Information processing device, access control system, program, and information processing method

The relay server system addresses the challenges of secure and convenient access to on-premise servers by managing user information, generating unique queries, and relaying authenticated communication, thereby enhancing security and optimizing network traffic.

JP7808644B2Active Publication Date: 2026-01-29HENNGE CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024108737
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-07-05
Publication Date
2026-01-29
Estimated Expiration
2041-04-19

AI Technical Summary

Technical Problem

Existing systems face challenges in providing secure and convenient access for user terminals to on-premise servers via the Internet, as VPNs are expensive, vulnerable to attacks, and inconvenient due to re-authentication requirements and network congestion.

Method used

A relay server system that manages user information, generates unique query information for each on-premise server/service, performs authentication, and relays secure communication between user terminals and on-premise servers, preventing unauthorized access.

Benefits of technology

Enhances security and convenience by allowing controlled access to on-premise servers while preventing unauthorized access and optimizing network traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007808644000001
    Figure 0007808644000001
  • Figure 0007808644000002
    Figure 0007808644000002
  • Figure 0007808644000003
    Figure 0007808644000003
Patent Text Reader

Abstract

To provide a relay server and an access control system which are highly convenient and are more safe for a user by a terminal of a user on the Internet, regarding the access to an on-premises server.SOLUTION: There is generated unique reference information which allows access to an on-premises server on the basis of information of the on-premises server. Whether a user is to be authenticated is determined in a case where an access from a terminal of a user is received. If the authentication of the user is permitted, the reference information is presented to the terminal of the user. The communication between the terminal of the user which is permitted to be authenticated and the on-premises server is relayed.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a relay server and an access control system. [Background technology]

[0002] In recent years, a system called cloud computing has made it possible for users to access services from anywhere via the Internet, thereby improving user convenience.

[0003] On the other hand, from a security perspective, many users prefer to operate their systems on-premise, where information stored on devices located within the user's environment (for example, within the company) is read. On-premise systems are said to be less susceptible to external attacks and to have a lower risk of information leaks.

[0004] Furthermore, in the prior art, there is a technology called a VPN (Virtual Private Network) that sets up a virtual dedicated line on the Internet, establishes a dedicated network that can only be used by specific people, and enables intercommunication between terminals connected to the Internet and on-premises. There is also a technology that connects a mutually authenticated Transport Layer Security (TLS) tunnel between a cloud (off-premises platform) and an on-premises platform environment to transfer data (see paragraph 0032 of Patent Document 1). [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Patent Publication No. 2021-501929 Summary of the Invention [Problem to be solved by the invention]

[0006] Furthermore, if a user's terminal connected via the Internet can also access on-premise, it will be more convenient for the user, but since the terminal is connected via the Internet, there is also a risk of information leakage.

[0007] VPNs can also be used to allow users to access on-premises servers, but they are expensive to implement and place a significant burden on users. VPNs also have the disadvantage that if an attacker penetrates an on-premises server, other services and servers in the LAN area can easily be accessed, and they can be inconvenient as users have to log in again after the connection is lost, and communication speeds can slow down due to congestion.

[0008] The present invention has been made in consideration of the above-mentioned problems, and its purpose is to provide a relay server and access control system that is highly convenient for users and has improved security when a user's terminal on the Internet accesses an on-premise server. [Means for solving the problem]

[0009] (1) The present invention provides A relay server is provided in which a user's terminal and an on-premise server are connected via the Internet, and the relay server is connected to the terminal and the on-premise server via the Internet, Accessing the on-premise server based on the information of the on-premise server a query generator for generating possible unique queries; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the query information to a terminal of the user when authentication of the user is permitted; a relay processing unit that relays communication between the terminal of the user who has been authenticated and the on-premise server; The present invention relates to a relay server including:

[0010] Incidentally, the present invention relates to a program that causes a computer to function as each part of the relay server. The present invention also relates to an information storage medium storing the program.

[0011] According to the present invention, when the authentication of a user is permitted, unique inquiry information that can be accessed by an on-premises server is presented to the user's terminal, and communication between the user's terminal for which the authentication is permitted and the on-premises server is relayed. Therefore, access to the on-premises server from an unauthorized user can be prevented, and security can be improved.

[0012] (2) Further, the server, program, and information storage medium of the present invention The inquiry information generation unit may generate different inquiry information for each on-premises server.

[0013] <000006-4>According to the present invention, when there are a plurality of on-premises servers, different inquiry information is generated for each on-premises server, so that each of the plurality of on-premises servers can be appropriately managed and communication can be relayed.

[0014] (3) Further, the server, program, and information storage medium of the present invention The inquiry information generation unit may generate different inquiry information for each service.

[0015] [[ID=3(]] According to the present invention, when a plurality of services are provided in an on-premises server, different inquiry information is generated for each service, so that each of the plurality of services can be appropriately managed and communication can be relayed.

[0016] (4) Further, the server, program, and information storage medium of the present invention The user control unit for each user, based on the user information of the user, determines whether the user can access each inquiry information, The presentation unit For each user, the query information that the user can access may be presented to the user's terminal.

[0017] According to the present invention, for each user, whether or not the user can access each piece of query information is determined based on the user's user information, making it possible to control the query information so that specific users can access it and other users cannot, thereby enabling control that takes into consideration both convenience and security.

[0018] (5) The present invention is The user's terminal, the on-premise server, and the relay server each have access to the Internet. An access control system connected via The relay server a query information generating unit that generates unique query information that can be accessed by the on-premise server based on information of the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the query information to a terminal of the user when authentication of the user is permitted; a relay processing unit that relays communication between the terminal of the user who has been authenticated and the on-premise server, The on-premise server This relates to an access control system that, when access based on the query information is received from the terminal of a user who has been authorized for authentication via the relay server, presents the information indicated in the query information to the user's terminal via the relay server.

[0019] According to the present invention, when user authentication is permitted, unique query information that can access the on-premises server is presented to the user's terminal, and communication between the user's terminal whose authentication has been permitted and the on-premises server is relayed, thereby preventing access to the on-premises server from unauthorized users and improving security. [Brief explanation of the drawings]

[0020] [Figure 1] FIG. 1 is an example of a network diagram of an access control system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a functional block diagram of a relay server 10 according to the present embodiment. [Figure 3] FIG. 4 is a diagram for explaining a relay process according to the embodiment. [Figure 4] 10 shows an example of an access permission flag for each piece of inquiry information for each user according to the present embodiment. [Figure 5] FIG. 4 is a diagram showing an example of a screen displayed on the terminal of the embodiment. [Figure 6] FIG. 3 is a flowchart showing the flow of processing according to the present embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0021] The present embodiment will be described below. Note that the present embodiment described below does not unduly limit the content of the present invention described in the claims. Furthermore, not all of the configurations described in the present embodiment are necessarily essential constituent elements of the present invention.

[0022] [1] Network 1 shows an example of a network diagram of an access control system. In the access control system of this embodiment, a relay server 10, a user terminal 20, and an on-premise server 30 are connected to each other via a network (the Internet).

[0023] In other words, the relay server 10 of this embodiment is a server that is connected to each of the user's terminal 20 and the on-premise server 30 via the Internet and is configured for the purpose of relaying communication between the terminal 20 and the server 30.

[0024] The relay server 10 of this embodiment is an information processing device that manages user information and performs user authentication processing.

[0025] The terminal 20 is a client device, and is an information processing device such as a smartphone, mobile phone, PHS, computer, game device, PDA, or image generating device, and is a device that can be connected to the relay server 10 via a network such as the Internet (WAN) or LAN.

[0026] The on-premise server 30 is a server constructed and operated by a user (for example, a company), and is an information processing device installed in a facility managed by the user.

[0027] The on-premise server 30 basically operates services that are kept private from the outside (Internet) (for example, services used only within a company or group, services for confidential information, an internal mail server, an internal conference system), but as will be described below, in this embodiment, the on-premise server 30 is controlled so that it can be accessed from the terminals 20 of some users who have been authenticated via the relay server 10.

[0028] [2] Configuration 2 is an example of a functional block diagram of the relay server 10 of this embodiment. Note that the relay server 10 of this embodiment does not need to include all of the units in FIG. 2, and may have a configuration in which some of them are omitted.

[0029] The storage unit 170 stores programs and various data for causing a computer to function as each unit of the processing unit 100, and also functions as a storage area for the processing unit 100.

[0030] The memory unit 170 includes a temporary storage area and storage. Storage refers to a device that permanently stores data, such as a hard disk, optical disk, flash memory, or magnetic tape. The memory unit 170 may also store programs and data stored in the information storage medium 180.

[0031] The storage unit 170 of this embodiment includes a main storage unit 171 used as a work area, a user information storage unit 172, and a query information storage unit 173. Note that some of these may be omitted.

[0032] The main storage unit 171 can be realized by a RAM etc. The main storage unit 171 is a storage area used in the processing of this embodiment.

[0033] The user information storage unit 172 stores user information (user account, password, email address, etc.) The user information storage unit 172 may be configured by a DB (DB is an abbreviation for database, the same applies hereinafter).

[0034] The query information storage unit 173 stores query information (URL). Note that the query information storage unit 173 may be configured as a DB.

[0035] The information storage medium 180 (computer-readable medium) stores programs, data, etc., and its functions can be realized by storage such as an optical disk (CD, DVD), a magneto-optical disk (MO), a magnetic disk, a hard disk, a magnetic tape, or a memory (ROM).

[0036] The communication unit 196 performs various controls for communicating with the outside (e.g., terminals, other servers, or other network systems), and its functions can be realized by hardware such as various processors or communication ASICs, or programs.

[0037] The processing unit 100 performs various processes of this embodiment based on programs (data) stored in the storage unit 170 or the information storage medium 180 .

[0038] The processing unit 100 (processor) uses the main memory unit 171 in the memory unit 170 as a work area. The functions of the processing unit 100 can be realized by hardware such as various processors (CPU, DSP, etc.) or by programs.

[0039] The processing unit 100 includes a user control unit 111 , an authentication processing unit 112 , a query information generating unit 113 , a presenting unit 114 , a relay processing unit 115 , and a Web processing unit 120 .

[0040] The user control unit 111 manages the user information of the users. Furthermore, the user control unit 111 may determine, for each user, whether or not the user is permitted to access each piece of inquiry information (each URL) based on the user information of the user.

[0041] When an access is received from a user terminal, the authentication processing unit 112 determines whether or not the user is authenticated.

[0042] The query information generating unit 113 generates unique query information (for example, a URL) that can access the on-premise server 30 based on the information of the on-premise server 30.

[0043] For example, when there are multiple on-premise servers 30, the query information generating unit 113 may generate different query information for each on-premise server 30. Furthermore, when there are multiple services, the query information generating unit 113 may generate different query information for each service.

[0044] If the user authentication is permitted, the presenting unit 114 presents the query information to the terminal 20 of the user.

[0045] The relay processing unit 115 relays communication between the terminal 20 of a user who has been authenticated and the on-premise server 30.

[0046] The Web processing unit 120 performs processing to send (provide) data such as HTML (HyperText Markup Language) documents and images via HTTP (Hypertext Transfer Protocol) in response to requests from client software such as a Web browser installed on the terminal 20, and processing to receive data accepted by the Web browser of the terminal. The server then processes emails, updates the database, etc. based on information received from each terminal of the administrator or user.

[0047] The Web processing unit 120 may perform processing to send (provide) management setting data, etc. to the administrator's terminal 20 in response to an access request from the web browser of the administrator's terminal 20, and may also perform processing to receive information from the administrator's terminal 20.

[0048] That is, the Web processing unit 120 may add, delete, update, etc. each piece of data to the DB based on input from the administrator. Note that only the administrator is authorized to access the web page (URL) for the administrator.

[0049] Furthermore, the Web processing unit 120 performs login processing and, in response to a request from the Web browser of the terminal 20, performs processing to control the Web page of information related to the logged-in user so that it can be viewed.

[0050] Note that some or all of the processing of the processing unit 100 and the memory unit 170 may be executed by a single device, or each process may be distributed to different devices depending on the purpose of the process.

[0051] [3] Agent Description 3, an agent program is installed in a given on-premise device that exists within the on-premise network (LAN). In other words, the on-premise device in which the agent program is installed can be called an agent (agent device).

[0052] For example, the on-premise device may be the on-premise server 30 (server 30A or server 30B), or may be a terminal 20X (not shown) connected to the on-premise server 30 (server 30A or server 30B). The terminal 20X is an information processing device present in the same network environment (LAN) as the on-premise server 30.

[0053] The agent stores in advance in a storage unit of the agent "information on the on-premise server 30" including the IP address of the on-premise server 30, the host name, and information on each service (each port number).

[0054] Here, "service" refers to a service for the TCP / IP network protocol. "Service" may also be interpreted as a port number for identifying the service.

[0055] For example, when an agent is installed in the on-premise server 30, "information on the on-premise server 30" is stored in the storage unit of the on-premise server 30. When an agent is installed in the terminal 20X, "information on the on-premise server 30" is stored in the storage unit of the terminal 20X.

[0056] An agent may manage multiple on-premise servers 30 (e.g., server 30A and server 30B). Alternatively, an agent may manage only one on-premise server 30 (e.g., server 30A). In such a case, there is one agent corresponding to one on-premise server 30.

[0057] An agent may also manage multiple services (e.g., service SA and service SB) of the on-premise server 30. An agent may also manage only one service (e.g., service SA) of the on-premise server 30. In such cases, there is one agent corresponding to one service.

[0058] The agent also controls the activation (enabling) and stopping (disabling) of the services of the on-premise server 30 that it manages. For example, the agent can control the activation or stopping of the services of the on-premise server 30 based on input information from the administrator of the access control system.

[0059] [4] Explanation of the generation of referral information The relay server 10 generates unique query information that can be accessed by the on-premise server 30 based on the information of the on-premise server 30 .

[0060] The query information is a global URL that the relay server 10 makes public to users who have been authorized for authentication. For example, it is a URL that allows a user's terminal 20 located outside (outside the organization, outside the company) such as on the Internet to access a network within the organization (for example, within the company).

[0061] Here, "reference information" refers to information that uniquely identifies a web page on the Internet using protocols such as HTTP (Hyper Text Transfer Protocol) and HTTPS (Hyper Text Transfer Protocol Secure). The query information may be a URL for specifying the server. The query information may also be information of a server that can send and receive data using other communication protocols such as FTP (File Transfer Protocol). For example, if the query information is a URL, the query information is generated according to a predetermined URL format.

[0062] When an agent starts a service, it establishes a TCP connection (for example, a long-lived TCP connection) with the relay server 10 and transmits query generation request information to the relay server 10. Then, upon receiving the query generation request information from the agent, the relay server 10 generates query information corresponding to the service of the server managed by the agent. Note that the connection may also be referred to as a tunnel.

[0063] For example, when an agent starts a service SA (e.g., a Web service on port 80) of on-premise server 30A, a TCP connection is established between the service SA and relay server 10, and the agent transmits a request for generating query information for the service SA to relay server 10. Then, upon receiving the request for generating query information from the agent, relay server 10 generates query information L1 (e.g., "https: / / example1.com.hennge.io / ") corresponding to the service SA. This connection and query information L1 are in a corresponding relationship.

[0064] Specifically, the relay server 10 generates a URL by executing an application program that is a tunneling tool. This application program performs processing to make the services running in the local environment publicly accessible from the Internet.

[0065] For example, the relay server 10 executes the application program based on the information of the service SA of the on-premise server 30A stored in the agent (for example, the host name, IP address, and port number "80" of the service SA of the on-premise server 30A ... In the embodiment, the domain of the acquired URL is changed to the domain of the relay server 10 by setting the DNS (Domain Name Server) based on the administrator's input information, and the URL (for example, "https: / / example1.com.hennge.io / ") is used as the query information L1.

[0066] Also, when the agent starts service SB of on-premise server 30A, service SC, and service SD of on-premise server 30B, relay server 10 generates query information corresponding to each service, just as when service SA is started.

[0067] That is, when the agent starts the service SB of the on-premise server 30A (for example, an HTTPS service on port 443), a TCP connection is established between the service SB and the relay server 10, and the relay server 10 transmits a request for generating query information for the service SB to the relay server 10. Then, upon receiving the request for generating query information from the agent, the relay server 10 generates query information L2 corresponding to the service SB (for example, "https: / / example2.com.hennge.io / "). The relay server 10 generates the query information L2 based on the information on the service SB of the on-premise server 30A stored in the agent (for example, the host name, IP address, and port number "443" of the service SB of the on-premise server 30A ...).

[0068] In addition, the agent may access the service SC (e.g., port When the agent (Web service No. 80) is started, a TCP connection is established between the service SC and the relay server 10, and a request for generating query information for the service SB is sent to the relay server 10. Then, upon receiving the request for generating query information from the agent, the relay server 10 generates query information L3 corresponding to the service SC (e.g., "https: / / example3.com.hennge.io / "). The relay server 10 generates the query information L3 based on the information on the service SC of the on-premise server 30B stored in the agent (e.g., the host name, IP address, and port number "80" of the service SC of the on-premise server 30B, etc.).

[0069] Furthermore, when the agent activates a service SD of the on-premise server 30B (e.g., an HTTPS service on port 443), a TCP connection is established between the service SD and the relay server 10, and the relay server 10 transmits a request for generating query information for the service SD to the relay server 10. Then, upon receiving the request for generating query information from the agent, the relay server 10 generates query information L4 corresponding to the service SD (e.g., "https: / / example4.com.hennge.io / "). The relay server 10 generates the query information L4 based on the information on the service SD of the on-premise server 30B stored in the agent (e.g., the host name, IP address, and port number "443" of the service SD of the on-premise server 30B ...

[0070] That is, when there are multiple on-premise servers 30, the relay server 10 generates different query information for each on-premise server 30. This allows for detailed access control for each on-premise server in this embodiment.

[0071] Furthermore, when there are multiple services, the relay server 10 generates different query information for each service. That is, in this embodiment, detailed access control can be performed on a service-by-service (port-by-port) basis.

[0072] [5] Explanation of User Information The relay server 10 manages user information of users. In particular, the relay server 10 of this embodiment determines, for each user, whether or not the user is permitted to access each piece of query information (each URL) based on the user information of the user.

[0073] For example, the relay server 10 may determine whether each piece of query information is accessible based on various information (server host name and service) of the on-premise server 30 corresponding to each piece of query information. Also, the user information includes information on attributes to which the user belongs (group name, department name, job title, etc.). The relay server 10 may determine whether each piece of query information is accessible based on the user attributes.

[0074] For example, as shown in Fig. 4, an accessibility flag for each piece of query information is set in association with the user ID for each user. If access is possible, "1" is set, and if access is not possible (access prohibited), "0" is set. The relay server 10 may store the accessibility flag for each piece of query information associated with the user ID for each user in the query information storage unit 173.

[0075] For example, user A (user ID=A) can access query information L1, L2, and L3. User B (user ID=B) can access query information L2 only. User C (user ID=C) can access query information L1, L3, and L4. User D (user ID=D) can access query information L4 only.

[0076] In this manner, in this embodiment, the on-premise server 30 that can be accessed is set for each user. In this embodiment, the services that can be accessed by the on-premise server 30 can be determined for each user. In this way, the minimum amount of necessary information can be disclosed to the necessary users. Furthermore, the traffic on the network related to the service can be kept to a necessary minimum.

[0077] The relay server 10 may manage user information for each organization (for example, each company, each group, each school, each department).

[0078] [6] Explanation of authentication process When the relay server 10 receives access from a user, it determines whether to permit authentication of the user. In this embodiment, if it is determined that the user is legitimate using at least one of the following methods (A) to (H), it determines that authentication of the user is permitted. On the other hand, if it is determined that the user is not legitimate using any of the methods, it determines that authentication of the user is denied.

[0079] Since multi-factor authentication can improve security, it may be determined that user authentication is permitted if at least two of the multiple methods (A) to (H) (for example, (A) and (B)) are determined to be valid.

[0080] (A) Password authentication Various authentication methods are possible. For example, an account (user ID) and password are defined in advance for each user, the user inputs the account and password, and the user's terminal 20 transmits the account and password to the relay server 10. The relay server 10 determines that the user is legitimate if the user's account and password received from the user's terminal 20 match the user's account and password registered in the relay server 10.

[0081] The password may also be a one-time password that is valid only once. For example, a one-time password generation program that generates one-time passwords using the same algorithm as that of the relay server 10 is installed in advance on the terminal 20, and authentication is performed using the one-time password. For example, the algorithm and seed number of the one-time password generation program installed on the terminal 20 and the one-time password generation program installed on the relay server 10 match, and as a result, the one-time password generated on the terminal side and the password generated on the relay server 10 match. For example, the one-time password generation program performs a process of generating a one-time password based on the time and seed number at a predetermined interval (for example, every 30 seconds).

[0082] (B) External authentication When the relay server 10 receives access from a user, it delegates authentication of the user to an external authentication server (authentication authority).

[0083] For example, the relay server 10 determines whether the user is authenticated by an external authentication server (authentication authority) and determines the legitimacy of the user based on the information received from the authentication server. If the information received from the authentication server includes user information (e.g., email address), and if the user information matches the user information managed by the relay server 10, the relay server 10 determines that the user is legitimate.

[0084] In this embodiment, the user is required to register in advance user information (for example, account and password) corresponding to the destination user in an external authentication server.

[0085] There may be multiple types of authentication servers, such as Google (registered trademark), Amazon (registered trademark), and Facebook (registered trademark), and the user may be instructed to select one authentication server. The relay server 10 then delegates authentication to the selected authentication server.

[0086] (C) Biometric authentication For example, biometric information (face, fingerprint, veins) for each user is registered in advance in the relay server 10, and the user inputs the biometric information and sends it to the relay server 10. If the user's biometric information received from the user's terminal 20 matches the user's biometric information registered in the relay server 10, the user is determined to be legitimate.

[0087] (D) Authentication using a second device (e.g., a smartphone) For example, the relay server 10 may register the terminal identification information of the second terminal in advance in association with the user's account using a given method, and may then determine the legitimacy of the user using the terminal identification information of the second terminal.

[0088] (E) Phone number authentication For example, the relay server 10 may register the telephone number of the user using a given method and determine the legitimacy of the user using the telephone number of the user.

[0089] (F)SSL Client Certificate The relay server 10 may determine whether or not the SSL (Secure Socket Layer) client certificate sent from the terminal 20 is valid, and if the SSL client certificate is valid, determine that the user is valid.

[0090] (G) User authentication without using a password The relay server 10 may execute a process for performing user authentication without using a password (public key-based user authentication process). For example, the relay server 10 may determine whether a user is legitimate by using authentication processes of FIDO (registered trademark) or FIDO2. For example, FIDO2 is configured with CTAP (Client To Authenticator Protocol) and WebAuthn (Web Authentication API), and enables user authentication via a web browser of the terminal 20.

[0091] (H) Authentication process for other users The relay server 10 may determine whether or not the user is legitimate by using various authentication processes other than those described above.

[0092] [7] Explanation of the presentation of inquiry information If the user authentication is permitted, the relay server 10 presents the query information to the user's terminal 20. Here, "presenting" means notifying or displaying the query information on a web page. "Presenting" may also mean that the relay server 10 makes the query information presentable to the user's terminal 20.

[0093] In addition, "presentation" may mean that the relay server 10 sends to the terminal 20 an email (which may be an email newsletter, etc.) sent and received via SMTP, that it sends using a given protocol other than SMTP, that it sends a push notification (that it displays a message window in a partial area (such as the top) of the terminal (smartphone) screen), or that it presents (controls so that it can be displayed and viewed) a specified screen of a specified application (a banner display screen, a notification screen, a pop-up screen, etc.).

[0094] Note that the relay server 10 may also transmit information to the terminal 20 that has made the request in response to a request from the terminal 20 of the user as one aspect of "presentation."

[0095] When the on-premise server 30 receives access from the terminal 20 of a user whose authentication has been permitted via the relay server using query information, the on-premise server 30 presents the information indicated in the query information to the terminal 20 of the user via the relay server 10.

[0096] For example, taking user A as an example, when the relay server 10 accepts access from user A's terminal 20A, it first presents an authentication screen. Then, when authentication of user A is permitted, the relay server 10 presents, on user A's terminal 20A, a screen Sc1 (query information list screen) presenting query information that user A can access, as shown in Fig. 5.

[0097] For example, as shown in Fig. 4, user A can access query information L1, L2, and L3. Therefore, as shown in Fig. 5, the query information L1, L2, and L3 are presented on the on-premise information screen Sc1. Note that, as shown in Fig. 5, the relay server 10 may present information on the on-premise servers corresponding to each of the query information L1, L2, and L3. Note that, for convenience of explanation, the query information displayed on the screen Sc1 is displayed in the form of a URL, but a link (hyperlink) to the query information may also be displayed.

[0098] When user A wants to access the service SA of the on-premise server 30A, user A can easily access the service SA of the on-premise server 30A with one click of the query information L1. For example, when the relay server 10 accepts access of the query information L1 from the terminal 20A of user A, the relay server 10 receives information corresponding to the query information L1 (for example, information on the web page of the query information L1) from the on-premise server 30A and transmits it to the user terminal 20.

[0099] [8] Explanation of relay processing Next, the relay process performed by the relay server 10 will be specifically described with reference to Fig. 3. For example, as shown in Fig. 3, it is assumed that the services SA and SB of the on-premise server 30A and the services SC and SD of the on-premise server 30B are activated by agents corresponding to the services, and a TCP connection is established to the relay server 10.

[0100] For example, an example will be described in which the relay server 10 relays communication between the terminal 20A of the user A and the service SA of the on-premise server 30A.

[0101] First, when the relay server 10 receives access to the query information L1 from the terminal 20A of user A, it determines whether to permit authentication of user A. Note that the relay server 10 may omit the process of determining whether to permit authentication of user A if it is within a predetermined period from the time when authentication of user A is permitted (for example, within a 10-minute period from the time when authentication of user A is permitted).

[0102] Furthermore, when the relay server 10 receives the query information "https: / / example1.com.hennge.io / " from the terminal 20A, it means that the relay server 10 has received access to the web server "example1.com.hennge.io" of the relay server 10 via the protocol (e.g., HTTPS protocol) specified by the query information (e.g., URL) from the terminal 20A.

[0103] Then, when authentication of user A is permitted, the relay server 10 can determine that the access to the query information L1 is an access to the service SA of the on-premise server 30A, and therefore, uses the connection of the service SA that has been established in advance to establish a connection between the service SA and the terminal 20A. relays communications between

[0104] In addition, the agent corresponding to the service SA determines that the information transmitted over the connection is the service SA (port 80) of the on-premise server 30, and sends (transmits) it to the service SA (port 80).

[0105] As a result, the terminal 20A can access the on-premise server 30A from the outside via the relay server 10.

[0106] The relay server 10 relays communication between the terminal 20 of the user whose authentication has been permitted and the service SA only while the agent is running the service SA. In other words, when the service SA is stopped, the relay server 10 cannot communicate between the terminal 20 of the user whose authentication has been permitted and the service SA.

[0107] Furthermore, the agent can manage multiple services, and establishes a connection with the relay server 10 for each service. Therefore, for example, if the agent manages service SA and service SB, when the authenticated terminal 20A accesses query information L1, the relay server 10 uses the connection of service SA corresponding to query information L1. When the authenticated terminal 20A accesses query information L2, the relay server 10 uses the connection of service SB corresponding to query information L2.

[0108] The agent then determines which service (which port) of the on-premise server 30A the information transmitted by the terminal 20A via the relay server 10 will reach. For example, if the received information is information transmitted via a service SA connection, the agent transmits the information to service SA (port 80) of the on-premise server 30A, and if the received information is information transmitted via a service SB connection, the agent transmits the information to service SB (port 443) of the server 30A.

[0109] As described above, in this embodiment, a secure network environment can be realized because the terminal 20A does not directly access the on-premise server 30A without going through the relay server 10. Furthermore, in this embodiment, permission of user authentication is a condition for accessing the on-premise server, so unauthorized access can be prevented.

[0110] In addition, in this embodiment, when the terminal 20 communicates with the on-premise server 30 via the relay server 10, data may be encrypted using SSL or TLS.

[0111] [9] Flowchart The flow of processing by the relay server of this embodiment will be described with reference to Fig. 6. For convenience of explanation, processing related to user A will be described. First, based on the information of the on-premise server 30, query information that can be accessed from the on-premise server 30 is generated (step S1).

[0112] Then, it is determined whether or not access has been accepted from terminal 20A of user A (step S2). If access has been accepted from terminal 20A of user A (Y in step S2), it is determined whether or not authentication of user A is permitted (permission or denial) (step S3).

[0113] If authentication of user A is permitted (Y in step S3), the query information is presented to user A's terminal 20A (step S4). On the other hand, if authentication of user A is not permitted (rejected) (N in step S3), the process ends.

[0114] Then, it is determined whether or not access for the query information has been accepted from user A's terminal 20A (step S5). If access for the query information has been accepted from user A's terminal 20A (Y in step S5), the relay server 10 relays communication between user A's terminal 20A and the on-premise server 30 (step S6). For example, the relay server 10 receives information from terminal 20A and transmits it to the on-premise server 30, and receives information corresponding to the query information from the on-premise server 30 and transmits it to terminal 20A. This ends the processing.

[0115]

[10] Authentication of on-premise devices Furthermore, after permitting authentication of the user, the relay server 10 may further delegate authentication to an on-premise device (e.g., an agent). In other words, the relay server 10 may perform control so that communication between the terminal 20 and the on-premise server 30 is enabled when authentication is finally permitted by the on-premise device.

[0116]

[11] Cloud services and single sign-on The relay server 10 may also be an information processing device that allows the terminal 20, which is connected via the Internet, to securely access and authenticate a given cloud service. Examples of cloud services include Microsoft 365 (registered trademark), Google (registered trademark), Slack (registered trademark), and Zoom (registered trademark). The relay server 10 controls the cloud service so that it can be provided to users whose authentication has been approved.

[0117] For example, the relay server 10 may be configured to be able to control a plurality of cloud services so that the user can use them all at once with a single sign-on, using SAML (Security Assertion Markup Language).

[0118]

[12] Other The present invention is not limited to the above-described embodiments, and various modifications are possible. For example, terms cited in the specification or drawings as broadly defined or synonymous terms can be replaced with broadly defined or synonymous terms in other descriptions in the specification or drawings. [Explanation of symbols]

[0119] 10 servers, 20 terminals, 30 on-premise servers, 100 Processing unit, 111 User control unit, 112 Authentication processing unit, 113 Query information generation unit, 114 Presentation unit, 115 Relay processing unit, 120 Web processing unit, 170 Storage unit, 171 Main storage unit, 172 User information storage unit, 173 Query information storage unit, 180 Information storage medium, 196 Communication unit

Claims

1. An information processing device in which a user terminal and an on-premise server are connected via the Internet, and the user terminal and the on-premise server are connected via the Internet, a query information generation unit that is managed by a web server of the information processing device, generates a unique URL for relaying access to an on-premise server based on information about the on-premise server, and associates the URL with the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the URL to the user's terminal when authentication of the user is permitted; a relay processing unit that, when receiving access to the URL from a terminal of the user whose authentication has been permitted, relays communication between the terminal of the user and the on-premise server corresponding to the URL; 10. An information processing device comprising:

2. An information processing device in which a user terminal and an on-premise server are connected via the Internet, and the user terminal and the on-premise server are connected via the Internet, a query information generation unit that is managed by a web server of the information processing device, generates a unique URL for relaying access to a service of an on-premise server based on information of the on-premise server, and associates the URL with the service of the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the URL to the user's terminal when authentication of the user is permitted; a relay processing unit that, when receiving access to the URL from a terminal of the user whose authentication has been permitted, relays communication between the terminal of the user and the service of the on-premise server corresponding to the URL; 10. An information processing device comprising:

3. In claim 1 or 2, The user control unit For each user, determine whether the user is permitted to access the URL based on the user information of the user; The presentation unit An information processing device that presents, for each user, URLs accessible by that user to the user's terminal.

4. An access control system in which a user terminal, an on-premise server, and an information processing device are connected via the Internet, The information processing device includes: a query information generation unit that is managed by a web server of the information processing device, generates a unique URL for relaying access to an on-premise server based on information about the on-premise server, and associates the URL with the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the URL to the user's terminal when authentication of the user is permitted; a relay processing unit that, when an access to the URL is received from a terminal of the user who has been authenticated, relays communication between the terminal of the user and the on-premise server corresponding to the URL; The on-premise server An access control system characterized by, when access via the URL is accepted from the terminal of the user who has been authorized for authentication via the information processing device, presenting the information indicated in the URL to the user's terminal via the information processing device.

5. In claim 4, an agent device that exists in the same network environment as the on-premise server; The agent device Establishing a connection between each on-premise server and the information processing device; The relay processing unit When the access to the URL is accepted, the on-premise server relays communication between the user terminal and the on-premise server using a connection of the on-premise server corresponding to the URL; The agent device An access control system characterized by controlling the start or stop of services of the on-premise server.

6. An access control system in which a user terminal, an on-premise server, and an information processing device are connected via the Internet, The information processing device includes: A unique URL managed by a web server of the information processing device and used to relay access to a service of the on-premise server is added to the information of the on-premise server. a query information generating unit that generates a query information based on the URL and associates the URL with the service of the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the URL to the user's terminal when authentication of the user is permitted; a relay processing unit that, when receiving access to the URL from a terminal of the user who has been authenticated, relays communication between the terminal of the user and the service of the on-premise server corresponding to the URL; The on-premise server An access control system characterized by, when access via the URL is accepted from the terminal of the user who has been authorized for authentication via the information processing device, presenting the information indicated in the URL to the user's terminal via the information processing device.

7. In claim 6, an agent device that exists in the same network environment as the on-premise server; The agent device Establishing a connection between each service and the information processing device; The relay processing unit When the access to the URL is accepted, the service relays communication between the user's terminal and the service using a connection of the service corresponding to the URL; The agent device An access control system characterized by controlling the start or stop of services of the on-premise server.

8. A program for an information processing device in which a user terminal and an on-premise server are connected via the Internet, and the terminal and the on-premise server are connected via the Internet, a query information generation unit that is managed by a web server of the information processing device, generates a unique URL for relaying access to an on-premise server based on information about the on-premise server, and associates the URL with the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the URL to the user's terminal when authentication of the user is permitted; A program that causes a computer to function as a relay processing unit that relays communication between the user's terminal and the on-premises server corresponding to the URL when access to the URL is received from the user's terminal whose authentication has been permitted.

9. A program for an information processing device in which a user terminal and an on-premise server are connected via the Internet, and the terminal and the on-premise server are connected via the Internet, a query information generation unit that is managed by a web server of the information processing device, generates a unique URL for relaying access to a service of an on-premise server based on information of the on-premise server, and associates the URL with the service of the on-premise server; a user control unit that manages user information of users; an authentication processing unit that determines whether or not to permit authentication of a user when access is accepted from the user's terminal; a presentation unit that presents the URL to the user's terminal when authentication of the user is permitted; A program that causes a computer to function as a relay processing unit that relays communication between the user's terminal and the service on the on-premises server corresponding to the URL when access to the URL is received from the user's terminal whose authentication has been authorized.

10. An information processing method of an information processing device in which a user terminal and an on-premise server are connected via the Internet, and the terminal and the on-premise server are connected via the Internet, generating a unique URL, which is managed by a web server of the information processing device and is used to relay access to an on-premise server, based on information about the on-premise server, and associating the URL with the on-premise server; managing user information of a user; a step of determining whether or not to permit authentication of a user when access is accepted from the user's terminal; If authentication of the user is permitted, presenting the URL to the user's terminal; An information processing method characterized by including a step of relaying communication between the user's terminal and the on-premises server corresponding to the URL when access to the URL is accepted from the user's terminal whose authentication has been approved.

11. An information processing method of an information processing device in which a user terminal and an on-premise server are connected via the Internet, and the terminal and the on-premise server are connected via the Internet, generating a unique URL, which is managed by a web server of the information processing device and is used to relay access to a service of an on-premise server, based on information about the on-premise server, and associating the URL with the service of the on-premise server; managing user information of a user; a step of determining whether or not to permit authentication of a user when access is accepted from the user's terminal; If authentication of the user is permitted, presenting the URL to the user's terminal; An information processing method characterized by including a step of relaying communication between the user's terminal and the service of the on-premises server corresponding to the URL when access to the URL is received from the user's terminal whose authentication has been permitted.

Citation Information

Patent Citations

  • Processing system for financial institution, and maintenance method of processing system

    JP2006343994A

  • Access management device

    JP2013045278A

  • Proxy server device, client terminal device, remote access system, transfer control method and program, and access method and program

    JP2013210896A

  • System, information processing method, information processing device, program

    JP2018067144A

  • Service managing system and service managing method

    JP2019008525A