File access authority management system and file access authority management method

The system securely manages file access by authenticating users and verifying their locations using a server-based method with one-time passwords and location verification, addressing vulnerabilities in teleworking environments.

JP7760400B2Active Publication Date: 2025-10-27ALSOK INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2022017508
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-07
Publication Date
2025-10-27
Estimated Expiration
2042-02-07

AI Technical Summary

Technical Problem

Existing file access management systems are vulnerable to unauthorized access when IC card readers or terminals are used in teleworking environments, as they lack the ability to authenticate users and verify their locations accurately, leading to potential file access in unintended locations.

Method used

A system and method that utilizes a server to manage access rights, where a first user terminal requests a one-time password, which is converted into a readable format by a second user terminal, and both terminals' locations are verified against pre-registered information to ensure authorized access.

Benefits of technology

This approach ensures secure file access by authenticating user identity and verifying proximity, preventing unauthorized access at unintended locations, thus enhancing security in teleworking scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007760400000001
    Figure 0007760400000001
  • Figure 0007760400000002
    Figure 0007760400000002
  • Figure 0007760400000003
    Figure 0007760400000003
Patent Text Reader

Abstract

To provide a file access authority management system and a file management method that restrict viewing of a file to which access authority is granted.SOLUTION: In a file access authority management system 1, when receiving a file opening operation from a user X, a file viewing terminal 4a transmits a file opening permission request to a file access authority management server 7, receives a one-time password issued by the server, converts it into a QR code, and displays it. A mobile terminal 5a reads information on the QR code, and transmits read IC card information of the user X and position information of the mobile terminal to the file access authority management server. As a result of performing comparison between the one-time password and the QR code information, and comparison between position information indicating a usage location of the file viewing terminal registered in association with the IC card information and the position information of the mobile terminal, if they match, the file access authority management server permits the file viewing terminal 4a to open a file.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a file access authority management system and a file access authority management method that restricts viewing of files to which access authority has been granted. [Background technology]

[0002] In information processing and information management devices such as servers that store document files, image files, etc., file access permissions are set on the devices where files are stored, from the viewpoint of maintaining confidentiality of information and preventing its dispersion, and in order to allow only authorized persons to access the files, it has been common practice to authenticate the account and ID of the file accessing person, and if the authentication is successful, file access is permitted.

[0003] In such cases, for example, to limit file viewing locations to a specific room, an IC card is read using an IC card reader installed in a fixed location, and the file access permissions associated with that IC card are enabled.

[0004] For example, Patent Document 1 discloses a system in which an IC card reader is used to enable or disable the account ID of a file accessing user who enters a room, allowing only file accessing users who are present in a specific room to access the file. Also known is a system that compares the current location of a terminal requesting access to a file with a location range in which access to the file is permitted, and permits the terminal to access the file if it is within the permitted range (for example, Patent Document 2). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2000-259567 [Patent Document 2] Japanese Patent Application Laid-Open No. 2008-250627 DISCLOSURE OF THE INVENTION [Problem to be solved by the invention]

[0006] Recently, with the increase in teleworking (working from home or remote locations) and remote meetings, there are more and more opportunities for users to access necessary information using mobile information terminals such as laptops in locations away from facilities where servers storing information files and the like are installed.

[0007] In such a situation, it is necessary to make it possible to view files in places other than a specific room, or in a telework environment, rather than limiting the location of file viewing. Therefore, if the IC card reader is not fixed but made movable, there is a problem that if the IC card reader itself or the IC card is lost or stolen, file access permissions will be activated in an unintended location, and files will be opened.

[0008] Furthermore, even if the IC card reader is in the intended location, if the terminal accessing the file is in a different location from the IC card reader, there is a problem in that the file may be opened in an unintended location.

[0009] The present invention has been made in consideration of the above-mentioned problems, and its object is to provide a file access permission management system and a file access permission management method that prevent files from being opened, viewed, etc. in places other than pre-designated locations. [Means for solving the problem]

[0010] As one means for achieving the above-mentioned object and solving the above-mentioned problem, the file access right management system of the present invention is configured to include a server for managing access rights to files, a first user terminal that accepts a user's operation to access a file and is able to open a file by receiving a file opening permission signal from the server, and a second user terminal that acquires second user information of the user and transmits it to the server, wherein the server comprises a location information registration unit that registers in advance first location information indicating a location where the first user terminal is used in association with first user information that identifies the user, a password issuing unit that issues a one-time password upon receiving a file opening request from the first user terminal, and a communication unit that transmits the issued one-time password to the first user terminal, and wherein the first user terminal, upon accepting the user's operation to access a file, transmits a file access request to the server and receives the issued one-time password and the file opening permission signal from the server. a first communication unit and a conversion unit that converts the received one-time password into code information in a format that can be acquired by the second user terminal, wherein the second user terminal comprises a code information acquisition unit that acquires the code information from the first user terminal, a location information acquisition unit that acquires second location information that indicates its own location, a user information acquisition unit that acquires the second user information, and a second communication unit that transmits the second user information acquired by the user information acquisition unit, the code information acquired by the code information acquisition unit, and the second location information acquired by the location information acquisition unit to the server, wherein the server comprises comparison means that compares the first user information with the second user information received from the second user terminal, compares the one-time password with the code information received from the second user terminal, and compares the first location information with the second location information received from the second user terminal, and when the comparison means determines that the first user information and the second user information match, and the one-time password and the code information match,The system further comprises a permission means for transmitting the file opening permission signal to the first user terminal and permitting the opening of the file requested to be opened when the first location information and the second location information match or the difference between the location information is within a predetermined range.

[0011] For example, the code information acquisition unit may capture a two-dimensional code and acquire the code information contained in the two-dimensional code, and the conversion unit may convert the one-time password into a two-dimensional code that can be captured by the second user terminal and visibly display it on the first user terminal. For example, the first user terminal and the second user terminal each further include wireless communication means for mutual communication, and the conversion unit converts the one-time password received by the first communication unit into code information that the second user terminal can receive via the wireless communication means, and the code information acquisition unit acquires the converted code information via the wireless communication means. For example, the user information acquisition unit may acquire the second user information from an IC card held by the user. For example, the difference between the first location information and the second location information may be the difference in physical distance between the location of use of the first user terminal, which is registered in advance in the location information registration unit, and the location indicated by the second location information. For example, the second user terminal may be a mobile terminal including at least a smartphone.

[0012] As a means for solving the above-mentioned problems, a file access right management method according to the present invention is a file access right management method in a file access right management system including a first user terminal, a second user terminal, and a server for managing access rights to files, the method including the steps of: the server registering in advance first location information indicating a location where the first user terminal is used in association with first user information that identifies the user; the server issuing a one-time password upon receiving a file opening request from the first user terminal; the first user terminal converting the one-time password into code information in a format that can be acquired by the second user terminal; the second user terminal acquiring the converted code information and second user information that identifies the user; and the server registering the location of the second user terminal in association with the first location information that identifies the user. a step of the second user terminal transmitting the second user information, the code information, and the second location information to the server; a comparison step in which the server compares the first user information with the second user information, compares the one-time password with the code information, and compares the first location information with the second location information; and a step in which the server permits the first user terminal to open the requested file if, in the comparison step, the first user information and the second user information match, the one-time password and the code information match, and the first location information and the second location information match, or if a difference between the first location information and the second location information is within a predetermined range. [Effects of the Invention]

[0013] According to the present invention, it is possible to simultaneously authenticate the identity of a user who has accessed a file using a first user terminal, confirm the current location, and confirm the proximity between the first user terminal and a second user terminal such as a smartphone that functions as an IC card reader, thereby reliably preventing the file from being opened, viewed, etc. in locations other than those designated in advance. [Brief explanation of the drawings]

[0014] [Figure 1] 1 is a diagram illustrating the overall configuration of a file access authority management system according to an embodiment of the present invention. [Figure 2] 1 is a block diagram showing an example of the configuration of a file access authority management server installed in a file management center. [Figure 3] FIG. 10 is a diagram showing a file opening permission sequence in a file access authority management system. [Figure 4] 10 is a diagram showing an example of information registered in a file opening permission storage unit of a file access authority management server. FIG. DETAILED DESCRIPTION OF THE INVENTION

[0015] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. FIG. 1 is an overall configuration diagram of a file access authority management system according to one embodiment of the present invention. The file access authority management system 1 shown in FIG. 1 is configured so that a file access authority management server 7 (corresponding to the server of the present invention) can transmit and receive data to and from file viewing terminals 4a-4c (corresponding to first user terminals of the present invention) such as personal computers (PCs), and mobile terminals 5a-5c (corresponding to second user terminals of the present invention) such as smartphones via a communication network (network) 2, such as the Internet or a high-speed optical communication network. The mobile terminals 5a-5c are equipped with a GPS (Global Positioning System) function and can obtain their current location information using a communication satellite 10.

[0016] The file access permission management server 7 is installed in a file access permission management center 3 that controls the file access permission management system 1. Under the management of the file access permission management center 3, a user X who is a file viewer uses a file viewing terminal 4a at a pre-registered location A to access a file stored in any storage medium, storage device, etc. (not shown) that can be accessed from the file viewing terminal 4a, open it, view the contents, and perform editing such as adding and deleting information.

[0017] Similarly, other users Y and Z can use file viewing terminals 4b and 4c and mobile terminals 5b and 5c at pre-registered locations B and C to access files stored on any storage medium, storage device, etc. (not shown) that can be accessed from the file viewing terminals 4b and 4c, open them, view the contents, add information, delete information, and perform other editing operations.

[0018] Fig. 2 is a block diagram showing an example of the configuration of the file access permission management server 7 installed in the file access permission management center 3. As shown in Fig. 2, the file access permission management server 7 includes a control unit 20 that controls the entire file access permission management server 7, a storage unit 30 that stores user information, control information, etc., and a communication control unit 40 that functions as a network interface (I / F) for the communication network 2.

[0019] The control unit 20 includes a central processing unit (CPU) 21, which is formed by a microprocessor or the like, a one-time password issuing unit 22, and a file opening permission determining unit 23. The storage unit 30 includes a control data storage unit 31, which stores file management software and control data necessary for the operation of the central processing unit (CPU) 21, a one-time password storage unit 32, and a file opening permission storage unit 33.

[0020] The storage unit 30 is made up of, for example, a hard disk drive (HDD), a large-capacity semiconductor memory, etc. The control data storage unit 31 is made up of, for example, a read-only memory (ROM), a non-volatile memory, etc.

[0021] In the above-mentioned file access permission management system 1, the control unit 20, memory unit 30, communication control unit 40, etc. are configured to be installed together inside a single file access permission management server 7, but these may also be appropriately distributed and arranged in multiple devices, each of which is connected to the communication network 2.

[0022] Next, a file opening permission control in the file access permission management system according to this embodiment will be described. Fig. 3 is a diagram showing a file opening permission sequence in the file access permission management system according to this embodiment. Note that the following description will be given taking the file opening operation by user X as an example.

[0023] 3, user X, who wishes to open a file stored in any storage medium, storage device, or the like (not shown) accessible from file viewing terminal 4a, performs an operation to open the file on file viewing terminal 4a, for example, by clicking an icon representing the file on the screen. Receiving this operation, file viewing terminal 4a transmits a file opening permission request signal to file access authority management server 7 via communication network 2 in step S2.

[0024] In step S3, the central processing unit (CPU) 21 of the file access authority management server 7, which has received the file opening permission request signal from the file viewing terminal 4a, starts the one-time password issuing unit 22. In step S5, the one-time password issuing unit 22 issues a one-time password to the file viewing terminal 4a via the communication network 2.

[0025] After issuing the one-time password to the file viewing terminal 4a, the one-time password issuing unit 22 stores the issued one-time password in the one-time password storage unit 32 in the storage unit 30 in step S7.

[0026] In step S8, the file viewing terminal 4a, which has received the one-time password from the file access authority management server 7, converts the one-time password into a two-dimensional code that can be captured by the mobile terminal 5a. Here, the one-time password is converted into a QR code (registered trademark), which is a two-dimensional code, and is visibly displayed on the screen.

[0027] In step S10, the user X uses the image capturing function (camera) of the portable terminal 5a to perform an operation to read the QR code displayed on the file viewing terminal 4a in step S8 above. As a result, in step S11, the portable terminal 5a reads the QR code information from the QR code visibly displayed on the file viewing terminal 4a.

[0028] Furthermore, in step S11, the portable terminal 5a displays a screen prompting the user X to read an IC card such as an ID card held by the user X. After visually checking this display, the user X performs an IC card reading operation in step S12 by holding the IC card over the portable terminal 5a that has an IC card reading function or by inserting the IC card into a predetermined reader (IC card reader) connected to the portable terminal 5a.

[0029] As a result, the mobile terminal 5a reads the predetermined information from the IC card in step S15. The predetermined information from the IC card (corresponding to the second user information of the present invention) may be, for example, the unique identification number of the IC card, the authentication number (user ID) of user X, an employee number, a subscriber number of the file access authority management system, etc.

[0030] In step S15, the mobile terminal 5a further uses the GPS function to acquire current location information (corresponding to second location information of the present invention) of the mobile terminal 5a from the communication satellite 10. The location information here is, for example, latitude and longitude information indicating the location of the user X who is using the mobile terminal 5a.

[0031] In step S17, the mobile terminal 5a transmits the QR code information and IC card information read in steps S11 and S15, respectively, and the location information acquired in step S15 to the file access authority management server 7 of the file access authority management center 3.

[0032] For example, a file opening permission request sending unit provided in the mobile terminal 5a sends this information to the communication control unit 40 of the file access authority management server 7 via the wireless communication network 6 and the communication network 2. The communication control unit 40 stores the received information in a file opening permission request receiving unit (not shown) provided within the communication control unit 40.

[0033] In step S18, the central processing unit (CPU) 21 compares the one-time password indicated by the QR code information received by the communication control unit 40 from the mobile terminal 5a and stored in the file opening permission request receiving unit within the communication control unit 40 with the one-time password stored in the password memory unit 32 in the above step S7.

[0034] If, as a result of this comparison, it is determined that the one-time password indicated by the QR code information received from the mobile terminal 5a matches the one-time password stored in the password memory unit 32 (step S18; YES), the central processing unit (CPU) 21 transmits the IC card information and location information stored in the file opening permission request receiving unit to the file opening permission determination unit 23 in the control unit 20.

[0035] If it is determined in step S18 that the one-time passwords do not match (step S18; NO), it is treated as if user X does not have the authority to access the file, and in step S19, a file opening denial signal is sent to the file viewing terminal 4a via the communication control unit 40.

[0036] In the file access permission management system 1 according to this embodiment, the location where a user accesses and opens a file (corresponding to the first location information of the present invention) is linked in advance to IC card information (corresponding to the first user information of the present invention) for each user and registered in the file opening permission memory unit 33 in the memory unit 30 by the system administrator of the file access permission management server 7.

[0037] 4 shows an example of information registered in the file opening permission storage unit 33. Here, for user X whose IC card information is 123A, location information 35-140, i.e., a location of "35 degrees north latitude, 140 degrees east longitude" (Tokyo) is registered in advance as the location where the file should be opened.

[0038] Similarly, user Y, whose IC card information is 819B, is pre-registered with a location of "34 degrees north latitude, 135 degrees east longitude" (Osaka) as the file opening location, and user Z, whose IC card information is 745C, is pre-registered with a location of "43 degrees north latitude, 141 degrees east longitude" (Sapporo).

[0039] The file access permission determination unit 23 of the file access authority management server 7 compares the IC card information and location information stored in the file opening permission request receiving unit with the IC card information and location information registered in advance in the file opening permission storage unit 33.

[0040] That is, in step S20, the file opening permission determination unit 23 compares the IC card information stored in the above-mentioned file opening permission request receiving unit with the pre-registered IC card information for user X. If these pieces of IC card information do not match (step S20; NO), it is treated as if user X does not have access authority to the file, and in step S21, it transmits a file opening denial signal to the file viewing terminal 4a via the communication control unit 40.

[0041] If it is determined in step S20 that the IC card information matches (step S20; YES), the file opening permission determination unit 23 determines that user X has the authority to access the file, and in step S23 compares the location information stored in the file opening permission request receiving unit with the pre-registered location information. This is a process to determine whether the location where user X is attempting to open the file on the file viewing terminal 4a matches the pre-registered location, or whether the location is within a short distance of the pre-registered location.

[0042] If a positive judgment (YES) is obtained in step S23, the file opening permission judgment unit 23 treats the location information (location of use) of user X's file viewing terminal 4a as being the same as the location information of a pre-registered location, or as being within a predetermined distance therefrom (in other words, user X is at or near that location), and in step S25, transmits a file opening permission signal to the file viewing terminal 4a via the communication control unit 40.

[0043] On the other hand, if the determination in step S23 is negative (NO), the file opening permission determination unit 23 determines that the location where user X is using the file viewing terminal 4a is different from the pre-registered location or is more than a predetermined distance away from that location, and that user X is not at or near the registered location, and in step S27, it sends a file opening denial signal to the file viewing terminal 4a via the communication control unit 40.

[0044] In addition, the "within a specified distance" between the location information (location of use) stored in the file opening permission request receiving unit and the pre-registered location information (registered location) is defined here as meaning a range of physical distance, such as "within a range of several hundred meters."

[0045] In step S29, the file viewing terminal 4a determines whether it has received a file opening permission signal from the file access authority management server 7 (i.e., file opening permission is granted) or whether it has received a file opening denial signal (i.e., file opening is not permitted). If it has received a file opening permission signal (step S29; YES), in step S30, the file viewing terminal 4a displays on the screen the contents of the file that user X opened (clicked) in step S1 above. This allows user X to view the contents of the accessed file or to edit it by adding or deleting information, etc.

[0046] In step S29, if a file opening denial signal is received from the file access authority management server 7 (step S29; NO), it is treated as if the user X of the file viewing terminal 4a does not have access authority to the file, or even if he has access authority, the location where the file viewing terminal 4a is being used is not a pre-registered location or is more than a predetermined distance away from the registered location, and in step S31, a message such as "File opening denial" is displayed on the screen of the file viewing terminal 4a.

[0047] It should be noted that if user X receives a file opening denial signal as a result of performing a file opening operation on the file viewing terminal 4a, a more detailed message may be displayed. For example, the file access authority management server 7 may make the file opening denial signal sent to the file viewing terminal 4a in steps S19 and S21 and the file opening denial signal sent in step S27 into distinguishable signals (for example, the former signal is a "file opening denial signal (no authority)" and the latter signal is a "file opening denial signal (location mismatch)"), and may display, for example, "no access authority" or "location of terminal use does not match registered location" depending on the type of signal received.

[0048] On the other hand, it is also possible that the user may receive a file opening permission signal from the file access authority management server 7 on the file viewing terminal 4a, open the file, and then move to a location different from the registered location. To deal with such a case, for example, even after opening the file, the QR code displayed on the file viewing terminal 4a may be periodically read by the mobile terminal 5a, and the read QR code information may be transmitted to the file access authority management server 7 together with the obtained current location information, thereby confirming the user's current location.

[0049] By configuring in this way to periodically check the user's location information, etc., it becomes possible for the user to access files using a file viewing terminal while traveling by train, car, or the like, for example.

[0050] Alternatively, the system may be configured so that the user's pre-registered location information can be updated to new location information by contacting the system administrator of the file access authority management server 7. Also, in order to allow the same user to use the file viewing terminal in multiple different locations, the file opening permission storage unit 33 may be configured so that multiple different location information can be registered in advance for the same user.

[0051] Furthermore, in order to prevent the QR code displayed on the screen after converting the one-time password received by the file viewing terminal from being transferred to anyone other than the user, for example, a time limit may be set for the QR code to be displayed on the screen, and the display may be removed from the screen after the time limit has elapsed. Alternatively, a QR code may be associated with a smartphone that can read it, and the QR code displayed on the screen may not be readable by any smartphone other than the smartphone that reads it.

[0052] The registered location information pre-registered in the file opening permission storage unit 33 described above is not limited to latitude and longitude information. For example, it may be the address of the location where the file viewing terminal is used, the building name, or the room number within the building. In this case, a map information database capable of searching for corresponding latitude and longitude information from this information may be provided separately, and the file opening permission determination unit 23 may search the map information database based on, for example, the address, extract the corresponding latitude and longitude, and use the extracted latitude and longitude information to compare with the location information stored in the file opening permission request receiving unit (the latitude and longitude information acquired by the mobile terminal 5a). Alternatively, location information used to identify the location of a mobile phone in a wireless network (mobile phone network) may be registered. Furthermore, information combining this location information with latitude and longitude information may be used as the registered location information.

[0053] In the file access permission management system 1 according to the above embodiment, a QR code displayed on the screen of the file viewing terminal is read by a smartphone to confirm that the file viewing terminal and the smartphone functioning as an IC card reader are in close proximity, but the confirmation method is not limited to this.

[0054] Specifically, as a means of short-range communication between the file viewing terminal and the IC card reader (smartphone), for example, low-power short-range wireless technology such as Bluetooth Low Energy (BLE) or Wi-Fi communication (Bluetooth and Wi-Fi are registered trademarks) may be used, and instead of the QR-coded one-time password in the above embodiment, the one-time password information may be sent directly from the file viewing terminal to the IC card reader.

[0055] Furthermore, BT beacons using Bluetooth signals can also be used as a means of acquiring user location information. In particular, BT beacons can determine the user's location within a range of several tens of meters, so they can be applied to determining the location of a user in a specific room within the building mentioned above.

[0056] As described above, the file access permission management system according to this embodiment is configured so that, when a file viewing terminal requests the file access permission management server that manages file access rights to open a file, the one-time password issued by the server is converted into a QR code and displayed on the file viewing terminal, and the user of the file viewing terminal reads the QR code with a mobile terminal such as a smartphone that is an IC card reading terminal, and then transmits the obtained QR code information, IC card information, and location information indicating the location of the mobile terminal such as a smartphone to the file access permission management server.

[0057] Therefore, the file access authority management server compares the one-time password issued to the user with the QR code information received from the mobile device such as a smartphone, and further compares the location information indicating the location of the file viewing device, which has been registered in advance by linking it to the IC card information, with the location information received from the mobile device such as a smartphone, and if they match, the file is allowed to be opened.

[0058] In this way, by performing user identity authentication, checking the current location, and checking the proximity of the file viewing terminal to the smartphone all at once, it is possible to quickly determine whether the location where the pre-specified file viewing terminal is being used matches the current location or is within a specified range, thereby reliably preventing files from being opened, viewed, etc. at locations other than the pre-specified location or a location nearby, thereby improving the security of file management.

[0059] In addition, by using a smartphone as an IC card reading terminal (IC card reader), the IC card reader can be moved.In addition, by linking the IC card information to the location (location information) where the file viewing terminal is used and registering it in advance, even if the IC card reader is moved (installed) to any location, files can only be opened, viewed, etc. at that location. [Explanation of symbols]

[0060] 1. File Access Permission Management System 2. Communication Network 3. File Management Center 4a~4c File viewing terminal 5a~5c Mobile devices 6. Wireless communication network 7 File access authority management server 10. Communications satellites 20 Control Unit 21 Central Processing Unit (CPU) 22 One-Time Password Issuance Department 23 File Opening Permission Determination Unit 30 Storage section 31 Control data storage unit 32 One-time password storage section 33 File Opening Permission Memory 40 Communication control unit

Claims

1. A file access authority management system comprising: a server that manages access rights to files; a first user terminal that accepts a user's access operation to a file and is able to open the file by receiving a file opening permission signal from the server; and a second user terminal that acquires second user information of the user and transmits the second user information to the server, The server a location information registration unit that registers in advance first location information indicating a location where the first user terminal is used in association with first user information that identifies the user; a password issuing unit that issues a one-time password in response to a request to open a file from the first user terminal; a communication unit that transmits the issued one-time password to the first user terminal; Equipped with The first user terminal a first communication unit that, upon receiving an operation to access a file from the user, transmits a file access request to the server and receives the issued one-time password and the file opening permission signal from the server; a conversion unit that converts the received one-time password into code information in a format that can be acquired by the second user terminal; Equipped with The second user terminal a code information acquisition unit that acquires the code information from the first user terminal; a location information acquisition unit that acquires second location information indicating its own location; a user information acquisition unit that acquires the second user information; a second communication unit that transmits the second user information acquired by the user information acquisition unit, the code information acquired by the code information acquisition unit, and the second location information acquired by the location information acquisition unit to the server, The server a comparison means for comparing the first user information with the second user information received from the second user terminal, for comparing the one-time password with the code information received from the second user terminal, and for comparing the first location information with the second location information received from the second user terminal; permission means for transmitting the file opening permission signal to the first user terminal and permitting the opening of the file requested to be opened when the first user information and the second user information match, the one-time password and the code information match, and the first location information and the second location information match or the difference between the location information is within a predetermined range in the comparison means; The file access authority management system further comprises:

2. the code information acquisition unit captures an image of a two-dimensional code and acquires the code information included in the two-dimensional code; 2. The file access authority management system according to claim 1, wherein the conversion unit converts the one-time password into a two-dimensional code that can be imaged by the second user terminal and visibly displays it on the first user terminal.

3. the first user terminal and the second user terminal each further include wireless communication means capable of communicating with each other; the conversion unit converts the one-time password received by the first communication unit into code information that can be received by the second user terminal via the wireless communication means; 2. The file access authority management system according to claim 1, wherein the code information acquisition unit acquires the converted code information via the wireless communication means.

4. 4. The file access authority management system according to claim 1, wherein the user information acquisition unit acquires the second user information from an IC card held by the user.

5. A file access authority management system described in any one of claims 1 to 4, characterized in that the difference between the first location information and the second location information is the physical distance between the location of use of the first user terminal, which is pre-registered in the location information registration unit, and the location indicated by the second location information.

6. 6. The file access authority management system according to claim 1, wherein the second user terminal is a mobile terminal including at least a smartphone.

7. A file access authority management method in a file access authority management system including a first user terminal, a second user terminal, and a server that manages access rights to files, comprising: The server registers in advance first location information indicating a location where the first user terminal is used, in association with first user information that identifies the user; the server issuing a one-time password when receiving a request to open a file from the first user terminal; a step of converting the one-time password by the first user terminal into code information in a format that can be acquired by the second user terminal; The second user terminal acquires the converted code information and second user information that identifies the user; acquiring second location information indicating a location of the second user terminal; The second user terminal transmits the second user information, the code information, and the second location information to the server; a comparison step in which the server compares the first user information with the second user information, compares the one-time password with the code information, and compares the first location information with the second location information; a step of permitting the first user terminal to open the requested file from the server if the first user information and the second user information match, the one-time password and the code information match, and the first location information and the second location information match, or if a difference between the first location information and the second location information is within a predetermined range in the comparison step; A file access authority management method comprising:

Citation Information

Patent Citations

  • Production of worcester sauces

    JP1988068062A

  • Device and method for controlling access and storage medium

    JP2000259567A

  • Authentication system, authentication server, authentication method, and authentication program

    JP2007058469A

  • File management system, file management method and program

    JP2008250627A

  • Access control method and access control system

    JP2008257412A