Data processing apparatus, data processing method, and program

The data processing apparatus and method address the vulnerabilities in existing data protection systems by using authentication codes and identification codes to ensure only authorized users can access and process data, independent of specific applications, thereby enhancing data protection and preventing unauthorized access.

JP7691084B2Active Publication Date: 2025-06-11NEC SOLUTION INNOVATORS LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2023561519
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-11-16
Filing Date
2022-11-02
Publication Date
2025-06-11
Estimated Expiration
2042-11-02

AI Technical Summary

Technical Problem

Existing data protection systems, such as the one described in Patent Document 1, are vulnerable to unauthorized data access due to reliance on specific applications for decryption and lack of application-independent data protection, leading to potential data exposure even after decryption keys are deleted.

Method used

A data processing apparatus and method that utilize an authentication code acquisition unit, a code management unit, a determination unit, and a processing permission unit to ensure only authorized users can access and process data, independent of specific applications, by managing authentication codes and identification codes to determine data access rights.

Benefits of technology

This solution effectively prevents unauthorized data access by ensuring that only users with the right to use the data can process it, even if encryption keys remain, thus enhancing data protection without relying on specific applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691084000001
    Figure 0007691084000001
  • Figure 0007691084000002
    Figure 0007691084000002
  • Figure 0007691084000003
    Figure 0007691084000003
Patent Text Reader

Abstract

This data processing device 20 comprises: an authentication code acquisition unit 1 that acquires an authentication code associated with a user who has logged in when login authentication has succeeded; a code management unit 2 that manages, in association with each other, an identification code for identifying the user who has succeeded in the login authentication and the authentication code; a determination unit 3 that determines whether the user corresponding to the authentication code has data usage rights on the basis of the presence or absence of the authentication code corresponding to the identification code of the user who has performed an access request during a data access request; and a processing permission unit 4 that permits processing of the data by the user when the user is granted usage rights.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to a data processing apparatus, a data processing method, and a program for realizing these. to the

Background Art

[0002] Conventionally, there is a system that enables data stored in storage to be accessed from a plurality of terminal devices. In such a system, in order to prevent unauthorized use of data, it is desired to enhance the security of the data, for example, by encrypting the data. For example, Patent Document 1 discloses a system for enhancing the security of data.

[0003] The system disclosed in Patent Document 1 includes a user terminal and a key generation management device. The key generation management device stores an encryption key and authentication information in association with each other. Then, the key generation management device performs authentication based on the authentication information transmitted from the user terminal, and when the authentication is successful, transmits the encryption key to the user terminal. The user terminal temporarily stores the received encryption key. The user terminal executes a specific application, and on that application, uses the encryption key to decrypt the stored encrypted data. Then, the user terminal deletes the received encryption key based on a predetermined condition, such as when a logout operation for a specific application is performed.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] ​However, even when data is protected as in the system disclosed in Patent Document 1, if the system is configured such that an administrator can change the data access rights, there is a possibility of unauthorized data access by users who use the data.

[0006] Also, in the system disclosed in Patent Document 1, encrypted data is decrypted by a specific application. Therefore, in order to protect the data, it is necessary to prepare and execute a specific application. Further, when data protection is performed by a specific application, there is a risk that a third party without the data usage right can access the protected data by using the specific application. For this reason, data protection that does not depend on an application is desired.

[0007] Furthermore, in the system disclosed in Patent Document 1, although encryption key is deleted under a predetermined condition, there is a possibility that the data once decrypted remains in plain text. At this time, since the data is accessible by a third party, sufficient data protection is not performed.

[0008] Therefore, an example of the object of the present disclosure is to enable only a user having the data usage right to perform data processing without depending on an application.

Means for Solving the Problem

[0009] To achieve the above object, a data processing apparatus according to an aspect of the present disclosure includes an authentication code acquisition unit that acquires an authentication code associated with the user when the user who has logged in has successfully passed the login authentication; a code management unit that manages by associating an identification code for identifying the user who has successfully passed the login authentication with the authentication code; When a data access request is made, based on the presence or absence of an authentication code corresponding to the identification code of the user who made the access request, a determination unit determines whether the user corresponding to the authentication code has the right to use the data. When the user is granted the right to use, a processing permission unit permits the user to process the data. It is characterized by comprising the above.

[0010] Also, in order to achieve the above object, a data processing method according to an aspect of the present disclosure When a user who has logged in has successfully passed the login authentication, a step of obtaining an authentication code associated with the user. A step of managing the identification code for identifying the user who has successfully passed the login authentication and the authentication code in association with each other. When a data access request is made, based on the presence or absence of an authentication code corresponding to the identification code of the user who made the access request, a step of determining whether the user corresponding to the authentication code has the right to use the data. When the user is granted the right to use, a step of permitting the user to process the data. It is characterized by having the above.

[0011] Furthermore, in order to achieve the above object, in an aspect of the present disclosure program is For a computer, When a user who has logged in has successfully passed the login authentication, a step of obtaining an authentication code associated with the user. A step of managing the identification code for identifying the user who has successfully passed the login authentication and the authentication code in association with each other. When a data access request is made, based on the presence or absence of an authentication code corresponding to the identification code of the user who made the access request, a step of determining whether the user corresponding to the authentication code has the right to use the data. When the user is granted the right to use, a step of permitting the user to process the data, to execute do, characterized in that.

Effect of the Invention

[0012] As described above, according to the present disclosure, only a user having the right to use data can perform data processing without depending on an application.

Brief Description of the Drawings

[0013]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Mode for Carrying Out the Invention

[0014] Hereinafter, a data processing apparatus, a data processing method, and a program according to an embodiment will be described with reference to FIGS. 1 to 7.

[0015] [Device Configuration] First, the schematic configuration of the data processing device in the embodiment will be described with reference to FIG. 1. FIG. 1 is a configuration diagram showing the schematic configuration of the data processing device 20 in the embodiment.

[0016] The data processing device 20 is a device that permits the processing of data by a user having the right to use the data. As shown in FIG. 1, the data processing device 20 includes an authentication code acquisition unit 1, a code management unit 2, a determination unit 3, and a processing permission unit 4.

[0017] The authentication code acquisition unit 1 acquires the authentication code associated with the user when the user who has logged in has successfully passed the login authentication.

[0018] The code management unit 2 manages by associating an identification code for identifying the user who has successfully passed the login authentication with the authentication code.

[0019] The determination unit 3 determines the presence or absence of the authentication code corresponding to the identification code of the user who has made the access request when an access request to the data is made. And when the determination unit 3 determines that there is an authentication code, it grants the user corresponding to the authentication code the right to use the data.

[0020] The processing permission unit 4 permits the processing of data by the user when the user is granted the right to use.

[0021] As described above, each time a user who has logged in successfully completes login authentication, the data processing apparatus 20 of the present embodiment acquires an authentication code set for that user. Then, on the condition that the authentication code set for the user can be acquired, the data processing apparatus 20 permits the user to use the data. Therefore, even when a third party uses the data processing apparatus 20, if the authentication code cannot be acquired, that third party is treated as having no right to use the data and cannot perform data processing on the data processing apparatus 20. That is, only a user who has the right to use the data can perform data processing. For example, even if an encryption key remains without being deleted, it is impossible for a third party to handle the data.

[0022] Further, the data processing apparatus 20 of the present embodiment does not permit an application executed within the apparatus to use the data, but permits the use of the data when the logged-in user has the right to use the data. That is, by using the data processing apparatus 20, it is possible to securely protect the data for each logged-in user without preparing an application for protecting the data for each piece of data to be used.

[0023] For example, assume that there is data X for which only user A has the right to use and data Y for which only user B has the right to use, and two applications P and Q for performing data processing are executed on the data processing apparatus 20. At this time, user A who has logged in to the data processing apparatus 20 can use data X using application P, but cannot use data Y. Also, user A can use data X using application Q, but cannot use data Y. On the other hand, user B who has logged in to the data processing apparatus 20 can use data Y using application P, but cannot use data X. Also, user B can use data Y using application Q, but cannot use data X. In this way, the data processing apparatus 20 enables data protection that is independent of the application.

[0024] Furthermore, each time the data processing apparatus 20 of the present embodiment accesses data, if the user has the usage right, the data processing is permitted. Therefore, even if a third party without the usage right accesses the data that a user with the usage right has accessed once, the third party cannot process the data, and sufficient data protection can be achieved.

[0025] Subsequently, with reference to FIGS. 2 to 6, the configuration and functions of the data processing apparatus 20 in the embodiment will be specifically described. Hereinafter, a data processing system including the data processing apparatus 20 will be described.

[0026] FIG. 2 is a block diagram showing the configuration of a data processing system 50 including the data processing apparatus 20. As shown in FIG. 2, the data processing apparatus 20 in the embodiment is connected to a storage 21 and an authentication server 22 so as to be capable of data communication, and together with these, constructs the data processing system 50. In the example of FIG. 2, only one data processing apparatus 20 is illustrated, but a plurality of data processing apparatuses 20 may exist in the data processing system 50.

[0027] The storage 21 is a device including an HDD (Hard Disk Drive), an SSD (Solid State Drive), etc., and stores data handled by the data processing apparatus 20. The storage 21 is accessed by the data processing apparatus 20 by wire or wirelessly. The data stored in the storage 21 is transferred between the data processing apparatus 20. The data stored in the storage 21 is encrypted. Also, the data is encrypted with different keys for each user who created the data.

[0028] The authentication server 22 is a server device that communicates with the data processing device 20 by wire or wirelessly. When a user logs in by inputting a login name, password, biometric information, etc. in the data processing device 20, the authentication server 22 collates the information input at the time of login with the pre-registered authentication information to authenticate the logged-in user. When the user's login authentication is successful, the authentication server 22 generates an authentication code for that user and transmits it to the data processing device 20. The authentication code is a character string (token) including an electronic signature. The authentication code is used to manage the user who performs data processing within the data processing device 20.

[0029] In addition, when the authentication server 22 generates an authentication code as described above, as shown in FIG. 3, it manages the generated authentication code in association with the user (login name). FIG. 3 is a diagram showing an example of a data table associating users with authentication codes.

[0030] The data table shown in FIG. 3 associates the login name of the user with the authentication code. The login name, as will be described later, is a character string that uniquely identifies the user, such as an email address, which is input when the user logs in to the data processing device 20. The authentication server 22 associates the authentication code with this login name and stores it in a memory or the like.

[0031] Note that the authentication server 22 can also generate an authentication code every time a predetermined period elapses and associate the generated authentication code with the user at the timing of successful login authentication. Further, the authentication server 22 can regenerate the authentication code when a certain period has elapsed since the authentication code was generated. By periodically generating the authentication code by the authentication server 22, the security of the data can be enhanced compared to the case where the same authentication code is continuously used.

[0032] Returning to FIG. 2. As shown in FIG. 2, in addition to the authentication code acquisition unit 1, code management unit 2, determination unit 3, and processing permission unit 4 described in FIG. 1, the data processing device 20 further includes a reception unit 5 and a data execution unit 6.

[0033] The data execution unit 6 constructs a data execution environment 7 for executing an application program. Specifically, the data execution environment 7 is constructed, for example, on an OS (Operating System) that constitutes the data processing device 20. Also, in the embodiment, the data stored in the storage 21 is encrypted. For this reason, in the data execution environment 7, the application program will use the decrypted data. The decryption of the data will be described later.

[0034] Also, when the user's login authentication is successful in the authentication server 22, the data execution unit 6 permits the user to log in to the data execution environment 7 and sets a unique identification code to be used in the data execution environment 7. Then, when the identification code is set by the data execution unit 6, the authentication code acquisition unit 1 acquires the identification code and further passes the acquired identification code to the code management unit 2.

[0035] The identification code is a user ID for identifying a user in the data execution environment 7 by the data execution unit 6. The identification code is an alphabet, a number, or a character string using these. The data execution unit 6 may set a different identification code for the user each time the user logs in to the data processing device 20, or may always set the same identification code for the same user.

[0036] The data execution unit 6 makes an access request for the stored data to the storage 21 according to the operation of the user received by the reception unit 5. For example, the data execution unit 6 outputs a signal including the identification information of the data to be accessed. The identification information of the data is, for example, an identifier (data name) such as the file name of the data.

[0037] The reception unit 5 receives various operations input by the user, such as operations by the user, for example, a login operation to the data processing device 20, a data access operation, etc. For example, in the login operation, when the user inputs authentication information such as a login name and a password, the reception unit 5 receives this information. Examples of the login name include an email address, a character string that uniquely identifies the user, etc. Further, the reception unit 5 may be configured to read the biometric information of the user, etc. instead of the login name and password. In the data access operation, the user inputs an identifier of the data to be processed, for example, a file name.

[0038] When the authentication code acquisition unit 1 receives the login operation by the user from the reception unit 5, it transmits the authentication information input in the login operation to the authentication server 22. As described above, the authentication server 22 determines whether the received authentication information matches the authentication information managed as a user having the usage right of the data processing device 20. If they match, the authentication server 22 authenticates the user who performed the login operation. When the login is successful, the authentication server 22 sets an authentication code for the user who performed the login and transmits the set authentication code to the data processing device 20.

[0039] The authentication code acquisition unit 1 acquires the authentication code transmitted from the authentication server 22. In the example of FIG. 2, the login authentication is performed by the external authentication server 22, but when the function of the authentication server is provided in the data processing device 20, it may be performed inside the data processing device 20.

[0040] When the code management unit 2 acquires the identification code from the data execution unit 6, it manages the acquired identification code in association with the authentication code acquired by the authentication code acquisition unit 1. The code management unit 2 performs management using, for example, the data table shown in FIG. 4 in which the authentication code and the identification code are associated. FIG. 4 is a diagram showing an example of a data table in which the identification code and the authentication code are associated.

[0041] When the identification code is set, the user can execute the application program in the data execution environment 7 based on the authority of the identification code. In this case, the application program reads the data stored in the storage 21. Also, when the application program reads the data, it executes the system call provided by the OS and attaches the identification code to the system call.

[0042] In the embodiment, the processing permission unit 4 hooks the system call by the application program, identifies the identification code related to the execution of the system call, and passes the identified identification code to the code management unit 2. Thereby, the code management unit 2 identifies the authentication code corresponding to the passed identification code from the data table it manages, and returns the identified authentication code to the processing permission unit 4. As a result, the processing permission unit 4 can obtain the corresponding authentication code.

[0043] In addition, the processing permission unit 4 obtains the data name (specifically, the location identifier where the data exists) of the data to be executed by the application program from the hooked system call. Then, the processing permission unit 4 passes the obtained data name and authentication code to the determination unit 3.

[0044] In the embodiment, the determination unit 3 determines whether the user who executed the application program in the data execution environment 7 has the right to use the data. Specifically, first, when the data name and the authentication code are passed from the processing permission unit 4, the determination unit 3 sends the authentication code to the authentication server 22. Thereby, the authentication server 22 returns the login name set with the sent authentication code. The determination unit 3 identifies the login name of the user who executed the application program.

[0045] Further, in the embodiment, the determination unit 3 manages, for each piece of data, by associating, a decryption key for decrypting each piece of data and a user who can use the data corresponding to the decryption key. FIG. 5 is a diagram showing an example of a data table in which a data name, a decryption key, and a login name of a user who can use the data are associated. As shown in FIG. 5, the determination unit 3 manages, by means of the data table, by associating, the data name (identification information) of the data, the decryption key of the data, and the user (login name) who has the right to use the data.

[0046] As described above, when the determination unit 3 identifies the login name, it compares the data name corresponding to the identified login name with the data name passed from the processing permission unit 4. As a result of the comparison, if the two match, the determination unit 3 determines that the user who executed the application program has the right to use the data. Also, in this case, the determination unit 3 sends the corresponding decryption key to the processing permission unit 4. The processing permission unit 4 decrypts the data with the decryption key and permits the user to process the data. On the other hand, if the two do not match, the determination unit 3 determines that the user who executed the application program does not have the right to use the data.

[0047] Note that the decryption key for decrypting the data may be managed separately by a key management unit that manages keys. Also, the keys required for encryption and decryption may be the same key (common key) or different keys (private key and public key). When the processing permission unit 4 obtains a decryption key from the outside, it is preferable to delete the obtained decryption key after decrypting the data.

[0048] [Device Operation] Next, the operation of the data processing device 20 in the embodiment will be described with reference to FIGS. 6 and 7. In the following description, FIGS. 1 to 5 will be referred to as appropriate. Also, in the embodiment, by operating the data processing device 20, a data processing method is implemented. Therefore, the description of the data processing method in the embodiment will be replaced by the following description of the operation of the data processing device 20.

[0049] Using FIG. 6, the login process in the data processing apparatus 20 will be described. FIG. 6 is a flowchart showing the operations during the execution of the login process of the data processing apparatus in the embodiment.

[0050] As shown in FIG. 6, first, in the data processing apparatus 20, when the reception unit 5 receives a login operation by the user, it accepts the login operation (step S1). When the reception unit 5 accepts the login operation, it passes the authentication information input by the login operation to the authentication code acquisition unit 1. Next, the authentication code acquisition unit 1 transmits the input authentication information to the authentication server 22 and requests login authentication (step S2).

[0051] When the authentication server 22 receives the authentication information, it executes an authentication process. If the login authentication is successful, it generates an authentication code and associates the generated authentication code with the user (login name) who performed the login. Also, when the login authentication is successful, the authentication server 22 transmits the authentication code associated with the logged-in user to the data processing apparatus 20. In this case, the authentication code acquisition unit 1 acquires the transmitted authentication code (step S3).

[0052] Next, when the user's login authentication is successful in the authentication server 22, the data execution unit 6 permits the user to log in to the data execution environment 7 (step S4). Subsequently, the data execution unit 6 sets an identification code for use by the user under the data execution environment 7 (step S5).

[0053] Next, as shown in FIG. 4 described above, the code management unit 2 manages the authentication code acquired in step S3 and the identification code set in step S5 in association with each other (step S6). Then, this process ends.

[0054] Subsequently, using FIG. 7, the data execution process in the data processing apparatus 20 will be described. FIG. 7 is a flowchart showing the operations during the execution of the application program of the data processing apparatus 20 in the embodiment.

[0055] First, as a premise, assume that a user with an identification code performs an execution operation of an application program via the reception unit 5, and the application program is executed in the data execution environment 7. Also, when the application program reads data stored in the storage 21, it executes a system call provided by the OS and attaches the identification code to the system call.

[0056] As shown in FIG. 7, when there is a system call by the application program, the processing permission unit 4 hooks it and identifies the identification code related to the execution of the system call (step S11). Further, the processing permission unit 4 passes the identified identification code to the code management unit 2.

[0057] Next, the code management unit 2 identifies the authentication code corresponding to the passed identification code from the managed data table and returns the identified authentication code to the processing permission unit 4. Thereby, the processing permission unit 4 acquires the authentication code corresponding to the user who made the data access request (step S12).

[0058] Next, the processing permission unit 4 acquires the data name of the data that the application program is about to read from the system call hooked in step S11 (step S13). Then, the processing permission unit 4 passes the acquired data name and the authentication code to the determination unit 3.

[0059] Next, the determination unit 3 sends the authentication code to the authentication server 22 to identify the login name of the user who executed the application program (step S14). Specifically, the determination unit 3 sends the acquired authentication code to the authentication server 22. Thereby, since the authentication server 22 returns the login name set with the sent authentication code, the determination unit 3 acquires the login name.

[0060] Next, the determination unit 3 determines whether the user who executed the application program has the right to use the data to be executed (step S15). Specifically, the determination unit 3 refers to the data table in FIG. 5, compares the data name corresponding to the specified login name with the data name passed from the process permission unit 4, and if both match, determines that the user who executed the application program has the right to use the data.

[0061] If the user does not have the right to use the data (step S15: NO), the data processing device 20 executes processing such as notifying the content without the right to use, and this processing ends. On the other hand, if the user has the right to use the data (step S15: YES), the determination unit 3 refers to the data table in FIG. 5 and specifies the decryption key corresponding to the login name and data name. Then, the determination unit 3 sends the corresponding decryption key to the process permission unit 4. Thereby, the process permission unit 4 decrypts the data with the decryption key and permits the user to process the data (step S16).

[0062] As described above, the data processing device 20 of the present embodiment manages the user by setting an authentication code for the logged-in user. Then, the data processing device 20 identifies the user who requested access to the data from the authentication code, determines whether the user has the right to use the data, and permits the processing of the data. That is, even if a third party uses the data processing device 20, if the authentication code is not set, it is treated as having no right to use the data, and the processing of the data by the third party is not permitted. Thereby, it is possible to exclude the use of data by users who do not have the right to use.

[0063] Also, when there are a plurality of data processing devices 20 in the data processing system 50, if the user has the right to use the data, the user can process the data from any of the data processing devices 20.

[0064] Furthermore, each data processing device 20 does not permit the use of data by the applications executed within the device, but permits the use of data when the logged-in user has the right to use the data. That is, for a device having each part described in FIG. 2, for each piece of data to be used, it is possible to securely protect the data for each logged-in user without preparing an application for protecting the data.

[0065] In addition, since the user can handle the data for which he / she has the right to use just by logging in to the data processing device 20, the user can use the data without being aware of decrypting the protected (encrypted) data.

[0066] Also, even for data that has been accessed once by a user with the right to use, since it is decrypted every time the data is accessed, the data does not remain in plain text. Therefore, even if a third party without the right to use accesses it again, the third party cannot process the data, and sufficient data protection can be achieved.

[0067] Note that in this embodiment, the authentication code has been described as a character string including an electronic signature, but the authentication code may include information on a list of data that the user can use. In this case, the determination unit 3 can determine which data the identified user can use from the authentication code. In this case, the determination unit 3 does not need to manage the data table shown in FIG. 5.

[0068] In addition, the storage 21 for storing data may be provided in the data processing device 20 or may be provided in the authentication server 22.

[0069] [Program] The program in the embodiment may be any program that causes a computer to execute steps S1 to S6 shown in FIG. 6 and S11 to S16 shown in FIG. 7. By installing and executing this program on a computer, the data processing apparatus 20 and the data processing method in the present embodiment can be realized. In this case, the processor of the computer functions as an authentication code acquisition unit 1, a code management unit 2, a determination unit 3, a processing permission unit 4, a reception unit 5, and a data execution unit 6, and performs processing. Examples of the computer include a general-purpose PC, a smartphone, and a tablet terminal device.

[0070] Also, the program in the embodiment may be executed by a computer system constructed by a plurality of computers. In this case, for example, each computer may function as any one of an authentication code acquisition unit 1, a code management unit 2, a determination unit 3, a processing permission unit 4, a reception unit 5, and a data execution unit 6.

[0071] [Physical Configuration] Here, a computer that realizes the data processing apparatus 20 by executing the program in the embodiment will be described with reference to FIG. 8. FIG. 8 is a block diagram showing an example of a computer that realizes the data processing apparatus 20 in the embodiment.

[0072] As shown in FIG. 8, the computer 110 includes a CPU (Central Processing Unit) 111, a main memory 112, a storage device 113, an input interface 114, a display controller 115, a data reader / writer 116, and a communication interface 117. These units are connected to each other via a bus 121 so as to be able to communicate data with each other.

[0073] In addition to, or instead of, the CPU 111, the computer 110 may include a GPU (Graphics Processing Unit) or an FPGA (Field-Programmable Gate Array). In this embodiment, the GPU or FPGA can execute the programs in the embodiments.

[0074] The CPU 111 expands the programs in the embodiments, which are composed of a code group stored in the storage device 113, into the main memory 112, and executes each code in a predetermined order to perform various operations. The main memory 112 is typically a volatile storage device such as a DRAM (Dynamic Random Access Memory).

[0075] Also, the programs in the present embodiment are provided in a state stored in a computer-readable recording medium 120. Note that the programs in the present embodiment may be distributed on the Internet connected via the communication interface 117.

[0076] Specific examples of the storage device 113 include a hard disk drive and semiconductor storage devices such as flash memories. The input interface 114 mediates data transmission between the CPU 111 and input devices 118 such as a keyboard and a mouse. The display controller 115 is connected to the display device 119 and controls the display on the display device 119.

[0077] The data reader / writer 116 mediates data transmission between the CPU 111 and the recording medium 120, and reads the programs from the recording medium 120 and writes the processing results in the computer 110 to the recording medium 120. The communication interface 117 mediates data transmission between the CPU 111 and other computers.

[0078] In addition, specific examples of the recording medium 120 include general-purpose semiconductor memory devices such as CF (Compact Flash (registered trademark)) and SD (Secure Digital), magnetic recording media such as Flexible Disk, or optical recording media such as CD-ROM (Compact Disk Read Only Memory).

[0079] Note that the data processing device 20 in the embodiment can also be realized by using hardware corresponding to each part, rather than a computer installed with a program. Furthermore, a part of the data processing device 20 may be realized by a program and the remaining part may be realized by hardware.

[0080] Some or all of the above-described embodiments can be expressed by (Appendix 1) to (Appendix 15) described below, but are not limited to the following description.

[0081] (Appendix 1) An authentication code acquisition unit that acquires an authentication code associated with the user when the user who has logged in succeeds in login authentication; A code management unit that manages by associating an identification code for identifying the user who has succeeded in the login authentication with the authentication code; A determination unit that, when an access request to data is made, determines whether the user corresponding to the authentication code has the right to use the data based on the presence or absence of the authentication code corresponding to the identification code of the user who made the access request; A process permission unit that permits the user to process the data when the user is granted the right to use; A data processing device comprising the above.

[0082] (Appendix 2) The data processing device according to Appendix 1, wherein the data is encrypted, The determination unit further manages, for each piece of data, by associating, a decryption key for decrypting the data and a user who can use the data. When the use permission is granted to the user, the processing permission unit acquires the decryption key corresponding to the user and decrypts the data with the decryption key. Data processing apparatus.

[0083] (Appendix 3) A data processing apparatus according to Appendix 1 or Appendix 2, The authentication code acquired by the authentication code acquisition unit is generated every predetermined period. Data processing apparatus.

[0084] (Appendix 4) A data processing apparatus according to any one of Appendices 1 to 3, When the user succeeds in the login authentication, an identification code is set for the user. When the user with the set identification code requests execution of an application program, the data execution unit further provided executes the application program. When the execution of the application program is requested, the processing permission unit identifies the identification code of the requesting user, further acquires the authentication code corresponding to the identified identification code, and notifies the determination unit of the data to be the execution target of the application program and the acquired authentication code. The determination unit determines whether the user associated with the authentication code has the use permission for the data to be the execution target of the application program. Data processing apparatus.

[0085] (Appendix 5) A data processing apparatus according to Appendix 4, The determination unit Manages the correspondence relationship between the identification information of the data and the users who have the usage rights to the data, and based on the correspondence relationship, determines whether the user associated with the authentication code has the usage rights to the data to be executed by the application program. Data processing device.

[0086] (Appendix 6) When the user who has logged in has successfully passed the login authentication, a step of obtaining the authentication code associated with the user. A step of managing the identification code for identifying the user who has successfully passed the login authentication and the authentication code in association with each other. When a data access request is made, based on the presence or absence of the authentication code corresponding to the identification code of the user who made the access request, a step of determining whether the user corresponding to the authentication code has the usage rights to the data. When the usage rights are granted to the user, a step of permitting the user to process the data. A data processing method comprising the above.

[0087] (Appendix 7) The data processing method according to Appendix 6, wherein The data is encrypted, In the step of determining whether the user has the usage rights to the data, further, for each data, manages the decryption key for decrypting the data and the user who can use the data in association with each other. In the step of permitting the processing of the data, when the usage rights are granted to the user, obtains the decryption key corresponding to the user and decrypts the data with the decryption key. Data processing method.

[0088] (Appendix 8) The data processing method according to Appendix 6 or Appendix 7, wherein The authentication code obtained in the step of obtaining the authentication code is generated every predetermined period. Data processing method.

[0089] (Appendix 9) A data processing method according to any one of Appendices 6 to 8, when the user succeeds in the login authentication, setting the identification code for the user, and when the user with the set identification code requests the execution of an application program, further comprising the step of executing the application program, In the step of permitting the processing of the data, when the execution of the application program is requested, identifying the identification code of the requesting user, further obtaining an authentication code corresponding to the identified identification code, and notifying the data to be the execution target of the application program and the obtained authentication code, In the step of determining whether the user has the right to use the data, determining whether the user associated with the authentication code has the right to use the data to be the execution target of the application program, Data processing method.

[0090] (Appendix 10) A data processing method according to Appendix 9, In the step of determining whether the user has the right to use the data, managing the correspondence relationship between the identification information of the data and the user having the right to use the data, and based on the correspondence relationship, determining whether the user associated with the authentication code has the right to use the data to be the execution target of the application program, Data processing method.

[0091] (Appendix 11) For a computer, when the user who has logged in succeeds in the login authentication, obtaining the authentication code associated with the user, associating and managing the identification code for identifying the user who has succeeded in the login authentication and the authentication code, When a data access request is made, based on the presence or absence of an authentication code corresponding to the identification code of the user who made the access request, determining whether the user corresponding to the authentication code has the right to use the data; When the user is granted the right to use, permitting the user to process the data; Causing to execute do the Logra program

[0092] (Appendix 12) As described in Appendix 11 program wherein the data is encrypted, In the step of determining whether the user has the right to use the data, further, for each data, managing by associating a decryption key for decrypting the data with the user who can use the data; In the step of permitting the processing of the data, when the user is granted the right to use, obtaining the decryption key corresponding to the user and decrypting the data with the decryption key; program .

[0093] (Appendix 13) As described in Appendix 11 or Appendix 12 program wherein the authentication code obtained in the step of obtaining the authentication code is generated every predetermined period; program .

[0094] (Appendix 14) As described in any one of Appendix 11 to Appendix 13 program wherein before In the computer, When the user succeeds in the login authentication, setting the identification code for the user, and when the user with the set identification code requests the execution of an application program, executing the application program; Causing to execute do, In the step of permitting the processing of the data, when the execution of the application program is requested, the identification code of the requesting user is specified, and further, an authentication code corresponding to the specified identification code is obtained, and the data to be the execution target of the application program and the obtained authentication code are notified. In the step of determining whether the user has the right to use the data, it is determined whether the user associated with the authentication code has the right to use the data to be the execution target of the application program. program 。

[0095] (Appendix 15) As described in Appendix 14 program and In the step of determining whether the user has the right to use the data, the correspondence relationship between the identification information of the data and the user having the right to use the data is managed, and based on the correspondence relationship, it is determined whether the user associated with the authentication code has the right to use the data to be the execution target of the application program. program 。

[0096] The present invention has been described with reference to the embodiments above, but the present invention is not limited to the above embodiments. Various changes that can be understood by those skilled in the art can be made to the configuration and details of the present invention within the scope of the present invention.

[0097] This application claims the priority based on Japanese Patent Application No. 2021-186328 filed on November 16, 2021, and incorporates all of its disclosures herein.

Industrial Applicability

[0098] The data processing apparatus of the present disclosure allows only the user having the right to use the data to perform data processing. The data processing apparatus of the present disclosure can be used in a system for safely handling data for each user.

Explanation of Signs

[0099] 1: Authentication code acquisition unit 2: Code management unit 3: Judgment unit 4: Processing permission unit 5: Reception unit 6: Data execution unit 20: Data processing device 20A: Data execution environment 21: Storage 22: Authentication server 50: Data processing system 110: Computer 111: CPU 112: Main memory 113: Storage device 114: Input interface 115: Display controller 116: Writer 117: Communication interface 118: Input device 119: Display device 120: Recording medium 121: Bus

Claims

1. An authentication code acquisition unit that acquires an authentication code associated with the user when the user who has logged in has successfully passed the login authentication; A code management unit that manages the identification code for identifying the user who has successfully passed the login authentication in association with the authentication code; A determination unit that determines whether the user corresponding to the authentication code has the right to use the data based on the presence or absence of the authentication code corresponding to the identification code of the user who made the access request when requesting access to the data; A processing permission unit that permits the user to process the data when the user is granted the right to use the data; A data execution unit that sets the identification code for the user when the user has successfully passed the login authentication, and executes the application program when the user with the set identification code requests execution of the application program; Comprising: When the execution of the application program is requested, the processing permission unit identifies the identification code of the requesting user, further acquires the authentication code corresponding to the identified identification code, and notifies the determination unit of the data to be the execution target of the application program and the acquired authentication code; The determination unit determines whether the user associated with the authentication code has the right to use the data to be the execution target of the application program; A data processing device.

2. The data processing device according to claim 1, wherein The data is encrypted, The determination unit further manages, for each data, in association with a decryption key for decrypting the data and a user who can use the data, When the user is granted the right to use the data, the processing permission unit acquires the decryption key corresponding to the user and decrypts the data with the decryption key; A data processing device.

3. The data processing device according to claim 1, wherein The authentication code acquired by the authentication code acquisition unit is generated every predetermined period; A data processing device.

4. The data processing device according to claim 1, wherein The determination unit Manages the correspondence relationship between the identification information of the data and the users who have the right to use the data, and based on the correspondence relationship, determines whether the user associated with the authentication code has the right to use the data to be executed by the application program. Data processing device.

5. A method executed by a computer, When the user who has logged in has successfully passed the login authentication, obtain the authentication code associated with the user. Manage by associating the identification code for identifying the user who has successfully passed the login authentication with the authentication code. When a data access request is made, based on the presence or absence of the authentication code corresponding to the identification code of the user who made the access request, determine whether the user corresponding to the authentication code has the right to use the data. When the user is granted the right to use the data, permit the user to process the data. When the user has successfully passed the login authentication, set the identification code for the user, and when the user with the set identification code requests the execution of an application program, execute the application program. In the permission for data processing, when the execution of the application program is requested, identify the identification code of the requesting user, further obtain the authentication code corresponding to the identified identification code, and notify the data to be the execution target of the application program and the obtained authentication code. In the determination of whether the user has the right to use the data, determine whether the user associated with the authentication code has the right to use the data to be executed by the application program. Data processing method.

6. The data processing method according to claim 5, The data is encrypted. In the determination of whether the user has the right to use the data, further manage by associating, for each data, the decryption key for decrypting the data with the users who can use the data. In the permission for data processing, when the user is granted the right to use the data, obtain the decryption key corresponding to the user, and decrypt the data with the decryption key. Data processing method.

7. The data processing method according to claim 5, The authentication code obtained in the step of obtaining the authentication code is generated every predetermined period. Data processing method.

8. The data processing method according to claim 5, wherein in the determination of whether or not the user has the right to use the data,[[]] the correspondence between the identification information of the data and the user having the right to use the data is managed, and based on the correspondence, it is determined whether or not the user associated with the authentication code has the right to use the data that is the execution target of the application program.[[]] Data processing method.[[]]

9. Causing a computer to acquire an authentication code associated with the user when the user who has logged in has successfully passed the login authentication,[[]] associate and manage an identification code for identifying the user who has successfully passed the login authentication with the authentication code,[[]] when a data access request is made, based on the presence or absence of the authentication code corresponding to the identification code of the user who made the access request, determine whether or not the user corresponding to the authentication code has the right to use the data,[[]] when the user is granted the right to use, permit the user to process the data,[[]] when the user has successfully passed the login authentication, cause the user to set the identification code, and when the user with the set identification code requests execution of an application program, execute the application program,[[]] in the permission of data processing, when the execution of the application program is requested, identify the identification code of the requesting user, further acquire the authentication code corresponding to the identified identification code, and notify the data that is the execution target of the application program and the acquired authentication code,[[]] in the determination of whether or not the user has the right to use the data, determine whether or not the user associated with the authentication code has the right to use the data that is the execution target of the application program,[[]] Program.[[]]

10. The program according to claim 9, wherein the data is encrypted,[[]] in the determination of whether or not the user has the right to use the data, further manage, for each data, the decryption key for decrypting the data in association with the user who can use the data,[[]] in the permission of data processing, when the user is granted the right to use, acquire the decryption key corresponding to the user, and decrypt the data with the decryption key,[[]] Program.[[]]

11. The program according to claim 9, wherein The authentication code obtained in the step of obtaining the authentication code is generated every predetermined period. Program.

12. A computer program according to claim 9, In the determination of whether or not to have the right to use the data, managing the correspondence relationship between the identification information of the data and the user having the right to use the data, and based on the correspondence relationship, determining whether or not the user associated with the authentication code has the right to use the data to be the execution target of the application program. Program.

Citation Information

Patent Citations

  • Data protection program and data protection method

    JP2004046307A

  • Information providing apparatus

    JP2011203900A

  • Content data management apparatus and program thereof

    JP2012118778A

  • Key management system, key management method, user terminal, key generation management device, and program

    JP2014149806A