IP Library › Granted Patent US 12,339,984
Granted Patent B2
US 12,339,984 · App. 18/009,385 · Granted Jun 24, 2025

Management apparatus, control method, computer readable medium, and access control system

Inventors: Takumi Hirota (Tokyo, JP); Morimichi Kojima (Tokyo, JP)
Assignees: NEC CORPORATION; NEC Solution Innovators, Ltd.
G06F21/6218G06F21/602H04L9/0861
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,339,984
App. No.
18/009,385
Granted
Jun 24, 2025
Kind
B2
Abstract

Access right information ( 20 ) indicating an access right of a user for a target file ( 10 ) is stored in a storage device ( 3100 ) accessible from a server apparatus ( 3000 ). A management apparatus ( 4000 ) acquires the access right information ( 20 ) from the server apparatus ( 3000 ) and puts it in a storage device ( 4100 ). The management apparatus ( 4000 ) acquires a request for key information that is used to decrypt a target file ( 10 ) from a user apparatus ( 2000 ) operated by a target user ( 40 ). The management apparatus ( 4000 ) determines, upon the acquisition of the request, whether or not the target user ( 10 ) has an access right for the target file ( 40 ) by using the access right information ( 20 ) stored in the storage device ( 4100 ). The management apparatus ( 4000 ) outputs the key information to the user apparatus ( 2000 ) when it is determined that the target user ( 40 ) has the access right for the target file ( 10 ).

Claims (78)

1. A management apparatus comprising:

at least one memory that stores instructions; and

at least one processor that is configured to execute the instructions to:

acquire access right information from a server apparatus configured to manage the access right information, the access right information indicating an access right of a user for each file stored in an encrypted state in a first storage device;

put the acquired access right information in a second storage device;

acquire a request for key information that is used to decrypt a target file from a user apparatus operated by a target user;

determine, upon the acquisition of the request, whether or not the target user has an access right for the target file by using the access right information stored in the second storage device;

output the key information to the user apparatus when it is determined that the target user has the access right for the target file; and

when the access right information is updated in the server apparatus, update the access right information stored in the second storage device by acquiring the access right transmitted from the server apparatus.

2. The management apparatus according to claim 1 , wherein the at least one processor is configured further to:

acquire the access right information updated in the server apparatus by accessing the server apparatus; and

update the access right information stored in the second storage device with the acquired access right information.

3. The management apparatus according to claim 1 ,

wherein an encryption key used to encrypt the target file is contained in the request, and

wherein the output of the key information includes:

generating a decryption key for decrypting the target file by using the encryption key; and

outputting key information containing the generated decryption key.

4. The management apparatus according to claim 1 ,

wherein in the access right information, the access right of the target user for the target file is determined based on a reference location, the reference location being a location where the target file was stored at a predetermined point in time that is earlier than a point in time when whether or not the user has an access right for the target file is determined,

wherein reference location information indicating the reference location of the target file is contained in the request, and

wherein whether or not the target user has the access right for the target file is determined by using the access right information and the reference location information.

5. The management apparatus according to claim 1 , wherein the server apparatus is a file server.

6. A control method performed by a management apparatus, comprising:

acquiring access right information from a server apparatus configured to manage the access right information, the access right information indicating an access right of a user for each file stored in an encrypted state in a first storage device;

putting the acquired access right information in a second storage device;

acquiring a request for key information that is used to decrypt a target file from a user apparatus operated by a target user;

determining, upon the acquisition of the request, whether or not the target user has an access right for the target file by using the access right information stored in the second storage device;

outputting the key information to the user apparatus when it is determined that the target user has the access right for the target file; and

when the access right information is updated in the server apparatus, the access right information stored in the second storage device is updated by acquiring the access right transmitted from the server apparatus.

7. The control method according to claim 6 , wherein the access right information updated in the server apparatus is acquired by accessing the server apparatus, and the access right information stored in the second storage device is updated with the acquired access right information.

8. The control method according to claim 6 ,

wherein an encryption key used to encrypt the target file is contained in the request, and

wherein a decryption key for decrypting the target file is generated by using the encryption key, and key information containing the generated decryption key is output.

9. The control method according to claim 6 ,

wherein in the access right information, the access right of the target user for the target file is determined based on a reference location, the reference location being a location where the target file was stored at a predetermined point in time that is earlier than a point in time when whether or not the user has an access right for the target file,

wherein reference location information indicating the reference location of the target file is contained in the request, and

wherein whether or not the target user has the access right for the target file is determined by using the access right information and the reference location information.

10. The control method according to claim 6 , wherein the server apparatus is a file server.

11. A non-transitory computer readable medium storing a program that causes a management apparatus to perform:

acquiring access right information from a server apparatus configured to manage the access right information, the access right information indicating an access right of a user for each file stored in an encrypted state in a first storage device;

putting the acquired access right information in a second storage device;

acquiring a request for key information that is used to decrypt a target file from a user apparatus operated by a target user;

determining, upon the acquisition of the request, whether or not the target user has an access right for the target file by using the access right information stored in the second storage device;

outputting the key information to the user apparatus when it is determined that the target user has the access right for the target file; and

when the access right information is updated in the server apparatus, the access right information stored in the second storage device is updated by acquiring the access right transmitted from the server apparatus.

12. The computer readable medium according to claim 11 , wherein the access right information updated in the server apparatus is acquired by accessing the server apparatus, and the access right information stored in the second storage device is updated with the acquired access right information.

13. The computer readable medium according to claim 11 ,

wherein an encryption key used to encrypt the target file is contained in the request, and

wherein a decryption key for decrypting the target file is generated by using the encryption key, and key information containing the generated decryption key is output.

14. The computer readable medium according to claim 11 ,

wherein in the access right information, the access right of the target user for the target file is determined based on a reference location, the reference location being a location where the target file was stored at a predetermined time that is earlier than a time when whether or not the user has an access right for the target file is determined,

wherein reference location information indicating the reference location of the target file is contained in the request, and

wherein whether or not the target user has the access right for the target file is determined by using the access right information and the reference location information.

15. The computer readable medium according to claim 11 , wherein the server apparatus is a file server.

16. An access control system comprising a user apparatus, a server apparatus, and a management apparatus,

wherein the user apparatus comprises at least one memory that stores instructions and at least one processor that is configured to execute the instructions to transmit a request for key information that is used to decrypt a target file accessed by a target user,

wherein the management apparatus comprises at least one memory that stores instructions and at least one processor that is configured to execute the instructions to:

acquire access right information from the server apparatus, the access right information indicating an access right of a user for each file stored in an encrypted state in a first storage device;

put the acquired access right information in a second storage device;

acquire the request from the user apparatus;

determine, upon the acquisition of the request, whether or not the target user has an access right for the target file by using the access right information stored in the second storage device; and

output the key information to the user apparatus when it is determined that the target user has the access right for the target file,

wherein the user apparatus comprises at least one memory that stores instructions and at least one processor that is configured to execute the instructions to decrypt the target file by using the key information output from the management apparatus,

wherein the at least one processor of the server apparatus is configured further to, when the access right information is updated, transmit the updated access right information to the management apparatus, and

wherein the at least one processor of the management apparatus is configured further to update the access right information stored in the second storage device by acquiring the access right transmitted from the server apparatus.

17. The access control system according to claim 16 ,

wherein the at least one processor of the management apparatus is configured further to transmit, to the server apparatus, a request for updated access right information,

wherein the at least one processor of the server apparatus is configured further to transmit, upon receiving the request transmitted from the management apparatus, the updated access right information to the management apparatus, and

wherein the at least one processor of the management apparatus is configured further to update the access right information stored in the second storage device with the access right information transmitted from the server apparatus.

18. The access control system according to claim 16 ,

wherein an encryption key used to encrypt the target file is contained in the request, and

wherein the at least one processor of the management apparatus is configured further to generate a decryption key for decrypting the target file by using the encryption key, and output key information containing the generated decryption key, and

wherein the at least one processor of the user apparatus is configured further to decrypt the target file by using the decryption key contained in the key information.

19. The access control system according to claim 16 ,

wherein in the access right information, the access right of the target user for the target file is determined based on a reference location, the reference location being a location where the target file was stored at a predetermined point in time that is earlier than a point in time when the process by the determination unit is performed,

wherein reference location information indicating the reference location of the target file is contained in the request, and

wherein whether or not the target user has the access right for the target file is determined by using the access right information and the reference location information.

20. The access control system according to claim 16 , wherein the server apparatus is a file server.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2022
From: HIROTA, TAKUMI; KOJIMA, MORIMICHI
To: NEC CORPORATION; NEC SOLUTION INNOVATORS, LTD.,
Reel/Frame 062037/0225 →
Continuity (1)
Related Publication 20230222238A1 · Jul 13, 2023
References Cited (8)
JP 2007219619A · 2007 [cited by examiner]
JP 2008276376A · 2008 [cited by applicant]
JP 2010129036A · 2010 [cited by applicant]
JP 2011076378A · 2011 [cited by examiner]
WO 2017064780A1 · 2017 [cited by applicant]
WO 2017064781A1 · 2017 [cited by applicant]
International Search Report for PCT Application No. PCT/JP2020/023081, mailed on Sep. 29, 2022. [cited by applicant]
JP Office Action for JP Application No. 2022-530467, mailed on Apr. 23, 2024 with English Translation. [cited by applicant]