computer program
The glasses-type device with iris authentication and wearing detection addresses security issues in VDI systems by ensuring only authorized users can access virtual desktops, enhancing security and reducing data exposure risks.
Patent Information
- Application Number
- JP2020128445
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-07-29
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2040-07-29
AI Technical Summary
VDI systems using laptop computers as thin clients face security challenges when used in public spaces due to the risk of unauthorized access and data exposure, especially during teleworking scenarios.
A computer program utilizing a glasses-type device equipped with iris authentication and wearing detection, which periodically acquires iris images and detection data to ensure secure access and display control, preventing unauthorized use and data leakage.
Enhances security by ensuring only authorized users can access virtual desktops, reducing risks of data exposure and theft, and allowing secure use of VDI systems in various environments.
Smart Images

Figure 0007796471000001 
Figure 0007796471000002 
Figure 0007796471000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a computer program. [Background technology]
[0002] In recent years, with the advancement of internet connection environments, an increasing number of companies, especially those in the IT industry, have been promoting teleworking. The recent COVID-19 pandemic has added to this trend, and teleworking has spread rapidly across all industries and occupations. Going forward, teleworking is expected to become even more widespread, not only during pandemics like the COVID-19 pandemic, but also in times of disasters like earthquakes, in order to continue operations.
[0003] BACKGROUND ART VDI (Virtual Desktop Infrastructure) is known as a technology for using one's own PC at work from an environment other than the workplace (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Publication No. 2019-053345 Summary of the Invention [Problem to be solved by the invention]
[0005] The VDI described in Patent Document 1 uses a laptop computer as a thin client. However, using a virtual desktop on such a laptop computer in a place where a third party can see it, such as a cafe or on a train, poses security challenges.
[0006] The present invention has been made in view of these problems, and its purpose is to provide a technology that can improve security when using a virtual desktop. [Means for solving the problem]
[0007] One aspect of the present invention relates to a computer program, which includes: a function for repeatedly acquiring images at a first frequency from an imaging unit provided in a glasses-type device so that an iris of a user can be imaged when the user wears the glasses-type device, and performing iris authentication based on the image each time the image is acquired; a function for receiving data transmitted from another device via a network when iris authentication based on the acquired image is successful; and a function for making the received data visible through the glasses-type device. Periodically or periodically The computer is made to realize a function of repeatedly acquiring images at the first frequency, while repeatedly acquiring detection results from a detection unit provided in the eyeglass-type device that detects whether the user is wearing the eyeglass-type device, at a second frequency higher than the first frequency, and a function of causing the eyeglass-type device to stop making data visible if the acquired detection result indicates that the device is not being worn.
[0008] In addition, any combination of the above components, or mutual substitution of the components or expressions of the present invention between devices, methods, systems, recording media storing computer programs, etc., are also valid aspects of the present invention. [Effects of the Invention]
[0009] According to the present invention, it is possible to improve security when using a virtual desktop. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a schematic diagram showing the configuration of a secure VDI system according to an embodiment. [Figure 2] FIG. 2 is a schematic diagram showing an example of the glasses-type device of FIG. [Figure 3] FIG. 2 is a hardware configuration diagram of the sorting server of FIG. [Figure 4] 2 is a block diagram showing the functions and configuration of the glasses-type device of FIG. 1. FIG. [Figure 5]FIG. 2 is a block diagram showing the functions and configuration of the mobile terminal of FIG. [Figure 6] 2 is a block diagram showing the functions and configuration of the sorting server of FIG. 1. FIG. [Figure 7] 7 is a data structure diagram showing an example of a user information storage unit in FIG. 6. [Figure 8] 7 is a data structure diagram showing an example of a device information storage unit in FIG. 6. [Figure 9] 2 is a flowchart showing the flow of a series of processes in the secure VDI system of FIG. 1. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, the same or equivalent components, parts, processes, and signals shown in each drawing will be denoted by the same reference numerals, and redundant explanations will be omitted where appropriate. In addition, some of the parts that are not important for the explanation will be omitted in each drawing.
[0012] 1 is a schematic diagram showing the configuration of a secure VDI system 2 according to an embodiment. The secure VDI system 2 includes an eyeglasses-type device 200, a mobile terminal 8, and a wireless keyboard 10 at a user 6 site, a terminal (not shown) of an administrator of an enterprise 16 to which the user 6 belongs, and a sorting server 100, a private cloud 12, and a public cloud 14 at a data center 4. The mobile terminal 8 and sorting server 100 are connected to each other via a network such as the Internet so that data can be communicated between them. The enterprise 16 and sorting server 100 are also connected via a network. The mobile terminal 8 is connected to the eyeglasses-type device 200 and the wireless keyboard 10 via short-range wireless communication such as Bluetooth (registered trademark), infrared communication, Wi-Fi communication, or NFC (Near Field Communication).
[0013] The secure VDI system 2 provides a VD (Virtual Desktop) service to a user 6. The sorting server 100 acquires screen information from the private cloud 12 or the public cloud 14 and transfers it to the mobile terminal 8. The mobile terminal 8 transfers the acquired screen information to the eyeglasses-type device 200. The eyeglasses-type device 200 displays a desktop screen based on the received screen information, making the desktop screen visible through the eyeglasses-type device 200. The user 6 performs operations such as character input, clicking, and dragging using an input device such as a wireless keyboard 10 or a wireless mouse (not shown). The operation details are transmitted to the mobile terminal 8 via short-range wireless communication and then transmitted from the mobile terminal 8 to the sorting server 100 via the network. The sorting server 100 transfers the received operation details to the private cloud 12 or the public cloud 14. In this way, a VD service is provided. In this VD service, the eyeglasses-type device 200 functions as a thin client in the VDI.
[0014] The VD service according to this embodiment uses the eyeglass-type device 200 as an interface with the user 6. This makes it easier to carry around than conventional notebook computers or the like, and allows for the provision of a VD service that is more suited to new work styles. Taking advantage of the property of the eyeglass-type device 200 that makes it difficult to peep, a more secure VD service can be provided. Furthermore, since the eyeglass-type device 200 allows the user to work in a relatively free posture, the eyeglass-type device 200 can also solve the problems of poor posture and reduced eyesight that accompany the operation of a smartphone or notebook computer. By employing a VD service using such an eyeglass-type device 200, the user 6 can obtain an environment in which he or she can work safely anytime, anywhere.
[0015] The glasses-type device 200 of the secure VDI system 2 is configured as a specialized terminal that operates only on a desktop screen. The glasses-type device 200 has no functions other than those required as a thin client of the VDI service, and in particular, the download and installation of applications is restricted or prohibited. Furthermore, the glasses-type device 200 does not have a camera for capturing images of the surrounding environment or the faces of other people. This eliminates concerns about privacy violations.
[0016] In other embodiments with looser security requirements, the thin client function of the VD service according to this embodiment may be realized by installing a dedicated application on a general-purpose glasses-type device.
[0017] The following describes the problems that arise when using a VD on a notebook computer and how the problems are solved by using the glasses-type device 200.
[0018] Scene 1: Use while on the move Issue 1: When using a laptop on the train, there is a risk that the person sitting next to you may be able to see what you are doing. Problem 2: When you want to use a laptop while sitting on a train, it can be cramped if there is little space between you and the person next to you. Issue 3: When you need to use a laptop computer, you cannot do so when there is no space to sit, such as when traveling on a train (standing). Problem 4: Bringing a laptop home makes my bag bulky and heavy. Reasons why the glasses-type device 200 solves the problem: Because the glasses-type device 200 is glasses-type, it is nearly impossible to sneak a peek at it. Therefore, problem 1 is solved. The glasses-type device 200 is more portable than a laptop computer, and it is also possible to use a simple keyboard that can be operated with one hand. Therefore, problems 2, 3, and 4 are solved.
[0019] Scene 2: Use on the go, such as at a cafe Issue 1: When using a laptop in a cafe, there is a risk that people around you will be able to see what you are doing. Issue 2: When using the service at a cafe, it can be difficult to use the restroom (it's difficult to carry a laptop computer to the restroom). Issue 3: There is a risk of theft when you take your eyes off the item, such as when you get up from your seat. Reasons why the glasses-type device 200 solves the problem: Because the glasses-type device 200 is glasses-shaped, it is nearly impossible to spy on it. Therefore, problem 1 is solved. The glasses-type device 200 is more portable than a laptop computer, so it is easy to take with you when you go to the restroom or get up from your seat. Therefore, problem 2 is solved. Regarding problem 3, the glasses-type device 200 is equipped with repeated iris authentication and connection destination control (connection destinations are fixed at the time of shipment from the factory), which will be described later, so even if it is stolen, it can be disabled except for legitimate use.
[0020] Scenario 3: Offshore partner using a laptop from home (for example, during a pandemic such as the COVID-19 outbreak in early 2020, when employees were prohibited from coming to the office) Issue: There is a risk that malicious partners may take out important data and documents (screenshots and recordings may be taken). Reasons why the eyeglass-type device 200 solves the problem: The eyeglass-type device 200 is equipped with a repeat iris authentication and wearing detection function, which will be described later, so the display turns off when the eyeglass-type device 200 is removed. Therefore, it is not possible to take an image of the display content by removing the eyeglass-type device 200. It is also not possible to record the display content while the eyeglass-type device 200 is still being worn. Therefore, the risk of data leakage via partners is reduced or eliminated.
[0021] Situation 4: If your device is stolen Issue: If the password is stolen, there is a possibility that an unauthorized person may connect to the VDI. Reasons why the glasses-type device 200 solves the problem: The glasses-type device 200 is equipped with a connection status control function (described later) that allows the sorting server 100 to block unauthorized access. The glasses-type device 200 also has repeated iris authentication implemented. Therefore, the risk of data leakage due to theft of the glasses-type device 200 is reduced or eliminated.
[0022] Fig. 2 is a schematic diagram showing an example of the eyeglass-type device 200 of Fig. 1. The eyeglass-type device 200 is a binocular see-through type device, and includes a left lens 202 with a display function, a right lens 204 with a display function, a bridge 206, a left eye iris imaging camera 208, a right eye iris imaging camera 210, a left temple 212, a left wearing sensor 214, a right temple 216, and a right wearing sensor 218.
[0023] The left eye iris imaging camera 208 and the right eye iris imaging camera 210 are both attached to the bridge 206, and their attachment positions and angles of view are set so that they can capture images of the left eye and right eye irises of the user 6 when the user 6 wears the eyeglass-type device 200. In this example, the left eye iris imaging camera 208 and the right eye iris imaging camera 210 are attached to the bridge 206, but they may be attached at any position as long as they can capture images of the user's irises, and may be attached, for example, around each lens or at the base of the temple.
[0024] The left wearing sensor 214 and the right wearing sensor 218 are attached to the left temple 212 and the right temple 216, respectively, and are both configured to detect whether or not the user 6 is wearing the eyeglass-type device 200. The left wearing sensor 214 and the right wearing sensor 218 may be object detection sensors such as capacitance sensors.
[0025] A battery, circuitry, antenna, etc. (not shown) are incorporated into the left temple 212 and / or the right temple 216. The configuration of the eyeglass-type device 200, excluding the left eye iris imaging camera 208, the right eye iris imaging camera 210, the left wearing sensor 214, and the right wearing sensor 218, may be the same as that of a known see-through type eyeglass-type device.
[0026] 2, a binocular see-through type eyeglass-type device 200 has been described, but in other examples, for example, a projector-type eyeglass-type device may be used. A projector-type eyeglass-type device is, for example, a head-mounted display that projects an image directly onto the retina using a micro-projector, so that what you want to see is "reflected" in your eyes, rather than "seeing" with your eyes (for example, the retinal scanning display "RETISSA Display II" manufactured by QD Laser).
[0027] As described above, the glasses-type device 200 in the secure VDI system 2 according to this embodiment includes at least a device that displays an image and a device that projects an image onto the retina of the eye, and other configurations are also possible. In this embodiment, it is sufficient that an image can be viewed through the glasses-type device 200, and any means for achieving this is acceptable.
[0028] Fig. 3 is a hardware configuration diagram of the sorting server 100 in Fig. 1. The sorting server 100 includes a memory 104, a processor 106, a communication interface 108, a display 102, and an input interface 110. These elements are each connected to a bus 112 and communicate with each other via the bus 112.
[0029] The memory 104 is a storage area for storing data and programs. The data and programs may be stored in the memory 104 permanently or temporarily. The processor 106 executes the programs stored in the memory 104 to realize various functions of the sorting server 100. The communication interface 108 is an interface for transmitting and receiving data to and from the outside of the sorting server 100. For example, the communication interface 106 includes an interface for accessing the Internet and an interface for accessing a LAN (Local Area Network) in the data center 4. The communication interface 108 may also include an interface for a wired network. The display 102 is a device for displaying various types of information, such as a liquid crystal display or an organic EL (Electroluminescence) display. The input interface 110 is a device for receiving input.
[0030] Figure 4 is a block diagram showing the functions and configuration of the glasses-type device 200 in Figure 1. Each block shown here can be realized in hardware by elements or mechanical devices such as a computer CPU, and in software by a computer program, etc., but here, functional blocks realized by the cooperation of these elements are depicted. Therefore, those skilled in the art who have read this specification will understand that these functional blocks can be realized in various ways by combining hardware and software.
[0031] The glasses-type device 200 includes an imaging unit 220, a wearing detection unit 222, a display control unit 224, and a short-range communication unit 226.
[0032] The imaging unit 220 includes a left eye iris imaging camera 208, a right eye iris imaging camera 210, and a peripheral circuit (IC chip, not shown) that processes data representing images captured by these cameras (hereinafter referred to as image data). The imaging unit 220 is configured to repeatedly, for example, periodically or periodically acquire image data and send the acquired image data to the portable terminal 8. Alternatively, the imaging unit 220 is configured to acquire image data every time an imaging instruction is received from the portable terminal 8 and send the image data to the portable terminal 8.
[0033] The wearing detection unit 222 includes the left wearing sensor 214, the right wearing sensor 218, and a peripheral circuit (IC chip, not shown) that processes data indicating the detection results of these sensors (hereinafter referred to as detection data). The wearing detection unit 222 is configured to repeatedly, for example, periodically or periodically acquire the detection data and send the acquired detection data to the portable terminal 8. Alternatively, the imaging unit 220 is configured to acquire the detection data every time a detection instruction is received from the portable terminal 8 and send it to the portable terminal 8.
[0034] If the frequency at which the imaging unit 220 acquires image data is A and the frequency at which the wearing detection unit 222 acquires detection data is B, then B is set to be greater than A. For example, if the imaging unit 220 acquires and transmits image data once per second, the wearing detection unit 222 is set to acquire and transmit detection data ten times per second.
[0035] The display control unit 224 displays the desktop screen on the left lens with display function 202 and the right lens with display function 204 based on the screen information received from the mobile terminal 8. The display control in the display control unit 224 may be realized using a display control technique for a known see-through type eyeglass-type device.
[0036] The short-range communication unit 226 functions as an interface for short-range wireless communication with the mobile terminal 8. The short-range communication unit 226 transmits image data and detection data to the mobile terminal 8 via short-range wireless communication, and receives screen information from the mobile terminal 8. The short-range wireless communication between the glasses-type device 200 and the mobile terminal 8 may be realized using known technology.
[0037] Figure 5 is a block diagram showing the functions and configuration of the mobile terminal 8 in Figure 1. Each block shown here can be realized in hardware terms by elements and mechanical devices such as a computer CPU, and in software terms by a computer program, etc., but here, functional blocks realized by the cooperation of these elements are depicted. Therefore, those skilled in the art who have read this specification will understand that these functional blocks can be realized in various ways by combining hardware and software.
[0038] The mobile terminal 8 is, for example, a smartphone or a tablet terminal, and has a means for displaying information such as a display, and a means for receiving input from a user such as a touch panel.
[0039] A user 6 of a mobile terminal 8 downloads and installs a VDI application program (hereinafter referred to as a VDI app) according to an embodiment from a download site via a network such as the Internet onto the mobile terminal 8. Alternatively, the VDI app may be pre-installed on the mobile terminal 8. When the VDI app is executed by the mobile terminal 8, the mobile terminal 8 realizes various functions. Below, functions realized by the mobile terminal 8 (its processing unit such as a CPU (Central Processing Unit)) executing the VDI app will be described as functions of the mobile terminal 8. These functions are actually functions that the VDI app causes the mobile terminal 8 to realize.
[0040] In another embodiment, a browser is used instead of installing a VDI application. A computer program according to another embodiment is a computer program written in a programming language such as HTML (Hypertext markup language), which is transmitted from a server to a web browser on the mobile terminal 8 via a network and executed by the web browser. This computer program has the same functions as the VDI application described in this specification.
[0041] The mobile terminal 8 includes a short-range communication unit 302 , an image acquisition unit 304 , a detection result acquisition unit 306 , a network communication unit 308 , a screen transfer unit 310 , an input information acquisition unit 312 , and a position acquisition unit 314 .
[0042] The short-range communication unit 302 functions as an interface for short-range wireless communication with the glasses-type device 200 and other peripheral devices such as the wireless keyboard 10. The wireless keyboard 10 may be a one-handed keyboard that can be operated while standing, or a foldable keyboard. The short-range communication unit 302 transmits screen information to the glasses-type device 200 via short-range wireless communication, receives image data and detection data from the glasses-type device 200, and receives input operation information from the wireless keyboard 10.
[0043] The image acquiring unit 304 repeatedly acquires image data from the imaging unit 220 of the glasses-type device 200. The image acquiring unit 304 may acquire image data repeatedly transmitted from the imaging unit 220 at a frequency A, or may transmit an imaging instruction to the imaging unit 220 at a frequency A and acquire image data returned in response to the imaging instruction. The image acquiring unit 304 transmits the acquired image data to the sorting server 100 every time it acquires image data.
[0044] The detection result acquisition unit 306 repeatedly acquires detection data from the wearing detection unit 222 of the glasses-type device 200. The detection result acquisition unit 306 may acquire detection data repeatedly transmitted from the wearing detection unit 222 at frequency B, or may transmit a detection instruction to the wearing detection unit 222 at frequency B and acquire detection data returned in response to the detection instruction.
[0045] If the acquired detection data indicates that the device is not being worn, the detection result acquisition unit 306 causes the glasses-type device 200 to stop displaying the desktop screen. If the detection data indicates that the device is not being worn, the detection result acquisition unit 306 causes the screen transfer unit 310, described below, to stop transferring screen information to the glasses-type device 200. In addition, the detection result acquisition unit 306 sends an instruction to the display control unit 224 of the glasses-type device 200 to stop or erase the display.
[0046] The network communication unit 308 functions as an interface for communication with the sorting server 100 via a network. The network communication unit 308 transmits image data and input operation information to the sorting server 100 via the network, and receives screen information from the sorting server 100. Screen information representing a desktop screen is transmitted from the sorting server 100 when iris authentication based on image data in the sorting server 100 is successful. When iris authentication fails, the sorting server 100 does not transmit screen information, or transmits screen information representing a screen indicating that authentication has failed. This iris authentication is performed based on image data every time the image data is acquired.
[0047] The screen transfer unit 310 transfers the screen information received from the sorting server 100 to the glasses-type device 200, thereby causing the glasses-type device 200 to display the desktop screen represented by the screen information. As described above, the screen transfer unit 310 stops the transfer when it detects that the glasses-type device 200 is not being worn.
[0048] The input information acquisition unit 312 acquires input operation information corresponding to a user's input operation from a peripheral device such as the wireless keyboard 10 or a wireless mouse. The input information acquisition unit 312 transmits the acquired input operation information to the sorting server 100.
[0049] The position acquisition unit 314 acquires the position of the mobile terminal 8, i.e., the position corresponding to the glasses-type device 200, from a positioning means such as a GPS (Global Positioning System) provided in the mobile terminal 8. The position acquisition unit 314 transmits the acquired position to the sorting server 100.
[0050] Figure 6 is a block diagram showing the functions and configuration of the sorting server 100 in Figure 1. Each block shown here can be realized in hardware terms by elements or mechanical devices such as a computer CPU, and in software terms by a computer program, etc., but here we show functional blocks realized by the cooperation of these. Therefore, those skilled in the art who have read this specification will understand that these functional blocks can be realized in various ways by combining hardware and software.
[0051] The sorting server 100 includes a network communication unit 120, a VDI control unit 122, an iris authentication unit 124, a position authentication unit 126, a user information storage unit 128, and a device information storage unit 130.
[0052] Fig. 7 is a data structure diagram showing an example of the user information storage unit 128 of Fig. 6. The user information storage unit 128 stores, in association with each other, a user ID that identifies a user, a password set by the user, iris information registered in advance by the user or an administrator, a device ID that identifies the eyeglass-type device used by the user, and a connection permission location that indicates a location where the user is permitted to use the VD service.
[0053] Fig. 8 is a data structure diagram showing an example of the device information storage unit 130 in Fig. 6. The device information storage unit 130 stores a device ID that identifies the glasses-type device, connection destination information that identifies a fixed connection destination set at the time of shipment from the glasses-type device, and whether or not a connection cutoff instruction has been issued to the glasses-type device, in association with each other.
[0054] Returning to FIG. 6 , the network communication unit 120 functions as an interface for communication with the mobile terminal 8 and the administrator terminal of the company 16 via a network. The network communication unit 120 receives image data and input operation information from the mobile terminal 8 via the network, and transmits screen information to the mobile terminal 8. The network communication unit 120 also functions as an interface for communication with the private cloud 12 and the public cloud 14 via a network.
[0055] The VDI control unit 122 realizes a virtual desktop service using the glasses-type device 200 as a thin client. The main functions of the VDI control unit 122 are as follows.
[0056] (1) The VDI control unit 122 communicates with the administrator terminal of the company 16, enabling the administrator of the company to register and manage glasses-type devices. The VDI control unit 122 acquires a pair of a user ID and a password to be registered in the user information storage unit 128 from the administrator terminal, and registers them in the user information storage unit 128. The VDI control unit 122 acquires the user's iris information from the administrator terminal, and registers them in the user information storage unit 128. Alternatively, the iris information may be transmitted to the sorting server 100 by the user himself / herself via the mobile terminal 8, and registered in the user information storage unit 128.
[0057] (2) The VDI control unit 122 enables the administrator of the company 16 to disable the use of eyeglasses-type devices. The VDI control unit 122 acquires the device ID of the eyeglasses-type device to be disconnected from the administrator's terminal, and registers the connection disconnection instruction for the device ID as "Yes" in the device information storage unit 130. When the VDI control unit 122 receives a request to start or continue a VD from an eyeglasses-type device for which the connection disconnection instruction is "Yes," it rejects or ignores such a request. When an administrator reports that an eyeglasses-type device under their management has been stolen, the administrator can disable the VD by the eyeglasses-type device by sending the device ID of the stolen eyeglasses-type device to the VDI control unit 122 as a connection disconnection target. This further improves the security of the VD service.
[0058] (3) The VDI control unit 122 performs user authentication and start processing of the VD between the mobile terminal 8. When the VDI control unit 122 receives a VD start request from the mobile terminal 8, which includes a user ID, a password, and location and destination information corresponding to the glasses-type device, the VDI control unit 122 performs user authentication by comparing the pair of user ID and password included in the received VD start request with the user information stored in the user information storage unit 128. If the user authentication is successful, the VDI control unit 122 accesses a resource (e.g., a desktop terminal) of the private cloud 12 or the public cloud 14 corresponding to the destination information included in the VD start request, and acquires screen information corresponding to the desktop screen of that resource.
[0059] If further authentication is required to access a resource, the VDI control unit 122 performs authentication using authentication information for the resource that is pre-registered in association with the user ID in the user information storage unit 128. The user ID and password registered in the user information storage unit 128 may themselves constitute the authentication information for the resource to be accessed.
[0060] The connection destination information may be written in a non-rewritable form to the glasses-type device 200. In this case, the mobile terminal 8 reads the connection destination information from the glasses-type device 200 when generating a VD start request. Alternatively, the connection destination information may be specified by an administrator of the company 16 when the administrator registers the glasses-type device.
[0061] If the iris authentication in the iris authentication unit 124 is successful and the position authentication in the position authentication unit 126 is successful, the VDI control unit 122 starts the VD by sending the acquired screen information to the mobile terminal 8. The VDI control unit 122 registers the device ID of the glasses-type device used in the started VD in the user information storage unit 128 in association with the user ID used in authenticating the VD. If either or both of the iris authentication in the iris authentication unit 124 and the position authentication in the position authentication unit 126 fail, the VDI control unit 122 denies the start of the VD.
[0062] (4) The VDI control unit 122 manages and controls the VDI between the glasses-type device 200 and the mobile terminal 8 and the above-mentioned resources. The VDI control unit 122 transmits input operation information received from the mobile terminal 8 to the resources, and transmits updated screen information received from the resources to the mobile terminal 8.
[0063] (5) If iris authentication by the iris authentication unit 124 fails while the VD is in progress, the VDI control unit 122 cancels or stops the VD. In this case, the VDI control unit 122 does not send the screen information received from the resource to the mobile terminal 8, or sends screen information showing a screen indicating that authentication has failed to the mobile terminal 8.
[0064] The iris authentication unit 124 performs iris authentication by comparing the iris information received from the mobile terminal 8 with the iris information registered in the user information storage unit 128. The iris authentication unit 124 compares the iris information registered in the user information storage unit 128 in association with the user ID included in the VD start request with the iris information received from the mobile terminal 8, and determines that the iris authentication is successful if they match, or that the iris authentication is unsuccessful if they do not match. As described above, iris information is acquired and sent at a predetermined frequency, so the iris authentication unit 124 performs iris authentication every time it acquires such iris information.
[0065] The location authentication unit 126 performs location authentication based on whether the location included in the VD start request satisfies a predetermined condition. If the location included in the acquired VD start request is included in the connection permitted location (range) registered in the user information storage unit 128, the location authentication unit 126 determines that the location authentication is successful, and if not, determines that the location authentication is unsuccessful.
[0066] The operation of the secure VDI system 2 configured as above will now be described. 9 is a flowchart showing a series of processing steps in the secure VDI system 2 of FIG. 1. The user 6, without wearing the glasses-type device 200, pairs the glasses-type device 200 with the mobile terminal 8 for Bluetooth communication (S902). The user 6 also pairs a peripheral device such as a wireless keyboard 10 with the mobile terminal 8. The user 6 logs in to the VD service on the mobile terminal 8 (S904). This login is performed, for example, by the sorting server 100 transmitting a login information input screen to the mobile terminal 8, the mobile terminal 8 displaying the screen, the user 6 entering a user ID and password on the screen, the mobile terminal 8 generating a VD start request including the entered user ID and password, connection destination information for the glasses-type device 200, and the location, and transmitting the VD start request to the sorting server 100. Note that authentication regarding the VD start request is performed using the user ID and password on the mobile terminal 8, but this authentication itself may be replaced by iris authentication.
[0067] The sorting server 100 performs location authentication based on the location included in the VD start request (S906). If the location authentication fails (NO in S906), the VD is not started and the process ends. If the location authentication is successful (YES in S906), the process continues.
[0068] When the user 6 puts on the glasses-type device 200 (S908), the imaging unit 220 of the glasses-type device 200 captures an image of the iris of the user 6. The mobile terminal 8 acquires an image from the imaging unit 220 (S910). The mobile terminal 8 transmits the acquired image to the sorting server 100 (S912). The sorting server 100 performs iris authentication based on the received image (S914). If the iris authentication fails (NO in S914), the start (or continuation) of the VD is rejected (S920), and the process returns to step S910. If the iris authentication is successful (YES in S914), the sorting server 100 starts and continues the VD (S916). While the VD is continuing in step S916, the mobile terminal 8 repeatedly acquires detection data from the wearing detection unit 222 of the glasses-type device 200, and turns off the display of the glasses-type device 200 when it detects that the glasses-type device 200 has been removed.
[0069] The mobile terminal 8 determines whether a predetermined period of time has passed since the previous acquisition of image data (S918). When the predetermined period of time has passed (YES in S918), the mobile terminal 8 returns the process to step S910 to repeat iris authentication. If iris authentication fails in step S914 while the VD is continuing, the sorting server 100 rejects the continuation of the VD (S920). After interrupting the VD, the sorting server 100 returns the process to step S910 to repeat iris authentication. If iris authentication is then successful again, the VD is resumed. The sorting server 100 may end the VD if the rejection of the continuation of the VD (step S920) occurs a predetermined number of times in succession.
[0070] In the above-described embodiments, examples of the storage unit are a hard disk and a semiconductor memory. Furthermore, based on the description in this specification, it will be understood by those skilled in the art that each unit can be realized by a CPU (not shown), an installed application program module, a system program module, a semiconductor memory that temporarily stores the contents of data read from a hard disk, or the like.
[0071] In the secure VDI system 2 according to this embodiment, the VD continues on the condition that repeated iris authentication is successful. Therefore, not only is it impossible for anyone other than the user to use it, but since repeated successful authentication is required, it is also possible to prevent impersonation, such as a malicious third party using an eyeglass-type device that has once passed the user's iris authentication. As a result, the security of the secure VDI system 2 in which the eyeglass-type device 200 is used as a thin client is further strengthened.
[0072] Furthermore, in the secure VDI system 2 according to this embodiment, when the glasses-type device 200 is removed, iris authentication fails and the display turns off. This reduces or eliminates the risk of the desktop screen being secretly viewed. Furthermore, in this embodiment, in addition to repeated iris authentication, wearing detection is performed more frequently. Therefore, it is also possible to reduce or eliminate the risk of the desktop screen being secretly viewed during the short time between when the glasses-type device 200 is removed and when the display of the glasses-type device 200 turns off due to iris authentication failure.
[0073] Furthermore, the secure VDI system 2 according to this embodiment allows you to specify the location range in which the VD service is available. This allows you to limit the locations where participants can participate via VD when holding a conference dealing with sensitive content via VD. For example, you can prohibit participants from participating in such conferences in places where there is a high probability that the content of the conversation will be overheard, such as a cafe or on the go, and limit participants to safe locations such as their own homes.
[0074] Furthermore, in the secure VDI system 2 according to this embodiment, security control is performed by the sorting server 100. Therefore, compared to when VDI is performed directly between the mobile terminal 8 and the resources of the private cloud 12 and the public cloud 14, response to failures is smoother, especially on holidays and at night.
[0075] Furthermore, in the secure VDI system 2 according to this embodiment, the eyeglasses 200 can be shared among employees of the company 16. Therefore, for example, the company 16 can be equipped with a predetermined number of eyeglasses 200, and employees can take their favorite eyeglasses 200 with them when they go out. This allows the company 16 to provide a VDI service that is less expensive than providing each employee with an eyeglasses device, yet still ensures security.
[0076] The above describes the configuration and operation of the secure VDI system 2 according to the embodiment. This embodiment is an example, and it will be understood by those skilled in the art that various modifications are possible in the combination of each component and each process, and that such modifications are also within the scope of the present invention.
[0077] In the embodiment, a VD (Virtual Desktop) has been described as an example, but this is not limited thereto, and the technical idea of the embodiment can be similarly applied to other applications that require a secure connection, such as a connection via a VPN (Virtual Private Network) or a web conference.
[0078] In the embodiment, the glasses-type device 200, the mobile terminal 8, and the sorting server 100 have the functions exemplified in FIGS. 4, 5, and 6, respectively. However, the present invention is not limited to this. For example, the glasses-type device 200 may implement some or all of the functions of the mobile terminal 8. If all of the functions of the mobile terminal 8 are implemented by the glasses-type device 200, the mobile terminal 8 is not required, and the glasses-type device 200 communicates directly with the sorting server 100 via a network. In this case, the glasses-type device 200 does not require the mobile terminal 8, and also does not require a short-range communication unit for communicating with the mobile terminal 8. Note that the configuration may be such that only the mobile communication function is performed via the mobile terminal 8, and the tethering function of the mobile terminal 8 (using the mobile terminal 8 as an access point) can be used. Alternatively, the iris authentication function and / or the position authentication function of the sorting server 100 may be realized by the mobile terminal 8 or the glasses-type device 200. In this way, which element realizes which function may be appropriately determined depending on the actual application. A specific operation of the glasses-type device 200 is to acquire an iris while wearing the device, compare it with iris information pre-registered in the device, and perform authentication based on whether the comparison is successful. "Pre-registered" is achieved by the user initially registering their own iris using the device when using it for the first time. In this embodiment, the operation is shown to be linked with the mobile terminal 8, but iris information may also be acquired by the device and transmitted to the mobile terminal 8, and the iris may be compared by the mobile terminal.
[0079] In the embodiment, the case where a wireless keyboard 10 or a wireless mouse is used as an input means has been described, but the present invention is not limited to this. For example, a system that projects a keyboard to enable operation similar to that of a PC, or a system that enables operation by hand gestures or eye contact may be used. In this case, the inconvenience of smartphone operation can be resolved and operability can be improved.
[0080] In the embodiment, a case where the glasses-type device 200 is provided with a wearing detection unit 222 has been described, but if it is not necessary to detect wearing or if repeated iris authentication can also serve as detection of wearing, the wearing detection unit 222 does not have to be provided.
[0081] In the embodiment, a case has been described in which the connection destination of the glasses-type device 200 is fixed at the time of shipment from the factory and written into the glasses-type device 200, but this is not limited to this and it does not have to be fixed, and the user may be able to specify it when starting the VD, or the connection destination may be set or changed from an administrator terminal of the company 16.
[0082] In the embodiment, the VDI application may run in the foreground or in the background. The VDI application may use the iris image data acquired from the glasses-type device 200 for purposes other than iris authentication for VD continuation. For example, the iris image data may be used to realize single sign-on when connecting to another service that requires further authentication within the VD environment.
[0083] In the embodiment, a case has been described in which the VD is monitored by position authentication, iris authentication, and wearing detection, but the present invention is not limited to this. For example, a period and timing during which the VD is possible may be specified.
[0084] Furthermore, in the embodiment, a configuration using position authentication has been described, but a configuration excluding position authentication may also be used (that is, a configuration using only iris authentication as authentication).
[0085] In the embodiment, as an example, iris authentication is used to determine whether to continue the VD. As a more specific implementation example, the VD continuation determination is performed based on iris authentication as one of the functions of a program installed in the sorting server 100, but the continuation process can also be implemented as a function of the eyeglass-type device 200 or the mobile terminal 8. As an example of implementing it as a function of the mobile terminal 8, it can be implemented as one function of a VD client installed in the mobile terminal 8. As an example of implementing it as a function of the eyeglass-type device 200, it can be implemented as one function of a VD client installed in the eyeglass-type device 200. The advantage of implementing it as a function of the VD client is that it is easy to stop providing the VD service when it is determined not to continue the VD. If it is implemented as a separate program rather than as a function of the VD client, when it is determined not to continue the VD, the display of the eyeglass-type device 200 can be turned off or shut down, or the communication function of the mobile terminal 8 can be turned off or shut down. In either case, it is possible to ultimately prevent the VD service from being provided. [Explanation of symbols]
[0086] 2 secure VDI systems, 4 data centers, 6 users, 8 mobile devices, 100 distribution servers.
Claims
1. a function of repeatedly acquiring images at a first frequency from an imaging unit provided in the eyeglass-type device so that an iris of the user can be imaged when the user wears the eyeglass-type device, and performing iris authentication based on the image each time the image is acquired; A function of receiving data transmitted from other devices via a network when iris authentication based on the acquired image is successful; A function of making the received data visible through the glasses-type device; a function of repeatedly acquiring images at the first frequency periodically or periodically, and repeatedly acquiring detection results at a second frequency higher than the first frequency from a detection unit provided in the glasses-type device that detects whether the user is wearing the glasses-type device; a function of causing the glasses-type device to stop making data visible when the acquired detection result indicates that the glasses-type device is not being worn; A computer program that enables a computer to achieve the above.
2. The computer further implements a function of acquiring a position corresponding to the glasses-type device; The computer program of claim 1 , wherein if the acquired location does not satisfy a predetermined condition, connection with the other device via the network is refused.
3. The computer program according to claim 1 or 2, wherein the glasses-type device functions as a thin client in a virtual desktop infrastructure (VDI).
Citation Information
Patent Citations
Authentication system
JP2005309890A
Image display apparatus and image display system
JP2007003745A
Web conference system, information processing device, control method, and program
JP2013141201A
Terminal apparatus, thin client conversion method and thin client conversion program
JP2019053345A