Communication system, communication method, and program

The communication system addresses the issue of unrestricted access by using a communication server to authenticate and authorize user terminals, ensuring secure and restricted connections.

JP7690816B2Active Publication Date: 2025-06-11RICOH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2021135687
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-23
Publication Date
2025-06-11
Estimated Expiration
2041-08-23

AI Technical Summary

Technical Problem

The existing authentication systems, such as the one disclosed in Patent Document 1, allow arbitrary users to obtain certificates on any terminal, leading to unrestricted access.

Method used

A communication system is designed with a user terminal and a communication server, where the user terminal requests authentication and identification information from the communication server, and the server determines whether to permit a connection based on the received identification information.

Benefits of technology

The system effectively restricts connectable terminals by ensuring that only authenticated and authorized user terminals can establish a connection, thereby enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007690816000001
    Figure 0007690816000001
  • Figure 0007690816000002
    Figure 0007690816000002
  • Figure 0007690816000003
    Figure 0007690816000003
Patent Text Reader

Abstract

To provide a communication system that limits connectable terminals.SOLUTION: In a communication system including a user terminal 5 and a communication server 2, an authentication request unit 501 of a user terminal 5 requests an authentication from the communication server 2. An authentication processing unit 201 of the communication server 2 obtains a result of authentication. A browser ID issuance unit 202 of the communication server 2 issues identification information in accordance with the result of authentication. A connection request unit 503 of the user terminal 5 transmits identification information identifying the user terminal 5 which is issued by the communication server 2 when the authentication is successful to the communication server 2 to request connection. A connection determination unit 204 of the communication server 2 determines whether or not connection is permitted on the basis of the identification information received from the user terminal 5.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a communication system, a communication method, and a program.

Background Art

[0002] In web applications, in addition to authentication using a user ID and a password, multi-factor authentication using different elements may be performed.

[0003] For example, Patent Document 1 discloses an authentication system that executes first authentication using a certificate and second authentication using a user ID and a password.

Summary of the Invention

Problems to be Solved by the Invention

[0004] However, the authentication system disclosed in Patent Document 1 has a problem that an arbitrary user can obtain a certificate on an arbitrary terminal because the certificate is issued in response to a request from the client terminal.

[0005] In view of the above technical problems, an embodiment of this invention aims to provide a communication system capable of restricting connectable terminals.

Means for Solving the Problems

[0006] To solve the above problems, a communication system according to an embodiment of this invention is a communication system including a user terminal and a communication server. The user terminal includes an authentication request unit that requests authentication from the communication server, and a connection request unit that transmits identification information for identifying the user terminal, which is issued by the communication server when authentication is successful, to the communication server and requests a connection. The communication server includes an authentication processing unit that obtains the result of authentication, an identification information issuing unit that issues identification information according to the result of authentication, and a connection determination unit that determines whether to permit a connection based on the identification information received from the user terminal.

Effects of the Invention

[0007] According to an embodiment of the present invention, a communication system capable of restricting connectable terminals can be provided.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Best Mode for Carrying Out the Invention

[0009] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In the drawings, components having the same function are denoted by the same reference numerals, and redundant description will be omitted.

[0010] [First Embodiment] The first embodiment of the present invention is a communication system in which a communication server provides a remote desktop connection to a user terminal. The communication system in the first embodiment permits a remote desktop connection only to a user terminal that has successfully authenticated, for example, by a user ID and password and that satisfies a predetermined condition. The predetermined condition is, for example, that when attempting to make a remote desktop connection from an external network, the user terminal has connected from an internal network in the past. This condition is an example, and in the communication system of the first embodiment, any condition that can be defined for the user terminal can be applied.

[0011] To achieve the above, the communication server in the first embodiment issues identification information (hereinafter referred to as "browser ID") that uniquely identifies the user terminal after the user terminal has first successfully authenticated. When the user terminal requests a remote desktop connection to the communication server, it transmits the browser ID issued by the communication server. The communication server determines whether the user terminal satisfies a predetermined condition based on the browser ID received from the user terminal, and permits a remote desktop connection only when the condition is satisfied.

[0012] Note that, although an example of providing a remote desktop connection has been used here for explanation, the communication system in the first embodiment can provide any connection for session management. Similarly, in all subsequent embodiments as well, the communication system can be configured to provide any connection.

[0013] <Overall Configuration of the Communication System in the First Embodiment> FIG. 1 is a diagram showing the overall configuration of a communication system 1 in the first embodiment of the present invention. As shown in FIG. 1, the communication system 1 in the first embodiment includes, for example, a communication server 2 and a user terminal 5.

[0014] The communication server 2 and the user terminal 5 are each connected to a communication network 100. The communication network 100 is configured such that each connected device can communicate with each other. The communication network 100 is constructed by a network using wired communication such as, for example, the Internet, a LAN (Local Area Network), or a WAN (Wide Area Network). The communication network 100 may include not only wired communication but also a network using wireless communication or mobile communication such as, for example, a wireless LAN, short-range wireless communication, 3G (3rd Generation), WiMAX (Worldwide Interoperability for Microwave Access), or LTE (Long Term Evolution).

[0015] The communication server 2 and the user terminal 5 are, for example, computers. Note that the communication server 2 and the user terminal 5 are not limited to computers as long as they are devices having a communication function. The communication server 2 and the user terminal 5 may be, for example, output devices such as a PJ (Projector), an IWB (Interactive White Board: a whiteboard having an electronic blackboard function capable of mutual communication), a digital signage, a HUD (Head Up Display) device, industrial machinery, an imaging device, a sound collecting device, a medical device, a network home appliance, an automobile (Connected Car), a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, or a desktop PC.

[0016] <Hardware Configuration of Communication System in the First Embodiment> <<Hardware Configuration of Computer>> Figure 2 is a hardware configuration diagram of the communication server 2 and the user terminal 5 when constructed by a computer. As shown in Figure 2, the communication server 2 and the user terminal 5 include a CPU 101, a ROM 102, a RAM 103, an HD 104, an HDD (Hard Disk Drive) controller 105, a display 106, an external device connection I / F (Interface) 108, a network I / F 109, a bus line 110, a keyboard 111, a pointing device 112, a DVD-RW (Digital Versatile Disk Rewritable) drive 114, and a media I / F 116.

[0017] Among these, the CPU 101 controls the operations of the entire communication server 2 and the user terminal 5. The ROM 102 stores programs used for driving the CPU 101 such as the IPL. The RAM 103 is used as a work area for the CPU 101. The HD 104 stores various data such as programs. The HDD controller 105 controls the reading or writing of various data to and from the HD 104 according to the control of the CPU 101. The display 106 displays various information such as a cursor, menu, window, characters, or images. The external device connection I / F 108 is an interface for connecting various external devices. The external devices in this case are, for example, a USB (Universal Serial Bus) memory, a printer, etc. The network I / F 109 is an interface for performing data communication using the communication network 100. The bus line 110 is an address bus, a data bus, etc. for electrically connecting the components such as the CPU 101 shown in Figure 2.

[0018] In addition, the keyboard 111 is a type of input means having a plurality of keys for inputting characters, numerical values, various instructions, and the like. The pointing device 112 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, and the like. The DVD-RW drive 114 controls reading or writing of various data with respect to the DVD-RW 113 as an example of a removable recording medium. Note that it is not limited to DVD-RW, and it may be DVD-R or the like. The media I / F 116 controls reading or writing (storage) of data with respect to the recording medium 115 such as a flash memory.

[0019] <Functional Configuration of Communication System in First Embodiment> FIG. 3 is a diagram showing the functional configuration of the communication system 1 in the first embodiment.

[0020] ≪Functional Configuration of Communication Server 2≫ As shown in FIG. 3, the communication server 2 in the first embodiment includes an authentication processing unit 201, a browser ID issuing unit 202, a browser ID storage unit 203, a connection determination unit 204, a connection processing unit 205, and a connection history storage unit 206.

[0021] Each unit (excluding each storage unit) included in the communication server 2 is a function or means realized by executing various instructions on the data read onto the RAM 103 according to the program expanded from the HD 104 by the CPU 101 shown in FIG. 2. Each storage unit included in the communication server 2 is a function or means realized by reading or writing data to the HD 104 via the HDD controller 105 shown in FIG. 2.

[0022] The authentication processing unit 201 receives a signal for requesting authentication from the user terminal 5 (hereinafter referred to as an "authentication request signal"). The authentication processing unit 201 performs authentication on the user terminal 5 using the authentication information included in the authentication request signal and obtains an authentication result. The authentication processing unit 201 transmits the authentication result to the user terminal 5.

[0023] After the authentication for the user terminal 5 is successful, the browser ID issuing unit 202 issues a browser ID that uniquely identifies the user terminal 5. The browser ID issuing unit 202 transmits the issued browser ID to the user terminal 5.

[0024] The browser ID storage unit 203 stores the browser ID issued to the user terminal 5 in association with user information regarding the user who uses the user terminal 5.

[0025] The connection determination unit 204 receives a signal requesting a connection from the user terminal 5 (hereinafter referred to as a "connection request signal"). The connection determination unit 204 determines whether to permit the connection with the user terminal 5 based on the browser ID included in the connection request signal.

[0026] When the determination result based on the browser ID output by the connection determination unit 204 permits the connection with the user terminal 5, the connection processing unit 205 makes a connection with the user terminal 5.

[0027] The connection history storage unit 206 stores a connection history recording the history of the connection with the user terminal 5.

[0028] ≪Functional Configuration of User Terminal 5≫ As shown in FIG. 3, the user terminal 5 in the first embodiment includes a browser 50. The browser 50 includes an authentication request unit 501, a browser ID storage unit 502, a connection request unit 503, and a connection processing unit 504.

[0029] Each unit (excluding each storage unit) included in the user terminal 5 is a function or means realized by executing various instructions on the data read onto the RAM 103 according to the program expanded from the HD 104 onto the RAM 103 by the CPU 101 shown in FIG. 2. Each storage unit included in the user terminal 5 is a function or means realized by reading or writing data to or from the HD 104 via the HDD controller 105 shown in FIG. 2.

[0030] The authentication request unit 501 transmits an authentication request signal to the communication server 2 in response to an operation of a user using the user terminal 5. The authentication request signal includes authentication information. If there is a browser ID issued by the communication server 2 to the user terminal 5, the authentication request signal includes the browser ID.

[0031] The browser ID storage unit 502 stores the browser ID issued by the communication server 2 to the user terminal 5.

[0032] The connection request unit 503 transmits a connection request signal to the communication server 2 in response to an operation of a user using the user terminal 5. The connection request signal includes connection information and the browser ID stored in the browser ID storage unit 502.

[0033] The connection processing unit 504 establishes a connection with the communication server 2 and communicates with the connection processing unit 205 provided in the communication server 2.

[0034] <Processing procedure of the communication system according to the first embodiment> FIG. 4 is a diagram showing a processing procedure of a communication method executed by the communication system 1 in the first embodiment.

[0035] The steps S501A to S502 shown in FIG. 4 are processing procedures executed when making the first authentication request from the user terminal 5 to the communication server 2.

[0036] In step S501A, the authentication request unit 501 provided in the browser 50 transmits an authentication request signal including authentication information to the communication server 2 in response to an operation of a user using the user terminal 5. The authentication request signal is transmitted by requesting a URL (Uniform Resource Locator) for authentication from the browser 50. The authentication information is, for example, the user ID and password entered by the user on the login screen. The authentication request signal may include user information regarding the user. The user information is, for example, the user ID entered by the user on the login screen. When the authentication information corresponds to the user information, the authentication request signal may include only the authentication information.

[0037] In step S201A, the authentication processing unit 201 included in the communication server 2 receives an authentication request signal from the user terminal 5. The authentication processing unit 201 performs authentication on the user terminal 5 using the authentication information included in the authentication request signal to obtain an authentication result. The authentication processing unit 201 obtains the authentication result by determining whether the received authentication information matches the pre-registered authentication information. The authentication processing unit 201 can also obtain the authentication result from the authentication server by transferring the received authentication information to an external authentication server.

[0038] In step S202, after successfully authenticating the user terminal 5, the browser ID issuing unit 202 included in the communication server 2 determines whether to issue a browser ID to the user terminal 5. The determination of whether to issue a browser ID can be made, for example, based on whether a browser ID issued to the user terminal 5 exists. The determination of whether a browser ID issued to the user terminal 5 exists can be made, for example, based on whether the authentication request signal received from the user terminal 5 includes a browser ID. Here, since the authentication request signal does not include a browser ID, the browser ID issuing unit 202 issues a browser ID that uniquely identifies the user terminal 5.

[0039] The browser ID issuing unit 202 may issue a browser ID so that the user information and the browser ID included in the connection request signal are associated one-to-one. In this case, if a browser ID associated with the user information included in the authentication request signal exists in the browser ID storage unit 203, the browser ID issuing unit 202 does not issue a new browser ID. Alternatively, the browser ID issuing unit 202 discards the browser ID already associated with the user information and issues a new browser ID and associates it with the user information. By associating the user information and the browser ID one-to-one, it becomes possible to limit the number of terminals that can be connected by one user to one.

[0040] In step S203, the browser ID issuing unit 202 provided in the communication server 2 stores the browser ID issued to the user terminal 5 in the browser ID storage unit 203. At this time, the user information included in the authentication request signal and the browser ID may be stored in association with each other.

[0041] In step S201B, the authentication processing unit 201 provided in the communication server 2 transmits the obtained authentication result to the user terminal 5 together with the browser ID issued by the browser ID issuing unit 202. For example, when the authentication result indicates successful authentication, the authentication processing unit 201 transmits the browser ID included in the post-login screen transitioned from the login screen to the user terminal 5. Since the browser ID is information that the user does not need to know, it may be included in the post-login screen as a hidden element. When the authentication result indicates authentication failure, the authentication processing unit 201 transmits an error screen indicating that the authentication has failed to the user terminal 5.

[0042] In step S502, the authentication request unit 501 provided in the browser 50 receives the browser ID together with the authentication result from the communication server 2. The authentication request unit 501 stores the received browser ID in the browser ID storage unit 502. As a means for storing information in the browser, known means such as a Cookie or Web Storage (localStorage or sessionStorage) can be used.

[0043] Steps S501B to S201D shown in FIG. 4 are processing procedures executed when the user terminal 5 makes a second or subsequent authentication request to the communication server 2.

[0044] In step S501B, the authentication request unit 501 provided in the browser 50 transmits an authentication request signal to the communication server 2 according to the operation of the user using the user terminal 5. The authentication request signal includes the browser ID stored in the browser ID storage unit 502 in addition to the authentication information.

[0045] In step S201C, the authentication processing unit 201 included in the communication server 2 receives an authentication request signal from the user terminal 5. The authentication processing unit 201 performs authentication on the user terminal 5 using the authentication information included in the authentication request signal and obtains an authentication result.

[0046] Since the browser ID issuing unit 202 determines that the authentication request signal received from the user terminal 5 does not include a browser ID, it determines not to issue a browser ID.

[0047] In step S201D, the authentication processing unit 201 included in the communication server 2 transmits the obtained authentication result to the user terminal 5. For example, when the authentication result indicates authentication success, the authentication processing unit 201 transmits the post-login screen transitioned from the login screen to the user terminal 5. Here, since the browser ID has not been issued, the post-login screen does not include the browser ID. When the authentication result indicates authentication failure, the authentication processing unit 201 transmits an error screen indicating that the authentication has failed to the user terminal 5.

[0048] Steps S503 to S206 shown in FIG. 4 are processes performed when the user terminal 5 requests a remote desktop connection to the communication server 2.

[0049] In step S503, the connection request unit 503 included in the browser 50 transmits a connection request signal to the communication server 2 according to the operation of the user using the user terminal 5. The connection request signal includes connection information and the browser ID stored in the browser ID storage unit 502. The connection request signal is transmitted by requesting a URL for performing a remote desktop connection from the browser 50. The connection information is, for example, the user ID and password of the remote desktop connection input by the user on the login screen of the remote desktop connection. The browser ID can be given as a query parameter to the URL for performing the remote desktop connection, for example.

[0050] In step S204, the connection determination unit 204 provided in the communication server 2 receives a connection request signal from the user terminal 5. Based on the browser ID included in the connection request signal, the connection determination unit 204 determines whether to permit a remote desktop connection with the user terminal 5. The determination as to whether to permit a remote desktop connection with the user terminal 5 is made based on whether the user terminal 5 indicated by the browser ID satisfies a predetermined condition. When the user terminal 5 indicated by the browser ID satisfies the predetermined condition, the connection determination unit 204 generates a determination result permitting a remote desktop connection with that user terminal 5. On the other hand, when the user terminal 5 indicated by the browser ID does not satisfy the predetermined condition, the connection determination unit 204 generates a determination result rejecting a remote desktop connection with that user terminal 5.

[0051] The predetermined condition determined by the connection determination unit 204 is, for example, that when a remote desktop connection is requested from an external network, the user terminal 5 has connected from an internal network in the past, etc. Whether the user terminal 5 is requesting a remote desktop connection from an external network can be determined from the source network address of the connection request signal, etc. Also, whether the user terminal 5 has connected from an internal network for remote desktop in the past can be determined from the connection history stored in the connection history storage unit 206. In this case, the user terminal 5 needs to have made at least one remote desktop connection from an internal network.

[0052] In step S205, when the connection determination unit 204 permits a remote desktop connection from the user terminal 5, the connection processing unit 205 provided in the communication server 2 communicates with the connection processing unit 504 provided in that user terminal 5 and makes a remote desktop connection with that user terminal 5. When the connection determination unit 204 rejects a remote desktop connection from the user terminal 5, an error screen indicating that the remote desktop connection has been rejected is transmitted to that user terminal 5.

[0053] In step S206, the connection processing unit 205 included in the communication server 2 stores the connection history that records the history of remote desktop connection with the user terminal 5 in the connection history storage unit 206. The connection history includes information indicating the user terminal 5 and information indicating the network of the connection source.

[0054] <Effect of the First Embodiment> The communication system in the first embodiment is configured to determine whether to permit a remote desktop connection based on the browser ID received from the user terminal. The browser ID is issued only when authentication is successful for the first time, stored in the storage unit in the browser, and is not rewritten thereafter, so that the user terminal can be uniquely identified. By determining whether to permit a remote desktop connection based on this browser ID, only the permitted user terminal can make a remote desktop connection.

[0055] Furthermore, the communication system in the first embodiment can also be configured to issue a browser ID so that the user information and the browser ID are associated one-to-one. In this case, it is possible to limit the number of terminals that can be connected by one user to one.

[0056] [Second Embodiment] The communication system in the first embodiment issued a browser ID so as to uniquely identify the user terminal, and determined whether to permit a remote desktop connection based on the browser ID. The communication system in the second embodiment, in addition to the determination based on the browser ID, makes a determination based on the hardware unique information (hereinafter also simply referred to as "unique information") of the user terminal, and determines whether to permit a remote desktop connection based on the combination of those determination results.

[0057] Hereinafter, the communication system 1 in the second embodiment of the present invention will be described centering on the differences from the first embodiment.

[0058] <Overall Configuration of the Communication System in the Second Embodiment> FIG. 5 is a diagram showing the overall configuration of the communication system 1 in the second embodiment of the present invention. As shown in FIG. 5, the communication system 1 in the second embodiment includes, for example, a communication server 2, a user terminal 5, and an administrator terminal 6. The administrator terminal 6 is connected to the communication network 100 and can communicate with the communication server 2 and the user terminal 5 mutually.

[0059] The administrator terminal 6 is, for example, a computer. Note that the administrator terminal 6 is not limited to a computer as long as it is a device having a communication function. The administrator terminal 6 may be, for example, an output device such as a PJ (Projector), an IWB (Interactive White Board: a whiteboard having an electronic blackboard function capable of mutual communication), a digital signage, a HUD (Head Up Display) device, an industrial machine, an imaging device, a sound collecting device, a medical device, a network home appliance, an automobile (Connected Car), a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, or a desktop PC.

[0060] <Functional Configuration of the Communication System in the Second Embodiment> FIG. 6 is a diagram showing the functional configuration of the communication system 1 in the second embodiment.

[0061] <<Functional Configuration of the Communication Server 2>> As shown in FIG. 6, the communication server 2 in the second embodiment includes, in the same manner as the first embodiment, an authentication processing unit 201, a browser ID issuing unit 202, a browser ID storage unit 203, a connection determination unit 204, a connection processing unit 205, and a connection history storage unit 206, and further includes a unique information storage unit 207.

[0062] The unique information storage unit 207 stores unique information regarding the user terminal 5 that permits remote desktop connection. The unique information regarding the user terminal 5 stored in the unique information storage unit 207 is pre-registered from the administrator terminal 6.

[0063] <<Functional Configuration of User Terminal 5>> As shown in FIG. 6, the user terminal 5 in the second embodiment includes a browser 50 as in the first embodiment, and further includes a desktop application 51. The desktop application 51 includes a startup information storage unit 510, a unique information acquisition unit 511, and a browser startup unit 512. The browser 50 in the second embodiment includes an authentication request unit 501, a browser ID storage unit 502, a connection request unit 503, and a connection processing unit 504 as in the first embodiment, and further includes a unique information storage unit 513.

[0064] The startup information storage unit 510 stores startup information for starting the browser 50. The startup information includes a command for starting the browser 50, a URL for acquiring a login screen, information indicating query parameters given to the URL, and the like.

[0065] The unique information acquisition unit 511 acquires unique information about the user terminal 5 from the hardware of the user terminal 5.

[0066] The browser startup unit 512 starts the browser 50 using the startup information stored in the startup information storage unit 510, and passes the unique information about the user terminal 5 acquired by the unique information acquisition unit 511 to the browser 50.

[0067] The unique information storage unit 513 stores the unique information about the user terminal 5 passed from the browser startup unit 512 to the browser 50.

[0068] <<Functional Configuration of Administrator Terminal 6>> As shown in FIG. 6, the administrator terminal 6 in the second embodiment includes a unique information registration unit 601.

[0069] The unique information registration unit 601 included in the administrator terminal 6 is a function or means realized by executing various instructions on the data read onto the RAM 103 according to the program expanded from the HD 104 to the RAM 103 by the CPU 101 shown in FIG. 2.

[0070] The unique information registration unit 601 registers in advance the unique information regarding the user terminal 5 that permits remote desktop connection in the unique information storage unit 207 provided in the communication server 2.

[0071] <Processing procedure of the communication system in the second embodiment> FIG. 7 is a diagram showing the processing procedure of the communication method executed by the communication system 1 in the second embodiment. Here, the processing procedure when the user terminal 5 makes an authentication request for the second time or later to the communication server 2 (that is, when the browser ID issued by the communication server 2 to the user terminal 5 exists) is shown. Note that the processing procedure when the user terminal 5 makes the first authentication request to the communication server 2 (that is, when the browser ID issued by the communication server 2 to the user terminal 5 does not exist) may be obtained by replacing steps S501B to S201D shown in FIG. 7 with steps S501A to S502 shown in FIG. 4.

[0072] In step S601, the unique information registration unit 601 provided in the administrator terminal 6 transmits the unique information regarding the user terminal 5 that permits remote desktop connection to the communication server 2. The unique information is information that can be obtained from the hardware of the user terminal 5 and includes one or more pieces of attribute information. When the user terminal 5 is managed by a device management system or the like, the unique information registration unit 601 may automatically obtain the unique information regarding the user terminal 5 from the device management system or the like and transmit only the unique information regarding the user terminal 5 selected as the user terminal 5 that permits remote desktop connection to the communication server 2. Further, the unique information registration unit 601 may input the obtained unique information into a predetermined hash function to convert it into a hash value, and transmit the obtained hash value to the communication server 2 as the unique information.

[0073] FIG. 8 shows an example of hardware-specific information. As shown in FIG. 8, the hardware-specific information includes, for example, a MAC (Media Access Control) address, an OS (Operating System) name, a version, an OS manufacturer, a system name, a system manufacturer, a system model, a system type, a system SKU, a processor, a BIOS (Basic Input Output System) version / date, an SMBIOS version, an embedded controller version, a BIOS mode, a baseboard manufacturer, a baseboard product, a baseboard version, a role of the platform, a status of secure boot, a PCR7 configuration, an OS directory, a system directory, a boot device, a locale, a hardware abstraction layer version, a memory, a user name, and a time zone, etc. Among these attribute information, there is information that is determined at the time of hardware manufacturing and does not change, and there is also information that changes due to maintenance work such as software updates. The specific information registration unit 601 acquires, as specific information, one or a combination of a plurality of predetermined attribute information among the attribute information shown in FIG. 8.

[0074] Returning to FIG. 7 for explanation. In step S207, the communication server 2 receives specific information from the administrator terminal 6. The communication server 2 stores the received specific information in the specific information storage unit 207 in association with the information indicating the user terminal 5.

[0075] In step S511, the specific information acquisition unit 511 provided in the desktop application 51 acquires specific information regarding the user terminal 5 from the hardware of the user terminal 5. The specific information acquired by the specific information acquisition unit 511 is the same as the specific information registered by the specific information registration unit 601. That is, if the specific information registration unit 601 registers specific information composed of a plurality of attribute information, the specific information acquisition unit 511 acquires specific information composed of the same attribute information. If the specific information registration unit 601 registers the hash value of the specific information, the specific information acquisition unit 511 generates a hash value from the acquired specific information.

[0076] In step S512, the browser startup unit 512 included in the desktop application 51 starts the browser 50 using the startup information stored in the startup information storage unit 510, and transfers the unique information about the user terminal 5 acquired by the unique information acquisition unit 511 to the browser 50. The browser startup unit 512 can transfer the unique information to the browser 50, for example, by giving the unique information as a query parameter to the URL for acquiring the login screen.

[0077] In step S513, the browser 50 receives the unique information about the user terminal 5 from the browser startup unit 512 and stores it in the unique information storage unit 513. The unique information storage unit 513 may store the information in the browser using known means, similar to the browser ID storage unit 502.

[0078] In step S503, the connection request unit 503 included in the browser 50 transmits a connection request signal to the communication server 2. The connection request signal in the second embodiment further includes the unique information stored in the unique information storage unit 513 in addition to the connection information input by the user and the browser ID stored in the browser ID storage unit 502.

[0079] In step S204A, the connection determination unit 204 included in the communication server 2 receives a connection request signal from the user terminal 5. The connection determination unit 204 determines whether to permit a remote desktop connection with the user terminal 5 based on the browser ID included in the connection request signal.

[0080] In step S204B, the connection determination unit 204 provided in the communication server 2 determines whether to permit a remote desktop connection with the user terminal 5 based on the unique information included in the connection request signal. First, the connection determination unit 204 compares the unique information received from the user terminal 5 with the unique information stored in the unique information storage unit 207. When the unique information received from the user terminal 5 matches the unique information stored in the unique information storage unit 207, the connection determination unit 204 generates a determination result permitting the remote desktop connection with that user terminal 5. On the other hand, when the unique information received from the user terminal 5 does not match the unique information stored in the unique information storage unit 207, the connection determination unit 204 generates a determination result rejecting the remote desktop connection with that user terminal 5.

[0081] When the unique information includes a plurality of pieces of attribute information, the connection determination unit 204 compares each piece of attribute information included in the unique information, and if the number of matching pieces of attribute information is equal to or greater than a predetermined threshold, the unique information is treated as matching. The connection determination unit 204 may treat the unique information as matching if the ratio of the number of matching pieces of attribute information to the number of all pieces of attribute information is equal to or greater than a predetermined threshold. Further, when the unique information is a hash value, the connection determination unit 204 treats the unique information as matching when the hash value received from the user terminal 5 matches the hash value stored in the unique information storage unit 207.

[0082] The connection determination unit 204 determines whether to permit a remote desktop connection with the user terminal 5 by using the determination result based on the browser ID obtained in step S204A and the determination result based on the unique information obtained in step S204B. For example, the connection determination unit 204 determines whether to permit the connection with the user terminal 5 by referring to a predetermined connection permission determination table in light of the determination result based on the browser ID and the determination result based on the unique information. The connection permission determination table is a table that defines whether to permit the connection for all combinations of the determination result based on the browser ID and the determination result based on the unique information.

[0083] Fig. 9 shows an example of a connection availability determination table. In the example shown in Fig. 9, when the determination result based on the browser ID is "〇 (connection available)" and the determination result based on the unique information is "〇 (connection available)", remote desktop connection is permitted, and in other cases (i.e., when any of the determination results is "× (connection not available)"), remote desktop connection is denied. Since Fig. 9 is an example of a connection availability determination table, for example, it is also possible to set so that remote desktop connection is permitted if either the determination result based on the browser ID or the determination result based on the unique information is "〇 (connection available)".

[0084] <Effect of the Second Embodiment> The communication system in the second embodiment is configured to perform a determination based on the unique information of the user terminal in addition to the determination based on the browser ID, and to determine whether to permit remote desktop connection based on the combination of those determination results. By registering only the unique information regarding the user terminal previously permitted by the administrator, only the permitted user terminal can establish a remote desktop connection. Also, by using hardware unique information, it is possible to prevent a user terminal from impersonating another to establish a remote desktop connection. Furthermore, when the unique information is a hash value, it is possible to prevent information such as the hardware configuration from leaking from the registered unique information.

[0085] [Third Embodiment] The communication system in the first embodiment is configured to permit remote desktop connection only to user terminals that have a history of connecting from within the company network in the past, based on the browser ID that uniquely identifies the user terminal. The communication system in the third embodiment is configured to permit remote desktop connection only to user terminals managed by the device management system.

[0086] Hereinafter, the communication system 1 in the third embodiment of the present invention will be described focusing on the differences from the first embodiment.

[0087] <Overall Configuration of the Communication System in the Third Embodiment> FIG. 10 is a diagram showing the overall configuration of a communication system 1 in the third embodiment of the present invention. As shown in FIG. 10, the communication system 1 in the third embodiment includes, for example, a communication server 2, a device management server 3, and a user terminal 5. The device management server 3 is connected to a communication network 100 and can communicate with the communication server 2 and the user terminal 5.

[0088] The device management server 3 is, for example, a computer. Note that the device management server 3 is not limited to a computer as long as it is a device having a communication function. The device management server 3 may be, for example, an output device such as a PJ (Projector), an IWB (Interactive White Board), a digital signage, a HUD (Head Up Display) device, an industrial machine, an imaging device, a sound collection device, a medical device, a network home appliance, an automobile (Connected Car), a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, or a desktop PC.

[0089] <Functional Configuration of Each Device in the Communication System in the Third Embodiment> FIG. 11 is a diagram showing the functional configuration of the communication system 1 in the third embodiment.

[0090] ≪Functional Configuration of the Communication Server 2≫ As shown in FIG. 11, the communication server 2 in the third embodiment includes, in the same manner as in the first embodiment, an authentication processing unit 201, a browser ID issuing unit 202, a browser ID storage unit 203, a connection determination unit 204, a connection processing unit 205, and further includes a device ID storage unit 208.

[0091] The device ID storage unit 208 stores the browser ID and the device ID included in the connection request notification signal received from the device management server 3 in association with each other.

[0092] ≪Functional Configuration of User Terminal 5≫ As shown in FIG. 11, the user terminal 5 in the third embodiment includes a browser 50 as in the first embodiment, and further includes an agent 52. The agent 52 includes a device ID storage unit 520, a connection request detection unit 521, and a connection request notification unit 522.

[0093] The device ID storage unit 520 stores a device ID that uniquely identifies the user terminal 5. The device ID is pre-issued to the user terminal 5 by the device management server 3 and is stored in the device ID storage unit 520.

[0094] The connection request detection unit 521 detects that the connection request unit 503 has transmitted a connection request signal to the communication server 2.

[0095] The connection request notification unit 522 transmits a connection request notification signal notifying that the connection request detection unit 521 has detected a connection request signal to the device management server 3. The connection request notification signal includes the browser ID stored in the browser ID storage unit 502 and the device ID stored in the device ID storage unit 520.

[0096] ≪Functional Configuration of Device Management Server 3≫ As shown in FIG. 11, the device management server 3 in the third embodiment includes a connection request notification transfer unit 301.

[0097] The connection request notification transfer unit 301 included in the device management server 3 is a function or means realized by executing various instructions on the data read onto the RAM 103 according to the program expanded from the HD 104 to the RAM 103 by the CPU 101 shown in FIG. 2.

[0098] The connection request notification transfer unit 301 transfers the connection request notification signal received from the user terminal 5 to the communication server 2.

[0099] <Processing procedure of the communication system in the third embodiment> FIG. 12 is a diagram showing the processing procedure of the communication method executed by the communication system 1 in the third embodiment. Here, similar to the second embodiment, the processing procedure when there is a browser ID issued by the communication server 2 to the user terminal 5 is shown.

[0100] In step S503, the connection request unit 503 provided in the browser 50 transmits a connection request signal including the connection information input by the user and the browser ID stored in the browser ID storage unit 502 to the communication server 2 according to the operation of the user using the user terminal 5.

[0101] In step S521, the connection request detection unit 521 provided in the agent 52 detects that the connection request unit 503 has transmitted a connection request signal to the communication server 2. Since the connection request signal is transmitted by requesting a URL for remote desktop connection from the browser 50, it is possible to detect the connection request by presetting a URL for remote desktop connection from the device management server 3 to the agent 52 and monitoring the transmission of a signal requesting that URL.

[0102] In step S522, the connection request notification unit 522 provided in the agent 52 transmits a connection request notification signal notifying that the connection request detection unit 521 has detected a connection request signal to the device management server 3. The connection request notification signal includes the browser ID stored in the browser ID storage unit 502 and the device ID stored in the device ID storage unit 520.

[0103] In step S301, the connection request notification transfer unit 301 provided in the device management server 3 receives a connection request notification signal from the user terminal 5. The connection request notification transfer unit 301 transfers the received connection request notification signal to the communication server 2.

[0104] In step S208, the communication server 2 associates the browser ID and the device ID included in the connection request notification signal received from the device management server 3 with the date and time when the connection request notification signal was received, and stores them in the device ID storage unit 208.

[0105] In step S204, the connection determination unit 204 provided in the communication server 2 receives a connection request signal from the user terminal 5. The connection determination unit 204 determines whether to permit a remote desktop connection with the user terminal 5 based on the browser ID included in the connection request signal. The connection determination unit 204 in the third embodiment makes it a predetermined condition that the browser ID included in the connection request signal received from the user terminal 5 matches the browser ID included in the connection request notification signal received from the device management server 3.

[0106] To determine whether the above conditions are satisfied, the connection determination unit 204 determines whether the browser ID included in the connection request signal received from the user terminal 5 is stored in the device ID storage unit 208. If the browser ID is stored in the device ID storage unit 208, it indicates that the browser ID and the device ID have been notified from the device management server 3. This means that the agent 52 is installed on the user terminal 5 and is managed by the device management server 3.

[0107] The connection determination unit 204 may also determine whether the combination of the browser ID and the device ID most recently stored in the device ID storage unit 208 matches the combination of the browser ID and the device ID stored in the past. If the combination of the browser ID and the device ID has changed, there is a high possibility that the browser ID or the device ID has been spoofed. In this case, the connection determination unit 204 rejects the remote desktop connection.

[0108] The communication server 2 may not be provided with the device ID storage unit 208, and the connection determination unit 204 may directly receive a connection request notification signal from the device management server 3. In this case, the connection determination unit 204 waits for receiving a connection request notification signal from the device management server 3 for a predetermined time after receiving a connection request signal from the user terminal 5. The time for which the connection determination unit 204 waits for the connection request notification signal may be set arbitrarily, for example, it can be set to 10 seconds or the like. If the reception of the connection request notification signal times out, the connection determination unit 204 determines that a remote desktop connection has been requested from the user terminal 5 in which the agent 52 is not installed, and rejects the remote desktop connection.

[0109] <Effect of the Third Embodiment> The communication system according to the third embodiment is configured to permit a remote desktop connection when the browser ID included in the connection request signal received from the user terminal matches the browser ID included in the connection request notification signal received from the device management server. Receiving the browser ID from the device management server indicates that an agent is installed in the user terminal that requests the remote desktop connection, and that the user terminal is managed by the device management server. Therefore, according to the communication system in the third embodiment, only the user terminal managed by the device management server can establish a remote desktop connection.

[0110] Furthermore, the communication system according to the third embodiment determines whether or not the browser ID included in the connection request signal received from the user terminal matches the browser ID included in the connection request notification signal received from the device management server. Also, the communication system according to the third embodiment determines whether or not the combination of the browser ID and the device ID included in the connection request notification signal has changed from the combination received in the past. Thereby, it is possible to prevent impersonation of performing a remote desktop connection by disguising the browser ID or the device ID.

[0111] [Fourth Embodiment] The communication system in the first embodiment issued a browser ID so as to uniquely identify a user terminal, and determined whether to permit a remote desktop connection based on the browser ID. The communication system in the fourth embodiment added a relay device connected to a predetermined network, issued a certificate only to user terminals capable of communicating with the relay device, and determined whether to permit a remote desktop connection based on the certificate.

[0112] Hereinafter, the communication system 1 in the fourth embodiment of the present invention will be described centering on the differences from the first embodiment.

[0113] <Overall Configuration of Communication System in Fourth Embodiment> FIG. 13 is a diagram showing the overall configuration of the communication system 1 in the fourth embodiment of the present invention. As shown in FIG. 13, the communication system 1 in the fourth embodiment includes, for example, a communication server 2, a relay device 4, and user terminals 5. The relay device 4 is connected to the communication network 100 and is capable of mutually communicating with at least the communication server 2.

[0114] The relay device 4 is, for example, a computer. Note that the relay device 4 is not limited to a computer as long as it is a device having a communication function. The relay device 4 may be, for example, an output device such as a PJ (Projector), an IWB (Interactive White Board: a whiteboard having an electronic blackboard function capable of mutual communication), a digital signage, a HUD (Head Up Display) device, an industrial machine, an imaging device, a sound collection device, a medical device, a network home appliance, an automobile (Connected Car), a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, or a desktop PC.

[0115] <Functional Configuration of Communication System in Fourth Embodiment> FIG. 14 is a diagram showing the functional configuration of the communication system 1 in the fourth embodiment.

[0116] <<Functional Configuration of Communication Server 2>> As shown in FIG. 14, the communication server 2 in the fourth embodiment includes a connection determination unit 204 and a connection processing unit 205, similar to the first embodiment, and further includes a one-time ID issuing unit 211, a communication determination request unit 212, an access request unit 213, and a certificate issuing unit 214.

[0117] The one-time ID issuing unit 211 receives a signal (hereinafter referred to as a "certificate request signal") for requesting a certificate from the user terminal 5. The one-time ID issuing unit 211 issues a one-time ID used to determine whether communication between the relay device 4 and the user terminal 5 is possible.

[0118] The communication determination request unit 212 transmits a signal (hereinafter referred to as a "communication availability determination request signal") for requesting a determination as to whether communication with the user terminal 5 is possible to the relay device 4. The communication availability determination request signal includes the one-time ID issued by the one-time ID issuing unit 211.

[0119] The access request unit 213 transmits a signal (hereinafter referred to as an "access request signal") for requesting access to the relay device 4 to the user terminal 5. The access request signal includes the one-time ID issued by the one-time ID issuing unit 211.

[0120] The certificate issuing unit 214 receives the result (hereinafter referred to as the "communication availability determination result") of determining whether communication with the user terminal 5 is possible from the relay device 4. The certificate issuing unit 214 issues a certificate to the user terminal 5 that can communicate with the relay device 4. The certificate issuing unit 214 transmits the issued certificate to the user terminal 5.

[0121] <<Functional Configuration of Relay Device 4>> As shown in FIG. 14, the relay device 4 in the fourth embodiment includes a communication determination unit 401 and a determination result transmission unit 402.

[0122] The communication determination unit 401 and the determination result transmission unit 402 included in the relay device 4 are functions or means that are realized by executing various instructions on the data read onto the RAM 103 according to the program expanded from the HD 104 by the CPU 101 shown in FIG. 2.

[0123] The communication determination unit 401 receives a communication availability determination request signal from the communication server 2. The communication determination unit 401 determines whether communication with the user terminal 5 is possible using the one-time ID included in the communication availability determination request signal.

[0124] The determination result transmission unit 402 transmits the communication availability determination result by the communication determination unit 401 to the communication server 2.

[0125] ≪Functional Configuration of User Terminal 5≫ As shown in FIG. 14, the user terminal 5 in the fourth embodiment includes a browser 50 as in the first embodiment. The browser 50 in the fourth embodiment includes a connection request unit 503 and a connection processing unit 504 as in the first embodiment, and further includes a certificate request unit 531, an access response unit 532, and a certificate storage unit 533.

[0126] The certificate request unit 531 transmits a certificate request signal to the communication server 2 according to the operation of the user using the user terminal 5.

[0127] The access response unit 532 receives an access request signal from the communication server 2. The access response unit 532 accesses the relay device 4 using the one-time ID included in the access request signal.

[0128] The certificate storage unit 533 stores the certificate issued by the communication server 2 to the user terminal 5.

[0129] <Processing Procedure of Communication System According to Fourth Embodiment> FIG. 15 is a diagram showing the processing procedure of the communication method executed by the communication system 1 in the fourth embodiment.

[0130] In step S531, the certificate request unit 531 provided in the browser 50 transmits a certificate request signal to the communication server 2 in response to an operation of a user using the user terminal 5.

[0131] In step S211, the one-time ID issuing unit 211 provided in the communication server 2 receives a certificate request signal from the user terminal 5. The one-time ID issuing unit 211 issues a one-time ID used to determine whether communication with the user terminal 5 is possible.

[0132] In step S212, the communication determination request unit 212 provided in the communication server 2 transmits a communication availability determination request signal to the relay device 4. The access request signal includes the one-time ID issued by the one-time ID issuing unit 211.

[0133] In step S401, the communication determination unit 401 provided in the relay device 4 receives a communication availability determination request signal from the communication server 2. The communication determination unit 401 waits for a predetermined time for an access using the one-time ID included in the communication availability determination request signal. The time for which the communication determination unit 401 waits for an access using the one-time ID can be arbitrarily set, for example, it can be set to 10 seconds or the like.

[0134] If there is an access using the one-time ID within the predetermined time, the communication determination unit 401 determines that communication with the user terminal 5 is possible. On the other hand, if there is no access using the one-time ID within the predetermined time, the communication determination unit 401 determines that communication with the user terminal 5 is impossible. Also, even if there is an access using the one-time ID within the predetermined time, if the one-time ID received from the communication server 2 is different from the one-time ID for which the access occurred, it is determined that communication with the user terminal 5 is impossible.

[0135] In step S213, the access request unit 213 provided in the communication server 2 transmits an access request signal to the user terminal 5. The access request signal includes the one-time ID issued by the one-time ID issuing unit 211.

[0136] In step S532, the access response unit 532 provided in the browser 50 receives an access request signal from the communication server 2. Using the one-time ID included in the access request signal, the access response unit 532 accesses the relay device 4. The access to the relay device 4 is performed, for example, by requesting a URL for determining communication availability from the browser 50. In this case, the one-time ID is given as a query parameter when accessing the URL, for example.

[0137] In step S402, the determination result transmission unit 402 provided in the relay device 4 transmits the communication availability determination result determined by the communication determination unit 401 as to whether the communication of the user terminal 5 is possible to the communication server 2.

[0138] In step S214A, the certificate issuing unit 214 provided in the communication server 2 receives the communication availability determination result from the relay device 4. When the communication availability determination result indicates that communication with the user terminal 5 is possible, the certificate issuing unit 214 issues a certificate to the user terminal 5. When the communication availability determination result indicates that communication with the user terminal 5 is impossible, the certificate issuing unit 214 transmits an error screen indicating that the issuance of the certificate has been rejected to the user terminal 5.

[0139] In step S214B, the certificate issuing unit 214 provided in the communication server 2 transmits the issued certificate to the user terminal 5.

[0140] In step S533, the certificate request unit 531 provided in the browser 50 receives a certificate from the communication server 2. The certificate request unit 531 stores the received certificate in the certificate storage unit 533. As a means for storing the certificate in the browser, a function generally provided in the browser may be used. When the OS installed in the user terminal 5 has a function for managing the certificate, the certificate may be stored in the OS.

[0141] In step S503, a connection request unit 503 provided in the browser 50 transmits a connection request signal to the communication server 2 according to an operation of a user who uses the user terminal 5. The connection request signal in the fourth embodiment includes connection information input by the user and a certificate stored in the certificate storage unit 533.

[0142] In step S204, a connection determination unit 204 provided in the communication server 2 receives a connection request signal from the user terminal 5. The connection determination unit 204 determines whether to permit a remote desktop connection with the user terminal 5 based on the certificate included in the connection request signal. For example, the connection determination unit 204 verifies the certificate received from the user terminal 5, and if it is a valid certificate, permits the remote desktop connection with the user terminal 5. On the other hand, if the certificate received from the user terminal 5 is an invalid certificate, the connection determination unit 204 rejects the remote desktop connection with the user terminal 5.

[0143] <Effect of the Fourth Embodiment> The communication system in the fourth embodiment is configured to issue a certificate only to user terminals that can be connected to the relay device. For example, when the relay device is connected to the in-house network, a certificate can be issued only to user terminals connected to the in-house network that can communicate with the relay device. By determining whether to permit a remote desktop connection based on this certificate, only user terminals connected to the in-house network can establish a remote desktop connection.

[0144] <Supplementary Note> Each function of the embodiments described above can be realized by one or more processing circuits. Here, the "processing circuit" in this specification refers to a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, an ASIC (Application Specific Integrated Circuit) designed to execute each function described above, a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), or a device such as a conventional circuit module.

[0145] The device group described in the examples only shows one of a plurality of computing environments for implementing the embodiments disclosed in this specification. In one embodiment, the communication server 2 includes a plurality of computing devices such as a server cluster. The plurality of computing devices are configured to communicate with each other via any type of communication link including a network or a shared memory, and implement the processing disclosed in this specification.

[0146] Note that in each of the above embodiments, the browser ID is an example of identification information. The browser ID issuing unit 202 is an example of an identification information issuing unit.

[0147] Although the embodiments of the present invention have been described in detail above, the present invention is not limited to these embodiments, and various modifications or changes are possible within the scope of the gist of the present invention described in the claims.

Explanation of Reference Numerals

[0148] 1 Communication system 2 Communication server 3 Device management server 4 Relay device 5 User terminal 6 Administrator terminal 50 Browser 51 Desktop application 52 Agent 100 Communication Network 201 Authentication Processing Unit 202 Browser ID Issuing Unit 203 Browser ID Storage Unit 204 Connection Judgment Unit 205 Connection Processing Unit 206 Connection History Storage Unit 207 Proprietary Information Storage Unit 208 Device ID Storage Unit 211 One-Time ID Issuing Unit 212 Communication Judgment Request Unit 213 Access Request Unit 214 Certificate Issuing Unit 301 Connection Request Notification Transfer Unit 401 Communication Judgment Unit 402 Judgment Result Sending Unit 501 Authentication Request Unit 502 Browser ID Storage Unit 503 Connection Request Unit 504 Connection Processing Unit 510 Startup Information Storage Unit 511 Proprietary Information Acquisition Unit 512 Browser Startup Unit 513 Proprietary Information Storage Unit 520 Device ID Storage Unit 521 Connection Request Detection Unit 522 Connection Request Notification Unit 531 Certificate Request Unit 532 Access Response Unit 533 Certificate Storage Unit 601 Proprietary Information Registration Unit

Prior Art Documents

Patent Documents

[0149]

Patent Document 1

Claims

1. A communication system including a user terminal, a communication server, and a device management server, wherein the user terminal includes: an authentication request unit that requests authentication from the communication server; a connection request unit that transmits, to the communication server, identification information for identifying the user terminal, which is issued by the communication server when the authentication is successful, and requests a connection; a connection request notification unit that, when detecting that the connection has been requested, notifies the device management server of the identification information; and the device management server includes a connection request notification transfer unit that transfers the identification information notified from the user terminal to the communication server, wherein the communication server includes: an authentication processing unit that obtains a result of the authentication; an identification information issuing unit that issues the identification information according to the result of the authentication; a connection determination unit that determines whether to permit the connection based on the identification information received from the user terminal; and the connection determination unit permits the connection when the identification information received from the user terminal matches the identification information transferred from the device management server. The communication system.

2. The communication system according to claim 1, wherein the connection determination unit permits the connection when the identification information received from the user terminal indicates a user terminal that has made the connection from a predetermined network. The communication system.

3. The communication system according to claim 2, wherein the identification information is associated with user information regarding the user terminal, and the identification information issuing unit issues the identification information such that the user information and the identification information that are successful in the authentication are associated with each other in a one-to-one manner. The communication system.

4. The communication system according to claim 1, wherein the connection request unit transmits unique information regarding the hardware of the user terminal together with the identification information and requests the connection, and the connection determination unit determines whether to permit the connection based on a determination result based on the identification information received from the user terminal and a determination result based on the unique information received from the user terminal. The communication system.

5. The communication system according to claim 4, wherein the unique information is a hash value obtained by inputting attribute information acquired from the hardware of the user terminal into a hash function. The communication system.

6. The communication system according to claim 4, The unique information includes a plurality of attribute information obtained from the hardware of the user terminal. The connection determination unit compares the unique information received from the user terminal with the pre-registered unique information, and determines whether to permit the connection based on the number of the matching attribute information. Communication system.

7. A communication method executed by a communication system including a user terminal, a communication server, and a device management server, wherein the user terminal requests authentication from the communication server; the communication server obtains the result of the authentication; the communication server issues identification information for identifying the user terminal according to the result of the authentication; when the authentication is successful, the user terminal transmits the identification information issued by the communication server to the communication server and requests a connection; when the user terminal detects that the connection is requested, the user terminal notifies the device management server of the identification information; the device management server transfers the identification information notified from the user terminal to the communication server; the communication server determines whether to permit the connection based on the identification information received from the user terminal; including in the determining step, when the identification information received from the user terminal matches the identification information transferred from the device management server, the connection is permitted. Communication method.

8. A computer capable of communicating with a user terminal and a device management server, obtaining the result of the authentication requested by the user terminal; issuing identification information for identifying the user terminal according to the result of the authentication; determining whether to permit the connection with the user terminal based on the identification information received from the user terminal; executing when the user terminal detects that the connection is requested, the user terminal notifies the device management server of the identification information, the device management server transfers the identification information notified from the user terminal to the computer, in the determining step, when the identification information received from the user terminal matches the identification information transferred from the device management server, the connection is permitted. Program.

Citation Information

Patent Citations

  • Authentication processing device, authentication processing method and authentication processing program

    JP2009211529A

  • Client authentication system

    JP2010079795A

  • Key management device and key managing method

    JP2011071721A

  • Authentication system, client terminal, server, method to be authenticated, method to authenticate, authentication client program, and authentication server program

    JP2012113549A

  • Program of registration server, information device, program of information device, and network system

    JP2015018473A