Distribution program, distribution device, distribution method, recording medium containing the distribution program, update program, update device, update method, recording medium containing the update program, and update management system.

The distribution program and device address the challenge of managing updates for individual targets by using an acquisition, specification, and output procedure to ensure targeted and efficient update distribution.

JP2026070708APending Publication Date: 2026-04-28NEC SOLUTION INNOVATORS LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
NEC SOLUTION INNOVATORS LTD
Filing Date
2024-10-16
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing systems lack the ability to manage updates for individual targets effectively.

Method used

A distribution program and device that includes an acquisition, specification, and output procedure to manage updates by identifying and distributing update content information based on pre-assigned identification information for each target.

Benefits of technology

Enables targeted and efficient management of updates for each individual target, ensuring appropriate update content is distributed based on the specific needs and status of the target.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026070708000001_ABST
    Figure 2026070708000001_ABST
Patent Text Reader

Abstract

This disclosure provides a distribution program that allows for the management of updates on a per-target basis. [Solution] The distribution program of this disclosure includes an acquisition procedure, an identification procedure, and an output procedure, wherein the acquisition procedure acquires request information relating to a request to acquire update content information from an update device, the request information includes identification information for identifying a target, the update content information is information relating to the update content of the software provided by the update device, the identification procedure identifies a storage area corresponding to the identification information from a group of storage areas, the storage area is pre-assigned the identification information for each target and includes the update content information for each target, and the output procedure outputs the update content information contained in the identified storage area to the update device as a response to the request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a distribution program, a distribution device, a distribution method, a recording medium storing the distribution program, an update program, an update device, an update method, a recording medium storing the update program, and an update management system.

Background Art

[0002] In Patent Document 1, there is disclosed an information processing apparatus including a connection means for automatically connecting to a server, a reception means for automatically performing reception processing of one or more programs from the server, and an installation means for automatically performing installation processing of the program to the information processing apparatus.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] According to the invention according to Patent Document 1, updates can be automatically executed. On the other hand, the invention according to Patent Document 1 is not capable of managing updates for each target.

[0005] Therefore, an object of the present disclosure is to provide a distribution program, a distribution device, a distribution method, and a recording medium storing the distribution program that can manage updates for each target.

Means for Solving the Problems

[0006] In order to achieve the above object, the distribution program of the present disclosure includes an acquisition procedure, a specification procedure, and an output procedure, wherein the acquisition procedure acquires request information regarding a request for acquiring update content information from an update device, The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification procedure involves identifying the storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output procedure involves outputting the update content information contained in the identified storage area to the update device as a response to the request. This is a program that causes a computer to execute each of the aforementioned steps.

[0007] The distribution device in this disclosure is The acquisition unit acquires request information relating to a request to acquire update content information from the update device. The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification unit identifies the storage area corresponding to the identification information from the group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output unit outputs the update content information contained in the identified storage area to the update device as a response to the request. It is a device.

[0008] The distribution method of this disclosure is: Including the acquisition process, the identification process, and the output process, The acquisition step involves acquiring request information related to a request to acquire update content information from the update device. The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The aforementioned identification step involves identifying a storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output step outputs the update content information contained in the identified storage area to the update device as a response to the request. This method involves each of the aforementioned steps being performed by a computer.

[0009] The recording medium disclosed herein is Including acquisition procedures, identification procedures, and output procedures, The acquisition procedure described above involves obtaining request information regarding the request to acquire update content information from the update device, The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification procedure involves identifying the storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output procedure involves outputting the update content information contained in the identified storage area to the update device as a response to the request. This is a computer-readable recording medium containing a distribution program that causes a computer to execute each of the aforementioned procedures. [Effects of the Invention]

[0010] According to this disclosure, updates can be managed for each individual target. [Brief explanation of the drawing]

[0011] [Figure 1] Figure 1(A) is a block diagram showing an example of the configuration of the distribution device of this disclosure. Figure 1(B) is a block diagram showing another example of the configuration of the distribution device of this disclosure. Figure 1(C) is a block diagram showing yet another example of the configuration of the distribution device of this disclosure. [Figure 2] Figure 2 is a block diagram showing an example of the hardware configuration of the distribution device of the present disclosure. [Figure 3] Figure 3(A) is a flowchart showing an example of the procedure by the distribution program of the present disclosure. Figure 3(B) is a flowchart showing another example of the procedure by the distribution program of the present disclosure. Figure 3(C) is a flowchart showing another example of the procedure by the distribution program of the present disclosure. [Figure 4] Figure 4(A) is a block diagram showing an example of the configuration of the update device of the present disclosure. Figure 4(B) is a block diagram showing another example of the configuration of the update device of the present disclosure. [Figure 5] Figure 5 is a block diagram showing an example of the hardware configuration of the update device of the present disclosure. [Figure 6] Figure 6(A) is a flowchart showing an example of the procedure by the update program of the present disclosure. Figure 6(B) is a flowchart showing another example of the procedure by the update program of the present disclosure. [Figure 7] Figure 7 is a block diagram showing an example of the configuration of the update management system of the present disclosure. [Figure 8] Figure 8 is a flowchart showing an example of the procedure by the update management program of the present disclosure. [Figure 9] Figure 9 is a schematic diagram showing an example of the usage form of the update management system of the present disclosure.

Mode for Carrying Out the Invention

[0012] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. The present disclosure is not limited to the following embodiments. In the following figures, the same parts are denoted by the same reference numerals. Also, the descriptions of the respective embodiments can be mutually referred to unless otherwise specified, and the configurations of the respective embodiments can be combined unless otherwise specified. In the present disclosure, each drawing can apply to one or more embodiments.

[0013] [Embodiment 1] The distribution program of this disclosure is a program that causes a computer to perform acquisition procedures, identification procedures, and output procedures. The distribution program of this disclosure can also be described as a program that causes a computer to function as the acquisition procedure, identification procedure, and output procedure. Furthermore, the distribution program of this disclosure can also be described as a program that causes a computer to perform each step of the distribution method described later.

[0014] The acquisition procedure involves acquiring request information from the update device for a request to acquire update content information, wherein the request information includes identification information for identifying a target, and the update content information is information relating to the update content of the software provided by the update device; the identification procedure involves identifying a storage area corresponding to the identification information from a group of storage areas, wherein the storage area is pre-assigned the identification information for each target and includes the update content information for each target; and the output procedure outputs the update content information contained in the identified storage area to the update device as a response to the request.

[0015] Each of the aforementioned procedures can be reinterpreted, for example, as a "process." The distribution program of this disclosure may also be recorded on, for example, a computer-readable storage medium. The storage medium is, for example, a non-transitory computer-readable storage medium. The storage medium is not particularly limited and includes, for example, random access memory (RAM), read-only memory (ROM), hard disk (HD), flash memory (e.g., SSD (Solid State Drive), USB flash memory, SD / SDHC card, etc.), optical disc (e.g., CD-R / CD-RW, DVD-R / DVD-RW, BD-R / BD-RE, etc.), magneto-optical disk (MO), floppy disk (FD), etc. The distribution program of this disclosure (for example, also called a programming product or program product) may also be delivered, for example, from an external computer. The "delivery" may be, for example, delivery via a communication network or delivery via a wired device. The distribution program of this disclosure may be installed and executed on the device to which it is distributed, or it may be executed without being installed. An information processing device capable of executing the distribution program of this disclosure may be, for example, the distribution device of this disclosure.

[0016] Next, an example of the configuration of the distribution device of this disclosure will be described using Figure 1(A). Figure 1(A) is a block diagram showing an example of the configuration of the distribution device 10 of this disclosure (hereinafter also referred to as "the device 10"). As shown in Figure 1(A), the device 10 includes an acquisition unit 11, a specification unit 12, and an output unit 13. The device 10 may also include, for example, an input unit, other output units, a display unit, and / or a storage unit, although these are not shown. The acquisition unit 11, the specification unit 12, and the output unit 13 can each execute, for example, the acquisition procedure, specification procedure, and output procedure in the distribution program of this disclosure. The acquisition unit 11 can also be called, for example, a request information acquisition unit. The output unit 13 can also be called, for example, an update content information output unit.

[0017] The device 10 may be, for example, a single device including the aforementioned parts, or it may be a device in which each of the aforementioned parts can be connected via a communication network. Furthermore, the device 10 can be connected to an external device described later via the communication network. The communication network is not particularly limited and can use a known network, for example, it may be wired or wireless. Examples of the communication network include the Internet, WWW (World Wide Web), telephone lines, LAN (Local Area Network), SAN (Storage Area Network), DTN (Delay Tolerant Networking), LPWA (Low Power Wide Area), L5G (Local 5G), etc. Examples of wireless communication include Wi-Fi (registered trademark), Bluetooth (registered trademark), Local 5G, LPWA, etc. The wireless communication may be in the form of direct communication between devices (Ad Hoc communication), infrastructure communication, indirect communication via an access point, etc. The device 10 may be, for example, incorporated into a server as a system. Furthermore, the device 10 may be, for example, a personal computer (PC, e.g., desktop or notebook), smartphone, tablet terminal, etc., on which the program of this disclosure is installed. The device 10 may also be in the form of cloud computing or edge computing, for example, in which at least one of the aforementioned parts is on a server and the other aforementioned parts are on a terminal.

[0018] Figure 2 illustrates a block diagram of the hardware configuration of the device 10. The device 10 includes, for example, a central processing unit (CPU, GPU, etc.) 101, memory 102, bus 103, storage device 104, input device 105, output device 106, communication device 107, etc. Each part of the device 10 is interconnected via the bus 103 through its respective interface (I / F).

[0019] The central processing unit 101 operates in coordination with other components via controllers (system controller, I / O controller, etc.) and is responsible for the overall control of the device 10. In the device 10, the central processing unit 101 executes, for example, the program disclosed herein (distribution program) and other programs, and also reads and writes various types of information. Specifically, for example, the central processing unit 101 functions as an acquisition unit 11, a specification unit 12, and an output unit 13. The device 10 may also include other computing devices such as a CPU, GPU (Graphics Processing Unit), APU (Accelerated Processing Unit), or a combination thereof as computing devices.

[0020] Bus 103 can also be connected to external devices, for example. Examples of such external devices include external storage devices (external databases, etc.), printers, external input devices, external display devices, and external imaging devices. The device 10 can be connected to an external network (the aforementioned communication network) via a communication device 107 connected to bus 103, for example, and can also be connected to other devices via the external network.

[0021] Memory 102 may be, for example, main memory. When the central processing unit 101 performs processing, memory 102 reads various operational programs, such as the program of this disclosure, stored in the storage device 104 (described later), and the central processing unit 101 receives data from memory 102 and executes the program. The main memory may be, for example, RAM (random access memory). Alternatively, memory 102 may be, for example, ROM (read-only memory).

[0022] The storage device 104 is also called an auxiliary storage device, for example, in relation to the main memory (primary memory). As described above, the storage device 104 stores an operating program including the program of this disclosure. The storage device 104 may be, for example, a combination of a recording medium and a drive for reading and writing to the recording medium. The recording medium is not particularly limited and may be internal or external, for example, an HD (hard disk), CD-ROM, CD-R, CD-RW, MO, DVD, flash memory, memory card, etc. The storage device 104 may be, for example, a hard disk drive (HDD) in which the recording medium and the drive are integrated, or a solid state drive (SSD). If the device 10 includes the storage unit, for example, the storage device 104 functions as the storage unit. The storage unit can record, for example, identification information, request information, request-related information, update content information, update content-related information, log information, etc., which will be described later.

[0023] In this device 10, the memory 102 and storage device 104 can also store various types of information, such as log information, information obtained from an external database (not shown) or external devices, information generated by this device 10, and information used by this device 10 when executing processing. In this case, the memory 102 and storage device 104 may store, for example, the user information of this device as described above. At least some of the information may be stored on an external server other than the memory 102 and storage device 104, or it may be stored in a distributed manner across multiple terminals using blockchain technology or the like.

[0024] The device 10 further includes, for example, an input device 105 and an output device 106. The input device 105 may include, for example, a pointing device such as a touch panel, trackpad, or mouse; a keyboard; imaging means such as a camera or scanner; a card reader such as an IC card reader or magnetic card reader; an audio input means such as a microphone; and so on. The output device 106 may include, for example, a display device such as an LED display or liquid crystal display; an audio output device such as a speaker; a printer; and so on. In this embodiment 1, the input device 105 and the output device 106 are configured separately, but the input device 105 and the output device 106 may be configured as an integrated unit, such as a touch panel display.

[0025] An example of processing performed by the distribution program of this disclosure will be explained in more detail using Figure 3(A). Figure 3(A) is a flowchart showing an example of each step in the distribution program of this disclosure.

[0026] The acquisition unit 11 acquires request information relating to a request to acquire update content information from the update device (S11, acquisition procedure). Note that S11 can also be called, for example, the request information acquisition procedure. The update device may be, for example, the update device disclosed herein.

[0027] The acquisition unit 11 may, for example, acquire request information relating to a request to acquire update content information from multiple update devices, or from update devices for multiple targets, or from multiple update devices for multiple targets.

[0028] The aforementioned request information is information relating to a request to obtain update content information. The number of the aforementioned request information may vary, for example, depending on the number of update devices and the number of targets. The number of the aforementioned request information may be, for example, one or two or more. The format of the request may be set appropriately, for example, depending on the protocol relating to communication between the update device and the distribution device. The protocol may be set appropriately, for example, depending on the format in which the storage device provided by the distribution device, described later, manages information. For example, if the format in which the storage device provided by the distribution device manages information is a file storage format, the protocol may include NFS (Network File System), CIFS (Common Internet File System), and SMB (Server Message Block), but there is no limit to the description. For example, if the format in which the storage device provided by the distribution device manages information is a block storage format, the protocol may include SCSI (Small Computer System Interface), iSCSI (Internet SCSI), and FC (Fibre Channel), but there is no limit to the description. The protocol may include, for example, HTTP (Hypertext Transfer Protocol) and HTTPS (Hypertext Transfer Protocol Secure) when the storage device provided by the distribution device manages information in an object storage format, but is not limited to this description. The format of the request may be, for example, an HTTP request when the protocol is HTTP or HTTPS. The format of the HTTP request may include, for example, the GET method, the PUT method, and the POST method, but is not limited to this description.

[0029] The request information includes identification information for identifying the target. The identification information may be, for example, information pre-assigned to the update device. The identification information may be, for example, information pre-assigned to the configuration information described later. The identification information may be stored, for example, in the memory or storage device of the update device. The identification information may be obtained, for example, from a file to which the identification information has been assigned by the update device, or from the account information of an account to which the identification information has been assigned by the update device. The identification information may be, for example, letters, numbers, symbols, or a combination thereof. The identification information may be, for example, plain text or ciphertext. In the latter case, the form of encryption of the identification information may include, for example, a form using symmetric key cryptography, a form using public key cryptography, and a form using a hash function, but there is no limit to the description. The hash function may be, for example, as described later. The identification information may be included, for example, in the request line, request header, or request body of the request information if the form of the request is the HTTP request. The identification information may, for example, be included in the request parameters of the request information if the format of the request is the HTTP request. The request parameters may include, for example, query parameters, body parameters, header parameters, and path parameters, but are not limited to such descriptions. The identification information may, for example, be included in the URI (Uniform Resource Identifier) ​​parameter if the format of the request is the HTTP request. The URI parameters may include, for example, URL (Uniform Resource Locator) parameters and URN (Uniform Resource Name) parameters. The identification information may be set appropriately depending on the type of target, for example. The identification information may include, for example, at least one of organization identification information and device identification information.

[0030] The aforementioned identification information may, for example, be organizational identification information that can identify the organization if the subject is an organization. The aforementioned organizational identification information may, for example, be a medical institution code and a code including the medical institution code if the organization is a medical institution or a pharmacy, but there are no restrictions on the description. The code including the medical institution code may, for example, be a code that includes an arbitrary code in addition to the medical institution code. The aforementioned code including the medical institution code may, for example, be a code that includes a prefecture number and a fee category code in addition to the medical institution code. The aforementioned organizational identification information may, for example, be a national local government code and a code including the national local government code if the organization is a local government, but there are no restrictions on the description. The aforementioned code including the national local government code may, for example, be a code that includes an arbitrary code in addition to the national local government code. The aforementioned organizational identification information may, for example, be a government agency code and a code including the government agency code if the organization is a government agency, but there are no restrictions on the description. The aforementioned code including the government agency code may, for example, be a code that includes an arbitrary code in addition to the government agency code. The aforementioned organizational identification information may include, for example, a financial institution code and a code including the financial institution code if the organization is a financial institution, but there are no limitations on the description. The code including the financial institution code may also include, for example, a code including an arbitrary code in addition to the financial institution code. The aforementioned organizational identification information may also be, for example, a code in a foreign country other than Japan if the subject is an organization in a foreign country other than Japan that corresponds to the code mentioned above. According to this disclosure, for example, updates can be managed on an organization-by-organization basis. According to this disclosure, for example, update content information suitable for each organization can be distributed to multiple organizations. According to this disclosure, for example, if the software update status differs from organization to organization, update content information can be distributed according to the update status of each organization. According to this disclosure, for example, if the software settings differ from organization to organization, update content information can be distributed according to the settings of each organization. According to this disclosure, for example, if the software execution environment differs from organization to organization, update content information can be distributed according to the execution environment of each organization.

[0031] The aforementioned identification information may, for example, be device identification information that can identify the device if the target is a device. The aforementioned device identification information may, for example, be the International Mobile Equipment Identity (IMEI), Mobile Equipment IDentifier (MEID), International Mobile Subscriber Identity (IMSI), IC Card IDentifier (ICCID), Media Access Control address (MAC address), and codes including these, if the device is an information processing device, but there are no limitations to the description. The aforementioned device identification information may, for example, be an identifier unique to the operating system if the device is an information processing device. The aforementioned device identification information may, for example, be the serial number of the peripheral device if the device is a peripheral device. According to this disclosure, for example, updates can be managed for each device. Also, according to this disclosure, for example, update content information suitable for each device can be distributed to multiple devices. Also, according to this disclosure, for example, if the software update status differs for each device, update content information according to the update status of each device can be distributed. Also, according to this disclosure, for example, if the software settings differ for each device, update content information according to the settings of each device can be distributed. Furthermore, according to this disclosure, for example, if the software execution environment differs for each device, update information corresponding to the execution environment of each device can be distributed.

[0032] The aforementioned subject includes, for example, at least one of an organization and / or a device. The number of the aforementioned subject may be, for example, one or two or more. The aforementioned organization may include, for example, a healthcare institution, a pharmacy, a local government, a government agency, a financial institution, and equivalent organizations in foreign countries other than Japan, but there are no limitations on the description. The aforementioned healthcare institution may be, for example, a hospital or a clinic. The aforementioned hospital may be, for example, a medical hospital or a dental hospital. The aforementioned hospital may include, for example, a general hospital, a specialized hospital, a regional medical support hospital, a clinical research core hospital, a psychiatric hospital, and a tuberculosis hospital. The aforementioned clinic may be, for example, a general clinic or a dental clinic.

[0033] The aforementioned device includes, for example, an information processing device and at least one of peripheral devices. The information processing device is, for example, a personal computer, a tablet personal computer, and a smartphone, but is not limited to such descriptions. The peripheral devices are, for example, an input device (e.g., a keyboard and mouse), an output device (e.g., a display and a printer), a communication device (e.g., a modem and a router), and a storage device (e.g., a hard disk drive (HDD) and a solid state drive (SSD)), but is not limited to such descriptions.

[0034] The aforementioned request information may include, for example, request-related information. The aforementioned request-related information may include, for example, update device identification information for identifying the update device, software identification information for identifying the software to be updated, and at least one of the following: authorization information. The authorization information can be described, for example, by referring to the explanation described later.

[0035] The update device identification information may be, for example, an IP (Internet Protocol) address. The IP address may be, for example, the IP address of the update device itself, or the IP address of a forward proxy connected to the update device. The IP address may be, for example, a private IP address or a public IP address. In the latter case, the public IP address may be, for example, an IP address obtained by address translation of the private IP address of the update device, or an IP address obtained by address translation of the private IP address of a forward proxy connected to the update device. The address translation may be, for example, Network Address Translation (NAT), but is not limited to this description. The service that provides the address translation may be, for example, Amazon Web Services (AWS®) NAT Gateway, but is not limited to this description.

[0036] The software identification information may include, for example, information about the software name, information about the software ID (identifier), information about the software version, information about the software's OS (operating system) type, information about the software vendor, and information about a hash value based on the software's source program, but there are no limitations on the description. The software identification information may be in plain text or ciphertext. In the latter case, the form of encryption of the software identification information may be, for example, based on the description of the form of encryption of identification information described above. The software identification information may be included in the request line, request header, or request body of the request information, for example, if the form of the request is the HTTP request. The software identification information may be included in the request parameters of the request information, for example, if the form of the request is the HTTP request. The request parameters may be, for example, based on the description described above. The software identification information may be included in the URI parameters, for example, if the form of the request is the HTTP request. The URI parameters may be, for example, based on the description described above.

[0037] The update content information is information relating to the update content of the software provided by the update device. The update content information may include, for example, at least one of the following: native code information relating to native code, source code information relating to source code, and configuration information relating to software settings. The native code information and the source code information may be set appropriately, for example, according to the software update content. The native code information and the source code information may also be, for example, information relating to a module. The native code information and the source code information may also be, for example, information relating to a main program, information relating to a subprogram, or a combination of both. The format of the information relating to the main program may be, for example, an Executable (EXE) file, but there are no limitations on the description. The information relating to a subprogram may be, for example, information relating to one subprogram, or information relating to two or more subprograms. In the latter case, the information relating to the subprogram may be, for example, information relating to a library containing two or more subprograms. The format for linking the information relating to the subprogram to the information relating to the main program may be, for example, static linking or dynamic linking. The format of the information regarding the subprogram may be, for example, a dynamic link library (DLL) file, but there are no limitations to this description. The configuration information may be set appropriately according to the execution environment of the software for each target, for example. The configuration information may be, for example, a configuration file. The software may be, for example, firmware, middleware, and application software. The update content may be, for example, differential update data for differentially updating the software, or cumulative update data for cumulatively updating the software. The update content may be set appropriately according to the updates required for the software provided by the update device, for example. The update content may be, for example, the addition of functions, the correction of bugs, the optimization of performance, and the enhancement of security, but there are no limitations to this description.

[0038] The update content information may include, for example, update content-related information. The update content-related information may include, for example, at least one of the following: software identification information, hashed update content information obtained by hashing the update content using a hash function, and information regarding the source from which the update content is obtained. For example, the above-mentioned explanation can be used for the software identification information. Specifically, the software identification information may include, for example, information regarding the software version. The hash function algorithm may include, for example, an algorithm belonging to the SHA (Secure Hash Algorithm) family. Examples of algorithms belonging to the SHA family include SHA-0, SHA-1, SHA-2, and SHA-3. The algorithm belonging to the SHA family may be appropriately selected, for example, depending on the hash size suitable for the execution environment. Examples of SHA-2 include SHA-256 and SHA-512, but there is no limit to the above description. Information regarding the source from which the update content is obtained may be, for example, a URI from which the update content can be obtained. Examples of URIs include URLs and URNs.

[0039] The update device may, for example, be a device to which the update content information is to be distributed. The update device may, for example, be a device equipped with software that is the target of the update process. The update device may, for example, be a client device in a client-server model. The update device may, for example, be a device to which a forward proxy is connected. In this case, the update device may, for example, output various information to the distribution device via the forward proxy, or obtain various information from the distribution device via the forward proxy. The forward proxy may, for example, be a proxy server or a cloud proxy. The number of update devices may, for example, be one or two or more. The update device may, for example, be a device located in the organization if the target is the organization. The update device may, for example, be the device itself if the target is the device. The update device may, for example, be a device operated in an on-premise format or a device operated in a cloud format. The update device may, for example, be a device connected to a medical information system for managing medical information if the organization is a healthcare institution. The aforementioned medical information systems include, but are not limited to, systems related to HIS (Hospital Information Systems), PACS (Picture Archiving and Communication Systems), RIS (Radiology Information Systems), and MWM (Modality Worklist Management). The aforementioned update device may be, for example, the update device disclosed later in this disclosure.

[0040] The update device may be, for example, a device to which the identification information for each target has been pre-assigned. The format in which the identification information is assigned to the update device may be, for example, by assigning the identification information to a file, or by assigning the identification information to account information. The identification information may be stored, for example, in the memory or storage device of the update device. The update device may include, for example, update device identification information for identifying the update device, and software identification information for identifying the software provided by the update device. The update device identification information may be described, for example, by referring to the above explanation. The software identification information may be described, for example, by referring to the above explanation. The update device identification information and the software identification information may be stored, for example, in the memory or storage device of the update device.

[0041] The distribution device may, for example, be a device that distributes the update content information. The distribution device may, for example, be a server device in a client-server model. The distribution device may, for example, be a device to which a reverse proxy is connected. In this case, the distribution device may, for example, output various information to the update device via the reverse proxy, or obtain various information from the update device via the reverse proxy. The reverse proxy may, for example, be a proxy server or a cloud proxy. The reverse proxy may, for example, be Amazon Web Services (AWS) CloudFront®, but is not limited to this description. The number of distribution devices may, for example, be one or two or more. The distribution device may, for example, be a device that provides storage services. In this case, the distribution device may, for example, be a device that provides cloud-based storage services, a device that provides hosting-based storage services, or a device that provides housing-based storage services.

[0042] The distribution device may be, for example, a device equipped with a storage device. The type of storage device may be, for example, a hard disk drive (HDD), a solid state drive (SSD), or a combination thereof. The distribution device may be, for example, a device that has a storage device inside it, or a device that has a storage device outside it. In the former case, the storage device may be, for example, the memory 102 or storage device 104 of the device 10. In the latter case, the distribution device may be, for example, a device to which the storage device is directly connected, a device to which the storage device is connected via a SAN (Storage Area Network), a device to which the storage device is connected via a LAN (Local Area Network), or a device that combines these using unified storage. When the storage device is directly connected to the distribution device, for example, it can also be called DAS (Direct Attached Storage). When the storage device is connected to the distribution device via a LAN, for example, it can also be called NAS (Network Attached Storage). The format in which the storage device manages information may be, for example, a file storage format, a block storage format, or an object storage format. The aforementioned file storage includes, but is not limited to, Google Drive, OneDrive®, and Dropbox®. The aforementioned block storage includes, but is not limited to, Amazon Elastic Block Storage, Persistent Disk, and Azure Managed Disks. The aforementioned object storage includes, but is not limited to, Amazon S3 (Amazon Simple Storage Service)®, Cloud Storage, and Azure Blob Storage. The distribution device may include, for example, an API (Application Programming Interface) corresponding to the format in which the storage device manages information.The API mentioned above could be, for example, a REST (Representational State Transfer) API if the format in which the storage device manages information is the format of the object storage, but this description is not limited in any way.

[0043] The storage device provided by the distribution device may, for example, include a storage area containing the update content information. The storage area may, for example, be an area to which the identification information for each target has been pre-assigned. The storage area may, for example, include update content-related information in addition to the update content information. The storage area may be appropriately configured, for example, depending on the format in which the storage device manages information. Specifically, the storage area may be, for example, a file, directory, block, volume, object, or bucket, but is not limited to this description.

[0044] The identification unit 12 identifies the storage area corresponding to the identification information from the group of storage areas (S12, identification procedure).

[0045] The identification unit 12 may, for example, identify a storage area corresponding to the identification information from a group of storage areas, and then identify the update content information corresponding to the software identification information from the identified storage area. In this case, the output unit 13 may, for example, output the identified update content information to the update device as a response to the request.

[0046] The storage area is pre-assigned the identification information for each target and includes the update content information for each target. The storage area may also include, for example, the update content-related information for each target. The storage area may include, for example, the storage device provided by the distribution device. The storage area may include, for example, the storage device provided inside the distribution device, or the storage device provided outside the distribution device. The storage area may be appropriately configured, for example, as described above, depending on the format in which the storage device manages information. The storage area may include, for example, files, directories, blocks, volumes, objects, or buckets, as described above, but is not limited to such descriptions. The group of storage areas may, for example, have the identification information for each target pre-assigned to each storage area and include the update content information for each target. The group of storage areas may, for example, have the identification information for each target pre-assigned to each storage area, include the update content information for each target, and include the update content related information for each target. The group of storage areas may, for example, include one storage area or two or more storage areas. The group of storage areas may include, for example, a group of files, a group of directories, a group of blocks, a group of volumes, a group of objects, or a group of buckets, but there are no limitations to this description. The format in which the identification information is assigned to the storage areas may be set appropriately according to, for example, the format in which the storage device provided by the distribution device manages information. Specifically, the format in which the identification information is assigned to the storage areas may, for example, be a format in which the identification information is assigned to files, directories, blocks, volumes, objects, or buckets. The format in which the identification information is assigned to the storage areas may, for example, be a format in which the identification information is assigned to the address of a file, a directory, a block, a volume, an object, or a bucket.The format in which the identification information is assigned to the storage area may, for example, be a format in which the identification information is assigned to the name of a file, the name of a directory, the name of a block, the name of a volume, the name of an object, or the name of a bucket. The format in which the identification information is assigned to the storage area may, for example, be a format in which the identification information is assigned to the metadata of a file, the metadata of a directory, the metadata of a block, the metadata of a volume, the metadata of an object, or the metadata of a bucket. The format in which the identification information is assigned to the storage area may, for example, be a format in which the identification information is assigned to an index contained in the metadata of an object, or an index contained in the metadata of a bucket.

[0047] The storage area corresponding to the identification information may be identified as appropriate, for example, using the search function provided by various storage devices. The storage area corresponding to the identification information may also be identified using a search function that uses the identification information as a query. The query may be set as appropriate, for example, according to the format in which the storage device provided by the distribution device manages information. The storage area corresponding to the identification information may also be identified using the search function of Amazon Athena, for example, if the object storage is Amazon S3.

[0048] The output unit 13 outputs the update content information contained in the identified storage area to the update device as a response to the request (S13, output procedure). Note that S13 can also be called, for example, the update content information output procedure.

[0049] The format of the response may be set appropriately, for example, depending on the protocol for communication between the update device and the distribution device. The type of protocol can be described, for example, by referring to the above-mentioned explanation. The format of the response may be, for example, an HTTP response if the protocol is HTTP or HTTPS. The update content information contained in the specified storage area may be included in the response body of the response, for example, if the response is an HTTP response.

[0050] The output unit 13 may, for example, output only the update content information contained in the specified storage area to the update device as a response to the request, or it may output only the update content-related information from the update content information contained in the specified storage area to the update device. In the latter case, if the update device determines, for example, that the update content-related information is complete, the output unit 13 may further output only the update content information contained in the specified storage area to the update device as a response to the request. The update content-related information contained in the update content information may, for example, be included in the response body of the response if the response is an HTTP response.

[0051] The output unit 13 may, for example, output the update content information contained in the specified storage area to a device to which the update content information is to be distributed, or to a device connected to the device to which the update content information is to be distributed. Alternatively, the output unit 13 may, for example, output the update content information contained in the specified storage area to a device equipped with software to which the update processing is to be performed, or to a device connected to the device equipped with software to which the update processing is to be performed. In other words, the output unit 13 may, for example, output the update content information contained in the specified storage area to a client device in a client-server model, or to a forward proxy device connected to the client device.

[0052] Furthermore, the acquisition unit 11 may acquire request information from the update device for a request to acquire only the native code information or source code information from the update content information. In this case, the identification unit 12 may identify the storage area corresponding to the identification information from a group of storage areas. The output unit 13 may output only the native code information or source code information contained in the identified storage area as a response to the request to the update device. Furthermore, the acquisition unit 11 may acquire request information from the update device for a request to acquire only the setting information from the update content information. In this case, the identification unit 12 may identify the storage area corresponding to the identification information from a group of storage areas. The output unit 13 may output only the setting information contained in the identified storage area as a response to the request to the update device.

[0053] The distribution method of this disclosure (hereinafter also referred to as the method of this disclosure) is a method that is carried out by, for example, replacing each "procedure" in the program of this disclosure with a "process". Specifically, the method of this disclosure includes an acquisition process, an identification process, and an output process. The acquisition process acquires request information relating to a request to acquire update content information from an update device, the request information includes identification information for identifying a target, and the update content information is information relating to the update content of the software provided by the update device. The identification process identifies a storage area corresponding to the identification information from a group of storage areas, the storage area is pre-assigned with the identification information for each target, and includes the update content information for each target. The output process outputs the update content information contained in the identified storage area to the update device as a response to the request. The method of this disclosure can be carried out, for example, using the device 10 of this disclosure shown in Figure 1(A) or Figure 2. However, the method of this disclosure is not limited to, for example, a method using the device 10 of this disclosure. The method disclosed herein may, for example, be a method utilizing distribution device 10A or 10B. The method disclosed herein may, for example, be based on the descriptions in the program and the apparatus disclosed herein.

[0054] As described above, according to the distribution program of this disclosure, the acquisition procedure acquires request information relating to a request to acquire update content information from the update device, the request information includes identification information for identifying a target, the update content information is information relating to the update content of the software provided by the update device, the identification procedure identifies a storage area corresponding to the identification information from a group of storage areas, the storage area is pre-assigned the identification information for each target and includes the update content information for each target, and the output procedure outputs the update content information contained in the identified storage area to the update device as a response to the request. For this reason, according to this disclosure, updates can be managed for each target. Furthermore, according to this disclosure, for example, update content information suitable for each target can be distributed to multiple targets. Furthermore, according to this disclosure, for example, if the software update status differs for each target, update content information according to the update status of each target can be distributed. Furthermore, according to this disclosure, for example, if the software settings differ for each target, update content information according to the settings of each target can be distributed. Furthermore, according to this disclosure, for example, if the software execution environment differs for each target, update content information according to the execution environment of each target can be distributed.

[0055] [Embodiment 2] The distribution program of this disclosure is a program that causes a computer to execute an acquisition procedure, an identification procedure, an output procedure, and a determination procedure. The distribution program of this disclosure can also be described as a program that causes a computer to function as the acquisition procedure, an identification procedure, an output procedure, and a determination procedure. Furthermore, the distribution program of this disclosure can also be described as a program that causes a computer to execute each step of the distribution method described later. This embodiment can draw upon various descriptions of other embodiments.

[0056] Furthermore, the distribution program of this disclosure is a program that causes a computer to execute an acquisition procedure, an identification procedure, an output procedure, and a storage procedure. The distribution program of this disclosure can also be described as a program that causes a computer to function as an acquisition procedure, an identification procedure, an output procedure, and a storage procedure. Alternatively, the distribution program of this disclosure can also be described as a program that causes a computer to execute each step of the distribution method described later. This embodiment can draw upon various descriptions of other embodiments.

[0057] An example of the configuration of the distribution device of this disclosure will be explained using Figure 1(B). Figure 1(B) is a block diagram showing an example of the configuration of the distribution device 10A of this disclosure (hereinafter also referred to as "device 10A"). As shown in Figure 1(B), device 10A includes a determination unit 14 in addition to the configuration of device 10. Device 10A may also include, for example, an input unit, other output units, a display unit and / or a storage unit, although these are not shown. The acquisition unit 11, the identification unit 12, the output unit 13, and the determination unit 14 can each execute, for example, the acquisition procedure, identification procedure, output procedure, and determination procedure in the distribution program of this disclosure. The determination unit 14 can also be called, for example, an access rights determination unit.

[0058] The hardware configuration of the device 10A is the same as that of the device 10 in Figure 2, except that the central processing unit has the configuration of the device 10A in Figure 1(B) instead of the configuration of the device 10 in Figure 1. The processing of the determination unit 14 will now be described. The processing of the determination unit 14 can be inserted at any appropriate position in the flowchart in Figure 3(A), for example, but as shown in Figure 3(B), it is preferable that the processing of the determination unit 14 be inserted after S11, for example.

[0059] The determination unit 14 determines, for example, whether the request information includes permission information relating to access rights to the group of storage areas (S14-1, determination procedure).

[0060] If the determination unit 14 determines, for example, that the request information includes the authorization information, it executes the identification process according to the identification procedure and the output process according to the output procedure (S14-2, determination procedure). The identification unit 12 may also execute the identification process if the determination unit 14 determines that the request information includes the authorization information. The output unit 13 may also execute the output process if the determination unit 14 determines that the request information includes the authorization information. The identification process according to the identification procedure and the output process according to the output procedure can be described by referring to, for example, the above-mentioned explanation of the identification unit 12 and the above-mentioned explanation of the output unit 13. Note that S14-1 and S14-2 can also be called, for example, the access authorization determination procedure.

[0061] According to this disclosure, for example, updates can be managed for each target while ensuring security. Furthermore, according to this disclosure, for example, updates can be managed for each target while preventing unauthorized access.

[0062] The authorization information may be, for example, information used for basic authentication, digest authentication, session-based authentication, or token-based authentication. The authorization information may be set appropriately depending on the authentication method. The authorization information may be, for example, an ID and password, an ID and a password with an arbitrary string, a session ID, or an access token. The access token may include, for example, a signature and a part other than the signature. The signature may be, for example, information obtained by encrypting the part other than the signature with a predetermined key. The predetermined key may be, for example, a private key or a public key. The authorization information may be, for example, plaintext or ciphertext. In the latter case, the format of encryption of the authorization information may be, for example, based on the explanation of the format of encryption of identification information described above. The authorization information may be included in the request line, request header, or request body of the request information, for example, when the format of the request is the HTTP request. The aforementioned authorization information may, for example, be included in the request parameters of the request information if the format of the request is the HTTP request.

[0063] The token-based authentication may include, for example, JSON Web Token (JWT) authentication, but is not limited to this description. The access token may be, for example, a JSON Web Token (JWT) if the authorization information is the information used for JWT authentication. The JWT may include, for example, information including a header, payload, and signature. The payload may include, for example, at least one of the expiration date of access to the storage area and the scope of access permitted within the storage area. The signature may be, for example, information obtained by encrypting the header and payload based on an algorithm specified by the header and a predetermined key. The predetermined key may be, for example, a private key or a public key. The header and payload may be, for example, information encoded using a predetermined encoding scheme. The signature may be, for example, information obtained by encoding the encrypted information of the header and payload using a predetermined encoding scheme.

[0064] The determination of whether or not the authorization information is included may be performed appropriately by a known method, for example, depending on the form of authentication. The determination of whether or not the authorization information is included may be performed by a determination based on the session ID, for example, when the form of authentication is session-based authentication. Specifically, in determining whether or not the authorization information is included, the distribution device issues a session ID to the update device, for example. The determination unit 14 determines, for example, whether the session ID included in the request information obtained from the update device matches the session ID issued by the distribution device to the update device. If the determination unit 14 determines that each session ID matches, it may determine that the request information includes the authorization information.

[0065] Furthermore, the determination of whether or not the request information contains the authorization information may be performed by a determination based on the access token, for example, if the authentication method is token-based authentication. Specifically, in the determination of whether or not the request information contains the authorization information, the update device is, for example, a device to which an access token has been pre-assigned. The determination unit 14 performs a validity check on the access token contained in the request information obtained from the update device, for example. The validity check may be performed by, for example, decrypting the signature contained in the access token with a predetermined key, and then determining whether the decrypted signature matches the part of the access token other than the signature. In this case, the determination unit 14 may determine that the request information contains the authorization information if it determines that the decrypted signature matches the part of the access token other than the signature. The validity check may also be performed after, for example, decoding the signature using a predetermined decoding method. Furthermore, the determination unit 14 may perform a validity check on the JWT if the access token is a JWT, for example. The determination unit 14 may, for example, decrypt the signature contained in the JWT using a predetermined key, and then determine whether the decrypted signature and the parts other than the signature (i.e., the header and payload contained in the JWT) match. In this case, if the determination unit 14 determines that the decrypted signature and the parts other than the signature match, it may determine that the request information contains the authorization information. Alternatively, the determination of whether or not the authorization information is contained may be made, for example, by determining whether or not the access to the storage area has expired, if the form of authentication is token-based authentication.

[0066] The determination unit 14 may, for example, determine whether the request information satisfies predetermined conditions relating to the Web Application Firewall (WAF) provided by the distribution device. In this case, if the determination unit 14 determines, for example, that the request information satisfies the predetermined conditions relating to the WAF, it may further determine whether the request information includes permission information relating to access rights to the group of storage areas. The WAF may be, for example, Amazon WAF if the object storage is Amazon S3. The predetermined conditions relating to the WAF may be, for example, known conditions available in the WAF. The predetermined conditions relating to the WAF may include, for example, conditions for determining whether the request information is unauthorized access, but there is no limit to such descriptions. In this case, if the determination unit 14 determines, for example, that the request information is not unauthorized access, it may determine that the request information satisfies the predetermined conditions relating to the WAF. The aforementioned unauthorized access includes, but is not limited to, injection attacks (such as SQL injection and OS command injection), cross-site scripting, brute-force attacks, DDoS attacks, and bot access.

[0067] The determination unit 14 may, for example, determine whether the request information satisfies predetermined conditions regarding access to the storage area. In this case, if the determination unit 14 determines, for example, that the request information satisfies the predetermined conditions regarding access, it may execute the identification process according to the identification procedure and the output process according to the output procedure. Alternatively, the determination unit 14 may, for example, after executing the determination process for the predetermined conditions regarding the WAF, determine whether the request information includes the permission information, and if it determines that the request information includes the permission information, it may further execute the determination process for the predetermined conditions regarding access. The predetermined conditions regarding access may, for example, be predetermined conditions regarding the S3 bucket policy if the object storage is Amazon S3. The predetermined conditions regarding access may, for example, be publicly known conditions available in various storage services. The predetermined conditions regarding access may include, for example, conditions for determining whether to allow access to the storage area, or conditions for determining whether to prohibit access to the storage area, but there are no limitations to this description. In this case, the determination unit 14 may determine, for example, that the request information satisfies the predetermined conditions for access if it determines that the request information is permitted to access the storage area, or if it determines that the request information is not prohibited from accessing the storage area. The predetermined conditions for access may be, for example, conditions based on a whitelist or conditions based on a blacklist. The predetermined conditions for access may be, for example, conditions that permit or prohibit access to the storage area for access performed by a predetermined operation. The predetermined operation may be, for example, the GET method and the PUT method when the format of the request is the HTTP request, but is not limited to such descriptions. The predetermined conditions for access may be, for example, conditions that permit or prohibit access to the storage area for access performed by a predetermined software.The aforementioned specified software may be, for example, software that includes the aforementioned WAF. The aforementioned specified software may include, for example, a CDN (Content Delivery Network), but is not limited to this description. The CDN may be, for example, Amazon CloudFront if the object storage is Amazon S3.

[0068] Furthermore, another example of the configuration of the distribution device of this disclosure will be described with reference to Figure 1(C). Figure 1(C) is a block diagram showing an example of the configuration of the distribution device 10B of this disclosure (hereinafter also referred to as "device 10B"). As shown in Figure 1(C), device 10B includes a storage unit 15 in addition to the configuration of device 10. Device 10B may also include, for example, an input unit, other output units, a display unit and / or a storage unit, although these are not shown. The acquisition unit 11, the identification unit 12, the output unit 13, and the storage unit 15 can each execute, for example, the acquisition procedure, identification procedure, output procedure, and storage procedure in the distribution program of this disclosure.

[0069] The hardware configuration of the device 10B is the same as that of the device 10 in Figure 2, except that the central processing unit has the configuration of the device 10B in Figure 1(C) instead of the configuration of the device 10 in Figure 1(A). The processing of the storage unit 15 will now be described. The processing of the storage unit 15 can be inserted at any position in the flowchart in Figure 3(A), for example, but as shown in Figure 3(C), it is preferable that the processing of the storage unit 15 be inserted after the processing of S11 to S13 and after S12.

[0070] S11, S12, and S13 perform, for example, acquisition processing, identification processing, and output processing, similar to Embodiment 1.

[0071] The acquisition unit 11 acquires, for example, log information relating to the log of the software update process provided by the update device from the update device (S11A, acquisition procedure). In this case, the log information includes, for example, the identification information.

[0072] The identification procedure, for example, identifies the storage area corresponding to the identification information from the group of storage areas (S12, identification procedure).

[0073] The storage unit 15 stores the acquired log information in the specified storage area, for example (S15, storage procedure).

[0074] According to this disclosure, for example, update processing can be managed for each target based on log information. Furthermore, according to this disclosure, for example, the status of update processing for each target can be recorded as log information. Furthermore, according to this disclosure, for example, the status of update processing can be notified for each target. Furthermore, according to this disclosure, for example, problems that occurred during software update processing can be identified for each target by analyzing log information. Furthermore, according to this disclosure, for example, the degree of adoption of a particular version of software can be identified for each target by analyzing log information.

[0075] The log information may include, for example, at least one of event log information and configuration change log information. The event log information is, for example, information about logs for events in the software update process provided by the update device. The event log information may include, for example, at least one of completion log information regarding the completion of the software update process provided by the update device, warning log information regarding warning logs in the software update process provided by the update device, and error log information regarding error logs in the software update process provided by the update device. The completion log information may include, for example, information about the content of the update process, information about the time the update process was completed, and information about the status of the update process completion, but there are no limitations on the description. The warning log information may include, for example, information about the content of warnings in the update process, information about the time the warning occurred in the update process, and information about the status of the warning in the update process, but there are no limitations on the description. The error log information may include, for example, information about the content of errors in the update process, information about the time the error occurred in the update process, and information about the status of the error in the update process, but there are no limitations on the description. The configuration change log information is, for example, information regarding logs of configuration changes in the software update process of the update device. The configuration change log information may include, for example, information regarding the version of the software after the update process of the update device, but there are no limitations on the description.

[0076] The format for obtaining the log information may be set appropriately, for example, according to the protocol for communication between the update device and the distribution device. The format for obtaining the log information may be an HTTP request, for example, if the protocol is HTTP or HTTPS. Examples of the format of the HTTP request include the PUT method and the PATCH method, but there are no limitations to this description. The log information may be included in the request line, request header, or request body, for example, if the format for obtaining the log information is an HTTP request.

[0077] The format in which the log information is stored may be set appropriately depending on the format in which the log information is obtained. Specifically, the format in which the log information is stored may be such that, for example, when the format of the HTTP request is the PUT method, the log information is stored in a format that overwrites all of the log information contained in the specified storage area. The format in which the log information is stored may be such that, for example, when the format of the HTTP request is the PATCH method, the log information is stored in a format that overwrites a portion of the log information contained in the specified storage area.

[0078] The storage unit 15 may further store the log information in a database relating to the logs for each software, for example. The database may be stored in a storage device or memory of the distribution device, or in a storage device connected to the distribution device. The format of the database may be, for example, hierarchical, network, or relational.

[0079] If the apparatus 10B of this disclosure includes an output unit 13, the output unit 13 may perform, for example, the following processing. Specifically, if the output unit 13 stores the log information in the specified storage area, it may output log notification information relating to the notification of the log information to the update device. The output of the log notification information by the output unit 13 may be performed, for example, by sending an email to the email address corresponding to the target.

[0080] The distribution method of this disclosure (hereinafter also referred to as the "method of this disclosure") is a method implemented by, for example, replacing each "procedure" in the program of this disclosure with a "process". The method of this disclosure can be implemented, for example, using the apparatus 10A or apparatus 10B of this disclosure shown in Figure 1(B) or Figure 1(C). The method of this disclosure can also be implemented, for example, using a hardware configuration in the hardware configuration of the apparatus 10 shown in Figure 2, in which the central processing unit 101 includes the apparatus 10A or apparatus 10B of this disclosure shown in Figure 1(B) or Figure 1(C). However, the method of this disclosure is not limited to, for example, a method using the apparatus 10A or 10B of this disclosure. The method of this disclosure can be implemented by, for example, referring to the descriptions in the program and apparatus of this disclosure.

[0081] As described above, according to the distribution program of this disclosure, a determination procedure determines whether the request information includes permission information relating to access rights to the group of storage areas, and if it is determined that the request information includes the permission information, the identification procedure and the output procedure can be executed. Furthermore, according to the distribution program of this disclosure, an acquisition procedure obtains log information relating to the update process of the software provided by the update device from the update device, the log information includes the identification information, and the storage procedure can store the acquired log information in the identified storage area. For this reason, according to this disclosure, updates can be managed for each target. Furthermore, according to this disclosure, updates can be managed for each target, for example, in a secure environment. Furthermore, according to this disclosure, updates can be managed for each target, for example, in a situation where unauthorized access is prevented. Furthermore, according to this disclosure, update processing can be managed for each target based on log information. Furthermore, according to this disclosure, the status of update processing for each target can be recorded as log information. Furthermore, according to this disclosure, the status of update processing can be notified for each target. Furthermore, according to this disclosure, for example, by analyzing log information, it is possible to understand the problems that occurred during the software update process for each target. Also, according to this disclosure, for example, by analyzing log information, it is possible to understand the degree of adoption of a particular version of the software for each target.

[0082] [Embodiment 3] The update program described herein is a program that causes a computer to perform output, retrieval, and update procedures. The update program described herein can also be described as a program that causes a computer to function as an output, retrieval, and update procedure. Furthermore, the update program described herein can also be described as a program that causes a computer to perform, for example, each step of the update method described later. This embodiment may draw upon various descriptions of other embodiments.

[0083] The output procedure outputs request information relating to a request to obtain update content information to a distribution device, the request information includes identification information for identifying a target, the update content information is information relating to the update content of the software provided by the update device, the acquisition procedure acquires the update content information contained in a storage area corresponding to the identification information from the distribution device as a response to the request, the storage area is pre-assigned with the identification information for each target and includes the update content information for each target, and the update procedure executes the software update process provided by the update device based on the acquired update content information.

[0084] Each of the aforementioned procedures can be reinterpreted, for example, as a "process." The update program of this disclosure may also be recorded on, for example, a computer-readable storage medium. The storage medium is, for example, a non-transitory computer-readable storage medium. The storage medium is not particularly limited and includes, for example, random access memory (RAM), read-only memory (ROM), hard disk (HD), flash memory (e.g., SSD (Solid State Drive), USB flash memory, SD / SDHC card, etc.), optical disc (e.g., CD-R / CD-RW, DVD-R / DVD-RW, BD-R / BD-RE, etc.), magneto-optical disk (MO), floppy disk (FD), etc. The update program of this disclosure (for example, also called a programming product or program product) may also be delivered, for example, from an external computer. The "delivery" may be, for example, delivered via a communication network or delivered via a wired device. The updates described herein may be installed and run on the device to which they are delivered, or they may be run without being installed. An information processing device capable of running the updates described herein may be, for example, an update device.

[0085] Next, an example of the configuration of the update device of this disclosure will be described using Figure 4(A). Figure 4(A) is a block diagram showing an example of the configuration of the update device 20 of this disclosure (hereinafter also referred to as the device 20). As shown in Figure 4(A), the device 20 includes an output unit 21, an acquisition unit 22, and an update unit 23. The device 20 may also include, for example, an input unit, another output unit, a display unit, and / or a storage unit, although these are not shown. The output unit 21, the acquisition unit 22, and the update unit 23 can each execute, for example, the output procedure, acquisition procedure, and update procedure in the update program of this disclosure. The output unit 21 may also be called, for example, a request information output unit. The acquisition unit 22 may also be called, for example, an update content information acquisition unit.

[0086] The device 20 may be, for example, a single device including the aforementioned parts, or it may be a device in which the aforementioned parts can be connected via a communication network. Furthermore, the device 20 can be connected to external devices described later via the communication network. The communication network is not particularly limited and can use any known network, for example, it may be wired or wireless. Examples of the communication network include the Internet, WWW (World Wide Web), telephone lines, LAN (Local Area Network), SAN (Storage Area Network), DTN (Delay Tolerant Networking), LPWA (Low Power Wide Area), L5G (Local 5G), etc. Examples of wireless communication include Wi-Fi (registered trademark), Bluetooth (registered trademark), Local 5G, LPWA, etc. The wireless communication may be in the form of direct communication between devices (Ad Hoc communication), infrastructure communication, indirect communication via an access point, etc. The device 20 may be, for example, incorporated into a server as a system. Furthermore, the device 20 may be, for example, a personal computer (PC, e.g., desktop or notebook), smartphone, tablet terminal, etc., on which the program of this disclosure is installed. The device 20 may also be in the form of cloud computing or edge computing, for example, in which at least one of the aforementioned parts is on a server and the other aforementioned parts are on a terminal.

[0087] Figure 5 illustrates a block diagram of the hardware configuration of the device 20. The device 20 includes, for example, a central processing unit (CPU, GPU, etc.) 201, memory 202, bus 203, storage device 204, input device 205, output device 206, communication device 207, etc. Each part of the device 20 is interconnected via the bus 203 through its respective interface (I / F).

[0088] The central processing unit 201 operates in coordination with other components via controllers (system controller, I / O controller, etc.) and is responsible for the overall control of the device 20. In the device 20, the central processing unit 201 executes, for example, the program (update program) of this disclosure and other programs, and also reads and writes various types of information. Specifically, for example, the central processing unit 201 functions as an output unit 21, an acquisition unit 22, and an update unit 23. The device 20 may also include other computing devices such as a CPU, GPU (Graphics Processing Unit), APU (Accelerated Processing Unit), or a combination thereof as computing devices.

[0089] Bus 203 can also be connected to external devices, for example. Examples of such external devices include external storage devices (external databases, etc.), printers, external input devices, external display devices, and external imaging devices. The device 20 can be connected to an external network (the aforementioned communication network) via a communication device 207 connected to bus 203, and can also be connected to other devices via the external network.

[0090] Memory 202 may be, for example, main memory. When the central processing unit 201 performs processing, memory 202 reads various operational programs, such as the program of this disclosure, stored in the storage device 204 (described later), and the central processing unit 201 receives data from memory 202 and executes the program. The main memory may be, for example, RAM (random access memory). Alternatively, memory 202 may be, for example, ROM (read-only memory).

[0091] The storage device 204 is also called an auxiliary storage device, for example, in relation to the main memory (primary memory). As described above, the storage device 204 stores an operating program including the program of this disclosure. The storage device 204 may be, for example, a combination of a recording medium and a drive for reading and writing to the recording medium. The recording medium is not particularly limited and may be internal or external, for example, an HD (hard disk), CD-ROM, CD-R, CD-RW, MO, DVD, flash memory, memory card, etc. The storage device 204 may be, for example, a hard disk drive (HDD) in which the recording medium and the drive are integrated, or a solid state drive (SSD). If the device 20 includes the storage unit, for example, the storage device 204 functions as the storage unit. The storage unit can record, for example, identification information, request information, request-related information, update content information, update content-related information, log information, etc., which will be described later.

[0092] In this device 20, the memory 202 and storage device 204 can also store various types of information, such as log information, information obtained from an external database (not shown) or external devices, information generated by this device 20, and information used by this device 20 when executing processing. In this case, the memory 202 and storage device 204 may store, for example, the user information of this device as described above. At least some of the information may be stored on an external server other than the memory 202 and storage device 204, or it may be stored in a distributed manner across multiple terminals using blockchain technology or the like.

[0093] The device 20 further includes, for example, an input device 205 and an output device 206. The input device 205 may include, for example, a pointing device such as a touch panel, trackpad, or mouse; a keyboard; imaging means such as a camera or scanner; a card reader such as an IC card reader or magnetic card reader; an audio input means such as a microphone; and so on. The output device 206 may include, for example, a display device such as an LED display or liquid crystal display; an audio output device such as a speaker; a printer; and so on. In this embodiment 1, the input device 205 and the output device 206 are configured separately, but the input device 205 and the output device 206 may be configured as an integrated unit, such as a touch panel display.

[0094] An example of the processing performed by the update program described in this disclosure will be explained in more detail using Figure 6(A). Figure 6(A) is a flowchart illustrating an example of each step in the update program described in this disclosure.

[0095] The output unit 21 outputs request information to the distribution device, for example, regarding a request to obtain update content information (S21, output procedure). In this case, the request information includes, for example, identification information for identifying the target. The update content information is, for example, information regarding the update content of the software provided by the update device. Note that S21 can also be called, for example, the request information output procedure.

[0096] The acquisition unit 22 acquires, for example, the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request (S22, acquisition procedure). In this case, the storage area is, for example, pre-assigned with the identification information for each target and contains the update content information for each target. Note that S22 can also be called, for example, the update content information acquisition procedure.

[0097] The update unit 23, for example, executes a software update process for the update device based on the acquired update content information (S23, update procedure).

[0098] Furthermore, the output unit 21 may output request information to the distribution device for a request to acquire only the native code information or source code information from the update content information. In this case, the acquisition unit 22 may acquire the native code information or source code information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. Furthermore, the output unit 21 may output request information to the distribution device for a request to acquire only the setting information from the update content information. In this case, the acquisition unit 22 may acquire the setting information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. The update unit 23 may, for example, perform software update processing on the update device based on the acquired native code information or source code information, or based on the acquired setting information.

[0099] The output unit 21 may output the log information to the distribution device, for example, when the update unit 23 performs an update process. In this case, the output unit 21 may output the log information to the distribution device, for example, with the identification information added to it. The format of the output of the log information may be set appropriately, for example, according to the protocol for communication between the update device and the distribution device. The format of the output of the log information may be an HTTP request, for example, when the protocol is HTTP or HTTPS. Examples of the format of the HTTP request include the PUT method and the PATCH method, but there are no limitations to this description. The log information may be included in the request line, request header, or request body, for example, when the format for obtaining the log information is an HTTP request.

[0100] The execution of the update process based on the acquired update information may, for example, be performed by performing an update process for the software provided by the update device based on the update content included in the acquired update information. Specifically, the update unit 23 may, for example, perform an update process for the software provided by the update device based on the update content included in the acquired update information.

[0101] The execution of the update process based on the acquired update content information may, for example, be performed by performing an update process on the software provided by the update device based on the update content-related information contained in the acquired update content information. Specifically, the update unit 23 may, for example, acquire the update content from the update content acquisition source based on the information about the update content acquisition source contained in the update content-related information. The update unit 23 may, for example, perform an update process on the software provided by the update device based on the update content acquired from the acquisition source.

[0102] Furthermore, another example of the configuration of the update device of the present disclosure will be described using Figure 4(B). Figure 4(B) is a block diagram showing an example of the configuration of the update device 20A of the present disclosure (hereinafter also referred to as the device 20A). As shown in Figure 4(B), the device 20A includes a determination unit 24 in addition to the configuration of the device 20. The device 20A may also include, for example, an input unit, other output units, a display unit and / or a storage unit, although these are not shown. The output unit 21, acquisition unit 22, update unit 23, and determination unit 24 are capable of executing, for example, the output procedure, acquisition procedure, update procedure, and determination procedure in the update program of the present disclosure, respectively. The determination unit 24 may also be called, for example, an integrity determination unit.

[0103] The hardware configuration of the device 20A is the same as that of the device 20 in Figure 5, except that the central processing unit has the configuration of the device 20A in Figure 4(B) instead of the configuration of the device 20 in Figure 4(A). The processing of the determination unit 24 will now be described. The processing of the determination unit 24 can be inserted at any position in the flowchart in Figure 6(A), for example, but as shown in Figure 6(B), it is preferable that the processing of the determination unit 24 be inserted between, for example, S22 and S23 (in Figure 6(B), S23 is shown as S23A).

[0104] The determination unit 24 determines, for example, whether the acquired update information is complete or not (S24, determination procedure). Note that S24 can also be called, for example, a completeness determination procedure.

[0105] If the update unit 23 determines, for example, that the acquired update information is complete, it executes the software update process of the update device based on the acquired update information (S23A, update procedure).

[0106] According to this disclosure, for example, the secure distribution of update information can be verified for each target. Furthermore, according to this disclosure, for example, tampering with or corruption of update information can be verified for each target. Furthermore, according to this disclosure, for example, if tampering with or corruption of update information is confirmed, a request can be made to the distribution device of this disclosure to redistribute the update information.

[0107] The determination of whether the acquired update content information is complete may be performed, for example, by a determination based on the update content-related information contained in the acquired update content information. The determination of whether the acquired update content information is complete may also be performed, for example, by a determination based on each hashed update content piece. Specifically, the determination unit 24 may determine, for example, whether the hashed update content information obtained by hashing the update content contained in the acquired update content information using a hash function matches the hashed update content information contained in the update content-related information. If the determination unit 24 determines, for example, that each hashed update content piece matches, it may determine that the acquired update content information is complete. The hash function can be, for example, the one described above.

[0108] On the other hand, if the determination unit 24 determines, for example, that the hashed update content information does not match, it may perform output processing by the output unit 21 and acquisition processing by the acquisition unit 22, and then perform the determination processing by the determination unit 24 again. After the determination processing by the determination unit 24 is performed again, if the determination result that the hashed update content information does not match is repeated a predetermined number of times or more, the output unit 21 may output the log information to the distribution device. The output unit 21 may output the log information to which the identification information has been added, for example, to the distribution device.

[0109] The determination of whether the acquired update information is complete may be performed, for example, by performing a determination based on the information regarding the version of each software, followed by a determination based on the hashed update information. Specifically, the determination unit 24 may determine, for example, whether the information regarding the version of the software provided by the update device is older than the information regarding the version of the software included in the update information. If the determination unit 24 determines, for example, that the information regarding the version of the software provided by the update device is older, it may perform a determination based on the hashed update information. If the determination unit 24 determines, for example, that the hashed update information matches, it may determine that the acquired update information is complete.

[0110] The determination of whether the acquired update information is complete may be performed, for example, by performing a determination based on information about the version of each software, and then by performing a determination based on each hashed update information using the update information acquired from the source. Specifically, the determination unit 24 may, for example, perform a determination based on information about the version of each software, as described above. If the determination unit 24 determines, for example, that the information about the version of the software provided by the update device is outdated, it may acquire the update information from the source of the update information based on the information about the source of the update information included in the update information related information. The determination unit 24 may, for example, determine whether the hashed update information obtained by hashing the acquired update information using a hash function matches the hashed update information included in the update information related information. If the determination unit 24 determines, for example, that each hashed update information matches, it may determine that the acquired update information is complete. The hash function can, for example, be based on the explanation described above.

[0111] The update method of this disclosure (hereinafter also referred to as the method of this disclosure) is a method that is carried out by, for example, replacing each "procedure" in the program of this disclosure with a "process". Specifically, the method of this disclosure includes an output process, an acquisition process, and an update process, wherein the output process outputs request information relating to a request for acquiring update content information to a distribution device, the request information includes identification information for identifying a target, and the update content information is information relating to the update content of the software provided by the update device, the acquisition process acquires the update content information contained in a storage area corresponding to the identification information from the distribution device as a response to the request, the storage area is pre-assigned with the identification information for each target and includes the update content information for each target, and the update process executes the software update process of the update device based on the acquired update content information. The method of this disclosure can be carried out, for example, using the device 20 of this disclosure shown in Figure 4 or Figure 5. However, the method of this disclosure is not limited to, for example, a method using the device 20 of this disclosure. The method disclosed herein may, for example, utilize the update device 20A. The method disclosed herein may, for example, utilize the descriptions in the program and the device disclosed herein.

[0112] As described above, according to the update program of this disclosure, the output procedure outputs request information regarding a request to obtain update content information to the distribution device, the request information includes identification information for identifying the target, the update content information is information regarding the update content of the software provided by the update device, the acquisition procedure obtains the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request, the storage area is pre-assigned the identification information for each target and includes the update content information for each target, and the update procedure allows the update process of the software provided by the update device to be executed based on the acquired update content information. For this reason, according to this disclosure, updates can be managed for each target. Furthermore, according to this disclosure, for example, update processing can be performed for multiple targets using update content information appropriate for each target. Furthermore, according to this disclosure, for example, if the software update status differs for each target, update processing can be performed using update content information corresponding to the update status for each target. Furthermore, according to this disclosure, for example, if the software settings differ for each target, update processing can be performed using update content information corresponding to the settings for each target. Furthermore, according to this disclosure, for example, if the software execution environment differs for each target, the update process can be executed using update content information corresponding to the execution environment for each target.

[0113] [Embodiment 4] An example of an update management system of the present disclosure will be described with reference to Figure 7. Figure 7 is a block diagram showing an example configuration of the update management system of the present disclosure. As shown in Figure 7, the update management system 100 of the present disclosure includes a distribution device 10 and an update device 20. In Figure 7, the update management system 100 includes one distribution device 10 and one update device 20, but the update management system of the present disclosure is not limited to this and may include multiple distribution devices 10 and update devices 20. Also, as shown in Figure 7, the distribution device 10 and the update device 20 can communicate with each other, for example, via a communication network 30. This embodiment can be adapted from various descriptions of other embodiments. Note that the update management system of the present disclosure is not limited to a system using the distribution device 10 and the update device 20. The update management system of the present disclosure may be a system using the distribution device 10A or 10B. The update management system of the present disclosure may be a system using the update device 20A.

[0114] As shown in Figure 7, the distribution device 10 (hereinafter also referred to as "this device 10") includes a configuration similar to that of the distribution device 10 in Embodiment 1. The hardware configuration of the distribution device 10 is such that, in the hardware configuration of the distribution device 10 in Figure 2, the central processing unit 101 includes a configuration similar to that of the distribution device 10 in Figure 1(A).

[0115] As shown in Figure 7, the update device 20 (hereinafter also referred to as "this device 20") includes a configuration similar to that of the update device 20 in Embodiment 3. The hardware configuration of the update device 20 includes a central processing unit 201 with a configuration similar to that of the update device 20 in Figure 4(A), as seen in the hardware configuration of the distribution device 20 in Figure 5.

[0116] An example of processing by the update management program of this disclosure will be explained with reference to Figure 8. Figure 8 is a flowchart showing an example of each step of the update management program of this disclosure. The update management program of this disclosure (hereinafter also referred to as "the program of this disclosure") can be implemented using, for example, the distribution device 10 shown in Figure 1(A) or the distribution device 10 included in the central processing unit 101 in the hardware configuration shown in Figure 2, and the update device 20 shown in Figure 4(A) or the update device 20 included in the central processing unit 201 in the hardware configuration shown in Figure 5. Figure 8 shows an example of processing by the program using the distribution device 10 (S11~S13) and an example of processing by the program using the update device 20 (S21~S23). Note that the program of this disclosure is not limited to, for example, the program using the device 10 and the device 20. The program of this disclosure may also be a program using the distribution device 10A or 10B. The program of this disclosure may also be a program using the update device 20A. The program of this disclosure may, for example, utilize the descriptions in the method and the apparatus of this disclosure.

[0117] The output unit 21 of the update device outputs, for example, request information relating to a request to obtain update content information to the distribution device (S21, output procedure). In this case, the request information includes, for example, identification information for identifying the target. The update content information is, for example, information relating to the update content of the software provided by the update device.

[0118] The acquisition unit 11 of the distribution device acquires, for example, request information related to a request to acquire update content information from the update device (S11, acquisition procedure).

[0119] The identification unit 12 of the distribution device identifies, for example, a storage area corresponding to the identification information from a group of storage areas (S12, identification procedure). In this case, the storage area is, for example, pre-assigned with the identification information for each target and includes the update content information for each target.

[0120] The output unit 13 of the distribution device outputs, for example, the update content information contained in the identified storage area to the update device as a response to the request (S13, output procedure).

[0121] The acquisition unit 22 of the update device acquires, for example, the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request (S22, acquisition procedure).

[0122] The update unit 23 of the update device, for example, executes an update process for the software of the update device based on the acquired update content information (S23, update procedure).

[0123] The update management method of this disclosure (hereinafter also referred to as the method of this disclosure) is a method that is carried out by, for example, replacing each "procedure" in the program of this disclosure with a "process". Specifically, the method of this disclosure using a distribution device includes an acquisition process, an identification process, and an output process, wherein the acquisition process acquires request information relating to a request to acquire update content information from an update device, the request information includes identification information for identifying a target, the update content information is information relating to the update content of the software provided by the update device, the identification process identifies a storage area corresponding to the identification information from a group of storage areas, the storage area is pre-assigned the identification information for each target and includes the update content information for each target, and the output process outputs the update content information contained in the identified storage area to the update device as a response to the request. Furthermore, the method of this disclosure using an update device includes an output step, an acquisition step, and an update step, wherein the output step outputs request information relating to a request to acquire update content information to a distribution device, the request information includes identification information for identifying a target, the update content information is information relating to the update content of the software provided by the update device, the acquisition step acquires the update content information contained in a storage area corresponding to the identification information from the distribution device as a response to the request, the storage area is pre-assigned with the identification information for each target and includes the update content information for each target, and the update step executes the software update process provided by the update device based on the acquired update content information. The method of this disclosure can be implemented, for example, using the distribution device 10 shown in Figure 1(A) or the distribution device 10 included in the central processing unit 101 in the hardware configuration shown in Figure 2, and the update device 20 shown in Figure 4(A) or the update device 20 included in the central processing unit 201 in the hardware configuration shown in Figure 5. However, the method of this disclosure is not limited to, for example, the method using the device 10 and the device 20. The method disclosed herein may also be a method using distribution device 10A or 10B. The method disclosed herein may also be a method using update device 20A. The method disclosed herein may, for example, be based on the descriptions in the program and the apparatus disclosed herein.

[0124] As described above, according to the update management system of this disclosure, the distribution device acquires request information relating to a request to acquire update content information from the update device by an acquisition procedure provided by the distribution device, the request information includes identification information for identifying a target, the update content information is information relating to the update content of the software provided by the update device, the distribution device identifies a storage area corresponding to the identification information from a group of storage areas by an identification procedure provided by the distribution device, the storage area is pre-assigned the identification information for each target and includes the update content information for each target, and the distribution device can output the update content information contained in the identified storage area to the update device as a response to the request by an output procedure provided by the distribution device. Furthermore, according to the update management system of this disclosure, the update device outputs request information to the distribution device via an output procedure, the request information includes identification information for identifying a target, the update information is information regarding the update content of the software provided by the update device, the update device obtains the update information contained in a storage area corresponding to the identification information from the distribution device as a response to the request via an acquisition procedure, the storage area is pre-assigned with the identification information for each target and includes the update information for each target, and the update procedure of the update device allows the update device to execute the software update process based on the acquired update information. For this reason, updates can be managed for each target. Furthermore, according to this disclosure, for example, appropriate update information can be distributed to multiple targets. Furthermore, according to this disclosure, for example, if the software update status differs for each target, update information can be distributed according to the update status for each target. Furthermore, according to this disclosure, for example, if the software settings differ for each target, update information can be distributed according to the settings for each target. Furthermore, according to this disclosure, for example, if the software execution environment differs for each target, update information can be distributed according to the execution environment of each target. Also, according to this disclosure, for example, update processing can be performed for multiple targets using update information appropriate for each target.Furthermore, according to this disclosure, for example, if the software update status differs for each target, the update process can be executed using update content information corresponding to the update status of each target. Furthermore, according to this disclosure, for example, if the software settings differ for each target, the update process can be executed using update content information corresponding to the settings of each target. Furthermore, according to this disclosure, for example, if the software execution environment differs for each target, the update process can be executed using update content information corresponding to the execution environment of each target.

[0125] [Embodiment 5] An example of how the device described in this disclosure can be used will be explained below with reference to Figure 9. In the following explanation, we will use the case where the target is a hospital and Amazon S3 is used as the storage device provided by the distribution device as an example, but this disclosure is not limited in any way to the following explanation.

[0126] An update device deployed in a hospital requests, for example, the distribution of update content for software modules from a distribution device as an HTTP request. Specifically, the update device is, for example, a client device deployed in a hospital. The distribution device is, for example, a server device equipped with Amazon S3 of Amazon Web Services (AWS) as object storage. The update device is connected to the distribution device, for example, via a wireless communication network. The update device is, for example, a device pre-assigned a JSON Web Token (JWT). The JWT consists of, for example, a header, a payload, and a signature. The header and payload are, for example, information encoded using a predetermined encoding scheme. The signature is, for example, information encrypted using an algorithm specified by the header and a predetermined secret key. The update device outputs the request information, including the JWT, to the distribution device as an HTTP request using the GET method. The update device outputs the request information to the distribution device via HTTPS-based communication.

[0127] The distribution device, for example, authenticates the HTTP request and then distributes the update content for the software module as an HTTP response to the update device. Specifically, the distribution device, for example, obtains the request information and performs three authentications on the obtained request information. In the first authentication, the distribution device determines, for example, whether the request information satisfies predetermined conditions related to the AWS Web Application Firewall (WAF) provided by AWS CloudFront. In detail, the distribution device determines, for example, whether the request information is unauthorized access. If the distribution device determines, for example, that the request information is not unauthorized access, it determines that the request information satisfies the predetermined conditions related to the AWS WAF and proceeds to the second authentication. In the second authentication, the distribution device, for example, uses the CloudFront Functions provided by AWS CloudFront to determine whether the request information includes permission information regarding access rights to a group of objects. In detail, the distribution device performs verification of the JWT signature included in the request information using a predetermined public key. The distribution device, for example, if the signature of the JWT included in the request information is authenticated as a result of the verification, determines that the request information includes the authorization information and proceeds to the third authentication. In the third authentication, the distribution device determines, for example, whether the request information satisfies predetermined conditions regarding access to a group of objects, based on the S3 bucket policy set for the AWS S3 bucket. Specifically, the distribution device determines, for example, whether the access to the S3 bucket is via the GET method and whether the access to the S3 bucket is via CloudFront. If the distribution device determines, for example, that the access to the S3 bucket is via the GET method and is via CloudFront, it determines that the request information satisfies predetermined conditions regarding access to a group of objects and terminates the three authentications.After the three authentications described above are completed, the distribution device performs a search for the software update information, for example, using the search function of Amazon Athena. The distribution device identifies the software update information as a result of the search. The distribution device outputs the identified software update information to the update device as a response to the request. The update information includes, for example, information about the software version on the update device, hashed update information obtained by hashing the source code of the update using a hash function, and information about where the source code of the update was obtained, as update-related information.

[0128] The update device, for example, verifies the completeness of the update content information and then performs an update process on the software module provided by the update device based on the source code of the update content. Specifically, the update device determines, for example, whether the information regarding the software version of the update device is older than the information regarding the software version included in the update content information. If the update device determines, for example, that the information regarding the software version of the update device is older, it obtains the source code of the update content from the source of the source code of the update content based on the information regarding the source of the source code of the update content. The update device determines, for example, whether the hashed update content information obtained by hashing the source code of the update content obtained from the source matches the hashed update content information included in the update content information. If the update device determines that each hashed update content information matches, it determines that the update content information is complete and performs an update process on the software module based on the source code of the update content obtained from the source.

[0129] The update device performs update processing on the configuration file of the software it provides, based on a configuration file containing update content corresponding to the hospital. Specifically, as shown in Figure 9, the update device obtains organization identification information 1 for identifying the hospital from a configuration file on the update device's storage device prior to outputting an HTTP request. As shown in Figure 9, the update device outputs request information including the obtained organization identification information 1 to the distribution device as an HTTP request using the GET method. The request information also includes, for example, the JWT. The update device outputs the request information to the distribution device via HTTPS-based communication. The distribution device performs the three authentications described above based on the obtained request information. As shown in Figure 9, after the three authentications are completed, the distribution device accesses the S3 bucket and identifies the object corresponding to the organization identification information 1 from the group of objects. As shown in Figure 9, each of the group of objects includes, for example, organization identification information (in Figure 9, the organization identification information is shown as organization identification information 1 to organization identification information N) in its metadata. In detail, the distribution device, for example, uses the search function of Amazon Athena to perform a search process using the organization identification information 1 as a query. As shown in Figure 9, the distribution device identifies, for example, an object from a group of objects that contains the organization identification information 1 in its metadata as a result of the search process. As shown in Figure 9, the distribution device outputs, for example, a configuration file containing the update content of the identified object to the update device as a response to the request. The update device, for example, performs a check of the integrity of the acquired configuration file in the same way as the check of the integrity of the update content information described above. After the integrity check is completed, the update device, for example, performs an update process on the software configuration file based on the acquired update content configuration file.

[0130] According to this disclosure, updates can be managed for each target. Furthermore, according to this disclosure, for example, appropriate update information can be distributed to multiple targets. Furthermore, according to this disclosure, for example, if the software update status differs for each target, update information can be distributed according to the update status of each target. Furthermore, according to this disclosure, for example, if the software settings differ for each target, update information can be distributed according to the settings of each target. Furthermore, according to this disclosure, for example, if the software execution environment differs for each target, update information can be distributed according to the execution environment of each target. Furthermore, according to this disclosure, for example, update processing can be performed for multiple targets using appropriate update information for each target. Furthermore, according to this disclosure, for example, if the software update status differs for each target, update processing can be performed using update information according to the update status of each target. Furthermore, according to this disclosure, for example, if the software settings differ for each target, update processing can be performed using update information according to the settings of each target. Furthermore, according to this disclosure, for example, if the software execution environment differs for each target, update processing can be performed using update information according to the execution environment of each target.

[0131] Although the present disclosure has been described above with reference to embodiments, the present disclosure is not limited to the embodiments described above. Various modifications to the structure and details of the present disclosure can be made as can be understood by those skilled in the art within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.

[0132] <Note> Some or all of the above embodiments may be described as follows, but are not limited to the following: (Note 1) Including acquisition procedures, identification procedures, and output procedures, The acquisition procedure described above involves obtaining request information regarding the request to acquire update content information from the update device, The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification procedure involves identifying the storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output procedure involves outputting the update content information contained in the identified storage area to the update device as a response to the request. A distribution program that causes a computer to perform each of the above steps. (Note 2) The subject mentioned above is an organization, The aforementioned identification information is organizational identification information for identifying the aforementioned organization. The distribution program described in Appendix 1. (Note 3) Furthermore, including the judgment procedure, The determination procedure determines whether the request information includes permission information relating to access rights to the group of storage areas, If it is determined that the request information includes the authorization information, the identification process according to the identification procedure and the output process according to the output procedure are executed. The distribution program described in Appendix 1 or 2. (Note 4) Furthermore, including the storage procedure, The acquisition procedure involves acquiring log information relating to the software update process provided by the update device from the update device, The log information includes the identification information, The storage procedure involves storing the acquired log information in the specified storage area. The distribution program described in any of the appendices 1 to 3. (Note 5) Including output procedures, acquisition procedures, and update procedures, The output procedure involves outputting request information related to the request to obtain update content information to the distribution device. The aforementioned request information includes identification information for identifying the target, The aforementioned update information is information regarding the software update content of the update device, The acquisition procedure involves acquiring the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The update procedure executes the software update process of the update device based on the acquired update content information. An update program that causes the computer to perform each of the above steps. (Note 6) Furthermore, including the judgment procedure, The aforementioned determination procedure determines whether the acquired update information is complete or not. The update procedure, if it is determined that the acquired update information is complete, executes the software update process of the update device based on the acquired update information. The update program described in Appendix 5. (Note 7) An update management system including a distribution device equipped with a distribution program described in any of the appendices 1 to 4, and an update device equipped with an update program described in appendice 5 or 6. (Note 8) Including an acquisition unit, a specification unit, and an output unit, The acquisition unit acquires request information relating to a request to acquire update content information from the update device. The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification unit identifies the storage area corresponding to the identification information from the group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output unit outputs the update content information contained in the identified storage area to the update device as a response to the request. Distribution device. (Note 9) The subject mentioned above is an organization, The aforementioned identification information is organizational identification information for identifying the aforementioned organization. The distribution device described in Appendix 8. (Note 10) Furthermore, including a determination unit, The determination unit determines whether the request information includes permission information relating to access rights to the group of storage areas, If it is determined that the request information includes the authorization information, the identification unit performs the identification process and the output unit performs the output process. The distribution device described in Appendix 8 or 9. (Note 11) Furthermore, including the storage compartment, The acquisition unit acquires log information relating to the update process of the update device from the update device, The log information includes the identification information, The storage unit stores the acquired log information in the specified storage area. A distribution device as described in any of the appendices 8 to 10. (Note 12) Including an output unit, an acquisition unit, and an update unit, The output unit outputs request information related to the request to obtain update content information to the distribution device. The aforementioned request information includes identification information for identifying the target, The aforementioned update information is information regarding the software update content of the update device, The acquisition unit acquires the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The update unit executes the software update process of the update device based on the acquired update content information. Update device. (Note 13) Furthermore, including a determination unit, The determination unit determines whether the acquired update information is complete or not. If the update unit determines that the acquired update information is complete, it will perform the software update process of the update device based on the acquired update information. The update device described in Appendix 12. (Note 14) An update management system including a distribution device described in any of the appendices 8 to 11, and an update device described in appendice 12 or 13. (Note 15) Including the acquisition process, the identification process, and the output process, The acquisition step involves acquiring request information related to a request to acquire update content information from the update device. The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The aforementioned identification step involves identifying a storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output step outputs the update content information contained in the identified storage area to the update device as a response to the request. A distribution method in which each of the aforementioned steps is performed by a computer. (Note 16) The subject mentioned above is an organization, The aforementioned identification information is organizational identification information for identifying the aforementioned organization. Distribution method as described in Appendix 15. (Note 17) Furthermore, including a determination process, The determination step determines whether the request information includes permission information relating to access rights to the group of storage areas, If it is determined that the request information includes the authorization information, the specific processing by the specific step and the output processing by the output step are executed. Distribution method as described in Appendix 15 or 16. (Note 18) Furthermore, including the storage process, The acquisition step involves acquiring log information relating to the log in the software update process provided by the update device from the update device. The log information includes the identification information, The storage step involves storing the acquired log information in the specified storage area. The distribution method described in any of the appendices 15 to 17. (Note 19) Including output, acquisition, and update processes, The output step outputs request information related to the request to obtain update content information to the distribution device. The aforementioned request information includes identification information for identifying the target, The aforementioned update information is information regarding the software update content of the update device, The acquisition step involves acquiring the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The update process executes the software update process of the update device based on the acquired update content information. An update method in which each of the aforementioned steps is performed by a computer. (Note 20) Furthermore, including a determination process, The determination step determines whether the acquired update information is complete or not. If the update process determines that the acquired update information is complete, it will perform a software update process on the update device based on the acquired update information. Update method as described in Appendix 19. (Note 21) An update management system including a distribution device that performs the distribution method described in any of the appendices 15 to 18, and an update device that performs the update method described in appendice 19 or 20. (Note 22) Including acquisition procedures, identification procedures, and output procedures, The acquisition procedure described above involves obtaining request information regarding the request to acquire update content information from the update device, The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification procedure involves identifying the storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output procedure involves outputting the update content information contained in the identified storage area to the update device as a response to the request. A computer-readable recording medium containing a distribution program that causes a computer to perform each of the aforementioned procedures. (Note 23) The subject mentioned above is an organization, The aforementioned identification information is organizational identification information for identifying the aforementioned organization. Recording medium as described in Appendix 22. (Note 24) Furthermore, including the judgment procedure, The determination procedure determines whether the request information includes permission information relating to access rights to the group of storage areas, If it is determined that the request information includes the authorization information, the identification process according to the identification procedure and the output process according to the output procedure are executed. Recording medium as described in Appendix 22 or 23. (Note 25) Furthermore, including the storage procedure, The acquisition procedure involves acquiring log information relating to the software update process provided by the update device from the update device, The log information includes the identification information, The storage procedure involves storing the acquired log information in the specified storage area. A recording medium as described in any of the appendices 22 to 24. (Note 26) Including output procedures, acquisition procedures, and update procedures, The output procedure involves outputting request information related to the request to obtain update content information to the distribution device. The aforementioned request information includes identification information for identifying the target, The aforementioned update information is information regarding the software update content of the update device, The acquisition procedure involves acquiring the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The update procedure executes the software update process of the update device based on the acquired update content information. A computer-readable storage medium containing updates that cause the computer to perform each of the aforementioned steps. (Note 27) Furthermore, including the judgment procedure, The aforementioned determination procedure determines whether the acquired update information is complete or not. The update procedure, if it is determined that the acquired update information is complete, executes the software update process of the update device based on the acquired update information. Recording medium as described in Appendix 26. (Note 28) An update management system including a distribution device equipped with a recording medium described in any of appendices 22 to 25, and an update device equipped with a recording medium described in appendice 26 or 27. [Industrial applicability]

[0133] According to this disclosure, updates can be managed on a per-target basis. Therefore, this disclosure can be widely and usefully applied in various fields that require software update management. [Explanation of Symbols]

[0134] 10, 10A, 10B distribution device 20, 20A update device 11 Acquisition Department 12 Specific part 13 Output section 14 Judgment section 15 Storage Unit 21 Output section 22 Acquisition Department 23 Update section 24 Judgment section 30 Communication Network 100 Update Management System 101, 201 Central Processing Unit 102, 202 memory Buses 103 and 203 104, 204 Storage device 105, 205 Input devices 106, 206 Output devices 107, 207 Communication devices

Claims

1. Including acquisition procedures, identification procedures, and output procedures, The acquisition procedure described above involves obtaining request information regarding the request to acquire update content information from the update device, The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification procedure involves identifying the storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output procedure involves outputting the update content information contained in the identified storage area to the update device as a response to the request. A distribution program that causes a computer to perform each of the above steps.

2. The subject mentioned above is an organization, The aforementioned identification information is organizational identification information for identifying the aforementioned organization. The distribution program according to claim 1.

3. Furthermore, including the judgment procedure, The determination procedure determines whether the request information includes permission information relating to access rights to the group of storage areas, If it is determined that the request information includes the authorization information, the identification process according to the identification procedure and the output process according to the output procedure are executed. The distribution program according to claim 1 or 2.

4. Furthermore, including the storage procedure, The acquisition procedure involves acquiring log information relating to the software update process provided by the update device from the update device, The log information includes the identification information, The storage procedure involves storing the acquired log information in the specified storage area. The distribution program according to claim 1 or 2.

5. Including output procedures, acquisition procedures, and update procedures, The output procedure involves outputting request information related to the request to obtain update content information to the distribution device. The aforementioned request information includes identification information for identifying the target, The aforementioned update information is information regarding the software update content of the update device, The acquisition procedure involves acquiring the update content information contained in the storage area corresponding to the identification information from the distribution device as a response to the request. The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The update procedure executes the software update process of the update device based on the acquired update content information. An update program that causes the computer to perform each of the above steps.

6. Furthermore, including the judgment procedure, The aforementioned determination procedure determines whether the acquired update information is complete or not. The update procedure, if it is determined that the acquired update information is complete, executes the software update process of the update device based on the acquired update information. The update program according to claim 5.

7. An update management system comprising a distribution device equipped with the distribution program described in claim 1, and an update device equipped with the update program described in claim 5.

8. Including an acquisition unit, a specification unit, and an output unit, The acquisition unit acquires request information relating to a request to acquire update content information from the update device. The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification unit identifies the storage area corresponding to the identification information from the group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output unit outputs the update content information contained in the identified storage area to the update device as a response to the request. Distribution device.

9. Including the acquisition process, the identification process, and the output process, The acquisition step involves acquiring request information related to a request to acquire update content information from the update device. The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The aforementioned identification step involves identifying a storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output step outputs the update content information contained in the identified storage area to the update device as a response to the request. A distribution method in which each of the aforementioned steps is performed by a computer.

10. Including acquisition procedures, identification procedures, and output procedures, The acquisition procedure described above involves obtaining request information regarding the request to acquire update content information from the update device, The aforementioned request information includes identification information for identifying the target, The update content information is information relating to the update content of the software provided by the update device, The identification procedure involves identifying the storage area corresponding to the identification information from a group of storage areas, The storage area is pre-assigned the identification information for each object and includes the update content information for each object. The output procedure involves outputting the update content information contained in the identified storage area to the update device as a response to the request. A computer-readable recording medium containing a distribution program that causes a computer to perform each of the aforementioned procedures.

Citation Information

Patent Citations

  • Information processing terminal, information processing system, and information processing program

    JP2017004548A