Programs, methods, information processing devices, systems
Patent Information
- Application Number
- JP2024057307
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2024-03-29
- Publication Date
- 2026-09-30
- Estimated Expiration
- 2044-03-29
AI Technical Summary
【0007】 組織内のユーザにおけるサービスの利用権限の管理を容易に行うことができる。
Smart Images

Figure 0007926819000001 
Figure 0007926819000002 
Figure 0007926819000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to a program, a method, an information processing apparatus, and a system.
Background Art
[0002] In recent years, the use of SaaS (Software as a Service) has been expanding. In SaaS, software running on a server is provided as a service to users via a network such as the Internet. Additionally, in organizations such as corporations, there is a technology that reduces the occurrence of problems such as information leakage by setting available SaaS for each user and restricting the scope of SaaS usage. Patent Document 1 describes that, when a record of a certain user in a log of a CASB (Cloud Access Security Broker) records that the user used a cloud service unregistered in the user attribute information, the user is detected as a suspicious user.
Prior Art Literature
Patent Literature
[0003]
Patent Document 1
Summary of the Invention
Problem to be Solved by the Invention
[0004] In Patent Document 1, since available services are registered for each user, management work for usage authority for each user is complicated.
[0005] An object of the present disclosure is to easily manage service usage authority for users in an organization.
Means for Solving the Problem
[0006] A program for execution on a computer having a processor and memory, the program causing the processor to perform the following steps: acquiring information about a process performed by a terminal device, which is executed when a user operates the terminal device; acquiring information about the user's attributes in the organization to which the user belongs and information about the service related to the process, based on the acquired information about the process; and determining whether the user has the right to use the service, based on the information about the attributes and the information about the service related to the process. [Effects of the Invention]
[0007] This makes it easy to manage service access rights for users within an organization. [Brief explanation of the drawing]
[0008] [Figure 1] This is a block diagram showing an example of the overall configuration of System 1. [Figure 2] Figure 1 is a block diagram showing an example configuration of the terminal device 10. [Figure 3] This figure shows an example of the functional configuration of the first server 20. [Figure 4] This figure shows an example of the functional configuration of the second server 30. [Figure 5] This diagram shows the data structure of the correspondence table 2021. [Figure 6] This diagram shows the data structure of the SaaS table 2022. [Figure 7] This diagram shows the data structure of the restriction table 2023. [Figure 8] This diagram shows the data structure of the user information table 2024. [Figure 9] This diagram shows the data structure of the condition table 2025. [Figure 10] This diagram shows the data structure of the judgment result table 2026. [Figure 11] This is a schematic diagram illustrating an example of authority determination processing. [Figure 12]This is a schematic diagram illustrating an example of the display screen of the display 141 of the terminal device 10. [Figure 13] A block diagram showing the basic hardware configuration of Computer 90. [Modes for carrying out the invention]
[0009] Embodiments of the present disclosure will be described below with reference to the drawings. In the following description, identical parts are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions of them will not be repeated.
[0010] <Overview> An agent application is installed on the terminal device, and the agent implemented by the agent application monitors the actions performed by the user. When the user performs a predetermined process, the terminal device sends information about the user's process to the server. Based on the received information, the server obtains information about the user's attributes within the organization and information about the service related to the process. Based on the user's attributes, the server determines whether the user has the authority to use the service.
[0011] <1 System Configuration Diagram> Figure 1 is a block diagram showing an example of the overall configuration of System 1. System 1 shown in Figure 1 includes, for example, a terminal device 10, a first server 20, and a second server 30. The terminal device 10, the first server 20, and the second server 30 communicate with each other, for example, via a network 80.
[0012] Figure 1 shows an example where System 1 includes two terminal devices 10, but the number of terminal devices 10 included in System 1 is not limited to two. System 1 may include fewer than three terminal devices 10, or three or more.
[0013] In FIG. 1, an aggregate of a plurality of devices may be used as one first server 20. The method of allocating the plurality of functions required for implementing the first server 20 according to the present embodiment to one or more pieces of hardware can be appropriately determined in consideration of the processing capability of each piece of hardware and / or specifications required for the first server 20, and the like.
[0014] In FIG. 1, an aggregate of a plurality of devices may be used as one second server 30. The method of allocating the plurality of functions required for implementing the second server 30 according to the present embodiment to one or more pieces of hardware can be appropriately determined in consideration of the processing capability of each piece of hardware and / or specifications required for the second server 30, and the like.
[0015] The terminal device 10 shown in FIG. 1 is, for example, an information processing device operated by a user. Specifically, for example, the terminal device 10 is an information processing device operated by an employee belonging to a company.
[0016] The terminal device 10 is implemented by, for example, a stationary PC, a laptop PC, or the like. The terminal device 10 may also be, for example, a mobile terminal such as a smartphone or a tablet. The terminal device 10 may also be a wearable terminal such as an HMD (Head Mount Display) or a watch-type terminal.
[0017] The terminal device 10 includes a communication IF (Interface) 12, an input device 13, an output device 14, a memory 15, a storage 16, and a processor 19. The input device 13 is a device for accepting an input operation from a user (for example, a touch panel, a touch pad, a pointing device such as a mouse, a keyboard, etc.). The output device 14 is a device for presenting information to a user (a display, a speaker, etc.).
[0018] The first server 20 is, for example, an information processing device that manages web services used by employees belonging to a company. The first server 20 is implemented, for example, by a computer connected to a network 80. As shown in Figure 1, the first server 20 includes a communication IF 22, an I / O IF 23, memory 25, storage 26, and a processor 29. The I / O IF 23 functions as an interface to an input device for receiving input operations from a user and an output device for outputting information to the user.
[0019] The second server 30 is, for example, an information processing device that provides web services used by employees belonging to a company. In other words, the second server 30 is, for example, an information processing device that provides SaaS (Software as a Service). The second server 30 issues accounts to employees based on a contract with the company. Employees use the web services through the assigned accounts. The second server 30 is implemented by, for example, a computer connected to the network 80. The second server 30 has a configuration similar to the first server 20 in Figure 1.
[0020] Each information processing device consists of a computer equipped with an arithmetic unit and a memory device. The basic hardware configuration of the computer and the basic functional configuration of the computer realized by said hardware configuration will be described later. For each of the terminal device 10, the first server 20, and the second server 30, explanations that overlap with the basic hardware configuration and basic functional configuration of the computer described later will be omitted.
[0021] <1.1 Terminal Device Configuration> Figure 2 is a block diagram showing an example configuration of the terminal device 10 shown in Figure 1. As shown in Figure 2, the terminal device 10 includes a communication unit 120, an input device 13, an output device 14, an audio processing unit 17, a microphone 171, a speaker 172, a camera 160, a location information sensor 150, a storage unit 180, and a control unit 190. Each block included in the terminal device 10 is electrically connected, for example, by a bus.
[0022] The communication unit 120 performs processing such as modulation and demodulation processing for the terminal device 10 to communicate with other devices. The communication unit 120 performs transmission processing on the signal generated by the control unit 190 and transmits it to an external source (for example, the first server 20 or the second server 30). The communication unit 120 performs reception processing on the signal received from the external source and outputs it to the control unit 190.
[0023] The input device 13 is a device for a user operating the terminal device 10 to input instructions or information. The input device 13 can be implemented, for example, by a touch-sensitive device 131 on which instructions are input by touching the operating surface. If the terminal device 10 is a PC, the input device 13 may be implemented by a reader, keyboard, mouse, etc. The input device 13 converts the instructions input by the user into electrical signals and outputs the electrical signals to the control unit 190. The input device 13 may also include, for example, a receiving port that accepts electrical signals input from an external input device.
[0024] The output device 14 is a device for presenting information to the user operating the terminal device 10. The output device 14 is implemented, for example, by a display 141. The display 141 displays data according to the control of the control unit 190. The display 141 is implemented, for example, by an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display.
[0025] The audio processing unit 17 performs, for example, digital-to-analog conversion processing of the audio signal. The audio processing unit 17 converts the signal received from the microphone 171 into a digital signal and provides the converted signal to the control unit 190. The audio processing unit 17 also provides the audio signal to the speaker 172. The audio processing unit 17 is implemented, for example, by an audio processing processor. The microphone 171 receives an audio input and provides the audio signal corresponding to that audio input to the audio processing unit 17. The speaker 172 converts the audio signal received from the audio processing unit 17 into audio and outputs the audio to the outside of the terminal device 10.
[0026] Camera 160 is a device that receives light using a photodetector and outputs it as a shooting signal.
[0027] The location information sensor 150 is a sensor that detects the position of the terminal device 10, and is, for example, a GPS (Global Positioning System) module. A GPS module is a receiving device used in a satellite positioning system. In a satellite positioning system, signals are received from at least three or four satellites, and the current position of the terminal device 10, which is equipped with a GPS module, is detected based on the received signals. The location information sensor 150 may also detect the current position of the terminal device 10 from the position of the wireless base station to which the terminal device 10 is connected.
[0028] The storage unit 180 is implemented, for example, by memory 15 and storage 16, and stores data and programs used by the terminal device 10. The storage unit 180 stores, for example, user information 181 and agent applications 187. The information and applications stored in the storage unit 180 are not limited to these.
[0029] User information 181 includes, for example, information about a user who uses terminal device 10. User information includes, for example, user ID, user's name, age, address, date of birth, password, contact information (address), etc.
[0030] Agent app 187 is an application for managing user usage of SaaS. Agent app 187 is installed on terminal device 10. Agent app 187 runs in the background of other applications installed on terminal device 10, for example, and monitors processes performed by the user.
[0031] The control unit 190 is realized by the processor 19 reading a program, including an agent application 187, stored in the memory unit 180, and executing instructions contained in the program. The control unit 190 controls the operation of the terminal device 10. By operating according to the program, the control unit 190 performs the functions of an operation reception unit 191, a transmission / reception unit 192, a presentation control unit 193, and an acquisition unit 194.
[0032] The operation reception unit 191 processes instructions or information input from the input device 13. Specifically, for example, the operation reception unit 191 receives instructions or information input from a touch-sensitive device 131 or the like.
[0033] Furthermore, the operation reception unit 191 receives voice instructions input from the microphone 171. Specifically, for example, the operation reception unit 191 receives voice signals input from the microphone 171 and converted into digital signals by the voice processing unit 17. The operation reception unit 191 obtains instructions from the user by, for example, analyzing the received voice signals and extracting predetermined nouns.
[0034] The transmitting / receiving unit 192 performs processing to enable the terminal device 10 to send and receive data with an external device such as the first server 20 or the second server 30 in accordance with a communication protocol. Specifically, for example, the transmitting / receiving unit 192 transmits information or instructions from the user to the first server 20 or the second server 30. The transmitting / receiving unit 192 also receives information provided by the first server 20 or the second server 30.
[0035] The presentation control unit 193 controls the output device 14 in order to present information provided by the first server 20 or the second server 30 to the user. Specifically, for example, the presentation control unit 193 causes the information provided by the first server 20 or the second server 30 to be displayed on the display 141. The presentation control unit 193 also causes the information provided by the first server 20 or the second server 30 to be output from the speaker 172.
[0036] The acquisition unit 194 acquires information about processes executed by the user operating the terminal device 10. Specifically, for example, the acquisition unit 194 acquires the name of the application executed by the user's operation and the process name of that application. The acquisition unit 194 stores the acquired application name, process name, and the date and time these information was acquired in the storage unit 180 (not shown).
[0037] Furthermore, the acquisition unit 194 acquires information generated when a user operates the browser. This information includes, for example, the browser's usage history, and more specifically, the URLs and page titles of the web pages the user has visited using the browser. The acquisition unit 194 acquires this information from the browser used in the terminal device 10 at predetermined intervals, such as every 5 minutes. The acquisition unit 194 stores the acquired information, the date and time the information was acquired, the name of the browser from which the information was acquired, and the identification information of the terminal device 10 (e.g., device GUID) in the storage unit 180 (not shown).
[0038] <1.2 Functional Configuration of the First Server> Figure 3 shows an example of the functional configuration of the first server 20. As shown in Figure 3, the first server 20 functions as a communication unit 201, a storage unit 202, and a control unit 203.
[0039] The communications unit 201 performs processing to enable the first server 20 to communicate with external devices.
[0040] The storage unit 202 includes, for example, a correspondence table 2021, a SaaS table 2022, a restriction table 2023, a user information table 2024, a condition table 2025, and a judgment result table 2026. The tables stored in the storage unit 202 are not limited to these.
[0041] The Correspondence Table 2021 is a table that associates information used to identify SaaS applications with information about actions performed by users. Further details will be provided later.
[0042] The SaaS Table 2022 is a table that stores information for identifying SaaS applications, as well as details about the SaaS applications themselves. SaaS applications stored in the SaaS Table 2022 are, for example, SaaS applications that are not permitted for use within the organization. In other words, the SaaS Table 2022 is a blacklist. Alternatively, SaaS applications stored in the SaaS Table 2022 may be, for example, SaaS applications that are permitted for use within the organization. In other words, the SaaS Table 2022 can also be a whitelist. Further details will be provided later. The SaaS Table 2022 is updated whenever a company using System 1 contracts for a new SaaS application.
[0043] Restriction Table 2023 is a table that associates conditions for restricting the operation of terminal device 10 with the judgment results of judgment module 2037, and the restrictions on the operation of terminal device 10. Details will be described later. Restriction Table 2023 is updated when a new correspondence between the judgment result and the restrictions on the operation of terminal device 10 is registered.
[0044] User Information Table 2024 is a table that stores information about users. User Information Table 2024 is updated when new user information is registered. Further details will be provided later.
[0045] Conditions Table 2025 is a table that stores information about the conditions related to SaaS usage permissions. Further details will be provided later.
[0046] The judgment result table 2026 is a table that stores the detection logs of user SaaS usage and the judgment results from the judgment module 2037. Further details will be described later.
[0047] The control unit 203 is realized when the processor 29 reads a program stored in the memory unit 202 and executes instructions contained in the program. By operating according to the program, the control unit 203 performs the functions indicated as the receive control module 2031, transmit control module 2032, presentation control module 2033, management module 2034, first acquisition module 2035, second acquisition module 2036, decision module 2037, and restriction module 2038.
[0048] The receiver control module 2031 controls the process by which the first server 20 receives signals from an external device according to a communication protocol.
[0049] The transmission control module 2032 controls the process by which the first server 20 transmits signals to an external device according to a communication protocol.
[0050] The presentation control module 2033 presents the information extracted from the storage unit 202 to a designated user via an external terminal.
[0051] The management module 2034 manages the information stored in the storage unit 202. Specifically, for example, the management module 2034 updates the user information table 2024 when there is information about a new user or when there are updates to the information of an already registered user. Also, for example, the management module 2034 updates the correspondence table 2021 when there is a new correspondence between information for identifying a SaaS and information about the process performed by the user. Also, for example, the management module 2034 updates the SaaS table 2022 when there is information about a new SaaS. Also, for example, the management module 2034 updates the restriction table 2023 when there is a new correspondence between the judgment result by the judgment module 2037 and the restrictions on the operation of the terminal device 10. Also, for example, the management module 2034 updates the condition table 2025 when there is new information about the conditions related to the right to use a SaaS.
[0052] The first acquisition module 2035 acquires information about processes performed by the user operating the terminal device 10. At predetermined timings (for example, at predetermined intervals), the first acquisition module 2035 sends a request to the terminal device 10 for information acquired by the acquisition unit 194 of the terminal device 10. The terminal device 10 sends the information acquired by the acquisition unit 194 to the first server 20 in response to the request. The first acquisition module 2035 acquires the information sent from the terminal device 10.
[0053] Alternatively, the terminal device 10 transmits the information acquired by the acquisition unit 194 to the first server 20 at a predetermined timing (for example, at a predetermined interval, or at the timing when the acquisition unit 194 acquires the information). The first acquisition module 2035 acquires the information transmitted from the terminal device 10.
[0054] The second acquisition module 2036 acquires information about the user's attributes within the organization to which the user belongs, based on information about the processes performed by the user. Specifically, for example, in response to the first acquisition module 2035 acquiring information about the processes performed by the user through the operation of the terminal device 10, the second acquisition module 2036 extracts the user's user ID from that information. Then, the second acquisition module 2036 searches the user information table 2024 using the user's user ID and acquires the user's attribute information (for example, job title identification information, department identification information). In this way, the second acquisition module 2036 identifies the user's attributes.
[0055] Furthermore, the second acquisition module 2036 acquires information about the SaaS used by the user based on information about the processes performed by the user. Specifically, for example, in response to the first acquisition module 2035 acquiring information about the processes performed by the user through the operation of the terminal device 10, the second acquisition module 2036 extracts the URL of the web page visited by the user from that information. Then, the second acquisition module 2036 matches the URL of the web page visited by the user against the correspondence table 2021 and obtains the SaaSID of the SaaS used by the user. In this way, the second acquisition module 2036 identifies the SaaS used by the user.
[0056] The Decision Module 2037 determines whether a user has the right to use a SaaS application based on the user's attributes. Specifically, the Decision Module 2037 determines whether a user has the right to use a SaaS application by determining whether the attributes of the user who performed the processing meet the conditions for having the right to use that SaaS application. For example, the Decision Module 2037 obtains information about the user's attributes, such as their job title and department, from the information obtained by the Second Acquisition Module 2036, and obtains the SaaSID of the SaaS application used by the user from the information obtained by the Second Acquisition Module 2036. Then, the Decision Module 2037 refers to the Condition Table 2025 and determines whether the user's attributes, such as their job title and department, meet the conditions stored in the "Condition" field of the record related to the SaaSID of the SaaS application used by the user.
[0057] Furthermore, the decision module 2037 stores the decision result in the decision result table 2026, in accordance with the decision described above.
[0058] The restriction module 2038 restricts the operation of the terminal device 10 based on the decision result of the decision module 2037. In other words, the restriction module 2038 sends instructions to the terminal device 10 regarding restricting the operation of the terminal device 10's processor based on the decision result of the decision module 2037. Specifically, for example, the restriction module 2038 determines whether the decision result stored in the decision result table 2026 satisfies predetermined conditions. These predetermined conditions include, for example, the following: • It was determined that the user did not have the necessary permissions to use the SaaS application. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value.
[0059] The restriction module 2038 imposes a predetermined restriction on the operation of the terminal device 10 if, for example, the judgment result stored in the judgment result table 2026 satisfies at least one of the above conditions, or at least one combination thereof. The predetermined restriction includes, for example, the following:
[0060] (Restrictions on operations on terminal device 10) - Disable any operations on terminal device 10.
[0061] (Prohibition or restriction of access to SaaS resources for which the user is deemed not to have the necessary permissions.) Here, a resource refers to any element available on a network, including, for example, physical or virtual devices such as servers, and various types of data and information such as web pages, files, and databases. Examples of prohibiting or restricting access to resources are shown below. • Prohibit or restrict access to URLs. • Prohibit or restrict access to folders. • Prohibition or restriction of specific operations such as reading and writing.
[0062] (Prohibition of application operation related to SaaS for which the user does not have the necessary permissions) • Prohibit or restrict the execution of applications. • File execution prohibited or restricted • Stopping running applications
[0063] The decision result and the restrictions on the operation of the terminal device 10 are stored, for example, in the restriction table 2023. The restriction module 2038, for example, compares the decision result of the decision module 2037 with the restriction table 2023 to determine the restrictions on the operation of the terminal device 10.
[0064] <1.3 Functional Configuration of the Second Server> Figure 4 shows an example of the functional configuration of the second server 30. As shown in Figure 4, the second server 30 functions as a communication unit 301, a storage unit 302, and a control unit 303.
[0065] The communication unit 301 performs processing to enable the second server 30 to communicate with external devices.
[0066] The storage unit 302 includes, for example, a user information table 3021. The tables stored in the storage unit 302 are not limited to these. For example, tables other than the user information table 3021 may be stored.
[0067] User information table 3021 is, for example, a table that stores information about users of companies that receive services provided by the second server 30.
[0068] The control unit 303 is realized when the processor reads a program stored in the memory unit 302 and executes instructions contained in the program. By operating according to the program, the control unit 303 performs the functions indicated as the receive control module 3031, the transmit control module 3032, and the service provision module 3033.
[0069] The receiving control module 3031 controls the process by which the second server 30 receives signals from an external device in accordance with a communication protocol.
[0070] The transmission control module 3032 controls the process by which the second server 30 transmits signals to an external device according to a communication protocol.
[0071] The service provision module 3033 provides services to, for example, users of a company that receives services provided by the second server 30.
[0072] <2 Data Structure> Figures 5 to 10 show the data structure of the tables stored by the first server 20. Note that Figures 5 to 10 are examples and do not exclude data not shown. Furthermore, even data listed in the same table may be stored in separate memory areas within the storage unit 202.
[0073] Figure 5 shows the data structure of the correspondence table 2021. The correspondence table 2021 is a table that uses SaaSID as the key and has columns such as URL. Note that the correspondence table 2021 may also have columns that store other information.
[0074] The SaaSID is an item that stores an identifier to uniquely identify a SaaS. The URL is an example of information that indicates that the SaaS has been executed. The "URL" item stores, for example, the URL of the homepage that provides the corresponding SaaS.
[0075] Figure 6 shows the data structure of the SaaS table 2022. The SaaS table 2022 is a table with columns such as name, provider, version, and support information, with SaaSID as the key. Note that the SaaS table 2022 may have columns to store other information, or it may not have any of this information.
[0076] The "Name" field stores the name of the SaaS. The "Provider" field stores the entity that provides the SaaS. For example, the "Provider" field stores the name of the company or the address of the website providing the service. The "Version" field stores the version of the SaaS being provided. The "Support Information" field stores information about the support provided for the SaaS.
[0077] Figure 7 shows the data structure of the restriction table 2023. The restriction table 2023 is a table that uses conditions as keys and has columns for correspondence, priority, etc. Note that the restriction table 2023 may also have columns that store information other than these.
[0078] The "Condition" field stores the conditions under which restrictions are placed on the operation of the terminal device 10. For example, the following information may be stored in the "Condition" field: • The SaaS was used by a user who did not have the necessary permissions. • The number of times the same judgment has been made has reached a predetermined value. • The number of times the same judgment was made within a specified period reached a specified value.
[0079] The "Restrictions" item stores the restrictions imposed on the terminal device 10. For example, the following may be stored in the "Restrictions" item: - Disable any operations on terminal device 10. • Prohibition of access to the specified URL • Prohibit execution of specified applications. • Prohibit access to designated folders. • Execution of specified files is prohibited. • Prohibition of specified operations such as reading and writing. • Stopping running applications
[0080] Priority is an item that stores the order of priority when adopting a restriction. For example, priority 1 has a higher priority than priorities 2 and 3, and if multiple conditions are met simultaneously, the restriction with the highest priority will be adopted. Note that if multiple conditions are met simultaneously, multiple restrictions may be adopted.
[0081] Figure 8 shows the data structure of the User Information Table 2024. The User Information Table 2024 is a table that uses User ID as the key and has columns such as User Name, Department, and Job Title. The User Information Table 2024 may also have columns that store other information. For example, the User Information Table 2024 may store information about the user's attributes within the organization to which the user belongs, such as work style, employment type, qualifications, job title, etc., in addition to department and job title.
[0082] The User ID is an item that stores an identifier to uniquely identify a user. The Username stores a string that represents the user's name. The Username can be any string, such as the user's full name or nickname.
[0083] The "Department" field stores information about the department to which a user belongs within the organization they are affiliated with. The department is an example of a user's attributes within that organization. The "Department" field may store strings such as the department's identification information (Department ID) or the department's name. The "Department" field may store multiple values.
[0084] The "Job Title" field stores information about the job title assigned to a user within the organization to which the user belongs. The job title is an example of a user's attributes within the organization. The "Job Title" field may store strings such as job title identification information (job title ID) or job title name. The "Job Title" field may also store information about rank identification information, rank name, grade identification information, and grade name. The "Job Title" field may store multiple values.
[0085] Figure 9 shows the data structure of the Condition Table 2025. The Condition Table 2025 is a table that has columns for the target SaaS, conditions, etc., with the Condition ID as the key. Note that the Condition Table 2025 may also have columns that store other information.
[0086] The condition ID is an item that stores an identifier to uniquely identify a condition.
[0087] The "Target SaaS" field stores information identifying the target SaaS for which usage rights conditions are defined. For example, the SaaSID is stored under "Target SaaS."
[0088] The "Conditions" field stores the conditions under which a user has access to a target SaaS application. Specifically, it stores information about the user's attribute requirements for accessing the target SaaS. For example, it stores conditions related to the user's department, job title, etc. This allows the conditions for accessing each SaaS application to be determined based on the user's attributes within the organization. Therefore, if a user's attributes change in the user information table 2024, the user's access rights to each SaaS application will also change. For example, the "Conditions" field stores a conditional expression indicating a condition such as "Department ID is 001". The "Conditions" field may also store multiple conditional expressions using one or more pieces of identification information. As an example, the "Conditions" field may store a conditional expression indicating a condition such as "Job Title ID is 001, AND Department ID is 002".
[0089] Figure 10 shows the data structure of the Judgment Result Table 2026. The Judgment Result Table 2026 is a table that uses the Judgment Result ID as the key and has columns such as time, detected SaaS, user ID, and judgment result. The Judgment Result Table 2026 may also have columns that store other information.
[0090] The judgment result ID is an item that stores an identifier for uniquely identifying the detection log of the processing related to the terminal device 10 performed by the user.
[0091] The "Time" field stores the time when SaaS usage was detected. For example, the "Time" field stores the timestamp when the detection corresponding to the judgment result ID was performed.
[0092] The "Detected SaaS" field stores information about the detected SaaS that was detected in use during the detection process corresponding to the judgment result ID. Specifically, the "Detected SaaS" field stores the identification information (e.g., SaaSID) of the SaaS used by the user during the user's processing related to the detection process.
[0093] The user ID stored is that of the user who was using the discovery SaaS.
[0094] The "Decision Result" field stores the result of the determination of whether or not the detected user had the necessary permissions to use the detected SaaS during the user's processing. For example, the determination result stores "1" if the user had the necessary permissions, and "0" if the user did not.
[0095] <3 operations> (Authority Determination Process) Figure 11 is a schematic diagram illustrating an example of an authorization determination process in which the first server 20 monitors the terminal device 10 and determines whether the user has the authority to use the SaaS that the terminal device 10 is operating. In Figure 11, when a user operates the terminal device 10 on which the agent application 187 is running and uses a predetermined SaaS, the terminal device 10 detects the process performed by the user and sends information to the first server 20. Based on the acquired information, the first server 20 determines whether the user has the authority to use the SaaS.
[0096] First, the user who will use the terminal device 10 (hereinafter referred to as the user) starts the terminal device 10. The agent application 187 is configured to start automatically, for example, and is started by the OS of the terminal device 10, for example, when the terminal device 10 starts up. When the agent application 187 is started, the control unit 190 may or may not display to the user that the agent application 187 is running so that the user can recognize it. The user operates the terminal device 10 and performs the tasks assigned to the user, for example, using a predetermined SaaS.
[0097] In step S11, the control unit 190 acquires information about the processes performed by the user. Specifically, for example, the acquisition unit 194 accesses the browser log file at predetermined intervals and acquires the URLs of the web pages visited by the user during that period. The date and time on which the URL is acquired may be the date and time on which the user visited the web page related to the URL.
[0098] The control unit 190 transmits information regarding the processing performed by the user. Specifically, for example, the transmitting / receiving unit 192 transmits to the first server 20 the user ID of the user who performed the processing, the URL obtained by the acquisition unit 194, and the date and time on which the URL was obtained.
[0099] In step S12, the control unit 203 of the first server 20 obtains information about the SaaS used by the user based on information about the processing performed by the user. Specifically, the first acquisition module 2035 obtains the user ID of the user who performed the processing, the URL acquired by the acquisition unit 194, and the date and time the URL was acquired from the information received from the terminal device 10.
[0100] In step S13, the control unit 203 obtains information about the SaaS used by the user in the process executed by the user. Specifically, for example, the second acquisition module 2036 matches the URL obtained in step S13 with the correspondence table 2021 and obtains the SaaSID of the SaaS used by the user.
[0101] Furthermore, the second acquisition module 2036 acquires information about the user's attributes within the organization to which the user who performed the processing belongs. Specifically, for example, the attribute acquisition module 2039 matches the user ID acquired in step S12 with the user information table 2024 to obtain the user's department ID and job title ID.
[0102] In step S14, the control unit 203 obtains predetermined information regarding the user's access rights for the SaaS used by the user. Specifically, for example, the decision module 2037 searches the condition table 2025 for the item "Target SaaS" based on the obtained SaaSID and obtains information for the item "Conditions" to obtain information regarding the conditions for having access rights to use the SaaS.
[0103] The control unit 203 determines whether the user has the necessary permissions to use the SaaS that the user has used. Specifically, for example, the determination module 2037 determines whether the user's job title ID and department ID satisfy the conditions stored in the "Conditions" field of the SaaSID record of the SaaS used by the user in the condition table 2025.
[0104] The control unit 203 stores the decision result in the storage unit 202. Specifically, for example, the decision module 2037 stores the date and time the URL was obtained in the "Time" field of the decision result table 2026, the SaaSID of the SaaS used by the user in the "Detected SaaS" field, the user ID of the user in the "User ID" field, and the decision result in the "Decision Result" field. For example, the "Decision Result" field stores "0" if it is determined that the user does not have the right to use the service, and "1" if it is determined that the user has the right to use the service.
[0105] In step S15, the control unit 203 determines whether or not to restrict the operation of the terminal device 10. Specifically, for example, the restriction module 2038 determines whether the determination result in step S14 satisfies predetermined conditions. If the determination result satisfies the predetermined conditions, the restriction module 2038 moves the process to step S16. If the determination result does not satisfy the predetermined conditions, the restriction module 2038 terminates the process.
[0106] In step S16, the control unit 203 transmits information to the terminal device 10 regarding instructions to impose predetermined restrictions on the operation of the terminal device 10. Specifically, for example, the restriction module 2038 compares the determination result in step S14 with the restriction table 2023 to determine the restrictions on the operation of the terminal device 10, and transmits information to the terminal device 10 regarding instructions to impose the determined restrictions.
[0107] More specifically, for example, if the number of times a user has used a SaaS without authorization reaches N, the restriction module 2038 will prohibit the terminal device 10 from accessing the URL of the webpage providing the SaaS (the URL of the webpage visited by the user through their browser, obtained in step S11). Also, for example, if the number of times a user has used a SaaS without authorization reaches N within a predetermined period, the restriction module 2038 will prohibit the terminal device 10 from accessing the URL of the webpage providing the SaaS.
[0108] Furthermore, the control unit 203 presents the results of the decision made by the decision module 2037 to the user. Specifically, the presentation control module 2033 transmits information to the terminal device 10 indicating at least one of the following regarding the detected SaaS: that the user does not have permission to use it, and that the operation of the terminal device 10 has been restricted. As a result, the presentation control module 2033 presents or notifies the user via the terminal device 10 that at least one of the following is true regarding the detected SaaS: that the user does not have permission to use it, and that the operation of the terminal device 10 has been restricted.
[0109] In step S17, the control unit 190 restricts the operation of the terminal device 10 based on the information received from the first server 20. Specifically, for example, the terminal device 10 stores the URL of the web page providing the restricted SaaS or the domain included in that URL in the storage unit 180, and prohibits the terminal device 10 from accessing the web page corresponding to that URL or domain.
[0110] In step S18, the presentation control unit 193 presents or notifies the user of the result of the determination. The presentation control unit 193 presents or notifies the user that they do not have the right to use the SaaS that was detected, and that the operation of the terminal device 10 has been restricted.
[0111] Figure 12 is a schematic diagram showing an example of the display screen of the terminal device 10's display 141. Figure 12 shows an example where access to the web page providing a SaaS is prohibited due to the use of a SaaS for which the user does not have the necessary permissions. In the screen shown in Figure 12, a first area 1411 is displayed to notify the user that access to the SaaS provision page for which the user does not have the necessary permissions has been prohibited.
[0112] Furthermore, the control unit 203 may present or notify the administrator user of the results of the judgment made by the judgment module 2037. Specifically, the control unit 203 may present or notify the administrator user that the user does not have the right to use the SaaS that was detected to be used by that user, and that the operation of the terminal device 10 has been restricted. An administrator user is, for example, a terminal management user who manages the terminal device 10 (such as a user in the information systems department), or an employee management user who manages users who use the terminal device 10 to access the SaaS (such as a department head or a user in the human resources department). For example, the control unit 203 may transmit information to terminals owned by administrator users, thereby presenting or notifying the administrator user via each terminal that the user does not have the right to use the SaaS that was detected to be used by that user, and that the operation of the terminal device 10 has been restricted.
[0113] (summary) As described above, in the above embodiment, the first acquisition module 2035 acquires information about the processing performed by the terminal device when the user operates the terminal device. Based on the acquired information about the processing, the second acquisition module 2036 acquires information about the user's attributes in the organization to which the user belongs, and information about the service related to the processing. Based on the information about the attributes and the information about the service related to the processing, the determination module 2037 determines whether or not the user has the right to use the service. This allows determining whether a user has the right to use the service based on their attributes, thus eliminating the need to individually grant or revoke access rights for each user. Therefore, according to the above embodiment, it is possible to easily manage the access rights of users within an organization.
[0114] Furthermore, in the above embodiment, the presentation control module 2033 presents the result of the decision to the user via a terminal device. This allows the user to be informed whether or not they have the right to use the service they used. Therefore, it is possible to restrict the user's use of the service in the future.
[0115] Furthermore, in the above embodiment, the presentation control module 2033 presents the result of the decision to an administrator user who manages at least one of the user and the user's terminal device, via the administrator user's terminal device. This allows the administrator user to perform a predetermined action on the user or the user's terminal in response to the presentation of the information. Therefore, the administrator user can quickly respond to users who use services without the necessary access rights.
[0116] Furthermore, in the above embodiment, if it is determined that a user does not have the right to use the service, the restriction module 2038 restricts the user's terminal from accessing resources related to the service. This makes it possible to restrict the use of the service by a user who does not have the right to use it. Therefore, the risk of data leakage and other incidents caused by unauthorized users using the service can be reduced.
[0117] Furthermore, in the above embodiment, if it is determined that a user does not have the right to use the service, the restriction module 2038 restricts the operation of the application related to the service on the user's terminal. This makes it possible to restrict the use of the service by a user who does not have the right to use it. Therefore, the risk of data leakage and other incidents caused by a user using the service without the right to use it can be reduced.
[0118] Furthermore, in the above embodiment, the control unit 203 acquires information regarding the attributes of a predetermined user within the organization to which the predetermined user belongs, acquires information regarding services for which the predetermined user has access rights based on the information regarding the predetermined user's attributes, and presents the acquired information regarding services for which the specific user has access rights to at least one of the predetermined user and the predetermined user's terminal device to the administrator user via the administrator user's terminal device. This makes it possible to efficiently identify the SaaS for which a predetermined user has access rights.
[0119] Furthermore, in the above embodiment, the control unit 203 acquires information regarding changes in the attributes of a predetermined user, acquires information regarding changes in the user's access rights resulting from the attribute changes, and presents the acquired information regarding changes in the user's access rights to the administrator user via the administrator user's terminal device. This allows the administrator user to efficiently understand which SaaS applications should be installed or removed from their terminal due to the addition or removal of access rights resulting from the attribute changes.
[0120] <Variation> In the above embodiment, when the operation of the terminal device 10 is restricted because the user does not have the right to use the SaaS, an example of informing the user of the restriction, as shown in Figure 13, was described. However, the information presented to the user is not limited to the fact that the operation of the terminal device 10 has been restricted. The presentation control unit 193 may also present to the user that the user does not have the right to use the SaaS.
[0121] Furthermore, in the above embodiment, the case where browser usage history is used as information regarding the process performed by the user was explained as an example. However, the application name and process name of the application executed by the user may also be used as information regarding the process performed by the user. In this case, for example, the correspondence table 2021 associates the SaaS with the application name and process name of the application executed by the user. The second acquisition module 2036 matches the acquired application name and process name with the correspondence table 2021 to obtain the SaaSID of the SaaS used by the user. As a result, the second acquisition module 2036 identifies the SaaS used by the user.
[0122] Furthermore, although the above embodiment describes the case of monitoring the use of SaaS as an example, the use of applications by the terminal device 10 may also be monitored. In this case, the first server 20 stores, for example, a table in the correspondence table 2021 that stores the application name, process name, etc., and the SaaSID. The agent application 187 of the terminal device 10 sends information about execution events of applications, processes, etc. by the terminal device 10 to the first server 20. The decision module 2037 of the first server 20 compares the information obtained from the terminal device 10 with the table and determines whether the user has the right to use the application used by the user.
[0123] (Decision on granting authority) In the above embodiment, if the user did not have the right to use the SaaS, a predetermined restriction was imposed on the terminal device 10. In addition to this, or instead, the control unit 203 may determine whether or not to grant the user the right to use the SaaS.
[0124] Specifically, the control unit 203 may determine whether or not to grant access rights based on the number of times or frequency of use of the SaaS. For example, after step S14 of the access determination process, the control unit 203 may refer to the determination result table 2026 to obtain the number of times the user has used the SaaS or the frequency of use over a specific period. If the number of uses or frequency of use exceeds a predetermined threshold, the control unit 203 may present the administrator user with information regarding the user's frequency of SaaS use, information suggesting that the user be granted access rights to the SaaS, etc.
[0125] Alternatively, the control unit 203 may display a button on the terminal device 10's display 141 for requesting permission to use the SaaS. In response to the user pressing the button, the first server 20 may present information to the administrator user indicating that the user has requested permission to use the SaaS.
[0126] (Presentation of SaaS for which you have usage rights) The control unit 203 may present information regarding SaaS applications for which a given user has access rights to a user, such as an administrator user.
[0127] For example, in response to instructions from an administrator user's terminal, or when a new record is added to the user information table 2024, the control unit 203 retrieves information about the user's attributes stored in a predetermined record (the record in response to the instruction, or the newly added record). Based on the retrieved attribute information, the control unit 203 searches the condition table 2025 to obtain a list of SaaSIDs for records that satisfy the conditions. Then, based on the retrieved SaaSIDs, the control unit 203 searches the SaaS table 2022 to obtain information about the SaaS for which the user related to that record has usage rights. The control unit 203 may present the retrieved information to the administrator user. This allows the administrator user to efficiently understand which SaaS a given user has usage rights for (SaaS that should be installed on the given user's terminal). In particular, when a new user joins the organization, the administrator user can efficiently understand which SaaS a new user has usage rights for (SaaS that should be installed on the new user's terminal).
[0128] Furthermore, the control unit 203 may, based on the acquired information, install SaaS applications that the new user has access to on the terminal, or issue a SaaS user ID. The installation of SaaS applications and the issuance of IDs can be achieved using any SaaS management technology.
[0129] Furthermore, for example, the control unit 203 may obtain information regarding changes to a user's attributes in a predetermined record of the user information table 2024. The control unit 203 may search the condition table 2025 based on the user's attribute information for both the attribute before and after the change, and by comparing the search results before and after the attribute change, obtain the SaaSID of the SaaS whose usage rights have been changed (permissions have been added or removed) due to the change in the user's attributes. The control unit 203 may then search the SaaS table 2022 based on the obtained SaaSID and obtain information regarding the SaaS whose usage rights have been changed due to the change in the user's attributes. The control unit 203 may present the obtained information to the administrator user. This allows the administrator user to efficiently understand which SaaS should be installed or removed from the terminal due to the addition or removal of usage rights resulting from the change in attributes when a user's attributes change due to a transfer or promotion.
[0130] Furthermore, based on the acquired information, the control unit 203 may install the SaaS on the terminal for which usage rights have been added due to the attribute change, or issue a SaaS user ID. The control unit 203 may also uninstall the SaaS from the terminal for which usage rights have been removed due to the attribute change, or delete the SaaS user ID. The installation, uninstallation, issuance, and deletion of SaaS IDs can be achieved using any SaaS management technology.
[0131] (Identifying your account plan) Regardless of whether users have permission to use the SaaS, they may be performing their work by using a free plan with limited functionality. The fact that the SaaS is being used even with limited functionality suggests that formally introducing a paid plan within the user's organization would improve their work efficiency. Therefore, identifying the SaaS plan that users are using is useful for improving work efficiency within the organization.
[0132] Therefore, the control unit 203 may identify the account plan that the user is using in the SaaS related to the user's processing. For example, the control unit 203 may identify the account plan in the authorization determination process in the above embodiment. As an example, in step S15, the control unit 203 may identify the account plan that the user is using in the SaaS, whether it is determined that the user does not have the right to use the SaaS, whether it is determined that the user has the right to use the SaaS, or regardless of the result of the determination of whether or not the user has the right to use the SaaS.
[0133] For example, the control unit 203 may identify the account plan that the user is using in the SaaS related to the user's processing, as shown below.
[0134] (Judgment based on the presence or absence of advertisements) Some SaaS services offer a free plan that displays advertisements, but allow users to remove them by subscribing to a paid plan. Therefore, the control unit 203 determines whether the user is using a free plan or a paid plan by checking whether or not advertisements are present on the SaaS-related webpage.
[0135] For example, the control unit 203 obtains the source code of the web page corresponding to the URL received from the terminal device 10 and determines whether or not there is advertising content on that web page. If the presence of advertising content is detected, the control unit 203 determines that the web page corresponding to the URL accessed by the user is a web page for the free plan, and that the user was using the free plan for the SaaS. On the other hand, if the presence of advertising content is not detected, it determines that the user was using a paid plan for the SaaS.
[0136] For example, the control unit 203 determines the presence or absence of advertising content on a web page by detecting predetermined elements that are likely to be related to advertising content. Examples of predetermined elements are shown below. • Words related to advertising (e.g., "advertisement," "sponsor," "promotion," "commercial," etc.). For example, these may be included in text or comments. • Strings related to advertising ("ad", "advertisement", "sponsored", "promotion", "commercial", etc., and strings that abbreviate these strings). For example, these may be included in strings related to external resources in source code or in strings indicating class names. • Other strings that specify, in advance by administrators or other users, the destination (URL, domain, etc.) for accessing external resources related to advertising.
[0137] The control unit 203 may also input the body text or source code of a webpage related to a URL received from the terminal device 10 into a trained model constructed by machine learning, causing the trained model to output a result indicating whether or not advertising content is present on the webpage. The trained model may be constructed, for example, by performing machine learning using the source code of a webpage that actually contains advertising content as training data.
[0138] Furthermore, the control unit 203 may input a prompt to any artificial intelligence system that includes the body text or source code of the web page related to the URL received from the terminal device 10, and an instruction to determine whether or not there is advertising content on the web page, thereby causing the system to output a result of determining whether or not there is advertising content on the web page. Examples of artificial intelligence systems include ChatGPT, Google Bard, Bing AI, etc.
[0139] (Determination based on the number of times used) Some SaaS services offer free plans with usage limits, but these limits are removed with a paid plan. Therefore, the control unit 203 determines whether the user was using a free or paid plan based on the number of times the user used the SaaS.
[0140] For example, the control unit 203 determines that the plan the user was using was a free plan in at least one of the cases illustrated below. The control unit 203 can also determine the number of times a user has used a given SaaS during a given period or cycle by referring to the "Time," "Detected SaaS," and "User ID" items in the determination result table 2026, for example. - If the total number of times a user uses the service during a specified period exceeds a specified number, and the number of uses after the specified period has elapsed, it will be determined that the user has exceeded the number of free uses and has therefore ceased further use. • If the number of times a user uses the service within a predetermined period is less than or equal to the predetermined number. In this case, since the free plan has a limit on the number of uses within a predetermined period (e.g., 1 day), it is determined that the user cannot use the service beyond the predetermined number of times.
[0141] The control unit 203 may present the administrator user with the results of identifying the account plan used by the user in the SaaS related to the user's processing. This allows the administrator user to understand that the user is using the free plan of a given SaaS. Therefore, the administrator user can consider introducing a paid plan of the SaaS to the user. Thus, the consideration of introducing a paid plan of the SaaS can be carried out efficiently.
[0142] The control unit 203 may also present the user with the results of the account plan identification.
[0143] Furthermore, the control unit 203 may aggregate the results for each type of SaaS (for example, each SaaSID) and present the aggregated results to the administrator user. This allows the administrator user to understand, for example, the total number of users using the free plan for a given SaaS and the total number of uses. Therefore, they can efficiently consider introducing a paid plan for that SaaS.
[0144] Furthermore, the control unit 203 may receive information from the terminal device 10 regarding a request to introduce a paid plan in the SaaS related to the user's processing. Specifically, for example, the control unit 203 may display a request button for introducing a paid plan in the SaaS on the display 141 of the terminal device 10. In this case, when the user presses the request button, the terminal device 10 sends information regarding the request to introduce a paid plan to the first server 20. The control unit 203 may also present the request to the administrator user via the administrator user's terminal. This allows the administrator user to understand that the user wishes to introduce a paid plan. Therefore, the consideration of introducing a paid plan for the SaaS can be carried out efficiently.
[0145] Furthermore, the control unit 203 may aggregate requests for the introduction of paid plans in SaaS related to user processing, categorized by SaaS type (for example, by SaaSID), and present the aggregated results to the administrator user. This allows the administrator user to understand the need to introduce paid plans for the SaaS within their organization. Therefore, the administrator user can efficiently consider introducing paid plans for SaaS within their organization.
[0146] <4. Basic Hardware Configuration of a Computer> Figure 13 is a block diagram showing the basic hardware configuration of computer 90. Computer 90 includes at least a processor 91, main memory 92, auxiliary memory 93, and a communication interface 99. These are electrically connected to each other by a bus.
[0147] The processor 91 is hardware for executing the instruction set written in the program. The processor 91 consists of an arithmetic unit, registers, peripheral circuits, etc.
[0148] Main memory 92 is used to temporarily store programs and data processed by programs, etc. For example, it is a volatile memory such as DRAM (Dynamic Random Access Memory).
[0149] Auxiliary storage device 93 is a storage device for storing data and programs. Examples include flash memory, HDD (Hard Disc Drive), magneto-optical disk, CD-ROM, DVD-ROM, semiconductor memory, etc.
[0150] A communication IF99 is an interface for inputting and outputting signals for communication with other computers via a network using wired or wireless communication standards. A network consists of various mobile communication systems, such as the internet, LANs, and wireless base stations. For example, a network includes 3G, 4G, and 5G mobile communication systems, LTE (Long Term Evolution), and wireless networks that can connect to the internet via designated access points (e.g., Wi-Fi®). When connecting wirelessly, communication protocols include, for example, Z-Wave®, ZigBee®, and Bluetooth®. When connecting via a wired connection, the network also includes connections made directly via USB (Universal Serial Bus) cables, etc.
[0151] Furthermore, by distributing all or part of each hardware configuration across multiple computers 90 and connecting them to each other via a network, a computer 90 can be virtually realized. Thus, the concept of computer 90 includes not only a computer 90 housed in a single enclosure or case, but also a virtualized computer system.
[0152] <Basic Functional Configuration of Computer 90> The functional configuration of the computer realized by the basic hardware configuration of computer 90 shown in Figure 13 will be explained. The computer comprises at least one functional unit: a control unit, a memory unit, and a communication unit.
[0153] Furthermore, the functional units of computer 90 can also be realized by distributing all or part of each functional unit across multiple computers 90 interconnected via a network. The concept of computer 90 includes not only a single computer 90 but also a virtualized computer system.
[0154] The control unit is realized when the processor 91 reads various programs stored in the auxiliary storage device 93, loads them into the main memory device 92, and executes processing according to those programs. The control unit can realize various functional units that perform information processing depending on the type of program. In this way, the computer is realized as an information processing device that performs information processing.
[0155] The memory unit is implemented by a main memory 92 and an auxiliary memory 93. The memory unit stores data, various programs, and various databases. The processor 91 can also reserve memory areas corresponding to the memory unit in the main memory 92 or the auxiliary memory 93 according to the program. The control unit can also cause the processor 91 to perform operations such as adding, updating, and deleting data stored in the memory unit according to the various programs.
[0156] A database, specifically a relational database, is used to manage and link data sets called tables, which are structurally defined by rows and columns. In a database, tables are called tables, the columns of a table are called columns, and the rows of a table are called records. In a relational database, relationships can be established and linked between tables. Typically, each table has a key column to uniquely identify records, but setting a key on a column is not mandatory. The control unit can instruct the processor 91 to add, delete, or update records in specific tables stored in the memory unit according to various programs.
[0157] The communication unit is implemented by the communication IF99. The communication unit implements the function of communicating with other computers 90 via the network. The communication unit can receive information transmitted from other computers 90 and input it to the control unit. The control unit can cause the processor 91 to perform information processing on the received information according to various programs. The communication unit can also transmit information output from the control unit to other computers 90.
[0158] The functions realized by the components described herein may be implemented in a circuitry or processing circuitry, including general-purpose processors, application-specific processors, integrated circuits, ASICs (Application Specific Integrated Circuits), CPUs (a Central Processing Unit), conventional circuits, and / or combinations thereof, programmed to realize the functions described herein. A processor includes transistors and other circuits and is considered a circuitry or processing circuitry. A processor may be a programmed processor that executes a program stored in memory. In this specification, circuitry, unit, and means are hardware programmed to perform or execute the functions described herein. Such hardware may be any hardware disclosed herein, or any hardware known to be programmed to perform or execute the functions described herein. If the hardware is a processor that is considered to be a type of circuitry, then the circuitry, means, or unit is a combination of hardware and software used to constitute the hardware and / or processor.
[0159] While several embodiments of this disclosure have been described above, these embodiments can be implemented in a variety of other forms, and various omissions, substitutions, and modifications are permitted without departing from the spirit of the invention. These embodiments and their variations are included in the scope and spirit of the invention, as well as in the claims and their equivalents.
[0160] <Note> The details described in each of the above embodiments are noted below. (Note 1) A program for execution on a computer having a processor and memory, the program causing the processor to perform the following steps: acquiring information about a process performed by a terminal device, which is executed when a user operates the terminal device; acquiring information about the user's attributes in the organization to which the user belongs and information about the service related to the process, based on the acquired information about the process; and determining whether the user has the right to use the service, based on the information about the attributes and the information about the service related to the process. (Note 2) The program is the program described in Appendix 1, which causes the processor to perform a step of presenting the result of the decision to the user via a terminal device. (Note 3) The program described in Appendix 1, which causes the processor to perform a step of presenting the result of the decision to an administrator user who manages at least one of the user and the user's terminal device, via the administrator user's terminal device. (Note 4) The program, as described in Appendix 1, causes the processor to perform a step of restricting the user's terminal's access to resources related to the service if, in the decision-making step, it is determined that the user does not have the right to use the service. (Note 5) The program, as described in Appendix 1, causes the processor to execute a step that restricts the operation of applications related to the service on the user's terminal if, in the decision-making step, it is determined that the user does not have the right to use the service. (Note 6) The program is the program described in Appendix 1, which causes the processor to perform the steps of: obtaining information about the attributes of a given user in an organization to which a given user belongs; obtaining information about services on which a given user has the right to use based on the information about the attributes of the given user; and presenting the obtained information about services on which a specific user has the right to use to an administrator user who manages at least one of the given user and the given user's terminal device, via the administrator user's terminal device. (Note 7) The program is the program described in Appendix 6, which causes the processor to perform the steps of: obtaining information regarding changes in the attributes of a given user; obtaining information regarding changes in the user's access rights resulting from the changes in the attributes; and presenting the obtained information regarding changes in the user's access rights to an administrator user via the administrator user's terminal device. (Note 8) A method performed by a computer equipped with a processor, the method comprising: the step of obtaining information relating to a process performed by a user operating a terminal device; the step of obtaining information relating to the user's attributes in the organization to which the user belongs and information relating to the service related to the process, based on the obtained information relating to the process; and the step of determining whether the user has the right to use the service, based on the information relating to the attributes and information relating to the service related to the process. (Note 9) An information processing device comprising a control unit, wherein the control unit performs the following steps: acquiring information about a process performed by a terminal device, which is executed when a user operates a terminal device; acquiring information about the user's attributes in the organization to which the user belongs and information about the service related to the process, based on the acquired information about the process; and determining whether the user has the right to use the service, based on the information about the attributes and the information about the service related to the process. (Note 10) A system comprising a control unit and a storage unit, comprising the steps of: acquiring information regarding a process performed by a terminal device when a user operates a terminal device; acquiring information regarding the user's attributes within the organization to which the user belongs and information regarding the service related to the process, based on the acquired information regarding the process; and determining whether the user has the right to use the service, based on the information regarding the attributes and the information regarding the service related to the process. [Explanation of Symbols]
[0161] 1... System 10…Terminal device 120... Communications Department 13…Input device 131…Touch-sensitive devices 14…Output device 15…Memory 16…Storage 19… Processor 20… Server 1 22...Communication IF 23…Input / Output Interface 25…Memory 2 hours… storage 29… Processor 30…Second Server
Claims
1. A program to be executed by a computer having a processor and memory, wherein the program is to be executed by the processor, The steps include obtaining information about a process performed by the terminal device, which is an access to a specific URL or the launch of a specific application, performed by the user operating the terminal device, Based on the information obtained regarding the aforementioned processing, the steps include obtaining information regarding the user's attributes within the organization to which the user belongs, and information regarding predetermined terms of use for the service related to the aforementioned processing, A program that performs the step of determining whether the user has the right to use the service based on the attribute information and the terms of use information, The information relating to the aforementioned process is the user's browser usage history, or the application name or process name of the application executed by the user. A program that, in the step of acquiring information about the aforementioned process, acquires information about the aforementioned process at a predetermined interval.
2. The program is provided to the processor: The program according to claim 1, which causes the program to perform the step of presenting the result of the above determination to the user via the terminal device.
3. The program is provided to the processor: The program according to claim 1, which causes the administrator user who manages at least one of the user and the user's terminal device to perform the step of presenting the result of the above determination to the administrator user via the administrator user's terminal device.
4. The program is provided to the processor: The program according to claim 1, which, if it is determined in the aforementioned determination step that the user does not have the right to use the service, causes the program to perform a step of restricting the user's terminal's access to resources related to the service.
5. The program is provided to the processor: The program according to claim 1, which, if it is determined in the aforementioned determination step that the user does not have the right to use the service, causes the program to execute a step of restricting the operation of an application related to the service on the user's terminal.
6. The program is provided to the processor: The steps include obtaining information about the attributes of a specified user within the organization to which the specified user belongs, The steps include obtaining information about services that the predetermined user has access to, based on the information about the attributes of the predetermined user, The program according to claim 1, which causes the program to perform the step of presenting information obtained about services for which the predetermined user has usage rights to a designated user to an administrator user who manages at least one of the designated user and the terminal device of the designated user, via the terminal device of the administrator user.
7. The program is provided to the processor: The steps include obtaining information regarding changes in the attributes of the aforementioned predetermined user, The steps include: obtaining information regarding the change in the user rights of the predetermined user resulting from the change in the attribute; The program according to claim 6, which causes the program to perform the step of presenting to the administrator user, via the administrator user's terminal device, the acquired information regarding the change of the user's access rights.
8. A method performed by a computer having a processor, wherein the processor The steps include obtaining information about a process performed by the terminal device, which is an access to a specific URL or the launch of a specific application, performed by the user operating the terminal device, Based on the information obtained regarding the aforementioned processing, the steps include obtaining information regarding the user's attributes within the organization to which the user belongs, and information regarding predetermined terms of use for the service related to the aforementioned processing, A method for performing the steps of determining whether the user has the right to use the service based on the information relating to the attribute and the information relating to the terms of use, The information relating to the aforementioned process is the user's browser usage history, or the application name or process name of the application executed by the user. A method for acquiring information about the aforementioned process, wherein the information about the aforementioned process is acquired at a predetermined interval.
9. An information processing apparatus comprising a control unit, wherein the control unit is The steps include obtaining information about a process performed by the terminal device, which is an access to a specific URL or the launch of a specific application, performed by the user operating the terminal device, Based on the information obtained regarding the aforementioned processing, the steps include obtaining information regarding the user's attributes within the organization to which the user belongs, and information regarding predetermined terms of use for the service related to the aforementioned processing, An information processing device that performs the step of determining whether the user has the right to use the service based on the attribute information and the usage conditions information, The information relating to the aforementioned process is the user's browser usage history, or the application name or process name of the application executed by the user. An information processing device that, in the step of acquiring information related to the said process, acquires information related to the said process at a predetermined interval.
10. A system comprising a control unit and a storage unit, The steps include obtaining information about a process performed by the terminal device, which is an access to a specific URL or the launch of a specific application, performed by the user operating the terminal device, Based on the information obtained regarding the aforementioned processing, the steps include obtaining information regarding the user's attributes within the organization to which the user belongs, and information regarding predetermined terms of use for the service related to the aforementioned processing, A system comprising the step of determining whether the user has the right to use the service based on the attribute information and the usage conditions information, The information relating to the aforementioned process is the user's browser usage history, or the application name or process name of the application executed by the user. A system that, in the step of acquiring information about the aforementioned process, acquires information about the aforementioned process at a predetermined interval.
Citation Information
Patent Citations
Security gateway and identity verification method
CN117439805A
Communication device and voice recognition terminal device with communication device
JP2020004192A
Information processing system
JP2023054869A
Business card management system
JP2023181838A
Authentication system, authentication server, authentication method, and authentication program
WO2013042306A1