System, information processing apparatus, mediation method, and program
The system addresses the challenge of selecting appropriate output screen quality in remote access by using an index value to determine optimal screen quality settings, enhancing operability and reducing connection risks.
Patent Information
- Application Number
- JP2021112511
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-07-07
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-07-07
AI Technical Summary
Existing systems for remote access lack the ability to selectively choose an appropriate output screen quality, leading to potential operability issues and connection disruptions due to excessive processing demands or inadequate image quality.
A system that mediates remote access by storing an index value of screen quality and using a determination unit to set a use value based on this index, allowing for controlled communication relay settings to optimize screen quality during remote access.
Enables the selection of appropriate output screen quality in remote access, improving operability by matching screen settings with the processing capacity of the access source terminal and reducing the risk of connection disruptions.
Smart Images

Figure 0007697296000001 
Figure 0007697296000002 
Figure 0007697296000003
Abstract
Description
Technical Field
[0001] The present invention relates to a system, an information processing apparatus, an intermediation method, and a program.
Background Art
[0002] A method for accessing a service provided by an access destination terminal in an intranet inside a firewall, for example, a remote desktop service, from an access source terminal in a remote environment is known. As one method, there is a method of encrypting communication from the intranet to the access source terminal by a VPN (Virtual Private Network) or the like and connecting them. As another method, there is a remote access service that connects via encrypted communication with a cloud server.
[0003] Also, in relation to screen virtualization, Japanese Patent No. 5 459 693 (Patent Document 1) discloses a system that provides a screen virtualization service to various terminal devices. Patent Document 1 discloses that if a system profile is transmitted from a user terminal device to a cloud device, the cloud device generates a candidate screen virtualization technology list that can be processed by the terminal device from the system profile received from the terminal device, checks the device load amount and processability for each technology, and determines an optimal screen virtualization technology candidate based on the system profile of the terminal device and the available resources of the device through a screen virtualization technology determination unit, in terms of whether web services are available, whether RDP (Remote Desktop Protocol) / VNC (Virtual Network Computing) processing is available, and whether video streaming processing is available. However, in the prior art of Patent Document 1 described above, the server has a plurality of virtualization technologies, and a process of creating and determining a technology list is required, and it is necessary to check and judge the device load amount for each technology of the server.
Summary of the Invention
Problems to be Solved by the Invention
[0004] The present disclosure has been made in view of the above points, and an object thereof is to provide a system capable of selecting an appropriate output screen quality in remote access.
Means for Solving the Problems
[0005] In the present disclosure, in order to solve the above problems, a system having the following features is provided. The system mediates the establishment of access from an access source terminal to a service provided by an access destination terminal, relaying communication means of the same network as the access destination terminal. The system includes a storage unit that stores an index value of the quality of a screen related to the service, and a determination unit that determines a use value of the quality of the screen within a range based on the index value, based on the relationship between the stored index value of the quality of the screen and the specified value of the quality of the screen from the access source terminal. The system further includes a control unit that controls the communication relay means to set the quality of the screen based on the use value determined.
Advantages of the Invention
[0006] With the above configuration, it becomes possible to select an appropriate output screen quality in remote access.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Figure 18
BEST MODE FOR CARRYING OUT THE INVENTION
[0008] Hereinafter, embodiments of the present invention will be described. However, the embodiments of the present invention are not limited to the embodiments described below. In the embodiments described below, as an example of the system, a remote access support system 140 will be used for the description.
[0009] FIG. 1 is a diagram showing the overall configuration of a network environment 100 including a remote access support system 140 according to the present embodiment. As shown in FIG. 1, the network environment 100 includes the Internet 102, a first network 104 connected to the Internet 102, a second network 106, and a third network 108. The remote access support system 140 is constructed in such a network environment 100.
[0010] The first network 104 is a network in which a system for mediating the establishment of remote access to a predetermined service via the Internet 102 is arranged. The remote access support system 140 is deployed on the first network 104. More specifically, the remote access support system 140 includes an application system 150, a platform system 170, and a relay system 190. In a specific embodiment, the first network 104 is a platform-side network that provides a function of mediating the establishment of remote access and relaying remote access communication as a cloud service.
[0011] The second network 106 is a network to which a terminal that provides a predetermined service to be remotely accessed belongs. An access terminal 110 and a communication relay device 120 are arranged on the second network 106 shown in FIG. 1. The second network 106 is also referred to as a field-side network 106.
[0012] The third network 108 is a network to which a terminal (access source terminal) of a user who desires to remotely access a predetermined service provided by the target access terminal 110 belongs. An access source terminal 130 is arranged on the third network 108. The access source terminal 130 has a display device, and displays a screen of a predetermined service provided by the target access terminal 110 in a predetermined display area within the display device. The third network 108 is also referred to as a remote network 108.
[0013] The remote access support system 140 is a system that provides a remote access mediation service for mediating the establishment of access when an access source terminal 130 on the remote network 108 accesses a predetermined service provided by an access terminal 110 on the on-site network 106 via the Internet 102. Here, for the predetermined service provided by the access terminal 110, access will be made via a communication relay device 120 installed in the same on-site network 106 as the access terminal 110.
[0014] In the described embodiment, the predetermined service is more specifically a remote desktop service. In the remote desktop service, the desktop screen of the access terminal 110 is displayed within the screen of the display device of the access source terminal 130.
[0015] The application system 150 provides a user interface (UI) that enables mutual communication with the access source terminal 130. With the provided UI, the access source terminal 130 can utilize the remote desktop service. The platform system 170 provides basic functions such as user and device authentication, two-way communication with the communication relay device 120, contract management, and data lake. The relay system 190 mediates the connection between the access source terminal 130 and the communication relay device 120, and relays input / output data (screen information, voice information, operation information) of a predetermined service provided by the access terminal 110.
[0016] The access source terminal 130 is a general desktop or laptop personal computer on which a browser (e.g., a web browser) operates, a smartphone, a tablet terminal, a kiosk terminal, etc., and the type of the terminal is not limited. The access source terminal 130 may be provided with a dedicated application for using the remote access function, or may be provided with a general-purpose application such as the above-described browser. The access source terminal 130 may be, in addition to general-purpose terminals such as personal computers and smartphones, a warning light device, a device such as an electronic paper, an information system such as an electronic medical record system and a process management system, etc., and is not particularly limited.
[0017] The access destination terminal 110 is an information processing device such as a personal computer, a server, and a workstation that provides a remote desktop function within the on-site network 106. The protocol of the remote desktop is not particularly limited, and examples include RDP (Remote Desktop Protocol) and VNC (Virtual Network Computing).
[0018] The communication relay device 120 connects to the relay system 190 in response to an instruction from the application system 150, relays data communication with the access source terminal 130, and performs protocol conversion at that time. In the embodiment shown in FIG. 1, the communication relay device 120 is described as being separately provided as a device that exclusively implements the relay function, but is not limited thereto. In other embodiments, software implementing the function of the communication relay device 120 may be installed on the access destination terminal 110 or other terminals within the on-site network 106.
[0019] Before explaining the remote access service in detail, the hardware configuration of the related devices will be described below. Figure 2 is a hardware configuration diagram of a computer system that can be used as one or more servers constituting the access terminal 110, the access source terminal 130, the communication relay device 120, and the remote access support system 140 according to the present embodiment. Here, the hardware configuration of server 9 will be described.
[0020] As shown in Figure 2, server 9 is constructed by a computer and, as shown in Figure 2, includes a CPU 901, a ROM (Read Only Memory) 902, a RAM (Random Access Memory) 903, an HD 904, an HDD (Hard Disk Drive) controller 905, a display 906, an external device connection I / F (Interface) 908, a network I / F 909, a data bus 910, a keyboard 911, a pointing device 912, a DVD-RW (Digital Versatile Disk Rewritable) drive 914, and a media I / F 916.
[0021] Among these, the CPU 901 controls the operation of the entire server 9. The ROM 902 stores programs used for driving the CPU 901 such as IPL. The RAM 903 is used as a work area for the CPU 901. The HD 904 stores various data such as programs. The HDD controller 905 controls the reading or writing of various data to / from the HD 904 according to the control of the CPU 901. The display 906 displays various information such as a cursor, menu, window, characters, or images. The external device connection I / F 908 is an interface for connecting various external devices. The external devices in this case are, for example, a USB (Universal Serial Bus) memory, a printer, etc. The network I / F 909 is an interface for performing data communication using a communication network. The bus line 910 is an address bus, a data bus, etc. for electrically connecting each component such as the CPU 901 shown in FIG. 2.
[0022] Also, the keyboard 911 is a type of input means having a plurality of keys for inputting characters, numerical values, various instructions, etc. The pointing device 912 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The DVD-RW drive 914 controls the reading or writing of various data to / from the DVD-RW 913 as an example of a removable recording medium. Note that it is not limited to DVD-RW, and it may be DVD-R or the like. The media I / F 916 controls the reading or writing (storage) of data to / from the recording medium 915 such as a flash memory.
[0023] Hereinafter, with reference to FIG. 3, the remote access support system 140 according to the present embodiment will be described in more detail. FIG. 3 is a block diagram showing the functional configuration of the remote access support system 140 according to the present embodiment. FIG. 3 further shows the functional blocks 210, 220, 230 of the access destination terminal 110, the communication relay device 120, and the access source terminal 130.
[0024] The access destination terminal 110 provides a remote desktop service 212 on the on-site network 106. The access source terminal 130 is connected to the Internet 102 from the remote network 108, but is not directly connected to the on-site network 106. Therefore, the access source terminal 130 cannot directly access the remote desktop service 212 provided by the access destination terminal 110 on the on-site network 106.
[0025] Conventionally, in such a case, in order for the access source terminal 130 to access the on-site network 106, the network is connected from the access source terminal 130 or the remote network 108 to the on-site network 106 using tunneling technologies such as VPN.
[0026] As a method of connecting to the on-site network 106 from the remote network 108 via VPN, for example, IPsec (RFC4301 Security Architecture for the Internet Protocol, RFC4306 Internet Key Exchange (IKEv2) protocol) is known. When using this method, it is necessary to change the network settings in order to communicate correctly with IPsec. For example, it is necessary to correctly perform changes such as the routing settings of the router and the access control list of the firewall.
[0027] In the case of a VPN connection, once connected via VPN, the accessible resources (networks, services, etc.) can be controlled according to the access control of the firewall. However, this access control is basically possible by access control based on the IP address or the port number of the transport layer (for example, 3389 / tcp, etc.). In order to realize access control for each logged-in user, it is necessary to associate the logged-in user with an identifier such as an IP address, which requires complicated operations such as changing the existing network configuration.
[0028] As another method, a remote access service that connects via encrypted communication with a cloud server can also be considered. In the remote access service, the communication between the service on the cloud and the access destination terminal within the intranet is carried out using compressed data through protocol conversion and the like. Also, in the remote desktop, the desktop screen of the access destination terminal with a specified resolution is transmitted as image information and displayed on the display device of the access source terminal. Generally, the visibility of the output image is worse when data compression is performed than when it is not. Also, the visibility is best when the image is displayed in a size that is Dot-by-Dot with respect to the resolution setting of the access destination terminal. The visibility improves as the compression rate of the image data is lowered, but the communication volume (data amount) increases. The communication volume (data amount) and the load amount when relaying the communication of the communication relay device increase as the compression rate of the image data is lowered, and as the specified resolution is increased, that is, as the quality of the screen is improved. If the processing becomes excessive, there is a risk that the operability of the remote desktop will deteriorate or the connection will be disconnected due to a timeout. A method of restricting high-load settings can also be adopted, but usually, no means is provided for the service user to know an appropriate load amount.
[0029] Therefore, in the embodiment to be described, a mechanism is provided that enables the remote desktop service 212 on the site-side network 106 to be accessed with appropriate screen quality and secure communication using a browser 232 with a simple setting from the access source terminal 130 on the remote-side network 108.
[0030] The access source terminal 130 activates the browser 232 and connects to the remote access support system 140 (application system 150, platform system 170, and relay system 190) via the Internet from the browser 232. The access source terminal 130 establishes access via the communication relay device 120 for the remote desktop service 212 provided by the access destination terminal 110 through communication with the remote access support system 140. The screen of the browser 232 is displayed on the display screen 234 provided by the display device. After the access is established, the desktop screen of the remote desktop service 212 is displayed in a predetermined area in the display screen 234.
[0031] Note that, as a service provided by the access destination terminal 110, in the described embodiment, the remote desktop service 212 is taken as an example for explanation, but it is not limited thereto. The service provided by the access destination terminal 110 is not limited to other services as long as they are services capable of IP communication, and may also be services that are not capable of IP communication. For example, in the case of a service for controlling a device that can communicate with RS-S32C, it is sufficient if communication can be made with the device from the communication relay device 120 using the RS-232C protocol.
[0032] The application system 150 provides the access source terminal 130 with remote access and various management functions via a UI corresponding to authentication, and provides information of the relay system 190 in response to a remote access request. The application system 150 also manages information such as various policies of users, devices, and the communication relay device 120, issues instructions such as setting changes to the communication relay device 120 and connection to the relay system 190, and executes processing related to the resolution setting described later.
[0033] As shown in FIG. 3, the functional block 250 of the application system 150 includes a resolution selection UI providing unit 252, a resolution determination unit 254, a resolution setting storage unit 256, and an API (Application Programming Interface) communication unit 258. The API communication unit 258 performs processes related to the API.
[0034] The resolution selection UI providing unit 252 provides a UI for allowing selection of the screen resolution setting during use of the remote desktop service through operations as the screen quality. Here, the screen quality to be selected may include the screen resolution and the data compression rate of the screen information, but preferably is the screen resolution, and the following continues the description assuming that the screen quality to be selected is the screen resolution. Also, although the UI is not particularly limited, the following continues the description assuming it is a WebUI.
[0035] In the embodiment to be described, the selection of the screen resolution can be performed by selecting one from a plurality of candidate values (fixed values) and directly specifying a variable value. When selecting one from a plurality of candidate values (fixed values), the resolution selection UI providing unit 252 provides the plurality of candidate values stored in the resolution setting storage unit 256 as options and receives selection information by the user from among them. In this case, the resolution is determined in the remote access support system 140, and the value selected from the options becomes the specified value from the access source terminal 130. When directly specifying a variable value, code (for example, JavaScript (registered trademark)) configured to transmit the resolution information of the display screen of the access source terminal 130 or the display area of the browser is provided, and the transmitted resolution information is received. In this case, the access source terminal 130 determines the resolution, and the variable value indicated by the resolution information here becomes the specified value from the access source terminal 130.
[0036] The resolution setting storage unit 256 stores the index value of the screen resolution of the remote desktop service 212. In a specific embodiment, the index value defines the upper limit value of the appropriate resolution range for the communication relay device 120. The resolution setting storage unit 256 constitutes the storage unit in this embodiment that stores the index value of the screen resolution as the index value of the quality of the screen related to a predetermined service.
[0037] Based on the relationship between the index value of the screen resolution stored in the resolution setting storage unit 256 and the specified value of the screen resolution from the access source terminal 130, the resolution determination unit 254 determines the usage value of the screen resolution within the range based on the index value. In this embodiment, the resolution determination unit 254 constitutes the determination unit that determines the usage value of the screen resolution as the usage value of the quality of the screen related to a predetermined service.
[0038] When providing a plurality of candidate values as options, it may be configured to provide a plurality of candidate values as options regardless of the index value, and then determine whether the selected value is within the range based on the index value, or to provide only the options that have been determined in advance to be within the range based on the index value and receive the value selected from among them. In either case, it is considered to include determining the usage value within the range based on the index value based on the relationship between the stored index value and the specified value.
[0039] Note that, as described above, the application system 150 is composed of a plurality of components, but it may be realized by a single application on a single application server, or by a combination of a plurality of applications. Also, the application system 150 may be composed of a single or a plurality of applications by a combination of a plurality of application servers and network devices.
[0040] Furthermore, in the described embodiments, the application system 150 assumes access from the browser 232. However, in addition to access from the browser 232, operations from a Web API may also be possible, and it may also support access from applications other than the browser. As for access, in the described embodiments, web access (HTTPS / HTTP) is taken as an example for explanation, but it may also be MQTT (Message Queueing Telemetry Transport) or RPC (Remote Procedure Call).
[0041] The platform system 170 provides common services for efficiently providing services such as user and device authentication, two-way communication with the communication relay device, contract management, and data lake.
[0042] As shown in FIG. 3, the functional block 270 of the platform system 170 includes an authentication unit 272, a portal processing unit 274, and a control unit 276. The authentication unit 272 provides user authentication and device authentication. This authentication function realizes user name, password authentication, certificate-based authentication, multi-factor authentication, etc. The portal processing unit 274 provides a common portal site.
[0043] The control unit 276 is constantly connected to the communication relay device 120 and transmits instructions and settings from the application system 150 to the communication relay device 120. In particular, the control unit 276 controls the communication relay device 120 to set the resolution of the remote desktop screen based on the use value of the resolution of the above screen determined by the resolution determination unit 254. The control unit 276 constitutes the control unit in the present embodiment. The instructed communication relay device 120 performs connection resolution setting processing at the start of the service for the remote desktop service 212 provided by the access terminal 110. This constant connection can be realized by MQTT over Websocket over HTTPS as a configuration for establishing a connection from the communication relay device 120 to the control unit 276, and thus it is possible to realize it without changing the settings of the firewall of the on-site network 106.
[0044] In the embodiment to be described, it is described that the platform system 170 manages user information and the like. However, the role sharing between the platform system 170 and the application system 150 is only an example, and the application system 150 may manage user information. Also, in the embodiment to be described, it is described that the application system 150 includes a resolution setting storage unit 256 and a resolution determination unit 254. However, in other embodiments, the platform system 170 may include one or both of the resolution setting storage unit 256 and the resolution determination unit 254.
[0045] The relay system 190 relays the input / output data (screen information, audio information, operation information) of the service provided by the access terminal 110. As shown in FIG. 3, the functional block 290 of the relay system 190 includes a communication relay unit 292.
[0046] The communication relay unit 292 relays the connection between the access source terminal 130 and the communication relay device 120. More specifically, the communication relay unit 292 manages the session of WSS (WebSocket over HTTPS) and is responsible for relaying the data communication of remote access between the browser 232 and the communication relay device 120. Note that the communication relay unit 292 does not need to interpret the content of the WSS communication. The communication relay unit 292 correctly connects the communication between the browser 232 and the relay system 190 and the communication between the communication relay device 120 and the relay system 190, and transfers the data between the browser 232 and the communication relay device 120.
[0047] The communication relay device 120 connects to the relay system 190 in response to an instruction from the application system 150. The communication relay device 120 relays and performs protocol conversion, or at least one of these, for the operation on the service provided by the access destination terminal 110 accessed by the access source terminal 130 and the response from the service to the access source terminal 130. In addition, the communication relay device 120 provides a WebUI for setting its own relay function, device registration, execution of instructions from the application system 150 such as remote desktop access with the specified resolution setting, and its own network setting.
[0048] As shown in FIG. 3, the functional block 220 of the communication relay device 120 includes a protocol conversion unit 222 and a connection resolution setting holding unit 224. The connection resolution setting holding unit 224 holds the setting of the connection resolution when the connection resolution setting process is performed at the start of the service with the access destination terminal 110.
[0049] The protocol conversion unit 222 has a function of establishing a connection with the relay system 190 upon receiving an instruction from the application system 150, and a function of converting a protocol that enables correct control between the access destination service and the access source terminal 130. The protocol conversion unit 222 performs connection resolution setting processing on the access destination service at the start of the service. At that time, it receives information indicating the used value of the screen resolution from the remote access support system 140 and reflects it in the setting, and generates output screen information corresponding to the set resolution through communication with the access destination service. The above protocol conversion processes image information that is the difference within the image of the specified resolution.
[0050] In the embodiment to be described, the communication relay device 120 is configured to be connected to the control unit 276 of the platform system 170 and receive an instruction from the application system 150. However, it may be configured to receive an instruction through direct communication with the application system 150 without going through the control unit 276.
[0051] After the access between the access destination service and the access source terminal 130 is established through the mediation of the remote access support system 140, on the access source terminal 130, the display screen 234 displays the display area at the screen resolution of the screen information received from the communication relay device 120 based on the screen information. The browser 232 transmits operation information indicating the operation input to the communication relay device 120 based on the operation input related to the display area.
[0052] In the above description, the access destination terminal 110, the communication relay device 120, and the access source terminal 130 have been described as components not included in the system (remote access support system 140) according to this embodiment. However, it is not limited to this. The system according to this embodiment may include all or part of the access destination terminal 110, the communication relay device 120, and the access source terminal 130.
[0053] FIG. 4 is a diagram showing the redundant configuration 300 of the application system 150 in the present embodiment. As shown in FIG. 4, the application system 150 includes a load balancer 302, a web application 310, and a database 316.
[0054] In the application system 150, at the HTTP termination part 304 in the load balancer 302, an HTTPS connection from the access source terminal 130 is received. As shown in FIG. 4, the web application 310 starts a plurality of instances. The request analysis unit 306 decomposes the HTTP header, and the allocation determination unit 308 allocates the processing to the web application 310 based on the URL path and other information. In the web application 310, the WebUI unit 312 calls the WebAPI unit 314 as an internal process and accesses the database 316 via the WebAPI unit 314, but the WebUI unit 312 may directly access the database 316. As shown in FIG. 4, the web application 310 can have a redundant configuration with a plurality of instances, but it is not particularly limited and may be one instance. Also, FIG. 4 illustrates a realization method in the provision of computer resources by IaaS (Infrastructure as a Service), but it may also be realized by FaaS (Function as a Service).
[0055] Also, as shown in FIG. 4, the database 316 of the application system 150 includes a type list 318, a service list 320, a service group list 322, an action list 324, and a policy list 326.
[0056] FIG. 5 is a diagram showing the redundant configuration 330 of the relay system 190 in the present embodiment. As shown in FIG. 5, the relay system 190 includes a load balancer 332 and a web application 340.
[0057] The relay system 190 receives HTTPS connections from the access source terminal 130 and the communication relay device 120 at the HTTP termination part 334 in the load distribution device 332. As shown in FIG. 5, the web application 340 has multiple instances running. The request analysis unit 336 decomposes the HTTP header, and the allocation determination unit 338 allocates processing to the web application 340 based on the URL path and other information. As shown in FIG. 5, the web application 340 can have a redundant configuration with multiple instances, but it is not particularly limited and may be a single instance. The relay system 190 connects from the access source terminal 130 and the communication relay device 120 via Web Socket over HTTPS and tunnels both ends.
[0058] FIG. 6 is a diagram showing the configuration 350 of the platform system 170 in the present embodiment. As shown in FIG. 6, the platform system 170 includes a load distribution device 352, an authentication unit 360, a portal processing unit 362, a control unit 364, and a database 316. The authentication unit 360, the portal processing unit 362, and the control unit 364 correspond to the authentication unit 272, the portal processing unit 274, and the control unit 276 shown in FIG. 3.
[0059] The platform system 170 receives HTTPS connections from the application system 150 and the like at the HTTP termination part 354 in the load distribution device 352. The request analysis unit 356 decomposes the HTTP header, and the allocation determination unit 358 allocates processing to any one of the authentication unit 360, the portal processing unit 362, and the control unit 364 based on the URL path and other information. Also, as shown in FIG. 6, the database 366 of the platform system 170 includes a tenant list 368, a user list 370, and a user group list 372.
[0060] Hereinafter, various data structures managed in the databases 316 and 366 will be described with reference to FIGS. 7 and 8.
[0061] FIG. 7(A) illustrates the data structure of the type list 318 held in the database 316 of the application system 150 shown in FIG. 4. As shown in FIG. 7(A), the type list 318 has fields for tenant ID, type ID, type name, and conversion program, and associates a tenant with a type and a conversion program. A tenant corresponds to any organization or individual such as a government agency, an educational institution, a company, or a group of individuals. In the type list 318, a common conversion program and a conversion program for each tenant can be registered. The conversion program includes predetermined conversion processing contents. Here, the common type (common) is such that the system provider can register general-purpose modules in advance. For the type for each tenant, it is assumed that an administrator or the system provider registers in advance a conversion program required uniquely for the tenant, but the original conversion program may be created. Here, the conversion program only needs to be executable by the communication relay device 120, and any implementation language may be used as long as it is executable. In the example shown in FIG. 7(A), for the remote desktop (type name: RDP) service, a predetermined conversion program (app / common / rdp) is registered as a common type.
[0062] FIG. 7(B) illustrates the data structure of the service list 320 held in the database 316 of the application system 150 shown in FIG. 4. The service list 320 has fields for tenant ID, service ID, service name, type, and destination, and associates a tenant, a service, a type, and a destination. In the example shown in FIG. 7(B), for the remote desktop service, for a predetermined tenant (tenant ID = t_20171384), the service name "Information Systems Department Shared PC" and predetermined destination information (info-pc.info.example.co.jp:3389 / TCP) are registered. Note that the destination may be an FQDN (Fully Qualified Domain Name) or an IP address. Also, in the case of a type that cannot perform IP communication, an RS-232C COM port or the like may be used.
[0063] Figure 7(C) illustrates the data structure of the action list 324 held in the database 316 of the application system 150 shown in Figure 4. The action list 324 has fields for tenant ID, action ID, action name, and actions, and associates a tenant, an action, and the storage destination of the action. Actions include common actions and those defined for each tenant. Among the actions, it is possible to define whether to permit, deny, perform multi-factor authentication, etc.
[0064] Figure 7(D) illustrates the data structure of the policy list 326 held in the database 316 of the application system 150 shown in Figure 4. The policy list 326 has fields for tenant ID, policy ID, policy name, priority, user, service, and action, and associates a tenant, a policy, a priority, a user, a service, and an action. As defined in the policy list 326 shown in Figure 7(D), when the accessed user or user group matches the service or service group, the corresponding action is executed. Also, these policies may match a combination of multiple accessed users or user groups and services or service groups, and therefore, priorities are set, and the higher-priority policy is executed first.
[0065] Here, the policy is set to execute actions according to the set priority order. In the case of more detailed settings, it is also possible to adopt methods such as the longest match for executing actions, or to continue to check whether the next policy matches after the action is executed, and then execute the action of the next matching policy.
[0066] FIG. 8(A) illustrates the data structure of the tenant list 368 held by the database 366 of the platform system 170 shown in FIG. 6. As shown in FIG. 8(A), the tenant list 368 has fields for tenant ID and tenant name, associating the tenant ID with the tenant name. Here there are two tenants, but of course there may be more than two. Also, here it is a non-nested list of tenants, but it may have a hierarchical structure with nesting.
[0067] FIG. 8(B) illustrates the data structure of the user list 370 held by the database 366 of the platform system 170 shown in FIG. 6. As shown in FIG. 8(B), the user list 370 has fields for tenant ID, user ID, user name, display name, and password, associating the tenant, user, and password. Note that in the example shown in FIG. 8(B), the password is hashed. Here it is managed by password, but authentication by certificate is also possible.
[0068] FIG. 8(C) illustrates the data structure of the communication relay device list 380 held by the database 366 of the platform system 170 shown in FIG. 6. As shown in FIG. 8(C), the communication relay device list 380 has fields for tenant ID, device ID, UUID (Universally Unique Identifier), and device name, associating the tenant with the device and settings. Here, the UUID is defined in RFC4122 and is an ID used to uniquely identify the device.
[0069] FIG. 8(D) illustrates the data structure of the setting value list 390 held by the resolution setting storage unit 256 of the application system 150 shown in FIG. 6. As shown in FIG. 8(D), the setting value list 390 has an item and a setting value field. The resolution setting storage unit 256 stores an index value (upper limit value) as an upper limit value used in the determination process of the specified value of the resolution received by the application system 150, and a list of candidate values (candidate values 1 to 5) of the resolution provided as options. In the example shown in FIG. 8(D), further, in the case where the access source terminal 130 can change the display area of the service output screen in two modes (display modes 1 and 2), an item for storing the resolution information in each mode is provided. A plurality of the items shown in FIG. 8(D) are stored as one set, and it is also possible to provide different values according to the tenant, the communication relay device, and the service.
[0070] FIG. 9 is a diagram showing a more detailed configuration 400 of the on-site network 106 in the present embodiment. As shown in FIG. 9, the on-site network 106 is provided with a router 402, a firewall 404, a plurality of terminals 110A and 110B, and a plurality of services 410 and 412.
[0071] The on-site network 106 shown in FIG. 9 is separated into a plurality of networks 406 and 408 in order to minimize the range of information leakage even when attacked from the Internet 102. The first network 406 is a network accessible to the Internet 102 via the router 402, and the second network 408 is a network not connected to the Internet 102.
[0072] The communication relay device 120 is connected to a plurality of networks 406 and 408, but does not have the routing function of these plurality of networks. On the other hand, after a tunnel is established between the relay system 190 on the Internet 102 and the communication relay device 120, it is also possible to access the approval service 410 and the commuting service 412 in the second network 408 that is not directly connected to the Internet 102 from the communication relay device 120. In the example shown in FIG. 9, the access terminal 110 is the terminal 110A in the first network 406 that can access the Internet 102, and is in the network accessible by the communication relay device 120. However, it is not limited to this, and the access destination service may be in the second network 408 that is not connected to the Internet 102 as long as the communication relay device 120 can access it. For example, it may be the terminal 110B.
[0073] FIG. 10 is a diagram showing a more detailed configuration 420 of the communication relay device 120 in the present embodiment. As shown in FIG. 10, the communication relay device 120 has a plurality of network interfaces (I / F) 424 and 426, and the communication control unit 422 controls the plurality of network I / Fs 424 and 426. Although two network I / Fs are provided in FIG. 10, a single network I / F may be used. The communication relay device 120 further includes an application control unit 428, and holds an application 432, a private key 446, a root certificate 448, and a setting 450 in a storage 430. The setting 450 and the application 432 can have a redundant configuration and can operate even if the firmware update fails. The application 432 is divided into a common area 434 and a tenant-dependent tenant area 440. The application is a protocol conversion program. The protocol conversion program performs conversion between HTTP communication and a remote desktop protocol (such as RDP), and conversion between HTTP communications (converting the sequence).
[0074] Hereinafter, with reference to FIGS. 11 to 13, a process of starting a remote desktop including resolution determination processing according to the present embodiment will be described. FIG. 11 is a flowchart showing the resolution determination processing according to the present embodiment. Note that the processing shown in FIG. 11 is processing executed by an application server in the application system 150. The processing shown in FIG. 11 starts from step S100. In step S101, the application server performs a login process from the access source terminal 130.
[0075] FIG. 12 is a sequence diagram showing the login processing according to the present embodiment. FIG. 12 shows a process in which an end user logs in to the system through the browser 232. The login processing shown in FIG. 12 starts from step S200. In step S200, the browser 232 receives a browsing instruction specifying a predetermined URL from the end user. In step S201, the browser 232 accesses the application server 150 specified by the URL (one application server constituting the application system 150 is referred to as 150 by numbering), and in step S202, receives a WebUI.
[0076] In step S203, the browser 232 generates authorization request parameters, and in step S204, saves the generated authorization request parameters in the session storage. In step S205, the browser 232 attaches the authorization request parameters and sends an authorization request to the authentication unit 272 of the platform system 170. In step S206, the browser 232 obtains a login redirect destination URL. In step S207, the browser 232 sends a display request for the login screen based on the redirect destination URL. In step S208, the portal processing unit 274 receives this and sends the login screen. In step S209, the browser 232 displays the login screen.
[0077] FIG. 13(A) shows a login screen 460 for performing login processing displayed on the display screen of the access source terminal 130. The login screen 460 includes a dialog box 462, and the dialog box 462 includes a text box 464 for entering an account name such as an ID or an email address, a text box 466 for entering a password, and a login button 468 for making a login request based on the currently entered information. In the embodiment to be described, it is a screen for entering an account name (for example, an email address) and a password, but it is also possible to cooperate with an account of another system using a mechanism such as OAuth or perform multi-factor authentication. Further, the login screen 460 is a screen for logging in to the remote access support system 140.
[0078] Referring again to FIG. 12, in the login process, in step S300, the browser 232 continues to receive input of login information from the end user on the login screen 460 shown in FIG. 13(A). When information is entered in the text boxes 464 and 466 and the login button 468 is pressed, the input of login information is accepted.
[0079] In step S301, the browser 232 sends a login request with the login information attached. In step S302, in response to this, the portal processing unit 274 of the platform system 170 returns a callback destination temporary code. In step S303, the browser 232 issues a token acquisition request with the temporary code attached. In step S304, in response to this, the authentication unit 272 of the platform system 170 returns an access token, a refresh token, and an expiration date. In step S305, the browser 232 issues a login user information acquisition request with the ID and the access token attached. In step S306, in response to this, the authentication unit 272 of the platform system 170 returns user information. In step S307, the browser 232 executes processing related to screen update. In step S308, the screen display after login is performed.
[0080] Note that the login itself is authenticated using the functions of the platform system 170. Here, the authentication cooperation via OAuth, which is a mechanism for linking multiple web services between the platform system 170 and the application system 150, is realized, but it is not limited to this, and other cooperation methods other than OAuth may be used.
[0081] FIG. 13(B) shows a portal screen 470 displayed on the display screen of the access source terminal 130 after login. The portal screen 470 includes one or more icons representing services associated with the user, and the services are configured to be selectable. In FIG. 13(B), a remote desktop icon 472 for performing a remote desktop connection to a predetermined computer is shown. Further, FIG. 13(B) shows the case of an end-user login, and only the service part is displayed, and the setting part for administrators is not displayed. When the remote desktop icon 472 is pressed, a remote desktop start login screen 480 shown in FIG. 13(C) is displayed.
[0082] FIG. 13(C) shows a remote desktop start login screen 480 displayed on the display screen of the access source terminal 130. The screen 480 is a screen for logging in to the remote desktop service 212 provided by the access destination terminal 110. The screen 480 includes a text box 482 for accepting the input of a user name, a text box 484 for accepting the input of a password, a text box 486 for accepting the input of a domain, a menu box 488 for selecting a resolution, and further includes a connection button 490 for starting a remote desktop based on the input information. Here, the user name, password, domain name, and resolution information are input, but since the authentication on the login screen in FIG. 13(A) has been completed, this screen can be skipped and the pre-registered setting values can also be used.
[0083] For the input of resolution information, select a variable value or a fixed value. As the fixed value, it may be directly input, or it may be indicated by the value stored in the resolution information storage unit in the pull-down format and specified by selection. As the variable value, it is also possible to specify a method for obtaining the monitor size of the access source terminal 130 and the window size of the browser by the code (for example, javascript) executed in the browser 232.
[0084] Referring to FIG. 11 again, in step S102, in response to the successful processing of the login, the application server transmits a user interface for specifying the resolution (resolution specification UI) to the access source terminal 130. Here, it is assumed that the remote desktop service is selected on the portal screen 470 in FIG. 13(B) after the login process, and this resolution specification UI corresponds to the remote desktop start login screen 480 shown in FIG. 13(C). In step S103, the application server receives the specified value of the resolution based on the operation on the resolution specification UI from the access source terminal 130. In step S104, the application server reads the index value from the resolution setting storage unit 256 and branches the process based on the relationship between the index value and the specified value.
[0085] If it is determined in step S104 that the specified value of the screen resolution is less than or equal to the index value (NO), the process branches to step S105. In step S105, the application server transfers it to the communication relay device 120 via the platform system 170, assuming that the received specified value of the screen resolution is used as the use value. On the other hand, if it is determined in step S104 that the specified value of the screen resolution is greater than the index value (YES), the process branches to step S106. In step S106, the application server transmits it to the communication relay device 120 via the platform system 170, assuming that the stored index value of the screen resolution is used as the use value. In step S107, the remote desktop service is started.
[0086] FIG. 13(D) shows an operation screen 500 after the start of a remote desktop displayed on the display screen 234 of the access source terminal 130. The operation screen 500 is a screen for operating the remote desktop service. In response to a mouse operation or a keyboard operation using the cursor 504 on the desktop screen 502 displayed on the browser 232, the event information is transmitted to the communication relay device 120 via the relay system 190, where it is converted into the protocol of the remote desktop service 212 provided by the access destination terminal 110. Then, the feedback on the operation from the access destination terminal 110 is returned to the browser 232 in the reverse order. At this time, data from the browser 232 to the access destination terminal 110 and data from the access destination terminal 110 to the browser 232 can be transmitted simultaneously.
[0087] The resolution of the remote desktop screen 502 displayed on the operation screen 500 is the resolution determined by the resolution determination process by the application server 150 described above. The access source terminal 130 receives service output data from the communication relay device 120 through the relay system 190, and displays the image information in the service output data in the display area at the size (same magnification) of the resolution of the image information. Note that when displaying at the same magnification, it does not have to be displayed across the entire display area of the browser. When the browser 232 is displayed in a window, the display area of the browser does not match the size of the monitor, but when the browser is displayed in full screen, the display area of the browser will match the size of the monitor being displayed.
[0088] FIG. 14 explains the process when an end user logs in to the remote access support system 140 and specifies the resolution of the display area of the browser 232 as a specified value to use the remote desktop service. The end user can select a variable value of the resolution as login information when logging in. Here, it is assumed that the number of pixels in the display area of the browser is transmitted as a variable value of the resolution from the access source terminal 130 to the application server.
[0089] When the application server 150 receives the resolution information, it compares the variable value (designated value) with the upper limit value stored in the resolution setting storage unit 256 shown in FIG. 8(D). The comparison of values here is performed from the viewpoints of both the horizontal resolution and the vertical resolution. If the designated value exceeds the reference value (upper limit value) in either the horizontal resolution or the vertical resolution, it shall be determined that the designated value is larger than the reference value (upper limit value).
[0090] As shown in FIG. 14(A), when the resolution (number of pixels in the display area of the browser) 510 indicated by the designated value is less than or equal to the resolution 512 indicated by the reference value (upper limit value), the designated value is transferred as the usage value to the platform system 170 as it is. The communication relay device 120 starts the service with the connection resolution setting based on the designated value and generates output screen information 514 corresponding to the resolution based on the designated value. When the output screen is displayed at 100% magnification on the browser 232, as shown in FIG. 14(A), the service is started with a size equal to the display area 510 of the browser 232, and the desktop screen 514 is displayed at 100% magnification 516 in the display area 510 of the browser.
[0091] On the other hand, when the resolution (number of pixels in the display area of the browser) 520 indicated by the designated value is larger than the resolution 522 indicated by the reference value (upper limit value), as shown in FIG. 14(B), the reference value (upper limit value) is transmitted to the platform system 170 as the usage value. The communication relay device 120 starts the service with the connection resolution setting based on the reference value (upper limit value) and generates output screen information 524 corresponding to the resolution based on the reference value (performance value). When the output screen 524 is displayed at 100% magnification on the browser 232, as shown in FIG. 14(B), the service is started with a size smaller than the display area of the browser, and the desktop screen 524 is displayed at 100% magnification 526 within the display area 520 of the browser. In this case, the display area 520 of the browser may include a blank area 528 where the desktop screen 524 is not displayed.
[0092] In this way, within the range based on the stored resolution index value, the usage value of the screen resolution is determined based on the specified value of the resolution. When the specified value of the screen resolution is outside the range based on the stored index value (upper limit value) of the screen resolution, the stored index value of the screen resolution is determined as the usage value.
[0093] Hereinafter, with reference to FIGS. 15 and 16, the processing flow from the establishment (login) of access to the remote desktop service 212 to the termination (logout) of access will be described. FIGS. 15 and 16 are sequence diagrams showing the processing related to the remote desktop connection executed in the remote access support system 140 according to the present embodiment.
[0094] The processing shown in FIG. 15 starts from step S401. In step S401, the user instructs the browser 232 to browse the portal screen 470. In step S402, the browser 232 requests access to the portal screen 470 from the application server 150. In step S403, the API communication unit 258 returns the WebUI to the browser 232. In step S404, the browser 232 displays the portal screen 470 as shown in FIG. 13(B) on the display device.
[0095] In step S405, it is assumed that the end user selects a predetermined service (here, the service with the service name of "Emotional System Department Shared PC") on the portal screen 470. In step S406, the browser 232 requests the start of using the specified service from the application server. In step S407, the API communication unit 258 returns the WebUI to the browser 232. In step S408, the browser 232 displays the remote desktop start login screen 480 as shown in FIG. 13(C).
[0096] In step S409, it is assumed that the end user inputs login information (username, password, domain, resolution information) on screen 480. In step S410, browser 232 requests a login to application server 150 by specifying the login information (username, password, domain, resolution information). In step S411, in application server 150, API communication unit 258 passes the resolution information (specified value) included in the request to resolution determination unit 254. In step S412, resolution determination unit 254 executes a resolution determination process based on the passed resolution information (specified value), and in step S413, returns the determined resolution information (used value) to API communication unit 258.
[0097] In steps S414 and S415, API communication unit 258 instructs communication relay device 120 to establish a session with the relay server with a session ID via control unit 276 of platform system 170. In step S416, communication relay device 120 requests session establishment from relay system 190 with a session ID, and in step S417, establishes the session. In steps S418 and S419, API communication unit 258 receives a successful response to session establishment from communication relay device 120 via control unit 276 of platform system 170.
[0098] In step S420, API communication unit 258 instructs browser 232 to establish a session with the relay server with a session ID. In step S421, browser 232 requests session establishment from relay system 190 with a session ID, and in step S422, establishes the session. In steps S423 and S424, browser 232 transmits data to communication relay device 120 via relay system 190. In this data communication, login information and resolution information (used value) are transmitted.
[0099] In step S425, the communication relay device 120 performs protocol conversion. In step S426, the communication relay device 120 uses the received login information and resolution information (usage value) to access the remote desktop service 212 provided by the access terminal 110, and receives a success response in step S427. In step S428, the communication relay device 120 performs protocol conversion. In steps S429 and S430, the communication relay device 120 transmits data to the browser 232 via the relay system 190 and returns a response. In step S431, the browser 232 displays a remote operation screen.
[0100] Continuing to refer to FIG. 16, as shown in step S432, hereinafter, the end user uses the browser 232 to access the remote desktop service 212 via the relay system 190, performs remote operations, and receives the response.
[0101] Continuing with reference to FIG. 16, the logout process from the remote desktop service will be described. Logout starts from step S433. In step S433, the end user instructs the browser 232 to log out from the operation screen. In steps S434 and S435, the browser 232 transmits a logout request data to the communication relay device 120 via the relay system 190. In step S436, the communication relay device 120 makes a logout request to the remote desktop service 212, and in step S437, receives the success of logout. In step S438, the communication relay device 120 performs protocol conversion, and in steps S439 and S440, performs data communication to notify the browser 232 of the success of logout via the relay system 190. In step S441, the browser 232 requests the relay system 190 to disconnect the session. In step S442, the relay system 190 instructs the communication relay device 120 to disconnect the session, and in step S443, receives the success of session disconnection. In step S444, the relay system 190 notifies the browser 232 that the session has been successfully disconnected. In step S445, the browser 232 displays a logout success screen.
[0102] The sequence of remote desktop operations shown in FIGS. 15 and 6 can be broadly divided into three parts: a session establishment part (S401 to S431), a remote operation part (S432), and a remote operation end part (S433 to S445). The session establishment part and the remote operation end part are the same regardless of the access destination service, but the remote operation part varies depending on the type of service.
[0103] In the session establishment part, a tunnel is established between the browser 232 and the destination service (remote desktop service 212) via WebSocket over HTTPS. Communication is carried out between the browser 232 and the application server 150, and thereby, the communication relay device 120 connects to the relay system 190 using a session ID unique for each session, and the browser 232 also connects to the relay system 190 using the same session ID.
[0104] In the remote operation part, protocol conversion processing is performed by the communication relay device 120 to transfer operations and responses between the browser 232 and the destination service (remote desktop service 212). Here, for simplicity, a line is drawn between the end user and the destination service, which is omitted, but in reality, communication via the relay system 190 is involved.
[0105] In the remote operation termination part, the session between the browser 232 and the destination service (remote desktop service 212) is disconnected. The disconnection may be performed by executing a stop procedure from the browser 232, or may be performed from the browser 232, or the end user may end the use by closing the browser 232. Therefore, it may be possible to detect a timeout after the communication from the browser 232 is interrupted and end the session for which the timeout period has elapsed.
[0106] In the embodiment described above, when the specified value of the screen resolution is outside the range based on the stored index value of the screen resolution, the stored index value of the screen resolution is determined as the use value. Then, the access source terminal 130 displayed the image information in the service output data transmitted from the communication relay device 120 at an equal magnification based on the size of the resolution that the image information has. Hereinafter, a modification example of the resolution determination method when the specified value of the screen resolution is outside the range based on the stored index value will be described.
[0107] FIG. 17(A) illustrates a modified example of a method for determining the resolution when the specified value of the screen resolution is outside the range based on the stored index value. In the embodiment of the modified example shown in FIG. 17(A), when the specified value of the screen resolution is outside the range based on the index value of the screen resolution stored in the resolution setting storage unit 256, the resolution determination unit 254 further determines whether a predetermined fraction (e.g., 1 / 2 or 1 / 4) of the specified value of the screen resolution is within the range based on the stored index value of the screen resolution. If the value of the predetermined fraction is within the range based on the stored index value of the screen resolution, the resolution determination unit 254 can determine the value that is a predetermined fraction of the specified value as the use value. For example, in the example shown in FIG. 17(A), an example is illustrated where the resolution (specified value) 530 of the monitor display area of the access source terminal 130 is 1800×1800 pixels, and the index value 532 of the resolution is a resolution of 900×900 pixels. In this case, the specified value 530 of the screen resolution is outside the range based on the stored index value 532 of the screen resolution. However, a predetermined fraction of the specified value of the screen resolution is equal to the stored index value of the screen resolution and is within the range based on the index value of the screen resolution. In this case, as shown in FIG. 17(A), the resolution 534 that is 1 / 2 (0.5 times) of the specified value of this screen resolution is determined as the use value. Then, in the access source terminal 130, an image with a resolution that is 1 / 2 of this specified value is received and enlarged and displayed 536 by a factor of 2. In this way, by enlarging and displaying the service output screen output at a resolution that is a fraction (e.g., 2 or 4) of a predetermined integer by a factor of a predetermined integer (e.g., 2 or 4), it becomes possible to display dot-by-dot on the access source terminal 130, and it becomes possible to improve the visibility even when a resolution higher than the index value is specified.
[0108] In the embodiments described above, the resolution of the remote desktop service did not change after being set once. Hereinafter, with reference to FIGS. 17(B) and 18, an embodiment of a modification that enables the resolution of the remote desktop to be dynamically changed will be described. In the embodiment of the modification shown in FIG. 17(B), the access source terminal 130 has a first mode (full-screen display) in which the size 540 of the display device of the access source terminal 130 is equal to the size of the display area 542 for displaying the remote desktop screen, and a second mode (window display) in which the size 540 of the display device of the access source terminal 130 is different from the size of the display area 542 for displaying the remote desktop screen.
[0109] In the embodiment of the modification shown in FIG. 17(B), the code (e.g., JavaScript) included in the WebUI is configured to resend the number of pixels (designated value) of the display area after switching to the application server 150 in response to the switching when the display mode is switched in the access source terminal 130 during the use of the remote desktop.
[0110] By resending the designated value of the resolution according to the mode change, it becomes possible to use the remote desktop service with a resolution setting suitable for the mode after switching. Also, there is a method in which the application server 150 holds the setting values for each display mode shown in FIG. 8(D), and the browser only transmits information regarding the mode switch. In this case, switching is possible even when the resolution information (designated value) cannot be obtained due to restrictions caused by differences in the monitors and browsers of the terminals.
[0111] Hereinafter, with reference to FIG. 18, session reconnection accompanying the change in the resolution of the remote desktop service 212 will be described. FIG. 18 is a sequence diagram showing the processing at the time of reconnection accompanying the change in the resolution of the remote desktop executed in the remote access support system 140 according to the embodiment of the modification. FIG. 18 corresponds to the processing of reconnecting the session with the resolution after switching when the display mode in FIG. 17(B) is switched.
[0112] Here, the login process to the service has already been completed. As shown in step S501, the end user can use the browser 232 to access the remote desktop service 212 via the relay system 190, perform remote operations, and receive responses thereto. Step S501 corresponds to step S432 shown in FIG. 6.
[0113] In step S502, the end user performs an operation to change the resolution on the operation screen. Here, it is assumed that the display mode has been switched. In step S503, the browser 232 requests the application server 150 to change the resolution by specifying the changed resolution information (designated value). In step S504, in the application server 150, the API communication unit 258 passes the resolution information (designated value) included in the request to the resolution determination unit 254. In step S505, the resolution determination unit 254 executes a resolution determination process based on the passed resolution information (designated value), and in step S506, returns the determined resolution information (used value) to the API communication unit 258.
[0114] In steps S507 and S508, the API communication unit 258 commands the communication relay device 120 to change the resolution via the control unit 276 of the platform system 170. In step S509, the communication relay device 120 requests a re - session to the remote desktop service 212 provided by the access terminal 110 using the received resolution information (used value), and succeeds in step S510. In steps S511 and S512, the API communication unit 258 receives a response of successful resolution change from the communication relay device 120 via the control unit 276 of the platform system 170.
[0115] As shown in step S513, hereafter, the end user uses the browser 232 to access the remote desktop service 212 at the new resolution via the relay system 190, perform remote operations, and receive responses thereto.
[0116] As described above, when changing the display range of the desktop image of the access destination terminal 110 on the monitor of the access source terminal 130 while maintaining Dot-by-Dot, it is necessary to change the connection resolution setting regarding the remote desktop connection of the access destination terminal 110 from the communication relay device 120. For example, when the screen of the access destination terminal 110 is displayed on a browser, since the display area of the browser and the display area of the monitor are different, when it is desired to switch between browser display and monitor full-screen display, it is necessary to change the connection resolution setting. At this time, if the access destination terminal 110 does not support the RDP protocol 8.1, reconnection of the session is required, and the usability may decrease.
[0117] As described above, in the embodiment of the modification to be described, when switching between modes, the session between the communication relay device 120 and the access destination terminal 110 is once disconnected, and the session is re-established at the resolution after switching. Thereby, even when the RDP protocol does not support dynamic resolution change, it is possible to switch at high speed by re-establishing the session at a position close to the access destination terminal 110. When the RDP protocol supports dynamic resolution change (when it is a version of RDP 8.1 or higher), it is also possible to perform the resolution change process without disconnecting once at the communication relay device 120.
[0118] In the above-described embodiment, it is premised that the application server 150 can acquire the used value of the resolution at the time of remote desktop connection. Hereinafter, an embodiment of a modification that can cope even when the application server 150 cannot acquire the used value of the resolution after the start of the remote desktop connection will be described. FIG. 17(C) shows the embodiment of the modification.
[0119] Depending on the restrictions due to differences in the monitors and browsers of the access source terminal 130, resolution information may not be acquirable, and it may not be possible to transmit the resolution information (designated value) of the monitor or display area. In such cases, in the remote access support system 140 (more specifically, the application system 150), for example, it is preferable to save the display size at the time of first service use, and based on the held display size, use the magnification information when enlarged and reduced by the user's operation to adjust to a suitable resolution setting. FIG. 17(C) shows an embodiment of a modification example that can be adjusted to a suitable resolution setting using such magnification information.
[0120] In the example shown in FIG. 17(C), the access source terminal 130 has a display area 550 of, for example, 1600x1200 pixels, and at the time of the first access, it is connected at a resolution smaller than that, 800x600 pixels, and it is assumed that the desktop screen 552 is displayed at a 1:1 scale. Here, assume that the size is adjusted by enlarging or reducing the screen by an operation such as the window size change operation 554 of the access source terminal 130, and the size to be displayed in the display area is specified. Here, assume that both the horizontal direction and the vertical direction are changed to twice the original. Then, the magnification is 2.0. In the embodiment of this modification example, the browser 232 can calculate the adjusted resolution based on the stored value of the resolution of the screen used in the past and the magnification after this change, and transmit it to the application server 150. Alternatively, the browser 232 can directly transmit this magnification to the application server 150. In this case, in the application server 150, the adjusted resolution is calculated based on, for example, the stored value of the resolution of the screen used in the past and the magnification after the change, which are held by the remote access support system 140 (more specifically, the application system 150). Then, the resolution determination unit 254 determines the resolution using the value of the adjusted resolution as the specified value. In the example of FIG. 17(C), in the horizontal direction, it is 800 pixels x 2.0 times = 1600 pixels, and in the vertical direction, it is 400 x 2.0 = 1200 pixels, and the specified value of the adjusted resolution is 1600x1200 pixels. After being transmitted to the application server 150, the service output is updated at the resolution after the change, and the size of the display area of the browser and the service output screen match.
[0121] According to the embodiments described above, it is possible to provide a system, an information processing apparatus, an intermediation method, and a program capable of selecting appropriate output screen quality in remote access.
[0122] In particular, in the case of remote access, (1) the processing capacity of the device used by the system, (2) the monitor size of the access source terminal where the service is provided, and (3) the size of the area where the service screen is displayed within the access source terminal are restricted. Regarding the restrictions in (2) and (3), by transmitting appropriate setting values to the remote access service accordingly, the system will not request the device used by the system to have a processing capacity exceeding the restrictions of the access source terminal. Also, since an excessive processing capacity is not required, the device will not be in an overloaded state, and it becomes possible to improve the operability. Further, by the remote access service system recognizing the monitor size through the transmission of the specified value, it becomes possible to output a service screen suitable for the monitor size, and the output image quality is improved. Also, by presetting a value considering the processing capacity of the communication relay device as an index value, it becomes possible to select the quality of the screen according to the performance of the communication relay device.
[0123] Also, when switching between the sizes in (2) and (3), there may be a case where it is necessary to recreate the service screen, during which an inoperable time may occur and the operability may deteriorate. By configuring to reconnect from the communication relay device at a network position close to the accessed service, it becomes possible to shorten the inoperable time and further improve the operability.
[0124] Each function of the embodiment described above can be realized by one or more processing circuits. Here, the "processing circuit" in this specification includes a processor programmed to execute each function by software like a processor implemented by an electronic circuit, an ASIC (Application Specific Integrated Circuit) designed to execute each function described above, a DSP (digital signal processor), an FPGA (field programmable gate array), and devices such as conventional circuit modules.
[0125] The above functions can be realized by a computer-executable program written in legacy programming languages such as assembler, C, C++, C#, Java (registered trademark), and object-oriented programming languages, and stored in a device-readable recording medium such as ROM, EEPROM, EPROM, flash memory, flexible disk, CD-ROM, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, Blu-ray disc, SD card, MO, etc., or distributed through an electric communication line.
[0126] So far, the system, information processing apparatus, mediation method, and program according to an embodiment of the present invention have been described. However, the present invention is not limited to the above-described embodiment, and can be changed within the scope that those skilled in the art can conceive, such as addition, change, or deletion of other embodiments. As long as the functions and effects of the present invention are achieved in any aspect, it is included in the scope of the present invention.
Explanation of Reference Numerals
[0127] 100…Network environment, 102…Internet, 104, 1106, 108…Networks, 110…Access terminal, 120…Communication relay device, 130…Access source terminal, 140…Remote access support system, 150…Application system, 170…Platform system, 190…Relay system, 212…Remote desktop service, 222…Protocol conversion unit, 224…Connection resolution setting holding unit, 232…Browser, 234…Display screen, 252…Resolution selection UI providing unit, 254…Resolution determination unit, 256…Resolution setting storage unit, 258…API communication unit, 272…Authentication unit, 274…Portal processing unit, 276…Control unit, 292…Communication relay unit, 316…Database, 318…Type list, 320…Service list, 322…Service group list, 324…Action list, 326…Policy list, 366…Database, 368…Tenant list, 370…User list, 372…User group list, 380…Communication relay device, 390…Setting value list, 901…CPU, 902…ROM, 903…RAM, 904…HD, 905…HDD controller, 906‥Display, 908…External device connection I / F, 909…Network I / F, 910…Data bus, 911…Keyboard, 912…Pointing device, 914…DVD-RW drive, 916…Media I / F
Prior art documents
Patent documents
[0128]
Patent Document 1
Claims
1. A system for mediating the establishment of access to a service provided by an access destination terminal from an access source terminal, which relays communication relay means of the same network as the access destination terminal, comprising: a storage unit that stores an index value of the quality of a screen related to the service; a determination unit that determines a usage value of the quality of the screen within a range based on the index value, based on the relationship between the stored index value of the quality of the screen and the specified value of the quality of the screen from the access source terminal; a control unit that controls to set the quality of the screen based on the usage value determined by the communication relay means A system comprising.
2. The system according to claim 1, wherein the quality of the screen is the resolution of the screen output by the service.
3. The system according to claim 2, wherein the determination unit determines the stored index value of the resolution of the screen as the usage value when the specified value of the resolution of the screen is outside the range based on the stored index value of the resolution of the screen.
4. The system according to claim 2, wherein the determination unit determines, as the usage value, a value that is one of a predetermined number of the specified value when the specified value of the resolution of the screen is outside the range based on the stored index value of the resolution of the screen and one of a predetermined number of the specified value is within the range based on the stored index value of the resolution of the screen.
5. The access source terminal has a first mode in which the size of a display device included in the access source terminal is equal to the size of a display area for displaying the screen, and a second mode in which they are different, and is configured to transmit information indicating the resolution of the display area in response to switching between the first mode and the second mode. The system according to any one of claims 2 to 4.
6. The system according to claim 5, wherein the communication relay means is configured to temporarily disconnect a session between the communication relay means and the access destination terminal when switching between the first mode and the second mode, and to re-establish the session at the resolution after the switching.
7. When the specified value of the resolution of the screen is not received from the access source terminal, the determination unit temporarily determines the stored value of the resolution of the screen held by the system as the usage value, and calculates the usage value of the resolution of the screen from the magnification of the change in response to a change in the display area for displaying the screen on the access source terminal. The system according to any one of claims 2 to 6.
8. The system further includes a providing unit that provides a user interface capable of communicating with the access source terminal. The providing unit receives a specification of the resolution when using the service through an operation, and the specification of the resolution is performed by a value selected from a plurality of candidate values or a variable value. The system according to any one of claims 2 to 7.
9. The access source terminal is on a second network separated from the network via the Internet, and the system further includes a relay server that relays Internet communication related to one or both of the screen information and the operation information between the communication relay means and the access source terminal. The system according to any one of claims 2 to 8.
10. The access source terminal is a display unit that displays the display area at the resolution of the screen included in the screen information received from the communication relay means; a transmission unit that transmits the operation information indicating the operation input to the communication relay means based on an operation input related to the display area The system according to claim 9.
11. The service is a remote desktop service. The access source terminal has a display area for displaying the screen on a display device. The communication relay means sets the remote desktop service with the access destination terminal based on the determined usage value of the resolution of the screen, generates an output screen corresponding to the resolution set through communication with the service, and protocol-converts the input / output data of the service provided by the access destination terminal. The system according to any one of claims 2 to 10.
12. An information processing apparatus that mediates the establishment of access from an access source terminal to a service provided by an access destination terminal, via a communication relay means on the same network as the access destination terminal, a storage unit that stores an index value of the quality of the screen related to the service A determination unit that determines a usage value of the quality of the screen within a range based on the index value, based on the relationship between the index value of the quality of the stored screen and the specified value of the quality of the screen from the access source terminal; A transmission unit that transmits the determined usage value to the communication relay means via a platform or directly so that the communication relay means uses it when setting the quality of the screen; An information processing apparatus comprising:
13. A mediation method for mediating the establishment of access from an access source terminal to a service provided by an access destination terminal, via a communication relay means of the same network as the access destination terminal, wherein at least one computer Reads an index value of the quality of the screen related to the service; Determines a usage value of the quality of the screen within a range based on the index value, based on the relationship between the index value of the quality of the stored screen and the specified value of the quality of the screen from the access source terminal; Controls the communication relay means to set the quality of the screen based on the determined usage value; A mediation method for executing.
14. A program for realizing an information processing apparatus that mediates the establishment of access from an access source terminal to a service provided by an access destination terminal, via a communication relay means of the same network as the access destination terminal, wherein the computer A storage unit that stores an index value of the quality of the screen related to the service; A determination unit that determines a usage value of the quality of the screen within a range based on the index value, based on the relationship between the index value of the quality of the stored screen and the specified value of the quality of the screen from the access source terminal; and A transmission unit that transmits the determined usage value to a platform connected to the communication relay means or to the communication relay means so that the communication relay means uses it when setting the quality of the screen; A program for functioning as.
Citation Information
Patent Citations
Device of automatically grinding nose of injection needle
JP1979059693A
Remote operation control program utilizing web server
JP2005323093A
Screen data relay server, screen data relay program and screen data relay method
JP2018159984A
Information processing device, information processing system, computer program, and information processing method
WO2009093333A1
Providing virtual desktop within computing environment
WO2020082210A1