Communication system

The communication system addresses VPN vulnerabilities by using a cloud-based service with a reverse proxy and tunnel connection control to establish secure WebSocket tunnels, enhancing security and simplifying remote access setups for on-premises resources.

JP7894110B2Active Publication Date: 2026-07-29E JAN NETWORKS CO
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
E JAN NETWORKS CO
Filing Date
2023-05-19
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Existing VPN solutions for remote work expose companies to risks of third-party attacks due to global IP address exposure, require frequent updates and complex configurations, and pose security threats if remote PCs are hacked.

Method used

A communication system that uses a cloud-based service unit with a reverse proxy and tunnel connection control to establish a WebSocket tunnel for secure communication, eliminating the need for VPN devices and configurations by enabling secure access to on-premises resources through SSH authentication and encrypted data transmission.

Benefits of technology

This system enhances security by preventing unauthorized access, reduces the risk of third-party attacks, and simplifies the setup and maintenance of remote access, ensuring secure and efficient access to on-premises resources without disclosing global IP addresses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007894110000001
    Figure 0007894110000001
  • Figure 0007894110000002
    Figure 0007894110000002
  • Figure 0007894110000003
    Figure 0007894110000003
Patent Text Reader

Abstract

Provided is a communication system that comprises: a connector unit that is provided within an on-premises site; and a service unit. The service unit has: a reverse proxy unit that communicates with the connector unit and a communication terminal via the Internet; a tunnel connection control unit that performs SSH authentication with the connector unit and, when the SSH authentication is successful, generates a WebSocket tunnel between the reverse proxy unit and the connector unit; and a client handling unit that receives information about a resource within the on-premises site that corresponds to the connector unit by encrypted communication via the WebSocket tunnel and transmits the resource information to the communication terminal via the reverse proxy unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a communication system, an information processing apparatus, a program, an information processing method, and a connector device.

Background Art

[0002] Patent Document 1 describes that the security of remote work is improved by connecting a company's information system and an employee's home line via a VPN (Virtual Private Network). [Prior Art Document] [Patent Document] [Patent Document 1] Japanese Unexamined Patent Application Publication No. 2022-081071 General Disclosure

[0003] According to an embodiment of the present invention, a communication system is provided. The communication system may include a connector unit disposed within an on-premises site. The communication system may include a service unit. The service unit may have a reverse proxy unit that communicates with the connector unit and a communication terminal via the Internet. The service unit may have a tunnel connection control unit that executes SSH authentication with the connector unit and generates a WebSocket tunnel between the reverse proxy unit and the connector unit when the authentication is successful. The service unit may have a client correspondence unit that receives resource information within the on-premises site corresponding to the connector unit by encrypted communication via the WebSocket tunnel and transmits the resource information to the communication terminal via the reverse proxy unit.

[0004] In the communication system, the client correspondence unit may execute the encrypted communication by SSH.

[0005] In the communication system, the tunnel connection control unit may, when the reverse proxy unit receives a connection request from the connector unit, perform SSH authentication with the connector unit, and if authentication is successful, generate the WebSocket tunnel between the reverse proxy unit and the connector unit. The client support unit may, when the reverse proxy unit receives a login request from the communication terminal to the service unit by a user of the communication terminal, authenticate the user, and if authentication is successful, receive the user's login information for the on-premises site from the communication terminal and send the login information to the directory server of the on-premises site via the WebSocket tunnel. When the client support unit receives a request from the communication terminal of the user whose login information has been successfully authenticated by the directory server to the user server of the on-premises site, it may access the file server of the on-premises site via the WebSocket tunnel to receive the resource information, convert the resource information into HTML data, and place it on the web server of the client support unit. Similarly, when the client support unit receives a request to the on-premises site's web server from the communication terminal of the user whose login information has been successfully authenticated by the directory server, it may access the on-premises site's web server via the WebSocket tunnel, receive the resource information, convert the on-premises URL described in the HTML data within the resource information into a URL accessible from the communication terminal on the internet, and place it on the web server of the client support unit.

[0006] In the communication system, the connector unit may have a private key storage unit for storing a private key for SSH authentication, the tunnel connection control unit may have a public key storage unit for storing a public key corresponding to the private key, and the tunnel connection control unit and the connector unit may perform the SSH authentication using the private key and the public key. The communication terminal may have a terminal key storage unit for storing a public key corresponding to the private key, and when the client response unit receives an SSH authentication request from the communication terminal via the reverse proxy unit, including the public key stored in the terminal storage unit, it may transmit the SSH authentication request to the connector unit via the WebSocket tunnel, the connector unit may perform SSH authentication with respect to the received SSH authentication request using the public key included in the SSH authentication request and the private key stored in the private key storage unit, and if authentication is successful, it may transmit success notification data to the client response unit notifying that authentication was successful, and the client response unit may request the communication terminal to send the login information of the user of the communication terminal to the on-premises site in response to receiving the success notification data.

[0007] In the communication system, the tunnel connection control unit may have a private key storage unit for storing a private key for SSH authentication, the connector unit may have a public key storage unit for storing a public key corresponding to the private key, and the tunnel connection control unit and the connector unit may perform the SSH authentication using the private key and the public key. The communication terminal may have a terminal storage unit for storing a public key corresponding to the private key, and when the client response unit receives an SSH authentication request from the communication terminal via the reverse proxy unit, including the public key stored in the terminal storage unit, it may perform SSH authentication using the public key included in the SSH authentication request and the private key stored in the private key storage unit, and if authentication is successful, it may request the communication terminal to provide the login information for the user of the communication terminal to the on-premises site.

[0008] According to one embodiment of the present invention, an information providing device is provided. The information providing device may include a reverse proxy unit that communicates with a communication terminal and a connector unit located in an on-premises site via the Internet. The information providing device may include a tunnel connection control unit that performs SSH authentication with the connector unit and, upon successful authentication, generates a WebSocket tunnel between the reverse proxy unit and the connector unit. The information providing device may include a client-response unit that receives resource information in the on-premises site corresponding to the connector unit via encrypted communication through the WebSocket tunnel and transmits the resource information to the communication terminal via the reverse proxy unit.

[0009] According to one embodiment of the present invention, a program is provided for causing a computer to function as the above-mentioned information providing device.

[0010] According to one embodiment of the present invention, a method for providing information performed by a computer is provided. The information providing method may include a tunnel connection control step in which SSH authentication is performed between the reverse proxy unit and a connector unit located in an on-premises site via the Internet, and if authentication is successful, a WebSocket tunnel is generated between the reverse proxy unit and the connector unit. The information providing method may include a receiving step in which resource information in the on-premises site corresponding to the connector unit is received via encrypted communication through the WebSocket tunnel. The information providing method may include a transmitting step in which the resource information is transmitted to a communication terminal via the Internet.

[0011] According to one embodiment of the present invention, a connector device is provided. The connector device may include a private key storage unit for storing a private key for SSH authentication. The connector device may include a connector unit that performs SSH authentication using the private key with a service unit located in the cloud via the internet, and generates a WebSocket tunnel with the service unit if authentication is successful.

[0012] It should be noted that the above summary of the invention does not list all the necessary features of the present invention. Furthermore, subcombinations of these features may also constitute an invention. [Brief explanation of the drawing]

[0013] [Figure 1] An example of communication system 10 is shown in outline. [Figure 2] This is an explanatory diagram illustrating the processing in the communication system 10. [Figure 3] An example of the processing flow in the communication system 10 is shown in outline. [Figure 4] This is an explanatory diagram illustrating the processing in the communication system 10. [Figure 5] An example of the processing flow in the communication system 10 is shown in outline. [Figure 6] This is an explanatory diagram illustrating the processing in the communication system 10. [Figure 7] An example of the processing flow in the communication system 10 is shown in outline. [Figure 8] A schematic example of the hardware configuration of a computer 1200 that functions as a service unit 100, a connector unit 300, or a communication terminal 400 is shown. [Modes for carrying out the invention]

[0014] The present invention will be described below through embodiments, but these embodiments are not intended to limit the scope of the claims. Furthermore, not all combinations of features described in the embodiments are necessarily essential to the solution of the invention.

[0015] Figure 1 schematically shows an example of a communication system 10. The communication system 10 comprises a service unit 100 and a connector unit 300.

[0016] For example, when a company sets up a VPN environment at an on-premises site for its employees working remotely, there are several challenges. For instance, the risk of exposure to third-party attacks due to exposing global IP addresses to the internet must be considered. For instance, VPN devices need to be updated and maintained to maintain security in preparation for attacks. For instance, since remote PCs connect directly to the company network, there is a significant risk if the remote PC is hacked. For instance, it is necessary to deal with complex VPN configurations.

[0017] In the communication system 10 according to this embodiment, the service unit 100 is implemented as a cloud service. The connector unit 300 is located within an on-premise site 200 of a company or the like. The connector unit 300 and the reverse proxy unit 130 of the service unit 100 generate a WebSocket tunnel 180 to realize TCP (Transmission Control Protocol) / UDP (User Datagram Protocol) communication.

[0018] The service unit 100 communicates with the connector unit 300 via the WebSocket tunnel 180 and communicates with the communication terminals 400 of users 40, such as employees, via the internet 20. The communication terminals 400 may be smart devices. For example, the communication terminal 400 is a smartphone. For example, the communication terminal 400 is a tablet device. For example, the communication terminal 400 is a PC (Personal Computer).

[0019] The service unit 100 provides a remote connection environment to the on-premises site 200 for the communication terminal 400 of the user 40 without using a VPN device / VPN connection, and enables access to on-premises resources 220 such as a web portal, a mail server, a web application, a file server, and file sharing within the on-premises site 200. Thereby, in an enterprise, it is possible to eliminate the need to prepare a VPN environment for remote workers, and it is possible to eliminate the update operation of the VPN device and the load of complex VPN settings.

[0020] The service unit 100 includes a license management unit 110, a client support unit 120, a reverse proxy unit 130, and a tunnel connection control unit 140.

[0021] The license management unit 110 manages the contract status of service users for the cloud services provided by the service unit 100. The license management unit 110 manages, for example, information on enterprises having licenses. The license management unit 110 manages, for example, an enterprise that has provided the connector unit 300 as an enterprise having a license.

[0022] The client support unit 120 may have a function of authenticating the user 40 who wishes to connect to the service unit 100. The client support unit 120 may manage information on the user 40 registered by an enterprise having a license for the cloud service provided by the service unit 100. The information on the user 40 may include authentication information used for authentication of the user 40. The information on the communication terminal 400 of the user 40 may be included. When the user 40 connects to the service unit 100 by the communication terminal 400, the client support unit 120 refers to the managed information and confirms whether use is permitted.

[0023] The client support unit 120 may have a function of authenticating a user 40 who wishes to access the on-premises resources 220 of the on-premises site 200. The client support unit 120 may connect to a directory service or the like of the on-premises site 200 via the WebSocket tunnel 180 to authenticate the user 40.

[0024] The client support unit 120 performs authentication using, for example, a user ID and a password. The client support unit 120 may send the user ID and password received from the communication terminal 400 to the directory service of the on-premises site 200 and receive an authentication result. The client support unit 120 may use a UUID (Universally Unique Identifier).

[0025] The client support unit 120 may perform multi-factor authentication combined with a one-time password. The client support unit 120 may use a one-time password using email or SMS (Short Message Service). The client support unit 120 may use a one-time password using a phone. The client support unit 120 may use a one-time password using an app. The client support unit 120 may use a one-time password using a token. The client support unit 120 may use TOTP (Time-based One-time Password), HOTP (Hash-based Message Authentication Code One-Time Password), etc. as the one-time password.

[0026] The client support unit 120 may provide the user interface (UI) of the file server at the on-premises site 200 to the user 40. The client support unit 120 connects to the file server at the on-premises site 200 via the WebSocket tunnel 180 and converts the directory information of the file server into a web interface (HTML) so that it can be viewed, downloaded, and uploaded from the browser 410 of the communication terminal 400.

[0027] The reverse proxy unit 130 has a global IP address exposed to the Internet 20. The reverse proxy unit 130 has a reverse proxy function for communicating with on-premises resources 220 at the on-premises site 200 via the connector unit 300. The reverse proxy unit 130 may further have a load balancer function for load balancing in response to an increase in the capacity of the number of remote access clients to the on-premises site 200.

[0028] The tunnel connection control unit 140 has a server function that generates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300. The tunnel connection control unit 140 performs SSH authentication with the connector unit 300, and if authentication is successful, generates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300. The tunnel connection control unit 140 may perform SSH public key authentication.

[0029] The reverse proxy unit 130 and the connector unit 300 communicate via the WebSocket tunnel 180. The reverse proxy unit 130 and the connector unit 300 may perform encrypted communication. For example, the reverse proxy unit 130 and the connector unit 300 may perform encrypted communication using SSH.

[0030] The service unit 100 may include a license management unit 110, a client support unit 120, a reverse proxy unit 130, and a tunnel connection control unit 140 for each of the multiple companies. For example, the service unit 100 may implement the license management unit 110, client support unit 120, reverse proxy unit 130, and tunnel connection control unit 140 as instances for each of the multiple companies.

[0031] The connector unit 300 has a client function that communicates with the reverse proxy unit 130 and generates a WebSocket tunnel 180. The connector unit 300 uses only outbound connections and does not need to open any inbound connection ports, so it does not require a fixed global IP address and can eliminate external attacks. The connector unit 300 may have an SSH client function for performing SSH public key authentication by the tunnel connection control unit 140. The connector unit 300 may have a local bridge function and a port mapping function for connections from the client support unit 120.

[0032] The communication terminal 400 may use a secure browser as its browser 410. That is, the browser 410 may be a secure browser. The browser 410 may also be a general-purpose internet browser.

[0033] As described above, according to the communication system 10 of this embodiment, when the WebSocket tunnel 180 is established, SSH-based public key authentication is performed between the service unit 100 and the connector unit 300 installed at the on-premise site 200. This eliminates unauthorized connections by third parties. Furthermore, according to the communication system 10, encryption using SSH or the like may be performed on the communication data transmitted through the WebSocket tunnel 180. This makes the WebSocket tunneling more secure.

[0034] Furthermore, the communication system 10 allows companies to avoid disclosing the global IP addresses of their on-premises sites 200, thereby reducing the risk of third-party attacks. Additionally, external access can be routed through the services of the service department 100 via a secure browser on the communication terminal 400, preventing direct connection to the internal network and thus improving security.

[0035] Figure 2 is an explanatory diagram illustrating the processing in the communication system 10. Here, directory server 222, file server 224, and web server 226 are given as examples of on-premises resources 220.

[0036] The connector unit 300 located within the on-premises site 200 sends a connection request to the reverse proxy unit 130. The connector unit 300 may send the connection request to the reverse proxy unit 130 via HTTPS. The connection request may include license information of the company or other entity at the on-premises site 200 where the connector unit 300 is located. The reverse proxy unit 130 relays the connection request to the tunnel connection control unit 140.

[0037] The tunnel connection control unit 140 determines whether a license is legitimate based on the contract status managed by the license management unit 110. If the connection request comes from the connector unit 300 of a formally registered company, the license is determined to be legitimate. If the license information is forged, or if there was a contract in the past but the contract has now expired, the license is determined to be illegitimate.

[0038] If the tunnel connection control unit 140 determines that the license is legitimate, it performs SSH authentication with the connector unit 300. The tunnel connection control unit 140 and the connector unit 300 each store a private key and a corresponding public key, and perform SSH authentication using these private and public keys. If SSH authentication is successful, the tunnel connection control unit 140 creates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300. Even if the license authentication is incorrectly determined to be legitimate, the SSH authentication will cause the authentication to fail, thus preventing unauthorized use.

[0039] The reverse proxy unit 130 and the connector unit 300 may perform encrypted communication when communicating via the WebSocket tunnel 180. That is, the reverse proxy unit 130 and the connector unit 300 may encrypt the data when communicating data via the WebSocket tunnel 180. The reverse proxy unit 130 and the connector unit 300 may use SSH encrypted communication as the encryption method, or they may use other encrypted communication methods.

[0040] The creation of the WebSocket tunnel 180 prepares the system for providing services to the communication terminal 400. The communication terminal 400 sends a login request to the reverse proxy unit 130 via the internet 20. The communication terminal 400 may also send the login request to the reverse proxy unit 130 via HTTPS. The reverse proxy unit 130 relays the login request to the client response unit 120.

[0041] The client support unit 120 may determine whether or not user 40 can use the service by authenticating user 40 or the communication terminal 400 using the authentication information of user 40 that has been registered in advance. If the client support unit 120 determines that the service cannot be used, it transmits that fact to the communication terminal 400 via the reverse proxy unit 130.

[0042] If the client support unit 120 determines that it is available, it requests login information for user 40's on-premises site 200 from the communication terminal 400 via the reverse proxy unit 130. The communication terminal 400 sends the login information to the reverse proxy unit 130 in response to the request. The reverse proxy unit 130 relays the received login information to the client support unit 120.

[0043] The client support unit 120 transmits the received login information to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180. At this time, the reverse proxy unit 130 may transmit the login information to the connector unit 300 via the WebSocket tunnel 180 using encrypted communication. The connector unit 300 relays the received login information to the directory server 222 of the on-premises site 200.

[0044] The directory server 222 authenticates user 40 using the received login information and sends the authentication result to the connector unit 300. The connector unit 300 sends the received authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180. At this time, the connector unit 300 may send the authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180 using encrypted communication. The reverse proxy unit 130 relays the received authentication result to the client handling unit 120.

[0045] The client support unit 120 transmits the received authentication result to the communication terminal 400 via the reverse proxy unit 130. If authentication is successful, the communication terminal 400 will be able to access the resources at the on-premises site 200.

[0046] For example, the communication terminal 400 sends a connection request to the web server 226 of the on-premises site 200 to the reverse proxy unit 130 in accordance with the instructions of the user 40. The reverse proxy unit 130 relays the received connection request to the client response unit 120. In response to receiving the connection request, the client response unit 120 connects to the web server 226 via the reverse proxy unit 130, the WebSocket tunnel 180, and the connector unit 300. The client response unit 120 receives resource information from the web server 226 via the connector unit 300, the WebSocket tunnel 180, and the reverse proxy unit 130. The client response unit 120 may convert the received resource information into HTML data and place it on the web server of the client response unit 120. Alternatively, if the received resource information includes HTML data, the client response unit 120 may convert the on-premises URL described in the HTML data within the resource information into a URL accessible from the communication terminal 400 on the internet and place it on the web server of the client response unit 120. The HTML data may, for example, be data indicating a connection to the web server 226, and may include a so-called top page. The HTML data may also be other data. The client response unit 120 converts the internal URL address in the HTML data into a URL address of the web server of the client response unit 120 that the communication terminal 400 can access via the internet 20. The communication terminal 400 receives the HTML data from the web server of the client response unit 120 via the internet 20.

[0047] The communication terminal 400, for example, sends a list data request to the reverse proxy unit 130 requesting a list of files in the file server 224 of the on-premise site 200, in accordance with instructions from user 40. The reverse proxy unit 130 relays the received list data request to the client response unit 120. Upon receiving the list data request, the client response unit 120 connects to the file server 224 via the reverse proxy unit 130, the WebSocket tunnel 180, and the connector unit 300. The client response unit 120 receives the list data from the file server 224 via the connector unit 300, the WebSocket tunnel 180, and the reverse proxy unit 130. The client response unit 120 converts the list data into HTML format. The client response unit 120 places the converted list data on its web server. The communication terminal 400 receives the list data from the web server of the client response unit 120 via the internet 20.

[0048] The communication terminal 400, for example, sends a file request to the reverse proxy unit 130 requesting one of the files from the list data, in accordance with the instructions of user 40. The reverse proxy unit 130 relays the received file request to the client response unit 120. In response to receiving the file request, the client response unit 120 connects to the file server 224 via the reverse proxy unit 130, the WebSocket tunnel 180, and the connector unit 300. The client response unit 120 receives a copy of the target file from the file server 224 via the connector unit 300, the WebSocket tunnel 180, and the reverse proxy unit 130. The communication terminal 400 accesses the file stored in the client response unit 120 via the internet 20. If the file is edited on the communication terminal 400, the client response unit 120 may notify the file server 224 of the edited content or send a file reflecting the edited content to the file server 224.

[0049] Figure 3 schematically shows an example of the processing flow in the communication system 10. In Figure 3, both the connector unit 300 and the user 40 are assumed to be legitimate.

[0050] In step 102 (sometimes abbreviated as S), the connector unit 300 sends a connection request to the reverse proxy unit 130. The reverse proxy unit 130 relays the received connection request to the tunnel connection control unit 140.

[0051] In S104, the tunnel connection control unit 140 performs license authentication for the connector unit 300 based on the contract status managed by the license management unit 110. In this example, since the connector unit 300 is legitimate, the authentication is successful.

[0052] In S106, the tunnel connection control unit 140 performs SSH authentication with the connector unit 300. In this example, the authentication is successful because the connector unit 300 is legitimate. In S108, the tunnel connection control unit 140 creates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300.

[0053] In S110, the communication terminal 400 sends a login request to the reverse proxy unit 130. The reverse proxy unit 130 relays the received login request to the client support unit 120.

[0054] In S112, the client support unit 120 performs user authentication for user 40 of the communication terminal 400. In this example, since user 40 is legitimate, authentication is successful.

[0055] In S114, the client support unit 120 requests login information for user 40 to the on-premises site 200 from the communication terminal 400. In S116, the communication terminal 400 sends the login information to the reverse proxy unit 130 in response to the request. The reverse proxy unit 130 relays the received login information to the client support unit 120. In S118, the client support unit 120 sends the login information to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180.

[0056] In S120, the connector unit 300 performs authentication processing on the received login information. In this example, since user 40 is legitimate, authentication is successful. The connector unit 300 sends the login information to the directory server 222 and receives the authentication result from the directory server 222.

[0057] In S122, the connector unit 300 transmits the authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client support unit 120. In S124, the client support unit 120 transmits the authentication result to the communication terminal 400.

[0058] In S126, the communication terminal 400 sends a connection request to the web server 226 of the on-premises site 200 to the reverse proxy unit 130. The reverse proxy unit 130 relays the connection request to the client handling unit 120.

[0059] In S128, the client support unit 120 sends a connection request to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180. The connector unit 300 relays the connection request to the web server 226. In S130, the connector unit 300 receives HTML data from the web server 226 and sends it to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the HTML data to the client support unit 120.

[0060] In S132, the client support unit 120 converts the internal URL addresses in the HTML data into URL addresses of the client support unit 120's web server, which the communication terminal 400 can access via the internet 20. The client support unit 120 places the converted HTML data on the client support unit 120's web server. In S184, the communication terminal 400 receives the HTML data from the client support unit 120's web server.

[0061] Figure 4 is an explanatory diagram illustrating the processing in the communication system 10. Here, we will explain the processing in the communication system 10 when the connector unit 300 has a private key storage unit 312 that stores a private key, the tunnel connection control unit 140 has a public key storage unit 142 that stores a public key corresponding to the private key, and the communication terminal 400 has a terminal key storage unit 420 that stores a public key corresponding to the private key. Note that we will mainly explain the differences from Figure 2.

[0062] The connector unit 300 sends a connection request to the reverse proxy unit 130. The reverse proxy unit 130 relays the connection request to the tunnel connection control unit 140. The tunnel connection control unit 140 determines whether the license is legitimate based on the contract status managed by the license management unit 110. If the tunnel connection control unit 140 determines that the license is legitimate, it performs SSH authentication with the connector unit 300. The tunnel connection control unit 140 and the connector unit 300 perform SSH authentication using the public key stored in the public key storage unit 142 and the private key stored in the private key storage unit 312. If SSH authentication is successful, the tunnel connection control unit 140 creates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300.

[0063] The communication terminal 400 sends a login request to the reverse proxy unit 130. The reverse proxy unit 130 relays the login request to the client support unit 120. The client support unit 120 may determine whether user 40 can use the service by authenticating user 40 or the communication terminal 400 using the authentication information of user 40 that has been registered in advance.

[0064] If the client support unit 120 determines that it is available, it requests a public key from the communication terminal 400 via the reverse proxy unit 130. In response to the request, the communication terminal 400 sends the public key stored in the terminal key storage unit 420 to the reverse proxy unit 130. The reverse proxy unit 130 relays the public key back to the client support unit 120.

[0065] The client support unit 120 sends the authentication request, including the received public key, to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180. The connector unit 300 performs SSH authentication using the private key stored in the private key storage unit 312 and the public key included in the received authentication request. The connector unit 300 sends the authentication result of the SSH authentication to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client support unit 120.

[0066] If the authentication result is an authentication failure, the client support unit 120 notifies the communication terminal 400 of the authentication failure via the reverse proxy unit 130. If the authentication result is an authentication success, the client support unit 120 requests login information for user 40 to the on-premises site 200 from the communication terminal 400 via the reverse proxy unit 130. The communication terminal 400 sends the login information to the reverse proxy unit 130 in response to the request. The reverse proxy unit 130 relays the received login information to the client support unit 120. The client support unit 120 sends the login information to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180. The connector unit 300 relays the received login information to the directory server 222 of the on-premises site 200.

[0067] The directory server 222 authenticates user 40 using the received login information and sends the authentication result to the connector unit 300. The connector unit 300 sends the received authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client handling unit 120.

[0068] The client support unit 120 sends the authentication result to the communication terminal 400. If authentication is successful, the communication terminal 400 will be able to access the resources at the on-premises site 200.

[0069] Figure 5 schematically shows an example of the processing flow in the communication system 10. Here, we will explain the flow in the communication system 10 shown in Figure 4, from when the connector unit 300 sends a connection request to the service unit 100 until the authentication of user 40 by the directory server 222 is completed. We will mainly explain the differences from Figure 3.

[0070] In S202, the connector unit 300 transmits a connection request to the reverse proxy unit 130. The reverse proxy unit 130 relays the received connection request to the tunnel connection control unit 140.

[0071] In S204, the tunnel connection control unit 140 performs license authentication for the connector unit 300 based on the contract status managed by the license management unit 110. In this example, since the connector unit 300 is legitimate, the authentication is successful.

[0072] In S206, the tunnel connection control unit 140 performs SSH authentication with the connector unit 300. The tunnel connection control unit 140 and the connector unit 300 perform SSH authentication using the public key stored in the public key storage unit 142 and the private key stored in the private key storage unit 312. In this example, since the connector unit 300 is legitimate, authentication is successful. In S208, the tunnel connection control unit 140 creates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300.

[0073] In S210, the communication terminal 400 sends a login request to the reverse proxy unit 130. The reverse proxy unit 130 relays the received login request to the client support unit 120.

[0074] In S212, the client support unit 120 performs user authentication for user 40 of the communication terminal 400. In this example, since user 40 is legitimate, authentication is successful.

[0075] In S214, the client support unit 120 requests the public key from the communication terminal 400 via the reverse proxy unit 130. In S216, the communication terminal 400, in response to the request, sends the public key stored in the terminal key storage unit 420 to the reverse proxy unit 130. The reverse proxy unit 130 relays the public key to the client support unit 120.

[0076] In S218, the client support unit 120 sends the authentication request, including the received public key, to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180. In S220, the connector unit 300 performs SSH authentication using the private key stored in the private key storage unit 312 and the public key included in the received authentication request. In this example, since user 40 is legitimate, authentication is successful. In S222, the connector unit 300 sends the authentication result of the SSH authentication to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client support unit 120.

[0077] In S224, the client support unit 120 requests login information for user 40 to the on-premises site 200 from the communication terminal 400 via the reverse proxy unit 130. In S226, the communication terminal 400 sends the login information to the reverse proxy unit 130 in response to the request. The reverse proxy unit 130 relays the received login information to the client support unit 120. In S228, the client support unit 120 sends the login information to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180.

[0078] In S230, the connector unit 300 performs authentication processing for the received login information. The connector unit 300 sends the login information to the directory server 222 and receives the authentication result from the directory server 222.

[0079] In S232, the connector unit 300 transmits the authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client support unit 120. In S234, the client support unit 120 transmits the authentication result to the communication terminal 400.

[0080] Figure 6 is an explanatory diagram illustrating the processing in the communication system 10. Here, we will explain the processing in the communication system 10 when the tunnel connection control unit 140 has a private key storage unit 144 that stores a private key, the connector unit 300 has a public key storage unit 314 that stores a public key corresponding to the private key, and the communication terminal 400 has a terminal key storage unit 420 that stores a public key corresponding to the private key. Note that we will mainly explain the differences from Figure 4.

[0081] The connector unit 300 sends a connection request to the reverse proxy unit 130. The reverse proxy unit 130 relays the connection request to the tunnel connection control unit 140. The tunnel connection control unit 140 determines whether the license is legitimate based on the contract status managed by the license management unit 110. If the tunnel connection control unit 140 determines that the license is legitimate, it performs SSH authentication with the connector unit 300. The tunnel connection control unit 140 and the connector unit 300 perform SSH authentication using the private key stored in the private key storage unit 144 and the public key stored in the public key storage unit 314. If SSH authentication is successful, the tunnel connection control unit 140 creates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300.

[0082] The communication terminal 400 sends a login request to the reverse proxy unit 130. The reverse proxy unit 130 relays the login request to the client support unit 120. The client support unit 120 may determine whether user 40 can use the service by authenticating user 40 or the communication terminal 400 using the authentication information of user 40 that has been registered in advance.

[0083] If the client support unit 120 determines that it is available, it requests a public key from the communication terminal 400 via the reverse proxy unit 130. In response to the request, the communication terminal 400 sends the public key stored in the terminal key storage unit 420 to the reverse proxy unit 130. The reverse proxy unit 130 relays the public key back to the client support unit 120.

[0084] The client support unit 120 performs SSH authentication using the received public key and the private key stored in the private key storage unit 144. If the authentication result is an authentication failure, the client support unit 120 notifies the communication terminal 400 of the authentication failure via the reverse proxy unit 130. If the authentication is successful, the client support unit 120 requests login information for user 40 to the on-premises site 200 from the communication terminal 400 via the reverse proxy unit 130. The communication terminal 400 sends the login information to the reverse proxy unit 130 in response to the request. The reverse proxy unit 130 relays the received login information to the client support unit 120. The client support unit 120 sends the login information to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180. The connector unit 300 relays the received login information to the directory server 222 of the on-premises site 200.

[0085] The directory server 222 authenticates user 40 using the received login information and sends the authentication result to the connector unit 300. The connector unit 300 sends the received authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client support unit 120. The client support unit 120 sends the authentication result to the communication terminal 400. If authentication is successful, the communication terminal 400 can access resources at the on-premises site 200.

[0086] Figure 7 schematically shows an example of the processing flow in the communication system 10. Here, we will explain the flow in the communication system 10 shown in Figure 6, from when the connector unit 300 sends a connection request to the service unit 100 until the authentication of user 40 by the directory server 222 is completed. We will mainly explain the differences from Figure 5.

[0087] In S302, the connector unit 300 sends a connection request to the reverse proxy unit 130. The reverse proxy unit 130 relays the received connection request to the tunnel connection control unit 140.

[0088] In S304, the tunnel connection control unit 140 performs license authentication for the connector unit 300 based on the contract status managed by the license management unit 110. In this example, since the connector unit 300 is legitimate, the authentication is successful.

[0089] In S306, the tunnel connection control unit 140 performs SSH authentication with the connector unit 300. The tunnel connection control unit 140 and the connector unit 300 perform SSH authentication using the public key stored in the public key storage unit 314 and the private key stored in the private key storage unit 144. In this example, since the connector unit 300 is legitimate, authentication is successful. In S308, the tunnel connection control unit 140 creates a WebSocket tunnel 180 between the reverse proxy unit 130 and the connector unit 300.

[0090] In S310, the communication terminal 400 sends a login request to the reverse proxy unit 130. The reverse proxy unit 130 relays the received login request to the client support unit 120.

[0091] In S312, the client support unit 120 performs user authentication for user 40 of the communication terminal 400. In this example, since user 40 is legitimate, authentication is successful.

[0092] In S314, the client support unit 120 requests the public key from the communication terminal 400 via the reverse proxy unit 130. In S316, the communication terminal 400, in response to the request, sends the public key stored in the terminal key storage unit 420 to the reverse proxy unit 130. The reverse proxy unit 130 relays the public key to the client support unit 120.

[0093] In S318, the client handling unit 120 performs SSH authentication using the received public key and the private key stored in the private key storage unit 144. In this example, since user 40 is legitimate, authentication is successful.

[0094] In S320, the client support unit 120 requests login information for user 40 to the on-premises site 200 from the communication terminal 400 via the reverse proxy unit 130. In S322, the communication terminal 400 sends the login information to the reverse proxy unit 130 in response to the request. The reverse proxy unit 130 relays the received login information to the client support unit 120. In S324, the client support unit 120 sends the login information to the connector unit 300 via the reverse proxy unit 130 and the WebSocket tunnel 180.

[0095] In S326, the connector unit 300 performs authentication processing on the received login information. The connector unit 300 sends the login information to the directory server 222 and receives the authentication result from the directory server 222. In S328, the connector unit 300 sends the authentication result to the reverse proxy unit 130 via the WebSocket tunnel 180. The reverse proxy unit 130 relays the received authentication result to the client support unit 120. In S330, the client support unit 120 sends the authentication result to the communication terminal 400.

[0096] Figure 8 schematically shows an example of the hardware configuration of a computer 1200 that functions as a service unit 100 or a connector unit 300. A program installed on the computer 1200 can cause the computer 1200 to function as one or more "parts" of the apparatus according to this embodiment, or to cause the computer 1200 to execute operations associated with the apparatus according to this embodiment or such one or more "parts", and / or to cause the computer 1200 to execute a process or a stage of such process according to this embodiment. Such a program may be executed by the CPU 1212 to cause the computer 1200 to execute specific operations associated with some or all of the blocks in the flowcharts and block diagrams described herein.

[0097] The computer 1200 according to this embodiment includes a CPU 1212, RAM 1214, and a graphics controller 1216, which are interconnected by a host controller 1210. The computer 1200 also includes input / output units such as a communication interface 1222, a storage device 1224, a DVD drive 1226, and an IC card drive, which are connected to the host controller 1210 via an input / output controller 1220. The DVD drive 1226 may be a DVD-ROM drive and a DVD-RAM drive, etc. The storage device 1224 may be a hard disk drive and a solid-state drive, etc. The computer 1200 also includes legacy input / output units such as a ROM 1230 and a keyboard, which are connected to the input / output controller 1220 via an input / output chip 1240.

[0098] The CPU 1212 operates according to the programs stored in the ROM 1230 and RAM 1214, thereby controlling each unit. The graphics controller 1216 acquires the image data generated by the CPU 1212 and stores it in the frame buffer provided in RAM 1214 or within itself, so that the image data is displayed on the display device 1218.

[0099] The communication interface 1222 communicates with other electronic devices via a network. The storage device 1224 stores programs and data used by the CPU 1212 in the computer 1200. The DVD drive 1226 reads programs or data from a DVD-ROM 1227, etc., and provides them to the storage device 1224. The IC card drive reads programs and data from an IC card and / or writes programs and data to an IC card.

[0100] The ROM 1230 stores boot programs and / or hardware-dependent programs of the computer 1200, which are executed by the computer 1200 upon activation. The input / output chip 1240 may also connect various input / output units to the input / output controller 1220 via USB ports, parallel ports, serial ports, keyboard ports, mouse ports, etc.

[0101] The program is provided on a computer-readable storage medium such as a DVD-ROM 1227 or an IC card. The program is read from the computer-readable storage medium and installed on a storage device 1224, RAM 1214, or ROM 1230, which are examples of computer-readable storage media, and executed by the CPU 1212. The information processing described within these programs is read by the computer 1200, resulting in coordination between the program and the various types of hardware resources described above. The apparatus or method may be configured to realize the operation or processing of information in accordance with the use of the computer 1200.

[0102] For example, when communication is performed between a computer 1200 and an external device, the CPU 1212 may execute a communication program loaded into RAM 1214 and, based on the processing described in the communication program, instruct the communication interface 1222 to perform communication processing. Under the control of the CPU 1212, the communication interface 1222 reads transmission data stored in a transmission buffer area provided in a recording medium such as RAM 1214, storage device 1224, DVD-ROM 1227, or IC card, transmits the read transmission data to the network, or writes received data received from the network to a reception buffer area or the like provided on the recording medium.

[0103] Furthermore, the CPU 1212 may read all or necessary parts of files or databases stored on external recording media such as the storage device 1224, DVD drive 1226 (DVD-ROM 1227), or IC card into the RAM 1214, and perform various types of processing on the data in the RAM 1214. The CPU 1212 may then write the processed data back to the external recording media.

[0104] Various types of information, such as various types of programs, data, tables, and databases, may be stored on the recording medium and subjected to information processing. The CPU 1212 may perform various types of processing on the data read from RAM 1214, including various types of operations, information processing, conditional judgments, conditional branching, unconditional branching, information retrieval / replacement, etc., as described throughout this disclosure and specified by the program instruction sequence, and write the results back to RAM 1214. The CPU 1212 may also retrieve information in files, databases, etc., within the recording medium. For example, if multiple entries are stored in the recording medium, each having an attribute value of a first attribute associated with an attribute value of a second attribute, the CPU 1212 may search among the multiple entries for an entry that matches the specified condition for the attribute value of the first attribute, read the attribute value of the second attribute stored in that entry, and thereby obtain the attribute value of the second attribute associated with the first attribute that satisfies the predetermined condition.

[0105] The program or software module described above may be stored on or near computer 1200 on a computer-readable storage medium. Alternatively, a recording medium such as a hard disk or RAM provided within a server system connected to a dedicated communication network or the Internet can be used as a computer-readable storage medium, thereby providing the program to computer 1200 via the network.

[0106] In this embodiment, blocks in the flowchart and block diagram may represent a stage in a process in which an operation is performed or a "part" of a device that has the role of performing an operation. A particular stage and "part" may be implemented by a dedicated circuit, a programmable circuit supplied with computer-readable instructions stored on a computer-readable storage medium, and / or a processor supplied with computer-readable instructions stored on a computer-readable storage medium. The dedicated circuit may include digital and / or analog hardware circuits, and may include integrated circuits (ICs) and / or discrete circuits. The programmable circuit may include reconfigurable hardware circuits, such as field-programmable gate arrays (FPGAs) and programmable logic arrays (PLAs), which include logical AND, logical OR, exclusive OR, negated AND, negated OR, and other logical operations, flip-flops, registers, and memory elements.

[0107] A computer-readable storage medium may include any tangible device capable of storing instructions that can be executed by a suitable device, and as a result, a computer-readable storage medium having instructions stored therein will comprise a product that includes instructions that can be executed to create means for performing operations specified in a flowchart or block diagram. Examples of computer-readable storage media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, etc. More specific examples of computer-readable storage media may include floppy disks, diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disk read-only memory (CD-ROM), digital multipurpose disc (DVD), Blu-ray® disc, memory stick, integrated circuit card, etc.

[0108] Computer-readable instructions may include assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk®, Java®, C++, and traditional procedural programming languages ​​such as the C programming language or similar languages.

[0109] Computer-readable instructions may be provided to a general-purpose computer, a special-purpose computer, or a programmable circuit, either locally or via a local area network (LAN), the Internet, or other wide area network (WAN), so that the computer-readable instructions may be executed by the processor or programmable circuit of a general-purpose computer, a special-purpose computer, or other programmable data processing device, in order to generate means for performing operations specified in a flowchart or block diagram. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, and the like.

[0110] Although the present invention has been described above using embodiments, the technical scope of the present invention is not limited to the scope described in the above embodiments. It will be apparent to those skilled in the art that various modifications or improvements can be made to the above embodiments. It will be clear from the claims that such modified or improved forms may also be included in the technical scope of the present invention.

[0111] It should be noted that the execution order of operations, procedures, steps, and stages in the devices, systems, programs, and methods shown in the claims, specifications, and drawings is not explicitly stated as "before" or "prior to," and that these can be performed in any order unless the output of a previous operation is used in a later operation. Even if the operation flow in the claims, specifications, and drawings is described using phrases such as "first," and "next," for convenience, this does not mean that it is mandatory to perform them in that order. [Explanation of Symbols]

[0112] 10 Communication System, 20 Internet, 100 Service Department, 110 License Management Department, 120 Client Support Department, 130 Reverse Proxy Department, 140 Tunnel Connection Control Unit, 142 Public Key Storage Unit, 144 Private Key Storage Unit, 180 WebSocket Tunnel, 200 On-Premise Site, 210 Firewall, 220 On-Premise Resources, 222 Directory Server, 224 File Server, 226 Web Server, 300 Connector Department, 312 Private Key Storage Unit, 314 Public Key Storage Unit, 400 Communication Terminal, 410 Browser, 420 Terminal Key Storage Unit, 1200 Computer, 1210 Host Controller, 1212 CPU, 1214 RAM, 1216 Graphics Controller, 1218 Display Device, 1220 Input / Output Controller, 1222 Communication Interface, 1224 Storage Device, 1226 DVD Drive, 1227 DVD-ROM, 1230 ROM, 1240 input / output chip

Claims

1. The connector unit is located within the on-premises site, Service Department and Equipped with, The aforementioned service unit is A reverse proxy unit that communicates with the connector unit and the communication terminal via the internet, A tunnel connection control unit performs SSH authentication with the connector unit, and if authentication is successful, generates a WebSocket tunnel between the reverse proxy unit and the connector unit. A client-side unit receives resource information within the on-premises site corresponding to the connector unit via encrypted communication through the WebSocket tunnel, and transmits the resource information to the communication terminal via the reverse proxy unit. It has, The connector unit has a private key storage unit that stores a private key for SSH authentication. The tunnel connection control unit has a public key storage unit that stores a public key corresponding to the private key, The tunnel connection control unit and the connector unit perform the SSH authentication using the private key and the public key. The aforementioned communication terminal has a terminal key storage unit that stores a public key corresponding to the private key, The client support unit receives a login request from the communication terminal via the reverse proxy unit, requests the public key from the communication terminal via the reverse proxy unit, and transmits an SSH authentication request including the public key received from the communication terminal via the reverse proxy unit to the connector unit via the reverse proxy unit and the WebSocket tunnel. The connector unit performs SSH authentication using the public key included in the received SSH authentication request and the private key stored in the private key storage unit, and transmits the authentication result to the client handling unit via the WebSocket tunnel and the reverse proxy unit. The client handling unit, if the authentication result is successful, requests the communication terminal, via the reverse proxy unit, to log in to the on-premises site for the user of the communication terminal, and transmits the login information received from the communication terminal to the connector unit via the reverse proxy unit and the WebSocket tunnel. Communication system.

2. A connector unit located within an on-premise site, Service Department and Equipped with, The aforementioned service unit is A reverse proxy unit that communicates with the connector unit and the communication terminal via the internet, A tunnel connection control unit performs SSH authentication with the connector unit, and if authentication is successful, generates a WebSocket tunnel between the reverse proxy unit and the connector unit. A client-side unit receives resource information within the on-premises site corresponding to the connector unit via encrypted communication through the WebSocket tunnel, and transmits the resource information to the communication terminal via the reverse proxy unit. It has, The tunnel connection control unit has a secret key storage unit that stores a secret key for SSH authentication, The connector unit has a public key storage unit that stores a public key corresponding to the private key. The tunnel connection control unit and the connector unit perform the SSH authentication using the private key and the public key. The aforementioned communication terminal has a terminal key storage unit that stores a public key corresponding to the private key, The client handling unit receives a login request from the communication terminal via the reverse proxy unit, requests the public key from the communication terminal via the reverse proxy unit, performs SSH authentication using the public key received from the communication terminal via the reverse proxy unit and the private key stored in the private key storage unit, and if authentication is successful, requests the communication terminal, via the reverse proxy unit, the login information of the user of the communication terminal to the on-premises site, and transmits the login information received from the communication terminal to the connector unit via the reverse proxy unit and the WebSocket tunnel. Communication system.

3. The communication system according to claim 1 or 2, wherein the client handling unit performs the encrypted communication by SSH.

4. The communication system according to claim 3, wherein the tunnel connection control unit performs SSH authentication with the connector unit when the reverse proxy unit receives a connection request from the connector unit, and generates the WebSocket tunnel between the reverse proxy unit and the connector unit if the authentication is successful.

5. The communication system according to claim 1, wherein the client handling unit authenticates the user when the reverse proxy unit receives the login request from the communication terminal to the service unit by a user of the communication terminal, requests the public key from the communication terminal via the reverse proxy unit if the authentication is successful, transmits the SSH authentication request including the public key received from the communication terminal via the reverse proxy unit to the connector unit via the reverse proxy unit and the WebSocket tunnel, and if the authentication result received from the connector unit is successful, requests the login information for the on-premises site of the user of the communication terminal from the communication terminal via the reverse proxy unit, and transmits the login information received from the communication terminal to the directory server of the on-premises site via the reverse proxy unit and the WebSocket tunnel.

6. The communication system according to claim 2, wherein the client handling unit authenticates the user when the reverse proxy unit receives the login request from the communication terminal to the service unit by a user of the communication terminal, requests the public key from the communication terminal via the reverse proxy unit if authentication is successful, performs SSH authentication using the public key received from the communication terminal via the reverse proxy unit and the private key stored in the private key storage unit, requests the login information for the on-premise site of the user of the communication terminal from the communication terminal via the reverse proxy unit, and transmits the login information received from the communication terminal to the directory server of the on-premise site via the reverse proxy unit and the WebSocket tunnel.

7. The communication system according to claim 5 or 6, wherein the client handling unit, upon receiving a request to the on-premises site's web server from the communication terminal of the user whose login information has been successfully authenticated by the directory server, accesses the on-premises site's web server via the WebSocket tunnel to receive the resource information, converts the resource information into HTML data, and places it on the web server of the client handling unit.

8. The communication system according to claim 5 or 6, wherein the client handling unit, upon receiving a request to the on-premises site's web server from the communication terminal of the user whose login information has been successfully authenticated by the directory server, accesses the on-premises site's web server via the WebSocket tunnel, receives the resource information, converts the on-premises URL described in the HTML data within the resource information into a URL accessible from the communication terminal on the internet, and places it on the web server of the client handling unit.