbers, connected user IDs, passwords corresponding to the connected user IDs (connected user passwords), registered position information, and distance thresholds are associated with each other.
[0048] Furthermore, the ID management database 102 stores authentication information corresponding to a third ID. In the following description, a table storing the third ID and the password corresponding to the third ID is referred to as a work user table 107. In the following description, the third ID is referred to as a work user. In the following description, authentication information corresponding to a work user ID (third ID) is referred to as work user authentication information.
[0049] The work user ID is a user ID corresponding to a user who uses the terminal 200. The work user authentication information is information including the work user ID and a password corresponding to the work user ID.
[0050] Fig. 5 shows an example of the work user table 107. Specifically, Fig. 5 shows an example of a table that associates work user IDs with passwords. For example, referring to Fig. 5, the password corresponding to the work user ID "suzuki" is "B7343a7cbdd302".
[0051] In the following explanation, for the sake of convenience, it is assumed that the ID management database 102 stores a user table, a usage application information table 105, and a managed server table 106. However, this does not mean that the ID management database 102 is limited to storing (holding) data in table format.
[0052] The use application management unit 103 authenticates the work user. Furthermore, the use application management unit 103 accepts use application information and registers the accepted use application information in the ID management database 102. Specifically, the use application management unit 103 accepts use application information including the managed server ID, privileged ID, the requested authority, the use start time, and the use end time, which are the subject of the use application. Then, the use application management unit 103 registers the use application information including the managed server ID, privileged ID, the requested authority, the use start time, and the use end time in the ID management database 102.
[0053] The management server control unit 104 receives a login request of the working user from the ID management relay unit 201. When the management server control unit 104 receives the login request from the ID management relay unit 201, it responds to the ID management relay unit 201 with a list of managed servers 310 corresponding to the working user from among the managed servers 310 registered in advance. Then, when the management server control unit 104 receives a managed server ID from the ID management relay unit 201, it refers to the use application information table 105 and responds to the ID management relay unit 201 with use application information corresponding to the received managed server ID.
[0054] The terminal 200 will be described in detail below.
[0055] The location information acquisition unit 202 acquires terminal location information indicating the location of the terminal 200. The location information acquisition unit 202 is realized using, for example, a GPS (Global Positioning System) function.
[0056] The ID management relay unit 201 transmits connecting user authentication information corresponding to the connecting user ID and terminal location information to the control device 300. Furthermore, the ID management relay unit 201 transmits registered location information and a distance threshold to the control device 300. Specifically, when making a use application, the ID management relay unit 201 transmits the registered location information and the distance threshold to the control device 300. More specifically, the ID management relay unit 201 receives connecting user authentication information and use application information corresponding to the managed server 310 to be connected from the management server 100. Then, the ID management relay unit 201 transmits the connecting user authentication information, use application information, and terminal location information to the control device 300.
[0057] Furthermore, the terminal 200 acquires terminal location information at predetermined time intervals and transmits the terminal location information to the control device 300. Specifically, after the control device 300 permits the terminal 200 to use the privileged ID of the managed server 310, the location information acquisition unit 202 acquires the terminal location information at predetermined time intervals. Then, after the control device 300 permits the terminal 200 to use the privileged ID of the managed server 310, the ID management relay unit 201 transmits the terminal location information to the control device 300 at predetermined time intervals.
[0058] The control device 300 will be described in detail below.
[0059] When the managed server 310 authenticates the connected user authentication information transmitted from the terminal 200, the ID usage management unit 301 determines whether or not to permit the terminal 200 to use the privileged ID (first ID) based on the terminal location information and the time when the terminal location information was received. In the following description, the time when the ID usage management unit 301 received the terminal location information is also referred to as the usage determination time.
[0060] Specifically, it is assumed that the managed server 310 authenticates the connecting user authentication information transmitted from the terminal 200, and the difference between the location of the terminal 200 and the location previously requested for use is equal to or less than the distance threshold. Furthermore, it is assumed that the use determination time is after the predetermined use start time and before the predetermined use end time. In this case, the ID use management unit 301 permits the terminal 200 to use the first ID. Here, it is assumed that the managed server 310 is the managed server 310 to which the terminal 200 is to connect. Furthermore, it is assumed that the use start time and use end time are times previously registered as use application information.
[0061] Furthermore, it is assumed that the ID usage management unit 301 receives terminal location information from the terminal 200 after permitting the terminal 200 to use the privileged ID of the managed server 310. In this case, the ID usage management unit 301 determines whether or not to permit the terminal 200 to use the privileged ID corresponding to the managed server 310 to which it is connected, based on the terminal location information and the usage determination time.
[0062] Furthermore, suppose that after the ID usage management unit 301 permits the terminal 200 to use the privileged ID corresponding to the target managed server 310, at least one of the terminal location information and the usage determination time no longer satisfies the predetermined conditions. In this case, the ID usage management unit 301 makes the privileged ID unavailable for use by the terminal 200.
[0063] Specifically, after the ID usage management unit 301 permits the terminal 200 to use the privileged ID corresponding to the managed server 310 to which the terminal 200 is to be connected, if the distance between the location of the terminal 200 and the work location for which use has been requested in advance exceeds the distance threshold for which use has been requested in advance, the ID usage management unit 301 disables the use of the privileged ID from the terminal 200.
[0064] Furthermore, if the ID usage management unit 301 permits the terminal 200 to use the privileged ID corresponding to the target managed server 310, and the usage determination time exceeds the usage application time that was previously applied for, the ID usage management unit 301 disables the use of the privileged ID from the terminal 200.
[0065] Furthermore, suppose that the ID usage management unit 301 receives terminal location information from the terminal 200 after disabling the use of the privileged ID corresponding to the managed server 310 to be connected from the terminal 200. In this case, suppose that the usage determination time is after the usage start time previously applied for and before the usage end time previously applied for. In this case, the ID usage management unit 301 again permits the terminal 200 to use the privileged ID corresponding to the managed server 310 based on the received terminal location information. Specifically, if the received terminal location information satisfies a predetermined condition, the ID usage management unit 301 again permits the terminal 200 to use the privileged ID corresponding to the managed server 310.
[0066] Next, the operation of the management system 1 according to this embodiment will be described in detail.
[0067] First, the process of registering an operation user will be described with reference to FIG.
[0068] In step A1, the management server control unit 104 accepts input of the work user ID and password.
[0069] For example, an administrator of the management server 100 may use an input device (such as a keyboard (not shown)) connected to the management server 100 to input an operation user ID and a password corresponding to the operation user ID. Alternatively, for example, an administrator of the management server 100 may use an information processing device (computer) different from the management server 100 to input an operation user ID and a password corresponding to the operation user ID. Then, the information processing device different from the management server 100 may transmit the input operation user ID and the password corresponding to the operation user ID to the management server 100. In this case, the information processing device may transmit the operation user ID and the password corresponding to the operation user ID to the management server 100 via a network (for example, the Internet).
[0070] Similarly, hereinafter, it is assumed that the administrator of the management server 100 may input information using an input device (such as a keyboard (not shown)) connected to the management server 100, and a detailed description thereof will be omitted. Similarly, hereinafter, it is assumed that the administrator of the management server 100 may input information using an information processing device (computer) different from the management server 100, and a detailed description thereof will be omitted. In that case, it is assumed that the information processing device may transmit the input information to the management server 100 via a network (for example, the Internet), as described above, and a detailed description thereof will be omitted.
[0071] In step A2, the management server control unit 104 registers the input work user ID and password in the work user table 107.
[0072] Next, with reference to FIG. 7, a process for registering server connection information and connected user authentication information will be described.
[0073] In step A11, the management server control unit 104 accepts input of management target server information including server connection information, connected user authentication information, registered location information, and distance threshold for one or more management target servers 310. It is assumed here that the input connected user authentication information has been registered in advance in the management target server 310.
[0074] In step A12, the management server control unit 104 registers the received input of the management target server information in the management target server table 106.
[0075] In step A13, the management server control unit 104 accepts input of registered location information and a distance threshold for the managed server 310 corresponding to the managed server information registered in the ID management database 102. In step A14, the management server control unit 104 registers the input registered location information and distance threshold in the managed server table 106.
[0076] Next, the process of registering application information will be described with reference to FIG.
[0077] In step A21, the usage application management unit 103 accepts usage application information for one or more managed servers 310. Specifically, the usage application management unit 103 accepts usage application information for one or more managed servers 310, including a managed server ID, a privileged ID, the authority for which the request is made, a usage start time, and a usage end time.
[0078] In step A22, the use application management unit 103 presents the received use application information to the administrator or the like (i.e., the person approving the use application) of the management server 100. Specifically, the use application management unit 103 presents the use application information, including the managed server ID, the privileged ID, the requested authority, the use start time, and the use end time, for one or more managed servers 310 to the administrator or the like of the management server 100.
[0079] For example, the use application management unit 103 may output the received use application information using a display device (such as a display (not shown)). Alternatively, the use application management unit 103 may transmit the received use application information to an information processing device (such as a PC (Personal Computer)) used by an administrator or the like of the management server 100 via a network (such as the Internet). There are various methods for presenting the received use application information to an administrator or the like of the management server 100 (i.e., a person who approves the use application), and the details thereof are not important.
[0080] The administrator of the management server 100 checks the presented use application information. If the administrator of the management server 100 approves the use application information, the administrator performs a predetermined approval operation. For example, the use application management unit 103 may display an "Approve" button on the display screen. Then, if the administrator of the management server 100 approves the use application information, the administrator may perform the approval operation by pressing the "Approve" button.
[0081] In step A23, the use application management unit 103 accepts an approval operation for the accepted use application information from the administrator or the like of the management server 100. In step A24, the use application management unit 103 registers the approved use application information in the use application information table 105.
[0082] Next, the operation of the management system 1 will be described with reference to Fig. 9. In the following description, it is assumed that the management server 100 has already executed the processes shown in Figs. 6 to 8. In other words, it is assumed that the management server 100 has already registered the necessary information in the ID management database 102. In other words, it is assumed that the management server 100 has already registered information in the work user table 107, the managed server table 106, and the use application information table 105.
[0083] In step S1, the terminal 200 requests authentication of the work user. Specifically, the ID management relay unit 201 transmits the work user ID and password to the management server 100 and requests authentication of the work user. Here, it is assumed that the terminal 200 is connectable to the management server 100 via a network (second network) different from the managed server network 400.
[0084] In step S2, the management server 100 authenticates the work user. Specifically, the management server control unit 104 receives the work user ID and password from the terminal 200. Then, the management server control unit 104 determines whether the received work user ID and password are registered in the work user table 107.
[0085] If the received work user ID and password are not registered in the work user table 107, the management server control unit 104 does not authenticate the work user for whom authentication is requested. In this case, the management server control unit 104 notifies the terminal 200 that is the source of the authentication request that the work user for whom authentication is requested will not be authenticated.
[0086] If the received work user ID and password are registered in the work user table 107, the management server control unit 104 authenticates the work user for whom authentication is requested. In the following explanation, the management server control unit 104 will be described assuming that the work user for whom authentication is requested is authenticated.
[0087] In step S3, if the management server 100 authenticates the work user, it acquires a list of managed servers 310 corresponding to the work user. Specifically, the management server control unit 104 refers to the usage application information table 105 and acquires one or more managed server IDs corresponding to the authenticated work user as a list of managed servers 310.
[0088] In step S4, the management server 100 transmits the acquired list of managed servers 310 to the terminal 200. In step S5, the terminal 200 receives the list of managed servers 310.
[0089] In step S6, the terminal 200 determines a managed server ID corresponding to the managed server 310 that is the target of the usage request, based on the user's operation. Specifically, the ID management relay unit 201 displays the received list of managed server IDs on the display screen of the terminal 200. The user of the terminal 200 selects the managed server ID that is the target of the usage request from the displayed list of managed server IDs. Then, the ID management relay unit 201 determines the managed server ID selected by the user as the managed server ID that corresponds to the managed server 310 that is the target of the usage request.
[0090] In step S7, the terminal 200 transmits the determined managed server ID. In step S8, the management server 100 receives the managed server ID.
[0091] In step S9, the management server 100 transmits the managed server information, including server connection information, connected user authentication information, registered location information, and distance threshold, and usage application information to the terminal 200. Specifically, the management server control unit 104 references the managed server table 106 and acquires the managed server information corresponding to the received managed server ID. Here, the managed server information includes the server connection information, connected user authentication information, registered location information, and distance threshold. Furthermore, the management server control unit 104 references the usage application information table 105 and acquires the usage application information corresponding to the received managed server ID. Then, the management server control unit 104 transmits the acquired managed server information and usage application information to the terminal 200.
[0092] In step S10, the terminal 200 receives the management target server information and the usage application information.
[0093] Here, the ID management relay unit 201 may display the server connection information out of the received management target server information on the display screen of the terminal 200. Furthermore, the ID management relay unit 201 may display the received usage application information on the display screen of the terminal 200.
[0094] It is assumed that the management system 1 prohibits a user from directly logging in to the managed server 310 using the connected user ID. In this case, it is preferable that the ID management relay unit 201 does not present the connected user authentication information, which is included in the received managed server information, to the user.
[0095] In step S11, the terminal 200 uses the server connection information from the received managed server information to connect to the managed server 310. Then, the process proceeds to step S21 shown in FIG.
[0096] Next, the operation of the management system 1 will be described with reference to Fig. 10. In the following description, it is assumed that the terminal 200 is connectable to the control device 300 and the managed server 310 via the managed server network 400. In other words, in the following description, it is assumed that the user operates the terminal 200 at a location where it can be connected to the managed server network 400.
[0097] In step S21, the terminal 200 transmits the received management target server information, use application information, and terminal location information to the control device 300. Specifically, the location information acquisition unit 202 acquires terminal location information indicating the location of the terminal 200. Then, the ID management relay unit 201 transmits the received management target server information, use application information, and acquired terminal location information to the control device 300.
[0098] In step S22, the control device 300 receives the managed server information, the usage application information, and the terminal location information.
[0099] In step S23, the control device 300 transmits connecting user authentication information to the managed server 310 for which usage has been requested, and requests user authentication. Specifically, the ID usage management unit 301 connects to the managed server 310 using the server connection information from the received managed server information. The ID usage management unit 301 then transmits connecting user authentication information to the connected managed server 310, and requests authentication of the connecting user. Specifically, the ID usage management unit 301 transmits the connecting user ID and password to the connected managed server 310, and requests authentication of the connecting user.
[0100] In step S24, the managed server 310 performs user authentication using the connected user authentication information. For example, if the OS (Operating System) of the managed server 310 is Linux (registered trademark), the managed server 310 may perform user authentication using SSH. Also, for example, if the OS of the managed server 310 is Windows (registered trademark), the managed server 310 may perform user authentication using PowerShell. Of course, the managed server 310 may perform user authentication using a method appropriate for the operating environment. Then, the managed server 310 responds with the result of authentication of the connected user to the control device 300 (step S25).
[0101] In step S26, the control device 300 determines whether authentication of the connecting user has been successful. If authentication of the connecting user has been successful (Yes branch of step S26), the process proceeds to step S101 shown in Fig. 11. If authentication of the connecting user has failed (No branch of step S26), the ID usage management unit 301 transmits a notification of failure of the usage request to the terminal 200 (step S27). Then, the terminal 200 receives the notification of failure of the usage request (step S28).
[0102] Next, the operation of the control device 300 will be described with reference to FIG.
[0103] In step S101, the ID usage management unit 301 determines whether the difference between the location of the terminal 200 and the location previously applied for usage is equal to or less than a predetermined distance threshold. Specifically, the ID usage management unit 301 compares the terminal location information with the registered location information included in the usage application information. The ID usage management unit 301 then determines whether the difference between the terminal location information and the registered location information included in the usage application information (for example, the location where the user of the terminal 200 plans to work) is equal to or less than the distance threshold included in the usage application information.
[0104] If the difference between the location of terminal 200 and the location previously requested for use exceeds a predetermined distance threshold (No branch in step S101), the process proceeds to step S103. In step S103, ID usage management unit 301 determines that the requested privileged ID is not permitted to be used on managed server 310 for which the request for use of the privileged ID has been made. Then, the process proceeds to step S106.
[0105] On the other hand, if the difference between the location of the terminal 200 and the location previously applied for use is equal to or less than the predetermined distance threshold (Yes branch of step S101), the process proceeds to step S102.
[0106] In step S102, ID usage management unit 301 determines whether the time at which the terminal location information was received is between the usage start time and usage end time included in the usage application information. In other words, ID usage management unit 301 determines whether the usage judgment time is after the specified usage start time and before the specified usage end time.
[0107] If the time at which the terminal location information was received is not between the usage start time and usage end time included in the usage application information (No branch in step S102), the process proceeds to step S103. In step S103, the ID usage management unit 301 determines that the use of the requested privileged ID is not permitted on the managed server 310 for which usage of the privileged ID has been requested. The process then proceeds to step S106.
[0108] On the other hand, if the time when the terminal location information was received is between the usage start time and usage end time included in the usage application information (Yes branch of step S102), the process proceeds to step S104. In step S104, the ID usage management unit 301 permits the terminal 200 to use the requested privileged ID on the managed server 310 for which usage has been requested.
[0109] In step S105, the ID usage management unit 301 sets the requested authority for the requested privileged ID on the managed server 310. Here, the ID usage management unit 301 may set a password for the privileged ID that has been permitted for use. For example, the ID usage management unit 301 may create a random password as the password corresponding to the privileged ID.
[0110] In step S106, ID usage management unit 301 transmits information relating to whether the privileged ID can be used, etc. to terminal 200. Specifically, ID usage management unit 301 transmits information relating to whether the privileged ID can be used to terminal 200. Furthermore, if a password has been set for the privileged ID whose use has been permitted, ID usage management unit 301 notifies terminal 200 of the set password.
[0111] When terminal 200 receives information regarding whether or not a privileged ID can be used, ID management relay unit 201 displays the information regarding whether or not the privileged ID can be used on the display screen of terminal 200. Furthermore, when terminal 200 receives a password corresponding to the privileged ID, ID management relay unit 201 displays the received password on the display screen of terminal 200. In this case, the user of terminal 200 uses the displayed password to log in to managed server 310 and perform work on managed server 310.
[0112] Next, with reference to FIG. 12, a process after the control device 300 permits the terminal 200 to use the privileged ID of the managed server 310 will be described.
[0113] In step S201, ID usage management unit 301 determines whether terminal location information has been received at predetermined time intervals from terminal 200. Specifically, ID usage management unit 301 determines whether terminal location information has been received at predetermined time intervals from terminal 200 that is permitted to use the privileged ID of managed server 310.
[0114] If the ID usage management unit 301 receives terminal location information from the terminal 200 (Yes branch in step S201), the process proceeds to step S202. On the other hand, if the ID usage management unit 301 does not receive terminal location information from the terminal 200 (No branch in step S201), the process proceeds to step S203.
[0115] In step S202, ID usage management unit 301 determines whether the difference between the location of terminal 200 and the location for which usage has been applied in advance is equal to or less than a predetermined distance threshold. That is, the same process as step S101 shown in FIG. 11 is performed.
[0116] If the difference between the location of terminal 200 and the location for which usage has been requested in advance exceeds a predetermined distance threshold (No branch in step S202), the process proceeds to step S203. In step S203, ID usage management unit 301 disables the requested privileged ID on managed server 310. Then, the process proceeds to step S207.
[0117] On the other hand, if the difference between the location of the terminal 200 and the location previously applied for use is equal to or less than the predetermined distance threshold (Yes branch of step S202), the process proceeds to step S204.
[0118] In step S204, the ID usage management unit 301 determines whether the requested authority is set for the privileged ID on the managed server 310 for which usage has been requested. If the requested authority is set for the privileged ID on the managed server 310 for which usage has been requested (Yes branch in step S204), the process proceeds to step S208.
[0119] On the other hand, if the requested authority is not set for the privileged ID on the managed server 310 for which usage has been requested (No branch in step S204), the process proceeds to step S205. In step S205, the ID usage management unit 301 makes the requested privileged ID available on the managed server 310 for which usage has been requested. In other words, after making the requested privileged ID unavailable from the terminal 200, the ID usage management unit 301 permits the terminal 200 to use the privileged ID if the terminal location information and the usage determination time satisfy predetermined conditions.
[0120] In step S206, the ID usage management unit 301 sets the requested privilege for the privileged ID on the managed server 310 for which usage has been requested.
[0121] In step S207, the ID usage management unit 301 transmits to the terminal whether or not the privileged ID can be used.
[0122] In step S208, ID usage management unit 301 determines whether the current time has passed the usage end time. If the current time has not passed the usage end time (No branch in step S208), the process returns to step S201 and continues. On the other hand, if the current time has passed the usage end time (Yes branch in step S208), ID usage management unit 301 makes the requested privileged ID unavailable on managed server 310 (step S209). Then, ID usage management unit 301 notifies terminal 200 that the requested privileged ID has been made unavailable.
[0123] As described above, in the management system 1 according to this embodiment, the control device 300 permits an external device (i.e., the terminal 200) different from the managed device 1010 to use the privileged ID of the managed server 310. Furthermore, in the management system 1 according to this embodiment, the control device 300 determines whether to permit the terminal 200 to use the privileged ID of the managed server 310 based on the location and time of the terminal 200. Specifically, in the management system 1 according to this embodiment, when a worker (a user of the terminal 200) is at a pre-approved location within a pre-approved time, the control device 300 allows the worker to use the privileged ID of the managed server 310. As a result, the management system 1 according to this embodiment contributes to reducing the security risk of the managed server 310 while improving user convenience.
[0124] Furthermore, in the management system 1 according to this embodiment, if the control device 300 does not receive terminal location information within a predetermined time interval after permitting use of the privileged ID, the control device 300 disables the privileged ID of the managed server 310. For example, suppose that the user of the terminal 200 finishes using the privileged ID and turns off the power of the terminal 200. When the terminal 200 is turned off, the control device 300 is no longer able to receive terminal location information within the predetermined time interval. In this case, the control device 300 disables the privileged ID of the managed server 310. In other words, in a situation where the user is not actually using the privileged ID, the management system 1 according to this embodiment disables the privileged ID. Therefore, the management system 1 according to this embodiment contributes to protecting the managed server 310 appropriately according to the situation while improving user convenience.
[0125] In the management system 1 according to this embodiment, the control device 300 and the managed server 310 are arranged within a LAN (managed server network 400). Furthermore, in the management system 1 according to this embodiment, the terminal 200 connects to the management server 100 via a network different from the managed server network 400. Therefore, the management system 1 according to this embodiment can manage privileged IDs for the managed server 310 present within the LAN. As a result, the management system 1 according to this embodiment contributes to reducing security risks while improving user convenience for the managed server 310 present within the LAN.
[0126] In the above explanation, the management server 100 transmits the managed server IDs corresponding to the authenticated work user to the terminal 200 as a list of managed servers 310. Here, it goes without saying that the management server 100 may associate the managed server IDs with registered location information, distance thresholds, etc., and transmit the list of managed servers 310. The details of the list of managed servers 310 transmitted from the management server 100 to the terminal 200 do not matter as long as the information is usable when the user selects the managed server 310 that is the target of a usage application.
[0127] Furthermore, the terminal 200 may transmit terminal location information to the management server 100 together with an authentication request for the operation user. Then, when the management server 100 authenticates the operation user, it may refer to the managed server table 106 and identify managed servers 310 for which the difference between the terminal location information and the registered location information is within a predetermined range. Then, the management server 100 may transmit the managed server IDs of the identified managed servers 310 to the terminal 200 as a list of managed servers 310.
[0128] Also, a QR (Quick Response) code (registered trademark) including the managed server ID may be affixed to the managed server 310. Furthermore, in this first modification, the terminal 200 is assumed to be equipped with a camera (not shown). In this case, the terminal 200 uses the camera to photograph the QR code affixed to the managed server 310 and reads the information stored in the QR code (i.e., information including the managed server ID). The terminal 200 transmits the read information to the management server 100. The management server 100 refers to the managed server table 106 and acquires the managed server information based on the received managed server ID. Furthermore, the management server 100 refers to the usage application information table 105 and acquires the use application information based on the received managed server ID. The management server 100 may then transmit the acquired managed server information and use application information to the terminal 200.
[0129] In the above description, the control device 300 controls whether or not the privileged ID of the information processing device (managed server 310) can be used. However, this does not mean that the control target of the control device 300 is limited to the managed server 310. The managed device may be a network device. In this case, the control device 300 may connect to the network device (i.e., the managed device) and control whether or not the privileged ID of the network device can be used.
[0130] Furthermore, for example, the control device 300 may control a system configured to include two or more information processing devices. Specifically, the control device 300 may connect to the system and control whether or not privileged IDs can be used in the system. Any device with an ID set can be used, regardless of its type. The present invention is also described as follows: (Appendix 1) a managed device that can be operated using a first ID having a predetermined authority; a control device that controls the managed device; a terminal that acquires terminal location information indicating the location of the terminal and transmits the terminal location information to the control device; Including, The control device requests the managed device to authenticate the terminal, and if the managed device authenticates the terminal, the control device includes an ID usage management unit that determines whether to allow the terminal to use the first ID based on the terminal location information and the usage judgment time. (Appendix 2) The terminal acquires the terminal location information at predetermined time intervals and transmits the terminal location information to the control device; The management system described in Appendix 1, wherein, when the ID usage management unit receives the terminal location information from the terminal after the managed device has authenticated the terminal, it determines whether to allow the terminal to use the first ID corresponding to the managed device to which it is connected based on the terminal location information and the usage judgment time. (Appendix 3) The terminal transmits registered position information and a distance threshold to the control device; The management system described in Appendix 1 or 2, wherein the ID usage management unit permits the terminal to use the first ID when the managed device authenticates the terminal, when the difference between the terminal location information and the registered location information is less than the distance threshold, and when the usage judgment time is after a specified usage start time and before a specified usage end time. (Appendix 4) The management system described in Appendix 3, wherein the ID usage management unit makes the first ID corresponding to the managed device to be connected unavailable from the terminal, and then receives the terminal location information from the terminal, and if the usage determination time is after the usage start time and before the usage end time, allows the terminal to use the first ID corresponding to the managed device again based on the terminal location information. (Appendix 5) the managed device is connectable using a second ID different from the first ID, the terminal transmits authentication information corresponding to the second ID and the terminal location information to the control device; The management system described in any one of Appendices 1 to 4, wherein, when the ID usage management unit receives the authentication information, it requests the managed device to authenticate the authentication information, and when the managed device authenticates the authentication information sent from the terminal, it determines whether to allow the terminal to use the first ID based on the terminal location information and the usage judgment time when the terminal location information was received. (Appendix 6) Controlling a managed device that can be operated using a first ID having a predetermined authority; A control device comprising an ID usage management unit that requests the managed device to authenticate a terminal, and when the managed device authenticates the terminal, determines whether to permit the terminal to use the first ID based on terminal location information indicating the location of the terminal and a usage determination time. (Appendix 7) acquiring terminal location information indicating the location of the terminal; a step of requesting authentication of the terminal from a managed device that can be operated using a first ID having a predetermined authority; If the terminal is authenticated, determining whether or not to permit the terminal to use the first ID based on the terminal location information and the use determination time; A management method executed by a computer that controls a control device, comprising: (Appendix 8) receiving terminal location information indicating a location of the terminal from the terminal; a process of requesting authentication of a terminal from a managed device that can be operated using a first ID having a predetermined authority; If the terminal is authenticated, a process of determining whether or not to permit the terminal to use the first ID based on the terminal location information and the use determination time; A program that causes a computer that controls the control device to execute the above. The present invention can also be described as follows. (Form 1) a managed device that can be operated using a first ID having a predetermined authority; a control device that controls the managed device; a terminal that transmits terminal location information indicating the location of the terminal to the control device; Including, The control device requests the managed device to authenticate a second ID for using the first ID, and when the managed device authenticates the second ID, determines whether to permit the terminal to use the first ID based on a first time when terminal location information is received from the terminal. Management system. (Form 2) a managed device that can be operated using a first ID having a predetermined authority; a control device that controls the managed device; a terminal that transmits terminal location information indicating the location of the terminal to the control device; Including, The control device requests the managed device to authenticate a second ID in order to use the first ID, and when the managed device authenticates the second ID, determines whether to permit the terminal to use the first ID based on terminal location information received from the terminal at a first time. Management system. (Form 3) the control device, after permitting the terminal to use the first ID, makes the first ID that has been permitted for use unavailable when terminal location information is not received from the terminal within a first time interval; 3. The management system according to claim 1 or 2. (Form 4) the control device stores a start time and an end time that are a time range in which use of the first ID is permitted; If the first time is outside the range between the start time and the end time of the previous period, it is determined that the first ID is not to be used. The management system according to any one of the first to third aspects. (Form 5) when the current time passes the end time after the control device has permitted the terminal to use the first ID, the control device disables the first ID that has been permitted to be used. 5. The management system according to claim 4. (Form 6) Controlling an operable managed device using a first ID having a predetermined authority; receiving terminal location information indicating the location of the terminal from the terminal; A request is made to the managed device to authenticate a second ID for use of the first ID, and if the managed device authenticates the second ID, a determination is made as to whether or not to permit the terminal to use the first ID based on a first time when terminal location information is received from the terminal. Control device. (Form 7) Controlling an operable managed device using a first ID having a predetermined authority; receiving terminal location information indicating the location of the terminal from the terminal; A request is made to the managed device to authenticate a second ID in order to use the first ID, and if the managed device authenticates the second ID, a determination is made as to whether or not to permit the terminal to use the first ID based on terminal location information received from the terminal at a first time. Control device. (Form 8) the control device, after permitting the terminal to use the first ID, makes the first ID that has been permitted for use unavailable when terminal location information is not received from the terminal within a first time interval; The control device according to aspect 6 or 7. (Form 9) storing a start time and an end time of a time range in which the use of the first ID is permitted; If the first time is outside the range between the start time and the end time of the previous period, it is determined that the first ID is not to be used. The control device according to any one of aspects 6 to 8. (Form 10) when the current time passes the end time after the control device has permitted the terminal to use the first ID, the control device disables the first ID that has been permitted to be used. A control device according to aspect 9. (Form 11) receiving terminal location information indicating a location of the terminal from the terminal; a step of requesting a managed device, which is operable using a first ID having a predetermined authority, to authenticate a second ID for using the first ID; If the second ID is authenticated, determining whether to permit the terminal to use the first ID based on a first time when terminal location information is received from the terminal; A management method executed by a computer that controls a control device, comprising: (Form 12) receiving terminal location information indicating a location of the terminal from the terminal; a step of requesting a managed device, which is operable using a first ID having a predetermined authority, to authenticate a second ID for using the first ID; If the second ID is authenticated, determining whether or not to permit the terminal to use the first ID based on terminal location information received from the terminal at a first time; A management method executed by a computer that controls a control device, comprising: (Form 13) a step of disabling the first ID that has been permitted to be used when terminal location information is not received from the terminal within a first time interval after the terminal is permitted to use the first ID; 13. The management method according to aspect 11 or 12, comprising: (Form 14) a step of determining that use of the first ID is not permitted when the first time is outside a range of a start time and an end time that is a time range in which use of the first ID is permitted; 14. The management method according to any one of aspects 11 to 13, comprising: (Form 15) a step of disabling the first ID that has been permitted for use when the current time has passed the end time after the terminal has been permitted to use the first ID; 15. The method of claim 14, comprising: (Form 16) receiving terminal location information indicating the location of the terminal from the terminal; a process of requesting a managed device, which is operable using a first ID having a predetermined authority, to authenticate a second ID for using the first ID; If the second ID is authenticated, a process of determining whether or not to permit the terminal to use the first ID based on a first time when terminal location information is received from the terminal; A program that causes a computer that controls the control device to execute the above. (Form 17) receiving terminal location information indicating the location of the terminal from the terminal; a process of requesting a managed device, which is operable using a first ID having a predetermined authority, to authenticate a second ID for using the first ID; If the second ID is authenticated, a process of determining whether or not to permit the terminal to use the first ID based on terminal location information received from the terminal at a first time; A program that causes a computer that controls the control device to execute the above.
[0131] The disclosures of the above-mentioned patent documents are incorporated herein by reference. Modifications and adjustments of the embodiments are possible within the scope of the entire disclosure of the present invention (including the claims), and further based on the basic technical concept thereof. Furthermore, various combinations and selections of various disclosed elements (including each element of each claim, each element of each embodiment, each element of each drawing, etc.) are possible within the scope of the entire disclosure of the present invention. In other words, the present invention naturally embraces various modifications and alterations that would be possible by those skilled in the art in accordance with the entire disclosure, including the claims, and the technical concept thereof. In particular, with regard to the numerical ranges described herein, any numerical value or subrange within the range should be construed as specifically described, even if not otherwise specified. When algorithms, software, flowcharts, or automated process steps are described in the present invention, it is obvious that a computer is used, and that the computer is equipped with a processor, memory, or storage device. Therefore, even if such explicit content is not explicitly stated, these elements are considered to be included in the present application. [Explanation of symbols]
[0132] 1, 1000 Management System 100 Management Server 101 Management Server Memory Unit 102 ID Management Database 103 Usage Application Management Department 104 Management Server Control Unit 105 Usage application information table 106 Managed Server Table 107 Working User Table 200, 1030 terminals 201 ID Management Relay Unit 202 Location information acquisition section 300, 1020 Control device 301, 1021 ID Usage Management Department 310, 310a, 310b Managed Servers 400 Managed Server Network 1010 Managed Device
Claims
1. A control method in which a control device permits access to a managed device based on an ID used to use the managed device and location information of the terminal, and then acquires location information of the terminal and determines whether to allow continued access to the managed device based on the acquired location information.
2. The control method according to claim 1 , wherein the acquisition is performed a plurality of times, and whether or not to permit the continuation of the access is determined based on the location information acquired each time the acquisition is performed a plurality of times.
3. The control method according to claim 1 , wherein, if the control device does not acquire location information of the terminal after permitting the access, the control device denies continuation of the access.
4. A control device that, after permitting access to a managed device based on an ID used to use the managed device and location information of the terminal, acquires location information of the terminal and determines whether to allow continued access to the managed device based on the acquired location information.
5. The control device according to claim 4 , wherein the acquisition is performed a plurality of times, and whether or not to permit the continuation of the access is determined based on the position information acquired each time the acquisition is performed a plurality of times.
6. The control device according to claim 4 , wherein if location information of the terminal is not acquired after the access is permitted, continuation of the access is denied.
7. A program that causes a control device to execute a process of permitting access to a managed device based on an ID used to use the managed device and location information of the terminal, obtaining location information of the terminal after permitting the access, and determining whether to allow continued access to the managed device based on the location information.
8. a managed device; A terminal and a control device that, after permitting access to the managed device based on an ID used to use the managed device and location information of the terminal, acquires location information of the terminal, and determines whether to permit continued access to the managed device based on the acquired location information; A system comprising:
9. The system according to claim 8 , wherein the acquisition is performed a plurality of times, and the control device determines whether or not to permit the continuation of the access based on the location information acquired each time the acquisition is performed a plurality of times.
10. The system according to claim 8 , wherein the control device denies continuation of the access if the control device does not acquire location information of the terminal after permitting the access.
Citation Information
Patent Citations
Equipment, management module, program, and control method
JP2016058035A