Information processing method, program, and storage medium
The described method addresses the complexity and cost issues of managing multiple PCs by dynamically applying access control policies based on user and task context, ensuring secure and efficient resource access through API capture technology, thereby enhancing security and reducing operational costs.
Patent Information
- Application Number
- JP2023576459
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-01-26
- Publication Date
- 2025-08-07
- Estimated Expiration
- 2042-01-26
AI Technical Summary
Existing methods for managing access to network resources in diverse work environments increase complexity and costs due to the need for multiple physical and virtual PCs, complicating user management and security, particularly in handling confidential information and preventing cyberattacks.
An information processing method that dynamically selects and applies access control policies based on user and task context, using API capture technology to monitor and control resource access requests through a resource management program, ensuring access rights are granted or denied based on predefined isolation policies.
This approach enables flexible and efficient access control for network resources, reducing complexity and costs while maintaining security, allowing seamless transitions between different work scenarios without compromising convenience.
Smart Images

Figure 0007720421000001 
Figure 0007720421000002 
Figure 0007720421000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing method, a program, and a storage medium for controlling access to network resources. [Background technology]
[0002] Conventionally, it has become common for each employee to be provided with a personal computer (PC) in the business of a company, etc. From the viewpoint of security when using a PC, there is known a technology that uses an existing OS (Operating System) and processes to restrict the operation of resources by users who do not have access rights to computer resources (Patent Document 1).
[0003] As the nature of work at companies and other organizations becomes more diverse, security is increasingly driving the use of multiple PCs for different tasks. For example, using the same PC for tasks involving highly confidential company information, tasks that use the Internet, or tasks performed while teleworking raises concerns about the risk of internal information leaks and cyberattacks. For this reason, some companies use separate PCs, each with its own operating environment, including accessible storage space and available networks, depending on the task. In practice, separate operating environments for different tasks can be achieved by using multiple physical PCs or by using a single PC with a Virtual Desktop Infrastructure (VDI) or virtual PC. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2011-175649 Summary of the Invention [Problem to be solved by the invention]
[0005] On the other hand, preparing separate physical and virtual PCs for each business task entails an increase in assets to be managed (PCs themselves, operating systems, and other software), the complexity of using multiple PCs, and various costs. Furthermore, while it is possible to physically separate access terminals using conventional virtualization technology to separate physically existing network resources depending on the user and task, achieving sufficient separation requires preparing many virtual machines. Furthermore, when separating file servers, for example, one approach would be to prepare multiple user accounts for different tasks and use them at the login stage, but this complicates user management. In either case, convenience is compromised and overall costs can increase.
[0006] The present invention has been made in view of the above-mentioned problems, and an object of the present invention is to realize extended access control for network resources available to workers in accordance with the usage situation of the workers. [Means for solving the problem]
[0007] According to the present invention, 1. An information processing method for controlling access to computer resources on a network resource from a communication device used by a user, comprising: a selection step of selecting a policy suitable for the state of the communication device from a plurality of policies that define access rights granted for each of a plurality of types of business as policies for each business; In the communication device, a first capturing step of capturing an operation request from a process or an operating system for a computer resource on the communication device before the computer resource is accessed; a first determination step of determining whether or not the user has access authority to the computer resource designated by the operation request acquired in the first acquisition step, based on information about the policy selected in the selection step; In the network resource, an acquisition step of acquiring information about a policy selected for the communication device; when receiving an access request for a computer resource on the network resource from the communication device, capturing an operation request from a process or an operating system for the computer resource on the network resource before accessing the computer resource. 2 a capture step; The above 2 determining whether or not there is an access right to the computer resource designated by the operation request captured in the capturing step based on the policy information acquired in the acquiring step; 2 A judgment process; The above 2 a processing step of transferring the operation request to the operating system as it is if the access right is determined as a result of the determination step, and returning the result to the request source; The above 2 a refusal step of refusing access to the computer resource designated by the operation request if the determination result of the determination step indicates that the access right is not granted; death, the first determination step and the second determination step perform different access controls based on information about the policy selected in the selection step; An information processing method is provided. [Effects of the Invention]
[0008] According to the present invention, it is possible to realize extended access control for network resources available to workers that is suited to the workers' usage situations, while utilizing the existing operating systems and processes of terminals and devices on the network. Other features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings, in which the same or similar elements are designated by the same reference numerals. [Brief explanation of the drawings]
[0009] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention. [Figure 1A] 1 is a diagram illustrating an example of the configuration of an access control system according to an embodiment of the present invention. [Figure 1B] FIG. 2 is a diagram illustrating an example of the functional configuration of a PC according to an embodiment of the present invention. [Figure 1C] FIG. 2 is a diagram illustrating an example of a functional configuration of a server according to an embodiment of the present invention. [Figure 2] FIG. 1 is a diagram illustrating a functional configuration of a resource management program and a relationship between an OS and applications, for explaining an API capture technology of an embodiment. [Figure 3] FIG. 10 is a diagram illustrating an example of the data configuration of an access permission management table for explaining an API capture technology according to an embodiment. [Figure 4] FIG. 1 is a sequence diagram showing a first basic type of API monitoring / control for explaining an API capture technique of an embodiment. [Figure 5] FIG. 10 is a sequence diagram showing a second basic type of API monitoring / control for explaining an API capture technique of an embodiment. [Figure 6A] FIG. 1 is a diagram (1) showing an example of an isolation policy according to an embodiment. [Figure 6B] FIG. 2 shows an example of an isolation policy according to an embodiment. [Figure 7] FIG. 10 is a diagram illustrating an operation of a terminal PC selecting a separation policy in one embodiment of the present invention. [Figure 8] FIG. 10 is a diagram illustrating an operation in which a server selects an isolation policy in an embodiment of the present invention. [Figure 9A] FIG. 1 is a diagram (1) illustrating an example of an isolation policy for isolating network resources in an embodiment of the present invention. [Figure 9B-1] FIG. 2 is a diagram (2-1) for explaining an example of an isolation policy for isolating network resources in one embodiment of the present invention. [Figure 9B-2] FIG. 2B is a diagram (2-2) for explaining an example of an isolation policy for isolating network resources in one embodiment of the present invention. [Figure 10] FIG. 10 is a diagram illustrating an example of an operation in which a separation policy is applied to a PC and a file server in one embodiment of the present invention. [Figure 11]A diagram showing the operation of a file server in an embodiment of the present invention executing access control processing.
Embodiment for Carrying Out the Invention
[0010] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims, and not all combinations of the features described in the embodiments are essential for the invention. Two or more of the plurality of features described in the embodiments may be arbitrarily combined. Also, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.
[0011] <Configuration of Access Control System> Referring to FIG. 1A, the configuration of an access control system 10 according to the present embodiment will be described. The access control system 10 includes a server 100 and a personal computer (PC) 102. The access control system 10 may further include a proxy 104. The server 100 and the PC 102 can communicate with each other via a network 106. The communication of the PC 102 may be connected to, for example, the Internet via the proxy 104 as necessary. The PC 102 is an example of a communication device. However, the communication device may be other terminals, such as a tablet terminal or a smartphone. The PC 102 provides appropriate access to internal resources and network resources for the user 101. The server 100 for controlling is an example of an information processing device, and for example, a file server for storing in-house file data is operating. The proxy 104 is an example of a communication device, and operates as a proxy server for controlling access when the PC 102 accesses the Internet.
[0012] <Example of Functional Configuration of PC> An example of the functional configuration of the PC 102 will be described with reference to Fig. 1B. The configuration shown in Fig. 1B shows functional blocks constituting a personal computer as an example of a communication device of this embodiment. Each of the functional blocks described may be integrated or separated, and the functions described may be realized by different blocks. Furthermore, what is described as hardware may be realized by software, and vice versa.
[0013] The communication unit 1201 includes, for example, a communication circuit and the like, and accesses the server 100 or the Internet via wireless communication such as a wireless LAN, and transmits and receives necessary data. The control unit 1202 includes a CPU 1210 and a RAM 1211, and controls the operation of each unit in the PC 102 by, for example, loading a computer program recorded in the recording unit 1207 into the RAM 1211 and executing it with the CPU 1210. The control unit 1202 also controls access to internal resources of the PC 102 and external network resources of the PC, which are input via, for example, the operation unit 1203, etc.
[0014] The operation unit 1203 may include input devices such as a keyboard, mouse, or touch panel provided in the PC 102, and accepts operations on GUIs for various operations displayed on the display unit 1206. The external IF 204 is an interface between a predetermined device such as a printer and the PC 102. The imaging device 205 is, for example, a camera device including an imaging element, and takes images in response to instructions from the control unit 1202. The display unit 1206 includes a display device such as an LCD or OLED, and displays, for example, the GUI for operations and data that the user has successfully accessed.
[0015] The recording unit 1207 includes a nonvolatile memory (nonvolatile storage medium) such as a semiconductor memory, and holds computer programs and setting values executed by the control unit 1202. It also stores data such as files created for the business of a company, etc. The computer programs stored in the recording unit 1207 include an operating system for realizing the various functions of the PC 102, various applications, and programs for executing various processes such as an access control program described below.
[0016] <Server configuration> Next, an example of the functional configuration of server 100 will be described with reference to Fig. 1C. Note that each of the functional blocks described may be integrated or separated, and the described functions may be realized by different blocks. Also, what is described as hardware may be realized by software, and vice versa.
[0017] The communication unit 1301 includes a communication circuit for communicating with the PC 102 via a network, and transmits information processed by the control unit 1302 to the PC 102, and receives information processed by the control unit 1302 from the PC 102.
[0018] The control unit 1302 includes a CPU 1310 and a RAM 1311. The CPU 1310 is a central processing unit. The control unit 1302 implements each function of the server 100 by causing the CPU 1310 to load a computer program stored in the recording unit 1304 into the RAM 1311 and execute the program. The RAM 1311 includes a volatile storage medium such as a DRAM, and temporarily stores parameters, processing results, and the like used by the control unit 1302 to execute the computer program.
[0019] The recording unit 1304 includes a non-volatile storage medium such as a hard disk or a semiconductor memory, and stores setting values and computer programs necessary for the operation of the server 100. Further, the recording unit 1304 stores data of various files related to business, which are uploaded from the PC 102, in the database 1330. The computer programs stored in the recording unit 1304 include an operating system for realizing various functions of the server 100, various applications, and programs for executing various processes such as an access control program described below, etc. The operation unit 1303 is an operation mechanism that can directly or remotely operate the server 100, and includes, in addition to a mouse and a keyboard, a configuration for receiving an operation instruction from an external device via communication. For example, an administrator of the server 100 performs several operations such as making necessary settings and inputting necessary information using the operation unit 1303.
[0020] Before explaining the separation of network resources according to this embodiment, two technologies for realizing this embodiment, namely, the API capture technology and the separation policy application technology, will be explained.
[0021] <API Capture Technology> First, the API capture technology will be explained. In this embodiment, the API capture technology is applied not only to the terminal (e.g., PC) used by the user, but also to, for example, a file server or network device (network resource) on the network. To explain the API capture technology more generally, the case where the API capture technology is applied to a general electronic device (e.g., PC) will be taken as an example. It is obvious to those skilled in the art that the API capture technology described below can be applied substantially in the same way between the operating systems and applications of file servers and network devices.
[0022] Generally, an application uses an API (Application Program Interface) provided by the OS to access resources managed by the OS. The method of using this API is determined by the OS, and it is possible to identify the executable code portion that uses the API. In this invention, a monitoring routine is provided to monitor all APIs required to access resources. Before an application uses an API, the executable code portion is modified or the API processing entry point is replaced with the monitoring routine, so that the monitoring routine is used when the API is used. The monitoring routine either processes the API required by the application, or does not process the API and returns a result to the application as an illegal command. The management of access rights extended by the resource management program of this invention is managed by this program separately from the OS, and monitoring routines are provided for each type of access right. This method restricts access from applications that use resources illegally.
[0023] More specifically, a resource management program intervening between an application and an operating system monitors and captures operation requests issued by an application for accessing a specified computer resource before the computer resource is accessed, and then determines whether or not access is permitted to the computer resource specified by the captured operation request based on an isolation policy summarizing computer access rights (described later), thereby restricting access.
[0024] Figure 2 is a diagram showing the configuration of the resource management program 203 and the concept of API monitoring / control related to the present invention, and the resource management program 203 is composed of an API monitoring controller (API monitoring CTRL) 2031, an APL (application) monitoring controller (APL monitoring CTRL) 2032, an access control controller (access control CTRL) 2033, and an OS monitoring controller (OS monitoring CTRL) 2034.
[0025] This resource management program 203 is located between a user environment 202 consisting of an application 2021 that issues resource access requests and general applications that have OS function operations 2022 such as screen capture, and a general-purpose OS 201, and is configured to monitor requests for resources provided by the general-purpose OS 201 and the user environment 202.
[0026] The general-purpose OS 201 includes resources 2011 managed by the OS and a set of APIs 2012 provided to an application 2021 by the OS.
[0027] The API monitoring CTRL 2031 in the resource management program 203 according to the present invention is a module that monitors all APIs required for access control. The APL monitoring CTRL 2032 is a module that stores resources held by the application 2021. The access control CTRL 2033 is a module that determines whether access to the resource 2011 is permitted, and includes an access permission management table 2035. The OS monitoring CTRL 2034 is a module that monitors operations for accessing resources using the functions of the general-purpose OS 201.
[0028] As shown in FIG. 3, the access permission management table 2035 is configured so that resource designation information 20351, conditions 20352, and n pieces of access permission information 20353 to 2035n can be registered for each resource.
[0029] The resource specification information 20351 is information for specifying a specific resource 2011 managed by the general-purpose OS 201. For example, in the case of a file, information such as the file name and file ID is registered. In the case of an application, for example, the program name is registered. In the case of communication data, in addition to the host name, port number, and IP address, a Bluetooth identifier and a Wi-Fi AP (access point) address are registered. In the case of memory, the object name and address indicating the object are registered. In addition, in the case of an external device, the device name indicating the device driver and a unique identifier called a device ID are registered.
[0030] The condition 20352 indicates the condition or combination of conditions under which the access authority is valid, and for example, a user name / ID, a group name / ID, a time, etc. are registered.
[0031] Access permission information 20353 to 2035n indicates the extended access permissions added to the specified resource, among the permissions not defined in the existing environment. Examples include permission to move to other media, permission to copy to other media, permission to print, permission to read from shared memory (such as the clipboard in Windows), permission to capture screens, and restrictions on the application used (prohibition of use by applications other than specific applications, prohibition of email attachments). Each permission can be registered for resources with both read and write capabilities. For example, a specific USB memory stick can be set to allow reading but not writing. Even when writing is permitted, encryption can be specified for writing, with the encryption key defined in the separation policy (separation policies are explained in detail later). Therefore, only separation policies with the same encryption key can read the information, enabling the separation of information that can be accessed effectively by separation policy. This specification is possible for resources with write permissions, such as files, USB devices, and clipboards. Communication resources also have information on connection (CONNECT) and acceptance (ACCEPT) in addition to reading (receiving) and writing (sending).
[0032] Generally, a resource may be accessed using multiple APIs, and in this case, the resource specification information may be converted into an ID (such as a handle) managed by the OS. In this case, the resource specification information and the ID are considered to be the same within the resource management program 203.
[0033] The processing of the resource management program 203 according to this configuration will be explained according to the information transmission procedure shown in (1) to (9) in FIG. 2 (corresponding to the numbers 1 to 9 in the figure).
[0034] (1) When an application 2021 issues an API request to access a resource, the API monitoring CTRL 2031 captures the request and transmits it to the access control CTRL 2033 .
[0035] (2) When checking access rights, the access control CTRL 2033 acquires information about resources held by the application 2021 from the APL monitoring CTRL 2032 as necessary.
[0036] (3) There are two conditions for denying access. In the first condition A (access denial A), for the access request in (1) above, an access permission check is performed for the resource by referring to the access permission management table 2035. If the check shows that there is no permission, the API issued by the application 2021 is not processed, and an access violation error is returned as a result.
[0037] (4) In the second condition B (access denial B), for the access request of (1), an access permission check for the resource is performed by referring to the access permission management table 2035. If the check shows that there is no permission and an error cannot be returned as a result of the API {processing} issued by the application 2021, the resource requested by the application 2021 is not processed, and instead, the resource management program 203 processes the API instead of an access request to a dummy resource prepared in advance.
[0038] As a result, application 2021 appears to have successfully completed the request, but is unable to access the requested resource.
[0039] (5) If the result of the access permission check for the access request (1) indicates that permission is granted, the API monitoring CTRL 2031 captures the access request, transmits the API processing issued by the application 2021 to the general-purpose OS 201 as is, and returns the result to the application 2021.
[0040] (6) If the API is successful and the application 2021 holds resources through the process of (5) above, this is reported to the APL monitoring CTRL 2032. The APL monitoring CTRL 2032 registers the correspondence between the application 2021 and the held resources.
[0041] When the application 2021 issues a resource release request API and the API is successful, the application 2021 also notifies the APL monitoring CTRL 2032. The APL monitoring CTRL 2032 deletes the association between the application 2021 and the resources it held.
[0042] (7) When a request for access to a resource is made by operating a standard OS function, the OS monitoring CTRL 2034 captures the access request and transmits it to the access control CTRL 2033 .
[0043] (8) In response to the access request (7), the access authority to the resource is checked by referring to the access authority management table 2035. If the check shows that the request does not have the authority, the operation in (7) is ignored.
[0044] (9) In response to the access request (7), the access authority to the resource is checked by referring to the access authority management table 2035. If the check shows that the access authority is granted, the operation of (7) is transmitted to the general-purpose OS 201.
[0045] Figure 4 is a sequence diagram of the first basic type (1) of API monitoring and control, showing the interactions between the application 2021, resource management program 203, and general-purpose OS 201 until the resource is released when there is access authority to the target resource.
[0046] In this first basic type (1), when an API issued by an application 2021 requests access to a target resource (step 401), the resource management program 203 checks whether the application 2021 has access authority to the resource (step 402). If the check shows that the application has access authority (step 403), the API issued by the application 2021 is transmitted as is to the generic OS 201. The generic OS 201 then performs the API processing native to the OS (step 404).
[0047] If the API processing is successful, the resource management program 203 registers information that the application 2021 holds the resource (step 405). Then, the resource management program 203 returns the API result from the generic OS 201 to the application 2021 as is (step 406). This completes the access to the resource (step 407).
[0048] Thereafter, when the application 2021 issues a request to release the held resource (step 408), the resource management program 203 transmits the release request to the generic OS 201. The generic OS 201 performs the API processing inherent to the OS (step 409). If the API processing is successful, the resource management program 203 cancels the information that the application 2021 is holding the resource (step 410). Then, the resource management program 203 returns the API result from the generic OS 201 to the application 2021 as is (step 411). This completes the release of the held resource (step 412).
[0049] Figure 5 is a sequence diagram of the second basic type (2) of API monitoring and control, showing the interactions between the application 2021, resource management program 203, and general-purpose OS 201 until access is denied when there is no access permission to the desired resource.
[0050] In this second basic type (2), when an API issued by the application 2021 requests access to a target resource (step 501), the resource management program 203 checks whether the application 2021 has access authority to the resource (step 502). If the check shows that the application does not have access authority (step 503), an access violation error is returned to the application 2021 (step 504). This ends the resource access process (step 505).
[0051] Furthermore, if an access request to a target resource is made by an API issued by an application 2021 that does not support access violation errors (step 506), the resource management program 203 checks whether the application 2021 has access authority to the resource (step 507). If the check shows that the application does not have access authority and the application 2021 does not support access violation errors (step 508), the resource management program 203 replaces the request with an access request to a dummy resource prepared in advance and passes it to the generic OS 201 (step 509).
[0052] The generic OS 201 performs the API processing that is inherent to the OS (step 510). The resource management program 203 returns the API processing result from the generic OS 201 to the application 2021 as is (step 511). As a result, the access processing to the target resource is completed, but since it is a dummy resource, nothing is actually done (step 512).
[0053] In the above explanation, if there is no access permission, an access violation error is returned to the application 2021, and the request is replaced with an access request to a dummy resource prepared in advance. However, the request may be replaced with an access to another resource for which access is permitted. The replacement with a dummy or another resource is specified in the access permission management table 2035.
[0054] <Overview of isolation policy application technology> The isolation policy application technology will be described below. In order to explain the isolation policy application technology more generally, the case where the isolation policy application technology is applied to a general electronic device (for example, a PC) will be described as an example. As will be described separately below, the isolation policy application technology can also be applied to, for example, a file server (or other network device) on a network.
[0055] The following explanation of application of isolation policies will show an example in which the resource management program 203 manages resource access requests based on the isolation policies. Isolation policies are information that collectively define the access rights required for each of multiple types of business as policies for each business (hereinafter referred to as isolation policies).
[0056] The isolation policy includes information such as the applications that can or cannot be executed for the corresponding business, the areas that can or cannot be read or written to (such as specific local disks or network disks), the permitted communication destinations (such as email or the Internet), the target users, PCs, time periods, and locations of use.
[0057] These multiple defined isolation policies can be switched by the user or automatically when the PC is in use, and one of the isolation policies will always be applied to the resource management program 203 when the PC is in operation.
[0058] For the OS and software running on the PC, the resource management program 203 controls so that access requests to resources are permitted only within the scope defined by the applied isolation policy. In other words, the resource management program 203 captures the processes executed by the OS and software at the API level, prohibits processes that violate the isolation policy, and allows only processes that satisfy the isolation policy to be executed, thereby performing control to satisfy the isolation policy. Alternatively, processes that violate the isolation policy are prohibited, and the program switches to another process that satisfies the isolation policy.
[0059] Furthermore, the "API capture" by the resource management program 203 performs necessary capture not only at the application level but also at the system level called drivers and services, thereby realizing separation equivalent to an environment in which PCs are physically separated.
[0060] For example, various conventional technologies can be used to prevent access to the Internet by refusing access along the communication path, but physical separation is achieved by not connecting the PC to such a network in the first place. In contrast, in this embodiment, the resource management program 203 determines whether access is permitted or denied to communication resources (e.g., network cards) that enable communication with the network at the API level inside the PC, so that if access is denied, communication does not flow through the connected network. This has the same effect as physical separation in addressing recent concerns that communication devices themselves may become targets of cyber attacks.
[0061] Next, examples of items that define permission and prohibition in the separation policy in this embodiment will be described.
[0062] First, the control information of the isolation policy includes the following: These can be made to correspond to the resource specification information in FIG. (1) Program executable The permission or prohibition of execution of each program is registered using the program name, program path, and program file hash. (2) Read access (connection) availability area Areas that specify whether or not various information can be read are registered using file paths, URLs, IP addresses, host names, USB device IDs, email addresses, and wireless LAN APs. (3) Writeable area Areas for which writing is permitted or prohibited are registered using the file path, URL (POST / PUT command), USB device ID, email address (SMTP), and clipboard data type. When specifying write permission, it is also possible to specify encrypted writing. The encryption key used in this case is defined in the separation policy. As explained above, by defining an encryption key for encrypted writing for each separation policy, only separation policies with the same encryption key can read the information, which makes it possible to effectively separate accessible information on a separation policy basis. (4) Temporarily accessible area When the applied isolation policy is changed, you can specify whether to log off or not, whether to terminate the programs you were using, the area to delete (specify the path), and whether to resume the programs you were using under the new isolation policy.
[0063] The following information can be listed as the target information for application of the isolation policy. These can be associated with the controllable conditions or the access rights shown in FIG. (1) Applicable device (PC) information Register the machine name, IP address, and MAC address. (2) Applicable user information Register the user name and group name. (3) Applicable location information Register the location information obtained from the OS, the connection AP, the connection domain name, and a specific company PC. (4) Applicable time information (time information) Register the applicable time, period, and day of the week.
[0064] Furthermore, when switching to another isolation policy, the information is cleared as follows. (1) Specify whether to clear the clipboard, limit it to a specific type, or leave it as is. (2) Specify whether to "clear" the temporarily accessible area, "make it inaccessible until the same policy is applied," or "leave it as is."
[0065] Then, one separation policy is defined as a set of the above control information, application target information, and clear information. Note that multiple separation policies can be defined by defining their names, and they are applied to the resource management program 203 by switching between them using a separation policy switching mechanism.
[0066] When applying an isolation policy to the resource management program 203, the isolation policy supplied to the resource management program 203 is analyzed by the access control CTRL 2033 shown in Fig. 2 and applied by expanding it into resource specification information, access permission information, etc. in the access permission management table 2035 as shown in Fig. 3. The mechanism for switching isolation policies may be configured so that the user can select and switch, or may be configured so that the policy is automatically switched based on location information (such as whether the PC is being used at work or at home)
[0067] Here, FIGS. 6A and 6B are diagrams showing specific examples of separation policies.
[0068] For example, possible isolation policies used by a company may include an isolation policy for confidential work within the company, an isolation policy for office work within the company, an isolation policy for remote work from home, an isolation policy for work outside the company on business trips, an isolation policy for unregistered locations, and a default isolation policy.
[0069] More specifically, an isolation policy for confidential internal work limits the PCs to which the isolation policy applies, restricts the people who can use the policy to, for example, certain managers or developers, and also strictly limits the locations where the policy can be used. The resource management program 203 to which the isolation policy for confidential internal work is applied permits access requests from the application 2021 to almost all resources. For example, essentially all programs, such as schedule management applications, development applications, and document creation applications, are accessible. Furthermore, almost all readable and writable areas, including external hard drives, the computer's own hard drive, and other storage areas, are accessible. This allows only certain individuals to access confidential internal information, and allows them to freely perform various tasks using that information. However, due to the nature of the system, which may involve handling confidential internal information, access to the internal network is permitted, but access to the Internet is prohibited.
[0070] Furthermore, compared to the isolation policy for confidential internal work, the isolation policy for internal work broadens the scope of people who can use a terminal to only those registered for office work within the company, and also broadens the scope of available location information, etc. Because expanding the scope of people and locations that can use a terminal reduces the level of security, the resource management program 203 reduces the accessible resources when this isolation policy is applied compared to the isolation policy for confidential internal work. For example, with regard to available programs, development applications and the like are not available, and only programs that are basically required for office work, such as schedule management applications and word processing applications, are accessible. Furthermore, with regard to readable and writable areas, access to external hard disk drives is prohibited, and only the user's own hard disk drive is accessible. Regarding network access, access to the internal network and the Internet is permitted, since the user may use the Internet for research, etc. Alternatively, depending on the business, access to the internal network may be permitted but communication to the Internet may be prohibited.
[0071] In addition, the isolation policy for remote work at home specifies that the applicable device is a mobile PC registered with the company, and that the location where it can be used is the home of the employee registered with the company. When applying the isolation policy for remote work, the device references its own GPS information and the registered employee's home address and applies this to the resource management program 203. Because security is lower for remote work at home than at the company, the programs that can be used are further restricted. For example, development apps and office work apps are not available, and only programs that are essentially required for work at home, such as word processing apps, are accessible. Regarding readable and writable areas, access to external hard disk drives is prohibited, while only reads are possible from the employee's own hard disk drive, and only reads and writes are possible for internal storage. Furthermore, to allow access to the Internet and internal storage via the internal network, only a Virtual Private Network (VPN) for connecting to the internal network is accessible.
[0072] Furthermore, in the case of an isolation policy for work outside the company, the applicable terminal is a mobile PC registered with the company, and the location where it can be used is a location registered with the company. When applying the isolation policy for work outside the company, the user's GPS information and the registered address of the location are referenced and applied to the resource management program 203. The programs that can be used are also more limited than for work at home, such as only browsers and email. Furthermore, the readable area is limited to the contents of a USB memory stick brought with the user. Also, access to the network is prohibited.
[0073] Furthermore, if an employee or other person attempts to use a terminal registered with the company in an unknown location such as an unregistered location, the resource management program 203 prohibits access to all resources because the security status is unknown.
[0074] The default isolation policy is a predefined isolation policy that is adopted when no applicable policy exists, and allows the use of general office work programs, word processing applications, email, etc. The default isolation policy assumes that the device will be used at work and allows general office work. As with the isolation policy for internal office work, access to the internal network and the Internet is also permitted, as users may use the Internet for research purposes.
[0075] Next, a method for managing isolation policies will be described. (1) When the isolation policy is stored in a file The isolation policy file contains the information in the "Example Isolation Policy" either as is or encrypted. The isolation policy file can be stored in advance on the terminal PC to be used, or it can be saved on the management server so that the latest policy is transferred to the terminal PC when it connects to the server. When the isolation policy file is managed by the management server, the management server and terminal PC are set to be able to communicate so that the isolation policy can be received from the management server regardless of the applied policy. (2) When the isolation policy is dynamically passed from the management server to the PC The terminal PC does not actually have a policy file; it stores and uses the isolation policy it receives from the management server in its own memory. The terminal PC sends the data required for policy selection (PC name, user name, location) to the server periodically or upon specific events, and the server provides the terminal PC with an isolation policy based on that information. When no policy exists, such as after a reboot, the aforementioned "default isolation policy" is used. (3) When using the default isolation policy As already explained, a default isolation policy is a predefined isolation policy that is adopted when no applicable policy exists. A default isolation policy may be saved as a file on the terminal, or may be implemented as a default value within the system. It is usually defined with restricted content, such as allowing communication between the management server and terminal PC, but disallowing the use of local disks, etc.
[0076] Next, a method for switching the above separation policy depending on the business will be described.
[0077] First, when a PC is first used, the isolation policies that become candidates for application are limited to those whose application target information registered in the isolation policy matches the PC's usage status. Furthermore, it is possible to define priorities for isolation policies based on the types of information among the application target information, such as applicable terminal information, applicable user information, applicable location information, and applicable time information, and the most suitable policy with the highest priority becomes the candidate.
[0078] For example, if the priority of information types is defined such that applicable terminal information is at the top and applicable user information is at the bottom, and if user B uses terminal A, when considering the separation policy for terminal A and the separation policy for user B, the candidate will be the separation policy for terminal A.
[0079] In addition, it is possible to define the application priority for separation policies belonging to the same information type, or to define the same priority. If there are still multiple candidates after narrowing down the options by the priority of the information type, they will be selected according to the priority of the separation policy.
[0080] If the result of narrowing down the isolation policy candidates in this way results in multiple isolation policy candidates, the user can select any one from them. If no selection is made, the first matching isolation policy within the PC will be applied.
[0081] Fig. 7 is a flowchart showing the operation when the terminal PC selects a separation policy. The operation of the flowchart in Fig. 7 starts when the terminal PC is started. Note that the terminal PC may be the terminal PC shown in Fig. 1B, and the operation of this flowchart may be realized by the CPU 1210 expanding and executing a program stored in the recording unit 1207.
[0082] In step S701, the CPU 1210 of the terminal PC acquires information on its own PC name, user name, place of use, and time.
[0083] In step S702, the CPU 1210 of the terminal PC acquires a file of the separation policy stored on its own hard disk or the like.
[0084] In step S703, the CPU 1210 of the terminal PC selects the separation policy that matches the application target information with the highest priority from among the application target information such as the PC name, user name, place of use, and time.
[0085] In step S704, the CPU 1210 of the terminal PC determines whether there are multiple policies corresponding to the highest priority target information selected in step S703, and if there are multiple policies, proceeds to step S705; if not, proceeds to step S706.
[0086] In step S705, the CPU 1210 of the terminal PC selects the separation policy with the highest preset priority from among a plurality of candidate separation policies.
[0087] In step S706, the CPU 1210 of the terminal PC determines whether or not there is one separation policy. If there is one separation policy, the process proceeds to step S708, and if there is no separation policy, the process proceeds to step S707.
[0088] In step S707, the CPU 1210 of the terminal PC selects a default separation policy.
[0089] In step S708, the separation policy selected in any one of steps S705 to S707 is applied to the resource management program 203.
[0090] In step S706, the separation policy with the highest preset priority is selected from among a plurality of candidate separation policies. However, the user may also make the selection.
[0091] Fig. 8 is a flowchart showing the operation of the management server selecting a separation policy when the management server that manages the separation policies supplies the separation policy to the terminal PC. The operation of the flowchart in Fig. 8 is started when the management server receives a request to send a separation policy from the terminal PC. The management server may be the management server shown in Fig. 10. The hardware configuration of the management server may be substantially the same as the hardware configuration (i.e., communication circuit, CPU, RAM, recording device, etc.) of the server shown in Fig. 1C.
[0092] In step S801, the CPU of the management server acquires information such as the PC name, user name, location of use, and time from the terminal PC.
[0093] In step S802, the CPU of the management server acquires the isolation policy file stored on its own hard disk or the like.
[0094] In step S803, the CPU of the management server selects the separation policy that matches the application target information with the highest priority from among the application target information such as the PC name, user name, use location, and time received from the terminal PC.
[0095] In step S804, the CPU of the management server determines whether there are multiple policies corresponding to the highest priority target information selected in step S803, and if there are multiple policies, proceeds to step S805; if not, proceeds to step S806.
[0096] In step S805, the CPU of the management server selects the separation policy with the highest preset priority from among a plurality of candidate separation policies.
[0097] In step S806, the CPU of the management server determines whether there is one separation policy. If there is one separation policy, the process proceeds to step S808, and if there is no separation policy, the process proceeds to step S807.
[0098] In step S807, the CPU of the management server selects a default isolation policy.
[0099] In step S808, the CPU of the management server transmits the separation policy selected in any one of steps S805 to S807 to the terminal PC.
[0100] In step S805, the separation policy with the highest pre-set priority is selected from among multiple candidate separation policies. However, multiple candidate separation policies may be sent directly to the terminal PC, and the user may select the separation policy to be applied on the terminal PC.
[0101] In the above explanation, it was assumed that the isolation policy to be selected is determined when the device is started up. However, the above process is also performed when user information is changed, such as when logging on or switching users, when registered location information is confirmed or changed, or when the date and time obtained from the OS is changed, and the isolation policy is updated as appropriate. Then, each time this happens, the operation of the OS and all programs when the PC is in use is controlled according to the isolation policy selected and applied using the above selection method.
[0102] <Isolation of network resources> Next, the separation of network resources according to this embodiment will be described. In the separation of network resources, API capture and separation policies are applied to network resources (for example, file servers, gateway machines, or proxy servers) to separate access targets. Note that access control for network resources may be performed using existing access control technology implemented in each network resource, instead of using the above-described API capture, as long as access control can be performed in accordance with the separation policy according to this embodiment.
[0103] An isolation policy that enables the isolation of network resources will be described with reference to Figures 9A, 9B-1, and 9B-2. The isolation policy that enables the isolation of network resources is an extension of the isolation policy described with reference to Figures 6A and 6B. A unique isolation policy name (i.e., information that identifies the isolation policy) is assigned to each isolation policy. Furthermore, as will be described later with reference to Figures 9B-1 and 9B-2, an isolation policy for isolating network resources further includes network resource control information in addition to the isolation policy control information and application target information shown in Figures 6A and 6B.
[0104] The isolation policy for isolating a network resource is applied by analyzing the isolation policy supplied to the resource management program 203 on the network resource in the same manner as the isolation policy described above, using the access control CTRL 2033 shown in FIG. 2, and expanding the policy into resource specification information, access permission information, etc. in the access permission management table 2035 as shown in FIG. 3.
[0105] FIG. 9A illustrates an example of an environment realized by a separation policy that enables the separation of network resources. The "Internal Confidential Work A" and "Internal Confidential Work B" illustrated in FIG. 9A show an example in which the separation policy for "Internal Confidential Work" illustrated in FIGS. 6A and 6B is expanded into separate work policies so that the access destinations differ for each work. In particular, the data areas that exist (or appear to exist) on the file server differ between "Internal Confidential Work A" and "Internal Confidential Work B." The separation policies for "Watermark Printing," "Cloud Only," and "Cloud Only (App Only)" illustrated in FIG. 9A are new examples that do not directly correspond to the examples illustrated in FIGS. 6A and 6B.
[0106] As shown in FIG. 9B-1, an isolation policy for isolating network resources includes isolation policy control information, application target information, and network resource control information. As described above, the control information includes information on available programs, readable areas, writable areas, and temporary access. Because the control information may be similar to that shown in FIG. 6A, detailed illustrations of the information are omitted in the example shown in FIG. 9B-1. The application target information of the isolation policy indicates targets (e.g., PCs) that can access network resources. As with the configurations described with reference to FIGS. 6A and 6B, the application target information of the isolation policy includes terminal information, user information, location information, and time information. That is, the "terminal information" may be specified by at least one of a machine name, an IP address, and a MAC address. The "user information" may be specified by a user name or a group name. The "location information" may include at least one of location information obtained from the OS of the PC used by the user, a connected AP, a connected domain name, an identifier indicating a specific company machine, and the like. Furthermore, the "time information" may be specified by a date and time period or a day of the week during which the PC can be used when the isolation policy is applied.
[0107] Network resource control information includes at least one of the following information about network resources subject to access control (permitted or prohibited): IP address, host name, URL, file server directory path, and network device name (e.g., printer, scanner). In the example shown in Figure 9B-2, for example, it includes an IP address, host name, server directory path, and URL. The IP address and host name specify the IP address or host name of the network resource to which access is permitted or prohibited. The server directory path specifies the resource on the file server or remote device to which access is permitted or prohibited. In the example shown in Figure 9B-2, the separation policies for "Internal Confidential Work A" and "Internal Confidential Work B" are configured to permit access only to the data areas on the file server dedicated to the respective business. The URL specifies the URL of the web service to which access is permitted or prohibited.
[0108] Furthermore, the network resource control information may specify this information in combination with the application program making the access. For example, the program for which permission or prohibition of access to the network resource is specified may be specified using at least one of the program name, program path, and program file hash. In the example shown in FIG. 9B-2, the isolation policy "Cloud Only (App Only)" specifies the programs making the access, "teams.exe" and "edge.exe." The program making the access is identified, for example, by an API capture control process that captures the API.
[0109] The information constituting the target of application and the information constituting the network resource control information can also be used as separate isolation policies that are omitted or masked according to the role (PC, gateway, file server, etc.) as needed. In that case, when applying the separate isolation policies to a PC or file server, they can be linked using the isolation policy name or isolation policy ID.
[0110] In the case of network resource isolation, multiple isolation policies may be automatically switched (to satisfy the provision target information) as explained in Fig. 7, or the isolation policy may be switched to the extent that the applicable target information is satisfied when the user uses the PC. By switching in this way, one of the isolation policies is always applied when the user operates the PC.
[0111] In a configuration in which a PC accesses a network resource such as a file server, the resource management program described above, which controls access according to the isolation policy, also runs on one or more network resources, such as gateways, proxies, and file servers. When a PC attempts to access a network resource, the resource management program on the network resource identifies the current isolation policy of the accessing PC and controls access according to the isolation policy stored in the resource management program that has the same name as the policy applied to the PC. If the isolation policy applied on the PC is changed, the PC can send the name of the changed isolation policy (information identifying the isolation policy) to the network resource (file server or proxy), thereby linking the isolation policy applied by the network resource to the isolation policy applied by the PC. Note that the resource management programs on both the PC and the network resource can apply an isolation policy with the same name to perform API capture. This allows both the PC and the network resource to be isolated in accordance with the applied isolation policy, ensuring strong security. Alternatively, the PC can obtain the name of the isolation policy to be applied but not perform API capture. In other words, API capture applying the isolation policy (corresponding to the isolation policy name acquired by the PC) may be performed only on the file server or gateway on the network resource side. Even in this case, network resources beyond the PC are appropriately isolated and controlled according to the isolation policy, but since there is no need for special control such as API capture on the PC side, implementation on the PC side is simplified and PC operation becomes faster. Also, if there are one or more gateways on the path from multiple PCs to access the file server, API capture according to the isolation policy may be performed only on one or more gateways on the path.In this case, the PC and file server do not require special control because they do not perform API capture, but by having one or more gateways perform access control in accordance with the isolation policy (corresponding to the isolation policy name obtained by the PC), network isolation can be achieved easily and with increased security.
[0112] The isolation policy for isolating network resources may be stored in the form of a file (an isolation policy file), for example. The isolation policy file may be encrypted. The isolation policy file may be stored in advance in the PC and the network resource.
[0113] Alternatively, a management server for managing the contents of the isolation policies may be provided, and the isolation policies may be distributed from the management server. Furthermore, the isolation policies held by the PCs may contain only application target information, and the isolation policies held by the network resources may contain only network resource control information. This may facilitate the management of network resource control, for example, in cases where policy contents need to be changed in conjunction with changes in the network configuration. When isolation policies are exchanged between devices, they may be exchanged after authentication between the devices. Furthermore, the exchanged isolation policies and other exchanged data may be encrypted.
[0114] When a management server is used, the PCs and network resources may access the management server periodically or irregularly to obtain the latest isolation policy file, thereby updating the isolation policy of each device. Note that when the isolation policies used by the PCs and network resources are managed by the management server, the PCs and network resources are configured to be able to access the management server so that they can obtain the isolation policy file, regardless of the content of the isolation policy that is set.
[0115] As another example of an isolation policy, the management server may dynamically provide isolation policy information to PCs and network resources. In this case, the PCs and network resources store the isolation policy information received from the management server in their internal memory or recording unit and use it. When isolation policy information is not available, such as after a reboot, the "default isolation policy" described below may be used.
[0116] Immediately after starting up the PC or when switching the isolation policy, the PC (and network resource) may use a specific isolation policy (referred to as a default isolation policy). The default isolation policy is, for example, a default isolation policy that is temporarily applied when there is no isolation policy to apply. If the access source has no applicable policy or is applying a non-existent isolation policy, the control unit in the network resource may apply the default isolation policy. The default isolation policy may be defined as the most restrictive policy. The most restrictive policy may, for example, allow communication only with the management server or prohibit access to all network resources.
[0117] FIG. 10 shows a schematic diagram of a PC 102 and a file server 100 located in a company, in which the PC 102 accesses file data on the file server 100 in accordance with an isolation policy. In this example, it is assumed that an isolation policy file (which isolates network resources) is pre-stored in the respective storage units of the PC 102 and the file server 100. The isolation policy files stored in the PC 102 and the file server 100 are pre-distributed and updated by a management server (S1000). When the user 101 starts using the PC 102, for example, an isolation policy is applied by the processing of the PC 102 shown in FIG. 7 (S1002). For example, it is assumed that the isolation policy "For Internal Confidential Work A" is applied to the PC 102 at this time. The PC 102 transmits identification information of the isolation policy applied to itself (i.e., the isolation policy name) to the file server 100 (S1004). As will be explained later in the description of the access control operation in the file server, the acquisition of the separation policy identification information may be performed after the PC 102 has accessed the file.
[0118] When the file server 100 receives a file access (i.e., an access request) from the PC 102 (S1006), it identifies (applies) an isolation policy (e.g., "For internal confidential work A") corresponding to the obtained isolation policy identification information, and the resource management program of the file server 100 performs access control in accordance with the isolation policy (S1008). If the access is to a data area permitted by the isolation policy, the file server 100 transmits the requested file data to the PC 102 (S1010).
[0119] When an access is made from PC 102, the resource management program of file server 100 checks the contents of the current isolation policy on that terminal (and also checks the program that made the access if control information is registered in combination with the program). Then, in the API capture and control process, the access is permitted or denied according to the isolation policy. This enables detailed control of network resources, such as access control to directories within the file server. Note that in the case of protocols that include a "connection establishment" process, such as TCP / UDP, or access that includes an "open" process, such as file access, control is exercised on the process in question, and control can be omitted for subsequent processes.
[0120] In the example shown in FIG. 10, the management server distributes isolation policy information to the PC and the file server and stores the isolation policy information in each storage unit. However, the distribution and selection of isolation policies are not limited to this. The application of an isolation policy to the PC 102 may be determined by the management server, as shown in FIG. 8, and the name of the determined isolation policy may be transmitted to the PC 102. In this case, for example, information on the corresponding isolation policy (e.g., network resource control information) to be applied to the file server 100 may be transmitted from the management server to the file server 100. In this case, the file server 100 may obtain the corresponding isolation policy information by transmitting information identifying the access source (e.g., information identifying the PC) to the management server. Furthermore, if the network configuration includes one or more gateway machines on the access path from the PC to the file server 100, the file server 100 may obtain the isolation policy identification information from the gateway machines. The file server 100 may then obtain the isolation policy information (e.g., network resource control information) corresponding to the identification information from the management server.
[0121] Furthermore, if one or more gateway machines are placed on the access path from a PC to the file server 100 in a network configuration, there is no need to have an isolation policy in subsequent network resources, and the gateway machine may transmit isolation policy information to the file server 100, for example. In this case, policy management becomes easier. Note that in cases where only the URLs that can be accessed by a proxy server are controlled, access control may be performed using existing simple control technology (such as a proxy program or gateway program).
[0122] In this way, for network resources within a network, access control can be implemented that is limited to the accessible network resources defined in the isolation policy, in conjunction with the current isolation policy applied to the PC from which the access is made. As a result, available network resources can be isolated as needed (as if they were different network resources) even when accessed from the same terminal.
[0123] <Access control processing on file servers> Next, with reference to Fig. 11, a process of performing access control in accordance with an isolation policy in the file server 100, which is a network resource, will be described. The operation of this flowchart may be implemented by the CPU 1310 expanding and executing a program stored in the recording unit 1304. In this case, part or all of this process by the CPU 1310 is implemented by the resource management program described above, which is executed by the CPU 1310. Note that in the operational example described below, an example is shown in which the timing at which the PC 102 transmits identification information of the isolation policy applied to itself to the file server 100 is different from the timing described in Fig. 10. However, the timing at which the identification information of the isolation policy applied to the PC 102 is transmitted may be the timing shown in Fig. 10.
[0124] In step 1101, the CPU 1310 of the file server 100 acquires the isolation policy file from, for example, a management server. It is not essential that the file server 100 acquire the isolation policy file from the management server in advance. The file server 100 may be configured to acquire the contents of the isolation policy in advance from a PC, or the file server 100 may acquire the contents of the isolation policy from the management server when a PC accesses the file server 100.
[0125] In step 1102, CPU 1310 determines whether there has been a file access request from PC 102. At this time, CPU 1310 may also acquire information related to the application target (terminal information, user information, location information, time information) along with the file access. If there has been a file access from PC 102, CPU 1310 proceeds to S1103, and if not, proceeds to S1102.
[0126] In step 1103, the CPU 1310 acquires identification information of the isolation policy to be applied by the PC 102. In step 1104, the CPU 1310 extracts network resource control information from the isolation policy file according to the acquired identification information of the isolation policy, and sets it as information to be used for access control (for example, the resource specification information, conditions, and access permissions shown in FIG. 3). The CPU 1310 may also set information on the target to which the isolation policy file is applied as information to be used for access control.
[0127] In step 1105, the CPU 1310 performs access control by a resource management program using API capture in accordance with the network resource control information set as information used for access control. At this time, if information on the target of application of the isolation policy file is set in S1104, the CPU 1310 also performs access control in accordance with the information on the target of application.
[0128] In step 1106, the CPU 1310 transmits the result of the access control by the resource management program (for example, transmits the accessed file to the PC 102). After transmitting the result, the CPU 1310 ends this process.
[0129] The above description has been given of an example in which a request for access to a file, which is a computer resource on the file server 100, is executed from the PC 102. However, the same applies when the PC 102 accesses a network device (for example, when a request for access to the Internet is made to a proxy). That is, the proxy applies an isolation policy and controls access to computer resources on the proxy (for example, ports, established connections, tunnels, etc.) in accordance with the isolation policy.
[0130] As described above, in the above-described embodiment, access control by API capture according to the separation policy is performed in conjunction with the PC used by the user and the network resource (e.g., file server or network device). In this way, it is possible to make the PC and the network resource behave as if they are physically separated environments for each task. Furthermore, because the PC and the network resource are linked and operate under the same separation policy, the network environment itself can behave as if it were a physically separated and distinct environment. In other words, it is possible to realize extended access control for network resources available to workers that is suited to their usage status, while utilizing the existing OS and processes of terminals and devices on the network.
[0131] The invention is not limited to the above-described embodiment, and various modifications and variations are possible within the scope of the gist of the invention.
Claims
1. 1. An information processing method for controlling access to computer resources on a network resource from a communication device used by a user, comprising: a selection step of selecting a policy suitable for the state of the communication device from a plurality of policies that define access rights granted for each of a plurality of types of business as policies for each business; In the communication device, a first capturing step of capturing an operation request from a process or an operating system for a computer resource on the communication device before the computer resource is accessed; a first determination step of determining whether or not the user has access authority to the computer resource designated by the operation request acquired in the first acquisition step, based on information about the policy selected in the selection step; In the network resource, an acquisition step of acquiring information about a policy selected for the communication device; a second capturing step of capturing, when receiving an access request for a computer resource on the network resource from the communication device, an operation request from a process or an operating system for the computer resource on the network resource before accessing the computer resource; a second determination step of determining whether or not there is an access right to the computer resource designated by the operation request acquired in the second acquisition step, based on the policy information acquired in the acquisition step; a processing step of transferring the operation request to the operating system as is if the access right is determined as a result of the determination in the second determination step, and returning the result to the request source; a refusal step of refusing access to the computer resource designated by the operation request if the second determination step determines that the user does not have access authority, An information processing method, characterized in that the first determination step and the second determination step perform different access controls based on information of the policy selected in the selection step.
2. 2. The information processing method according to claim 1, wherein the acquisition step includes receiving information identifying a policy selected for the communication device from the communication device, and then acquiring information on the policy selected for the communication device that corresponds to the information identifying the policy.
3. The information processing method according to claim 1, characterized in that in the acquisition step, information identifying a policy selected for the communication device is received from another network resource, and information on the policy selected for the communication device corresponding to the information identifying the policy is acquired.
4. 4. The information processing method according to claim 2, wherein in the acquisition step, information on the policy selected for the communication device corresponding to the information identifying the policy is acquired from a file stored in a storage means of the network resource.
5. 4. The information processing method according to claim 2, wherein in the obtaining step, information on the policy selected for the communication device, which corresponds to the information identifying the policy, is obtained from an external management server.
6. 2. The information processing method according to claim 1, wherein said obtaining step obtains information about the policy selected for said communication device from said communication device.
7. In a second network resource that is a network resource accessed from the communication device, a second acquisition step of acquiring information about a policy selected for the communication device; a third capturing step of capturing an operation request from a process or an operating system for a computer resource on the second network resource before accessing the computer resource; 7. The information processing method according to claim 1, further comprising a third determination step of determining whether or not there is access authority to the computer resource specified by the operation request captured in the third capture step based on the policy information acquired in the second acquisition step.
8. the plurality of policies each include, for a network resource that is the object of access control, at least one of information on an IP address, a host name, a URL, a directory path of a file server, and a network device name; An information processing method according to any one of claims 1 to 7, characterized in that in the second determination step, whether or not there is access authority to the computer resource specified by the operation request captured in the second capture step is determined based on information about the network resource contained in each policy.
9. the plurality of policies further include, for each policy, information specifying a program to be run on the communication device for accessing a network resource that is subject to access control; The information processing method according to claim 8, characterized in that in the second determination step, whether or not there is access authority to the computer resource specified by the operation request captured in the second capture step is determined further based on information specifying the program contained in each policy.
10. The information processing method according to claim 8 or 9, characterized in that the plurality of policies further include, for each policy, information on the target of application that specifies at least one of information on the communication device, information on the user, location information on the communication device, and time information for using the communication device.
11. 10. The information processing method according to claim 1, wherein the state of the communication device includes information on the applicable communication device, information on the user, location information of the communication device, and time information.
12. One or more programs that cause one or more computers to execute each step of an information processing method for controlling access to computer resources on a network resource from a communication device used by a user, the information processing method comprising: a selection step of selecting a policy suitable for the state of the communication device from a plurality of policies that define access rights granted for each of a plurality of types of business as policies for each business; In the communication device, a first capturing step of capturing an operation request from a process or an operating system for a computer resource on the communication device before the computer resource is accessed; a first determination step of determining whether or not the user has access authority to the computer resource designated by the operation request acquired in the first acquisition step, based on information about the policy selected in the selection step; In the network resource, an acquisition step of acquiring information about a policy selected for the communication device; a second capturing step of capturing, when receiving an access request for a computer resource on the network resource from the communication device, an operation request from a process or an operating system for the computer resource on the network resource before accessing the computer resource; a second determination step of determining whether or not there is an access right to the computer resource designated by the operation request acquired in the second acquisition step, based on the policy information acquired in the acquisition step; a processing step of transferring the operation request to the operating system as is if the access right is determined as a result of the determination in the second determination step, and returning the result to the request source; a refusal step of refusing access to the computer resource designated by the operation request if the second determination step determines that the user does not have access authority, The one or more programs, wherein the first determination step and the second determination step perform different access controls based on information of the policy selected in the selection step.
13. One or more storage media storing one or more programs according to claim 12.
Citation Information
Patent Citations
Security managing system
JP1989209561A
Information processing method and device controlling computer resource, information processing system, control method therefor, storage medium and program
JP2003044297A
Access control system, device and program
JP2006053824A
Information processing apparatus, method, and program
JP2011175649A