Information processing system and method
The information processing system addresses the challenge of integrating services with different tenant structures by creating new resources and using dummy resources to manage overlapping IDs, ensuring secure and efficient data migration.
Patent Information
- Application Number
- JP2021064277
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-04-05
- Publication Date
- 2025-07-31
- Estimated Expiration
- 2041-04-05
AI Technical Summary
Existing technologies fail to seamlessly integrate and migrate data between services with different tenant structures, particularly when resources with overlapping resource IDs are involved, leading to potential data loss and security risks.
An information processing system that determines the existence of corresponding tenants and resources, creates new tenants and resources if necessary, and migrates data either directly or through dummy resources to ensure smooth integration while ensuring security.
Facilitates safe and efficient service integration by handling resource ID overlaps and ensuring data integrity and security during tenant-separated service migrations.
Smart Images

Figure 0007716216000001 
Figure 0007716216000002 
Figure 0007716216000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system and method, and more particularly to data migration and integration between services. [Background technology]
[0002] Conventionally, there is a technology that facilitates cooperation between services by providing a common ID that links different IDs for each service among multiple services that manage content using IDs. In Patent Document 1, authentication in cooperation between services is made easy by providing a common server that links and manages different IDs between multiple services with a common user ID and client ID.
[0003] Furthermore, in a tenant-separated service in which resources are managed by linking them to tenants, there is a technology for moving resources to a different tenant. In Patent Document 2, when a device linked to a tenant is moved to another tenant, an authorization server stores destination tenant information, and the response to an authorization request from the device includes the destination tenant, thereby smoothly managing permissions when the device is moved. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2018-022501 [Patent Document 2] Japanese Patent Publication No. 2020-119147 Summary of the Invention [Problem to be solved by the invention]
[0005] Assume a tenant-separated service where resources are linked to and managed by tenants. There are cases where data is integrated between multiple services when merging or abolishing services for operational reasons or migrating data to a new service under development. In such cases, if the tenants were used by the same users before the integration, it is desirable to integrate and transfer the data even if the services are different.
[0006] As mentioned above, there are technologies for managing IDs that are shared across multiple services. However, when considering a service that manages tenants and the resources associated with those tenants, it is conceivable that the tenant structures may differ between services. If a resource has a unique resource ID and each tenant that is not associated with another service has a resource with that resource ID, it is not possible to determine whether to prioritize the association between the resource and tenant or the resource ID when coordinating between services.
[0007] As mentioned above, there is technology to move resources owned by one tenant to another, but it does not mention moving resources across services. Because moving resources across services changes the resources owned within a service, it cannot handle situations where resources with resource IDs that overlap with those of the resources being moved to a location other than the destination are present.
[0008] The present invention has been made in view of the above-mentioned problems, and has as its object to facilitate service integration and also to perform service integration safely. [Means for solving the problem]
[0009] In order to achieve the above object, the present invention has the following configuration: That is, according to one aspect of the present invention, there is provided an information processing system that migrates a source tenant that is a tenant of a source service to a destination tenant that is a tenant of a destination service corresponding to the source tenant, the information processing system comprising: a first determination means for determining whether or not there is a destination tenant corresponding to the source tenant; a tenant creation means for newly creating the destination tenant when it is determined that the destination tenant does not exist; a second determination means for determining whether a destination resource having the same ID as a source resource included in the source tenant is included in the tenant of the destination service; a resource creation means for newly creating the destination resource in the destination tenant when it is determined that the destination resource is not included in the tenant of the destination service; The source resource Resource a migration means for migrating data to the destination resource; The transition means is If the tenant including the destination resource is the destination tenant, Resource Migrating data directly to the destination resource; If the tenant including the destination resource is not the destination tenant, the said resource The data is migrated to the destination resource via a dummy resource created in the destination tenant. An information processing system is provided.
[0010] According to another aspect of the present invention, there is provided an information processing system that migrates a source tenant that is a tenant of a source service to a destination tenant that is a tenant of a destination service corresponding to the source tenant, the information processing system comprising: a first determination means for determining whether or not there is a destination tenant corresponding to the source tenant; a tenant creation means for newly creating the destination tenant when it is determined that the destination tenant does not exist; a second determination means for determining whether a destination resource having the same ID as a source resource included in the source tenant is included in the tenant of the destination service; a resource creation means for newly creating the destination resource in the destination tenant when it is determined that the destination resource is not included in the tenant of the destination service; The data of the source resource beforementioned Resource has migration means for migrating the data to the destination resource, and if the tenant including the destination resource is not the destination tenant, the migration means migrates the data of the source resource to the destination resource in response to authentication by an administrator. the said resource An information processing system is provided, which is characterized by the above.
Effect of the Invention
[0011] According to the present invention, the smoothness of service integration can be achieved, and at the same time, service integration can be performed safely.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Modes for Carrying Out the Invention
[0013] [Embodiment 1] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0014] The information processing system of the present embodiment is applied to an information processing system including an integration source service providing server, an integration destination service providing server, and an integration execution server. Note that the integration source service providing server and the integration destination service providing server have a function of managing a plurality of tenants, a plurality of resources associated with the tenants, and a plurality of resource data associated with the resources. Specific examples of resources include a PC, a smartphone, a tablet, an image forming apparatus, a smart watch, a digital camera, and the like. The image forming apparatus includes, for example, a printer and a multifunction peripheral (MFP).
[0015] However, the integration source service providing server and the integration execution server may be the same server. Alternatively, the integration destination service providing server and the integration execution server may be the same server.
[0016] In the present embodiment, it is assumed that the integration source service and the integration destination service have a function of managing a plurality of tenants. Further, the integration source service and the integration destination service have a function of associating and managing a plurality of resources with each tenant, and users of the integration source service and the integration destination service cannot acquire and view data related to resources other than the tenant to which the user belongs. Further, the integration source service and the integration destination service have a function of associating and managing a plurality of resource data with each resource. Further, in the present embodiment, it is assumed that a resource has a unique resource ID, and a plurality of resources having duplicate resource IDs cannot be registered in the same service.
[0017] Examples of tenant management information managed by the source integration service and the destination integration service are shown below. Example 1. Tenant Management Information { "TenantId": "BEF0001", "CustomerName": "MyCompany", "MailAddress": "my-company@mail.address", "Language": "Japanese" "Contract": { "Data": "2020 / 6 / 1", "Name": "MyDistributor" "MailAddress": "my-distributor@mail.address", } } As such, tenant management information includes tenant ID, customer name, mail address, language used, and contract information.
[0018] Examples of management information for the resources associated with a tenant, managed by the source integration service and the destination integration service, are shown below. Example 2. Resource Management Information { "ResourceID": "RSC0001", "TenantId": "BEF0001", "ResourceName": "MyResource", "ProductName": "RSC-0001", "ResourceType": "Personal Computer", } As such, resource management information includes resource ID, tenant ID to which it belongs, resource name, product name, and resource type. Resource management information is created when the resource is created, and the values of each item may be the values specified at that time.
[0019] The following shows an example of management information for resource data associated with resources, which is managed by the source service and the destination service for integration. Example 3. Resource Data Management Information { "ResourceDataID": "DAT0001", "ResourceID": "RSC0001", "TenantId": "BEF0001", "ResouceDataPath": " / rcsdata / BEF0001 / RSC0001 / DAT0001.zip", "Date": "2020 / 6 / 30", "Containts": "settings", "address_book", "application_licenses" } In this way, the resource data management information includes a resource data ID, a resource ID, a tenant ID, the location of the resource data, a date, and a display of the contents.
[0020] In addition, an example of resource data associated with a resource is shown in FIG. 11. FIG. 11 is an example when, for example, a multifunction peripheral (MFP) is used as the resource. In this example, the resource data 1100 includes, for example, a basic settings ledger containing various basic settings of the device, an address book containing senders and contacts, etc. Furthermore, it includes installed application licenses installed on the device that is the resource, installed application setting values. It may also include resource internal storage files stored in the device. The resource data will, of course, correspond to the type of resource or, in the case of a device, its model, etc. As described above, the resource data is associated with the resource by the resource data management information.
[0021] [Embodiment 1] ●System Configuration FIG. 1 is a block diagram showing an example of a system configuration and a network configuration for implementing the present invention.
[0022] The integrated source service providing server 101 has a function of managing a plurality of tenants, a plurality of resources associated with the tenants, and a plurality of resource data associated with the resources. Also, it can communicate with the outside such as the integrated execution server 103 via the network 100.
[0023] The integrated destination service providing server 102 has a function of managing a plurality of tenants, a plurality of resources associated with the tenants, and a plurality of resource data associated with the resources. Also, it can communicate with the outside such as the integrated execution server 103 via the network 100.
[0024] The integrated execution server 103 executes service integration processing by transmitting operation commands to the integrated source service providing server 101 and the integrated destination service providing server 102 via the network 100. Note that the present invention is applicable even if the integrated source service providing server 101 and the integrated execution server 103 are the same server. Alternatively, the present invention is applicable even if the integrated destination service providing server 102 and the integrated execution server 103 are the same server.
[0025] Figure 2 shows a hardware configuration diagram of the integrated source service providing server 101, the integrated destination service providing server 102, and the integrated execution server 103. The RAM 201 is a temporary memory area. The storage 202 stores the embedded program and data. The network interface 204 is connected to the network to communicate with other computers and network devices. The secondary storage device 205 is a secondary storage device typified by an HDD or a flash memory. The CPU 200 executes a program read from the RAM 201, the storage 202, the secondary storage device 205, etc., processes data, or inputs / outputs data. Each part is connected via the system bus 203. In the present embodiment, unless otherwise specified, the system bus 203 propagates control commands from the CPU 200 to each hardware connected to the system bus 203.
[0026] ● Functional configuration of each server FIG. 3 is a block diagram showing an example of the functional configuration of the integration source service providing server 101. The program of the integration source service providing server 101 is read from the RAM 201, the storage 202, the secondary storage device 205, etc., and is realized by being executed by the CPU 200. External access via a network such as the integration execution server 103 is performed via the network interface 204.
[0027] The integration source service providing server 101 manages tenant management information such as Example 1, resource information such as Example 2, and resource data management information such as Example 3 in the tenant resource storage unit 302. Also, in the resource data management storage 303, the actual file of the resource data is held.
[0028] The integration source service providing server 101 also receives an operation command from the communication unit 304, accesses the tenant resource storage unit 302 via the tenant resource operation unit 300, and acquires and updates tenant management information, resource management information, and resource data management information. Alternatively, it receives an operation command from the communication unit 304, accesses the resource data management storage 303 via the resource data operation unit 301, and acquires the actual file of the resource data.
[0029] FIG. 4 is a block diagram showing an example of the functional configuration of the integration destination service providing server 102. The program of the integration destination service providing server 102 is read from the RAM 201, the storage 202, the secondary storage device 205, etc., and is realized by being executed by the CPU 200. External access via a network such as the integration execution server 103 is performed via the network interface 204.
[0030] The integration destination service providing server 102 manages tenant management information such as Example 1, resource information such as Example 2, and resource data management information such as Example 3 in the tenant resource storage unit 402. Also, in the resource data management storage 403, the actual file of the resource data is held.
[0031] The integration destination service providing server 102 also receives an operation instruction from the communication unit 404, accesses the tenant resource storage unit 402 via the tenant resource operation unit 400, and acquires and updates tenant management information, resource management information, and resource data management information. Alternatively, it receives an operation instruction from the communication unit 404, accesses the resource data management storage 403 via the resource data operation unit 401, and acquires the actual file of the resource data.
[0032] Note that the resource has a unique resource ID (hereinafter, the unique resource ID). When writing resource management information, the resource duplication determination unit 405 determines whether there is no duplication of the unique resource ID. If a duplicate unique resource ID already exists within the service, the write fails. In the case of a failed write, no write is performed, and operations such as sending a message indicating failure to the integration execution server 103 or the integration source service providing server 101 or both are performed.
[0033] FIG. 5 is a block diagram showing an example of the functional configuration of the integration execution server 103. The program of the integration execution server 103 is read from the RAM 201, the storage 202, the secondary storage device 205, etc., and realized by being executed by the CPU 200. External access via a network such as the integration source service providing server 101 and the integration destination service providing server 102 is performed via the network interface 204.
[0034] The integration execution server 103 holds, in the tenant correspondence relationship management unit 500, the correspondence relationship between the integration source tenant managed by the integration source service providing server 101 and the integration destination tenant managed by the integration destination service providing server 102. This correspondence relationship may be automatically created by linking from the tenant ID, registered email address, address information, telephone number information, etc., or may be created manually in advance. An example of holding the correspondence relationship is shown below.
[0035] Example 4. Example of holding the integration source / destination correspondence relationship Integrating source tenant, integrating destination tenant BEF001 AFT00A BEF002 AFT00B :: The correspondence relationship between tenants is specified by associating the tenant ID of the source integration tenant and the tenant ID of the destination integration tenant as in this example.
[0036] The command creation unit 501 creates commands for the source integration service providing server 101 and the destination integration service providing server 102, and transmits them via the communication unit 504, thereby executing service integration from the source integration service providing server 101 to the destination integration service providing server 102.
[0037] When creating resources of the destination integration service providing server 102 by integration execution, if the creation fails due to duplication of unique resource IDs in the destination integration service, the integration with the existing resources is not immediately executed, and the source integration resources are put into an integration standby state. That is, the integration is postponed. For the source integration resources in the integration standby state, for example, a list of resources in the integration standby state may be created, and the resource management information may be registered there to indicate that it is in the integration standby state. When the source integration resources are put into the standby state, the temporary authentication information creation unit 502 creates temporary authentication information and notifies the administrator of the destination integration tenant. The created temporary authentication information is managed by the temporary authentication information management unit 503. When the corresponding temporary authentication information is input in the destination integration tenant, the integration that was in the standby state is executed (or resumed). Note that the integration standby or standby state may also be referred to as the integration preparation or preparation state. Also, the integration standby state may be managed for the source integration resources instead of the destination integration resources.
[0038] ● Service integration process 6 is a diagram showing the service integration processing flow by the integrating execution server 103. The integrating execution server 103 generates a tenant list acquisition command for the integrating source service in the command creation unit 501 and transmits it to the integrating source service providing server 101 to acquire the tenant list of the integrating source service (S600). Note that the acquisition command can also be referred to as a request. This also applies to other parts of this specification.
[0039] Thereafter, the system sequentially focuses on the tenants included in the acquired integrating source tenant list, and performs processing on the target tenant. The integrating source tenant being processed in the integrating source tenant list is designated as the integrating source tenant of interest.
[0040] The tenant correspondence management unit 500 determines whether there is a tenant correspondence for the target integration-source tenant (S601). That is, it determines whether there is a destination tenant corresponding to the target migration-source tenant. If there is a correspondence, the tenant in the integration-destination service described in the correspondence, i.e., the corresponding tenant, is called the integration-destination tenant. If there is no correspondence, the command creation unit 501 creates a tenant creation command for the integration-destination service and sends it to the integration-destination service providing server 102. In response to this command, the integration-destination service providing server 102 creates a new tenant and designates the created tenant as the integration-destination tenant (S602). When sending the tenant creation command in step S602, the integration execution server 103 may, for example, associate the target integration-source tenant with the tenant created in step S602 and save the correspondence in the tenant correspondence management unit 500. This ensures that an integration-destination tenant corresponding to the integration-source tenant always exists in the integration-destination service during integration processing. Note that this association may be performed after the creation of the tenant in response to the tenant creation command has been confirmed.
[0041] Next, the command creation unit 501 creates a resource list acquisition command for the target integrating-source tenant and sends it to the integrating-source service providing server 101. In response to the resource list acquisition command, the integrating-source service providing server 101 replies with the resource list of the target integrating-source tenant. In this way, the integrating execution server 103 acquires the resource list of the target integrating-source tenant (S603).
[0042] Thereafter, the resources included in the acquired source resource list are sequentially focused on, and processing is performed on the focused resource. The source tenant being processed in the source resource list is designated as the source resource of interest. Resource integration processing is performed on the source resource of interest (S604). Details of the resource integration processing are shown in FIG. 7. Step S604 is repeated sequentially for all resources included in the resource list (S605), and steps S601 to S605 are repeated sequentially for all tenants included in the tenant list (S606).
[0043] FIG. 7 is a diagram showing the flow of the resource integration process (S604) that appears in the service integration process flow by the integrated execution server 103 in FIG.
[0044] The command creation unit 501 creates a destination resource acquisition command and transmits it to the destination service providing server 102 (S700-1). At this time, the unique resource ID of the source resource of interest is specified as the ID of the resource to be acquired. Note that the resource to be acquired here may be resource management information. If a corresponding resource is found, for example, the resource management information is returned as a response. If not, a response is made indicating that there is no corresponding resource. It is determined whether a resource in the destination service having the unique resource ID of the specified source resource of interest has been acquired (S700-2). If it is determined that it has not been acquired, the command creation unit 501 creates a resource creation command for the destination service and transmits it to the destination service providing server 102. As a result, a new resource is created in the destination tenant (S702). At this time, the unique resource ID of the source resource of interest is specified as the ID of the resource to be created. Furthermore, the destination tenant is specified as the tenant to which the resource to be created belongs. The created resource becomes the destination resource corresponding to the source resource of interest. Although resources may include hardware, the resources dealt with here are logicalized or virtualized resources.
[0045] Thereafter, the command creation unit 501 creates a resource data acquisition command for the target integrating resource and sends it to the integrating service providing server 101 to acquire the resource data of the target integrating resource (S703). The command creation unit 501 creates a resource data save command for the integration destination resource and sends it to the integration destination service providing server 102 together with the acquired resource data of the target integrating resource. At this time, the integration destination resource ID to be associated with the resource data is specified. Upon receiving this, the integration destination service providing server 102 saves the received resource data of the integrating resource as resource data of the integration destination resource (S704). The processing of steps S703 and S704 can be said to be processing for directly migrating the data of the integrating source resource to the integration destination resource.
[0046] Note that after step S702, the process may proceed to step S701 instead of step S703. Even in this case, ultimately, step S701 will result in an affirmative determination result, so the process will branch to step S703.
[0047] If it is determined in step S700-2 that a resource within the destination service having the unique resource ID of the source resource to be integrated has been acquired, the resource acquired in step S700-1 is set as the destination resource, and the tenant possessing the destination resource is confirmed (S701). The tenant possessing the destination resource can be confirmed by referring to the tenant ID included in the received resource management information.
[0048] If it is determined that the tenant possessing the destination resource is the destination tenant (S701 - YES), the source resource to be integrated is integrated into the destination resource. Therefore, the instruction creation unit 501 creates a resource data acquisition instruction for the source resource to be integrated. By transmitting this to the source service providing server 101, the resource data of the source resource to be integrated is acquired as a response (S703). The instruction creation unit 501 creates a resource data storage instruction for the destination resource, and transmits it together with the acquired resource data of the source resource to be integrated to the destination service providing server 102, and stores it as the resource data of the destination resource (S704). The resource data storage instruction specifies the destination resource ID with which the resource data is associated.
[0049] If it is determined that the tenant holding the integration destination resource is not the integration destination tenant (S701-No), the integration process for the target integration source resource is suspended, and the integration destination resource is set as the integration destination resource on standby. That is, the integration destination resource is set to the integration waiting state. To achieve this, for example, the resource management information of the integration destination resource obtained in step S700-1 can be registered in the list of the integration waiting state, or information indicating the waiting state can be associated. The tenant holding the integration destination resource on standby is called the integration destination tenant on standby. Also, the integration destination tenant is called the temporary integration destination tenant. Being in the integration waiting state is also referred to as being on standby or suspended. Also, the target integration source resource for which the integration destination resource has entered the waiting state may be called the integration source resource on standby. The integration execution server 103 creates a dummy resource in the temporary integration destination tenant, associates the resource data, and performs a process of waiting for the integration from the dummy resource to the integration destination resource on standby (S705~S710). Next, the details will be described.
[0050] The command creation unit 501 creates a resource creation command for the integration destination service and sends it to the integration destination service providing server 102 to create a resource in the temporary integration destination tenant (S705). At this time, a unique resource ID that does not duplicate within the integration destination service is specified for the resource ID of the resource to be created. The created resource is called a dummy resource. An example of the dummy resource management information is shown below.
[0051] Example 5. Dummy Resource Management Information { "ResourceID": "DMYxXio3qjA", "TenantId": "AFT000A", "ResourceName": "", "ProductName": "", "ResourceType": "", } As described above, the dummy resource management information includes a resource ID, a tenant ID, a resource name, a product name, and a resource type. The tenant ID is the ID of the temporary integration destination tenant. The resource name, product name, and resource type may be the resource name, product name, and resource type specified in the resource creation instruction. The specified resource name, product name, and resource type may be those of the corresponding source integration resource, respectively. Since the resource ID of the source integration resource of interest is held by the destination integration resource in a waiting state in the destination service, a different ID from the resource ID of the source integration resource of interest is assigned to the dummy resource. As a result, the source integration resource of interest and the dummy resource cannot be directly associated by the resource ID. Therefore, when creating a dummy resource, information indicating that it is a dummy resource and its association with the waiting destination integration resource that caused the creation of the dummy resource is saved.
[0052] The instruction creation unit 501 creates a resource data acquisition instruction for the source integration resource of interest and transmits it to the source service providing server 101. The source service providing server 101 acquires the resource data of the source integration resource and responds to the integration execution server 103 (S706). The instruction creation unit 501 creates a resource data storage instruction for the dummy resource and transmits it to the destination service providing server 102 together with the acquired resource data. The destination service providing server 102 stores the received resource data as the resource data of the dummy resource (S707). Since the dummy resource is created temporarily or provisionally, it may be called a provisional resource. The temporary authentication information creation unit 502 creates temporary authentication information that associates the temporary integration destination tenant, the waiting destination tenant, and the unique resource ID of the source integration resource of interest (S708). Here, to explain again, the temporary integration destination tenant is the tenant of the destination service associated with the source integration tenant of interest. The waiting destination tenant is the tenant of the destination service that holds a resource (waiting destination integration resource) with the same ID as the source integration resource of interest.
[0053] Here, the temporary authentication information (also simply referred to as recognition information) is notified to the administrator of the temporary integration destination tenant (S709). Here, not only the temporary authentication information but also a message notifying the administrator of the occurrence of the waiting state may be notified together. Note that since the temporary integration destination tenant is the tenant to which the integration source tenant is integrated or migrated from the integration source tenant, this notification may be sent to the administrator of the integration source tenant. Also, prior to the temporary authentication information, a message indicating that a waiting state has occurred in the integration process and asking for the continuation of the process may be notified first, and when the administrator gives an instruction to continue the integration, the temporary authentication information may be sent to the administrator.
[0054] The temporary authentication information management unit 503 saves the created temporary authentication information (S710). An example of the management information of the temporary authentication information is shown below. The destination of the tenant administrator may be a pre-registered destination, or it may be sent to the integration destination service providing server 102 of the temporary integration destination tenant and then transferred or distributed from there to the administrator's terminal or the like.
[0055] Example 6. Example of management information of temporary authentication information in Embodiment 1 Waiting | Temporary authentication information | Temporary | Unique resource ID Integrating destination tenant| |Integrating destination tenant| AFT0042 | Ljg432hfhew84GtO | AFT0022 | RSC0009 AFT0090 | p46JLoImEh6G65d2 | AFT0045 | RSC0025 Note that for resources where the combination of the temporary integration destination tenant and the waiting integration destination tenant is the same, the temporary authentication information may be the same regardless of the value of the unique resource ID.
[0056] According to the procedure of FIG. 7, if there is an integration destination resource in the integration destination tenant, the integration source resource can be integrated (or migrated) to the integration destination resource. Also, if the integration destination resource does not exist in the integration destination service, a new integration destination resource can be created and the integration source resource can be integrated into it. On the other hand, if the integration destination resource belongs to a tenant other than the integration destination tenant, after setting temporary authentication information, the integration process for the integration source resource is put on hold.
[0057] FIG. 8 is a diagram showing a processing flow when executing the integration of a resource that has entered the integration waiting state in the resource integration process of FIG. 7. According to step S709 of FIG. 7, the temporary authentication information has been notified to the administrator of the temporary integration destination tenant. When the temporary authentication information is input in the waiting integration destination tenant, authentication is given to the suspended integration process and the integration process is resumed. The process of FIG. 8 is executed by the integration execution server 103.
[0058] In FIG. 8, when the user of the integration destination tenant waiting for integration transmits the temporary authentication information notified to the temporary integration destination tenant at S709, the execution of the integration process waiting to start is triggered (S800). The transmission of the temporary authentication information in step S800 may be performed on the screen of the terminal of the integration destination service providing server 102 logged in as the user of the integration destination tenant waiting for integration. An example of the management screen is shown in FIG. 12. FIG. 12(A) shows an example of the display of migration information on the screen after logging in to the integration destination tenant waiting for integration. This screen is determined by referring to, for example, the management information of the temporary authentication information as to whether the tenant of the logged-in user is the integration source tenant waiting for integration, and is displayed when it corresponds. Also, FIG. 12(B) shows an example of the temporary authentication information transmission screen in the integration destination tenant waiting for integration. This screen is displayed when, for example, the "Go to Migration Execution Screen" button in FIG. 12(A) is touched. When there are a plurality of resources corresponding to the input temporary authentication information, the integration of the plurality of resources may be continuously executed. The temporary authentication information and its management information are stored in the integration execution server 103. Therefore, in step S800, in order to determine whether the tenant of the logged-in user is the integration destination tenant waiting for integration, the integration execution server 103 may be queried or the management information may be acquired and determined. Although FIG. 12(B) states that the temporary authentication information (temporary authentication key) has been transmitted to the administrator of the source tenant for migration, this indicates that it has been transmitted to the administrator of the integration source tenant waiting for integration as shown in step S709.
[0059] Determine whether the temporary authentication information input on the screen of FIG. 12(B) exists in association with the integration destination tenant waiting for integration (S801). This determination is also made by referring to the management information of the temporary authentication information. If it does not exist, an error response is returned as an input error (S805), and the integration process waiting to start is not executed and ends. When the input temporary authentication information exists in association with the integration destination tenant waiting for integration (S801-Yes), it is determined that the authentication for resuming the integration process between the notified temporary integration destination tenant and the integration destination tenant waiting for input has succeeded. Therefore, in that case, the integration process waiting to start (S802 to S804) is executed.
[0060] The command creation unit 501 creates a resource data acquisition command for the dummy resource and transmits it to the integration destination service providing server 102 to acquire the resource data of the dummy resource (S802). The command creation unit 501 creates a resource data save command for the standby integration destination resource and transmits it to the integration destination service providing server 102 together with the resource data of the dummy resource to save it as resource data of the standby integration destination resource (S803). Thereafter, the command creation unit 501 creates a dummy resource deletion command and transmits it to the integration destination service providing server 102 to delete the dummy resource (S804). At this time, along with the deletion of the dummy resource, management information for the dummy resource may be deleted, and further resource data linked to the dummy resource may be deleted. The processing from steps S705 to S710 to S802 and S803 can be said to be processing for transferring data of the integration source resource to the integration destination resource via the dummy resource.
[0061] With the above configuration and processes, in this embodiment, if resource duplication occurs during data integration between services, the integration of the resources is put on hold and put into a standby state, and the integration is carried out only when authentication between tenants before and after the integration is confirmed. This allows for smooth service integration even when the tenant structures are different.
[0062] Furthermore, tenant and resource data can be integrated based on the correspondence between services. Also, resource duplication before and after integration can be resolved based on the tenant correspondence. More specifically, when resource ID duplication occurs in the target service, integration can be carried out smoothly if there is a correspondence between the tenant that owns the existing resource and the tenant that owns the source resource. At the same time, if there is no correspondence between the tenant that owns the existing resource and the tenant that owns the source resource, integration can be avoided and data leakage can be prevented.
[0063] More specifically, when the tenant to which the destination resource corresponding to the source resource belonging to the source tenant belongs is different from the destination tenant, the integration process of the resource is performed through authentication. Also in that case, the authentication information is sent to the user of the destination tenant, while the input of the authentication information is performed in the tenant to which the destination resource belongs. For this reason, in such a case, it is difficult for the user of the destination tenant to authenticate at their own discretion, and the consent and monitoring of the user of the tenant to which the destination resource belongs are required. That is, substantially, the integration of the resource is executed only after receiving the authentication of both the user of the destination tenant and the user of the tenant to which the destination resource belongs, and the security at the time of tenant integration can be improved.
[0064] Furthermore, by creating a dummy resource, when the integration process is in a waiting state, it becomes unnecessary to refer to the resources and resource data of the source tenant for resuming the integration process. That is, once the integration process is performed, even if there are resources that become integration waiting, the source tenant is no longer necessary, and the options for disposal including its stop are expanded.
[0065] [Embodiment 2] In Embodiment 2, the behavior (process) of putting the integration in a waiting state when a duplication of the unique resource ID occurs in the creation of a new resource at the time of resource integration is different from that in Embodiment 1. In Embodiment 1, in such a case, a dummy resource is created in a temporary destination tenant within the destination service to integrate the resources, and the integration is put in a waiting state from the dummy resource of the temporary destination tenant to the destination resource of the waiting destination tenant.
[0066] On the other hand, in Embodiment 2, no temporary integration is performed, that is, no dummy resource is created, and the integration is put in a waiting state from the source tenant in the source service to the waiting destination tenant while retaining the data in the source tenant.
[0067] By using the form of Embodiment 1, all the data within the source service including during standby can be moved to the destination service, so that the source service can be stopped immediately after integration. Therefore, the management and operation costs can be reduced.
[0068] On the other hand, by using the form of Embodiment 2, the amount of data transfer during integration is reduced, so that the integration execution time can be shortened. Considering the case of stopping the service to prevent data inconsistency during integration, since the integration execution time directly becomes the service downtime, the merit of shortening the integration execution time is significant. Hereinafter, only the parts different from Embodiment 1 will be described for Embodiment 2.
[0069] FIG. 9 is a diagram showing the flow of resource integration processing (S604) that appears during the service integration processing flow by the integration execution server 103 in FIG. 6. In this embodiment, the procedure in FIG. 9 is executed instead of FIG. 7 of Embodiment 1.
[0070] The command creation unit 501 creates an acquisition command for destination resources and transmits it to the destination service providing server 102 (S900-1). At this time, the unique resource ID of the source resource is specified for the resources to be acquired. Thereby, if there is a corresponding resource, for example, the resource management information thereof is responded. If not, a response indicating that there is no corresponding resource is given.
[0071] It is determined whether a resource in the integration destination service having the unique resource ID of the target integration source resource has been acquired (S900-2). If acquired, the command creation unit 501 creates a resource creation command for the integration destination service and sends it to the integration destination service providing server 102. As a result, a resource is created in the integration destination tenant (S902). At this time, the unique resource ID of the target integration source resource is specified for the resource to be created. The created resource is designated as the integration destination resource. Thereafter, the command creation unit 501 creates a resource data acquisition command for the target integration source resource and sends it to the integration source service providing server 101 to acquire the resource data of the target integration source resource (S903). The command creation unit 501 creates a resource data save command for the integration destination resource and sends it to the integration destination service providing server 102 to save it as resource data of the integration destination resource (S904).
[0072] If a resource in the integration destination service having the unique resource ID of the target integration source resource can be acquired (S900-1-Yes), the acquired resource is set as the integration destination resource, and the tenant that owns the integration destination resource is confirmed (S901).
[0073] If the tenant that owns the integration destination resource is the integration destination tenant (S901-Yes), the command creation unit 501 creates a resource data acquisition command for the integration source resource. This is sent to the integration source service providing server 101 to acquire the resource data of the integration source resource (S903). The command creation unit 501 creates a resource data save command for the integration destination resource and sends it to the integration destination service providing server 102 to save it as resource data of the integration destination resource (S904). Note that steps S900-1 to S904 are the same processes as steps S700-1 to S704 in FIG. 7.
[0074] After step S902, the process may proceed to step S901 instead of step S903. Even in this case, the determination result in step S901 will ultimately be affirmative, so the process will branch to step S903.
[0075] On the other hand, if the tenant that owns the destination resource is not the destination tenant (S901-No), the destination resource is set as a waiting destination resource. Also, the tenant that owns the waiting destination resource is set as a waiting destination tenant.
[0076] The process (S905 to S907) is performed to put the integration of the target integration source resource into the waiting integration destination resource into a waiting state.
[0077] The temporary authentication information creation unit 502 creates temporary authentication information linking the integrating-source tenant, the waiting integration-target tenant, and the unique resource ID of the integrating-source resource (S905). The temporary authentication information is notified to the administrator of the integrating-source tenant of interest (S906). The temporary authentication information management unit 503 saves the created temporary authentication information (S907). S905-S907 are almost the same as S708-S710 in Fig. 7, but differ from S709 in that the notification destination of the temporary authentication information in step S906 is the integrating-source tenant.
[0078] An example of management information for temporary authentication information is shown below. In this example, the temporary integration destination tenant in the management information of Example 6 is replaced with the integration source tenant.
[0079] Example 7. Example 2 Temporary authentication information management information example Waiting | Temporary Credentials | Source Tenant | Unique Resource ID Integrating destination tenant| | | AFT0040 | Ljg432hfhew84GtO | BEF0022 | RSC0014 AFT0065 | p46JLoImEh6G65d2 | BEF0045 | RSC0030 Note that when the combination of the integration-source tenant and the waiting integration-target tenant is the same, the temporary authentication information may be the same regardless of the value of the unique resource ID.
[0080] FIG. 10 is a diagram showing a processing flow when integrating resources that have entered an integration standby state in the resource integration processing of FIG. 9. Execution of the standby integration processing is started when the temporary authentication information notified to the integration source tenant in S906 is transmitted by a user of the standby integration-target tenant (S1000). The transmission may be performed on a screen logged in as a user of the standby integration-target tenant. FIG. 12(A) shows an example of the display of migration information on a screen after login of the standby integration-target tenant. FIG. 12(B) shows an example of a temporary authentication information transmission screen in the standby integration-target tenant. Note that if there are multiple resources corresponding to the input temporary authentication information, the integration of multiple resources may be performed consecutively.
[0081] If the input temporary authentication information is not associated with the waiting integration-target tenant (S1001), an error response is returned indicating an input error (S1004), and the waiting integration process is terminated without being executed. If the input temporary authentication information is associated with the waiting integration-target tenant (S1001), it is determined that authentication between the target integration-source tenant of interest and the input waiting integration tenant has been successful, and the waiting integration process (S1002 to S1003) is executed. The command creation unit 501 creates a resource data acquisition command for the target integration-source resource and transmits it to the integration-source service providing server 101 to acquire the resource data of the target integration-source resource (S1002). The command creation unit 501 creates a resource data save command for the waiting integration-target resource and transmits it to the integration-target service providing server 102 to save it as resource data of the waiting integration-target resource (S1003).
[0082] The processing in FIG. 10 differs from that in FIG. 8 in the first embodiment in that the source of resource data is the integration source resource of interest and that dummy resources are not deleted, but is otherwise the same.
[0083] According to the present embodiment described above, the processing time for the tenant integration process can be reduced, the utilization rate of the tenants can be increased, and the resources required by the service providing server at the integration destination can be reduced.
[0084] [Other embodiments] In the above first and second embodiments, tenant integration is used as an example of the process, but the same applies to tenant migration processing. In that case, "integration" in the embodiments is replaced with "migration." That is, "source service" is replaced with "source service," and "target service" is replaced with "target service." "Source tenant" is replaced with "source tenant," and "target tenant" is replaced with "target tenant." Furthermore, "source resource" is replaced with "source resource," and "target resource" is replaced with "target resource."
[0085] Furthermore, the "integration" in the first and second embodiments can also be understood as a process of integrating or consolidating tenants by migrating multiple source tenants to one destination tenant, for example.
[0086] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.
[0087] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]
[0088] 101 integrating source service providing server, 102 integrating destination service providing server, 103 integrating execution server
Claims
1. An information processing system for migrating a source tenant, which is a tenant of a source service, to a destination tenant, which is a tenant of a destination service corresponding to the source tenant, comprising: a first determination means for determining the presence or absence of the destination tenant corresponding to the source tenant; a tenant creation means for newly creating the destination tenant when it is determined that the destination tenant does not exist; a second determination means for determining whether a destination resource having the same ID as the source resource included in the source tenant is included in the tenant of the destination service; a resource creation means for newly creating the destination resource in the destination tenant when it is determined that the destination resource is not included in the tenant of the destination service; a migration means for migrating the resource data of the source resource to the destination resource, wherein the migration means: if the tenant including the destination resource is the destination tenant, directly migrates the resource data of the source resource to the destination resource; if the tenant including the destination resource is not the destination tenant, migrates the resource data of the source resource to the destination resource via a dummy resource created in the destination tenant An information processing system characterized by the above.
2. The information processing system according to claim 1, wherein the migration means waits for the migration of the resource data from the source resource to the destination resource if the tenant including the destination resource is not the destination tenant. An information processing system characterized by the above.
3. The information processing system according to claim 2, wherein the migration means sends a notification of the waiting state to the source tenant when the migration of the resource data enters the waiting state. An information processing system characterized by the above.
4. The information processing system according to claim 3, wherein the notification further includes an inquiry as to whether to perform the migration of the resource data in the waiting state. An information processing system characterized by the above.
5. The information processing system according to claim 4, wherein when it is selected to perform the migration of the resource data in response to the inquiry, authentication information for authenticating and resuming the migration process of the resource data is transmitted to the source tenant in the waiting state. An information processing system characterized by the following.
6. The information processing system according to claim 3, wherein the notification further includes authentication information for authenticating and resuming the transfer process of the resource data to the source tenant. An information processing system characterized by the following.
7. The information processing system according to claim 5 or 6, wherein when the authentication information is input on the management screen of the tenant including the destination resource for the transfer of the resource data in the waiting state, the transfer of the resource data of the source resource in the waiting state is performed. An information processing system characterized by the following.
8. The information processing system according to any one of claims 2 to 7, wherein if the tenant including the destination resource is not the destination tenant, the transfer means transfers the resource data of the source resource to a dummy resource created in the destination tenant, and then waits for the transfer of the resource data from the source resource to the destination resource, and transfers the resource data from the dummy resource to the destination resource and the resource data in response to the authentication of the transfer of the resource data in the waiting state. An information processing system characterized by the following.
9. An information processing system for transferring a source tenant, which is a tenant of a source service, to a destination tenant, which is a tenant of a destination service corresponding to the source tenant, comprising: a first determination means for determining the presence or absence of the destination tenant corresponding to the source tenant; a tenant creation means for newly creating the destination tenant when it is determined that there is no destination tenant; a second determination means for determining whether a destination resource having the same ID as the source resource included in the source tenant is included in the tenant of the destination service; a resource creation means for newly creating the destination resource in the destination tenant when it is determined that the destination resource is not included in the tenant of the destination service; and a transfer means for transferring the resource data of the source resource to the destination resource, wherein if the tenant including the destination resource is not the destination tenant, the transfer means transfers the resource data of the source resource to the destination resource in response to authentication by an administrator. An information processing system characterized by the following.
10. The information processing system according to claim 9, wherein when the migration means migrates the resource data of the source resource to the destination resource in response to authentication by an administrator, the resource data of the source resource is migrated to the destination resource via a dummy resource created in the destination tenant An information processing system characterized by the above.
11. An information processing method in an information processing system that migrates a source tenant, which is a tenant of a source service, to a destination tenant, which is a tenant of a destination service corresponding to the source tenant, comprising: a first determination means for determining the presence or absence of the destination tenant corresponding to the source tenant; a tenant creation means for newly creating the destination tenant when it is determined that the destination tenant does not exist; a second determination means for determining whether a destination resource having the same ID as the source resource included in the source tenant is included in the tenant of the destination service; a resource creation means for newly creating the destination resource in the destination tenant when it is determined that the destination resource is not included in the tenant of the destination service; a migration means, if the tenant including the destination resource is the destination tenant, directly migrating the resource data of the source resource to the destination resource; if the tenant including the destination resource is not the destination tenant, migrating the resource data of the source resource to the destination resource via a dummy resource created in the destination tenant An information processing method characterized by the above.
12. An information processing method in an information processing system that migrates a source tenant, which is a tenant of a source service, to a destination tenant, which is a tenant of a destination service corresponding to the source tenant, comprising: a first determination means for determining the presence or absence of the destination tenant corresponding to the source tenant; a tenant creation means for newly creating the destination tenant when it is determined that the destination tenant does not exist; a second determination means for determining whether a destination resource having the same ID as the source resource included in the source tenant is included in the tenant of the destination service; When the resource creation means determines that the destination resource is not included in the tenant of the destination service, the destination resource is newly created in the destination tenant, the migration means migrates the resource data of the source resource to the destination resource, if the tenant including the destination resource is not the destination tenant, the migration means migrates the resource data of the source resource to the destination resource in response to authentication by an administrator An information processing method characterized by the above.
Citation Information
Patent Citations
Image processing controller
JP1992296986A
Information processing apparatus, information processing method, and program
JP2013254304A
Management system and control method therefor
JP2015210653A
Server system and method for controlling multiple service systems
JP2018022501A
Information processing apparatus, information processing system, and integration method
JP2019121092A