Apparatus management device, apparatus management method, and apparatus management program
Patent Information
- Application Number
- PCT/JP2024/037684
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-07
- Filing Date
- 2024-10-23
- Publication Date
- 2025-10-02
AI Technical Summary
Existing network security technologies face challenges in achieving superior security functionality, particularly in managing devices across multiple groups, where common authentication information increases the risk of unauthorized access and resource misuse, and individual authentication information raises manufacturing and registration costs.
A device management system that utilizes first, second, and third authentication information to determine device legitimacy, granting authority based on group membership, and includes a communication unit, determination unit, and authority setting unit to manage access rights, reducing the impact of authentication information leaks.
Enhances network security by accurately identifying legitimate devices and granting appropriate access rights, minimizing unauthorized access, and reducing manufacturing costs through common authentication information usage.
Smart Images

Figure JP2024037684_02102025_PF_FP_ABST
Abstract
Description
Equipment management device, equipment management method, and equipment management program
[0001] This application claims priority from Japanese Patent Application No. 2024-034483, filed March 7, 2024, the disclosure of which is incorporated herein by reference in its entirety.
[0002] Conventionally, techniques for improving security in networks have been developed. For example, Patent Document 1 (JP 2014-174560 A) discloses the following technique. An information processing device is an information processing device that accesses a server via a network, and includes: a transmitting means that transmits a certificate issuance request including information unique to the information processing device to a certification authority; a receiving means that receives the certificate transmitted from the certification authority in response to the issuance request; a determining means that, when connecting to a server, compares the information unique to the information processing device with the unique information included in the certificate to determine whether the information processing device can access the server; and a prohibiting means that, when the determining means determines that the server cannot be accessed, prohibits issuance of a connection request to the server.
[0003] JP 2014-174560 A JP 2020-187746 A
[0004] The device management device disclosed herein is a device management device used in a system in which there are multiple groups each containing multiple devices, and includes: a communication unit that receives first authentication information that is common to two or more of the groups and second authentication information that is unique to each of the multiple groups from a source device that is the device that sent the first authentication information and the second authentication information; a judgment unit that determines whether the source device is a legitimate device based on the first authentication information and the second authentication information received by the communication unit; and an authority setting unit that performs authority setting processing to grant the source device the authority to operate on specified resources if the judgment unit determines that the source device is a legitimate device.
[0005] One aspect of the present disclosure can be achieved not only as an equipment management device equipped with such a characteristic processing unit, but also as a semiconductor integrated circuit that achieves part or all of the equipment management device, or as a system that includes the equipment management device.
[0006] FIG. 1 is a diagram illustrating an example of a configuration of a communication system according to an embodiment of the present disclosure. FIG. 2 is a diagram illustrating an example of common authentication information stored in a device according to an embodiment of the present disclosure. FIG. 3 is a diagram illustrating an example of provider authentication information and device authentication information stored in a device according to an embodiment of the present disclosure. FIG. 4 is a diagram illustrating an example of a configuration of a device management device according to an embodiment of the present disclosure. FIG. 5 is a diagram illustrating an example of a correspondence table stored in a device management device according to an embodiment of the present disclosure. FIG. 6 is a diagram illustrating an example of an authentication list stored in a device management device according to an embodiment of the present disclosure. FIG. 7 is a diagram illustrating an example of a determination process performed by a device management device according to an embodiment of the present disclosure. FIG. 8 is a diagram illustrating access authority granted to a device by a device management device according to an embodiment of the present disclosure. FIG. 9 is a diagram illustrating an example of an authority setting process performed by a device management device according to an embodiment of the present disclosure. FIG. 10 is a diagram illustrating an example of an authentication process performed by a device management device according to an embodiment of the present disclosure. FIG. 11 is a diagram illustrating an example of an area confirmation process performed by a device management device according to an embodiment of the present disclosure. FIG. 12 is a diagram illustrating an example of a notification process performed by a device management device according to an embodiment of the present disclosure. Fig. 13 is a flowchart defining an example of an operation procedure when a device management device according to an embodiment of the present disclosure performs authority setting processing. Fig. 14 is a flowchart defining an example of an operation procedure when a device management device according to an embodiment of the present disclosure transmits access permission information. Fig. 15 is a diagram illustrating an example of a correspondence table stored in a modified example of a device management device according to an embodiment of the present disclosure. Fig. 16 is a diagram for explaining an example of a determination process by a modified example of a device management device according to an embodiment of the present disclosure. Fig. 17 is a diagram for explaining an example of an authority setting process by a modified example of a device management device according to an embodiment of the present disclosure.
[0007] <Problem to be Solved by the Present Disclosure> There is a demand for a technology that goes beyond the technology described in Patent Document 1 and is capable of achieving superior functionality regarding security in a network.
[0008] The present disclosure has been made to solve the above-mentioned problems, and its purpose is to provide an equipment management device, an equipment management method, and an equipment management program that are capable of achieving excellent security functions in a network.
[0009] <Effects of the Present Disclosure> According to the present disclosure, it is possible to achieve excellent security functions in a network.
[0010] First, the contents of an embodiment of the present disclosure will be listed and described. (1) A device management device according to an embodiment of the present disclosure is a device management device used in a system in which a plurality of groups exist, each including a plurality of devices, and includes: a communication unit that receives first authentication information common to two or more groups and second authentication information unique to each of the plurality of groups from a source device that is the device that transmitted the first authentication information and the second authentication information; a determination unit that determines whether the source device is a legitimate device based on the first authentication information and the second authentication information received by the communication unit; and an authority setting unit that performs authority setting processing to grant the source device authority to operate a predetermined resource when the determination unit determines that the source device is a legitimate device.
[0011] In this way, in addition to the first authentication information, the second authentication information unique to each of the multiple groups to which the device belongs is used to determine whether the sending device is a legitimate device, and authorization is granted to the device determined to be a legitimate device. With this configuration, even if the first authentication information is leaked, for example, the second authentication information can be used to reduce the possibility of an unintended device accessing resources, thereby suppressing attacks by the device. Therefore, excellent security functions can be achieved in the network.
[0012] (2) In the above (1), the authority setting unit may grant the authority corresponding to each of the plurality of groups to the source device in the authority setting process.
[0013] With this configuration, it is possible to give the source device appropriate authority according to the group to which the device belongs.
[0014] (3) In (1) or (2) above, the communication unit may further receive third authentication information unique to each of the source devices in one of the groups from the devices, and the judgment unit may perform a judgment process to determine whether the source device is a legitimate device based on the first authentication information, the second authentication information, and the third authentication information received by the communication unit.
[0015] In this way, by performing the judgment process using the third authentication information specific to the device in addition to the first authentication information and second authentication information, the accuracy of determining whether the device is legitimate can be improved.
[0016] (4) In the above (3), the judgment unit may further acquire an authentication list showing the third authentication information received by the communication unit corresponding to each of the multiple groups, and the judgment unit may determine that the sending device is not a legitimate device if the third authentication information received by the communication unit is registered in the acquired authentication list during the judgment process.
[0017] With this configuration, it is possible to easily and reliably determine whether the source device is an authorized device by using the authentication list.
[0018] (5) In the above (3) or (4), the device management device may further include a notification unit that performs a predetermined notification process when the first authentication information, the second authentication information, and the third authentication information received by the communication unit are the same as the first authentication information, the second authentication information, and the third authentication information that the communication unit has already received from another device, respectively.
[0019] With this configuration, it is possible to detect an attack such as unauthorized access to the device management device by an unauthorized device masquerading as the source device, and to take measures against the attack.
[0020] (6) In the above (1) or (2), the communication unit may further receive third authentication information unique to each of the source devices in one of the groups, and the judgment unit may judge whether the source device is a legitimate device based on at least the first authentication information and the second authentication information out of the first authentication information, the second authentication information, and the third authentication information received by the communication unit, and the authority setting unit may perform the authority setting process for each of the source devices based on at least the third authentication information.
[0021] With this configuration, for each source device that is determined to be a legitimate device, it is possible to suppress adverse effects such as unauthorized access to resources by an unauthorized device masquerading as the source device.
[0022] (7) A device management method according to an embodiment of the present disclosure is a device management method in a device management device used in a system in which there are multiple groups, each containing multiple devices, and includes the steps of receiving first authentication information that is common to two or more of the groups and second authentication information that is unique to each of the multiple groups from a source device that is the device that sent the first authentication information and the second authentication information; determining whether the source device is a legitimate device based on the received first authentication information and second authentication information; and performing an authority setting process to grant the source device authority to operate on a specified resource if it is determined that the source device is a legitimate device.
[0023] In this way, in addition to the first authentication information, the second authentication information unique to each of the multiple groups to which the device belongs is used to determine whether the sending device is a legitimate device, and authorization is granted to the device determined to be a legitimate device. With this method, even if the first authentication information is leaked, for example, the second authentication information can be used to reduce the possibility of an unintended device accessing resources, thereby suppressing attacks by the device. Therefore, excellent security functions can be achieved in the network.
[0024] (8) A device management program according to an embodiment of the present disclosure is a device management program used in a device management device used in a system in which there are multiple groups, each containing multiple devices, and causes a computer to function as: a communication unit that receives first authentication information common to two or more groups and second authentication information unique to each of the multiple groups from a source device that is the device that sent the first authentication information and the second authentication information; a judgment unit that determines whether the source device is a legitimate device based on the first authentication information and the second authentication information received by the communication unit; and an authority setting unit that performs authority setting processing to grant the source device the authority to operate on specified resources if the judgment unit determines that the source device is a legitimate device.
[0025] In this way, in addition to the first authentication information, the second authentication information unique to each of the multiple groups to which the device belongs is used to determine whether the sending device is a legitimate device, and authorization is granted to the device determined to be a legitimate device. With this configuration, even if the first authentication information is leaked, for example, the second authentication information can be used to reduce the possibility of an unintended device accessing resources, thereby suppressing attacks by the device. Therefore, excellent security functions can be achieved in the network.
[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In the drawings, the same or corresponding parts are designated by the same reference numerals, and the description thereof will not be repeated. At least some of the embodiments described below may be combined in any manner.
[0027] [Communication System] Fig. 1 is a diagram illustrating an example of the configuration of a communication system according to an embodiment of the present disclosure. Referring to Fig. 1, a communication system 501 includes a device management device 101 and a plurality of devices 201. The device management device 101 and each device 201 transmit and receive information via an external network 151 such as the Internet. The device management device 101 is, for example, a server.
[0028] The device 201 is a vehicle, a camera, a sensor, an actuator, a robot, an ECU (Electronic Control Unit), or the like.
[0029] In the example shown in FIG. 1, the communication system 501 includes devices 201A, 201B, 201C, 201D, 201E, 201F, 201G, 201H, 201J, 201K, 201L, and 201M.
[0030] The device management device 101 collects device information about each device 201 from each device 201. Then, based on the collected device information, the device management device 101 provides a service related to the device 201 that sent the device information. The device information includes various data acquired by the device 201 and measurement results of sensors connected to the device 201. The device management device 101 is managed, for example, by a business operator that provides the service. The device 201 is managed, for example, by a business operator or individual (hereinafter collectively referred to as a user) that receives the service.
[0031] In the communication system 501, there are a plurality of groups G each including a plurality of devices 201. More specifically, in the communication system 501, for example, there are groups G1, G2, G3, G4, and G5 as the plurality of groups G.
[0032] Group G1 is a group G to which devices 201A and 201B belong. Group G2 is a group G to which devices 201C, 201D, and 201E belong. Group G3 is a group G to which devices 201F and 201G belong. Group G4 is a group G to which devices 201H, 201J, and 201K belong. Group G5 is a group G to which devices 201L and 201M belong.
[0033] For example, a group G is provided for each manufacturer of the device 201. Note that a group G is not limited to each manufacturer of the device 201, but may be provided for each department established in the manufacturer.
[0034] [Description of the Problem] The device management device 101 performs authentication processing to establish a communication connection with a device 201 using authentication information such as a certificate. In order to minimize the impact of leakage of the authentication information, it is conceivable to prepare unique authentication information for each device 201. In this case, when manufacturing each device 201, it is necessary to prepare authentication information individually and register it in each device 201, which increases costs.
[0035] It is conceivable that common authentication information is prepared for multiple devices 201, and each device 201 transmits a connection request including the authentication information to the device management device 101, and then the device management device 101 transmits individual authentication information to each device 201. In this case, the impact of leaking the common authentication information is large. When performing authentication processing using common authentication information, it is difficult for the device management device 101 to grant unique authority to each device 201.
[0036] Therefore, the communication system 501 according to the embodiment of the present disclosure solves the above problem by the following configuration and operation.
[0037] [Communication System] Referring back to FIG. 1, the device 201 transmits connection request information to the device management apparatus 101 to request a communication connection with the device management apparatus 101 .
[0038] More specifically, for example, the connection request information includes authentication information common to two or more groups G (hereinafter also referred to as a "common authentication information set P"), authentication information unique to each group G (hereinafter also referred to as a "business authentication information set Q"), and authentication information unique to each device 201 in one group G (hereinafter also referred to as a "device authentication information set S"). The common authentication information set P is an example of first authentication information, the business authentication information set Q is an example of second authentication information, and the device authentication information set S is an example of third authentication information.
[0039] FIG. 2 is a diagram illustrating an example of common authentication information stored in a device according to an embodiment of the present disclosure.
[0040] 2 , common authentication information P1, which is a common authentication information set P, is stored in each device 201 belonging to group G1 and each device 201 belonging to group G2. Common authentication information P2, which is a common authentication information set P, is stored in each device 201 belonging to group G3 and each device 201 belonging to group G4. Common authentication information P3, which is a common authentication information set P, is stored in each device 201 belonging to group G5. The common authentication information set P includes a certificate, a private key, etc. In this way, by registering the common authentication information set P, which is authentication information common to two or more groups, in the devices 201, the manufacturing cost of the devices 201 can be reduced.
[0041] FIG. 3 is a diagram illustrating an example of business authentication information and device authentication information stored in a device according to an embodiment of the present disclosure.
[0042] 3, business operator authentication information set Q includes, for example, identification information and a password for identifying the manufacturer of device 201. In the example shown in Fig. 3, business operator authentication information sets Q for group G1, group G2, group G3, group G4, and group G5 are business operator authentication information Q1, business operator authentication information Q2, business operator authentication information Q3, business operator authentication information Q4, and business operator authentication information Q5, respectively.
[0043] The device authentication information set S includes, for example, identification information for identifying the device 201. The identification information is, for example, the serial number of the device 201.
[0044] Hereinafter, the device authentication information sets S of devices 201A, 201B, 201C, 201D, 201E, 201F, 201G, 201H, 201J, 201K, 201L, and 201M will also be referred to as device authentication information S1, S2, S3, S4, S5, S6, S7, S8, S9, S10, S11, and S12, respectively.
[0045] When the equipment management device 101 receives connection request information from the equipment 201, it performs authentication processing to establish a communication connection with the equipment 201 based on the common authentication information set P, the operator authentication information set Q, and the equipment authentication information set S contained in the received connection request information.
[0046] [Device Management Device] Fig. 4 is a diagram illustrating an example of the configuration of a device management device according to an embodiment of the present disclosure. Referring to Fig. 4, the device management device 101 includes a communication unit 11, a processing unit 12, and a storage unit 13. The processing unit 12 includes a determination unit 21, an authority setting unit 22, a list management unit 23, and a notification unit 24. One or both of the communication unit 11 and the processing unit 12 are implemented, for example, by a processing circuit including one or more processors. The storage unit 13 is, for example, a non-volatile memory included in the processing circuit. The list management unit 23 is an example of an acquisition unit.
[0047] (Communication Unit) The communication unit 11 receives the common authentication information set P, the business operator authentication information set Q, and the device authentication information set S. More specifically, for example, the communication unit 11 receives connection request information including the common authentication information set P, the business operator authentication information set Q, and the device authentication information set S from the device 201. Then, the communication unit 11 outputs the received connection request information to the determination unit 21.
[0048] (Correspondence Table) FIG. 5 is a diagram illustrating an example of a correspondence table stored by the device management device according to the embodiment of the present disclosure.
[0049] 5, for example, storage unit 13 stores a correspondence table Tb1 indicating a correspondence relationship E1 between a common authentication information set P, a business authentication information set Q, and a device authentication information set S. The "access authority" shown in FIG. 5 will be described later.
[0050] In the correspondence table Tb1 shown in Fig. 5, the business authentication information set Q corresponding to the common authentication information P1 is business authentication information Q1 and Q2. The business authentication information set Q corresponding to the common authentication information P2 is business authentication information Q3 and Q4. The business authentication information set Q corresponding to the common authentication information P3 is business authentication information Q5.
[0051] The device authentication information set S corresponding to the business authentication information Q1 is device authentication information S1 and S2. The device authentication information set S corresponding to the business authentication information Q2 is device authentication information S3, S4, and S5. The device authentication information set S corresponding to the business authentication information Q3 is device authentication information S6 and S7. The device authentication information set S corresponding to the business authentication information Q4 is device authentication information S8, S9, and S10. The device authentication information set S corresponding to the business authentication information Q5 is device authentication information S11 and S12.
[0052] (Authentication List) FIG. 6 is a diagram illustrating an example of an authentication list stored by the device management device according to the embodiment of the present disclosure.
[0053] 6 , for example, the storage unit 13 stores an authentication list L indicating the device authentication information sets S that have been received by the communication unit 11, corresponding to each of a plurality of groups G. Specifically, for example, the authentication list L indicates a set W of the common authentication information set P, the business operator authentication information set Q, and the device authentication information set S that have been received by the communication unit 11.
[0054] In the authentication list L shown in Figure 6, the sets W that the communication unit 11 has received are the set of common authentication information P2, business operator authentication information Q3, and device authentication information S7, and the set of common authentication information P3, business operator authentication information Q5, and device authentication information S12.
[0055] (Determination Unit) Referring again to FIG. 4, for example, the determination unit 21 performs a determination process to determine whether or not the device 201 (hereinafter also referred to as the "transmitting device") that transmitted the common authentication information set P, the business operator authentication information set Q, and the device authentication information set S is a legitimate device, based on the common authentication information set P, the business operator authentication information set Q, and the device authentication information set S received by the communication unit 11.
[0056] More specifically, for example, when the determination unit 21 receives connection request information from the communication unit 11, the determination unit 21 reads the correspondence table Tb1 in the storage unit 13. Then, the determination unit 21 checks whether a set W of a common authentication information set P, a business operator authentication information set Q, and a device authentication information set S included in the connection request information is registered in the correspondence table Tb1.
[0057] For example, if the group W is not registered in the correspondence table Tb1, the determination unit 21 determines that the sending device is not a legitimate device.
[0058] For example, the determination unit 21 acquires the authentication list L when the group W is registered in the correspondence table Tb1.
[0059] Specifically, for example, when the group W is registered in the correspondence table Tb1, the determination unit 21 reads out the authentication list L in the storage unit 13. Then, the determination unit 21 checks whether the group W is registered in the authentication list L.
[0060] The determination unit 21 determines that the sending device is not a legitimate device if the group W is registered in the authentication list L. Then, the determination unit 21 outputs the connection request information received from the communication unit 11 to the notification unit 24.
[0061] The determination unit 21 determines that the sending device is a legitimate device if the group W is not registered in the authentication list L. Then, the determination unit 21 outputs the connection request information received from the communication unit 11 to the authority setting unit 22 and the list management unit 23.
[0062] 7 is a diagram illustrating an example of a determination process performed by the device management device 101 according to an embodiment of the present disclosure, in which the device management device 101 receives connection request information C1 from the device 201A, the connection request information C1 including common authentication information P1, business operator authentication information Q1, and device authentication information S1.
[0063] 4, 5 and 7, in the device management apparatus 101, upon receiving connection request information C1 from the device 201A, the communication unit 11 outputs the received connection request information C1 to the determination unit 21.
[0064] When the determination unit 21 receives connection request information C1 from the communication unit 11, it reads out the correspondence table Tb1 in the storage unit 13. Then, the determination unit 21 checks whether a set W1 of common authentication information P1, business operator authentication information Q1, and device authentication information S1 included in the connection request information C1 is registered in the correspondence table Tb1.
[0065] 5, a group W1 is registered. In this case, the determination unit 21 reads out the authentication list L from the storage unit 13. Then, the determination unit 21 checks whether the group W1 is registered in the authentication list L.
[0066] The group W1 is not registered in the authentication list L shown in Fig. 6. In this case, the determination unit 21 determines that the device 201A is an authorized device.
[0067] 4 , when the determination unit 21 determines that the source device is a legitimate device, the authority setting unit 22 performs an authority setting process to grant the source device the authority to operate a predetermined resource (hereinafter also referred to as "access authority") based on the business authentication information set Q received by the communication unit 11. Below, an example will be described in which the authority setting unit 22 grants the source device the authority to operate the memory unit 13 in its own device management device 101 as access authority in the authority setting process.
[0068] For example, in the authority setting process, the authority setting unit 22 gives access authority corresponding to each of the plurality of groups G, that is, corresponding to each of the plurality of business authentication information sets Q, to the source device.
[0069] For example, the correspondence table Tb1 shown in FIG. 5 indicates a correspondence relationship E2 between the business authentication information set Q and the access authority in addition to the above-mentioned correspondence relationship E1.
[0070] In the correspondence table Tb1, the access authority corresponding to the business authentication information Q1 is access authority K1. The access authority corresponding to the business authentication information Q2 is access authority K2. The access authority corresponding to the business authentication information Q3 is access authority K3. The access authority corresponding to the business authentication information Q4 is access authority K4. The access authority corresponding to the business authentication information Q5 is access authority K5.
[0071] FIG. 8 is a diagram illustrating access rights given to devices by a device management device according to an embodiment of the present disclosure.
[0072] 8, for example, storage unit 13 of device management apparatus 101 has storage areas R1, R2, R3, R4, and R5.
[0073] The access authorities K1, K2, K3, K4, and K5 are authorities for the storage areas R1, R2, R3, R4, and R5 in the storage unit 13 of the device management apparatus 101, respectively.
[0074] In the authority setting process, the authority setting unit 22 may be configured to grant to the source device, as access authority, not only the authority to operate the storage unit 13 in its own device management device 101, but also the authority to operate other resources different from the storage unit 13. The other resources include the processor in the device management device 101 and services provided by the device management device 101.
[0075] 4 , for example, when authority setting unit 22 receives connection request information from determination unit 21, authority setting unit 22 reads correspondence table Tb1 in storage unit 13. Then, authority setting unit 22 refers to correspondence table Tb1 to identify the access authority corresponding to business operator authentication information set Q included in the connection request information.
[0076] The authority setting unit 22 then creates individual authentication information for authenticating access to the storage area corresponding to the identified access authority, and transmits the created individual authentication information to the source device via the communication unit 11 and the external network 151. The individual authentication information includes a certificate, a private key, etc.
[0077] For example, when the source device receives the individual authentication information from the device management apparatus 101, the source device stores the received individual authentication information in a storage unit (not shown).
[0078] 9 is a diagram illustrating an example of the authority setting process performed by the device management device 101 according to the embodiment of the present disclosure, in which the device management device 101 receives the connection request information C1 shown in FIG. 7 from the device 201A and determines that the device 201A is a legitimate device.
[0079] Referring to Figures 4, 5 and 9, when the authority setting unit 22 receives connection request information C1 from the judgment unit 21, it refers to the correspondence table Tb1 in the memory unit 13 and identifies the access authority K1 as the access authority corresponding to the business authentication information Q1 included in the connection request information C1.
[0080] The authority setting unit 22 then creates individual authentication information Da for authenticating access to the storage area R1 corresponding to the identified access authority K1, and transmits the created individual authentication information Da to the device 201A via the communication unit 11 and the external network 151.
[0081] When the device 201A receives the individual authentication information Da from the device management apparatus 101, the device 201A stores the received individual authentication information Da in its own storage unit.
[0082] [Creating and transmitting temporary authentication information] Referring again to Figures 1 and 4, when the sending device accesses the device management device 101, it transmits to the device management device 101 first access request information including the individual authentication information stored in its own memory unit and its own device authentication information set S.
[0083] In the equipment management device 101, when the authority setting unit 22 receives first access request information from the equipment 201 via the external network 151 and the communication unit 11, it authenticates the equipment 201 using the individual authentication information included in the received first access request information.
[0084] 5, the device management device 101 checks the access authority corresponding to the device authentication information set S included in the first access request information received from the device 201. Then, the device management device 101 performs a creation process to create temporary authentication information for temporarily permitting access to the storage area of the storage unit 13 corresponding to the access authority.
[0085] Specifically, for example, the storage unit 13 stores an authority list indicating the correspondence between storage areas and access authorities.
[0086] When the authority setting unit 22 confirms the access authority corresponding to the device authentication information set S included in the first access request information received from the device 201, it identifies the memory area of the memory unit 13 corresponding to the access authority by referring to the authority list in the memory unit 13.
[0087] Then, the authority setting unit 22 creates temporary authentication information to temporarily permit access to the identified storage area, and sends the created temporary authentication information to the device 201 that sent the first access request information.
[0088] If the device management apparatus 101 fails to authenticate the device 201, it does not perform the creation process and transmits authentication failure information indicating that the authentication has failed to the device 201.
[0089] 10 is a diagram illustrating an example of a creation process performed by a device management device 101 according to an embodiment of the present disclosure, in which the device management device 101 receives first access request information A including individual authentication information Da and device authentication information S1 from a device 201A.
[0090] Referring to Figures 4 and 10, in the equipment management device 101, when the communication unit 11 receives first access request information A from the equipment 201 via the external network 151, it outputs the received first access request information A to the authority setting unit 22.
[0091] When the authority setting unit 22 receives the first access request information A from the communication unit 11, the authority setting unit 22 performs authentication processing for the device 201A using the individual authentication information Da included in the first access request information A.
[0092] When the equipment management device 101 successfully authenticates the equipment 201A, it confirms that the access authority corresponding to the equipment authentication information S1 contained in the first access request information A is access authority K1 by referring to the correspondence table Tb1 shown in Figure 5.
[0093] Then, the equipment management device 101 identifies the memory area of the memory unit 13 corresponding to the access authority K1, i.e., memory area R1, by referring to the authority list in the memory unit 13, and creates temporary authentication information Wa to temporarily permit access to the memory area R1.
[0094] After creating the temporary authentication information Wa, the authority setting unit 22 transmits the temporary authentication information Wa to the device 201A via the communication unit 11 and the external network 151.
[0095] [Second Access Request Information] When the device 201 receives the temporary authentication information from the device management device 101, it transmits to the device management device 101 second access request information including the temporary authentication information and storage area information E indicating the storage area to which the device 201 requests access (hereinafter also referred to as the "requested storage area").
[0096] Here, the device 201 may mistakenly request access to another storage area different from the storage area corresponding to the temporary authentication information received from the device management apparatus 101. That is, the device 201 may mistakenly send second access request information B including storage area information E indicating the other storage area. Therefore, the device management apparatus 101 performs area confirmation processing to confirm whether the requested storage area indicated by the storage area information E included in the second access request information received from the device 201 is the storage area corresponding to the temporary authentication information.
[0097] 11 is a diagram illustrating an example of an area confirmation process performed by the device management device 101 according to an embodiment of the present disclosure, in which the device management device 101 receives second access request information B from the device 201A.
[0098] 11 , when the device 201A receives the temporary authentication information Wa from the device management device 101, the device 201A transmits second access request information B including the temporary authentication information Wa and storage area information E to the device management device 101 via the external network 151. Here, it is assumed that the requested storage area indicated by the storage area information E is storage area R1.
[0099] In the device management apparatus 101 , when the communication unit 11 receives the second access request information B from the device 201A via the external network 151 , the communication unit 11 outputs the received second access request information B to the authority setting unit 22 .
[0100] When the authority setting unit 22 receives the second access request information B from the communication unit 11, it confirms that the access authority corresponding to the temporary authentication information Wa included in the second access request information B is the access authority K1.
[0101] Then, the authority setting unit 22 identifies the storage area (hereinafter also referred to as the "corresponding storage area") corresponding to the access authority K1 by referring to the authority list in the storage unit 13, and confirms whether the identified corresponding storage area is the same as the requested storage area indicated by the storage area information E included in the second access request information B, i.e., the storage area R1.
[0102] Here, it is assumed that the identified corresponding storage area is the same as storage area R1 indicated by storage area information E included in second access request information B. In this case, authority setting unit 22 transmits access permission information indicating that device 201A is permitted to access storage area R1 to device 201A via communication unit 11 and external network 151.
[0103] If the identified corresponding storage area is different from the storage area R1 indicated by the storage area information E included in the second access request information B, the authority setting unit 22 sends access denial information indicating that access to the storage area R1 by the device 201A is not permitted to the device 201A via the communication unit 11 and the external network 151.
[0104] [Device Management Apparatus] (List Management Unit) Referring again to FIG. 4, for example, in the device management apparatus 101, the list management unit 23 performs a list update process for updating the authentication list L.
[0105] More specifically, for example, when list management unit 23 receives connection request information from determination unit 21, list management unit 23 reads out authentication list L from storage unit 13. Then, list management unit 23 registers in authentication list L the common authentication information set P, the business operator authentication information set Q, and the device authentication information included in the connection request information.
[0106] (Notification unit) For example, if the common authentication information, business authentication information, and device authentication information received by the communication unit 11 are the same as the common authentication information, business authentication information, and device authentication information already received from another device 201, the notification unit 24 performs a predetermined notification process.
[0107] For example, the storage unit 13 stores a device table indicating the correspondence between the device 201 and the device authentication information set S.
[0108] For example, when the notification unit 24 receives connection request information from the communication unit 11, it refers to the device table in the storage unit 13 to identify the device 201 corresponding to the device authentication information set S included in the connection request information.
[0109] Then, the notification unit 24 notifies the user of the device 201 of connection refusal information indicating that a communication connection between the identified device 201 and its own device management device 101 is refused. Specifically, for example, the notification unit 24 transmits the connection refusal information to a terminal device (not shown) held by the user via the communication unit 11 and the external network 151.
[0110] 12 is a diagram illustrating an example of a notification process performed by a device management device according to an embodiment of the present disclosure, in which the device management device 101 receives connection request information C2 including common authentication information P2, business operator authentication information Q3, and device authentication information S7 from an unauthorized device masquerading as device 201G.
[0111] 4, 6 and 12, in the device management apparatus 101, when the communication unit 11 receives the connection request information C2 from the unauthorized device, the communication unit 11 outputs the received connection request information C2 to the determination unit 21.
[0112] When the judgment unit 21 receives connection request information C2 from the communication unit 11, it refers to the correspondence table Tb1 in the memory unit 13 and confirms that the set W2 of common authentication information P2, operator authentication information Q3, and device authentication information S7 contained in the connection request information C2 is registered in the correspondence table Tb1.
[0113] Then, the determination unit 21 checks whether the group W2 is registered in the authentication list L by referring to the authentication list L in the storage unit 13. In this case, the group W2 is registered in the authentication list L. In this case, the determination unit 21 determines that the device that sent the connection request information C2 is not a legitimate device. Then, the determination unit 21 outputs the connection request information C2 received from the communication unit 11 to the notification unit 24.
[0114] When the notification unit 24 receives the connection request information C2 from the determination unit 21, it refers to the device table in the storage unit 13 and identifies the device 201G as the device 201 corresponding to the device authentication information S7 included in the connection request information C2. Then, the notification unit 24 notifies the user of the device 201G of the connection refusal information.
[0115] [Operation Flow] Next, the operation flow of the device management device 101 in the communication system 501 according to the embodiment of the present disclosure will be described with reference to the drawings.
[0116] FIG. 13 is a flowchart illustrating an example of an operation procedure when the device management device according to the embodiment of the present disclosure performs the authority setting process.
[0117] Referring to FIG. 13, first, device management apparatus 101 waits for reception of connection request information from device 201 (NO in step ST101).
[0118] Then, when the equipment management device 101 receives connection request information from the equipment 201 (YES in step ST101), it checks whether the set W of the common authentication information set P, the operator authentication information set Q, and the equipment authentication information set S contained in the received connection request information is registered in the correspondence table Tb1 in the memory unit 13 (step ST102).
[0119] Next, if the group W is registered in the correspondence table Tb1 (YES in step ST102), the device management device 101 checks whether the group W is registered in the authentication list L in the storage unit 13 (step ST103).
[0120] If group W is not registered in the authentication list L (NO in step ST103), the device management device 101 determines that the source device, which is device 201 that sent the connection request information including group W, is a legitimate device (step ST104).
[0121] Next, the device management device 101 performs an authority setting process to grant access authority to the source device that has been determined to be a legitimate device. For example, as described above, the device management device 101 refers to the correspondence table Tb1 in the storage unit 13 to identify the access authority corresponding to the device authentication information set S included in the connection request information received from the source device (step ST105).
[0122] Next, the device management apparatus 101 transmits authority information indicating the identified access authority to the source device (step ST106).
[0123] Next, the device management device 101 performs a list update process to update the authentication list L. For example, as described above, the device management device 101 registers the set W included in the connection request information received from the source device that has been determined to be a legitimate device in the authentication list L (step ST107), and waits for the reception of new connection request information (NO in step ST101).
[0124] If the group W included in the connection request information received from the device 201 is not registered in the correspondence table Tb1 (NO in step ST102), the device management device 101 determines that the device 201 is not a legitimate device (step ST108) and waits for the reception of new connection request information (NO in step ST101).
[0125] If the group W included in the connection request information received from the device 201 is registered in the authentication list L (YES in step ST103), the device management device 101 determines that the device 201 is not a legitimate device (step ST109), performs a notification process to notify the user of the device 201 of connection refusal information indicating that the communication connection with the device 201 is refused (step ST110), and waits for the reception of new connection request information (NO in step ST101).
[0126] FIG. 14 is a flowchart illustrating an example of an operation procedure when the device management device according to the embodiment of the present disclosure transmits access permission information.
[0127] Referring to FIG. 14, first, device management apparatus 101 waits for reception of first access request information from device 201 (NO in step ST201).
[0128] Then, when the equipment management apparatus 101 receives first access request information from the equipment 201 (YES in step ST201), it authenticates the equipment 201 using the individual authentication information included in the received first access request information (step ST202).
[0129] Next, if the equipment management device 101 successfully authenticates the equipment 201 (YES in step ST202), it refers to the correspondence table Tb1 in the memory unit 13 to confirm the access authority corresponding to the equipment authentication information set S included in the first access request information received from the equipment 201 (step ST203).
[0130] Next, the device management device 101 creates and transmits temporary authentication information. For example, as described above, the device management device 101 identifies a storage area corresponding to the confirmed access authority by referring to the authority list in the storage unit 13. Then, the device management device 101 creates temporary authentication information for temporarily permitting access to the identified storage area, and transmits the created temporary authentication information to the device 201 (step ST204).
[0131] Next, device management apparatus 101 waits for reception of second access request information from device 201 (NO in step ST205).
[0132] Then, when the equipment management device 101 receives second access request information from the equipment 201 (YES in step ST205), it checks the access authority corresponding to the temporary authentication information included in the received second access request information (step ST206).
[0133] Next, the device management apparatus 101 refers to the authority list in the storage unit 13 to confirm the corresponding storage area that corresponds to the confirmed access authority (step ST207).
[0134] Next, the device management apparatus 101 checks whether the confirmed corresponding storage area is the same as the requested storage area indicated by the storage area information included in the second access request information received from the device 201 (step ST208).
[0135] If the corresponding storage area and the requested storage area are the same (YES in step ST208), the equipment management device 101 transmits access permission information indicating that access to the requested storage area is permitted to the equipment 201 that sent the second access request information (step ST209), and waits to receive new first access request information (NO in step ST201).
[0136] If the corresponding storage area and the requested storage area are different (NO in step ST208), the equipment management device 101 sends access denial information to the equipment 201 indicating that access to the requested storage area is not permitted (step ST210), and waits to receive new first access request information (NO in step ST201).
[0137] If the device management device 101 fails to authenticate the device 201 (in step ST202), it sends authentication failure information indicating that the authentication has failed to the device 201 (step ST211), and waits to receive new first access request information (NO in step ST201).
[0138] In the communication system 501 according to the embodiment of the present disclosure, the device management device 101 is configured to grant access rights corresponding to each of the multiple groups G to a source device, but this is not limited to this. The device management device 101 may be configured to grant the same access rights as devices 201 belonging to other groups G to a source device, regardless of the group G.
[0139] In the communication system 501 according to the embodiment of the present disclosure, the device management device 101 is configured to receive the device authentication information set S from the device 201 in addition to the common authentication information set P and the service provider authentication information set Q, and to perform a determination process to determine whether the transmitting device is a legitimate device based on the common authentication information set P, the service provider authentication information set Q, and the device authentication information set S. However, this is not limited to this. The device authentication information set S may not be registered in each device 201. In this case, each device 201 transmits connection request information to the device management device 101 that includes the common authentication information set P and the service provider authentication information set Q, but does not include the device authentication information set S. The device management device 101 determines whether the transmitting device is a legitimate device based on the common authentication information set P and the service provider authentication information set Q included in the connection request information.
[0140] In the communication system 501 according to the embodiment of the present disclosure, the device management device 101 is configured to determine in the determination process that the sending device is not a legitimate device if the device authentication information set S received from the device 201 is registered in the authentication list L indicating the previously received device authentication information sets S. However, this is not limited to this. For example, the device management device 101 may be configured to determine that the sending device is not a legitimate device if it receives a predetermined device authentication information set S without using the authentication list L.
[0141] In the communication system 501 according to the embodiment of the present disclosure, the device management device 101 is configured to perform notification processing when the received common authentication information set P, business operator authentication information set Q, and device authentication information set S are the same as the previously received common authentication information set P, business operator authentication information set Q, and device authentication information set S, respectively, but this is not limited to this. The device management device 101 may also be configured not to perform notification processing.
[0142] Some or all of the functions of the device management device 101 according to the embodiment of the present disclosure may be provided by cloud computing. That is, the device management device 101 according to the embodiment of the present disclosure may be a cloud server configured by multiple servers.
[0143] [Modification] When the device management apparatus 101 receives connection request information from the device 201A, the device management apparatus 101 may be configured to perform the following processes as a determination process and an authority setting process.
[0144] FIG. 15 is a diagram illustrating an example of a correspondence table stored in a modification of a device management apparatus according to an embodiment of the present disclosure.
[0145] 15, in the modified example, the storage unit 13 stores a correspondence table Tb2 instead of the correspondence table Tb1 shown in Fig. 5. The correspondence table Tb2 indicates a correspondence relationship E1 between the common authentication information set P, the business operator authentication information set Q, and the device authentication information set S, and a correspondence relationship E2 between the device authentication information set S and access authority.
[0146] The correspondence relationship E2 in the correspondence table Tb2 shown in Fig. 15 is different from that in the correspondence table Tb1 shown in Fig. 5. The details of the correspondence relationship E2 in the correspondence table Tb2 will be described later.
[0147] 16 is a diagram illustrating an example of a determination process performed by a modification of the device management apparatus according to an embodiment of the present disclosure, in which the device management apparatus 101 receives connection request information C1 from the device 201A.
[0148] Referring to Figure 16, in the modified example, the judgment unit 21 in the equipment management device 101 judges whether the sending equipment is a legitimate equipment based on at least the common authentication information set P and the business authentication information set Q out of the common authentication information set P, business authentication information set Q, and equipment authentication information set S received by the communication unit 11.
[0149] In the example shown in Figure 16, the judgment unit 21 judges whether the device 201A is a legitimate device based on the common authentication information P1 and the business authentication information Q1 included in the connection request information C1, without using the device authentication information S1 included in the connection request information C1 from the device 201A.
[0150] Specifically, for example, when the determination unit 21 receives connection request information C1 from the device 201A via the communication unit 11, the determination unit 21 reads the correspondence table Tb2 in the storage unit 13. Then, the determination unit 21 checks whether a set W20 of the common authentication information P1 and the business authentication information Q1 included in the connection request information C1 is registered in the correspondence table Tb2.
[0151] 15, a group W20 is registered. In this case, the determination unit 21 reads out the authentication list L from the storage unit 13. Then, the determination unit 21 checks whether the group W20 is registered in the authentication list L.
[0152] 6, group W20 is not registered. In this case, the determination unit 21 determines that the device 201A is a legitimate device. The determination unit 21 then outputs connection request information C1 to the authority setting unit 22 and the list management unit 23.
[0153] In the example shown in FIG. 16, the judgment unit 21 may be configured to judge whether the device 201A is a legitimate device based on the device authentication information S1 in addition to the common authentication information P1 and the business authentication information Q1 included in the connection request information C1.
[0154] 17 is a diagram illustrating an example of an authority setting process performed by a modification of the device management apparatus according to an embodiment of the present disclosure, in which the device management apparatus 101 receives the connection request information C1 shown in FIG. 16 from the device 201A and determines that the device 201A is a legitimate device.
[0155] 15 and 17 , for example, the authority setting unit 22 performs the authority setting process for each source device based on at least the device authentication information set S out of the business operator authentication information set Q and the device authentication information set S received by the communication unit 11. Hereinafter, an example will be described in which the authority setting unit 22 performs the authority setting process using the device authentication information set S without using the business operator authentication information set Q.
[0156] More specifically, for example, the authority setting unit 22 gives different access authorities to a plurality of devices 201 belonging to the same group G.
[0157] For example, in the correspondence table Tb2 shown in Fig. 15, device authentication information S1 and S2 correspond to access authorities K2 and K1, respectively. Device authentication information S3, S4, and S5 correspond to access authorities K2, K1, and K3, respectively. Device authentication information S6 and S7 correspond to access authorities K3 and K1, respectively. Device authentication information S8, S9, and S10 correspond to access authorities K4, K1, and K2, respectively. Device authentication information S11 and S12 correspond to access authorities K5 and K3, respectively.
[0158] When the authority setting unit 22 receives the connection request information C1 from the judgment unit 21, it refers to the correspondence table Tb2 in the memory unit 13 and identifies the access authority K2 as the access authority corresponding to the device authentication information S1 included in the connection request information C1.
[0159] Then, the authority setting unit 22 transmits authority information indicating the identified access authority K2 to the device 201A via the external network 151.
[0160] It should be noted that there may be devices 201 with overlapping device authentication information sets S between manufacturers of the devices 201. In this case, the authority setting unit 22 in the device management device 101 performs authority setting processing for each source device based on the business authentication information set Q and the device authentication information set S received by the communication unit 11.
[0161] The above-described embodiments should be considered to be illustrative in all respects and not restrictive. The scope of the present invention is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope of the claims.
[0162] Each process (each function) in the above-described embodiments is achieved by a processing circuit including one or more processors. The processing circuit may be configured as an integrated circuit or the like that combines one or more memories, various analog circuits, and various digital circuits in addition to the one or more processors. The one or more memories store programs (instructions) that cause the one or more processors to execute each of the processes. The one or more processors may execute each of the processes according to the program read from the one or more memories, or may execute each of the processes according to a logic circuit designed in advance to execute each of the processes. The processor may be any of various processors suitable for computer control, such as a CPU (Central Processing Unit), a GPU (Graphics Processing Unit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and an ASIC (Application Specific Integrated Circuit). Note that the physically separated processors may cooperate with each other to execute the processes. For example, the processors installed in the physically separated computers may cooperate with each other via a network such as a LAN (Local Area Network), a WAN (Wide Area Network), or the Internet to execute the processes. The program may be installed into the memory from an external server device or the like via the network, or may be distributed in a state stored on a recording medium such as a CD-ROM (Compact Disc Read Only Memory), a DVD-ROM (Digital Versatile Disc Read Only Memory), or a semiconductor memory, and then installed into the memory from the recording medium.
[0163] The above description includes the following additional features: [Supplementary Note 1] A device management device used in a system in which there are multiple groups each containing a multiple number of devices, the device management device comprising: a communication unit that receives first authentication information common to two or more of the groups and second authentication information unique to each of the multiple groups from a source device that is the device that transmitted the first authentication information and the second authentication information, a determination unit that determines whether the source device is a legitimate device based on the first authentication information and the second authentication information received by the communication unit, and an authority setting unit that performs authority setting processing to grant the source device authority to operate a predetermined resource when the determination unit determines that the source device is a legitimate device, wherein the group is provided for each manufacturer of the devices or a department established at the manufacturer.
[0164] [Supplementary Note 2] A device management device used in a system in which there are multiple groups each containing multiple devices, comprising a processing circuit, the processing circuit receiving first authentication information that is common to two or more of the groups and second authentication information that is unique to each of the multiple groups from a source device that is the device that has transmitted the first authentication information and the second authentication information, determining whether the source device is a legitimate device based on the received first authentication information and second authentication information, and if it is determined that the source device is a legitimate device, performing an authority setting process to grant the source device authority to operate on a specified resource.
[0165] REFERENCE SIGNS LIST 11 Communication unit 12 Processing unit 13 Storage unit 21 Determination unit 22 Authority setting unit 23 List management unit 24 Notification unit 101 Device management device 151 External network 201 Device 501 Communication system G Group L Authentication list P Common authentication information set P1, P2, P3 Common authentication information Q Business authentication information set Q1, Q2, Q3, Q4, Q5 Business authentication information S Device authentication information set S1, S2, S3, S4, S5, S6, S7, S8, S9, S10, S11, S12 Device authentication information Tb1, Tb2 Correspondence table
Claims
1. A device management device used in a system in which there are multiple groups each containing multiple devices, comprising: a communication unit that receives first authentication information that is common to two or more of the groups and second authentication information that is unique to each of the multiple groups from a source device that is the device that transmitted the first authentication information and the second authentication information; a determination unit that determines whether the source device is a legitimate device based on the first authentication information and the second authentication information received by the communication unit; and an authority setting unit that performs authority setting processing to grant the source device the authority to operate specified resources when the determination unit determines that the source device is a legitimate device.
2. The device management apparatus according to claim 1, wherein the authority setting section, in the authority setting process, gives the authority corresponding to each of a plurality of groups to the source device.
3. The device management device of claim 1 or claim 2, wherein the communication unit further receives third authentication information unique to each of the source devices in one of the groups from the devices, and the judgment unit performs a judgment process to determine whether the source device is a legitimate device based on the first authentication information, the second authentication information, and the third authentication information received by the communication unit.
4. The device management device of claim 3, wherein the judgment unit further acquires an authentication list showing the third authentication information already received by the communication unit corresponding to each of the multiple groups, and the judgment unit determines that the sending device is not a legitimate device if the third authentication information received by the communication unit is registered in the acquired authentication list during the judgment process.
5. The device management device according to claim 3 or claim 4, further comprising a notification unit that performs a predetermined notification process when the first authentication information, the second authentication information, and the third authentication information received by the communication unit are the same as the first authentication information, the second authentication information, and the third authentication information that the communication unit has already received from another device.
6. The device management device described in claim 1 or claim 2, wherein the communication unit further receives third authentication information unique to each of the source devices in one of the groups, the determination unit determines whether the source device is a legitimate device based on at least the first authentication information and the second authentication information out of the first authentication information, the second authentication information, and the third authentication information received by the communication unit, and the authority setting unit performs the authority setting process for each of the source devices based on at least the third authentication information.
7. A device management method in a device management device used in a system in which there are multiple groups each containing multiple devices, comprising the steps of: receiving first authentication information that is common to two or more of the groups and second authentication information that is unique to each of the multiple groups from a source device that is the device that sent the first authentication information and the second authentication information; determining whether the source device is a legitimate device based on the received first authentication information and second authentication information; and performing an authority setting process to grant the source device the authority to operate specified resources if it is determined that the source device is a legitimate device.
8. A device management program used in a device management device used in a system in which there are multiple groups each containing multiple devices, the program causing a computer to function as: a communication unit that receives first authentication information common to two or more groups and second authentication information unique to each of the multiple groups from a source device that is the device that transmitted the first authentication information and the second authentication information; a determination unit that determines whether the source device is a legitimate device based on the first authentication information and the second authentication information received by the communication unit; and an authority setting unit that performs authority setting processing to grant the source device the authority to operate specified resources when the determination unit determines that the source device is a legitimate device.