WO2010074094A1 - 情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム - Google Patents

情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム Download PDF

Info

Publication number
WO2010074094A1
WO2010074094A1 PCT/JP2009/071345 JP2009071345W WO2010074094A1 WO 2010074094 A1 WO2010074094 A1 WO 2010074094A1 JP 2009071345 W JP2009071345 W JP 2009071345W WO 2010074094 A1 WO2010074094 A1 WO 2010074094A1
Authority
WO
WIPO (PCT)
Prior art keywords
management
information
child
office box
post office
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2009/071345
Other languages
English (en)
French (fr)
Inventor
宮崎 真悟
朗人 丹羽
森尻 智昭
和也 橋本
美奈子 小川
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Toshiba Corp
Toshiba Digital Solutions Corp
Original Assignee
Toshiba Corp
Toshiba Solutions Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Toshiba Corp, Toshiba Solutions Corp filed Critical Toshiba Corp
Priority to CN200980152350.7A priority Critical patent/CN102265286B/zh
Publication of WO2010074094A1 publication Critical patent/WO2010074094A1/ja
Priority to US13/167,860 priority patent/US8478724B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/552Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/20Information retrieval; Database structures therefor; File system structures therefor of structured data, e.g. relational data
    • G06F16/27Replication, distribution or synchronisation of data between databases or within a distributed database system; Distributed database system architectures therefor
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • G06F16/40Information retrieval; Database structures therefor; File system structures therefor of multimedia data, e.g. slideshows comprising image and additional audio data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L51/00User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail
    • H04L51/42Mailbox-related aspects, e.g. synchronisation of mailboxes
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L69/00Network arrangements, protocols or services independent of the application payload and not provided for in the other groups of this subclass

Definitions

  • the present invention relates to an information life cycle management system, an information management server device, an information medium control device, and a program that can prevent the occurrence of a time when the information life cycle of a child management file cannot be managed.
  • This type of technology includes, for example, a system that manages a history of printing and discarding a paper document to which an ID (identification) is assigned (see, for example, JP-A-2005-190365), or an identifier for print image data.
  • a system see, for example, JP-A-2007-88796, that manages document disposal information such as collection and disposal is known.
  • an information life cycle management technique has been proposed by the present inventor in Japanese Patent Application No. 2008-27776 which is an unpublished prior application at the time of basic application of this application.
  • a unique ID for individually identifying “information holding medium” (hereinafter referred to as “information medium”) such as digital data or physical medium is assigned to the original information and information medium.
  • information medium such as digital data or physical medium
  • centralized system management is performed by associating information media creation / disposal, interrelationships (systems and medium types), and medium usage conditions with the original information.
  • the physical medium is a superordinate concept such as paper, CDROM, DVD, SD card, and FD, and is a physical information medium that is not related to a method of holding information.
  • the requested client wants to pass this child management file to another client, it is via a system that is not under the control of the information lifecycle management system (central system management system), such as via e-mail, shared folder, or portable storage.
  • central system management system central system management system
  • the other client sends a processing completion notification indicating that the child management file has been received to the management server.
  • the management server manages the information life cycle of the child management file with the location of the child management file as the other client.
  • such an information life cycle management technique is based on information life cycle management when a client who has requested replication of a management file wants to pass a child management file to another client. There is room for improvement in that it is temporarily out of management by the system and the information life cycle of the child management file cannot be managed.
  • An object of the present invention is to provide an information life cycle management system, an information management server device, and an information management server device that can manage the information life cycle of a child management file even when a client that has requested replication of the management file wants to pass the child management file to another client.
  • An object is to provide an information medium control device and a program.
  • One aspect of the present invention is an information life cycle management system including a plurality of information medium control devices and an information management server device that can communicate with each other, and each of the information medium control devices includes a management ID and an electronic data body.
  • a management file management table storage means for storing a management file management table in which a child management file including the management information is written, means for transmitting new registration request information including the electronic data body to be managed to the information management server apparatus, Means for transmitting copy registration request information including a management ID corresponding to electronic data and a post office box ID corresponding to an information medium control device of a copy acquisition destination to the information management server device; and a post office box check request including the post office box ID Means for transmitting to the information management server device, and in the PO box confirmation information received from the information management server device;
  • the issued child management ID is registered in the system management table in association with the same management ID, and this child management ID is associated with the post office box ID in the replication registration request and registered in the post office box management table.
  • the entity ID corresponding to the child management ID in the copy acquisition request is read from the system management table
  • the electronic data body corresponding to the entity ID is read from the data source management table
  • one aspect of the present invention represents a collection of devices as a system
  • the present invention is not limited thereto, and a device, a method, a program, or a program is stored for each collection of devices or for each device. It can be expressed as a computer-readable storage medium.
  • the information In the management server device based on the copy registration request information received from one information medium control device, the child data management ID of the electronic data and the post office box ID from which the child management file is acquired are registered in the post office box management table, Based on the table, the child management file is acquired by the information medium control device of the other acquisition destination.
  • the information life cycle of the child management file can be managed even when the client who requested the replication of the management file wants to pass the child management file to another client.
  • the information life cycle of the child management file can be managed even when the client who has requested the replication of the management file wants to pass the child management file to another client.
  • FIG. 1 is a schematic diagram showing a configuration of an information life cycle management system according to each embodiment of the present invention.
  • FIG. 2 is a configuration example of a management file in the system.
  • FIG. 3 is a schematic diagram showing the configuration of the information life cycle management system according to the first embodiment of the present invention.
  • FIG. 4 is a schematic diagram showing the configuration of the information management DB in the embodiment.
  • FIG. 5 is a schematic diagram showing a configuration of a management ID table in the embodiment.
  • FIG. 6 is a schematic diagram showing a configuration of a system management table in the same embodiment.
  • FIG. 7 is a schematic diagram showing the configuration of the post office box management table in the embodiment.
  • FIG. 8 is a schematic diagram showing the configuration of an access log table in the same embodiment.
  • FIG. 1 is a schematic diagram showing a configuration of an information life cycle management system according to each embodiment of the present invention.
  • FIG. 2 is a configuration example of a management file in the system.
  • FIG. 3 is a schematic
  • FIG. 9 is a schematic diagram showing a configuration of a master policy table in the same embodiment.
  • FIG. 10 is a schematic diagram showing a configuration of a client management table in the embodiment.
  • FIG. 11 is a schematic diagram showing a configuration of a data original management table in the embodiment.
  • FIG. 12 is a schematic diagram showing the configuration of the management client DB in the same embodiment.
  • FIG. 13 is a schematic diagram for explaining the operation of new registration in the embodiment.
  • FIG. 14 is a schematic diagram for explaining the operation of new registration in the embodiment.
  • FIG. 15 is a schematic diagram for explaining the operation of new registration in the embodiment.
  • FIG. 16 is a schematic diagram for explaining the operation of new registration in the embodiment.
  • FIG. 17 is a schematic diagram for explaining the operation of new registration in the embodiment.
  • FIG. 18 is a schematic diagram for explaining the copy registration operation in the embodiment.
  • FIG. 19 is a schematic diagram for explaining a copy registration operation in the embodiment.
  • FIG. 20 is a schematic diagram for explaining the copy registration operation in the embodiment.
  • FIG. 21 is a schematic diagram for explaining the copy registration operation in the embodiment.
  • FIG. 22 is a schematic diagram for explaining the operation of copy registration in the embodiment.
  • FIG. 23 is a schematic diagram for explaining an operation of copy registration in the embodiment.
  • FIG. 24 is a schematic diagram for explaining a copy registration operation in the embodiment.
  • FIG. 25 is a schematic diagram for explaining a copy registration operation in the embodiment.
  • FIG. 26 is a schematic diagram for explaining a copy registration operation in the embodiment.
  • FIG. 27 is a schematic diagram for explaining a copy acquisition operation in the embodiment.
  • FIG. 28 is a schematic diagram for explaining a copy acquisition operation according to the embodiment.
  • FIG. 29 is a schematic diagram for explaining a copy acquisition operation in the embodiment.
  • FIG. 30 is a schematic diagram for explaining a copy acquisition operation according to the embodiment.
  • FIG. 31 is a schematic diagram for explaining a copy acquisition operation in the embodiment.
  • FIG. 32 is a schematic diagram for explaining a copy acquisition operation in the embodiment.
  • FIG. 33 is a schematic diagram for explaining a copy acquisition operation according to the embodiment.
  • FIG. 34 is a schematic diagram showing a configuration of an information life cycle management system according to the second embodiment of the present invention.
  • FIG. 35 is a schematic diagram showing a configuration of an information life cycle management system according to the third embodiment of the present invention.
  • Each of the following devices can be implemented for each device with either a hardware configuration or a combination configuration of hardware resources and software.
  • the software combination configuration as shown in FIG. 1, in advance from the network or a storage medium M, M1-Mm, is installed in the corresponding device 101, 201 1 to 201 m of a computer, a corresponding device 101, 201 1 - A program for realizing a 201 m function is used.
  • FIG. 1 is a schematic diagram showing a configuration of an information life cycle management system according to each embodiment of the present invention.
  • an information management server device 101 for centrally managing information media and a plurality of information media control devices 201 1 to 201 m for using information media managed in a centralized system are mutually connected.
  • the configuration is communicable.
  • an arbitrary information medium control device is represented as “information medium control device 201”.
  • the information medium control apparatus 201 has a general configuration excluding various authentication functions and log storage functions, and includes a storage device that stores a management file management table and the following functions (f201-1) to (f201-5). ). In the management file management table, a child management file including a management ID and an electronic data body is written.
  • (F201-1) A function of transmitting new registration request information including the electronic data body to be managed to the information management server apparatus 101.
  • (F201-2) A function of transmitting, to the information management server apparatus 101, copy registration request information including a management ID corresponding to electronic data to be copied and registered, and a post office box ID corresponding to the information medium control apparatus 201 as a copy acquisition destination.
  • (F201-3) A function to send a post office box check request including the post office box ID to the information management server apparatus 101.
  • (F201-5) A function to write the child management file received from the information management server device to the management file management table.
  • the information management server device 101 has a generalized configuration excluding various authentication functions and log storage functions.
  • the information management server device 101 includes a storage device that stores a system management table, a data original management table, and a post office box management table, and the following functions (f101 -1) to (f101-5).
  • the system management table the management ID and the entity ID are written in association with each other, and the child management ID is written in association with the management ID.
  • the entity ID and the electronic data body are written.
  • the post office box management table is written with the post office box ID and the child management ID associated with each other.
  • a child management ID different from the management ID in the replication registration request information is issued, and the management ID in the replication registration request information is the same as the management ID in the system management table.
  • the issued child management ID is registered in the system management table in association with the management ID, and the child management ID is registered in the post office box management table in association with the post office box ID in the replication registration request.
  • the child management ID corresponding to the post office box ID in the post office box check request is read from the post office box management table and the post office box confirmation information including the child management ID is transmitted to the information medium controller 201. function.
  • the entity ID corresponding to the child management ID in the copy acquisition request is read from the system management table, the electronic data body corresponding to this entity ID is read from the data source management table, A function for generating a child management file including a child management ID and an electronic data body.
  • (F101-5) A function of deleting the child management ID from the post office box management table and transmitting the child management file to the information medium control device 201.
  • the information medium means a “medium holding information” such as electronic data or a physical medium (paper medium, recording medium, etc.).
  • a CDROM, DVD, SD card, FD or the like can be used.
  • each of the information medium control devices 201 1 to 202 m can be realized as long as it can input electronic data.
  • each of the information medium control devices 201 1 to 202 m includes a mobile phone, a PC (Personal Computer), a digital multifunction peripheral, a printer, a copier / scanner, a shredder, a microfilm reader, a DVD, depending on the information medium to be used. It is realized as various devices such as a reader and a multi-drive, and operates in cooperation with the information management server device 101.
  • a unique management ID (Identification) for individual identification of the information medium described above is given, and information medium creation / disposal based on the management ID, interrelationship (system or medium) Type), and the status related to medium usage is linked to the original information and managed in a unified system.
  • the information life cycle management system converts the electronic data into an electronic file in a file format including a management ID.
  • the converted electronic file is called a management file.
  • the management file includes header information including a management ID and attribute information, a usage control policy, and authentication information for the management file, in addition to the electronic data body of the target information.
  • the management file includes a header part, a usage control policy part, a body part, and a data authentication part.
  • the header section includes a management ID of the electronic data, a management ID of the parent information medium, a generation number, a medium type, file information, file storage information, and information management server information.
  • the configuration of the header portion is not limited to this.
  • the management ID of the parent information medium for example, the management ID of the original electronic data when the electronic data is copied, the management ID of the original electronic data when printing the electronic data and outputting the paper medium, and the paper medium with a scanner
  • the management ID assigned to the paper medium when converted to electronic data is used.
  • the generation number is a generation value indicating how many generations the management file corresponds to in the system relationship in which the management file is managed with the parent, child, and grandchild starting from the management file first registered in the management system. For example, if the generation number of the management file corresponding to the parent is 1, the generation number of the child information medium corresponding to the duplication is 2, and the generation number of the grandchild information medium corresponding to the duplication of the child information medium is 3.
  • the expression format of the generation number is not limited to this.
  • the file information includes the file format, file size, creator information, creation date information, and creation location information of the electronic data.
  • the file storage information includes information indicating whether or not the electronic data main body stored in the body portion is encrypted, and if encrypted, further includes information on the encryption algorithm, the encryption key, and the encryption module. It is out.
  • Information management server information is information for verifying the MAC address, IP address, URI, and authentication data part of the information management server. As information for verifying the authentication data portion, encryption key information or an encryption key certificate related to the key may be stored.
  • the usage control policy section stores usage control policy information related to usage restrictions in which processing of the electronic file permitted or prohibited for the usage conditions of the electronic file is described.
  • examples of the usage conditions include a usage time limit, available location information and network environment, user and available device information, usage count, and the like.
  • the body part stores the electronic data itself or encrypted data obtained by performing encryption processing on the electronic data.
  • the data authentication unit stores authentication data information obtained by performing an encryption process on the header unit, the usage control policy unit, and the body unit.
  • data authentication information digital signatures using public key cryptography such as DSA (Digital Signature Algorithm), RSA (Rivest-Shamir-Adleman Scheme), ECDSA (Elliptic Curves DSA), MAC using hash function or common key cryptography (Message (Authentication Code) can be used.
  • FIG. 3 is a schematic diagram showing the configuration of the information life cycle management system according to the first embodiment of the present invention.
  • one information management server device 101 and one arbitrary unit The information medium control device 201 is shown.
  • the information medium control devices 201 1 to 201 m shown in FIG. 1 have the same functions as the information life cycle management system, although the functions unique to the devices such as the mobile phone and the PC are different from each other. Therefore, an arbitrary information medium control device 201 is shown as a representative example.
  • the information management server apparatus 101 includes a management request receiving unit 111, an information management control unit 112, a context authentication unit 113, an information management DB control unit 114, a management file generation unit 115, and an information management DB 121.
  • each unit may be appropriately integrated when sending the received information as it is.
  • the management request receiving unit 111 and the information management control unit 112 may be integrated when the received information is sent as it is.
  • the respective units may be integrated as appropriate in the other devices and the following embodiments.
  • the management request accepting unit 111, the information management control unit 112, the context authentication unit 113, the information management DB control unit 114, and the management file generation unit 115 are, for example, a CPU (not shown) in the information management server device 101 described later. It is a functional block realized by executing a program including each step.
  • the information management DB 121 can be realized as a storage device readable / writable by a CPU (not shown). As shown in FIG. 4, a management ID table 1211, a system management table 1212, a post office box management table 1213, an access log management A table 1214, a master policy table 1215, a client management table 1216, and a data original management table 1217 are stored.
  • the management ID table 1211 stores the issued management ID, issue date and time, and issue request source information in association with each other. In the case of revocation, the revocation date and revocation request source information are further associated with each other.
  • the system management table 1212 includes a management ID corresponding to the parent-child relationship of the electronic data body, creation date and time information of the electronic data body, user information, medium type, usage restriction policy, location information, and entity ID. Store it in association.
  • the system management table 1212 shows the management ID newly issued for duplication and the duplicate (child) for the management ID of the electronic data body or management file of the duplication source (parent).
  • the creation date / time information, user information, medium type, usage restriction policy, location information, and entity ID in the header portion of the management file are stored in association with each other.
  • a serial number may be used as long as uniqueness in the system is guaranteed and the parent-child relationship of replication is managed in association with the management ID.
  • the management ID may be issued with a meaning so that the parent-child relationship of each management ID can be understood.
  • a value of a specific digit may be used as a parent-child relation value.
  • the lower third digit is a medium type, “1” indicates electronic data, “2” indicates a paper medium, and “3” indicates a recording medium.
  • the first and second digits are identification numbers for the same generation and the same medium type.
  • the lower 5th to 8th digits (# and 3 digits to the right of it) are electronic data IDs. If the management file has the same electronic data ID, it contains the same electronic data regardless of the parent and child. Yes.
  • the devices X, Y, Z and the employee B in the location information correspond to any one of the information medium control devices 201 x , 201 y , 201 z , 201 B , so the information medium control devices 201 x , 201 y , It may be read as 201 z and 201 B.
  • a management file is not created for the highest parent indicated by the parent-child relationship value “0”.
  • a management file is created for the parent indicated by the parent-child relationship value “1” or higher.
  • the entity ID is information for identifying the electronic data body (data original). When the electronic data is duplicated, unlike the management ID described above, the entity ID of the duplication source (parent) and the duplicate (child) The entity ID is the same as each other.
  • the post office box management table 1213 is a management ID list that lists, for each post office box ID, a posting number (acquisition number) that indicates the number of child management files to be acquired and management IDs of the child management files to be acquired. Are stored in association with each other.
  • the post office box ID is described as an example in which the post office box ID is assigned to each information medium control apparatus 201. However, the present invention is not limited thereto, and any post office box ID may be configured to be able to specify an arbitrary post office box ID.
  • the access log management table 1214 includes a client ID, an operation type, a management ID, and a processing status for each operation date and time.
  • the client ID is an ID indicating the operated employee, and may be read as an operator ID or an employee ID.
  • the operation type indicates the type of operation such as login status, new registration, electronic data replication, browsing, and deletion.
  • the management ID is a management ID indicating the operated electronic data.
  • the process status is status information indicating a process result such as success or failure (authentication error or the like) of the process indicated by the operation type.
  • the contents managed by the access log management table 1214 may also use the location information (internal / external, GPS information) of the device that has been operated on the target management file, as shown in FIG. It is not limited to information.
  • the master policy table 1215 stores a policy type and a rejection / permission policy in association with each other for each policy number.
  • the policy number is policy identification information and may be read as a policy ID.
  • the policy type is information indicating the type of object to be controlled by the rejection / permission policy. For example, location control, time control, authority control, etc. can be used as appropriate.
  • the rejection / permission policy is information indicating a determination condition and control contents when the determination condition is satisfied.
  • the control content includes an object to be permitted or rejected (such as a command or a request), and may include processing such as in-house wired connection or in-house wireless connection.
  • the client management table 1216 stores the client ID, employee number, authority class, terminal type, and MAC address in association with each other.
  • the data original management table 1217 stores an entity ID, a file name, a size, a hash value, an electronic data body, and external storage information in association with each other.
  • the entity ID is identification information of the electronic data body (data original).
  • the file name is the file name of the management target data body (electronic data body) stored in the management file.
  • the size is the file size of the management target data body stored in the management file.
  • the hash value is a hash value of the management target data body stored in the management file.
  • the electronic data body is a management target data body stored in the management file.
  • the external storage information is storage destination information when the management target data body is stored outside the information management DB 121. In the present embodiment, external storage information is not used.
  • the information medium control apparatus 201 includes a host system unit 211, a request reception unit 212, an information medium management unit 213, a context information acquisition unit 214, a management request transmission unit 215, and a management file control unit 216. And a management client DB 217.
  • the request reception unit 212, the information medium management unit 213, the management request transmission unit 214, and the management file control unit 216 may be integrated when the received information is transmitted as it is.
  • the host system unit 211, the request reception unit 212, the information medium management unit 213, the context information acquisition unit 214, the management request transmission unit 215, and the management file control unit 216 are, for example, an information medium control described later by a CPU (not shown).
  • the function block is realized by executing a program including each step in the apparatus 201.
  • the management client DB 217 can be realized as a storage device that can be read / written by a CPU (not shown).
  • the management client DB 217 is a storage device that can be accessed from the management file control unit 216.
  • a file management table 2171 and an access log table 2172 are stored.
  • the management file management table 2171 For each management ID, the management file management table 2171 has status information (eg, browsing,-(deprecated), available, etc.), management file attribute information (creation date information and abolition date information if abolished) And a management file entity.
  • management file attribute information partial information of the management file header portion is used.
  • the management ID corresponding to the top parent electronic data body of the management file or the management file of the replication source is shown.
  • a management ID is available.
  • the “replication source management file” means “a parent management file that is a source of a child management file for replication”.
  • the description range of the management file attribute information is not limited to the partial information of the management file header part, and various forms are possible based on the environment setting of the device and the regulations with the information management server device.
  • the management file attribute information may include dynamic usage information that is not described in the management file header part, such as the number of accesses to each management file by the device.
  • the management file entity may be stored in an external storage device (not shown).
  • the access log table 2172 includes an operation type, user information, a management ID, and a management file name for each operation date and time.
  • the operation type indicates the type of operation such as login status, new registration, copy registration, post office box check, copy acquisition, browsing, and deletion.
  • the management ID is a management ID indicating the operated electronic data.
  • the management file name is, for example, information obtained by concatenating an extension indicating the file format of the electronic data to the management ID of the electronic data.
  • the contents managed by the access log table 2171 may also use the location information (internal / external, GPS information) of the device in which an operation is performed on the target management file, as well as the information shown in FIG. It is not limited to.
  • the information medium control apparatus 201 transmits new registration request information including the electronic data body to be managed to the information management server apparatus 101.
  • the management ID and entity ID are issued to the electronic data body, the management ID and entity ID are registered in the system management table 1212, and the entity ID and electronic data are registered.
  • the main body is registered in the data original data management table 1217.
  • the host system unit 211 sends unregistered electronic data and a new registration request to the request receiving unit 212 by the operation of the operator (electronic data creator) (ST1).
  • the new registration request includes a usage control policy relating to usage restrictions on the electronic data, and creator information indicating the electronic data creator.
  • the creator information is user information including a client ID and an employee number, for example.
  • the request accepting unit 212 sends the electronic data and the new registration request to the information medium managing unit 213, for example, in the order of acceptance (ST2).
  • the information medium management unit 213 Upon receiving the electronic data and the new registration request, the information medium management unit 213 sends a context acquisition request for acquiring the context information necessary for the requested processing to the context information acquisition unit 214 (ST3).
  • the context information acquisition unit 214 acquires context information related to the information medium control device 201 from the operating system and related hardware of the information medium control device 201, and the context information is acquired from the information medium management unit. It is sent to 213 (ST4).
  • the context information for example, device information such as a MAC address and IP address related to the information medium control device 201, information related to a connection network such as domain information and connectable device information, and physical location information of the device such as GPS , Etc. can be used as appropriate.
  • the information medium management unit 213 Upon receiving the context information, the information medium management unit 213 sends the creator information in the new registration request and the context authentication request information including the context information to the management request transmission unit 215 (ST5).
  • the management request transmission unit 215 transmits context authentication request information to the information management server apparatus 101 (ST6).
  • the management request receiving unit 111 sends the context authentication request information to the information management control unit 112 in the order of reception, for example (ST7).
  • the information management control unit 112 sends the context authentication request information to the context authentication unit 113 and requests authentication of the context information (ST8).
  • the context authentication unit 113 When acquiring the context authentication request information, the context authentication unit 113 refers to the client management table 1216 in the information management DB 121 and refers to the authority class corresponding to the creator information (employee number) indicating the requesting user and the authority based on the connection form. Get class.
  • security authentication information such as an electronic signature or MAC is added to the context authentication request information, the validity of the security authentication information is verified.
  • the connection environment in the creator information or the context information is unknown, or when the verification result of the security authentication information indicates invalidity, determination result information indicating an error is sent to the information management control unit 112.
  • the context authentication unit 113 manages the context determination result regarding the client identity and authority.
  • the data is sent to the control unit 112 (ST9).
  • the identity of the client is the creator information described above, and the authority of the client is the authority class acquired from the client management table 1216.
  • the information management control unit 112 sends the context determination result to the management request receiving unit 111 (ST10).
  • the management request receiving unit 111 transmits the context determination result to the information medium control device 201 (ST11).
  • the management request transmission unit 215 sends the received context determination result to the information medium management unit 213 (ST12).
  • the information medium management unit 213 When the context determination result is an error, the information medium management unit 213 notifies the host system unit 211 of the error via the request input / output unit 212. If it is not an error, new registration request information of electronic data to be registered is sent to the management request transmission unit 215 (ST13).
  • the new registration request information includes electronic data to be registered and a usage control policy relating to usage restrictions on the electronic data.
  • the management request transmission unit 215 transmits new registration request information to the information management server apparatus 101 (ST14).
  • the management request receiving unit 111 sends new registration request information to the information management control unit 112 (ST15).
  • the information management control unit 112 sends new registration processing request information including the new registration request information and the context determination result to the information management DB control unit 114, and requests a new registration process of electronic data (ST16).
  • the information management DB control unit 114 Upon receipt of the new registration processing request information, the information management DB control unit 114 collates the new registration processing request information with the master policy table 1215 of the information management DB 121, and as a result of the collation, permission / rejection in the master policy table 1215 is confirmed. Only when it is permitted or not rejected by the policy, double registration confirmation is executed as to whether or not the target electronic data has already been registered.
  • the context determination result in the new registration processing request information is collated with the master policy table 1215 of the information management DB 121, and information on the client identity and authority in the context determination result is collated. Is permitted or not rejected by the permission / rejection policy of the master policy table 1215, and other information such as the request reception time and the IP address of the information medium control device 201 is also permitted or not rejected by the permission / rejection policy. Only in some cases, the process proceeds to the double registration confirmation process.
  • a hash value of electronic data newly registered in the past is registered in advance in the system management table 1212 of the information management DB 121, and a hash value of electronic data to be newly registered this time is calculated. Then, it is confirmed that the hash value does not exist in the system management table 1212.
  • the information management DB control unit 114 issues a management ID and an entity ID for the data, and a management ID including the management ID, issue date and issue request source information
  • the issue information is registered in the management ID table 1211 in the information management DB 121.
  • the information management DB control unit 114 associates the issued entity ID, the file name of the electronic data body, the size (file size) of the electronic data body, the hash value of the electronic data body, and the electronic data body with each other to associate with each other. Register at 1217.
  • the information management DB control unit 114 registers access log information including date and time, client ID, operation type, management ID, and processing status in the access log management table 1214 in the information management DB 121.
  • the information management DB control unit 114 After registration, the information management DB control unit 114 sends new registration processing result information including the management ID to the information management control unit 112 (ST17).
  • the new registration processing result information includes information for registration in each table 2171 and 2172 in the management client DB 217, and specifically includes a management ID, a date and an operation type.
  • the information management control unit 112 sends the new registration processing result information to the management request receiving unit 111 (ST18).
  • the management request receiving unit 111 transmits new registration processing result information to the information medium control device 201 (ST19).
  • the management request transmission unit 215 sends new registration processing result information to the information medium management unit 213 as shown in FIG. 17 (ST20).
  • the information medium management unit 213 sends the new registration processing result information to the management file control unit 216, and requests to register the processing result in the management client DB 217 (ST21).
  • the management file control unit 216 registers the management ID and status in the management file management table 2171 in order to reflect the status with the management ID as the primary key to the management client DB 217 based on the new registration processing result information.
  • the management file control unit 216 registers a newly registered operation log including operation date / time information, operation type, and management ID in the access log table 2172 of the management client DB 217 in order to reflect the operation log in the management client DB 217. To do.
  • the management file control unit 216 sends a registration process completion notification to the information medium management unit 213 (ST22).
  • the information medium management unit 213 Upon receiving the registration processing completion notification, the information medium management unit 213 requests the management request transmission unit 215 to disconnect communication with the information management server device 101 (ST23).
  • the management request transmission unit 215 disconnects communication with the information management server apparatus 101 and sends a completion notification to the information medium management unit 213 (ST24).
  • the information medium management unit 213 sends a new registration process completion notification of newly registered electronic data to the request input / output unit 212.
  • the management ID issued for the electronic data may be included in the new registration process completion notification (ST25).
  • the request input / output unit 212 sends a new registration process completion notification to the host system unit 211 and completes the process (ST26).
  • the information medium control apparatus 201 transmits, to the information management server apparatus 101, copy registration request information including a management ID corresponding to the electronic data to be copied and registered, and a post office box ID corresponding to the information medium control apparatus 201 that is the copy acquisition destination.
  • the information management server apparatus 101 Upon receiving the copy registration request information, the information management server apparatus 101 issues a child management ID different from the management ID in the copy registration request information, and among the management IDs in the system management table 1212, the copy registration request information The issued child management ID is registered in the system management table 1212 in association with the same management ID as that in the post office box management table 1216, and the child management ID is associated with the post office box ID in the replication registration request. And the copy registration processing result information including the child management ID is transmitted to the information medium control apparatus 201 that is the transmission source of the copy registration request information.
  • duplication registration operation will be described in detail including various authentication operations.
  • the host system unit 211 sends a usage control policy acquisition request to the request input / output unit 212 for acquiring the usage control policy of the electronic data body corresponding to the management ID to be duplicated by the operation of the operator.
  • Send out (ST31).
  • the usage control policy acquisition request includes user information related to the user who makes the acquisition request and a management ID corresponding to the electronic data body to be requested. It may include location information of the information medium control device 201, IP address, MAC address, and connection network usage environment information. This management ID is called a parent management ID.
  • the information medium control apparatus 201 and the information management server apparatus 101 execute the same processing as the electronic data new registration processing ST2 to ST12 to authenticate the context information (ST32 to ST42). ).
  • the information medium management unit 213 When the context determination result is an error, the information medium management unit 213 notifies the host system unit 211 of the error via the request input / output unit 212. If it is not an error, the usage control policy acquisition request information is sent to the management request transmission unit 215 (ST43).
  • the usage control policy acquisition request information includes user information, parent management ID, location information, and usage environment information.
  • the management request transmission unit 215 transmits usage control policy acquisition request information including the parent management ID to the information management server apparatus 101 (ST44).
  • the management request receiving unit 111 sends usage control policy acquisition request information to the information management control unit 112 as shown in FIG. 21 (ST45).
  • the information management control unit 112 sends usage control policy acquisition request information to the information management DB control unit 114, and requests a usage control policy related to the parent management ID (ST46).
  • the information management DB control unit 114 Upon receipt of the usage control policy acquisition request information, the information management DB control unit 114 compares the usage control policy acquisition request information with the master policy table 1215 of the information management DB 121, and as a result of the verification, permission in the master policy table 1215 is obtained. When it is permitted or not rejected by the rejection policy, it is determined that the usage control policy can be transmitted.
  • This verification processing is, for example, a case where user information or usage environment information included in the usage control policy acquisition request information is permitted or not rejected by the permission / rejection policy of the master policy table 1215, and the request reception time. It is determined that the usage control policy can be transmitted only when other information such as “Allow / Reject” is permitted or not rejected.
  • the information management DB control unit 114 reads the usage control policy for the parent management ID in the usage control policy acquisition request information from the system management table 1212 in the information management DB 121, and determines the usage control policy and master policy. The result is sent to the information management control unit 112 (ST47).
  • the information management control unit 112 sends the usage control policy and the master policy determination result to the management request receiving unit 111 (ST48).
  • the management request receiving unit 111 transmits the usage control policy and the master policy determination result to the information medium control apparatus 201 (ST49).
  • the management request transmission unit 215 when the management request transmission unit 215 receives the usage control policy and the master policy determination result, the management request transmission unit 215 transmits a session disconnection request to the information management server apparatus 101 and disconnects communication with the information management server apparatus 101. To do.
  • the management request transmission unit 215 transmits the usage control policy and the master policy determination result to the information medium management unit 213 (ST50).
  • the order of the disconnection process and the information transmission process to the information medium management unit 213 may be any.
  • the information medium management unit 213 collates the usage control policy corresponding to the parent management ID with the user information and the usage environment information, and determines whether or not there is an authority to execute the replication registration process. If there is an execution right, the information medium management unit 213 sends a usage control policy setting request for the child management file that is electronically copied and derived from the electronic data body indicated by the entity ID corresponding to the parent management ID to the request input / output unit 212. Send out (ST51).
  • the request input / output unit 212 sends a usage control policy setting request to the upper system unit 211 (ST52).
  • the upper system unit 211 Upon receiving the usage control policy setting request, the upper system unit 211 sets the usage control policy for the child management file by the user operation.
  • the usage control policy for the child management file defines a system policy that is determined within the limitation of the usage control policy corresponding to the parent management ID.
  • the usage control policy for each child management file may be common, or as appropriate according to the acquisition destination of the child management file. Different settings may be used.
  • the usage control policy need not be set by the user, and may be a program that sets an appropriate policy according to the situation and environment.
  • the upper system unit 211 copies the parent management ID, the acquisition destination information of the child management file, the post office box ID, the usage control policy corresponding to the parent management ID, and the usage control policy of the child management file. Registration request information is sent to request input / output section 212 (ST53).
  • the request input / output unit 212 sends copy registration request information to the information medium management unit 213 (ST54).
  • the information medium management unit 213 determines whether the usage control policy of the child management file is within the restrictions of the usage control policy corresponding to the parent management ID. If the constraint is violated, correct the usage control policy of the child management file again or output an error and terminate the process. If the constraint is not violated, as shown in FIGS. 22 to 24, context authentication processing is executed in the same manner as ST33 to ST42, and a communication session is established through authentication processing with the information management server apparatus 101 (ST55 to ST64).
  • the information medium management unit 213 sends copy registration request information to the management request transmission unit 215 (ST65).
  • the parent management file usage control policy is held by the information management server 101 and need not be transmitted.
  • the management request transmission unit 215 transmits replication registration request information to the information management server 101 (ST66).
  • the management request receiving unit 111 sends copy registration request information to the information management control unit 112 as shown in FIG. 25 (ST67).
  • the information management control unit 112 sends a copy registration processing request including the copy registration request information to the information management DB control unit 114 (ST68), issues a child management ID based on the copy registration request information, and manages it in the information management DB 121.
  • the information management DB control unit 114 When receiving the replication registration processing request, the information management DB control unit 114 refers to the master policy table 1215 in the information management DB 121 and determines whether or not the requested replication registration processing can be executed. If the master policy is not violated, whether the information medium control device 201 or the processing requester of the device has the authority to perform replication registration in the situation or environment at the time of the request, the usage control policy of the child management file is set as the parent management ID It is determined whether or not the process can be executed, including items such as whether the corresponding usage control policy is within the restriction. The determination may include a determination item indicating whether the child management file to be issued is within a generation range in which derivation is permitted from the starting point of the target management ID or whether the derivation number exceeds the upper limit.
  • the information management DB control unit 114 issues a child management ID, and manages the management ID issuance information including the child management ID, issue date and time, and issue request source information in the information management DB 121. Register in the ID table 1211.
  • the information management DB control unit 114 registers the child management ID in the system management table 1212 in association with the parent management ID, and associates the acquisition information of the child management file with the child management ID in the system management table 1212 as location information. sign up.
  • the information management DB control unit 114 registers the child management ID in the post office box management table 1213 in association with the post office box ID in the replication registration request information, and sets the number of registered child management IDs for each designated post office box. It writes in the post office box management table 1213 as a posting number.
  • the information management DB control unit 114 registers access log information including date and time, client ID, operation type, management ID, and processing status in the access log management table 1214 in the information management DB 121.
  • the information management DB control unit 114 executes the same processing for each of the plurality of child management IDs issued.
  • the information management DB control unit 114 sends the copy registration processing result information including the issued child management ID to the information management control unit 112 (ST69).
  • the copy registration processing result information includes information for registration in the access log table 2172 in the management client DB 217, specifically, includes a child management ID, date and time, and operation type, and includes a management file name. Not.
  • the information management control unit 112 sends the copy registration processing result information to the management request receiving unit 111 (ST70).
  • the management request receiving unit 111 transmits the copy registration processing result information to the information medium control apparatus 201 as a response to the copy registration request (ST71). If the process fails, error information is transmitted.
  • the management request transmission unit 215 sends the received replication registration processing result information to the information medium management unit 213 as shown in FIG. 26 (ST72). At the same time, a communication session disconnection request is transmitted to the information management server apparatus 101 to disconnect the communication.
  • the information medium management unit 213 sends the copy registration processing result information to the management file control unit 216, and requests to register the processing result in the management client DB 217 (ST73).
  • the management file control unit 216 registers a copy registration operation log including operation date and time information, operation type, and child management ID in the access log table 2172 of the management client DB 217 based on the copy registration processing result information.
  • the management file control unit 216 sends a copy registration process completion notification to the information medium management unit 213 (ST74).
  • the information medium management unit 213 receives the copy registration process completion notification and sends the copy registration completion notification to the request input / output unit 212 (ST75).
  • the request input / output unit 212 sends a copy registration completion notification to the host system unit 211, and ends a series of copy registration request sessions (ST76).
  • the host system unit 211 Upon receiving the copy registration completion notification, the host system unit 211 transmits the copy registration completion notification to the acquisition destination information medium control device 201 by, for example, an operation of the operator, thereby confirming that there is copy registration of electronic data. You may notify to the information medium control apparatus 201 of an acquisition destination. In this case, the host system unit 211 of the information medium control apparatus 201 of the acquisition destination easily confirms the presence / absence of replication registration for the information medium control apparatus 201, triggered by the operation of the operator or the confirmation setting in the time period. It becomes possible.
  • the present invention is not limited to this, for example, the operator of the information medium control apparatus 201 that has registered for duplication can use the contact means such as oral, telephone, FAX, or e-mail to the operator of the information medium control apparatus 201 of the acquisition destination. You may be informed that there is a copy registration.
  • the information medium control apparatus 201 transmits a post office box check request including the post office box ID to the information management server apparatus 101.
  • the information management server apparatus 101 Upon receiving the post office box check request, the information management server apparatus 101 reads out the child management ID corresponding to the post office box ID in the post office box check request from the post office box management table 1216 and requests the post office box check information including the child management ID. To the information medium control apparatus 201 of the transmission source.
  • the information medium control device 201 transmits a copy acquisition request including the child management ID corresponding to the copy acquisition target management file to the information management server device 101 among the child management IDs in the post office box confirmation information.
  • the entity ID corresponding to the child management ID in the copy acquisition request is read from the system management table 1212 and the electronic data body corresponding to this entity ID is managed in the original data.
  • Read from the table 1217 generate a child management file including the child management ID and the electronic data body, delete the child management ID from the post office box management table 1216, and control the information medium of the transmission source of the copy acquisition request.
  • the information medium control apparatus 201 writes this child management file in the management file management table 2171.
  • the host system unit 211 confirms the presence or absence of replication registration for the information medium control apparatus 201, triggered by the operation of the operator or the confirmation setting in the time period.
  • a request for acquisition of copy-registered electronic data (hereinafter referred to as a copy acquisition request) is sent to request input / output section 212 (ST81).
  • the copy acquisition request includes user information of the user who makes the acquisition request.
  • This copy acquisition request may include location information and usage environment information of the information medium control apparatus 201, and may include a post office box ID corresponding to the information medium control apparatus 201.
  • the request input / output unit 212 sends a copy acquisition request to the information medium management unit 213 (ST82).
  • the information medium control apparatus 201 and the information management server apparatus 101 execute the same processing as the electronic data new registration processing ST3 to ST12 to authenticate the context information (ST83 to ST92). .
  • the information medium management unit 213 When the context determination result is an error, the information medium management unit 213 notifies the host system unit 211 of the error via the request input / output unit 212. If it is not an error, a post office box check request including the post office box ID of the post office box for which electronic data copy acquisition information is to be confirmed is sent to the management request transmitter 215 (ST93).
  • the post office box check process may be realized by a system configuration that accepts a request only for a post office box that is uniquely assigned to the information medium control apparatus 201. For any post office box, a system configuration that accepts a post office box check with a designated post office box ID may be used.
  • the management request transmission unit 215 transmits a post office box check request to the information management server apparatus 101 (ST94).
  • the management request reception unit 111 sends a post office box check request to the information management control unit 112 as shown in FIG. 30 (ST95).
  • the information management control unit 112 sends a post office box check request to the information management DB control unit 114, and requests processing for confirming the post office box state corresponding to the designated post office box ID (ST96).
  • the information management DB control unit 114 extracts the post office box ID from the post office box check request, and acquires the post office box confirmation information including the post office box ID, the number of postings, and the management ID list from the post office box management table 1216 of the information management DB 121.
  • the posting number is the number of management IDs registered for duplication, and is also the number of management files that can be duplicated.
  • the information management DB control unit 114 sends the acquired post office box confirmation information to the information management control unit 112 (ST97).
  • the information management control unit 112 sends the post office box confirmation information to the management request receiving unit 111 (ST98).
  • the management request receiving unit 111 transmits the post office box confirmation information to the information medium control device 201 (ST99).
  • the management request transmission unit 215 sends the post office box confirmation information to the information medium management unit 213 as shown in FIG. 31 (ST100).
  • the information medium management unit 213 confirms whether there is a management file that can be duplicated based on the number of postings or the management ID list in the post office box confirmation information. If there is no management file that can be acquired, the replication acquisition process ends. At this time, the information medium management unit 213 may request the management file control unit 216 to write the access log information to the management client DB 217. Further, the information medium management unit 213 may notify the upper system unit 211 that the management file does not exist via the request input / output unit 212. If there is an acquirable management file, the management ID of the management file to be acquired is selected from the management ID list in the post office box confirmation information, and a copy acquisition request including the management ID is sent to the management request transmission unit 215 (ST101). ).
  • the management request transmission unit 215 transmits the replication acquisition request information to the information management server 101 (ST102).
  • the management request accepting unit 111 sends copy acquisition request information to the information management control unit 112 as shown in FIG. 32 (ST103).
  • the information management control unit 112 sends the copy acquisition processing request information including the copy acquisition request information and the context determination result to the information management DB control unit 114 to generate a management file and register the parent-child relationship information in the information management DB 121.
  • the information management DB control unit 114 is requested to perform a replication acquisition process (ST104).
  • the information management DB control unit 114 Upon receiving the copy acquisition process request information, the information management DB control unit 114 compares the copy acquisition process request information with the master policy table 1215 of the information management DB 121, and as a result of the check, permission / rejection in the master policy table 1215 is confirmed. Only when the policy permits or rejects, the process proceeds to the management file generation request for the copy acquisition target. The matching process is executed in the same manner as described above.
  • the information management DB control unit 114 acquires information necessary for generating the management file from the information management DB 121 and sends a management file generation request including the information to the management file generation unit 115.
  • the information necessary for generating the management file includes a management ID that is a replication acquisition target, an electronic data body that is a management target associated with the management ID, and a usage control policy that is associated with the management ID. It is.
  • These management IDs and usage restriction policies are acquired from the system management table 1212 in the information management DB 121, for example.
  • the electronic data body is acquired from the data original management table 1217 in the information management DB 121.
  • the management file generation unit 115 when the management file generation unit 115 receives a management file generation request including the management ID, electronic data main body, and usage control policy to be replicated, the management file generation unit 115 generates a management file based on the management file generation request.
  • the management file generation procedure is, for example, as follows.
  • the management file generation unit 115 sets a management ID in the management ID area of the electronic data in the header part.
  • NULL is set to the management ID of the parent information medium in the header part.
  • a file format, file size, creator information, creation date information, and creation location information are set in the file information in the header part.
  • the management file generation unit 115 sets file storage information in the header based on the presence / absence of encryption processing, designation of encryption processing such as an encryption algorithm, encryption key, and encryption module.
  • designation of encryption processing for example, when the upper system unit 211 designates with the information of the replication acquisition request, when the information medium management unit 213 designates with the management request information of the replication acquisition, or the information management DB control unit Various forms are possible, such as when 114 is specified in the management file generation request.
  • the management file generation unit 115 sets file storage information, a usage restriction policy, and information management server information in the header part. Thereby, a header part is generated.
  • the management file generation unit 115 performs an encryption process on the electronic data based on the file storage information in the header part, and sets the obtained encrypted electronic data in the body part. Thereby, a body part is generated.
  • the management file generation unit 115 generates authentication data for the generated header part and body part based on an electronic signature scheme based on public key cryptography or a MAC scheme based on a hash function or common key cryptography. This authentication data is set in the authentication data part of the management file. As a result, a management file is created.
  • the management file generation unit 115 sends the created management file to the information management DB control unit 114.
  • the information management DB control unit 114 Upon receipt of the management file, the information management DB control unit 114 associates the management file with the management ID of the electronic data based on the management file, the management ID, and the copy acquisition processing request information, creation date / time information, creator information, medium type, usage restriction System information including policy, location information, and entity ID is registered in the system management table 1212 in the information management DB 121.
  • the management ID of the electronic data is registered in the system management table 1212 in association with the management ID of the parent information medium.
  • the management file generation unit 115 sends the generated management file to the information management DB control unit 114 (ST106).
  • the information management DB control unit 114 executes a process of registering access log information related to the management file generation process in the information management DB 121 in the access log management table 1214 and sets the post office box ID in the post office box management table 1213. A process of emptying the corresponding posting number and management ID list is executed. Thereafter, the information management DB control unit 114 sends the copy acquisition processing result information including the issued management ID, management file, date and time, and operation type to the information management control unit 112 (ST107).
  • the information management control unit 112 sends the copy acquisition processing result information to the management request receiving unit 111 (ST108).
  • the management request receiving unit 111 transmits the replication acquisition processing result information to the information medium control apparatus 201 (ST109). If the process fails, error information is transmitted.
  • the management request transmission unit 215 sends the received replication acquisition processing result information to the information medium management unit 213 as shown in FIG. 33 (ST110). At the same time, a communication session disconnection request is transmitted to the information management server apparatus 101 to disconnect the communication.
  • the information medium management unit 213 sends the copy acquisition processing result information to the management file control unit 216, and requests to register the processing result in the management client DB 217 (ST111).
  • the management file control unit 216 registers the management ID, status, management file header partial information, and management file entity in the management file management table 2171 as described above based on the replication acquisition processing result information.
  • the management file control unit 216 registers the operation log of the replication acquisition process including the operation date / time information, the operation type, the management ID, and the management file name in the access log table 2172.
  • the management file control unit 216 sends a copy acquisition process completion notification to the information medium management unit 213 (ST112).
  • the copy acquisition processing completion notification may include the management ID issued for the electronic data.
  • the information medium management unit 213 sends a copy acquisition process completion notification to the request input / output unit 212 (ST113).
  • the request input / output unit 212 sends a copy acquisition completion notification to the higher-level system unit 211 and terminates the request session (ST114).
  • the information medium control apparatus 201 that requests electronic data copy registration and the information medium control apparatus 201 that acquires a child management file generated by copy registration are separate apparatuses.
  • the post-office box management table 1216 shows the child management ID of the electronic data and the post-office box ID from which the child management file is acquired.
  • the information medium control device 201 of the other acquisition destination acquires the child management file based on the post office box management table 1216.
  • FIG. 34 is a schematic diagram showing the configuration of the information life cycle management system according to the second embodiment of the present invention. The same parts as those in FIG. The part is mainly described. In the following embodiments, the same description is omitted.
  • the present embodiment is a modification of the first embodiment, and is a form in which a post office box check is periodically and automatically performed.
  • a post office box check control unit 218 is added to the information medium control device 201 shown in FIG. It has an added configuration.
  • the post office box check control unit 218 has a function of sending a post office box check request including the post office box ID to the request input / output unit 212 periodically or when a predetermined condition is satisfied.
  • the post office box check control unit 218 sends a post office box check request to the request input / output unit 212 for a designated post office box under a time period or a predetermined condition.
  • the request input / output unit 212 sends this post-office box check request to the information medium management unit 213.
  • the post-office box confirmation result is acquired from the information medium management unit 213 through the processing of ST93 to ST100, the post-office box check control unit 218 To send.
  • the post office box check control unit 218 notifies the request input / output unit 212 that there is an acquirable management file when there is an acquirable management file based on the post office box confirmation result. Is sent out.
  • the request input / output unit 212 sends the copy acquisition possible notification to the higher system unit 211 to prompt the copy acquisition process.
  • the post-box check control unit 218 that periodically sends a post-office box check request to the request input / output unit 212 is replicated.
  • the higher-level system unit 211 can acquire the management file more quickly.
  • FIG. 35 is a schematic diagram showing a configuration of an information life cycle management system according to the third embodiment of the present invention.
  • This embodiment is a modification of the first embodiment, and based on the number of post office boxes posted and the number of stay days, acquisition of a management file staying in the information medium control device 201 corresponding to the post office box from the information management server device 101 is obtained.
  • the post office box confirmation request request unit 116 is added to the information management server apparatus 101 shown in FIG.
  • the post office box confirmation request request unit 218 has a function of sending a post office box check request including the post office box ID to the request input / output unit 212 periodically or when a predetermined condition is satisfied.
  • the post office box confirmation request requesting section 116 sends a post office box check request to the management request receiving section 111 for the designated post office box under a time period or a predetermined condition.
  • the management request receiving unit 111 acquires the post office box confirmation information through the processes of ST95 to ST98, and sends the post office box confirmation information to the post office box confirmation request request unit 116.
  • the post office box confirmation request requesting unit 116 confirms the post office box residence information such as the number of postings in the post office box and the number of days staying in the post office box. Is transmitted to the information medium control apparatus 201 from which the child management file is acquired via the management request receiving unit 111.
  • the specified condition for example, a case where the number of postings to the post office box exceeds 10 or a case where the number of days staying in the post office box exceeds 30 days can be considered.
  • the prescribed conditions are not limited to this.
  • the management request accepting unit 111 is monitored by the copy registration process, and at the same time when the child management ID arrives, the management request accepting unit 111 performs a post office box check to the information medium control device 201 that is the acquisition destination of the child management file.
  • a post office box confirmation request may be transmitted.
  • the configuration including the post office box check request requesting unit 116 that periodically sends the post office box check request to the management request receiving unit 111 can be replicated. It is possible to cause the information medium control apparatus 201 to acquire the management file thus obtained more quickly.
  • the method described in the above embodiment is a program that can be executed by a computer as a magnetic disk (floppy (registered trademark) disk, hard disk, etc.), optical disk (CD-ROM, DVD, etc.), magneto-optical disk (MO). ), And can be distributed in a storage medium such as a semiconductor memory.
  • a magnetic disk floppy (registered trademark) disk, hard disk, etc.
  • optical disk CD-ROM, DVD, etc.
  • MO magneto-optical disk
  • the storage medium can store a program and can be read by a computer
  • the storage format may be any form.
  • an OS operating system
  • MW middleware
  • database management software network software
  • the storage medium in the present invention is not limited to a medium independent of a computer, but also includes a storage medium in which a program transmitted via a LAN, the Internet, or the like is downloaded and stored or temporarily stored.
  • the number of storage media is not limited to one, and the case where the processing in the above embodiment is executed from a plurality of media is also included in the storage media in the present invention, and the media configuration may be any configuration.
  • the computer executes each process in the above-described embodiment based on a program stored in a storage medium, and includes a single device such as a personal computer or a system in which a plurality of devices are connected to a network. Any configuration may be used.
  • the computer in the present invention is not limited to a personal computer, but includes an arithmetic processing device, a microcomputer, and the like included in an information processing device, and is a generic term for devices and devices that can realize the functions of the present invention by a program. .
  • the present invention is not limited to the above-described embodiment as it is, and can be embodied by modifying components and the like without departing from the scope of the invention in the implementation stage.
  • the timing of converting the electronic data into the electronic file management file in the file format including the management ID in the information management server device 101 is not performed at the time of new registration and copy registration. It may be performed at the time of obtaining a copy, or a management file may be created before a request for obtaining a copy is made.
  • the management file can be converted prior to copy registration or copy acquisition.
  • various inventions can be formed by appropriately combining a plurality of constituent elements disclosed in the embodiment. For example, some components may be deleted from all the components shown in the embodiment. Furthermore, you may combine the component covering different embodiment suitably.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Signal Processing (AREA)
  • Databases & Information Systems (AREA)
  • Data Mining & Analysis (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Multimedia (AREA)
  • Storage Device Security (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)

Abstract

 電子データの複製登録を要求する情報媒体制御装置と、複製登録により生成された子管理ファイルを取得する情報媒体制御装置とが別々の装置の場合でも、情報管理サーバ装置(101)においては、一方の情報媒体制御装置から受けた複製登録要求情報に基づいて、電子データの子管理IDと子管理ファイルの取得先の私書箱IDとを私書箱管理テーブルに登録し、私書箱管理テーブルに基づいて子管理ファイルを他方の取得先の情報媒体制御装置に取得させる。これにより、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合でも、子管理ファイルの情報ライフサイクルを管理できる。

Description

情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム
 本発明は、子管理ファイルの情報ライフサイクルを管理できない時期の発生を阻止し得る情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラムに関する。
 単独の文書データの情報ライフサイクルを管理する技術が提案されている。この種の技術としては、例えば、ID(identification)を付与された紙文書の印刷から破棄に関する履歴をサーバ管理するシステム(例えば、特開2005-190365号公報参照)や、印刷画像データに識別子を付与して回収・廃棄等の文書処分情報を管理するシステム(例えば、特開2007-88796号公報参照)等が知られている。
 また、本発明者により、この出願の基礎出願時に未公開の先願である特願2008-27776号において、情報ライフサイクル管理技術が提案されている。この情報ライフサイクル管理技術においては、デジタルデータや物理媒体といった「情報を保有する媒体」(以下、「情報媒体」という)を個体識別するためのユニークなIDを情報原本及び情報媒体に付与することにより、情報媒体の作成・廃棄、相互関係性(系統や媒体種別)及び媒体利用に関する状況を情報原本に紐付けて一元系統管理する。なお、物理媒体とは、紙、CDROM、DVD、SDカード及びFD等の上位概念であり、情報を保有する方法に関わらない物理的な情報媒体である。
 しかしながら、以上のような情報ライフサイクル管理技術は、通常は特に問題ないが、本発明者の検討によれば、以下の点で改良の余地がある。
 始めに、提案された情報ライフサイクル管理技術においては、管理ファイルの複製を依頼するクライアント(情報媒体制御装置)側に複製対象の親管理データが存在する必要があり、管理サーバ(情報管理サーバ装置)が、複製した子管理ファイルを当該依頼したクライアントに出力している。
 当該依頼したクライアントは、この子管理ファイルを他のクライアントに渡したい場合、電子メールや共有フォルダ、可搬型ストレージ経由など、情報ライフサイクル管理システム(一元系統管理システム)の管理下から外れたシステム経由で子管理ファイルを他のクライアントに送付する。
 当該他のクライアントは、子管理ファイルを受けたことを示す処理完了通知を管理サーバに送付する。管理サーバは、処理完了通知を受けると、子管理ファイルの場所を当該他のクライアントとして、子管理ファイルの情報ライフサイクルを管理する。
 このような情報ライフサイクル管理技術は、本発明者の検討によれば、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合には、子管理ファイルが情報ライフサイクル管理システムによる管理から一時的に外れて、子管理ファイルの情報ライフサイクルを管理できなくなる点で改良の余地がある。
 本発明の目的は、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合でも、子管理ファイルの情報ライフサイクルを管理し得る情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラムを提供することにある。
 本発明の一つの局面は、互いに通信可能な複数の情報媒体制御装置及び情報管理サーバ装置を備えた情報ライフサイクル管理システムであって、前記各情報媒体制御装置としては、管理ID及び電子データ本体を含む子管理ファイルが書き込まれる管理ファイル管理テーブルを記憶する管理ファイル管理テーブル記憶手段と、管理対象の電子データ本体を含む新規登録要求情報を情報管理サーバ装置に送信する手段と、複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置に対応する私書箱IDを含む複製登録要求情報を前記情報管理サーバ装置に送信する手段と、前記私書箱IDを含む私書箱チェック要求を前記情報管理サーバ装置に送信する手段と、前記情報管理サーバ装置から受けた私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求を当該情報管理サーバ装置に送信する手段と、前記情報管理サーバ装置から受けた子管理ファイルを前記管理ファイル管理テーブルに書き込む手段と、を備えており、前記情報管理サーバ装置としては、管理IDと実体IDとが互いに関連付けられて書き込まれ且つ当該管理IDに子管理IDが互いに関連付けられて書き込まれる系統管理テーブルを記憶する系統管理テーブル記憶手段と、実体ID及び電子データ本体が書き込まれるデータ原本管理テーブルを記憶するデータ原本管理テーブル記憶手段と、私書箱IDと子管理IDとが互いに関連付けられて書き込まれる私書箱管理テーブルを記憶する私書箱管理テーブル記憶手段と、前記新規登録要求情報に基づいて、電子データ本体に対して管理ID及び実体IDを発行し、管理ID及び実体IDを前記系統管理テーブルに登録し、実体ID及び電子データ本体を前記データ原本管理テーブルに登録する手段と、前記複製登録要求情報を受けると、当該複製登録要求情報内の管理IDと異なる子管理IDを発行し、前記系統管理テーブル内の管理IDのうち、複製登録要求情報内の管理IDと同一の管理IDに対応付けて、当該発行した子管理IDを当該系統管理テーブルに登録し、この子管理IDと複製登録要求内の私書箱IDとを関連付けて前記私書箱管理テーブルに登録し、子管理IDを含む複製登録処理結果情報を前記複製登録要求情報の送信元の情報媒体制御装置に送信する手段と、前記私書箱チェック要求を受けると、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを前記私書箱管理テーブルから読み出して当該子管理IDを含む私書箱確認情報を前記私書箱チェック要求の送信元の情報媒体制御装置に送信する手段と、前記複製取得要求を受けると、当該複製取得要求内の子管理IDに対応する実体IDを前記系統管理テーブルから読み出し、この実体IDに対応する電子データ本体を前記データ原本管理テーブルから読み出し、当該子管理ID及び電子データ本体を含む子管理ファイルを生成し、この子管理IDを前記私書箱管理テーブルから削除し、当該子管理ファイルを前記複製取得要求の送信元の情報媒体制御装置に送信する手段と、を備えた情報ライフサイクル管理システムである。
 なお、本発明の一つの局面は、各装置の集合体をシステムとして表現したが、これに限らず、各装置の集合体毎に又は装置毎に、装置、方法、プログラム、又はプログラムを記憶したコンピュータ読み取り可能な記憶媒体として表現することができる。
 本発明の一つの局面によれば、電子データの複製登録を要求する情報媒体制御装置と、複製登録により生成された子管理ファイルを取得する情報媒体制御装置とが別々の装置の場合でも、情報管理サーバ装置においては、一方の情報媒体制御装置から受けた複製登録要求情報に基づいて、電子データの子管理IDと子管理ファイルの取得先の私書箱IDとを私書箱管理テーブルに登録し、私書箱管理テーブルに基づいて子管理ファイルを他方の取得先の情報媒体制御装置に取得させる。
 従って、情報ライフサイクル管理システムにおいては、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合でも、子管理ファイルの情報ライフサイクルを管理することができる。
 以上説明したように本発明によれば、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合でも、子管理ファイルの情報ライフサイクルを管理できる。
図1は、本発明の各実施形態に係る情報ライフサイクル管理システムの構成を示す模式図である。 図2は、同システムにおける管理ファイルの構成例である。 図3は、本発明の第1の実施形態に係る情報ライフサイクル管理システムの構成を示す模式図である。 図4は、同実施形態における情報管理DBの構成を示す模式図である。 図5は、同実施形態における管理IDテーブルの構成を示す模式図である。 図6は、同実施形態における系統管理テーブルの構成を示す模式図である。 図7は、同実施形態における私書箱管理テーブルの構成を示す模式図である。 図8は、同実施形態におけるアクセスログテーブルの構成を示す模式図である。 図9は、同実施形態におけるマスタポリシテーブルの構成を示す模式図である。 図10は、同実施形態におけるクライアント管理テーブルの構成を示す模式図である。 図11は、同実施形態におけるデータ原本管理テーブルの構成を示す模式図である。 図12は、同実施形態における管理クライアントDBの構成を示す模式図である。 図13は、同実施形態における新規登録の動作を説明するための模式図である。 図14は、同実施形態における新規登録の動作を説明するための模式図である。 図15は、同実施形態における新規登録の動作を説明するための模式図である。 図16は、同実施形態における新規登録の動作を説明するための模式図である。 図17は、同実施形態における新規登録の動作を説明するための模式図である。 図18は、同実施形態における複製登録の動作を説明するための模式図である。 図19は、同実施形態における複製登録の動作を説明するための模式図である。 図20は、同実施形態における複製登録の動作を説明するための模式図である。 図21は、同実施形態における複製登録の動作を説明するための模式図である。 図22は、同実施形態における複製登録の動作を説明するための模式図である。 図23は、同実施形態における複製登録の動作を説明するための模式図である。 図24は、同実施形態における複製登録の動作を説明するための模式図である。 図25は、同実施形態における複製登録の動作を説明するための模式図である。 図26は、同実施形態における複製登録の動作を説明するための模式図である。 図27は、同実施形態における複製取得の動作を説明するための模式図である。 図28は、同実施形態における複製取得の動作を説明するための模式図である。 図29は、同実施形態における複製取得の動作を説明するための模式図である。 図30は、同実施形態における複製取得の動作を説明するための模式図である。 図31は、同実施形態における複製取得の動作を説明するための模式図である。 図32は、同実施形態における複製取得の動作を説明するための模式図である。 図33は、同実施形態における複製取得の動作を説明するための模式図である。 図34は、本発明の第2の実施形態に係る情報ライフサイクル管理システムの構成を示す模式図である。 図35は、本発明の第3の実施形態に係る情報ライフサイクル管理システムの構成を示す模式図である。
 以下、本発明の各実施形態について図面を用いて説明する。なお、以下の各装置は、装置毎に、ハードウェア構成、又はハードウェア資源とソフトウェアとの組合せ構成のいずれでも実施可能となっている。組合せ構成のソフトウェアとしては、図1に示すように、予めネットワーク又は記憶媒体M,M1~Mmから、対応する装置101,201~201のコンピュータにインストールされ、対応する装置101,201~201の機能を実現させるためのプログラムが用いられる。
 始めに、本明細書中における情報ライフサイクル管理システムの前提となる用語や概要等を説明する。図1は本発明の各実施形態に係る情報ライフサイクル管理システムの構成を示す模式図である。この情報ライフサイクル管理システムは、情報媒体を一元系統管理するための情報管理サーバ装置101と、一元系統管理された情報媒体を利用するための複数の情報媒体制御装置201~201とが互いに通信可能な構成となっている。ここで、各情報媒体制御装置201~201のうち、任意の情報媒体制御装置を「情報媒体制御装置201」と表す。
 情報媒体制御装置201は、各種の認証機能やログ記憶機能を除いて一般化した構成としては、管理ファイル管理テーブルを記憶する記憶装置と、以下の各機能(f201-1)~(f201-5)とを備えている。管理ファイル管理テーブルは、管理ID及び電子データ本体を含む子管理ファイルが書き込まれる。
 (f201-1) 管理対象の電子データ本体を含む新規登録要求情報を情報管理サーバ装置101に送信する機能。
 (f201-2) 複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置201に対応する私書箱IDを含む複製登録要求情報を情報管理サーバ装置101に送信する機能。
 (f201-3) 私書箱IDを含む私書箱チェック要求を情報管理サーバ装置101に送信する機能。
 (f201-4) 情報媒体制御装置201から受けた私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求を情報管理サーバ装置101に送信する機能。
 (f201-5) 情報管理サーバ装置から受けた子管理ファイルを管理ファイル管理テーブルに書き込む機能。
 情報管理サーバ装置101は、各種の認証機能やログ記憶機能を除いて一般化した構成としては、系統管理テーブル、データ原本管理テーブル及び私書箱管理テーブルを記憶する記憶装置と、以下の各機能(f101-1)~(f101-5)とを備えている。系統管理テーブルは、管理IDと実体IDとが互いに関連付けられて書き込まれ且つ当該管理IDに子管理IDが互いに関連付けられて書き込まれる。データ原本管理テーブルは、実体ID及び電子データ本体が書き込まれる。私書箱管理テーブルは、私書箱IDと子管理IDとが互いに関連付けられて書き込まれる。
 (f101-1) 情報媒体制御装置201から受けた新規登録要求情報に基づいて、電子データ本体に対して管理ID及び実体IDを発行し、管理ID及び実体IDを系統管理テーブルに登録し、実体ID及び電子データ本体をデータ原本管理テーブルに登録する機能。
 (f101-2) 複製登録要求情報を受けると、複製登録要求情報内の管理IDと異なる子管理IDを発行し、系統管理テーブル内の管理IDのうち、複製登録要求情報内の管理IDと同一の管理IDに対応付けて、当該発行した子管理IDを当該系統管理テーブルに登録し、この子管理IDと複製登録要求内の私書箱IDとを関連付けて私書箱管理テーブルに登録し、子管理IDを含む複製登録処理結果情報を情報媒体制御装置201に送信する機能。
 (f101-3) 私書箱チェック要求を受けると、私書箱チェック要求内の私書箱IDに対応する子管理IDを私書箱管理テーブルから読み出して当該子管理IDを含む私書箱確認情報を情報媒体制御装置201に送信する機能。
 (f101-4) 複製取得要求を受けると、複製取得要求内の子管理IDに対応する実体IDを系統管理テーブルから読み出し、この実体IDに対応する電子データ本体をデータ原本管理テーブルから読み出し、当該子管理ID及び電子データ本体を含む子管理ファイルを生成する機能。
 (f101-5) 当該子管理IDを私書箱管理テーブルから削除し、子管理ファイルを情報媒体制御装置201に送信する機能。
 ここで、情報媒体とは、電子データ又は物理媒体(紙媒体、記録メディア等)の如き、「情報を保有する媒体」を意味している。記録メディアとしては、例えば、CDROM、DVD、SDカード、FD等が使用可能となっている。これに伴い、各情報媒体制御装置201~202は、電子データを入力可能な装置であれば実現可能である。例えば、各情報媒体制御装置201~202は、利用する情報媒体に応じて、携帯電話、PC(Personal Computer)、デジタル複合機、プリンタ、コピー機・スキャナ、シュレッダ、マイクロフィルム読取機、DVD読取機、マルチドライブといった様々な装置として実現され、情報管理サーバ装置101に連携して動作する。
 このような情報ライフサイクル管理システムでは、前述した情報媒体を個体識別するためのユニークな管理ID(Identification)を付与し、管理IDに基づいて情報媒体の作成・廃棄、相互関係性(系統や媒体種別)、媒体利用に関する状況を情報原本に紐付けて一元系統管理する。
 情報媒体が電子データの場合、情報ライフサイクル管理システムでは、当該電子データを、管理IDを含むファイル形式の電子ファイルに変換する。変換後の電子ファイルを管理ファイルと呼ぶ。
 管理ファイルは、対象となる情報の電子データ本体に加え、管理IDや属性情報を含むヘッダ情報、利用制御ポリシ、本管理ファイルに対する認証情報が含まれている。管理ファイルは、図2に構成例を示すように、ヘッダ部、利用制御ポリシ部、ボディ部、データ認証部を備えている。
 ヘッダ部は、当該電子データの管理ID、親情報媒体の管理ID、世代番号、媒体種別、ファイル情報、ファイル格納情報、情報管理サーバ情報を備えて構成される。但し、ヘッダ部の構成はこれに限定されない。
 親情報媒体の管理IDとしては、例えば、電子データをコピーした際の元電子データの管理ID、電子データを印刷して紙媒体を出力した際の元電子データの管理ID、紙媒体をスキャナで電子データ化した際の紙媒体に付与された管理IDが用いられる。
 世代番号は、本管理システムへ最初に登録された管理ファイルを起点として、当該管理ファイルが親、子、孫と管理された系統関係で何世代目にあたるかの世代数値である。例えば、親にあたる管理ファイルの世代番号を1とすると、その複製にあたる子情報媒体の世代番号が2、さらに子情報媒体の複製にあたる孫情報媒体の世代番号は3となる。但し、世代番号の表現形式はこれに限定されない。
 ファイル情報は、当該電子データのファイル形式、ファイルサイズ、当該電子データの作成者情報、作成日時情報及び作成場所情報を含んでいる。
 ファイル格納情報は、ボディ部に格納された当該電子データ本体を暗号化しているか否かを示す情報を含み、暗号化している場合には、その暗号アルゴリズム、暗号鍵及び暗号モジュールに関する情報を更に含んでいる。
 情報管理サーバ情報は、情報管理サーバのMACアドレスやIPアドレス、URI、認証データ部を検証するための情報である。認証データ部を検証するための情報として、暗号鍵情報や当該鍵に関する暗号鍵証明書を格納する形態でもよい。
 利用制御ポリシ部には、当該電子ファイルの利用条件に対して許可または禁止する当該電子ファイルの処理が記載された利用制約に関する利用制御ポリシ情報が格納される。ここで、利用条件としては、例えば、利用可能期限、利用可能な場所情報やネットワーク環境、利用者や利用可能な機器情報、利用回数など、が挙げられる。
 ボディ部には、当該電子データ自体、又は当該電子データに暗号処理を施した暗号化データが格納される。
 データ認証部には、ヘッダ部、利用制御ポリシ部及びボディ部に対して、情報管理サーバ装置が暗号処理を施した認証データ情報が格納される。データ認証情報として、DSA(Digital Signature Algorithm)、RSA(Rivest-Shamir-Adleman Scheme)、ECDSA(Elliptic Curve DSA)といった公開鍵暗号を用いた電子署名や、ハッシュ関数や共通鍵暗号を用いたMAC(Message Authentication Code)を利用可能である。
 以上が本明細書中における情報ライフサイクル管理システムの前提となる用語や概要等の説明である。係る情報ライフサイクル管理システムにおいては、前述した通り、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合でも、子管理ファイルの情報ライフサイクルを管理できることが望まれる。以下、このような情報ライフサイクル管理システムの各実施形態を順次説明する。
 <第1の実施形態>
 図3は本発明の第1の実施形態に係る情報ライフサイクル管理システムの構成を示す模式図であり、図1に示した構成のうち、1台の情報管理サーバ装置101と、任意の1台の情報媒体制御装置201とを示している。なお、図1に示した各情報媒体制御装置201~201については、前述した携帯電話やPC等といった装置固有の機能は互いに異なるが、情報ライフサイクル管理システムに関する機能が互いに同一構成であるので、任意の1台の情報媒体制御装置201を代表例として示している。
 ここで、情報管理サーバ装置101は、管理要求受付部111、情報管理制御部112、コンテキスト認証部113、情報管理DB制御部114、管理ファイル生成部115及び情報管理DB121を備えている。
 なお、各部は、受けた情報をそのまま送出する場合などには、適宜、一体化して構成してもよい。例えば、管理要求受付部111及び情報管理制御部112は、受けた情報をそのまま送出する場合などには一体化してもよい。また、受けた情報をそのまま送出する場合などに各部を適宜一体化してもよいことは、他の装置及び以下の各実施形態でも同様である。
 ここで、管理要求受付部111、情報管理制御部112、コンテキスト認証部113、情報管理DB制御部114及び管理ファイル生成部115は、例えば、図示しないCPUが、後述する情報管理サーバ装置101内の各ステップを含むプログラムを実行することにより実現される機能ブロックとなっている。
 情報管理DB121は、図示しないCPUから読出/書込可能な記憶装置として実現可能となっており、図4に示すように、管理IDテーブル1211、系統管理テーブル1212、私書箱管理テーブル1213、アクセスログ管理テーブル1214、マスタポリシテーブル1215、クライアント管理テーブル1216及びデータ原本管理テーブル1217を記憶する。
 管理IDテーブル1211は、図5に示すように、発行された管理ID、発行日時及び発行依頼元情報を互いに関連付けて記憶し、失効の場合には、更に失効日及び失効依頼元情報を関連付けて記憶する。
 系統管理テーブル1212は、図6に示すように、電子データ本体の親子関係に対応する管理ID、電子データ本体の作成日時情報、ユーザ情報、媒体種別、利用制限ポリシ、所在情報及び実体IDを互いに関連付けて記憶する。系統管理テーブル1212は、電子データが複製の場合には、複製元(親)の電子データ本体又は管理ファイルの管理IDに対し、複製のために新たに発行された管理ID、複製(子)の管理ファイルのヘッダ部内の作成日時情報、ユーザ情報、媒体種別、利用制限ポリシ、所在情報及び実体IDを互いに関連付けて記憶する。ここで、管理IDの発行番号の体系としては、当該システムにおける唯一無二性が保証され、複製の親子関係が管理IDで紐づいて管理されていれば、通し番号でもよい。また、各管理IDの親子関係がわかるように管理IDの構成に意味を持たせて発行されてもよい。これは例えば、特定桁の値を親子関係値とすればよい。図6の例では、下4桁目(千の位)が親子関係値となっており、“0”が最上位の親を示し、“1”がその親の子を示し、“2”がその子の子(=親の孫)を示している。なお、下3桁目(百の位)は媒体種別となっており、“1”が電子データを示し、“2”が紙媒体を示し、“3”が記録メディアを示している。下1~2桁目(一の位と十の位)は同世代・同一媒体種別における識別番号である。下5~8桁目(#とその右の3桁の値)は、電子データIDであり、同一の電子データIDをもつ管理ファイルであれば、親子に関わらず、同一の電子データを含んでいる。また、所在情報における機器X,Y,Z及び社員B等は、いずれかの情報媒体制御装置201,201,201,201に対応するので、情報媒体制御装置201,201,201,201と読み替えてもよい。なお、親子関係値“0”が示す最上位の親は、管理ファイルが作成されない。親子関係値“1”以上が示す親は管理ファイルが作成される。また、実体IDは、電子データ本体(データ原本)を識別する情報であり、電子データを複製した場合に、前述した管理IDとは異なり、複製元(親)の実体IDと複製(子)の実体IDとは互いに同一である。
 私書箱管理テーブル1213は、図7に示すように、私書箱ID毎に、取得する子管理ファイルの個数を意味する投函数(取得数)と、取得する子管理ファイルの管理IDを列挙した管理IDリストとを互いに関連付けて記憶する。私書箱IDは、情報媒体制御装置201毎に割り当てられた場合を例に挙げて述べるが、これに限らず、任意の情報媒体制御装置201が任意の私書箱IDを指定可能な構成にしてもよい。
 アクセスログ管理テーブル1214は、図8に示すように、操作した日時毎に、クライアントID、操作種別、管理ID、処理ステイタスを含んでいる。クライアントIDは、操作した社員を示すIDであり、操作者ID又は社員IDと読み替えてもよい。操作種別は、ログイン状況、新規登録、電子データ複製、閲覧、消去といった操作の種別を示している。管理IDは、操作された電子データを示す管理IDである。処理ステイタスは、操作種別が示す処理の成功又は失敗(認証エラー等)といった処理結果を示すステイタス情報である。アクセスログ管理テーブル1214で管理する内容は、この他にも対象管理ファイルに対して操作を加えた当該機器の場所情報(社内/社外、GPS情報)などを用いてもよく、図8に示した情報に限定されない。
 マスタポリシテーブル1215は、図9に示すように、ポリシ番号毎に、ポリシ種別及び拒否/許可ポリシを互いに関連付けて記憶する。ポリシ番号は、ポリシの識別情報であり、ポリシIDと読み替えてもよい。ポリシ種別は、拒否/許可ポリシにより制御する対象の種別を表す情報であり、例えばロケーション制御、時間制御、権限制御などが適宜使用可能となっている。拒否/許可ポリシは、判定条件と、判定条件を満たす場合の制御内容とを示す情報である。制御内容は、許可又は拒否する対象(コマンドや要求など)を含んでおり、また、社内有線接続又は社内無線接続などの処理を含む場合もある。
 クライアント管理テーブル1216は、図10に示すように、クライアントID、社員番号、権限クラス、端末種別及びMACアドレスを互いに関連付けて記憶する。
 データ原本管理テーブル1217は、図11に示すように、実体ID、ファイル名、サイズ、ハッシュ値、電子データ本体及び外部保存情報を互いに関連付けて記憶する。ここで、実体IDは、電子データ本体(データ原本)の識別情報である。ファイル名は、管理ファイルに格納する管理対象データ本体(電子データ本体)のファイル名である。サイズは、管理ファイルに格納する管理対象データ本体のファイルサイズである。ハッシュ値は、管理ファイルに格納する管理対象データ本体のハッシュ値である。電子データ本体は、管理ファイルに格納する管理対象データ本体である。外部保存情報は、管理対象データ本体を情報管理DB121の外部に保存する場合、その保存先情報である。本実施形態では、外部保存情報を用いていない。
 一方、情報媒体制御装置201は、図3に示したように、上位システム部211、要求受付部212、情報媒体管理部213、コンテキスト情報取得部214、管理要求送信部215、管理ファイル制御部216及び管理クライアントDB217を備えている。なお、各部は、適宜、一体化してもよい。例えば、要求受付部212、情報媒体管理部213、管理要求送信部214及び管理ファイル制御部216は、受けた情報をそのまま送出する場合などには一体化してもよい。
 ここで、上位システム部211、要求受付部212、情報媒体管理部213、コンテキスト情報取得部214、管理要求送信部215及び管理ファイル制御部216は、例えば、図示しないCPUが、後述する情報媒体制御装置201内の各ステップを含むプログラムを実行することにより実現される機能ブロックとなっている。
 管理クライアントDB217は、図示しないCPUから読出/書込可能な記憶装置として実現可能となっており、ここでは管理ファイル制御部216からアクセス可能な記憶装置であって、図12に示すように、管理ファイル管理テーブル2171及びアクセスログテーブル2172を記憶する。
 管理ファイル管理テーブル2171は、管理ID毎に、ステイタス情報(例、閲覧中、-(廃止)、利用可、など)、管理ファイル属性情報(作成日時情報と、廃止した場合には廃止日時情報)及び管理ファイル実体を含んでいる。管理ファイル属性情報としては、ここでは、管理ファイルヘッダ部の部分情報を用いている。管理ファイルヘッダ部の部分情報としては、例えば、前述した作成・廃止日時情報に加え、当該管理ファイルの複製元の最上位の親の電子データ本体に対応する管理ID又は複製元の管理ファイルを示す管理IDが使用可能となっている。「複製元の管理ファイル」とは、「複製の子管理ファイルの元となる親管理ファイル」を意味する。但し、管理ファイル属性情報の記載範囲は、管理ファイルヘッダ部の部分情報に限らず、当該機器の環境設定や情報管理サーバ装置との規定に基づき、多用な形態が可能である。また、管理ファイル属性情報としては、各管理ファイルに対する当該機器でのアクセス回数といった管理ファイルヘッダ部に記載がない動的な利用情報を含んでもよい。管理ファイル実体は外部の記憶装置(図示せず)に格納してもよい。
 アクセスログテーブル2172は、操作した日時毎に、操作種別、ユーザ情報、管理ID、管理ファイル名を含んでいる。操作種別は、ログイン状況、新規登録、複製登録、私書箱チェック、複製取得、閲覧、消去といった操作の種別を示している。管理IDは、操作された電子データを示す管理IDである。管理ファイル名は、例えば、当該電子データの管理IDに、当該電子データのファイル形式を示す拡張子を連接した情報である。アクセスログテーブル2171で管理する内容は、この他にも対象管理ファイルに対して操作を加えた当該機器の場所情報(社内/社外、GPS情報)などを用いてもよく、図12に示した情報に限定されない。
 次に、以上のように構成された情報ライフサイクル管理システムの動作を図13乃至図33の模式図を用いて説明する。なお、以下の説明は、電子データの新規登録(図13乃至図17)、電子データの複製登録(図18乃至図26)、電子データの複製取得(図27乃至図33)の順に行う。
 (電子データの新規登録:図13乃至図17)
 未登録の電子データを含む管理ファイル実体を情報媒体制御装置201に新規登録する際に、情報媒体制御装置201と情報管理サーバ装置101は次のような処理を実行する。始めに、各種の認証動作等を含めない一般化した動作を説明する。
 (新規登録の一般化した動作)
 情報媒体制御装置201は、管理対象の電子データ本体を含む新規登録要求情報を情報管理サーバ装置101に送信する。
 情報管理サーバ装置101においては、新規登録要求情報に基づいて、電子データ本体に対して管理ID及び実体IDを発行し、管理ID及び実体IDを系統管理テーブル1212に登録し、実体ID及び電子データ本体をデータ原本管理テーブル1217に登録する。
 次に、このような新規登録の動作について、各種の認証動作などを含めて詳細に説明する。
 (新規登録の詳細動作)
 上位システム部211は、図13に示すように、操作者(電子データ作成者)の操作により、未登録の電子データ及び新規登録要求を要求受付部212へ送出する(ST1)。当該新規登録要求は、当該電子データの利用制限に関する利用制御ポリシ、及び電子データ作成者を示す作成者情報を含んでいる。作成者情報は、例えば、クライアントID及び社員番号を含むユーザ情報である。
 要求受付部212は、例えば受付順に、この電子データ及び新規登録要求を情報媒体管理部213へ送出する(ST2)。
 情報媒体管理部213は、電子データ及び新規登録要求を受けると、当該要求された処理に必要なコンテキスト情報を取得するためのコンテキスト取得要求をコンテキスト情報取得部214に送出する(ST3)。
 コンテキスト情報取得部214は、コンテキスト情報取得要求に応じて、当該情報媒体制御装置201に関するコンテキスト情報を当該情報媒体制御装置201のオペレーティングシステムや関連ハードウェアから取得し、このコンテキスト情報を情報媒体管理部213へ送出する(ST4)。ここで、コンテキスト情報としては、例えば、当該情報媒体制御装置201に関するMACアドレスやIPアドレスといった機器情報、ドメイン情報や接続可能な機器情報といった接続ネットワークに関する情報、GPSといった当該機器の物理的な位置情報、などが適宜使用可能となっている。
 情報媒体管理部213は、コンテキスト情報を受けると、新規登録要求内の作成者情報及び当該コンテキスト情報を含むコンテキスト認証要求情報を管理要求送信部215へ送出する(ST5)。
 管理要求送信部215は、コンテキスト認証要求情報を情報管理サーバ装置101へ送信する(ST6)。
 情報管理サーバ装置101においては、図14に示すように、管理要求受付部111が、例えば受付順に、このコンテキスト認証要求情報を情報管理制御部112へ送出する(ST7)。
 情報管理制御部112は、コンテキスト認証要求情報をコンテキスト認証部113へ送出し、当該コンテキスト情報の認証を要求する(ST8)。
 コンテキスト認証部113は、コンテキスト認証要求情報を取得すると、情報管理DB121内のクライアント管理テーブル1216を参照しながら、依頼元ユーザを示す作成者情報(社員番号)に対応する権限クラスや接続形態による権限クラスを取得する。コンテキスト認証要求情報の中に、電子署名やMACといったセキュリティ認証情報が付与されている際には、そのセキュリティ認証情報の正当性を検証する。作成者情報又はコンテキスト情報内の接続環境が不明な場合や、セキュリティ認証情報の検証結果が不正を示す場合には、エラーを示す判定結果情報を情報管理制御部112に送出する。また、作成者情報及びコンテキスト情報内の接続環境が明確な場合や、セキュリティ認証情報の検証結果が正当を示す場合には、コンテキスト認証部113は、クライアントの身元や権限に関するコンテキスト判定結果を情報管理制御部112へ送出する(ST9)。ここで、クライアントの身元は、前述した作成者情報であり、クライアントの権限は、クライアント管理テーブル1216から取得した権限クラスである。
 情報管理制御部112は、コンテキスト判定結果を管理要求受付部111へ送出する(ST10)。
 管理要求受付部111は、コンテキスト判定結果を情報媒体制御装置201へ送信する(ST11)。
 管理要求送信部215は、図15に示すように、受信したコンテキスト判定結果を情報媒体管理部213へ送出する(ST12)。
 情報媒体管理部213は、コンテキスト判定結果がエラーの場合には、要求入出力部212経由で上位システム部211へエラーを通知する。エラーでなかった場合には、登録対象となる電子データの新規登録要求情報を管理要求送信部215へ送出する(ST13)。ここで、新規登録要求情報は、登録対象となる電子データ及び当該電子データの利用制限に関する利用制御ポリシを含んでいる。
 管理要求送信部215は、新規登録要求情報を情報管理サーバ装置101へ送信する(ST14)。
 管理要求受付部111は、図16に示すように、新規登録要求情報を情報管理制御部112へ送出する(ST15)。
 情報管理制御部112は、この新規登録要求情報とコンテキスト判定結果とを含む新規登録処理要求情報を情報管理DB制御部114に送出し、電子データの新規登録処理を要求する(ST16)。
 情報管理DB制御部114は、新規登録処理要求情報を受けると、新規登録処理要求情報と、情報管理DB121のマスタポリシテーブル1215とを照合し、照合の結果、マスタポリシテーブル1215内の許可/拒否ポリシにより許可されるか拒否されない場合に限り、対象となる電子データが既に登録されていないか否かの二重登録確認を実行する。
 この照合の処理としては、例えば、新規登録処理要求情報内のコンテキスト判定結果と、情報管理DB121のマスタポリシテーブル1215とを照合し、照合の結果、コンテキスト判定結果内のクライアントの身元や権限に関する情報がマスタポリシテーブル1215の許可/拒否ポリシにより許可されるか拒否されない場合であって、要求受付時間や情報媒体制御装置201のIPアドレスといった他の情報も許可/拒否ポリシにより許可されるか拒否されない場合に限り、二重登録確認の処理に進む。
 二重登録確認の処理としては、例えば、過去に新規登録した電子データのハッシュ値を情報管理DB121の系統管理テーブル1212に予め登録しておき、今回の新規登録対象の電子データのハッシュ値を計算し、当該ハッシュ値が系統管理テーブル1212に存在しないことを確認する。
 今回の新規登録対象の電子データが既に登録されていない場合、情報管理DB制御部114は、当該データに対する管理ID及び実体IDを発行し、管理ID、発行日時及び発行依頼元情報からなる管理ID発行情報を情報管理DB121内の管理IDテーブル1211に登録する。
 また、情報管理DB制御部114は、発行した実体ID、電子データ本体のファイル名、電子データ本体のサイズ(ファイルサイズ)、電子データ本体のハッシュ値及び電子データ本体を互いに関連付けてデータ原本管理テーブル1217に登録する。
 また、情報管理DB制御部114は、日時、クライアントID、操作種別、管理ID及び処理ステイタスを含むアクセスログ情報を情報管理DB121内のアクセスログ管理テーブル1214に登録する。
 登録後、情報管理DB制御部114は、管理IDを含む新規登録処理結果情報を情報管理制御部112へ送出する(ST17)。新規登録処理結果情報は、管理クライアントDB217内の各テーブル2171,2172に登録するための情報を含んでおり、具体的には、管理ID、日時及び操作種別を含んでいる。
 情報管理制御部112は、新規登録処理結果情報を管理要求受付部111へ送出する(ST18)。
 管理要求受付部111は、新規登録処理結果情報を情報媒体制御装置201へ送信する(ST19)。
 管理要求送信部215は、図17に示すように、新規登録処理結果情報を情報媒体管理部213へ送出する(ST20)。
 情報媒体管理部213は、新規登録処理結果情報を管理ファイル制御部216へ送出し、処理結果を管理クライアントDB217へ登録するよう要求する(ST21)。
 管理ファイル制御部216は、新規登録処理結果情報に基づき、管理IDを主キーとしたステイタスを管理クライアントDB217へ反映させるため、管理ID及びステイタスを管理ファイル管理テーブル2171に登録する。
 次に、管理ファイル制御部216は、管理クライアントDB217へ操作ログを反映させるため、管理クライアントDB217のアクセスログテーブル2172には、操作日時情報、操作種別及び管理IDを含む新規登録の操作ログを登録する。
 登録完了後、管理ファイル制御部216は、登録処理完了通知を情報媒体管理部213へ送出する(ST22)。
 情報媒体管理部213は、登録処理完了通知を受けると、管理要求送信部215へ情報管理サーバ装置101との通信を切断するように要求する(ST23)。
 管理要求送信部215は、情報管理サーバ装置101との通信を切断し、完了通知を情報媒体管理部213へ送出する(ST24)。
 情報媒体管理部213は、新規登録した電子データの新規登録処理完了通知を要求入出力部212へ送出する。新規登録処理完了通知には、当該電子データに対して発行された管理IDを含めてもよい(ST25)。
 要求入出力部212は、新規登録処理完了通知を上位システム部211へ送出し、処理を完了する(ST26)。
 (電子データの複製登録:図18乃至図26)
 始めに、各種の認証動作等を含めない一般化した動作を説明する。
 (複製登録の一般化した動作)
 情報媒体制御装置201は、複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置201に対応する私書箱IDを含む複製登録要求情報を情報管理サーバ装置101に送信する。
 情報管理サーバ装置101においては、複製登録要求情報を受けると、当該複製登録要求情報内の管理IDとは異なる子管理IDを発行し、系統管理テーブル1212内の管理IDのうち、複製登録要求情報内の管理IDと同一の管理IDに対応付けて、当該発行した子管理IDを当該系統管理テーブル1212に登録し、この子管理IDと複製登録要求内の私書箱IDとを関連付けて私書箱管理テーブル1216に登録し、子管理IDを含む複製登録処理結果情報を複製登録要求情報の送信元の情報媒体制御装置201に送信する。
 次に、このような複製登録の動作について、各種の認証動作などを含めて詳細に説明する。
 (複製登録の詳細動作)
 本システムに既登録の電子データに対して、ある情報媒体制御装置201が対象となる情報媒体制御装置201へ複製の電子データを取得できるように情報管理サーバ装置101へ依頼する際、情報媒体制御装置201と情報管理サーバ装置101は次のような処理を実行する。
 上位システム部211は、図18に示すように、操作者の操作により、複製したい管理IDに対応する電子データ本体の利用制御ポリシを取得するための利用制御ポリシ取得要求を要求入出力部212へ送出する(ST31)。当該利用制御ポリシ取得要求は、取得要求を行う利用者に関する利用者情報および要求対象となる電子データ本体に対応する管理IDを含んでいる。情報媒体制御装置201の場所情報や、IPアドレス、MACアドレス、接続ネットワークの利用環境情報を含んでもよい。当該管理IDを親管理IDと呼ぶ。
 情報媒体制御装置201と情報管理サーバ装置101は、図18乃至図20に示すように、電子データの新規登録処理ST2からST12と同様の処理を実行し、コンテキスト情報の認証を行う(ST32~ST42)。
 情報媒体管理部213は、コンテキスト判定結果がエラーの場合には、要求入出力部212経由で上位システム部211へエラーを通知する。エラーでなかった場合には、利用制御ポリシ取得要求情報を管理要求送信部215へ送出する(ST43)。ここで、利用制御ポリシ取得要求情報は、利用者情報、親管理ID、場所情報及び利用環境情報を含んでいる。
 管理要求送信部215は、親管理IDを含む利用制御ポリシ取得要求情報を情報管理サーバ装置101へ送信する(ST44)。
 管理要求受付部111は、図21に示すように、利用制御ポリシ取得要求情報を情報管理制御部112へ送出する(ST45)。
 情報管理制御部112は、情報管理DB制御部114へ利用制御ポリシ取得要求情報を送出し、親管理IDに関する利用制御ポリシを要求する(ST46)。
 情報管理DB制御部114は、利用制御ポリシ取得要求情報を受けると、利用制御ポリシ取得要求情報と、情報管理DB121のマスタポリシテーブル1215とを照合し、照合の結果、マスタポリシテーブル1215内の許可/拒否ポリシにより許可されるか拒否されない場合に、利用制御ポリシを送信可能と判定する。
 この照合の処理としては、例えば、利用制御ポリシ取得要求情報に含まれる利用者情報や利用環境情報がマスタポリシテーブル1215の許可/拒否ポリシにより許可されるか拒否されない場合であって、要求受付時間といった他の情報も許可/拒否ポリシにより許可されるか拒否されない場合に限り、利用制御ポリシを送信可能と判定する。
 送信可能と判定した場合、情報管理DB制御部114は、利用制御ポリシ取得要求情報内の親管理IDに対する利用制御ポリシを情報管理DB121内の系統管理テーブル1212から読み出し、当該利用制御ポリシ及びマスタポリシ判定結果を情報管理制御部112へ送出する(ST47)。
 情報管理制御部112は、利用制御ポリシ及びマスタポリシ判定結果を管理要求受付部111へ送出する(ST48)。
 管理要求受付部111は、利用制御ポリシ及びマスタポリシ判定結果を情報媒体制御装置201へ送信する(ST49)。
 管理要求送信部215は、図22に示すように、利用制御ポリシ及びマスタポリシ判定結果を受信すると、情報管理サーバ装置101へセッション切断要求を送信し、情報管理サーバ装置101との間の通信を切断する。管理要求送信部215は、利用制御ポリシ及びマスタポリシ判定結果を情報媒体管理部213へ送出する(ST50)。切断処理と情報媒体管理部213への情報送出処理の順序はいずれでも構わない。
 情報媒体管理部213は、親管理IDに対応した利用制御ポリシと、利用者情報及び利用環境情報とを照合し、当該複製登録処理を実行できる権限があるか否かを判定する。実行権限がある場合、情報媒体管理部213は、要求入出力部212に親管理IDに対応する実体IDが示す電子データ本体から電子的に複製され派生する子管理ファイルに対する利用制御ポリシ設定要求を送出する(ST51)。
 要求入出力部212は、上位システム部211に利用制御ポリシ設定要求を送出する(ST52)。
 上位システム部211では、利用制御ポリシ設定要求を受けると、利用者操作により、子管理ファイルに対する利用制御ポリシの設定を行う。子管理ファイルに対する利用制御ポリシは、親管理IDに対応する利用制御ポリシの制限内で定めるといったシステムポリシを定める。親管理IDに対応する実体IDが示す電子データ本体から複数の子管理ファイルを同時に複製する場合、各子管理ファイルに対する利用制御ポリシはすべて共通でもよいし、子管理ファイルの取得先に応じて適宜異なる設定にしてもよい。利用制御ポリシの設定は、利用者が行う必要はなく、状況や環境に応じて適切なポリシを設定するプログラムでもよい。利用制御ポリシが設定されると、上位システム部211は、親管理ID、子管理ファイルの取得先情報、私書箱ID、親管理IDに対応する利用制御ポリシ及び子管理ファイルの利用制御ポリシを含む複製登録要求情報を要求入出力部212へ送出する(ST53)。
 要求入出力部212は、複製登録要求情報を情報媒体管理部213へ送出する(ST54)。
 情報媒体管理部213は、子管理ファイルの利用制御ポリシが、親管理IDに対応する利用制御ポリシの制約内か否かを判定する。制約に違反する場合は、再度子管理ファイルの利用制御ポリシを修正させるか、エラーを出力して処理を終了させる。制約に違反しない場合、図22乃至図24に示すように、ST33~ST42と同様にコンテキスト認証処理を実行し、情報管理サーバ装置101と認証処理を経て通信セッションを確立する(ST55~ST64)。
 しかる後、情報媒体管理部213は、複製登録要求情報を管理要求送信部215へ送出する(ST65)。なお、複製登録要求情報に含まれる各情報のうち、親管理ファイルの利用制御ポリシは、情報管理サーバ101が保有することから、送出しなくてもよい。
 管理要求送信部215は、複製登録要求情報を情報管理サーバ101へ送信する(ST66)。
 管理要求受付部111は、図25に示すように、複製登録要求情報を情報管理制御部112へ送出する(ST67)。
 情報管理制御部112は、複製登録要求情報を含む複製登録処理要求を情報管理DB制御部114へ送出し(ST68)、複製登録要求情報に基づく子管理IDの発行と、情報管理DB121への管理ID発行情報、系統情報、私書箱情報及びアクセスログ情報の登録を要求する。
 情報管理DB制御部114は、複製登録処理要求を受けると、情報管理DB121内のマスタポリシテーブル1215を参照し、要求された複製登録処理を実行してよいか否かを判定する。マスタポリシに違反しない場合は、情報媒体制御装置201や当該装置の処理要求者が要求時の状況や環境で複製登録を行う権限があるか否か、子管理ファイルの利用制御ポリシが親管理IDに対応する利用制御ポリシの制約内か否かといった項目を含む、処理実行が可能か否かを判定する。当該判定には、発行対象となる子管理ファイルが対象管理IDの起点からして派生を認められた世代範囲内か、派生数の上限を上回っていないかといった判定項目を含めてもよい。
 判定の結果、実行可能な場合に限り、情報管理DB制御部114は、子管理IDを発行し、子管理ID、発行日時及び発行依頼元情報からなる管理ID発行情報を情報管理DB121内の管理IDテーブル1211に登録する。
 また、情報管理DB制御部114は、子管理IDを親管理IDに関連付けて系統管理テーブル1212に登録し、子管理ファイルの取得先情報を所在情報として子管理IDに関連付けて系統管理テーブル1212に登録する。
 さらに、情報管理DB制御部114は、複製登録要求情報内の私書箱IDに関連付けて子管理IDを私書箱管理テーブル1213に登録し、指定された各私書箱に対して、登録した子管理IDの個数を投函数として私書箱管理テーブル1213に書き込む。
 また、情報管理DB制御部114は、日時、クライアントID、操作種別、管理ID及び処理ステイタスを含むアクセスログ情報を情報管理DB121内のアクセスログ管理テーブル1214に登録する。
 なお、情報管理DB制御部114は、複数の子管理IDを発行した場合も各々に同様の処理を実行する。情報管理DB制御部114は、発行した子管理IDを含む複製登録処理結果情報を情報管理制御部112へ送出する(ST69)。複製登録処理結果情報は、管理クライアントDB217内のアクセスログテーブル2172に登録するための情報を含んでおり、具体的には、子管理ID、日時及び操作種別を含んでおり、管理ファイル名を含んでいない。
 情報管理制御部112は、複製登録処理結果情報を管理要求受付部111へ送出する(ST70)。
 管理要求受付部111は、複製登録要求への応答として情報媒体制御装置201へ複製登録処理結果情報を送信する(ST71)。処理が失敗した場合には、エラー情報を送信する。
 管理要求送信部215は、図26に示すように、受信した複製登録処理結果情報を情報媒体管理部213へ送出する(ST72)。同時に、通信セッションの切断要求を情報管理サーバ装置101へ送信し、通信を切断する。
 情報媒体管理部213は、管理ファイル制御部216へ複製登録処理結果情報を送出し、処理結果を管理クライアントDB217へ登録するよう要求する(ST73)。
 管理ファイル制御部216は、複製登録処理結果情報に基づき、操作日時情報、操作種別及び子管理IDを含む複製登録の操作ログを管理クライアントDB217のアクセスログテーブル2172に登録する。
 登録完了後、管理ファイル制御部216は、複製登録処理完了通知を情報媒体管理部213へ送出する(ST74)。
 情報媒体管理部213は、複製登録処理完了通知を受け、複製登録完了通知を要求入出力部212へ送出する(ST75)。
 要求入出力部212は、複製登録完了通知を上位システム部211へ送出し、一連の複製登録要求セッションを終了させる(ST76)。
 上位システム部211は、複製登録完了通知を受けると、例えば操作者の操作により、この複製登録完了通知を取得先の情報媒体制御装置201に送信することにより、電子データの複製登録があることを取得先の情報媒体制御装置201に通知してもよい。この場合、取得先の情報媒体制御装置201の上位システム部211は、操作者の操作や、時間周期での確認設定を契機として、当該情報媒体制御装置201向けの複製登録の有無を容易に確認可能となる。但し、これに限らず、例えば複製登録をした情報媒体制御装置201の操作者が、口頭、電話、FAX又は電子メール等の任意の連絡手段により、取得先の情報媒体制御装置201の操作者に複製登録が有ることを連絡してもよい。
 (電子データの複製取得:図27乃至図33)
 始めに、各種の認証動作等を含めない一般化した動作を説明する。
 (複製取得の一般化した動作)
 情報媒体制御装置201は、私書箱IDを含む私書箱チェック要求を情報管理サーバ装置101に送信する。
 情報管理サーバ装置101においては、私書箱チェック要求を受けると、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを私書箱管理テーブル1216から読み出して当該子管理IDを含む私書箱確認情報を私書箱チェック要求の送信元の情報媒体制御装置201に送信する。
 情報媒体制御装置201は、この私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求を当該情報管理サーバ装置101に送信する。
 情報管理サーバ装置101においては、複製取得要求を受けると、当該複製取得要求内の子管理IDに対応する実体IDを系統管理テーブル1212から読み出し、この実体IDに対応する電子データ本体をデータ原本管理テーブル1217から読み出し、当該子管理ID及び電子データ本体を含む子管理ファイルを生成し、この子管理IDを私書箱管理テーブル1216から削除し、当該子管理ファイルを複製取得要求の送信元の情報媒体制御装置201に送信する。
 情報媒体制御装置201は、この子管理ファイルを管理ファイル管理テーブル2171に書き込む。
 次に、このような複製取得の動作について、各種の認証動作などを含めて詳細に説明する。
 (複製取得の詳細動作)
 本システムにおいて、情報媒体制御装置201が当該装置向けに複製された電子データを情報管理サーバ装置101から取得する際、情報媒体制御装置201と情報管理サーバ装置101は次のような処理を実行する。なお、複製取得処理を実行する情報媒体制御装置201は、前述した複製登録処理を実行した情報媒体制御装置201とは別の装置であることを想定している。
 上位システム部211は、図27に示すように、操作者の操作や、時間周期での確認設定を契機として、当該情報媒体制御装置201向けの複製登録の有無を確認し、複製登録があれば複製登録された電子データの取得要求(以下、複製取得要求という)を要求入出力部212へ送出する(ST81)。当該複製取得要求は、取得要求を行う利用者の利用者情報を含んでいる。この複製取得要求は、情報媒体制御装置201の場所情報や利用環境情報を含んでもよく、また、情報媒体制御装置201に対応する私書箱IDを含んでもよい。
 要求入出力部212は、複製取得要求を情報媒体管理部213へ送出する(ST82)。
 情報媒体制御装置201と情報管理サーバ装置101は、図27乃至図29に示すように、電子データの新規登録処理ST3からST12と同様の処理を実行し、コンテキスト情報を認証する(ST83~ST92)。
 情報媒体管理部213は、コンテキスト判定結果がエラーの場合には、要求入出力部212経由で上位システム部211へエラーを通知する。エラーでなかった場合には、電子データの複製取得情報を確認したい私書箱の私書箱IDを含む私書箱チェック要求を管理要求送信部215へ送出する(ST93)。私書箱チェック処理は、当該情報媒体制御装置201に唯一割り当てられた私書箱に対してのみ要求として受け付けるシステム構成で実現してもよい。どんな私書箱に対しても、指定した私書箱IDで私書箱チェックを受け付けるシステム構成で実現してもよい。
 管理要求送信部215は、私書箱チェック要求を情報管理サーバ装置101へ送信する(ST94)。
 管理要求受付部111は、図30に示すように、私書箱チェック要求を情報管理制御部112へ送出する(ST95)。
 情報管理制御部112は、情報管理DB制御部114へ私書箱チェック要求を送出し、指定私書箱IDに対応する私書箱状態を確認する処理を要求する(ST96)。
 情報管理DB制御部114は、私書箱チェック要求から私書箱IDを抽出し、情報管理DB121の私書箱管理テーブル1216から私書箱ID、投函数及び管理IDリストを含む私書箱確認情報を取得する。投函数は、複製登録された管理IDの個数であり、複製取得可能な管理ファイルの個数でもある。情報管理DB制御部114は、取得した私書箱確認情報を情報管理制御部112へ送出する(ST97)。
 情報管理制御部112は、私書箱確認情報を管理要求受付部111へ送出する(ST98)。
 管理要求受付部111は、私書箱確認情報を情報媒体制御装置201へ送信する(ST99)。
 管理要求送信部215は、図31に示すように、私書箱確認情報を情報媒体管理部213へ送出する(ST100)。
 情報媒体管理部213は、私書箱確認情報内の投函数又は管理IDリストに基づいて、複製取得可能な管理ファイルが存在するか否かを確認する。取得可能な管理ファイルが存在しない場合、当該複製取得処理を終了する。この時、情報媒体管理部213は、管理ファイル制御部216へ、アクセスログ情報を管理クライアントDB217に書き込むよう要求してもよい。また、情報媒体管理部213は、要求入出力部212経由で上位システム部211へ管理ファイルが存在しないことを通知してもよい。取得可能な管理ファイルが存在する場合、私書箱確認情報内の管理IDリストから、取得したい管理ファイルの管理IDを選択し、当該管理IDを含む複製取得要求を管理要求送信部215へ送出する(ST101)。
 管理要求送信部215は、複製取得要求情報を情報管理サーバ101へ送信する(ST102)。
 管理要求受付部111は、図32に示すように、複製取得要求情報を情報管理制御部112へ送出する(ST103)。
 情報管理制御部112は、複製取得要求情報とコンテキスト判定結果とを含む複製取得処理要求情報を情報管理DB制御部114に送出し、管理ファイルの生成および情報管理DB121への親子関係情報の登録を含む、複製取得処理を情報管理DB制御部114へ要求する(ST104)。
 情報管理DB制御部114は、複製取得処理要求情報を受けると、複製取得処理要求情報と、情報管理DB121のマスタポリシテーブル1215とを照合し、照合の結果、マスタポリシテーブル1215内の許可/拒否ポリシにより許可されるか拒否されない場合に限り、複製取得対象の管理ファイル生成要求の処理に進む。なお、照合の処理は、前述同様に実行される。
 管理ファイル生成要求の処理に進むと、情報管理DB制御部114は、情報管理DB121から管理ファイル生成に必要な情報を取得し、管理ファイル生成部115へ当該情報を含む管理ファイル生成要求を送出する(ST105)。ここで、管理ファイル生成に必要な情報には、複製取得対象となる管理ID、当該管理IDに対応付けられた管理対象となる電子データ本体、当該管理IDに対応付けられた利用制御ポリシが含まれる。これら管理ID及び利用制限ポリシは、例えば情報管理DB121内の系統管理テーブル1212から取得される。また、電子データ本体は、情報管理DB121内のデータ原本管理テーブル1217から取得される。
 次に、管理ファイル生成部115は、複製取得対象となる管理ID、電子データ本体及び利用制御ポリシを含む管理ファイル生成要求を受けると、この管理ファイル生成要求に基づき、管理ファイルを生成する。管理ファイルの生成手順は、例えば次の通りである。
 管理ファイル生成部115は、ヘッダ部の電子データの管理IDの領域には、管理IDをセットする。ヘッダ部の親情報媒体の管理IDには、NULLをセットする。ヘッダ部のファイル情報には、ファイル形式、ファイルサイズ、作成者情報、作成日時情報及び作成場所情報をセットする。
 管理ファイル生成部115は、暗号処理の有無、暗号アルゴリズムや暗号鍵、暗号モジュール等の暗号処理の指定に基づき、ヘッダ部のファイル格納情報をセットする。ここで、暗号処理の指定としては、例えば、上位システム部211が複製取得要求の情報で指定する場合、情報媒体管理部213が複製取得の管理要求情報で指定する場合、又は情報管理DB制御部114が管理ファイル生成要求で指定する場合などさまざまな形態が可能である。
 また、管理ファイル生成部115は、ファイル格納情報、利用制限ポリシ及び情報管理サーバ情報をヘッダ部にセットする。これにより、ヘッダ部が生成される。
 続いて、管理ファイル生成部115は、ヘッダ部のファイル格納情報に基づいて、電子データに暗号処理を施し、この得られた暗号化電子データをボディ部にセットする。これにより、ボディ部が生成される。
 管理ファイル生成部115は、この生成されたヘッダ部及びボディ部に対し、公開鍵暗号に基づく電子署名方式やハッシュ関数や共通鍵暗号に基づくMAC方式に基づいて、認証データを生成する。この認証データを管理ファイルの認証データ部にセットする。これにより、管理ファイルが作成される。
 管理ファイル生成部115は、作成した管理ファイルを情報管理DB制御部114へ送出する。
 情報管理DB制御部114は、管理ファイルを受けると、管理ファイル、管理ID及び複製取得処理要求情報に基づき、電子データの管理IDに関連付けて、作成日時情報、作成者情報、媒体種別、利用制限ポリシ、所在情報及び実体IDを含む系統情報を情報管理DB121内の系統管理テーブル1212に登録する。ここで、電子データの管理IDは、親情報媒体の管理IDがある場合には親情報媒体の管理IDに関連付けて系統管理テーブル1212に登録する。
 また、対象となる管理IDが複数ある場合には、該当数の管理ファイル生成処理を行う。管理ファイルの構成例は、図2に示す通りである。管理ファイル生成部115は、生成した管理ファイルを情報管理DB制御部114へ送出する(ST106)。
 情報管理DB制御部114は、管理ファイルを受けると、情報管理DB121へ管理ファイル生成処理に関するアクセスログ情報をアクセスログ管理テーブル1214に登録する処理を実行すると共に、私書箱管理テーブル1213の当該私書箱IDに対応する投函数及び管理IDリストを空にする処理を実行する。しかる後、情報管理DB制御部114は、発行された管理ID、管理ファイル、日時及び操作種別を含む複製取得処理結果情報を情報管理制御部112へ送出する(ST107)。
 情報管理制御部112は、複製取得処理結果情報を管理要求受付部111へ送出する(ST108)。
 管理要求受付部111は、情報媒体制御装置201へ複製取得処理結果情報を送信する(ST109)。処理が失敗した場合には、エラー情報を送信する。
 管理要求送信部215は、図33に示すように、受信した複製取得処理結果情報を情報媒体管理部213へ送出する(ST110)。同時に、通信セッションの切断要求を情報管理サーバ装置101へ送信し、通信を切断する。
 情報媒体管理部213は、管理ファイル制御部216へ複製取得処理結果情報を送出し、処理結果を管理クライアントDB217へ登録するよう要求する(ST111)。
 管理ファイル制御部216は、複製取得処理結果情報に基づき、前述同様に、管理ID、ステイタス、管理ファイルヘッダ部分情報及び管理ファイル実体を管理ファイル管理テーブル2171に登録する。
 また同様に、管理ファイル制御部216は、アクセスログテーブル2172に、操作日時情報、操作種別、管理ID及び管理ファイル名を含む複製取得処理の操作ログを登録する。
 登録完了後、管理ファイル制御部216は、複製取得処理完了通知を情報媒体管理部213へ送出する(ST112)。複製取得処理完了通知には、当該電子データに対して発行された管理IDを含めてもよい。
 情報媒体管理部213は、複製取得処理完了通知を要求入出力部212へ送出する(ST113)。
 要求入出力部212は、複製取得完了通知を上位システム部211へ送出し、本要求セッションを終了させる(ST114)。
 上述したように本実施形態によれば、電子データの複製登録を要求する情報媒体制御装置201と、複製登録により生成された子管理ファイルを取得する情報媒体制御装置201とが別々の装置の場合でも、情報管理サーバ装置101においては、一方の情報媒体制御装置201から受けた複製登録要求情報に基づいて、電子データの子管理IDと子管理ファイルの取得先の私書箱IDとを私書箱管理テーブル1216に登録し、私書箱管理テーブル1216に基づいて子管理ファイルを他方の取得先の情報媒体制御装置201に取得させる。これにより、管理ファイルの複製を依頼したクライアントが子管理ファイルを他のクライアントに渡したい場合でも、子管理ファイルの情報ライフサイクルを管理することができる。
 <第2の実施形態>
 図34は本発明の第2の実施形態に係る情報ライフサイクル管理システムの構成を示す模式図であり、図3と同一部分には同一符号を付してその詳しい説明を省略し、ここでは異なる部分について主に述べる。なお、以下の各実施形態も同様にして重複した説明を省略する。
 本実施形態は、第1の実施形態の変形例であり、私書箱チェックを定期的かつ自動的に行う形態であって、図3に示した情報媒体制御装置201に対し、私書箱チェック制御部218を付加した構成となっている。
 ここで、私書箱チェック制御部218は、定期的に、又は所定条件を満たす場合に、私書箱IDを含む私書箱チェック要求を要求入出力部212に送出する機能をもっている。
 次に、以上のように構成された情報ライフサイクル管理システムの動作を説明する。
 私書箱チェック制御部218は、時間周期や定められた条件下で、指定した私書箱に対して私書箱チェック要求を要求入出力部212へ送出する。
 要求入出力部212は、この私書箱チェック要求を情報媒体管理部213へ送出し、ST93~ST100の処理を通じて私書箱確認結果を情報媒体管理部213から取得すると、当該私書箱確認結果を私書箱チェック制御部218へ送出する。
 私書箱チェック制御部218は、私書箱確認結果に基づき、対象となる私書箱に取得可能な管理ファイルが存在する場合、要求入出力部212へ取得可能な管理ファイルが存在することを通知する複製取得可能通知を送出する。
 要求入出力部212は、当該複製取得可能通知を上位システム部211へ送出し、複製取得処理を促す。
 上述したように本実施形態によれば、第1の実施形態の効果に加え、例えば定期的に私書箱チェック要求を要求入出力部212に送出する私書箱チェック制御部218を備えた構成により、複製された管理ファイルをより迅速に上位システム部211に取得させることができる。
 <第3の実施形態>
 図35は本発明の第3の実施形態に係る情報ライフサイクル管理システムの構成を示す模式図である。
 本実施形態は、第1の実施形態の変形例であり、私書箱の投函数や滞留日数を元に、情報管理サーバ装置101から当該私書箱に対応する情報媒体制御装置201へ滞留した管理ファイルの取得を能動的に要求する形態であって、図3に示した情報管理サーバ装置101に対し、私書箱確認依頼要求部116を付加した構成となっている。
 私書箱確認依頼要求部218は、定期的に、又は所定条件を満たす場合に、私書箱IDを含む私書箱チェック要求を要求入出力部212に送出する機能をもっている。
 次に、以上のように構成された情報ライフサイクル管理システムの動作を説明する。
 私書箱確認依頼要求部116は、時間周期や定められた条件下で、指定した私書箱に対して私書箱チェック要求を管理要求受付部111へ送出する。管理要求受付部111は、ST95~ST98の処理を通じて私書箱確認情報を取得し、当該私書箱確認情報を私書箱確認依頼要求部116へ送出する。
 私書箱確認依頼要求部116は、私書箱の投函数や私書箱への滞留日数といった私書箱滞留情報を確認して、規定条件を満たす場合、情報媒体制御装置201が私書箱チェックを実行するように私書箱確認依頼要求を管理要求受付部111を介して、当該子管理ファイルの取得先となる情報媒体制御装置201へ送信する。規定条件として、例えば、私書箱への投函数が10個を超えた場合や、私書箱への滞留日数が30日を超過した場合が考えられる。規定条件は、この限りではない。例えば、複製登録処理で管理要求受付部111を監視し、子管理IDが到達すると同時に、当該子管理ファイルの取得先となる情報媒体制御装置201へ私書箱チェックを実行するよう管理要求受付部111を通じて私書箱確認依頼要求を送信するようにしてもよい。
 上述したように本実施形態によれば、第1の実施形態の効果に加え、例えば定期的に私書箱チェック要求を管理要求受付部111に送出する私書箱確認依頼要求部116を備えた構成により、複製された管理ファイルをより迅速に情報媒体制御装置201に取得させることができる。
 なお、上記実施形態に記載した手法は、コンピュータに実行させることのできるプログラムとして、磁気ディスク(フロッピー(登録商標)ディスク、ハードディスクなど)、光ディスク(CD-ROM、DVDなど)、光磁気ディスク(MO)、半導体メモリなどの記憶媒体に格納して頒布することもできる。
 また、この記憶媒体としては、プログラムを記憶でき、かつコンピュータが読み取り可能な記憶媒体であれば、その記憶形式は何れの形態であっても良い。
 また、記憶媒体からコンピュータにインストールされたプログラムの指示に基づきコンピュータ上で稼働しているOS(オペレーティングシステム)や、データベース管理ソフト、ネットワークソフト等のMW(ミドルウェア)等が上記実施形態を実現するための各処理の一部を実行しても良い。
 さらに、本発明における記憶媒体は、コンピュータと独立した媒体に限らず、LANやインターネット等により伝送されたプログラムをダウンロードして記憶または一時記憶した記憶媒体も含まれる。
 また、記憶媒体は1つに限らず、複数の媒体から上記実施形態における処理が実行される場合も本発明における記憶媒体に含まれ、媒体構成は何れの構成であっても良い。
 なお、本発明におけるコンピュータは、記憶媒体に記憶されたプログラムに基づき、上記実施形態における各処理を実行するものであって、パソコン等の1つからなる装置、複数の装置がネットワーク接続されたシステム等の何れの構成であっても良い。
 また、本発明におけるコンピュータとは、パソコンに限らず、情報処理機器に含まれる演算処理装置、マイコン等も含み、プログラムによって本発明の機能を実現することが可能な機器、装置を総称している。
 なお、本願発明は、上記実施形態そのままに限定されるものではなく、実施段階ではその要旨を逸脱しない範囲で構成要素等を変形して具体化できる。例えば、情報媒体が電子データであった場合の当該電子データを、情報管理サーバ装置101において管理IDを含むファイル形式の電子ファイル管理ファイルへ変換するタイミングは、新規登録時及び複製登録時には行わず、複製取得の時に行うようにしても良いし、複製取得の要求がなされる前に管理ファイルを作成しておくようにしても良い。さらには、新規登録がなされた段階で、送付先のクライアントが予め予想できるときには、複製登録や複製取得よりも前に管理ファイルの変換を行っておくこともできる。
 また、上記実施形態に開示されている複数の構成要素の適宜な組合せにより種々の発明を形成できる。例えば、実施形態に示される全構成要素から幾つかの構成要素を削除してもよい。更に、異なる実施形態に亘る構成要素を適宜組合せてもよい。

Claims (5)

  1.  互いに通信可能な複数の情報媒体制御装置(201~201)及び情報管理サーバ装置(101)を備えた情報ライフサイクル管理システムであって、
     前記各情報媒体制御装置は、
     管理ID及び電子データ本体を含む子管理ファイルが書き込まれる管理ファイル管理テーブル(2171)を記憶する管理ファイル管理テーブル記憶手段(217)と、
     管理対象の電子データ本体を含む新規登録要求情報を情報管理サーバ装置に送信する手段(213,215,ST13~ST14)と、
     複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置に対応する私書箱IDを含む複製登録要求情報を前記情報管理サーバ装置に送信する手段(213,215,ST65~ST66)と、
     前記私書箱IDを含む私書箱チェック要求を前記情報管理サーバ装置に送信する手段(213,215,ST93~ST94)と、
     前記情報管理サーバ装置から受けた私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求を当該情報管理サーバ装置に送信する手段(213,215,ST100~ST102)と、
     前記情報管理サーバ装置から受けた子管理ファイルを前記管理ファイル管理テーブルに書き込む手段(213,215,216,ST110~ST112)と、
     を備えており、
     前記情報管理サーバ装置は、
     管理IDと実体IDとが互いに関連付けられて書き込まれ且つ当該管理IDに子管理IDが互いに関連付けられて書き込まれる系統管理テーブル(1212)を記憶する系統管理テーブル記憶手段(121)と、
     実体ID及び電子データ本体が書き込まれるデータ原本管理テーブル(1217)を記憶するデータ原本管理テーブル記憶手段(121)と、
     私書箱IDと子管理IDとが互いに関連付けられて書き込まれる私書箱管理テーブル(1213)を記憶する私書箱管理テーブル記憶手段(121)と、
     前記新規登録要求情報に基づいて、電子データ本体に対して管理ID及び実体IDを発行し、管理ID及び実体IDを前記系統管理テーブルに登録し、実体ID及び電子データ本体を前記データ原本管理テーブルに登録する手段(111,112,114,ST15~ST17)と、
     前記複製登録要求情報を受けると、当該複製登録要求情報内の管理IDと異なる子管理IDを発行し、前記系統管理テーブル内の管理IDのうち、複製登録要求情報内の管理IDと同一の管理IDに対応付けて、当該発行した子管理IDを当該系統管理テーブルに登録し、この子管理IDと複製登録要求内の私書箱IDとを関連付けて前記私書箱管理テーブルに登録し、子管理IDを含む複製登録処理結果情報を前記複製登録要求情報の送信元の情報媒体制御装置に送信する手段(111,112,114,ST67~ST71)と、
     前記私書箱チェック要求を受けると、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを前記私書箱管理テーブルから読み出して当該子管理IDを含む私書箱確認情報を前記私書箱チェック要求の送信元の情報媒体制御装置に送信する手段(111,112,114,ST95~ST99)と、
     前記複製取得要求を受けると、当該複製取得要求内の子管理IDに対応する実体IDを前記系統管理テーブルから読み出し、この実体IDに対応する電子データ本体を前記データ原本管理テーブルから読み出し、当該子管理ID及び電子データ本体を含む子管理ファイルを生成し、この子管理IDを前記私書箱管理テーブルから削除し、当該子管理ファイルを前記複製取得要求の送信元の情報媒体制御装置に送信する手段(111,112,114,ST103~ST109)と、
     を備えたことを特徴とする情報ライフサイクル管理システム。
  2.  複数の情報媒体制御装置(201~201)に個別に通信可能な情報管理サーバ装置(101)であって、
     管理IDと実体IDとが互いに関連付けられて書き込まれ且つ当該管理IDに子管理IDが互いに関連付けられて書き込まれる系統管理テーブル(1212)を記憶する系統管理テーブル記憶手段(121)と、
     実体ID及び電子データ本体が書き込まれるデータ原本管理テーブル(1217)を記憶するデータ原本管理テーブル記憶手段(121)と、
     私書箱IDと子管理IDとが互いに関連付けられて書き込まれる私書箱管理テーブル(1213)を記憶する私書箱管理テーブル記憶手段(121)と、
     管理対象の電子データ本体を含む新規登録要求情報をいずれかの情報媒体制御装置から受けると、前記新規登録要求情報に基づいて、電子データ本体に対して管理ID及び実体IDを発行し、管理ID及び実体IDを前記系統管理テーブルに登録し、実体ID及び電子データ本体を前記データ原本管理テーブルに登録する手段(111,112,114,ST15~ST17)と、
     複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置に対応する私書箱IDを含む複製登録要求情報をいずれかの情報媒体制御装置から受けると、当該複製登録要求情報内の管理IDと異なる子管理IDを発行し、前記系統管理テーブル内の管理IDのうち、複製登録要求情報内の管理IDと同一の管理IDに対応付けて、当該発行した子管理IDを当該系統管理テーブルに登録し、この子管理IDと複製登録要求内の私書箱IDとを関連付けて前記私書箱管理テーブルに登録し、子管理IDを含む複製登録処理結果情報を前記複製登録要求情報の送信元の情報媒体制御装置に送信する手段(111,112,114,ST67~ST71)と、
     私書箱IDを含む私書箱チェック要求をいずれかの情報媒体制御装置から受けると、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを前記私書箱管理テーブルから読み出して当該子管理IDを含む私書箱確認情報を前記私書箱チェック要求の送信元の情報媒体制御装置に送信する手段(111,112,114,ST95~ST99)と、
     前記私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求をいずれかの情報媒体制御装置から受けると、当該複製取得要求内の子管理IDに対応する実体IDを前記系統管理テーブルから読み出し、この実体IDに対応する電子データ本体を前記データ原本管理テーブルから読み出し、当該子管理ID及び電子データ本体を含む子管理ファイルを生成し、この子管理IDを前記私書箱管理テーブルから削除し、当該子管理ファイルを前記複製取得要求の送信元の情報媒体制御装置に送信する手段(111,112,114,ST103~ST109)と、
     を備えたことを特徴とする情報管理サーバ装置。
  3.  情報管理サーバ装置(101)に通信可能な情報媒体制御装置(201)であって、
     管理ID及び電子データ本体を含む子管理ファイルが書き込まれる管理ファイル管理テーブル(2171)を記憶する管理ファイル管理テーブル記憶手段(217)と、
     管理対象の電子データ本体を含む新規登録要求情報を情報管理サーバ装置に送信する手段(213,215,ST13~ST14)と、
     複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置に対応する私書箱IDを含む複製登録要求情報を前記情報管理サーバ装置に送信する手段(213,215,ST65~ST66)と、
     前記私書箱IDを含む私書箱チェック要求を前記情報管理サーバ装置に送信する手段(213,215,ST93~ST94)と、
     前記私書箱チェック要求の送信により、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを含む私書箱確認情報を前記情報管理サーバ装置から受けると、この私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求を当該情報管理サーバ装置に送信する手段(213,215,ST100~ST102)と、
     前記複製取得要求の送信により、当該複製取得要求内の子管理IDを含む子管理ファイルを前記情報管理サーバ装置から受けると、この子管理ファイルを前記管理ファイル管理テーブルに書き込む手段(213,215,216,ST110~ST112)と、
     を備えたことを特徴とする情報媒体制御装置。
  4.  複数の情報媒体制御装置(201~201)に個別に通信可能で記憶装置(121)を備えた情報管理サーバ装置(101)に用いられ、コンピュータ読み取り可能な記憶媒体(M)に記憶されたプログラムであって、
     管理IDと実体IDとが互いに関連付けられて書き込まれ且つ当該管理IDに子管理IDが互いに関連付けられて書き込まれる系統管理テーブル(1212)を前記記憶装置に書き込む処理を前記情報管理サーバ装置に実行させるための第1プログラムコード、
     実体ID及び電子データ本体が書き込まれるデータ原本管理テーブル(1217)を前記記憶装置に書き込む処理を前記情報管理サーバ装置に実行させるための第2プログラムコード、
     私書箱IDと子管理IDとが互いに関連付けられて書き込まれる私書箱管理テーブル(1213)を前記記憶装置に書き込む処理を前記情報管理サーバ装置に実行させるための第3プログラムコード、
     管理対象の電子データ本体を含む新規登録要求情報をいずれかの情報媒体制御装置から受けると、前記新規登録要求情報に基づいて、電子データ本体に対して管理ID及び実体IDを発行し、管理ID及び実体IDを前記系統管理テーブルに登録し、実体ID及び電子データ本体を前記データ原本管理テーブルに登録する処理を前記情報管理サーバ装置に実行させるための第4プログラムコード(111,112,114,ST15~ST17)、
     複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置に対応する私書箱IDを含む複製登録要求情報をいずれかの情報媒体制御装置から受けると、当該複製登録要求情報内の管理IDと異なる子管理IDを発行し、前記系統管理テーブル内の管理IDのうち、複製登録要求情報内の管理IDと同一の管理IDに対応付けて、当該発行した子管理IDを当該系統管理テーブルに登録し、この子管理IDと複製登録要求内の私書箱IDとを関連付けて前記私書箱管理テーブルに登録し、子管理IDを含む複製登録処理結果情報を前記複製登録要求情報の送信元の情報媒体制御装置に送信する処理を前記情報管理サーバ装置に実行させるための第5プログラムコード(111,112,114,ST67~ST71)、
     私書箱IDを含む私書箱チェック要求をいずれかの情報媒体制御装置から受けると、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを前記私書箱管理テーブルから読み出して当該子管理IDを含む私書箱確認情報を前記私書箱チェック要求の送信元の情報媒体制御装置に送信する処理を前記情報管理サーバ装置に実行させるための第6プログラムコード(111,112,114,ST95~ST99)、及び
     前記私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求をいずれかの情報媒体制御装置から受けると、当該複製取得要求内の子管理IDに対応する実体IDを前記系統管理テーブルから読み出し、この実体IDに対応する電子データ本体を前記データ原本管理テーブルから読み出し、当該子管理ID及び電子データ本体を含む子管理ファイルを生成し、この子管理IDを前記私書箱管理テーブルから削除し、当該子管理ファイルを前記複製取得要求の送信元の情報媒体制御装置に送信する処理を前記情報管理サーバ装置に実行させるための第7プログラムコード(111,112,114,ST103~ST109)、
     を備えたことを特徴とするプログラム。
  5.  情報管理サーバ装置(101)に通信可能であり、記憶装置(217)を備えた情報媒体制御装置(201)に用いられ、コンピュータ読み取り可能な記憶媒体(M)に記憶されたプログラムであって、
     管理ID及び電子データ本体を含む子管理ファイルが書き込まれる管理ファイル管理テーブル(2171)を前記記憶装置に書き込む処理を前記情報媒体制御装置に実行させるための第1プログラムコード、
     管理対象の電子データ本体を含む新規登録要求情報を情報管理サーバ装置に送信する処理を前記情報媒体制御装置に実行させるための第2プログラムコード(213,215,ST13~ST14)、
     複製登録対象の電子データに対応する管理ID、及び複製取得先の情報媒体制御装置に対応する私書箱IDを含む複製登録要求情報を前記情報管理サーバ装置に送信する処理を前記情報媒体制御装置に実行させるための第3プログラムコード(213,215,ST65~ST66)、
     前記私書箱IDを含む私書箱チェック要求を前記情報管理サーバ装置に送信する処理を前記情報媒体制御装置に実行させるための第4プログラムコード(213,215,ST93~ST94)、
     前記私書箱チェック要求の送信により、当該私書箱チェック要求内の私書箱IDに対応する子管理IDを含む私書箱確認情報を前記情報管理サーバ装置から受けると、この私書箱確認情報内の子管理IDのうち、複製取得対象の管理ファイルに対応する子管理IDを含む複製取得要求を当該情報管理サーバ装置に送信する処理を前記情報媒体制御装置に実行させるための第5プログラムコード(213,215,ST100~ST102)、及び
     前記複製取得要求の送信により、当該複製取得要求内の子管理IDを含む子管理ファイルを前記情報管理サーバ装置から受けると、この子管理ファイルを前記管理ファイル管理テーブルに書き込む処理を前記情報媒体制御装置に実行させるための第6プログラムコード(213,215,216,ST110~ST112)、
     を備えたことを特徴とするプログラム。
PCT/JP2009/071345 2008-12-26 2009-12-22 情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム Ceased WO2010074094A1 (ja)

Priority Applications (2)

Application Number Priority Date Filing Date Title
CN200980152350.7A CN102265286B (zh) 2008-12-26 2009-12-22 信息生命周期管理系统、信息管理服务器装置及信息介质控制装置
US13/167,860 US8478724B2 (en) 2008-12-26 2011-06-24 Information life cycle management system, information management server apparatus, information media controlling apparatus and program

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2008333595A JP4521462B2 (ja) 2008-12-26 2008-12-26 情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム
JP2008-333595 2008-12-26

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US13/167,860 Continuation US8478724B2 (en) 2008-12-26 2011-06-24 Information life cycle management system, information management server apparatus, information media controlling apparatus and program

Publications (1)

Publication Number Publication Date
WO2010074094A1 true WO2010074094A1 (ja) 2010-07-01

Family

ID=42287702

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2009/071345 Ceased WO2010074094A1 (ja) 2008-12-26 2009-12-22 情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム

Country Status (4)

Country Link
US (1) US8478724B2 (ja)
JP (1) JP4521462B2 (ja)
CN (1) CN102265286B (ja)
WO (1) WO2010074094A1 (ja)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2012001763A1 (ja) * 2010-06-28 2012-01-05 株式会社日立製作所 計算機システムの管理方法及びクライアントコンピュータ
US8533850B2 (en) 2010-06-29 2013-09-10 Hitachi, Ltd. Fraudulent manipulation detection method and computer for detecting fraudulent manipulation
US8850592B2 (en) 2010-03-10 2014-09-30 Hitachi, Ltd. Unauthorized operation detection system and unauthorized operation detection method

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5132698B2 (ja) * 2010-02-18 2013-01-30 株式会社東芝 選択的複製システム及び情報管理サーバ装置
KR20120033718A (ko) * 2010-09-30 2012-04-09 삼성전자주식회사 화상형성장치 및 그 장치에서의 이메일 전송 방법
US11271751B2 (en) * 2019-06-21 2022-03-08 Oracle International Corporation Distributed data records
CN111881087A (zh) * 2020-07-30 2020-11-03 北京浪潮数据技术有限公司 一种文件管理操作方法及相关装置

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH08190516A (ja) * 1995-01-10 1996-07-23 Nippon Telegr & Teleph Corp <Ntt> ドキュメント到着報告方法及びドキュメント到着報告システム
JPH08265361A (ja) * 1995-03-20 1996-10-11 Mitsubishi Denki Bill Techno Service Kk 電子回覧システム
JPH08292961A (ja) * 1995-04-20 1996-11-05 Fuji Xerox Co Ltd 文書複写関係管理システム
JPH11259459A (ja) * 1998-03-06 1999-09-24 Fuji Xerox Co Ltd 文書管理装置
JP2005189995A (ja) * 2003-12-24 2005-07-14 Hitachi Ltd ファイル授受プロセス管理方法、および、ファイル授受プロセス可視化方法、ならびに、ファイル授受システムにおけるファイル授受プロセス管理装置、および、ユーザ端末

Family Cites Families (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4340529B2 (ja) 2003-12-26 2009-10-07 株式会社リコー 出力文書管理システム、出力文書管理サーバ、出力文書管理方法、出力文書管理プログラム
JP4569228B2 (ja) * 2004-09-02 2010-10-27 ソニー株式会社 データ処理方法、情報記録媒体製造管理システム、記録データ生成装置、および方法、並びにコンピュータ・プログラム
JP2007088796A (ja) 2005-09-21 2007-04-05 Konica Minolta Business Technologies Inc 文書管理装置及びプログラム
JP4800137B2 (ja) 2006-07-21 2011-10-26 浜松ホトニクス株式会社 光電管
JP5127489B2 (ja) * 2008-02-07 2013-01-23 株式会社東芝 情報ライフサイクル管理システム、情報管理サーバ装置、電子媒体制御装置及びプログラム

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JPH08190516A (ja) * 1995-01-10 1996-07-23 Nippon Telegr & Teleph Corp <Ntt> ドキュメント到着報告方法及びドキュメント到着報告システム
JPH08265361A (ja) * 1995-03-20 1996-10-11 Mitsubishi Denki Bill Techno Service Kk 電子回覧システム
JPH08292961A (ja) * 1995-04-20 1996-11-05 Fuji Xerox Co Ltd 文書複写関係管理システム
JPH11259459A (ja) * 1998-03-06 1999-09-24 Fuji Xerox Co Ltd 文書管理装置
JP2005189995A (ja) * 2003-12-24 2005-07-14 Hitachi Ltd ファイル授受プロセス管理方法、および、ファイル授受プロセス可視化方法、ならびに、ファイル授受システムにおけるファイル授受プロセス管理装置、および、ユーザ端末

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US8850592B2 (en) 2010-03-10 2014-09-30 Hitachi, Ltd. Unauthorized operation detection system and unauthorized operation detection method
US9124616B2 (en) 2010-04-02 2015-09-01 Hitachi, Ltd. Computer system management method and client computer
WO2012001763A1 (ja) * 2010-06-28 2012-01-05 株式会社日立製作所 計算機システムの管理方法及びクライアントコンピュータ
JP5417533B2 (ja) * 2010-06-28 2014-02-19 株式会社日立製作所 計算機システムの管理方法及びクライアントコンピュータ
US8533850B2 (en) 2010-06-29 2013-09-10 Hitachi, Ltd. Fraudulent manipulation detection method and computer for detecting fraudulent manipulation

Also Published As

Publication number Publication date
US8478724B2 (en) 2013-07-02
JP2010157022A (ja) 2010-07-15
JP4521462B2 (ja) 2010-08-11
US20110307446A1 (en) 2011-12-15
CN102265286B (zh) 2014-11-19
CN102265286A (zh) 2011-11-30

Similar Documents

Publication Publication Date Title
JP4011243B2 (ja) 電子原本管理装置および方法
JP5127489B2 (ja) 情報ライフサイクル管理システム、情報管理サーバ装置、電子媒体制御装置及びプログラム
JP4521462B2 (ja) 情報ライフサイクル管理システム、情報管理サーバ装置、情報媒体制御装置及びプログラム
JP5355227B2 (ja) 文書管理支援システム、情報管理サーバ装置及び情報媒体制御装置
US11449285B2 (en) Document security and integrity verification based on blockchain in image forming device
US20230232222A1 (en) User terminal, authentication terminal, registration terminal, management system and program
JP5012525B2 (ja) セキュリティポリシーサーバ、セキュリティポリシー管理システム及びセキュリティポリシー管理プログラム
JP2004110197A (ja) センタ・システムにおける情報処理方法及びアクセス権限管理方法
US8675216B2 (en) Selective duplicating system and information management server device
US7797277B2 (en) Document management system, program, and computer data signal
JP2001077809A (ja) 電子証明書管理装置,方法および記録媒体
CN104145275B (zh) 复合媒体管理系统、信息管理服务器装置、复合利用制约制作装置及程序
JP4838734B2 (ja) 電子原本管理装置および方法
JP4011593B2 (ja) 電子原本管理装置および方法
JP3974144B2 (ja) 電子原本管理装置および方法
JP3974145B2 (ja) 電子原本管理装置および方法
JP2002082934A (ja) 履歴管理方法及び記憶媒体
CN119579249A (zh) 基于区块链的资源兑换方法、装置、设备、介质及产品

Legal Events

Date Code Title Description
WWE Wipo information: entry into national phase

Ref document number: 200980152350.7

Country of ref document: CN

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09834895

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 4840/DELNP/2011

Country of ref document: IN

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09834895

Country of ref document: EP

Kind code of ref document: A1