Log information acquisition system and log information acquisition method
By integrating a VPN function within user terminals to manage data encryption and authentication, the system addresses traffic load and operational costs while ensuring controlled data acquisition and secure user trend analysis.
Patent Information
- Application Number
- JP2024090086
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-03
- Publication Date
- 2025-12-15
- Estimated Expiration
- 2044-06-03
AI Technical Summary
Existing VPN devices installed externally lead to increased traffic load and operational costs as more user terminals communicate, and there is a risk of accessing unintended or restricted content when using external VPN devices.
Integrating a VPN function within a user terminal to encrypt and decrypt data, allowing the terminal to acquire communication history as log information, with user authentication and parameter settings to control data acquisition.
Reduces network traffic and operational costs, limits data acquisition to specific applications and periods, and prevents unintended content access, enabling efficient user trend analysis for service providers.
Smart Images

Figure 2025182488000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a log information acquisition system that acquires log information when a server is accessed from an application in a terminal via a network. [Background technology]
[0002] With the advancement of communication technology, many communication services are now being offered by various service providers, etc., and access to various communication services is now commonplace using mobile devices such as smartphones. Meanwhile, service providers are working to expand the services they offer by acquiring log information on communication services accessed from users' mobile devices and analyzing user trends.
[0003] For example, Patent Document 1 discloses a log analysis system that includes a VPN (Virtual Private Network) device that collects log information and an analysis device that analyzes the collected log information between a user terminal and a server that provides communication services, and the VPN device receives encrypted data, decrypts the encrypted data, and then records it as log information. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2020-197929 Summary of the Invention [Problem to be solved by the invention]
[0005] In Patent Document 1, the VPN device is configured to be installed externally, and therefore the more user terminals that communicate via the VPN device, the greater the traffic load on the VPN device, which is expected to result in a tendency for the development costs and operating costs of traffic load distribution to increase.
[0006] In view of the above circumstances, the present invention aims to provide a log information acquisition system that incorporates a VPN function in a user terminal that uses a communication service, and that uses the VPN function to acquire communication history between an application in the user terminal and a server that provides the communication service as log information. [Means for solving the problem]
[0007] The log acquisition system of the first invention is a system that acquires, as log information, a communication history between an application in a user terminal and a server that provides a communication service, a user terminal equipped with a VPN (Virtual Private Network) function, which encrypts and decrypts data communicated between the application and the server using the VPN function, and acquires communication history between the application and the server as log information; a user authentication server that performs user authentication between the user terminal and the user and determines whether or not the VPN function is permitted to be used; a log acquisition server that receives and records the log information acquired by the user terminal from the user terminal, The user terminal a user authentication request unit that performs user authentication for each user using the user terminal with the user authentication server to allow use of the VPN function; a log acquisition parameter receiving unit that receives, from the user authentication server, log acquisition parameters in which acquisition conditions for the log information are set; a log information acquisition unit that uses the VPN function to acquire, based on the log acquisition parameters, a communication history between an application in the user terminal and a server that provides the communication service as log information, and transmits the log information to the log acquisition server; The present invention is characterized by having the following.
[0008] Here, the user terminal, user authentication server, and log acquisition server are configured to send and receive data via a communication network (Internet line, Wi-Fi line, mobile phone line, etc.), and each has a communication control function.
[0009] Furthermore, the user terminal is equipped with a VPN function, and for example, a VPN application is pre-installed in the user terminal as the VPN function.
[0010] According to the log acquisition system of the first aspect of the invention, it becomes possible to acquire log information in a variety of ways depending on the settings of the log acquisition parameters.
[0011] The log acquisition system of the second invention is the log acquisition system of the first invention, The user authentication server a user authentication unit that performs user authentication for each user using the user terminal regarding permission to use the VPN function in response to a user authentication request from the user terminal; setting ON / OFF selection information regarding whether or not the VPN function is permitted to be used for each user authenticated by the user authentication unit in the log acquisition parameters; a log acquisition parameter setting unit that, when the VPN function is turned on, sets selection information of an application in the user terminal from which the log information is to be acquired in the log acquisition parameters and transmits the log acquisition parameters to the user terminal; The log information acquisition unit of the user terminal has a means for, when the VPN function ON is selected in the log acquisition parameters, using the VPN function to acquire, as log information, the communication history between the application selected in the log acquisition parameters and the server that provides the communication service.
[0012] According to the log acquisition system of the second invention, it is possible to limit the applications in the user terminal from which the log information is to be acquired depending on the setting contents of the log acquisition parameter "application selection information," which is expected to reduce communication volume on the network and the volume of the log information recorded on the log acquisition server.
[0013] The log acquisition system of the third invention is the log acquisition system of the second invention, the log acquisition parameter setting unit of the user authentication server has means for setting, when the VPN function is turned on, "date and time information" in the log acquisition parameters as a period for acquiring the log information for each application set in the log acquisition parameters; The log information acquisition unit of the user terminal has a feature of having means for acquiring the log information based on the "date and time information" set in the log acquisition parameters.
[0014] According to the log acquisition system of the third invention, it is possible to limit the period for acquiring the log information for each application depending on the setting of the log acquisition parameter "date and time information," which is expected to have the effect of reducing the amount of log information recorded on the log acquisition server.
[0015] A log acquisition system according to a fourth aspect of the present invention is the system according to the second aspect of the present invention, the log acquisition parameter setting unit of the user authentication server has means for setting, when the VPN function is turned on, in the log acquisition parameters, items including at least one of "user name," "device name," "application name," "application package name," "user agent information," "connection destination host name or IP address," "communication time," "communication capacity," and "remaining battery level" as "acquisition items" to be acquired in the log information, The log information acquisition unit of the user terminal has a feature of having means for acquiring the log information based on the "acquisition items" set in the log acquisition parameters.
[0016] According to the log acquisition system of the fourth invention, it is possible to limit the "acquisition items" of the log information for each application depending on the setting contents of the log acquisition parameter "acquisition items," which is expected to have the effect of reducing the volume of the log information recorded on the log acquisition server.
[0017] A log acquisition system according to a fifth aspect of the present invention is the system according to the first aspect of the present invention, a log information analysis unit that analyzes the log information recorded in the log acquisition server based on a log analysis parameter; The log analysis parameters include at least one of the following items as criteria for analyzing the log information: "user name," "device name," "application name," and "communication time."
[0018] According to the log acquisition system of the fifth aspect of the present invention, it becomes possible to analyze log information in a variety of ways depending on the settings of the log analysis parameters.
[0019] The log acquisition method of the sixth invention comprises: A method for acquiring a communication history between an application in a user terminal and a server that provides a communication service as log information, comprising: In a user terminal equipped with a VPN (Virtual Private Network) function and acquiring the log information using the VPN function, performing user authentication for each user using the user terminal with a user authentication server regarding permission to use the VPN function; receiving, from the user authentication server, log acquisition parameters in which acquisition conditions for the log information are set; using the VPN function to acquire, based on the log acquisition parameters, a communication history between an application in the user terminal and a server that provides the communication service as log information, and transmitting the log information to a log acquisition server; In the user authentication server, a step of performing user authentication for each user using the user terminal in response to a user authentication request from the user terminal regarding permission to use the VPN function; Setting ON / OFF selection information regarding whether or not the VPN function is permitted to be used for each authenticated user in the log acquisition parameters, When the VPN function is turned on, setting selection information of an application in the user terminal from which the log information is to be acquired in the log acquisition parameters, and transmitting the log acquisition parameters to the user terminal; The present invention is characterized by comprising: [Effects of the Invention]
[0020] According to the present invention, a VPN function is installed in a user terminal that uses a communication service, and the VPN function is used to obtain the communication history between the application in the user terminal and the server that provides the communication service as log information. This enables the service provider to analyze the log information and easily analyze user trends, etc., which is expected to lead to an expansion of the services provided.
[0021] Furthermore, in cases where the VPN function is configured externally as a VPN device, the more user terminals that communicate via the VPN device, the greater the traffic load on the VPN device, which is expected to increase the development and operational costs of traffic load distribution. However, by configuring the VPN function to be installed inside the user terminal, it is expected that the development and operational costs can be reduced.
[0022] Furthermore, when a VPN device is configured externally, it becomes possible to access a variety of domestic and international content using the global IP address of the VPN device, which can lead to problems such as accessing unintended inappropriate content or being unable to access the intended content.However, by configuring the VPN function within the user's terminal, there is the advantage that the possibility of such problems occurring is eliminated. [Brief explanation of the drawings]
[0023] [Figure 1] 1 is a system configuration diagram showing an example of the system configuration of a log information acquisition system according to an embodiment of the present invention. [Figure 2] 2 is a functional configuration diagram showing an example of the functional configuration of a user terminal, a user authentication server, and a log acquisition server in the log information acquisition system according to the embodiment of the present invention. FIG. [Figure 3] FIG. 2 is a schematic diagram illustrating an example of log information acquired by the log information acquisition system according to the embodiment of the present invention. [Figure 4] 10 is a flowchart illustrating an example of a processing procedure executed by a user terminal and a user authentication server in the log information acquisition system according to the embodiment of the present invention. FIG. DETAILED DESCRIPTION OF THE INVENTION
[0024] A log information acquisition system according to one embodiment of the present invention will be described with reference to FIG.
[0025] Fig. 1 is a system configuration diagram showing an example of the system configuration of a log information acquisition system according to an embodiment of the present invention. As shown in Fig. 1, the log information acquisition system includes a user terminal 10 equipped with a VPN (Virtual Private Network) function, a user authentication server 20 that performs user authentication between the user terminal 10, and a log acquisition server 30 that records log information transmitted from the user terminal 10. Here, the user terminal 10, the user authentication server 20, and the log acquisition server 30 each have a communication control function for transmitting and receiving data via a communication network (such as an Internet line, a Wi-Fi line, or a mobile phone line).
[0026] The user terminal 10 includes mobile terminals such as smartphones and tablet terminals, and computers such as notebook computers.
[0027] Furthermore, the user terminal 10 is equipped with a VPN function, and for example, a VPN application is pre-installed in the user terminal as the VPN function.
[0028] Here, the VPN function includes a function to encrypt and decrypt data communicated between an application in the user terminal 10 and the server 50 that provides the communication service, and a function to acquire communication history between the application in the user terminal 10 and the server 50 that provides the communication service as log information.
[0029] As shown in FIG. 1, the log information acquisition system performs user authentication between a user terminal 10 and a user authentication server 20 regarding permission to use a VPN function. When the VPN function is ON (the VPN function is being used), the system encrypts and decrypts data communicated between applications (apps A and C) in the user terminal 10 and servers 50 (servers A and B) that provide communication services. The system also acquires communication history between the applications (apps A and C) in the user terminal 10 and servers 50 (servers A and B) that provide communication services as log information and transmits the log information to a log acquisition server 30. In the example shown in FIG. 1, app B does not have a communication function and does not communicate with an external server, so the log information is not acquired even when the VPN function is ON. In the example shown in FIG. 1, a log acquisition app is pre-installed in the user terminal 10 as an application for acquiring the log information when the VPN function is ON.
[0030] Furthermore, when the VPN function is OFF (when the VPN function is not used), the log information is not acquired. Here, as the VPN encryption method, for example, encryption by the SSL (Secure Sockets Layer) protocol is used. Furthermore, when acquiring the log information, the user terminal 10 acquires unencrypted data as log information for upstream data (data sent from the user terminal 10 to the server 50), and acquires encrypted data as log information after decrypting it for downstream data (data received by the user terminal 10 from the server 50).
[0031] After acquiring the log information, the user terminal 10 transmits the log information to the log acquisition server 30 at a preset timing.
[0032] The log acquisition server 30 records the log information transmitted from the user terminal 10 .
[0033] Next, the functional configuration of the user terminal 10, the user authentication server 20, and the log acquisition server 30 in the log information acquisition system 1 will be described with reference to the functional configuration diagram shown in FIG.
[0034] <User terminal 10> The user terminal 10 includes a user authentication request unit 11, a log acquisition parameter receiving unit 12, and a log information acquiring unit 13.
[0035] The user authentication request unit 11 performs user authentication with the user authentication server 20 regarding permission to use the VPN function for each user who uses the user terminal 10, and receives from the user authentication server 20 either VPN function ON (VPN function is used) or VPN function OFF (VPN function is not used) as the authentication result.
[0036] The log acquisition parameter receiving unit 12 receives the log acquisition parameters 40 in which information relating to the acquisition of the log information is set. For example, the following information is set in the log acquisition parameters 40: VPN function ON / OFF selection information - Information on the selection of applications on the user's device from which log information is to be collected Date and time information for the period during which log information is acquired Items to be acquired from log information -Data type of data communication direction for which log information is to be acquired This allows log information to be acquired in a variety of ways depending on the settings of the log acquisition parameters 40.
[0037] The log information acquisition unit 13 acquires log information when the VPN function is selected as ON in the log acquisition parameters 40. That is, the log information acquisition unit 13 uses the VPN function to acquire, based on the settings of the log acquisition parameters 40, a communication history between an application in the user terminal 10 and the server 50 that provides the communication service as log information, and transmits the log information to the log acquisition server 30.
[0038] The log information acquisition unit 13 also has means for acquiring, as log information, a communication history between the application selected by the log acquisition parameter 40 and the server that provides the communication service, using the VPN function. This makes it possible to limit the applications in the user terminal 10 from which log information is to be acquired.
[0039] Furthermore, the log information acquisition unit 13 has a means for acquiring the log information using the VPN function based on "date and time information" that is the log information acquisition period set in the log acquisition parameters 40. This makes it possible to limit the period for acquiring log information, which is expected to have the effect of reducing the volume of log information.
[0040] Furthermore, the log information acquisition unit 13 has means for using the VPN function to acquire the log information based on at least one of the following "acquisition items" set in the log acquisition parameters 40 as targets for acquiring log information: "user name," "device name," "application name," "application package name," "user agent information," "destination host name or IP address," "communication time," "communication capacity," and "remaining battery capacity." This makes it possible to limit the "acquisition items" as targets for acquiring log information, which is expected to have the effect of reducing the volume of log information.
[0041] When the log information acquisition unit 13 acquires the communication history between the application in the user terminal 10 and the server 50 that provides the communication service as log information, there are cases where it is not possible to directly acquire the "application name" as an "acquisition item" to be acquired for the log information. In such cases, the log information acquired includes the "application package name," "user agent information," "destination host name or IP address," and the like, contained in the communication history. The "application name" can be identified from this information. Further specific examples will be described below.
[0042] When obtaining the log information, there may be cases where it is not possible to obtain, for example, [App A] as the "application name." In such cases, it may be possible to obtain the identification code of the application that is the source of the communication, and from this identification code, it may be possible to identify [App A] as the "application name," which may then be used as log information for [App A].
[0043] Alternatively, when obtaining the log information, there may be cases where it is not possible to obtain, for example, [App C] as the "application name." In such cases, it may be possible to obtain information such as the "destination host name," "destination IP address," and "user agent information," and then use this information to verify that it is an identifier contained in the log issued by [App C], thereby identifying [App C] as the "application name," which may then be used as log information for [App C].
[0044] Furthermore, the log information acquisition unit 13 has means for acquiring the log information using the VPN function, targeting either or both of "upstream data (data sent from the user terminal 10 to the server 50)" and "downstream data (data received by the user terminal 10 from the server 50)" based on the "data type in the data communication direction" for which log information is to be acquired and set in the log acquisition parameter 40. This makes it possible to limit the "data type in the data communication direction" for which log information is to be acquired, which is expected to have the effect of reducing the volume of log information.
[0045] <User authentication server 20> The user authentication server 20 includes a user authentication unit 21 and a log acquisition parameter setting unit 22.
[0046] In response to a user authentication request from the user terminal 10, the user authentication unit 21 performs user authentication regarding permission to use the VPN function for each user using the user terminal 10, and determines whether the VPN function is ON (the VPN function is used) or OFF (the VPN function is not used) as the authentication result.
[0047] The log acquisition parameter setting unit 21 sets ON / OFF selection information regarding whether or not to use the VPN function for each user authenticated by the user authentication unit in the log acquisition parameter 40, and when the VPN function ON is selected, it sets, for example, the following information in the "log acquisition parameter 40" and then transmits the log acquisition parameter 40 to the user terminal 10.
[0048] (1) Selection information for applications in the user terminal 10 from which log information is to be acquired →The applications from which log information is to be acquired are limited from among the applications in the user terminal 10.
[0049] (2) Date and time information for the period during which log information is to be collected → The period for acquiring log information is limited. Furthermore, for example, the period for acquiring log information may be limited for each application. Alternatively, for example, the period for acquiring log information may be limited for each user terminal.
[0050] (3) Item information for which log information is to be acquired → The "acquisition items" of the log information are limited by setting items including at least one of the following as the "acquisition items" of the log information: "user name," "device name," "application name," "application package name," "user agent information," "destination host name or IP address," "communication time," "communication capacity," and "remaining battery level." Furthermore, for example, the "acquisition items" of the log information may be limited for each application. Alternatively, for example, the "acquisition items" of the log information may be limited for each user terminal.
[0051] (4) Data type of data communication direction for which log information is to be acquired →By setting "upstream data (data sent from the user terminal 10 to the server 50)" and "downstream data (data received by the user terminal 10 from the server 50)" as targets for obtaining log information, the data type for which log information is to be obtained is limited. Furthermore, for example, the data type for which log information is to be obtained may be limited for each application.
[0052] The log acquisition parameter setting unit 21 may be configured to automatically set the above-described setting contents for each user for the log acquisition parameters 40. Alternatively, the log acquisition parameter setting unit 21 may be configured to provide a GUI (Graphical User Interface) so that the above-described setting contents can be set by manual input.
[0053] <Log Acquisition Server 30> The log acquisition server 30 includes a log information recording unit 31 .
[0054] The log information recording unit 31 receives the log information acquired by the user terminal 10 from the user terminal 10 and records it in a storage device.
[0055] Fig. 3 shows an example of the recorded log information. As shown in Fig. 3, information such as the "date and time" when the log information was acquired, the "device name," "user name," "application name," and "communication capacity" of the user terminal 10 that received the log information is recorded. In the example of Fig. 3, the log information is recorded in chronological order, but this is not limitative, and the log information may be recorded, for example, by dividing it into "device name" or "application name."
[0056] 2, it is also assumed that the log acquisition server 30 has a log information analysis unit that analyzes the log information recorded in the log acquisition server 30 based on log analysis parameters. These log analysis parameters include at least one of the following items, for example, "user name," "device name," "application name," and "communication time," as criteria for analyzing the log information. Note that the procedure for analyzing the log information here uses well-known conventional technology.
[0057] The above is the configuration of the log information acquisition system 1 of this embodiment. In the above configuration, the user terminal 10, the user authentication server 20, and the log acquisition server 30 are configured with hardware such as a CPU (Central Processing Unit), a ROM (Read Only Memory), and a RAM (Random Access Memory), and store and retain programs for executing various processes described below in memory (not shown), and function as an arithmetic device (sequencer) for executing various processes by executing the programs.
[0058] Next, the processing procedure executed by the log information acquisition system 1 will be described with reference to the flowchart shown in FIG.
[0059] <User terminal 10> In step S11, User authentication is performed between the user authentication server 20 and the user terminal 10 for each user regarding permission to use the VPN function, and either VPN function ON (VPN function is used) or VPN function OFF (VPN function is not used) is received as the authentication result from the user authentication server 20.
[0060] In step S12, The log acquisition parameters 40 are received, in which information related to the acquisition of the log information is set. For example, the following information is set in the log acquisition parameters 40. (For details of the log acquisition parameters 40, see the explanation above.) VPN function ON / OFF selection information - Information on the selection of applications on the user's device from which log information is to be collected Date and time information for the period during which log information is acquired Items to be acquired from log information -Data type of data communication direction for which log information is to be acquired This allows log information to be acquired in a variety of ways depending on the settings of the log acquisition parameters 40.
[0061] In step S13, It is determined whether or not the VPN function installed in the user terminal 10 is in use. If the VPN function is ON (the VPN function is in use), the process proceeds to the next step S14 to acquire log information. Alternatively, if the VPN function is OFF (the VPN function is not in use), the process ends because no log information is acquired.
[0062] In step S14, Using the VPN function, the communication history between the application in the user terminal 10 and the server 50 that provides the communication service is acquired as log information based on the settings of the log acquisition parameters 40. The acquired log information is also sent to the log acquisition server 30 at a preset timing.
[0063] <User authentication server> In step S21, In response to a user authentication request from the user terminal 10, user authentication is performed for each user using the user terminal 10 regarding permission to use the VPN function, and the authentication result determines whether the VPN function is ON (the VPN function is used) or OFF (the VPN function is not used).
[0064] In step S22, For each user authenticated by the user authentication unit, ON / OFF selection information regarding whether or not to use the VPN function is set in the log acquisition parameters 40, and when the VPN function ON is selected, for example, the following information is set in the log acquisition parameters 40, and then the log acquisition parameters 40 are transmitted to the user terminal 10. (See the explanation above for details of the log acquisition parameters 40.) VPN function ON / OFF selection information - Information on the selection of applications on the user's device from which log information is to be collected Date and time information for the period during which log information is collected -Item information for which log information is to be acquired -Data type of data communication direction for which log information is to be acquired The log acquisition parameters 40 may be configured so that the above-described settings are automatically set for each user, or may be configured so that a GUI (Graphical User Interface) is provided so that the above-described settings can be set manually.
[0065] Although the embodiments for carrying out the present invention have been described above with reference to the drawings, the present invention is not limited to these embodiments. [Explanation of symbols]
[0066] 1. Log information acquisition system 10...User terminal 11...User authentication request section 12...Log acquisition parameter receiver 13...Log information acquisition unit 20...User authentication server 21...User authentication section 22...Log acquisition parameter setting section 30...Log acquisition server 31...Log information recording section 40...Log acquisition parameters 50...Server that provides communication services
Claims
1. A system for acquiring communication history between an application in a user terminal and a server that provides a communication service as log information, a user terminal equipped with a VPN (Virtual Private Network) function, which encrypts and decrypts data communicated between the application and the server using the VPN function, and acquires communication history between the application and the server as log information; a user authentication server that performs user authentication between the user terminal and the user and determines whether or not the VPN function is permitted to be used; a log acquisition server that receives and records the log information acquired by the user terminal from the user terminal; Equipped with The user terminal a user authentication request unit that performs user authentication for each user using the user terminal with the user authentication server to allow the use of the VPN function; a log acquisition parameter receiving unit that receives, from the user authentication server, log acquisition parameters in which acquisition conditions for the log information are set; a log information acquisition unit that uses the VPN function to acquire, based on the log acquisition parameters, a communication history between an application in the user terminal and a server that provides the communication service as log information, and transmits the log information to the log acquisition server; A log information acquisition system comprising:
2. 2. The log information acquisition system according to claim 1, The user authentication server a user authentication unit that performs user authentication for each user using the user terminal in response to a user authentication request from the user terminal regarding permission to use the VPN function; setting, in the log acquisition parameters, ON / OFF selection information regarding whether or not the VPN function is permitted to be used for each user authenticated by the user authentication unit; a log acquisition parameter setting unit that, when the VPN function is turned on, sets selection information of an application in the user terminal from which the log information is to be acquired in the log acquisition parameters and transmits the log acquisition parameters to the user terminal; A log information acquisition system characterized in that the log information acquisition unit of the user terminal has a means for using the VPN function to acquire, as log information, the communication history between the application selected by the log acquisition parameters and the server providing the communication service when the VPN function ON is selected in the log acquisition parameters.
3. 3. The log information acquisition system according to claim 2, the log acquisition parameter setting unit of the user authentication server has means for setting "date and time information" as a period for acquiring the log information in the log acquisition parameters when the VPN function is selected to be ON; A log information acquisition system, wherein the log information acquisition unit of the user terminal has means for acquiring the log information based on the "date and time information" set in the log acquisition parameters.
4. 3. The log information acquisition system according to claim 2, the log acquisition parameter setting unit of the user authentication server has means for setting, when the VPN function is turned on, "acquisition items" to be acquired in the log information, items including at least one of "user name," "device name," "application name," "application package name," "user agent information," "destination host name or IP address," "communication time," "communication capacity," and "remaining battery level," in the log acquisition parameters; A log information acquisition system characterized in that the log information acquisition unit of the user terminal has means for acquiring the log information based on the "acquisition items" set in the log acquisition parameters.
5. 2. The log information acquisition system according to claim 1, a log information analysis unit that analyzes the log information recorded in the log acquisition server based on a log analysis parameter; A log information acquisition system characterized in that the log analysis parameters include at least one of the following items as criteria for analyzing the log information: "user name," "device name," "application name," and "communication time."
6. A method for acquiring a communication history between an application in a user terminal and a server that provides a communication service as log information, comprising: In a user terminal equipped with a VPN (Virtual Private Network) function and acquiring the log information using the VPN function, performing user authentication for each user using the user terminal with a user authentication server to grant permission to use the VPN function; receiving, from the user authentication server, log acquisition parameters in which acquisition conditions for the log information are set; using the VPN function to acquire, based on the log acquisition parameters, a communication history between an application in the user terminal and a server that provides the communication service as log information, and transmitting the log information to a log acquisition server; In the user authentication server, a step of performing user authentication for each user using the user terminal in response to a user authentication request from the user terminal regarding permission to use the VPN function; Setting ON / OFF selection information regarding whether or not the VPN function is permitted to be used for each authenticated user in the log acquisition parameters, When the VPN function is turned on, setting selection information of an application in the user terminal from which the log information is to be acquired in the log acquisition parameters, and transmitting the log acquisition parameters to the user terminal; A log information acquisition method comprising:
Citation Information
Patent Citations
Log analysis system and log analysis method
JP2020197929A