Storage media integrated management system and storage media management device
The storage medium integrated management system addresses the issue of unmanaged USB data transfer by authenticating users and devices, ensuring secure data usage and preventing unauthorized access.
Patent Information
- Application Number
- JP2023027104
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-02-24
- Publication Date
- 2025-08-14
- Estimated Expiration
- 2043-02-24
AI Technical Summary
Existing USB management devices fail to manage who sent information to which device, posing risks of information leakage and virus infection due to uncontrolled data transfer.
A storage medium integrated management system that includes a storage medium management device and an integrated management device, which manages storage media by generating authentication data based on user, device, and storage medium information, authenticating the storage medium, and controlling data transfer based on authentication results.
Enables effective management of data usage status, preventing unauthorized access and ensuring secure data transfer by authenticating users and devices, thereby reducing risks of information leakage and virus infection.
Smart Images

Figure 0007723693000001 
Figure 0007723693000002 
Figure 0007723693000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a storage media integrated management system and a storage media management device. [Background technology]
[0002] There are various standards for USB (Universal Serial Bus) depending on the type of data transmission. Furthermore, USB is backward compatible, so different standards can be connected. For this reason, storage devices with USB connectors (called "USB devices") are used. Such storage devices can be attached to various devices with USB ports. As the USB standard supports high-speed transmission, it has become possible to store large amounts of data in storage devices.
[0003] However, large-capacity storage poses significant risks to various servers and computers. These risks include the risk of information leakage due to the extraction of information, or the risk of virus infection due to the introduction of viruses. Therefore, technologies to protect information on USB devices have been proposed.
[0004] Patent document 1 states that "information on usage rights registered in the USB usage permission information database corresponding to the combination of terminal identification information, user personal authentication information, and USB device information received from the USB control unit is transmitted to the USB control unit." [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2018 / 173528 Summary of the Invention [Problem to be solved by the invention]
[0006] However, the USB management device described in Patent Document 1 has a problem in that it cannot manage who sent information to which device from a USB device. For this reason, there is a need to manage the usage status of USB devices.
[0007] The present invention has been made in view of the above circumstances, and has as its object to make it possible to manage the usage status of data stored on a storage medium. [Means for solving the problem]
[0008] A storage medium integrated management system according to the present invention includes a storage medium management device that manages storage media on which data is stored, and an integrated management device that manages the storage media and the storage medium management device. The integrated management device stores the information required to use the storage media. The data includes storage medium management device information that uniquely represents the storage medium management device, user information of the user who uses the data, and storage medium information specific to the storage medium. The authentication data generating unit generates authentication data to be used for authenticating the storage medium based on the above and stores the authentication data in the storage medium. The storage media management device When a storage medium is connected to the storage medium management device and the storage medium management device is connected to the user terminal, information and authentication data required for using the storage medium are obtained from the storage medium, and the authentication data is analyzed; The storage medium has an authentication data analysis unit that authenticates the storage medium based on the analysis result of the authentication data acquired from the storage medium and the information required for using the storage medium acquired from the storage medium, and a data transfer unit that, if the authentication result by the authentication data analysis unit is normal, makes the data stored in the storage medium available to the user terminal and transfers the data stored in the storage medium to the user terminal. [Effects of the Invention]
[0009] According to the present invention, it is possible to manage the usage status of data stored in a storage medium. Problems, configurations, and effects other than those described above will become apparent from the following description of the embodiments. [Brief explanation of the drawings]
[0010] [Figure 1] FIG. 1 is a diagram illustrating a usage pattern of a USB integrated management system according to an embodiment of the present invention. [Figure 2]1 is a schematic diagram illustrating an example of the internal configuration of a USB integrated management system according to an embodiment of the present invention. [Figure 3] 1 is a block diagram showing an example of the internal configuration of an integrated management system according to an embodiment of the present invention; [Figure 4] 10 is a flowchart illustrating an example of processing by an integrated management system according to an embodiment of the present invention. [Figure 5] 1 is a block diagram illustrating an example of the internal configuration of a USB management device according to an embodiment of the present invention. [Figure 6] 10 is a flowchart illustrating an example of processing of a USB management device according to an embodiment of the present invention. [Figure 7] FIG. 2 is a block diagram illustrating an example of the hardware configuration of a computer according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In this specification and drawings, components having substantially the same functions or configurations are designated by the same reference numerals, and redundant description will be omitted.
[0012] [One embodiment] First, a description will be given of how to use the USB integrated management system 1 according to one embodiment of the present invention. FIG. 1 is a diagram showing how the USB integrated management system 1 is used.
[0013] The USB integrated management system 1 (an example of a storage medium integrated management system) is configured to include an integrated management system 2 and a USB management device 12.
[0014] The USB client 8 (an example of a storage medium) is a storage device among USB devices that has the function of saving data. Examples of the USB client 8 include a USB memory, an external HDD (Hard Disk Drive), an external SSD (Solid State Drive), and a mobile terminal that can be connected via a USB cable. The USB client 8 includes a connector 8a that complies with the USB standard and is inserted into the socket 12b of the USB management device 12.
[0015] The USB management device 12 (an example of a storage medium management device) is a device that manages the usage status of the USB client 8 in which data is stored, and is assumed to be, for example, a USB hub. The USB management device 12 is connected between the USB client 8 and the USB user terminal 19. For this purpose, the USB management device 12 has a receptacle 12b conforming to the USB standard into which the connector 8a of the USB client 8 is inserted. The USB management device 12 also has a connector 12a conforming to the USB standard for insertion into the receptacle 19a of the USB user terminal 19.
[0016] The integrated management system 2 (an example of an integrated management device) manages the USB clients 8 and the USB management device 12. For this reason, the integrated management system 2 is connected to the USB management device 12 and has a function of providing the USB management device 12 with necessary information.
[0017] The USB usage terminal 19 (an example of a usage terminal) is a terminal on which the user 18 uses the USB client 8, and is assumed to be, for example, a PC (Personal Computer). The USB usage terminal 19 has a socket 19a that complies with the USB standard, and the connector 12a of the USB management device 12 is inserted into the socket 19a. The USB usage terminal 19 may also be a server or the like that has a socket 19a that complies with the USB standard. If the usage environment of the USB usage terminal 19 is a factory, a machine (such as a 3D printer) installed in the factory is also assumed to be the USB usage terminal 19. When the user 18 inputs user information as described below, the user 18 may use another terminal connected to the USB management device 12.
[0018] Here, the process of using the USB client 8 will be outlined. When the user 18 uses the USB client 8, the connector 8a of the USB client 8 is inserted into the insertion port 12b of the USB management device 12. Further, the connector 12a of the USB management device 12 is inserted into the insertion port 19a of the USB usage terminal 19. Then, the user 18 inputs user information such as the user ID and password assigned to themselves on the authentication screen displayed on the USB usage terminal 19. When the USB management device 12 determines that various information including the user information is normal, the USB usage terminal 19 can use the data of the USB client 8.
[0019] <Configuration Example of USB Integrated Management System> Next, an internal configuration example of the USB integrated management system 1 will be described. FIG. 2 is a schematic diagram showing an internal configuration example of the USB integrated management system 1.
[0020] The USB integrated management system 1 includes an integrated management system 2 and a USB management device 12. For convenience of explanation, the USB integrated management system 1 is illustrated with a dashed line so that the USB client 8 is included in the USB integrated management system 1.
[0021] (Integrated Management System) The integrated management system 2 includes a database 3 for user information, an authentication data creation unit 4, a database 5 for USB information, a database 6 for USB management device information, and data 7 used in the USB usage terminal.
[0022] The database 3 for user information stores user information in advance. The user information is information that can uniquely identify the user 18, such as an ID and password set by the individual or biometric authentication information. The user information may be registered by the user 18 himself / herself or may be registered collectively by an administrator who manages the users.
[0023] The USB information database 5 stores USB information for each USB client 8. The USB information is information specific to the USB client 8, such as a serial ID and a class code specific to the USB client 8. The USB information database 5 stores multiple pieces of USB information 10 registered for each of multiple USB clients 8.
[0024] The USB management device information database 6 stores USB management device information. The USB management device information is information that allows unique identification, such as a serial ID assigned to the USB management device 12. The USB management device 12 is managed using the USB management device information.
[0025] The data 7 used by the USB terminal is data sent from the integrated management system 2 to the USB client 8. The data 7 used by the USB terminal includes multiple pieces of data, and the data that the user 18 can use varies depending on the access authority of the user 18. For this reason, not all of the data 7 used by the USB terminal is sent to the USB client 8, but a selected portion of the data 7 used by the USB terminal is sent to the USB client 8 as data 11 used by the USB terminal.
[0026] The authentication data creation unit 4 creates authentication data 9 and stores the authentication data 9 in the USB client 8. The authentication data 9 is data used to authenticate the USB client 8 when the user 18 uses the USB client 8, based on information required to use the USB client 8. For example, the authentication data creation unit 4 creates the authentication data 9 based on the data information created by the used data information creation unit 24 shown in FIG. 3, user information, USB management device information, and USB information.
[0027] Authentication data 9 is created using user information read from user information database 3, USB information read from USB information database 5, USB management device information read from USB management device information database 6, and data (hash value, etc.) created from data 7 used in the USB terminal. The authentication data created by authentication data creation unit 4 is sent to USB client 8.
[0028] (USB client) The USB client 8 stores authentication data 9, USB information 10, and data 11 used by the USB terminal.
[0029] The authentication data 9 is data received from the authentication data creation unit 4. The authentication data 9 is information created using the USB management device information 16, the USB information 10, the user information registered in the user information database 3, and the data information to be used that is created by the data information to be used creation unit 24 (see FIG. 3 described later), and is assumed to be, for example, an electronic certificate.
[0030] The USB information 10 is data that is stored in advance in the USB client 8. The USB information 10 is registered in the USB information database 5 of the integrated management system 2 before the USB client 8 is used.
[0031] The data 11 used by the USB terminal is a portion of data selected from the data 7 used by the USB terminal of the integrated management system 2 , and is sent from the integrated management system 2 and saved in the USB client 8 .
[0032] (USB management device) The USB management device 12 includes an authentication data analysis unit 13, a user information input unit 14, a USB information acquisition unit 15, USB management device information 16, and a data transfer unit 17. The USB management device 12 is connected to a USB terminal 19.
[0033] The user information input unit 14 is activated when the USB management device 12 is connected to the USB terminal 19. The user information input unit 14 then accepts user information entered by the user 18. For this purpose, the user 18 enters the user information via a user information entry screen that is displayed on a display device (not shown) of the USB terminal 19 by the USB management device 12, for example. The user information accepted by the user information input unit 14 is sent to the authentication data analysis unit 13. Note that the information entered by the user information input unit 14 is not stored in the user information database 3 of the integrated management system 2.
[0034] The USB information acquisition unit 15 (an example of a storage medium information acquisition unit) acquires USB information 10 from the USB client 8 connected to the USB management device 12. Then, the USB information acquisition unit 15 outputs the acquired USB information 10 to the authentication data analysis unit 13.
[0035] The USB management device information 16 (an example of storage medium management device information) is information that enables unique identification of the USB management device 12, such as a serial ID. The USB management device information 16 is read out by the authentication data analysis unit 13.
[0036] The authentication data analysis unit 13 has a function of authenticating the USB client 8 based on the analysis result of the authentication data 9 acquired from the USB client 8 and the information required to use the USB client 8 acquired from the USB client 8. When the USB client 8 is connected to the USB management device 12 and the USB management device 12 is connected to the USB usage terminal 19, the authentication data analysis unit 13 acquires the information required to use the USB client 8 and the authentication data 9 from the USB client 8 and analyzes the authentication data 9.
[0037] At this time, the authentication data analysis unit 13 compares the user information received from the user information input unit 14, the USB information 10 received from the USB information acquisition unit 15, and the USB management device information 16 with the analysis result of the authentication data 9 acquired from the USB client 8. For example, the authentication data analysis unit 13 compares the user information registered in the user information database 3 in the integrated management system 2 with the user information input from the user information input unit 14.
[0038] If the authentication result is normal, the authentication data analysis unit 13 permits the data transfer unit 17 to transfer the data so that the data 11 used in the user terminal in the USB client 8 can be used in the USB user terminal 19. On the other hand, if the authentication result is abnormal, the authentication data analysis unit 13 does not permit the data transfer unit 17 to transfer the data so that the data used in the user terminal in the USB client 8 cannot be used in the USB user terminal 19.
[0039] If the authentication result by the authentication data analysis unit 13 is normal, the data transfer unit 17 makes the data stored in the USB client 8 available for use in the USB user terminal 19, and transfers the data stored in the USB client 8 to the USB user terminal 19. As described above, when the data transfer is permitted by the authentication data analysis unit 13, the data transfer unit 17 transfers the data 11 to be used in the USB user terminal that is stored in the USB client 8 to the USB user terminal 19. As a result, the USB user terminal 19 can import and use the data 11 to be used in the USB user terminal.
[0040] Furthermore, if the authentication result by the authentication data analysis unit 13 is normal, the USB user terminal 19 can acquire the authentication data 9 via the data transfer unit 17. Similarly, if the authentication result by the authentication data analysis unit 13 is normal, the USB user terminal 19 can acquire the USB information 10 via the data transfer unit 17. Therefore, the USB user terminal 19 can also check the authentication data 9 and the USB information 10. In this way, the USB management device 12 can manage the use of data in the USB terminal 19.
[0041] <Example of the internal configuration of the integrated management system> Next, a detailed example of the internal configuration of the functional unit involved in creating authentication data in the integrated management system 2 will be described. FIG. 3 is a block diagram showing an example of the internal configuration of the integrated management system 2. As shown in FIG.
[0042] 2, the integrated management system 2 includes input units 20-23 for inputting data from each database to the authentication data creation unit 4, and a data information creation unit 24 for use. The operation of the user 18 inputting necessary data into the input units 20-23 is shown by the user 18 entering data into a rectangular frame that surrounds the input units 20-23 with a dashed line. This user 18 may be a system administrator of the integrated management system 2.
[0043] The USB management device information input unit 20 is used to enable the user 18 to input USB management device information in the USB management device information database 6. Here, the USB management device information that the user 18 can input corresponds to the USB management device information 16 held by the USB management device 12 connected to the USB user terminal 19.
[0044] The USB information input unit 21 is used to enable the user 18 to input USB information in the USB information database 5. Here, the USB information that the user 18 can input corresponds to the USB information 10 of the USB client 8.
[0045] The user information input unit 22 is used to enable the user 18 to input user information in the user information database 3. Here, the user information that the user 18 can input is the same as the user information that the user 18 inputs through the user information input unit 14 when using the USB client 8.
[0046] The data to be used input unit 23 is used to enable the user 18 to input data that can be used by the user 18. Here, the data that can be used by the user 18 is a portion of data selected from the data 7 used by the USB terminal. The data selected from the data 7 used by the USB terminal is sent to the data to be used information creation unit 24.
[0047] The used data information creation unit 24 (an example of a first data information creation unit) creates used data information based on data used in the USB terminal 19. For example, the used data information creation unit 24 creates used data information from data selected from the data 7 used in the USB terminal received from the used data input unit 23. The used data information is information that is uniquely determined based on the data selected from the data 7 used in the USB terminal, such as a hash value that is the result of a hash function operation. Therefore, even if the amount of data 7 used in the USB terminal is large, the used data 7 can be converted into a character string of a predetermined length, and the amount of data in the used data information can be reduced.
[0048] The authentication data creation unit 4 creates authentication data 9 based on USB management device information, user information, USB information, and data information to be used, which are information required for using the USB client 8. The authentication data creation unit 4 acquires the USB management device information, USB information, and user information from the input units 20 to 22, and acquires data information to be used from the data information to be used creation unit 24. The authentication data creation unit 4 then creates authentication data using the USB management device information, USB information, user information, and data information to be used. The authentication data created by the authentication data creation unit 4 is stored in the USB client 8 as authentication data 9.
[0049] <Example of processing by the integrated management system> FIG. 4 is a flowchart showing an example of processing by the integrated management system 2.
[0050] First, the input units 20 to 23 shown in FIG. 3 input USB management device information, USB information, user information, and data used in the USB usage terminal (S1). At this time, the USB management device information input unit 20 inputs the USB management device information acquired from the database 6 of the USB management device to the authentication data creation unit 4. Also, the USB information input unit 21 inputs the USB information acquired from the database 5 of the USB information to the authentication data creation unit 4. Further, the user information input unit 22 inputs the user information acquired from the database 3 of the user information to the authentication data creation unit 4. Also, the used data input unit 23 inputs the data acquired from the data 7 used in the USB usage terminal to the used data information creation unit 24.
[0051] Next, the used data information creation unit 24 creates used data information based on the data acquired from the data 7 used in the USB usage terminal (S2).
[0052] Next, the authentication data creation unit 4 creates authentication data 9 based on the USB management device information, USB information, and user information input from the input units 20 to 22, and the used data information created by the used data information creation unit 24 (S3).
[0053] Then, the used data input unit 23 sends the data acquired from the data 7 used in the USB usage terminal to the USB client 8 (S4). This data is stored as the data 11 used in the USB usage terminal in the USB client 8. Also, the authentication data creation unit 4 sends the created authentication data 9 to the USB client 8 (S4). This authentication data 9 is stored in the USB client 8. After that, this process ends.
[0054] In this way, the integrated management system 2 can send the data used in the USB terminal and the authentication data 9 to the USB client 8.
[0055] <Internal configuration example of USB management device> Next, a detailed example of the internal configuration of the functional unit related to authentication data verification of the USB management device 12 will be described. FIG. 5 is a block diagram showing an example of the internal configuration of the USB control device 12. As shown in FIG.
[0056] The USB management device 12 has a data information creation unit 25 to be used, a USB information acquisition unit 15, an authentication data acquisition unit 29, USB management device information 16, an authentication data analysis unit 13, a user information input unit 14, and a data transfer unit 17.
[0057] The utilized data information creation unit 25 (an example of a second data information creation unit) creates utilized data information based on the data 11 utilized by the USB terminal, which is stored in the USB client 8. At this time, similar to the utilized data information creation unit 24 described with reference to FIG. 3, the utilized data information creation unit 25 calculates a hash value of the data 11 utilized by the USB terminal, and uses this hash value as the utilized data information. The utilized data information created by the utilized data information creation unit 25 is output to the authentication data analysis unit 13.
[0058] The USB information acquisition unit 15 acquires the USB information 10 from the USB client 8. The USB information 10 acquired by the USB information acquisition unit 15 is output to the authentication data analysis unit 13.
[0059] The authentication data acquisition unit 29 acquires the authentication data 9 from the USB client 8. The authentication data 9 acquired by the authentication data acquisition unit 29 is output to the authentication data analysis unit 13.
[0060] User information is input to the user information input unit 14 by the user 18. The user information input to the user information input unit 14 is output to the authentication data analysis unit 13.
[0061] The authentication data analysis unit 13 reads USB management device information 16 stored in advance in the USB management device 12. Then, the authentication data analysis unit 13 analyzes the authentication data 9 input from the authentication data acquisition unit 29 based on the data information to be used, the user information, the USB management device information, and the USB information created by the data information to be used creation unit 25. At this time, the authentication data analysis unit 13 determines that the authentication result of the USB client 8 is normal if the USB management device information obtained by the authentication data analysis unit 13 analyzing the authentication data 9 is the same as the USB management device information read from the USB management device information 16, if the USB information obtained by the authentication data analysis unit 13 analyzing the authentication data 9 is the same as the USB information read from the USB client 8, and if the user information obtained by the authentication data analysis unit 13 analyzing the authentication data 9 is the same as the user information input from the user information input unit 14.
[0062] Furthermore, the authentication data analysis unit 13 determines that the authentication result of the USB client 8 is normal if the data information to be used created by the data information to be used creation unit 25 is the same as the data information to be used obtained by analyzing the authentication data 9 by the authentication data analysis unit 13. Then, if the verified authentication data 9 is normal, the authentication data analysis unit 13 permits the data transfer unit 17 to transfer data.
[0063] When the authentication data analysis unit 13 permits the data transfer, the data transfer unit 17 transfers the data 11 used in the USB terminal of the USB client 8 to the USB terminal 19. This allows the USB terminal 19 to use the data 11 used in the USB terminal. Here, all data stored in the USB client 8 is sent to the data transfer unit 17. Therefore, the data transfer unit 17 that has been permitted to transfer data may be treated the same as a USB connector (extension cable) with no restrictions on the data that it can transfer.
[0064] In this way, the USB management device 12 can manage the usage status of the data stored in the USB client 8 on the USB usage terminal 19 by using the authentication data 9, the data information to be used, the USB information 10, the user information, and the USB management device information 16.
[0065] <Example of the processing of the USB management device> FIG. 6 is a flowchart showing an example of the processing of the USB management device 12. When the USB client 8 is connected to the USB management device 12, the USB management device 12 starts the processing.
[0066] First, the authentication data acquisition unit 29 acquires the authentication data 9 from the USB client 8 (S11). Next, the authentication data analysis unit 13 analyzes the authentication data 9 acquired by the authentication data acquisition unit 29 (S12). The authentication data analysis unit 13 acquires the USB management device information 16 in order to analyze the authentication data 9.
[0067] Next, based on the result of analyzing the authentication data 9, the authentication data analysis unit 13 determines that the USB management device information 16 registered in the integrated management system 2 is equal to the USB management device information 16 possessed by the USB management device 12. This process is performed by the authentication data analysis unit 13 determining whether the USB management device information that is the analysis result of the authentication data 9 is equal to the acquired USB management device information 16 (S13). If the USB management device information that is the analysis result of the authentication data 9 is different from the USB management device information 16 (NO in S13), this process ends.
[0068] On the other hand, if the USB management device information, which is the analysis result of the authentication data 9, is equal to the USB management device information 16 (YES in S13), the authentication data analysis unit 13 instructs the user information input unit 14 to acquire user information. Therefore, the user information input unit 14 displays a screen on the display unit of the USB user terminal 19 for the user 18 to input user information, and requests the user 18 to input user information (user ID, password, etc.) (S14). Then, the user information input unit 14 causes the user 18 to input the user information (S15). Thereafter, the user information input unit 14 outputs the user information input by the user 18 to the authentication data analysis unit 13.
[0069] Next, based on the result of analyzing the authentication data 9, the authentication data analysis unit 13 determines whether the user information registered in the integrated management system 2 is identical to the user information input from the user information input unit 14. This process is performed by the authentication data analysis unit 13 determining whether the user information resulting from the analysis of the authentication data 9 is identical to the user information input from the user information input unit 14 (S16). If the user information resulting from the analysis of the authentication data 9 is different from the user information input from the user information input unit 14 (NO in S16), this process ends.
[0070] On the other hand, if the user information obtained by analyzing the authentication data 9 is equal to the user information input from the user information input unit 14 (YES in S16), the authentication data analysis unit 13 instructs the USB information acquisition unit 15 to be used to acquire the USB information 10. Therefore, the USB information acquisition unit 15 acquires the USB information 10 from the USB client 8 (S17).
[0071] Next, based on the result of analyzing the authentication data 9, the authentication data analysis unit 13 determines whether the USB information registered in the integrated management system 2 is equal to the USB information 10 acquired by the USB information acquisition unit 15. This process is performed by the authentication data analysis unit 13 determining whether the USB information resulting from the analysis of the authentication data 9 is equal to the USB information 10 acquired from the USB information acquisition unit 15 (S18). If the USB information resulting from the analysis of the authentication data 9 is different from the USB information 10 acquired from the USB information acquisition unit 15 (NO in S18), this process ends.
[0072] On the other hand, if the USB information resulting from the analysis of the authentication data 9 is equal to the USB information 10 acquired from the USB information acquisition unit 15 (YES in S18), the authentication data analysis unit 13 instructs the utilized data information creation unit 25 to create the utilized data information. Therefore, the utilized data information creation unit 25 creates the utilized data information based on the data 11 used in the USB terminal of the USB client 8 (S19).
[0073] Next, the authentication data analysis unit 13 determines, based on the result of analyzing the authentication data 9, whether the data information to be used created by the integrated management system 2 is equal to the data information to be used created by the data information to be used creation unit 25. This process is performed by the authentication data analysis unit 13 determining whether the data information to be used, which is the analysis result of the authentication data 9, is equal to the data information to be used acquired from the data information to be used creation unit 25 (S20). If the data information to be used, which is the analysis result of the authentication data 9, is different from the data information to be used acquired from the data information to be used creation unit 25 (NO in S20), this process ends.
[0074] On the other hand, if the data information to be used, which is the analysis result of the authentication data 9, is equal to the data information to be used acquired from the data information to be used creation unit 25 (YES in S20), the data 7 to be used at the USB user terminal in the USB client 8 is made available at the user terminal. Therefore, the authentication data analysis unit 13 permits the data transfer unit 17 to transfer the data.
[0075] Then, the data transfer unit 17 transfers the data 11 used by the USB terminal stored in the USB client 8 to the USB terminal 19 (S21), and the process ends.
[0076] By the above process, the use of the USB client 8 at the user terminal can be managed by the USB management device information 16, user information, USB information 10 and used data information.
[0077] <Example of computer hardware configuration> Next, the hardware configuration of the computer 30 that constitutes each device of the USB integrated management system 1 will be described. Fig. 7 is a block diagram showing an example of the hardware configuration of the calculator 30. The calculator 30 is an example of hardware used as a computer that can operate as the integrated management system 2 and the USB management device 12 according to this embodiment. The integrated management system 2 according to this embodiment realizes an authentication method in which the functional blocks shown in Fig. 6 cooperate with each other by causing the calculator 30 (computer) to execute a program.
[0078] The computer 30 includes a CPU (Central Processing Unit) 31, a ROM (Read Only Memory) 32, and a RAM (Random Access Memory) 33, each connected to a bus 34. The computer 30 further includes a non-volatile storage 35 and a network interface 36.
[0079] The CPU 31 reads out program code of software that realizes each function according to this embodiment from the ROM 32, loads it into the RAM 33, and executes it. Variables, parameters, etc. that arise during the calculation processing of the CPU 31 are temporarily written to the RAM 33, and these variables, parameters, etc. are read out by the CPU 31 as appropriate. However, an MPU (Micro Processing Unit) may be used instead of the CPU 31. Each functional unit of the integrated management system 2 and the USB management device 12 is realized by the CPU 31.
[0080] The nonvolatile storage 35 may be, for example, a hard disk drive (HDD), a solid state drive (SSD), a flexible disk, an optical disk, a magneto-optical disk, a CD-ROM, a CD-R, a magnetic tape, or a nonvolatile memory. The nonvolatile storage 35 stores an operating system (OS), various parameters, and programs for operating the computer 30. The ROM 32 and the nonvolatile storage 35 store programs and data necessary for the CPU 31 to operate, and are used as an example of a computer-readable, non-transitory storage medium that stores programs executed by the computer 30. The nonvolatile storage 35 configures each database of the integrated management system 2 and stores USB management device information 16 of the USB management device 12.
[0081] The network interface 36 may be, for example, a network interface card (NIC), and various data may be transmitted and received between devices via a local area network (LAN) or dedicated line connected to the terminal of the NIC. The integrated management system 2 and the USB management device 12 are connected via the network interface 36.
[0082] In the USB integrated management system 1 according to the embodiment described above, processing is started with the USB client 8 connected to the USB management device 12, and the USB management device 12 further connected to the USB user terminal 19. Then, the authentication data analysis unit 13 of the USB management device 12 analyzes the authentication data 9 stored in the USB client 8 by the integrated management system 2. Then, the authentication data analysis unit 13 authenticates the USB client 8 based on the analysis result of the authentication data 9 and information required for use of the USB client 8, and can make the data 11 used by the USB user terminal in the USB client 8 available for use. This allows the USB management device 12 to manage the usage status of the data stored in the USB client 8.
[0083] Here, the authentication data 9 created by the integrated management system 2 is analyzed by the USB management device 12. At this time, whether the USB client 8 is a legitimate device is determined based on whether the user information, USB management device information, USB information, and data to be used obtained by analyzing the authentication data 9 match the data acquired by the USB management device 12 from the USB client 8. Furthermore, if the user information does not match, the USB user terminal 19 cannot use the data 11 that is stored in the USB client 8 and can be used by the USB user terminal. Therefore, the USB management device 12 can manage users who can use the data stored in the USB client 8. For example, it is managed which users can use the data stored in the USB client 8 for which USB user terminal 19.
[0084] Furthermore, if the USB client 8 is a device not authorized by the system administrator, the data in the authentication data 9 will not match. This makes it possible to prevent an unauthorized USB client 8 from being connected to the USB terminal 19 and data from being imported into the USB terminal 19.
[0085] Furthermore, the integrated management system 2 can separately manage data that can be used by the user 18 according to the authority of the user 18. For example, the data used by the USB terminal 19 differs according to the authority of the user or the type of data. Therefore, data that cannot be handled with the authority of the user 18 does not need to be transferred from the USB client 8 to the USB terminal 19.
[0086] [Variations] The integrated management system 2 may transfer the data 11 to be used by the USB terminal 19 and the authentication data 9 to the USB client 8 in advance before the USB terminal 19 uses the USB client 8. Therefore, the integrated management system 2 can be separated from the USB management device 12 after providing the necessary information to the USB management device 12. In this case, when the USB client 8 is used by the USB terminal 19, the USB integrated management system 1 can be configured as only the USB management device 12, excluding the integrated management system 2. Even in an offline environment where the USB management device 12 cannot be connected to the integrated management system 2, if the authentication data analysis unit 13 determines that the analysis result of the authentication data 9 is normal, the data 11 to be used by the USB terminal 19 is transferred to the USB terminal 19, and the USB terminal 19 can use the data.
[0087] Alternatively, data information may not be used to create the authentication data 9. In this case, the authentication data creation unit 4 creates the authentication data 9 based on USB management device information that uniquely identifies the USB management device 12, user information about the user who will use the data, and USB information, as information required for using the USB client 8. The authentication data analysis unit 13 can also analyze the authentication data 9 based on the USB management device information, user information, and USB information.
[0088] In the above-described embodiment, an example of a USB client 8 having a connector conforming to the USB standard has been described. Alternatively, a storage, memory card, or the like to which a communication cable conforming to a transmission standard other than USB can be connected may be used as the mass storage. Even in this case, the USB management device 12 can manage the usage status of data used by users of mass storage by providing a management device corresponding to the above-described USB management device 12 in the portion corresponding to the insertion port of each storage or memory card.
[0089] Furthermore, the present invention is not limited to the above-described embodiment, and it goes without saying that various other applications and modifications are possible without departing from the gist of the present invention as set forth in the claims. For example, the above-described embodiment has described the system configuration in detail and specifically to clearly explain the present invention, and is not necessarily limited to a system including all of the described configurations. Furthermore, it is also possible to add, delete, or replace part of the configuration of this embodiment with other configurations. In addition, the control lines and information lines shown are those that are considered necessary for the explanation, and do not necessarily show all the control lines and information lines in the product. In reality, it can be assumed that almost all components are interconnected. [Explanation of symbols]
[0090] 1...USB integrated management system, 2...integrated management system, 3...user information database, 4...authentication data creation unit, 5...USB information database, 6...USB management device information database, 7...data used in USB-using terminal, 8...USB client, 9...authentication data, 10...USB information, 11...data used in USB-using terminal, 12...USB management device, 13...authentication data analysis unit, 14...user information input unit, 15...USB information acquisition unit, 16...USB management device information, 17...data transfer unit, 18...user, 19...USB-using terminal
Claims
1. a storage medium management device that manages a storage medium in which data is stored, and an integrated management device that manages the storage medium and the storage medium management device; The integrated management device an authentication data creation unit that creates authentication data used to authenticate the storage medium based on storage medium management device information that uniquely represents the storage medium management device, user information of a user who uses the data, and storage medium information specific to the storage medium as information required for using the storage medium, and stores the authentication data in the storage medium; the storage medium management device, an authentication data analysis unit that, when the storage medium is connected to the storage medium management device and the storage medium management device is connected to a user terminal, acquires information required for use of the storage medium and the authentication data from the storage medium, analyzes the authentication data, and authenticates the storage medium based on the analysis result of the authentication data acquired from the storage medium and the information required for use of the storage medium acquired from the storage medium; a data transfer unit that, when the authentication result by the authentication data analysis unit is normal, makes the data stored in the storage medium available for use by the user terminal and transfers the data stored in the storage medium to the user terminal. Integrated storage media management system.
2. the storage medium management device, a storage medium information acquisition unit that acquires the storage medium information from the storage medium; Storage medium management device information stored in advance; a user information input unit into which the user information that uniquely represents the user is input; The storage media integrated management system according to claim 1 .
3. The authentication data analysis unit determines that the authentication result of the storage medium is normal if the storage medium management device information obtained by analyzing the authentication data by the authentication data analysis unit is the same as the storage medium management device information read from the storage medium, the storage medium information obtained by analyzing the authentication data by the authentication data analysis unit is the same as the storage medium information read from the storage medium, and the user information obtained by analyzing the authentication data by the authentication data analysis unit is the same as the user information input from the user information input unit. The storage media integrated management system according to claim 2 .
4. the integrated management device has a first data information creation unit that creates data information based on data used in the user terminal, the authentication data creation unit creates the authentication data based on the storage medium management device information, the user information, the storage medium information, and the data information created by the first data information creation unit as information required for using the storage medium; the storage medium management device, a second data information creation unit that creates data information based on data used by the user terminal and stored in the storage medium; The authentication data analysis unit analyzes the authentication data based on the data information created by the second data information creation unit, the user information, the storage medium management device information, and the storage medium information. The storage media integrated management system according to claim 3 .
5. The data used in the user terminal varies depending on the authority of the user or the type of the data. The storage media integrated management system according to claim 4 .
6. A storage medium management device for managing a storage medium on which data is stored, comprising: an authentication data analysis unit that acquires authentication data used to authenticate the storage medium from the storage medium, the authentication data being created based on storage medium management device information uniquely representing the storage medium management device, user information of the user who uses the data, and storage medium information specific to the storage medium as information required for use of the storage medium, by connecting the storage medium to the storage medium management device and connecting the storage medium management device to a user terminal, acquires the information required for use of the storage medium and the authentication data from the storage medium, analyzes the authentication data, and authenticates the storage medium based on the analysis result and the information required for use of the storage medium acquired from the storage medium; a data transfer unit that, when the authentication result by the authentication data analysis unit is normal, makes the data stored in the storage medium available to the user terminal and transfers the data stored in the storage medium to the user terminal. Storage media management device.
Citation Information
Patent Citations
Portable storage medium management system, portable storage medium management method, and portable storage medium management program
JP2009181176A
USB host, control method therefor, computer program, USB hub, and USB device
JP2009230685A
Information processing device, information processing method, and program
JP2012247961A
Storage device
JP2022071527A
Information processing device, information processing method, and program
US20140075195A1