Access Control Systems

The access management system uses a specific ID management server and TEE to manage and update identity and access conditions on a blockchain, addressing unnecessary dissemination and enhancing security by only notifying relevant parties of updates related to access conditions.

JP7719313B2Active Publication Date: 2025-08-05FUJIFILM CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2024548127
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-09-21
Filing Date
2023-08-10
Publication Date
2025-08-05
Estimated Expiration
2043-08-10

AI Technical Summary

Technical Problem

Existing access management systems face issues with unnecessary dissemination of identity information and access conditions during updates, leading to increased management costs and security risks.

Method used

An access management system utilizing a specific ID management server, a data store terminal, and a trusted execution environment (TEE) to manage and update identity information and access conditions, with updates being recorded on a blockchain and compared within the TEE to determine relevance to access conditions before notifying relevant parties.

Benefits of technology

Prevents unnecessary dissemination of identity and access information by only notifying relevant parties of updates related to access conditions, thereby reducing management costs and enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007719313000001
    Figure 0007719313000001
  • Figure 0007719313000002
    Figure 0007719313000002
  • Figure 0007719313000003
    Figure 0007719313000003
Patent Text Reader

Abstract

Provided is an access management system capable of preventing unnecessary spreading of information. When identity information (30) is updated, the update content (updated identity information (30)) is stored on a blockchain (70). Further, when the identity information (30) is updated, it is determined in a TEE (80) whether or not the update content is related to access conditions (42). Then if it is determined that the update content is related to the access conditions (42), a data store terminal (14) is notified that the update has been performed.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an access control system. [Background technology]

[0002] In an access management system, identity information is compared with access conditions to determine whether or not access is permitted. Patent Document 1 below also describes a configuration in which identity information managed by a third party can be used. This reduces the management costs of identity information. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Special Publication No. 2021-528722 Summary of the Invention [Problem to be solved by the invention]

[0004] However, the above-mentioned Patent Document 1 has a problem in that information is unnecessarily spread when identity information is updated. In other words, when identity information is updated, the identity information manager needs to notify the access management side of the details of the update, and the access management side needs to change (update) the access conditions based on the notification. However, notifying the access management side of updates unrelated to the access conditions leads to unnecessary spread of identity information. Furthermore, disclosing the access conditions to the identity information manager in order to notify only of updates related to the access conditions leads to unnecessary spread of the access conditions.

[0005] The present invention has been made in view of the above background, and has as its object to provide an access management system that can prevent unnecessary dissemination of information. [Means for solving the problem]

[0006] In order to solve the above problem, an access management system includes a data store terminal that compares the identity information of a user who has made an access request with access conditions to determine whether to grant access, a specific ID management server that stores the identity information of specific users who belong to a specific group, and at least one processor, wherein the data store terminal accepts access requests from specific users using the identity information stored in the specific ID management server. In the access management system, the processor updates the identity information stored in the specific ID management server, and when an update is made, stores the content of the update on a blockchain. When an update is made, in a trusted execution environment (TEE) that is independent of the operating system (OS) of the data store terminal and the OS of the specific ID management server, compares the content of the update with the access conditions to determine whether the update is related to the access conditions, and when it is determined that the update is related, notifies the data store terminal that the update has been made.

[0007] Preferably, the processor notifies the data store terminal of the content of the update.

[0008] Preferably, the processor notifies the data store terminal of the entire contents of the update.

[0009] Preferably, the processor notifies the data store terminal of only those parts of the update that are relevant to the access conditions.

[0010] The access conditions may be stored in a data store terminal.

[0011] The access conditions may be stored in a terminal separate from the data store terminal.

[0012] Preferably, at least one of the processors is provided in a specific ID management server, and the processor provided in the specific ID management server updates the identity information.

[0013] It is preferable that the processor updates the access conditions and stores the contents of the updated access conditions on the blockchain, and when the access conditions are updated, the TEE compares the contents of the updated access conditions with the identity information to determine whether the change in the access conditions is related to the identity information, and if it is determined that the change in the access conditions is related, notifies the specific ID management server that the access conditions have been changed. [Effects of the Invention]

[0014] According to the present invention, it is possible to provide an access control system that can prevent unnecessary dissemination of information. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a schematic diagram illustrating a configuration of an access control system. [Figure 2] FIG. 10 is an explanatory diagram of identity information. [Figure 3] FIG. 2 is an explanatory diagram of a data area. [Figure 4] FIG. 10 is an explanatory diagram of an access condition. [Figure 5] FIG. 10 is an explanatory diagram showing an example of updating identity information related to access conditions. [Figure 6] FIG. 10 is an explanatory diagram showing an example of updating an access condition. [Figure 7] FIG. 10 is an explanatory diagram showing an example of updating identity information not related to access conditions. [Figure 8] FIG. 1 is a schematic diagram illustrating a configuration of an access control system. [Figure 9] 3 is a flowchart showing a processing flow in the first embodiment. [Figure 10] FIG. 1 is a schematic diagram illustrating a configuration of an access control system. [Figure 11] 10 is a flowchart showing a processing flow according to a second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0016] [First embodiment] In FIG. 1, an access management system 10 of the present invention includes a specific ID management server 12 and a data store terminal 14.

[0017] The specific ID management server 12 stores identity information 30 indicating the identities of users (specific users) 21, 22, and 23 who belong to a specific group 20. The specific group 20 is a grouping of users (specific users 21, 22, and 23) who have a specific commonality; in this example, the specific group 20 is "Company A," and the specific users 21, 22, and 23 are "employees of Company A." In addition, in FIG. 1, reference numerals 31, 32, and 33 indicate the terminals of the specific users 21, 22, and 23, respectively.

[0018] As shown in FIG. 2, the identity information 30 associates information about the identity of each of the specific users 21, 22, and 23, employees of Company A, in this example, "Fuji Taro," "Fuji Jiro," and "Fuji Hanako," such as their name, department, employment status, job title, and year of joining the company. This identity information 30 is managed by the specific group 20, i.e., "Company A." Specifically, the process of updating the identity information 30, such as adding members due to new hires, removing members due to retirement, and changing departments due to reassignment, is carried out as appropriate under the management of Company A.

[0019] 1, the data store terminal 14 stores a data area 40 in which various data is stored, and access conditions 42 that indicate conditions for accessing the data area 40. As shown in Fig. 3, the data area 40 is further divided into a plurality of areas, such as a first area 51 and a second area 52.

[0020] 4, the access condition 42 is set for each area of the data area 40. In this embodiment, the access condition 42 for the first area 51 is set to "be an employee of Company A and be a section manager or higher." The access condition 42 for the second area 52 is set to "be an employee of Company A and belong to the development department."

[0021] Returning to FIG. 1, when a specific user 21 (e.g., "Fuji Taro") who is an employee of Company A wishes to access data area 40, he / she uses his / her own identity information 30 stored in the specific ID management server 12 to send an access request to data area 40 from his / her own terminal 31 to data store terminal 14. When data store terminal 14 receives this access request, it compares the identity information 30 of the person who made the access request (e.g., "Fuji Taro") with access conditions 42 to determine whether access is permitted, and permits access to areas determined to be accessible. For example, if the person who made the access request is "Fuji Taro" shown in FIG. 2, it is determined that access to second area 52 is permitted, as shown in FIG. 4, and access to second area 52 is permitted.

[0022] In this way, in the access management system 10, the data store terminal 14 determines whether access is permitted using identity information 30 managed by a third party (in this embodiment, "Company A"). This reduces the management costs of identity information 30 compared to when identity information is created and managed independently by the data store terminal 14 and used to determine whether access is permitted.

[0023] In this example, the specific group 20 is "Company A," that is, the specific user is an employee of Company A. However, the present invention is not limited to this. For example, the specific group may be formed by further subdividing a single company (group), such as the sales department of Company A, managers at the level of section manager or above in the sales department of Company A, employees in the sales department of Company A who have been with the company for more than three years, or full-time employees in the sales department of Company A who have been with the company for more than three years. Furthermore, the specific group does not necessarily have to be a concept that includes organizational groups such as a company, but may also be a collection that meets certain requirements, that is, a group gathered from the perspective of a specific age group, gender, qualifications, role, work location, etc.

[0024] Furthermore, in this example, an access request is made to the data store terminal 14 from only one specific group 20 (Company A), but the present invention is not limited to this. A configuration in which access requests are made to the data store terminal 14 from multiple specific groups, such as Company B, Company C, and Company D, may also be used. In this case, a specific ID management server may be provided for each specific group, and each specific ID management server may manage the identity information of the users (specific users) of the corresponding specific group. Alternatively, one ID management server may be provided for multiple specific groups, and the identity information may be managed by this single ID management server. Furthermore, as described above, multiple ID management servers may be provided to manage the identity information of multiple specific groups.

[0025] In addition, in this example, the specific ID management server 12 is provided within Company A, but the specific ID management server 12 may also be provided outside Company A. Also, the identity information 30 is stored within the specific ID management server 12, but the identity information 30 may also be stored outside the specific ID management server 12. Furthermore, although an example has been described in which the access conditions 42 are stored within the data store terminal 14, the access conditions 42 may also be stored outside the data store terminal 14.

[0026] As described above, in the access management system 10, the data store terminal 14 uses the identity information 30 managed by a third party, "Company A," thereby reducing the management costs of the identity information 30. However, this alone may result in unnecessary dissemination of information.

[0027] In other words, when there is a change in the identity information 30, it may be necessary to change the access conditions 42 on the data store terminal 14 side accordingly. Specifically, when, for example, the information shown in FIG. 5 is added as identity information 30 due to circumstances such as the addition of a part-time employee to the development department of Company A, it may be necessary to change the access conditions 42 on the data store terminal 14 side, for example, as shown in FIG. 6, so that access to the second area 52 is not permitted to anyone other than a full-time employee in the development department. In consideration of such a case, when the identity information 30 is changed, it is preferable to notify the data store terminal 14 side of the change.

[0028] On the other hand, for example, if the information shown in FIG. 7 is added to the identity information 30 due to circumstances such as the assignment of a new graduate employee to the sales department of Company A, there is no need to change the access condition 42 because this change does not affect the access condition 42. However, sending the above-mentioned notification even in such a case would cause unnecessary spread of the identity information 30. In addition, in order to prevent unnecessary spread of the identity information 30, it is also possible for the data store terminal 14 to disclose the access condition 42 to Company A and send the above-mentioned notification only when a change related to the access condition 42 has occurred, but this would cause unnecessary spread of the access condition 42.

[0029] Taking these circumstances into consideration, the access management system 10 is provided with a processor 60 as shown in Fig. 8. The processor 60 functions as an identity information update unit 62, an update history maintenance unit 64, and an update content notification unit 66 in conjunction with the execution of an update program for changing identity information and access conditions. The update program is started (executed) in conjunction with the start of update processing, for example, by launching update software for changing identity information and access conditions from a terminal under the management of Company A, such as the specific ID management server 12 or terminals 31, 32, and 33.

[0030] The processor 60 may be a single terminal itself (or a part of such a single terminal), such as the specific-ID management server 12, the terminals 31, 32, 33, the data store terminal 14, or a dedicated terminal provided separately from these, but the present invention is not limited to an example in which the processor 60 is configured from a single terminal (the terminal itself or a part thereof). A configuration may also be adopted in which a plurality of such terminals (the terminals themselves or parts thereof) are gathered together and function as the processor 60 in cooperation with each other.

[0031] The identity information update unit 62 accepts edits to the identity information 30 via a user interface (UI) of update software for updating the identity information and access conditions, and updates the identity information 30 based on the edits. Note that although the processor 60 has been described as functioning as the identity information update unit 62, the present invention is not limited to this. The specific ID management server 12 or the terminals 31, 32, and 33 may also be configured to function as the identity information update unit 62.

[0032] When the identity information 30 is updated, the update history maintenance unit 64 stores the details of the update (the updated identity information 30) on the blockchain 70. The blockchain 70 is constructed by a blockchain network made up of the specific ID management server 12, the data store terminal 14, etc., and is a chronological linking of blocks 71, each containing the updated identity information 30 and a hash value obtained by hashing the identity information 30 immediately before the update. The update history maintenance unit 64 generates a new block 71 every time the identity information 30 is updated and links this to the blockchain 70. By storing the identity information 30 on the blockchain 70 in this way, it is possible to prevent tampering with the identity information 30.

[0033] Although the example in which block 71 is constructed from the updated identity information 30 and a hash value obtained by hashing the identity information 30 immediately before the update has been described, the present invention is not limited to this. Block 71 may also be constructed from two hash values: a hash value obtained by hashing the updated identity information 30 and a hash value obtained by hashing the identity information 30 immediately before the update.

[0034] When the identity information 30 is updated, the update content notification unit 66 determines whether the content of the update is related to the access condition 42. In this determination, the update content notification unit 66 compares the accessibility status of each user when the identity information 30 immediately before the update is used (such as the number of users who satisfy the access condition 42 for each area in the data area 40) with the accessibility status of each user when the updated identity information is used, and if there is a change in the accessibility status before and after the update, it determines that the update content is related to the access condition 42, and if there is no change in the accessibility status before and after the update, it determines that the update content is not related to the access condition 42.

[0035] For example, if a change (update) is made to the identity information 30 shown in FIG. 2 by adding the information shown in FIG. 5, this update will increase the number of users who can access the second area 52 of the data store terminal 14 (see FIG. 4). Therefore, this update is determined to be related to the access condition 42. On the other hand, if a change (update) is made to the identity information 30 shown in FIG. 2 by adding the information shown in FIG. 7, this update will not change the number of users who can access any area of the data store terminal 14 (see FIG. 4). Therefore, this update is determined not to be related to the access condition 42.

[0036] The update content notification unit 66 performs the above-mentioned determination in a trusted execution environment (TEE) 80 that is independent of the operating systems (OS) of the terminals (such as the specific ID management server 12, terminals 31, 32, and 33, and the data store terminal 14) that constitute the access management system 10. Note that, like the processor 60, the TEE 80 may be formed in one terminal (the terminal itself or a part thereof), or may be formed by a group of such terminals (the terminals themselves or parts thereof) working together to form the TEE 80. Furthermore, the processing performed by the TEE 80 is not limited to the above-mentioned determination. Processing other than the above-mentioned determination that is performed in the access management system 10 or the processor 60 may also be performed by the TEE 80.

[0037] If it is determined that the update content is related to the access condition 42, the update content notification unit 66 notifies the data store terminal 14 that an update has been made. The update content may also be notified to the data store terminal 14 in synchronization with this notification. When notifying the update content, the entire update content (all of the changed identity information 30) may be notified, or only the part of the update content that is related to the access condition 42 may be extracted and notified.

[0038] The flow of processing performed by the processor 60 will be described below with reference to Fig. 9. As shown in Fig. 9, when the identity information 30 is updated, the details of the update (the updated identity information 30) are stored on the blockchain 70. Furthermore, when the identity information 30 is updated, the TEE 80 determines whether the details of the update are related to the access condition 42. Then, when it is determined that the details of the update are related to the access condition 42, the data store terminal 14 is notified that the update has been performed.

[0039] In this way, according to the access management system 10, only when it is determined that the updated content of the identity information 30 is related to the access condition 42, a notification is sent to the data store terminal 14, thereby preventing unnecessary dissemination of the identity information 30. Furthermore, because the determination of whether the updated content is related to the access condition 42 is performed by the TEE 80, unnecessary dissemination of not only the identity information 30 but also the access condition 42 can be prevented.

[0040] [Second embodiment] In the first embodiment, the configuration when the identity information 30 is updated is described, but in the second embodiment, the configuration when the access condition 42 is updated is described. In the following description, the same components as those in the first embodiment are denoted by the same reference numerals and description thereof is omitted.

[0041] 10, in the second embodiment, in conjunction with the execution of an update program for changing the identification information and access conditions, the processor 60 functions as an access condition update unit 90 in addition to the above-described identification information update unit 62, update history maintenance unit 64, and update content notification unit 66. The update program is started (executed) in conjunction with the start of update processing, for example, by launching update software for changing the identification information and access conditions from the data store terminal 14 or the like.

[0042] The access condition update unit 90 accepts edits to the access conditions 42 via a user interface (UI) of update software for changing identity information or access conditions, and updates the access conditions 42 based on the edited content. Note that although the processor 60 has been described as functioning as the access condition update unit 90, the present invention is not limited to this. The data store terminal 14 may also be configured to function as the access condition update unit 90.

[0043] In the second embodiment, when the access conditions 42 are changed (updated), the update history maintenance unit 64 stores the updated contents (updated access conditions 42) on the blockchain 70. By storing the access conditions 42 on the blockchain 70 in this way, it is possible to prevent tampering with the access conditions 42. Note that although an example has been described in which the updated contents of the access conditions 42 and the updated contents of the identity information 30 are stored on a common blockchain 70, the updated contents of the access conditions 42 may also be stored on a blockchain different from the blockchain 70 that stores the updated contents of the identity information 30.

[0044] Furthermore, in the second embodiment, when the access conditions 42 are changed (updated), the update content notification unit 66 determines in the TEE 80 whether the update content is related to the identity information 30. Specifically, the access permission status of each user to the data area 40 is compared before and after the change of the access conditions 42, and if there is a change in the access permission status, it is determined that the update content is related to the identity information 30, and if there is no change in the access permission status before and after the update, it is determined that the update content is not related to the identity information 30.

[0045] If the update content notification unit 66 determines that the update content is related to the identity information 30, it notifies the specific ID management server 12 and terminals 31, 32, 33, and other terminals under the management of Company A, that an update has been made. The update content may also be notified in synchronization with this notification. When notifying the update content, all of the update content (all of the changed access conditions 42) may be notified, or only the part of the update content that is related to the identity information 30 may be extracted and notified.

[0046] The processing flow of the second embodiment will be described below with reference to Fig. 11. As shown in Fig. 11, when the access conditions 42 are updated, the updated contents (updated access conditions 42) are stored on the blockchain 70. Furthermore, when the access conditions 42 are updated, the TEE 80 determines whether the updated contents are related to the identity information 30. Then, if it is determined that the updated contents are related to the identity information 30, the fact that the update has been performed is notified to the specific ID management server 12 and terminals 31, 32, 33, and other terminals under the management of Company A.

[0047] In the above embodiment, the hardware structure of the processing units that execute various processes, such as the identification information update unit 62, update history maintenance unit 64, update content notification unit 66, and access condition update unit 90, is the following various processors: The various processors include a CPU (Central Processing Unit), which is a general-purpose processor that executes software (programs) to function as various processing units, a programmable logic device (PLD), such as an FPGA (Field Programmable Gate Array), whose circuit configuration can be changed after manufacture, and a dedicated electrical circuit, which is a processor with a circuit configuration designed specifically for executing various processes.

[0048] A single processing unit may be configured with one of these various processors, or may be configured with a combination of two or more processors of the same or different types (for example, multiple FPGAs, or a combination of a CPU and an FPGA). Also, multiple processing units may be configured with a single processor. Examples of multiple processing units configured with a single processor include, first, a configuration in which one processor is configured with a combination of one or more CPUs and software, as typified by client or server computers, and this processor functions as multiple processing units. Second, a configuration in which a processor is used to realize the functions of an entire system including multiple processing units on a single IC (Integrated Circuit) chip, as typified by a System on Chip (SoC). In this way, the various processing units are configured with one or more of the above-mentioned various processors as a hardware structure.

[0049] Furthermore, the hardware structure of these various processors is, more specifically, an electric circuit in the form of a combination of circuit elements such as semiconductor elements. [Explanation of symbols]

[0050] 10. Access Control Systems 12 Specific ID management server 14 Data store terminal 20 Specific Groups 21, 22, 23 Specific users 30 Identification Information 31, 32, 33 terminals 40 Data Area 42 Access Conditions 51 First area 52 Second area 60 processors 62 Identity Update Department 64 Update History Maintenance Department 66 Update content notification section 70 Blockchain 71 blocks 80 TEE 90 Access condition update section

Claims

1. a data store terminal that checks the identity information of a user who has made an access request against access conditions to determine whether or not to grant access; a specific ID management server that stores identification information of specific users who belong to a specific group; at least one processor; In an access management system, the data store terminal accepts an access request from the specific user using identification information stored in the specific ID management server, The processor: Update the identity information stored in the specific ID management server, When the update is made, the content of the update is stored on the blockchain; When the update is made, an access management system compares the contents of the update with the access conditions in a trusted execution environment (TEE) that is independent of the operating system (OS) of the data store terminal and the OS of the specific ID management server to determine whether the update is related to the access conditions, and if it is determined that the update is related, notifies the data store terminal that the update has been made.

2. The access management system according to claim 1 , wherein the processor notifies the data store terminal of the content of the update when it is determined that the content of the update is related to the access condition.

3. The access management system according to claim 2 , wherein the processor notifies the data store terminal of all of the contents of the update.

4. The access management system according to claim 2 , wherein the processor notifies the data store terminal of only a portion of the content of the update that is related to the access condition.

5. The access management system according to claim 1 , wherein the access conditions are stored in the data store terminal.

6. The access management system according to claim 1 , wherein the access conditions are stored in a terminal separate from the data store terminal.

7. At least one of the processors is provided in the specific ID management server, The access management system according to claim 1 , wherein the processor provided in the specific ID management server updates the identity information.

8. The processor: updating the access conditions; Storing the updated content of the access conditions on the blockchain; When the access conditions are updated, the TEE compares the contents of the update of the access conditions with the identity information to determine whether the change in the access conditions is related to the identity information, and if it is determined that the change in the access conditions is related, notifies the specific ID management server that the access conditions have been changed. The access control system according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • User information management device, user information management method, and user information management program

    JP2014056550A

  • Information management device, method for managing information, and information management program

    JP2019175374A

  • Declarative Third-Party Identity Provider Integration for Multi-Tenant Identity Cloud Services

    JP2021528722A