WO2004019215A1 - クライアントサーバシステムのログイン方法、コンピュータプログラムおよび記録媒体 - Google Patents
クライアントサーバシステムのログイン方法、コンピュータプログラムおよび記録媒体 Download PDFInfo
- Publication number
- WO2004019215A1 WO2004019215A1 PCT/JP2003/009767 JP0309767W WO2004019215A1 WO 2004019215 A1 WO2004019215 A1 WO 2004019215A1 JP 0309767 W JP0309767 W JP 0309767W WO 2004019215 A1 WO2004019215 A1 WO 2004019215A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- client
- network
- login
- screen
- address
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
Definitions
- the present invention relates to a login method for a client-server system, and more particularly, to a balance in terms of security and operability when a client logs in to a server accessible from both the Internet and a LAN. And a computer program for executing the method, and a recording medium recording the computer program.
- Conventional technology a login method for a client-server system, and more particularly, to a balance in terms of security and operability when a client logs in to a server accessible from both the Internet and a LAN.
- a computer program for executing the method, and a recording medium recording the computer program recording the computer program.
- the method of logging in from the client to the server is to enter the login name and password in the text box (directly). Input method) is common.
- an object of the present invention is to provide a method of logging in a client-server system that balances security and operability when a client logs in to a server accessible from both the Internet and a LAN. It is an object of the present invention to provide a computer program for executing a login method and a recording medium on which the computer program is recorded.
- An object of the present invention is a login method of a client server system that causes a client to display a predetermined login screen, wherein the server acquires identification information of the client in response to a connection request from the client, A network to which the client is connected is determined based on the identification information, and when it is determined that the network is a first network, the client is provided with a first password.
- a mouth login method of a client-server system that causes a client to display a second login screen when a network screen is displayed and the network is determined to be the second network.
- a network to which a client attempting to log in is connected is determined, and a different login screen is displayed based on the determination result.
- a difference can be provided, and a mouth-guin method balanced in terms of security and operability can be provided.
- the second login screen is a screen that is simpler in login operation than the first login screen.
- the degree of simplicity of the log-in operation by the client is made different according to the network access restriction level. Can be provided.
- the first login screen is a screen for directly inputting both a user's login name and a password
- the second login screen is for selecting a user's login name.
- 5 is a screen for allowing the user to select the password and directly input the password.
- the first login screen employs a direct input method for both the login name and the password
- the login screen uses a direct input method only for the password and a selection method for the login name, so that it is possible to provide an optimal login method according to the security level of the network.
- the first login screen is a screen for directly inputting both a login name and a password of a user
- the second login screen is a login name for the user. Is a screen that allows the user to select a password by the auto-complete method and directly input the password.
- the first login screen employs a direct input method for both the login name and the password
- the second login screen employs a direct input method only for the password.
- a partial selection formula is adopted by the auto-complete method, so that an optimal login method can be provided according to the security level of the network.
- the second network is a network having more restricted access than the first network.
- the simplicity of the log-in operation by the client is made different according to the access restriction level of the network to which the client to be logged in is connected.
- a balanced mouth-guin method can be provided.
- the server when determining a network to which the client is connected based on the identification information, the server is connected to at least the second network.
- the client refers to a list in which the identification information of the client is registered.
- the correspondence between the identification information of the client and the network is registered in a list, and the network to which the client is connected is determined with reference to the list.
- the determined network can be determined easily and reliably. Also, Machine / network administrators can easily set and change access restrictions for each client on the list.
- the first network is an internet
- the second network is a local area network
- the client attempting to log in is connected to the Internet or a LAN, and based on the result of the determination, the login operation by the client is performed. Since there is a difference in simplicity, it is possible to provide a mouth-in method that balances security and operability.
- the identification information is an IP address
- the server is an address list in which at least an IP address of a client connected to the local area network is registered. If the IP address is registered in the address list, it is determined that the client is connected to the local area network, and the IP address is registered in the address list. If the client is not registered in the Internet, it is determined that the client is connected to the Internet.
- the server since it is determined whether the connection route of the client attempting to log in by referring to the address list is via the Internet or the LAN, without adding any special identification information, It is very easy to determine the network to which the client is connected. Also, it becomes easy for the administrator of the machine / network to set and change the access restriction of each client on the list. Further, in a further preferred embodiment of the present invention, when the identification information is an IP address and the server is a global IP address, the server is connected to the Internet when the IP address is a global IP address. And if the IP address is a local IP address, it is determined that the client is connected to the local area network.
- the object of the present invention is also to obtain the client's identification information in response to a connection request from the client, at least to the server in the client-server system that causes the client to display a predetermined login screen. Determining a network to which the client is connected based on the identification information; and, if determining that the network is a first network, displaying a first login screen to the client. Displaying a computer program for causing the client to execute a step of displaying a second login screen when the network is determined to be a second network. Is achieved by a simple recording medium.
- the present invention by installing the computer program on the server in the client server system, it is possible to realize a mouth login method that balances security and operability.
- the object of the present invention is also to obtain the client identification information of the client at least in response to a connection request from the client in the server in the client-server system that causes the client to display a predetermined login screen; Determining a network to which the client is connected based on the identification information; and, if determining that the network is a first network, displaying a first login screen to the client. Displaying a computer program for causing the client to execute a step of displaying a second login screen when the network is determined to be a second network. Recording media Achieved by
- the recording medium is set in a server in a client-server system, and a computer program is installed in the server, thereby realizing a mouth login method that balances security and operability. can do.
- FIG. 1 is a diagram showing a schematic configuration of a client server system to which a mouth login method according to a preferred embodiment of the present invention is applied.
- FIG. 2 is a schematic block diagram showing a hardware configuration of the server 101.
- FIG. 3 is a schematic block diagram showing a software configuration of the server 101.
- FIG. 4 is a screen diagram showing an example of a first login screen displayed on the client 102c when the client 102c accesses the server 101.
- FIG. 5 is a screen diagram showing an example of a second login screen displayed on a client 102a or a client 102b when the client 102b accesses the server 101.
- FIG. 6 is a flowchart showing the operation of the server 101 at the time of login.
- FIG. 7 is a screen diagram showing another embodiment of the second mouth guin screen shown in FIG.
- FIG. 8 is a screen diagram showing another embodiment of the second mouth gui screen shown in FIG.
- FIG. 9 is a screen diagram showing still another embodiment of the second mouth guin screen shown in FIG. , Embodiments of the Invention
- FIG. 1 is a diagram showing a schematic configuration of a client server system to which a mouth login method according to a preferred embodiment of the present invention is applied.
- the system includes a server 101 and clients 102a and 102b, which are connected to a LAN 103.
- An internet connection device 104 such as a broadband router is connected to the LAN 103, and a LAN 103 is connected to the internet 105 via the broadband router 104.
- the client 102c is connected to the LAN via the internet 105. Note that, depending on the connection form to the Internet 105, it is necessary to interpose a modem between the broadband router 104 and the Internet 105, but illustration is omitted here.
- the server 101 provides various services such as a Web server, an FTP server, and a POP server.
- the server 101 is preferably a computer having a relatively higher processing capability than the client, and is preferably a workstation if higher processing capability is required.
- FIG. 2 is a schematic block diagram showing the hardware configuration of the server 101.
- the server 101 has a CPU 201, a memory 202, a hard disk drive (HDD) 203, a flexible disk, a CD-ROM, a CD-R, It has a removable disk drive (RDD) 204 that can play back at least a recording medium such as a DVD-ROM, an input / output interface 205, and a network adapter 206, which are connected via a bus 207.
- the server 101 is connected to a display keyboard or the like via an input / output interface 205, and is connected to the internet 105 via a LAN adapter 206.
- Such a configuration is a configuration of a general computer.
- Fig. 3 is a schematic block diagram showing the software configuration of the server 101. Oh o 0
- the server 101 includes a device driver 301, an operation system (OS) 302, and an application software 303.
- the application software 303 also includes a login control program 304 for executing the login method according to the present embodiment, as one function of the server software.
- These software are recorded on the hard disk drive 203, read out from the hard disk drive 203 when the computer is started or when the executable file is started, stored in the memory, and executed by the CPU sequentially processing. .
- the server 101 includes a login data table 305 that records the login name and the passcode of each user, and clients 102 a to 102 c. When the server 101 is connected to the server 101, it has login screen data 306 to be displayed on the display of these clients.
- the clients 102a to 102c shown in FIG. 1 various terminal devices such as desktop personal computers, laptop personal computers, PDAs, and mobile phones can be considered.
- the configuration of the clients 102a to 102c is substantially the same as the configuration of a general computer, and is therefore substantially the same as the configuration of the server 101 shown in FIG.
- the client's application software also includes a web browser.
- Client 10 2 a through Client 10 2 c become server 10 1
- the server 101 first sends the login screen data to the client, and a login screen is displayed on the client display.
- FIG. 4 is a screen diagram showing an example of a first login screen displayed on the display of the client 102c when the client 102c accesses the server 101.
- FIG. 4 the display of the client 102c that accesses the server 101 via the Internet displays the login name and the password directly in the text boxes 402 and 403. 1 login screen 40 1 is displayed.
- the user places the pointer in the text box 402 for inputting the login name, enters the text input mode, and then inputs the login name. The same applies to passwords.
- FIG. 5 is a screen diagram showing an example of a second login screen displayed on the display of the client 102a or 102b when the client 102b accesses the server 101.
- the displays of the clients 102a and 102b accessing the server 101 via the LAN are easier to perform the mouth login operation than the first login screen.
- the second mouth login screen 501 is displayed.
- a screen is displayed in which a login name is selected from the list 502 and a password is directly input to the text box 503.
- the user selects a mouth guin name from the list 502, matches the mouth gin name with the pointer, and clicks.
- enter a password align the pointer with the text box 503 for entering the password, enter the text entry mode, and directly enter the password. Then, by clicking the "OKj button 504", the data of the login name and the password are transmitted to the server 101.
- the client requesting the connection is a client within the LAN or To determine whether a client is connected via the Internet, the IP address is referred to as identification information.
- FIG. 6 is a flow chart showing the operation of the server 101 at the time of mouth login.
- the server 101 acquires information on the IP address contained in the packet transmitted from the client (S601). ).
- the server 101 compares the obtained IP address with its own address list (S602).
- the address list records the local IP address of the client connected to the LAN. By referring to this address list, it is determined whether the acquired IP address is a low IP address or a global IP address.
- IP address is a global IP address (S603N)
- the client directly inputs both the login name and password in the login screen shown in FIG.
- the screen data is transmitted so as to display the login screen (S 604).
- the client is allowed to select a login name from the list and directly enter only the password.
- the screen data is transmitted so as to display the screen (second login screen) (S605).
- FIG. 7 and FIG. 8 are screen diagrams showing another embodiment of the second mouth guin screen shown in FIG.
- a list of login names is displayed first, and when a login name is selected, a screen for directly inputting a new password is displayed.
- Is configured to be c First as shown in FIG. 7, at the time of a connection request, only the list 502 is displayed, and a login screen 701, in which a text box for entering a password is not displayed, is displayed.
- a login name 8002 and a further mouth displaying a text box 8003 for entering a password are displayed.
- the GUI screen 8001 is displayed.
- the login name and password data are transmitted to the server 101.
- the login name and password may be transmitted separately instead of being transmitted simultaneously. That is, the login name may be transmitted when the first login name is selected, and then the password may be transmitted when the password is input.
- FIG. 9 is a screen diagram showing still another embodiment of the second login screen shown in FIG.
- clients 102a and 102b accessing the server 101 via the LAN are provided with a simpler login operation than the first login screen.
- the login screen is displayed in the same manner, in this embodiment, when the login name is selected from the list, the login name is selected by the auto-complete method.
- this auto-complete method when one character is entered in the text box, a login name having the same character as the first character is displayed in a list, and as the second and third characters are entered, candidates in the list are displayed. It is squeezed.
- the present invention is not limited to this, and the two networks may be both local area networks. I do not care. That is, the present invention is particularly applicable to a system in which a client connected to two networks having different security levels logs in to a server.
- the IP address is a local IP address
- it is determined that the request is a connection request from a client in the LAN
- a desired login screen is provided.
- the present invention can also be applied to a case where a global IP address is allocated to another client. For example, even if a global IP address is assigned to a network that is restricted from outside access by a firewall or proxy server, that is, a client connected to the LAN, these IP addresses are registered in the address list described above. If so, the network type can be determined by referring to this address list.
- the present invention is not limited to this, and a MAC address or other identification information may be used. That is, the identification information of the client may be any identification information that can determine whether the client is accessing from the first network or accessing from the second network, such as an IP address. This concept includes not only the identification information on the network but also the individual information of the client such as the MAC address. Further, dedicated identification information used only for selecting a login screen may be used. Further, in the above-described embodiment, an example has been described in which the local IP address of each client connected to the LAN is individually recorded in the address list, but the present invention is not limited to this.
- the range of the IP address assigned to the client connected to the LAN may be included as reference data.
- the address list may be created automatically by the server searching the LAN, or automatically by the server periodically searching the LAN to add and delete local IP addresses. It may be updated.
- the network administrator may create and update the address list itself.
- the web page includes various web pages created in a program language such as HTML, SGML, and XML, and can be viewed with a web browser.
- a program language such as HTML, SGML, and XML
- the port of the client server system is well balanced in terms of security and operability. Guin method can be provided.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Information Transfer Between Computers (AREA)
- User Interface Of Digital Computer (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| AU2003252309A AU2003252309A1 (en) | 2002-08-23 | 2003-07-31 | Client server system log-in method, computer program, and recording medium |
| US10/525,330 US20060152752A1 (en) | 2002-08-23 | 2003-07-31 | Log-in method for a client server system, a computer program, and a recording medium |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| JP2002243140A JP2004086284A (ja) | 2002-08-23 | 2002-08-23 | クライアントサーバシステムのログイン方法、コンピュータプログラムおよび記録媒体 |
| JP2002-243140 | 2002-08-23 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2004019215A1 true WO2004019215A1 (ja) | 2004-03-04 |
Family
ID=31944087
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/JP2003/009767 Ceased WO2004019215A1 (ja) | 2002-08-23 | 2003-07-31 | クライアントサーバシステムのログイン方法、コンピュータプログラムおよび記録媒体 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20060152752A1 (ja) |
| JP (1) | JP2004086284A (ja) |
| AU (1) | AU2003252309A1 (ja) |
| WO (1) | WO2004019215A1 (ja) |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP4890986B2 (ja) * | 2006-07-24 | 2012-03-07 | 楽天株式会社 | サービス料金請求システム、団体所属者情報管理装置、団体所属者情報管理方法及び団体所属者情報管理処理プログラム |
| JP5278816B2 (ja) * | 2009-04-27 | 2013-09-04 | キヤノンマーケティングジャパン株式会社 | 情報処理装置、およびその制御方法、プログラム、記録媒体。 |
| WO2011109777A1 (en) * | 2010-03-05 | 2011-09-09 | Brass Monkey, Inc. | System and method for two way communication and controlling content in a web browser |
| JP6330475B2 (ja) * | 2014-05-19 | 2018-05-30 | 富士通株式会社 | ログイン制御プログラム、ログイン制御方法、およびログイン制御システム |
| CN111105216B (zh) * | 2019-12-27 | 2023-08-25 | 中水北方勘测设计研究有限责任公司 | 基于局域网络的电缆统计方法及应用 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020046353A1 (en) * | 2000-08-18 | 2002-04-18 | Sony Corporation | User authentication method and user authentication server |
| JP2003108518A (ja) * | 2001-09-27 | 2003-04-11 | Sony Communication Network Corp | ユーザアクセス管理方法および装置 |
Family Cites Families (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7216292B1 (en) * | 1999-09-01 | 2007-05-08 | Microsoft Corporation | System and method for populating forms with previously used data values |
| JP2002314549A (ja) * | 2001-04-18 | 2002-10-25 | Nec Corp | ユーザ認証システム及びそれに用いるユーザ認証方法 |
| US6834795B1 (en) * | 2001-06-29 | 2004-12-28 | Sun Microsystems, Inc. | Secure user authentication to computing resource via smart card |
| JP2003018178A (ja) * | 2001-07-04 | 2003-01-17 | Allied Tereshisu Kk | インテリジェント中継機器における不正アクセス回避方法、インテリジェント中継機器用不正アクセス回避プログラム、インテリジェント中継機器用不正アクセス回避プログラムを記録した記録媒体、インテリジェント中継機器及びlanシステム |
| US7076539B2 (en) * | 2001-07-30 | 2006-07-11 | Hewlett-Packard Development Company, L.P. | Network connectivity establishment at user log-in |
-
2002
- 2002-08-23 JP JP2002243140A patent/JP2004086284A/ja active Pending
-
2003
- 2003-07-31 WO PCT/JP2003/009767 patent/WO2004019215A1/ja not_active Ceased
- 2003-07-31 US US10/525,330 patent/US20060152752A1/en not_active Abandoned
- 2003-07-31 AU AU2003252309A patent/AU2003252309A1/en not_active Abandoned
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20020046353A1 (en) * | 2000-08-18 | 2002-04-18 | Sony Corporation | User authentication method and user authentication server |
| JP2003108518A (ja) * | 2001-09-27 | 2003-04-11 | Sony Communication Network Corp | ユーザアクセス管理方法および装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| AU2003252309A1 (en) | 2004-03-11 |
| JP2004086284A (ja) | 2004-03-18 |
| US20060152752A1 (en) | 2006-07-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US7603375B2 (en) | System and method for generating a custom application | |
| US8326837B2 (en) | Dynamically generating a portal site map | |
| JP4068921B2 (ja) | ユーザ端末にウェブ・サービスを提供するサーバ、方法、コンピュータ・プログラム、記憶媒体、ネットワーク・システム | |
| US7630974B2 (en) | Multi-language support for enterprise identity and access management | |
| US20030167298A1 (en) | Method, system, and article of manufacture for implementing security features at a portal server | |
| US20210326537A1 (en) | Secure Translation of Sensitive Content | |
| US20080318199A1 (en) | Computer systems and method for educational use | |
| US20110225505A1 (en) | User Specific Focus Parameters | |
| US20070192485A1 (en) | Method, system, and computer program product for preventing a web browser from loading content from undesirable sources | |
| WO2004019215A1 (ja) | クライアントサーバシステムのログイン方法、コンピュータプログラムおよび記録媒体 | |
| US20050114523A1 (en) | Computer-implemented method, system and program product for providing real-time access to information on a computer system over a network | |
| Wempen | Computing fundamentals: IC3 edition | |
| US20050273717A1 (en) | System and method for improved managing of profiles in a web portal environment | |
| Song | The Self-Taught Cloud Computing Engineer: A comprehensive professional study guide to AWS, Azure, and GCP | |
| Wiggins | The University of Minnesota's Internet Gopher System: A tool for accessing network-based electronic information | |
| JP2002183203A (ja) | 情報検索方法及び情報記憶媒体 | |
| JP2001273180A (ja) | 個別ユーザごとにファイルアクセスのための環境設定が可能なシステム | |
| Gehne et al. | Technology Integrated Learning Environment-A Web-based Distance Learning System. | |
| Khan et al. | An Online Law Library Database for Legal Cases of Bangladesh for Study Purpose for Lawyers and Law Students | |
| Luo et al. | Using Single Sign-On Authentication with Multiple Open OnDemand Accounts: A Solution for HPC Hosted Courses | |
| US20050015465A1 (en) | System and method for client aware request dispatching in a portal server | |
| KR100379406B1 (ko) | 인터넷을 통한 멀티 검색 장치 및 방법 | |
| US20030103068A1 (en) | Universal server farm mass custom design tool | |
| Wempen | Computing fundamentals: Introduction to computers | |
| Mac Callum | Mobile Discussion Boards: An Analysis on Mobile Collaboration. |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CO CR CU CZ DE DK DM DZ EC EE ES FI GB GD GE GH GM HR HU ID IL IN IS KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ OM PH PL PT RO RU SC SD SE SG SK SL TJ TM TN TR TT TZ UA UG US UZ VC VN YU ZA ZM ZW |
|
| AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZM ZW AM AZ BY KG KZ MD RU TJ TM AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IT LU MC NL PT RO SE SI SK TR BF BJ CF CG CI CM GA GN GQ GW ML MR NE SN TD TG |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
| ENP | Entry into the national phase |
Ref document number: 2006152752 Country of ref document: US Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 10525330 Country of ref document: US |
|
| 122 | Ep: pct application non-entry in european phase | ||
| WWP | Wipo information: published in national office |
Ref document number: 10525330 Country of ref document: US |