WO2019064458A1 - コンピュータシステム、セキュリティ設定提案方法及びプログラム - Google Patents

コンピュータシステム、セキュリティ設定提案方法及びプログラム Download PDF

Info

Publication number
WO2019064458A1
WO2019064458A1 PCT/JP2017/035309 JP2017035309W WO2019064458A1 WO 2019064458 A1 WO2019064458 A1 WO 2019064458A1 JP 2017035309 W JP2017035309 W JP 2017035309W WO 2019064458 A1 WO2019064458 A1 WO 2019064458A1
Authority
WO
WIPO (PCT)
Prior art keywords
security
user
user information
security set
user terminal
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/JP2017/035309
Other languages
English (en)
French (fr)
Inventor
俊二 菅谷
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Optim Corp
Original Assignee
Optim Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Optim Corp filed Critical Optim Corp
Priority to PCT/JP2017/035309 priority Critical patent/WO2019064458A1/ja
Priority to US16/651,596 priority patent/US11916961B2/en
Priority to CN201780095464.7A priority patent/CN111164598B/zh
Priority to JP2019545515A priority patent/JP6775749B2/ja
Publication of WO2019064458A1 publication Critical patent/WO2019064458A1/ja
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/102Entity profiles
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • H04L63/105Multiple levels of security

Definitions

  • the present invention relates to a computer system, a security setting proposal method, and a program for proposing a security set appropriate for user information.
  • this method can provide an automatic and effective filtering function, the filtering result is the same as long as the learning information vector group is the same, so that the filtering criteria may be changed according to the user's attribute. Can not. Further, since the present invention is only filtering based on character information, there is a problem that effective security can not be set to other functions such as a telephone, a GPS function, and a settlement function provided in the user terminal 10.
  • the present invention provides a computer system, a security setting proposal method, and a program for proposing a security set suitable for a user from statistical information of statistical security parameters collected together with user information. With the goal.
  • the present invention provides the following solutions.
  • the invention according to the first aspect is a computer system communicably connected to one or more user terminals, comprising a security statistics database, Proposal request acquisition means for acquiring a proposal request of a security set from the user terminal together with user information including at least an attribute; A security set for extracting a security set associated with user information similar to the user information in the same range as the user information or within a predetermined range from the security set statistical database using the user information acquired together with the proposal request Extraction means, Proposal security set provision means for providing the user terminal with the one or more extracted security sets as a proposal security set; Providing a computer system characterized by comprising:
  • a computer system communicably connected to one or more user terminals and provided with a security statistical database is a proposal of a security set from the user terminal together with user information including at least an attribute.
  • a security set associated with user information similar to the user information in the same range as the user information or similar to the user information from the security set statistical database using the user information acquired with the request and acquired together with the proposal request And provide the one or more extracted security sets as a proposed security set to the user terminal.
  • the invention according to the first aspect is a category of computer system, but even a method and a program exhibit similar operations and effects according to the category.
  • the present invention it is possible to provide a computer system, a security setting proposal method, and a program for proposing an appropriate security set for a user from statistical information of statistical security parameters collected together with user information. .
  • FIG. 1 is a schematic view of a security setting proposal system 1 according to a preferred embodiment of the present invention.
  • FIG. 2 is an overall configuration diagram of the security setting proposal system 1.
  • FIG. 3 is a diagram showing the relationship between the functional blocks of the user terminal 10 and the security setting proposal server 200 and the respective functions.
  • FIG. 4 is a flowchart of the security setting proposal process performed by the user terminal 10 and the security setting proposal server 200.
  • FIG. 5 is an example of the screen of the user terminal 10 that has received the proposal of the security setting.
  • FIG. 6 is an example of a security set table in the security set statistics database 250.
  • FIG. 7 is an example of a security set statistics table in the security set statistics database 250.
  • FIG. 1 is a view for explaining an outline of a security setting proposal system 1 according to a preferred embodiment of the present invention. The outline of the security setting proposal system 1 will be described based on FIG.
  • the security setting proposal server 200 can communicate with a plurality of user terminals 10.
  • the terminal that receives the security setting proposal is distinguished as the user terminal 10, and the other user terminals 10 as the user terminal 10a, the user terminal 10b, and the user terminal 10c.
  • the user terminal 10a, the user terminal 10b, and the user terminal 10c transmit the security set in use together with the user information to the security setting proposal server 200 (step S01).
  • the security set is a series combination of parameters used as a security setting, and is a combination of setting parameters such as use place restriction of the user terminal 10, Internet restriction, telephone restriction, use time restriction, for example. These parameters may be flags that take on and off binary values, or may be specific values. Specific values include, for example, the range of location information for which use is permitted, the domain of a website for which access is not permitted, search words for which search results are not displayed, and numerical values of continuous use time related to use time restrictions. Be
  • the security setting proposal server 200 associates the received security set with the user information, and stores it in the security set statistics database 250 provided in the storage unit (step S02).
  • the security set statistics database 250 is a database that stores the security set in use for each user information as statistical data.
  • the security setting proposal system 1 acquires the security set and the user information by receiving the security set and the user information from the user terminal 10.
  • the user terminal 10 receiving the proposal of the security set this time transmits a proposal request to the security setting proposal server 200 together with the user information (step S05).
  • the user information may include at least an attribute of the user, and may be a value treated as a variable that can take significant statistics when providing a security set suitable for the user. That is, it is not an identifier that can identify a user, such as a personal name or a telephone number, but indicates demographic information such as information on a job (job title, title, hours of service, years of service).
  • the user terminal 10 performs predetermined questions such as questionnaire items such as whether to activate the Internet restriction in the security set or questions that measure the user's understanding of the Internet, and includes the result in the user information, It is possible to collect statistics of a more appropriate security set according to the user's request and understanding level.
  • predetermined questions such as questionnaire items such as whether to activate the Internet restriction in the security set or questions that measure the user's understanding of the Internet, and includes the result in the user information. It is possible to collect statistics of a more appropriate security set according to the user's request and understanding level.
  • the security setting proposal server 200 When the security setting proposal server 200 receives the proposal request, it extracts statistical information using the user information received simultaneously (step S04).
  • the security setting proposal system 1 acquires a proposal request by receiving a proposal request from the user terminal 10. And a proposal security set is produced
  • the security setting proposal system 1 provides the proposal security set by transmitting the proposal security set from the security setting proposal server 200 to the user terminal 10.
  • the simplest of the proposed security sets is to transmit statistical information of usage rates of a plurality of security sets as a pie chart as shown in FIG.
  • the user can select an appropriate security set while looking at the graph and details of the security set.
  • the user may customize individually or reflect the request answered for the question item. .
  • the above is the outline of the security setting proposal system 1.
  • FIG. 2 is an overall configuration diagram of the security setting proposal system 1.
  • the security setting proposal system 1 includes a plurality of user terminals 10 and a security setting proposal server 200.
  • the user terminal 10 and the security setting proposal server 200 are communicably connected via the public line network 3, respectively.
  • the user terminals 10 need not be able to communicate with each other.
  • the user terminal 10 may be a general information terminal used by a user, and is an information device or an electric appliance having a function to be described later.
  • the user terminal 10 may be, for example, a mobile phone, a smart phone, a combined printer, a network device such as a television, a router or a gateway, a computer, a white goods such as a refrigerator or a washing machine, It may be a general information appliance such as a book terminal, a slate terminal, an electronic book terminal, an electronic dictionary terminal, a portable music player, and a portable content reproduction / recording player.
  • the security setting proposal server 200 is a server that proposes a security set, and includes a security set statistics database 250 in a storage unit, and is an information device or an electric appliance having a function described later.
  • FIG. 3 is a diagram showing the relationship between the functional blocks of the user terminal 10 and the security setting proposal server 200 and the respective functions.
  • the user terminal 10 includes, as the control unit 11, a central processing unit (CPU), a random access memory (RAM), a read only memory (ROM), and the like, and as the communication unit 12, for example, WiFi (Wireless) compliant with IEEE 802.11.
  • the control unit 11 a central processing unit (CPU), a random access memory (RAM), a read only memory (ROM), and the like
  • the communication unit 12 for example, WiFi (Wireless) compliant with IEEE 802.11.
  • WiFi Wireless
  • a Fidelity compatible device or a wireless device conforming to the IMT-2000 standard such as a third generation mobile communication system is provided (a wired LAN connection may be used).
  • the user terminal 10 includes, as the input / output unit 13, an output unit for outputting and displaying data controlled by the control unit, an image, and a voice, and an input unit such as a touch panel, a keyboard, or a mouse receiving input from the user. Prepare.
  • the control unit 11 when the control unit 11 reads a predetermined program, the user information transmission module 14, the proposal request transmission module 15, the proposal security set reception module 16, and the proposal security set setting module cooperate with the communication unit 12. Realize 17. Further, in the user terminal 10, the control unit 11 reads a predetermined program to realize the question execution module 18 in cooperation with the input / output unit 13.
  • the security setting proposal server 200 includes a CPU, a RAM, a ROM, and the like as the control unit 201, and includes, for example, a WiFi compatible device compliant with IEEE 802.11 as the communication unit 202 (may be wired).
  • the security setting proposal server 200 includes, as the storage unit 203, a storage unit of data by a hard disk or a semiconductor memory.
  • the storage unit 203 includes a security set statistics database 250 in the storage unit.
  • the control unit 201 of the security setting proposal server 200 When the control unit 201 of the security setting proposal server 200 reads a predetermined program, the security set reception module 204, the user information reception module 205, the proposal request reception module 206, and the proposal security set transmission module cooperate with the communication unit 202. Realize 207. Further, the control unit 201 of the security setting proposal server 200 reads a predetermined program to realize the security set storage module 208 and the security set extraction module 209 in cooperation with the storage unit 203.
  • FIG. 4 is a flowchart of security setting proposal processing executed by the user terminal 10 and the security setting proposal server 200. The processing performed by the module of each device described above will be described together in this processing.
  • the question execution module 18 of the user terminal 10 performs a question for the user based on a predetermined question item (step S11).
  • This question is to receive suggestions for appropriate security settings, and is used to obtain user's demographic information, discuss security settings requests, and measure users' familiarity with the Internet and terminals. .
  • it may be considered to request the presence or absence of the Internet restriction, and the history of use of the Internet.
  • the user information transmission module 14 of the user terminal 10 transmits the answer to the question and the user's own information together as user information to the security setting proposal server 200 (step S12), and the user of the security setting proposal server 200
  • the information receiving module 205 receives this (step S13).
  • user information other than the question items is mainly demographic information, that is, demographic information.
  • the information indicating the attribute of the user includes information on the job duties (title, title, hours of use, years of service, etc.) of the user, and may be read from the registration information of the user terminal 10, You may get information by asking questions like
  • the proposal request transmission module 15 of the user terminal 10 transmits a security setting proposal request (step S14), and the proposal request receiving module 206 of the security setting proposal server 200 receives this (step S15).
  • the security set extraction module 209 of the security setting proposal server 200 extracts the security set from the security set statistics database 250 using the user information received together with the proposal request (step S16). Since the security set and the user information are stored in association with each other in the security set statistical database 250, the security set statistical data is created by extracting the security set whose user information is the same or similar and counting the number of each. It is possible.
  • FIG. 6 is an example of a security set table in the security set statistics database 250.
  • the security set table combinations of parameters that configure security settings are stored as a security set together with the security set name.
  • "security set A” has usage time restriction, Internet restriction, mail restriction, and GPS tracking enabled, and telephone restriction disabled.
  • security set statistics table in the security set statistics database 250.
  • security sets and user information in use are associated and stored.
  • security set A when the security set of the user whose user attribute is “1” to “3” is extracted, “security set A” is extracted.
  • security setting B when the security set of the user whose user attribute is “4” to “5” is extracted, “security setting B” is extracted.
  • security setting C when the security set of the user whose user attribute is “10” to “12” is extracted.
  • the attributes are obtained by numerically evaluating the positions, titles, hours of use, years of service, etc. described above.
  • the user terminal 10 is highly quantified for a user who is expected to use the terminal for a longer time than usual, such as midnight or early morning. Also, it is quantified based on the length of service years of the user. As the "attribute" actually stored as user information, any one of the average, the maximum value, and the minimum value of each of these numerical values is used. The security setting is such that the higher the value of the attribute, the more relaxed the restriction.
  • each numerical value may be weighted based on the job content of each user, and the numerical value of the content for which the weight is set to be the largest may be used as the numerical value of the "attribute”.
  • numerical values may be evaluated based on other conditions, and the evaluation result may be used as the numerical value of “attribute”. Further, the details of the restriction in the security setting may be determined for each numerical value instead of the numerical value of the attribute.
  • the extraction condition can be specified by the contents of the question item included in the user information, or the value may have a width to increase similar information.
  • the range of plus or minus 3 is extracted as similar from the received attribute of the user, the question item A which does not have a large influence in certain attribute is ignored and extracted, or the attribute of the user of certain attribute is extracted similar It is also possible to extract the similarity of the user's attribute of the attribute within the predetermined range without doing so.
  • the proposed security set transmission module 207 transmits the extracted security set to the user terminal 10 as a proposed security set (step S17).
  • the proposed security set may be all of the extracted security sets, or may be processed or sorted from the extracted security sets. For example, it is possible to exclude security sets that are obviously inconsistent with the answer to the question item, such as being disabled when you wish to restrict the Internet. Also, the proposed security set may include multiple security sets and allow the user to select among them.
  • the proposed security set setting module 17 sets the proposed security set as the security setting of the user terminal 10 (step S19).
  • FIG. 5 is an example of the screen of the user terminal 10 that has received the proposed security set.
  • the demographic information 51 conditions for extracting statistical information are indicated, and statistical information 52 is indicated below the condition.
  • pressing the setting button 53 it is possible to set the corresponding security set in the user terminal 10. Further, by touching each item of the pie chart, details of each item may be shown, and it may be set after making any change to the security set.
  • the user terminal 10 transmits the content of the set security set to the security setting proposal server (step S20).
  • the security set reception module 204 of the security setting proposal server 200 receives this (step S21).
  • the security set storage module 208 of the security setting proposal server 200 stores the received security set in the security set statistics database 250 in association with the user information received in step S13 (step S21). By doing this, statistical information available at the next proposal request increases.
  • the above-described means and functions are realized by a computer (including a CPU, an information processing device, and various terminals) reading and executing a predetermined program.
  • the program is provided, for example, in the form of being provided from a computer via a network (SaaS: software as a service).
  • the program is provided, for example, in the form of being recorded on a computer readable recording medium such as a flexible disk, a CD (CD-ROM etc.), a DVD (DVD-ROM, DVD-RAM etc).
  • the computer reads the program from the recording medium, transfers the program to the internal storage device or the external storage device, stores it, and executes it.
  • the program may be recorded in advance in a storage device (recording medium) such as, for example, a magnetic disk, an optical disk, or a magneto-optical disk, and may be provided from the storage device to the computer via a communication line.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Theoretical Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Automation & Control Theory (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

【課題】ユーザ情報とともに収集した統計的なセキュリティパラメータの統計情報から、あるユーザに対して適切なセキュリティセットを提案するコンピュータシステム、セキュリティ設定提案方法及びプログラムを提供することを目的とする。 【解決手段】一以上のユーザ端末10と通信可能に接続され、セキュリティ統計データベース250を備えたコンピュータシステムは、ユーザ端末10から、少なくとも属性を含むユーザ情報とともに、セキュリティセットの提案要求を取得し、この提案要求とともに取得したユーザ情報を用いて、セキュリティセット統計データベース250から、ユーザ情報と同一、又は所定の範囲でユーザ情報と類似するユーザ情報に関連付けられているセキュリティセットを抽出し、抽出した一以上のセキュリティセットを提案セキュリティセットとして、ユーザ端末10に提供する。

Description

コンピュータシステム、セキュリティ設定提案方法及びプログラム
 本発明は、ユーザ情報に対して適切なセキュリティセットを提案するコンピュータシステム、セキュリティ設定提案方法及びプログラムに関する。
 近年、公衆回線網に接続された携帯端末をWebサーバ等と接続することで、ユーザに様々なサービスが提供されている。特に、スマートフォン(高機能携帯電話)の登場により、従来、パソコンに対して行われていた高度なサービスを、携帯電話で行うことが可能になってきた。
 しかしながら、ユーザ端末の普及に伴い、インターネットに精通していなかったりするユーザが、個人の端末により、業務に関する情報を扱う事例が増えてきている。そうしたユーザによるインターネットへの無制限なアクセスを許可した結果、有害なコンテンツが提供されてしまったり、情報の漏洩が発生してしまったりすることがあった。
 したがって、こうしたユーザ端末には、利用するユーザに応じて適切なセキュリティを設定することで、利便性を可能な限り損なわずに、危険を回避する必要がある。
 このような課題に対して、協調フィルタリングを用いて、有害情報を自動的にフィルタリングする手法が開示されている。
特開2002-222193号公報
 特許文献1において開示される手法では、ブラウザに取り込もうとするインターネット情報から文字情報を抽出し、入力文ベクトルQを作成する。そしてあらかじめ登録してある学習情報ベクトル群30中の学習情報ベクトル各々との類似度又は相関係数を算出し、類似度又は相関係数が高い学習情報ベクトル群を抽出する。そして抽出された学習情報ベクトル群中に含まれる単語のスコアを利用して拡張対象単語を選択し、元の入力文ベクトルに対する拡張入力文ベクトルQnewを作成する。そしてこの拡張入力文ベクトルを用いて、取得しようとしているインターネット情報が不適切情報であるか否かを判断し、不適切情報であればその取込みを阻止する。
 しかしながら、この手法は自動的で有効なフィルタリング機能を提供可能ではあるものの、学習情報ベクトル群が同一である限りフィルタリング結果が同一となるため、ユーザの属性に応じてフィルタリングの基準を変更することができない。また、本発明は文字情報に基づくフィルタリングに過ぎないため、ユーザ端末10が備える電話やGPS機能、決済機能といった他の機能に有効なセキュリティを設定することもできないという課題がある。
 本発明は、これらの課題に鑑み、ユーザ情報とともに収集した統計的なセキュリティパラメータの統計情報から、あるユーザに対して適切なセキュリティセットを提案するコンピュータシステム、セキュリティ設定提案方法及びプログラムを提供する事を目的とする。
 本発明では、以下のような解決手段を提供する。
 第1の特徴に係る発明は、一以上のユーザ端末と通信可能に接続され、セキュリティ統計データベースを備えたコンピュータシステムであって、
 前記ユーザ端末から、少なくとも属性を含むユーザ情報とともに、セキュリティセットの提案要求を取得する提案要求取得手段と、
 前記提案要求とともに取得したユーザ情報を用いて、前記セキュリティセット統計データベースから、当該ユーザ情報と同一、又は所定の範囲で当該ユーザ情報と類似するユーザ情報に関連付けられているセキュリティセットを抽出するセキュリティセット抽出手段と、
 前記抽出した一以上のセキュリティセットを提案セキュリティセットとして、前記ユーザ端末に提供する提案セキュリティセット提供手段と、
 を備えることを特徴とするコンピュータシステムを提供する。
 第1の特徴に係る発明によれば、一以上のユーザ端末と通信可能に接続され、セキュリティ統計データベースを備えたコンピュータシステムは、前記ユーザ端末から、少なくとも属性を含むユーザ情報とともに、セキュリティセットの提案要求を取得し、前記提案要求とともに取得したユーザ情報を用いて、前記セキュリティセット統計データベースから、当該ユーザ情報と同一、又は所定の範囲で当該ユーザ情報と類似するユーザ情報に関連付けられているセキュリティセットを抽出し、前記抽出した一以上のセキュリティセットを提案セキュリティセットとして、前記ユーザ端末に提供する。
 第1の特徴に係る発明は、コンピュータシステムのカテゴリであるが、方法及びプログラムであってもカテゴリに応じた同様の作用、効果を奏する。
 本発明によれば、ユーザ情報とともに収集した統計的なセキュリティパラメータの統計情報から、あるユーザに対して適切なセキュリティセットを提案するコンピュータシステム、セキュリティ設定提案方法及びプログラムを提供することが可能となる。
図1は、本発明の好適な実施形態であるセキュリティ設定提案システム1の概要図である。 図2は、セキュリティ設定提案システム1の全体構成図である。 図3は、ユーザ端末10、セキュリティ設定提案サーバ200の機能ブロックと各機能の関係を示す図である。 図4は、ユーザ端末10、セキュリティ設定提案サーバ200が実行するセキュリティ設定提案処理のフローチャート図である。 図5は、セキュリティ設定の提案を受けたユーザ端末10の画面の一例である。 図6は、セキュリティセット統計データベース250内のセキュリティセットテーブルの一例である。 図7は、セキュリティセット統計データベース250内のセキュリティセット統計テーブルの一例である。
 以下、本発明を実施するための最良の形態について図を参照しながら説明する。なお、これはあくまでも一例であって、本発明の技術的範囲はこれに限られるものではない。
 [セキュリティ設定提案システム1の概要]
 図1は、本発明の好適な実施形態であるセキュリティ設定提案システム1の概要を説明するための図である。この図1に基づいて、セキュリティ設定提案システム1の概要を説明する。
 セキュリティ設定提案システム1において、セキュリティ設定提案サーバ200は、複数のユーザ端末10と通信可能となっている。ここでは、今セキュリティ設定の提案を受ける端末をユーザ端末10、それ以外のユーザ端末10をユーザ端末10a、ユーザ端末10b、ユーザ端末10cとして区別する。
 初めに、ユーザ端末10a、ユーザ端末10b、ユーザ端末10cは、利用中のセキュリティセットを、ユーザ情報とともにセキュリティ設定提案サーバ200へ送信する(ステップS01)。ここでセキュリティセットとは、セキュリティ設定として利用されるパラメータの一連の組み合わせであって、例えば、ユーザ端末10の使用場所制限、インターネット制限、電話制限、利用時間制限といった設定のパラメータの組み合わせである。これらのパラメータは、オン、オフの二値を取るフラグであってもよいし、具体的な値であってもよい。具体的な値とは、例えば、使用を許可する位置情報の範囲や、閲覧を許可しないウェブサイトのドメインや、検索結果を表示させない検索単語や、利用時間制限に係る連続利用時間の数値が挙げられる。
 次に、セキュリティ設定提案サーバ200は、受信したセキュリティセットとユーザ情報とを関連付けて、記憶部に備えるセキュリティセット統計データベース250に記憶させる(ステップS02)。セキュリティセット統計データベース250は、ユーザ情報ごとに利用中のセキュリティセットを統計データとして記憶させるデータベースである。セキュリティ設定提案システム1は、ユーザ端末10からセキュリティセットとユーザ情報とを受信することにより、セキュリティセットとユーザ情報とを取得する。
 次に、今回セキュリティセットの提案を受けるユーザ端末10は、ユーザ情報とともにセキュリティ設定提案サーバ200に提案要求を送信する(ステップS05)。ここで、ユーザ情報は少なくともユーザの属性を含み、ユーザに適したセキュリティセットを提供する際に有意な統計を取れる変数として扱われる値であればよい。すなわち、個人名や電話番号といったユーザを特定可能な識別子ではなく、職務に関する情報(役職、肩書、利用時間帯、勤続年数)といったデモグラフィー情報を指す。
 そのほか、ユーザ端末10は、セキュリティセットにおいインターネット制限を有効化するかといったアンケート項目や、利用者のインターネットに関する理解度を計る設問といった所定の質問を行い、その結果を前記ユーザ情報に含めることで、ユーザの要望や理解度に応じたより適切なセキュリティセットの統計を取ることが可能となる。
 セキュリティ設定提案サーバ200は、提案要求を受信すると、同時に受信したユーザ情報を用いて、統計情報を抽出する(ステップS04)。セキュリティ設定提案システム1は、ユーザ端末10から提案要求を受信することにより、提案要求を取得する。そしてその結果から提案セキュリティセットを生成し、提案要求を送信したユーザ端末10に送信する(ステップS05)。セキュリティ設定提案システム1は、セキュリティ設定提案サーバ200から提案セキュリティセットをユーザ端末10に送信することにより、提案セキュリティセットを提供する。
 提案セキュリティセットとして最も単純なのは、図1に示すように複数のセキュリティセットの利用割合の統計情報を、円グラフとしてそのまま送信することである。ユーザは、グラフとセキュリティセットの詳細を見ながら、適切なセキュリティセットを選ぶことが可能となる。そのほか、初めに最も多いセキュリティセット一件のみを送り、ユーザ端末10に設定させた後で、ユーザが個別にカスタマイズを行ったり、前記質問項目に対して回答した要望を反映させたりしてもよい。以上が、セキュリティ設定提案システム1の概要である。
 [セキュリティ設定提案システムのシステム構成]
 図2は、セキュリティ設定提案システム1の全体構成図である。セキュリティ設定提案システム1において、複数のユーザ端末10、セキュリティ設定提案サーバ200によって構成される。ユーザ端末10とセキュリティ設定提案サーバ200は、それぞれ公衆回線網3を介して通信可能に接続されている。ユーザ端末10同士は、相互に通信可能である必要はない。
 ユーザ端末10は、ユーザが利用する一般的な情報端末であってよく、後述する機能を備える情報機器や電化製品である。ユーザ端末10は、例えば、携帯電話、スマートフォン、複合型プリンタ、テレビ、ルータ又はゲートウェイ等のネットワーク機器、コンピュータに加えて、冷蔵庫、洗濯機等の白物家電であってもよいし、電話機、ネットブック端末、スレート端末、電子書籍端末、電子辞書端末、携帯型音楽プレーヤ、携帯型コンテンツ再生・録画プレーヤ等の一般的な情報家電であってよい。
 セキュリティ設定提案サーバ200は、セキュリティセットの提案を行うサーバであって、記憶部にセキュリティセット統計データベース250を備え、後述する機能を備える情報機器や電化製品である。
 [各機能の説明]
 図3は、ユーザ端末10、セキュリティ設定提案サーバ200の機能ブロックと各機能の関係を示す図である。
 ユーザ端末10は、制御部11として、CPU(Central Processing Unit),RAM(Random Access Memory),ROM(Read Only Memory)等を備え、通信部12として、例えば、IEEE802.11に準拠したWiFi(Wireless Fidelity対応デバイス又は、第3世代移動通信システム等のIMT-2000規格に準拠した無線デバイス等を備える(有線によるLAN接続であってもよい)。
 さらに、ユーザ端末10は、入出力部13として、制御部で制御したデータや画像、音声を出力表示する出力部を備え、かつ、ユーザからの入力を受付けるタッチパネルやキーボード、マウス等の入力部を備える。
 ユーザ端末10において、制御部11が所定のプログラムを読み込むことで、通信部12と協働して、ユーザ情報送信モジュール14、提案要求送信モジュール15、提案セキュリティセット受信モジュール16、提案セキュリティセット設定モジュール17を実現する。また、ユーザ端末10において、制御部11が所定のプログラムを読み込むことで、入出力部13と協働して、質問実施モジュール18を実現する。
 セキュリティ設定提案サーバ200は、同様に、制御部201として、CPU,RAM,ROM等を備え、通信部202として、例えば、IEEE802.11に準拠したWiFi対応デバイスを備える(有線であってもよい)。加えて、セキュリティ設定提案サーバ200は、記憶部203として、ハードディスクや半導体メモリによる、データのストレージ部を備える。記憶部203は、セキュリティセット統計データベース250を、記憶部に備える。
 セキュリティ設定提案サーバ200の制御部201が所定のプログラムを読み込むことで、通信部202と協働して、セキュリティセット受信モジュール204、ユーザ情報受信モジュール205、提案要求受信モジュール206、提案セキュリティセット送信モジュール207を実現する。また、セキュリティ設定提案サーバ200の制御部201が所定のプログラムを読み込むことで、記憶部203と協働して、セキュリティセット記憶モジュール208、セキュリティセット抽出モジュール209を実現する。
 [セキュリティ設定提案処理]
 図4は、ユーザ端末10、セキュリティ設定提案サーバ200が実行するセキュリティ設定提案処理のフローチャートである。上述した各装置のモジュールが行う処理について、本処理にて併せて説明する。
 初めに、セキュリティ設定の提案を受けるに先駆けて、ユーザ端末10の質問実施モジュール18は、所定の質問項目に基づいて、ユーザに質問を実施する(ステップS11)。この質問は、適切なセキュリティ設定の提案を受けるためのもので、ユーザのデモグラフィー情報を取得したり、セキュリティ設定に関する要望を諮ったり、インターネットや端末に関するユーザの習熟度を計ったりするために行う。具体的な質問として、インターネット制限の有無の希望や、インターネットの利用歴を問う事が考えられる。
 次に、ユーザ端末10のユーザ情報送信モジュール14は、質問に対する回答と、ユーザ自身の情報をあわせてユーザ情報として、セキュリティ設定提案サーバ200へ送信し(ステップS12)、セキュリティ設定提案サーバ200のユーザ情報受信モジュール205がこれを受信する(ステップS13)。ここで、質問項目以外のユーザ情報としては、主としてデモグラフィー情報、すなわち人口統計学的情報である。具体的には、ユーザの属性を示す情報として、このユーザの職務(役職、肩書、利用時間帯、勤続年数等)に関する情報等が挙げられ、ユーザ端末10の登録情報から読み込んでもよいし、前記の様な質問によって情報を取得しても良い。
 次に、ユーザ端末10の提案要求送信モジュール15は、セキュリティ設定の提案要求を送信し(ステップS14)、セキュリティ設定提案サーバ200の提案要求受信モジュール206はこれを受信する(ステップS15)。
 そして、セキュリティ設定提案サーバ200のセキュリティセット抽出モジュール209は、提案要求とともに受信したユーザ情報を用いて、セキュリティセット統計データベース250からセキュリティセットを抽出する(ステップS16)。セキュリティセット統計データベース250には、セキュリティセットとユーザ情報とが関連付けて記憶されているため、ユーザ情報が同一又は類似なセキュリティセットを抽出し、それぞれ数を数える事で、セキュリティセットの統計データを作成可能である。
 図6は、セキュリティセット統計データベース250内のセキュリティセットテーブルの一例である。セキュリティセットテーブルでは、セキュリティ設定を構成するパラメータの組み合わせが一つのセキュリティセットとして、セキュリティセット名とともに記憶されている。例えば図6によれば、「セキュリティセットA」は、利用時間制限、インターネット制限、メール制限、及びGPS追跡が有効になっており、電話制限は無効になっている。これらのセキュリティセットテーブルは、セキュリティ設定を行う種々のセキュリティソフトごとに必ずしも別れている必要はなく、上位概念化できる要素として記憶され、共有されていてよい。
 また、図7は、セキュリティセット統計データベース250内のセキュリティセット統計テーブルの一例である。セキュリティセット統計テーブルでは、セキュリティセットと利用中のユーザ情報とが関連付けられて記憶されている。この図に示される範囲において、ユーザの属性が「1」~「3」であるユーザのセキュリティセットを抽出した場合、「セキュリティセットA」が抽出される。また、ユーザの属性が「4」~「5」であるユーザのセキュリティセットを抽出した場合、「セキュリティ設定B」が抽出される。また、ユーザの属性が「10」~「12」であるユーザのセキュリティセットを抽出した場合、「セキュリティ設定C」が抽出される。属性とは、上述した役職、肩書、利用時間帯、勤続年数等を便宜的に評価して数値化したものである。例えば、役職や肩書が高位なユーザに対しては、高い数値とする(例えば、新人の場合には「1」、中間管理職である場合には「5」、執行役員である場合には「10」)。また、肩書も役職と同様に評価し数値化する。また、ユーザ端末10を使用する時間帯が深夜や早朝等の通常よりも長時間の使用が想定されるユーザに対しては、高く数値化する。また、ユーザの勤続年数の長短に基づいて数値化する。実際にユーザ情報として記憶される「属性」は、これらの各数値の平均、最大値又は最小値の何れかの数値が用いられる。セキュリティ設定は、属性の数値が高くなるほど、その制限を緩和したものになる。なお、各ユーザの職務内容に基づいて、各数値の重み付けを行い、最も重み付けが大きく設定された内容の数値を「属性」の数値として用いてもよい。また、その他の条件に基づいて、数値を評価し、評価結果を「属性」の数値として用いてもよい。また、属性の数値の大小ではなく、数値毎にセキュリティ設定における制限の詳細を決定していてもよい。
 また、抽出の条件はユーザ情報に含まれる質問項目の内容でも指定可能であるし、値に幅を持たせ、類似の情報を増やしてもよい。例えば、受信したユーザの属性からプラスマイナス三の範囲を類似として抽出したり、ある属性においては大きな影響を与えない質問項目Aを無視して抽出したり、ある属性のユーザの属性は類似を抽出せずに、所定の範囲内の属性のユーザの属性は類似を抽出したりといったことも可能である。
 その後、提案セキュリティセット送信モジュール207が、抽出したセキュリティセットをユーザ端末10に提案セキュリティセットとして送信する(ステップS17)。提案セキュリティセットは、抽出したセキュリティセット全てであってもよいし、抽出したセキュリティセットから、加工や選別がなされていてもよい。例えば、インターネット制限を希望するのに無効になっているといった、質問項目の回答結果に明らかに矛盾するセキュリティセットを除外することが可能である。また、提案セキュリティセットは複数のセキュリティセットを含み、ユーザにその中から選択をさせる形式であってよい。
 ユーザ端末10の提案セキュリティセット受信モジュール16が提案セキュリティセットを受信すると(ステップS18)、提案セキュリティセット設定モジュール17が、その提案セキュリティセットをユーザ端末10のセキュリティ設定として設定する(ステップS19)。
 図5は、提案セキュリティセットを受信したユーザ端末10の画面の一例である。デモグラフィー情報51のように、統計情報の抽出条件が示され、その下に統計情報52が示される。設定ボタン53を押す事で、対応するセキュリティセットをユーザ端末10に設定することが可能である。また、円グラフの各項目をタッチすることで、各項目の詳細が示されてよいし、そこからセキュリティセットに任意の変更を加えたうえで設定可能であってよい。
 次に、ユーザ端末10は設定したセキュリティセットの内容をセキュリティ設定提案サーバに送信する(ステップS20)。セキュリティ設定提案サーバ200のセキュリティセット受信モジュール204は、これを受信する(ステップS21)。
 最後に、セキュリティ設定提案サーバ200のセキュリティセット記憶モジュール208は、受信したセキュリティセットを、ステップS13で受信したユーザ情報と関連付けて、セキュリティセット統計データベース250に記憶する(ステップS21)。こうすることで、次回の提案要求の際に利用可能な統計情報が増加する。
 上述した手段、機能は、コンピュータ(CPU,情報処理装置,各種端末を含む)が、所定のプログラムを読み込んで、実行することによって実現される。プログラムは、例えば、コンピュータからネットワーク経由で提供される(SaaS:ソフトウェア・アズ・ア・サービス)形態で提供される。プログラムは、例えば、フレキシブルディスク、CD(CD-ROMなど)、DVD(DVD-ROM、DVD-RAMなど)等のコンピュータ読取可能な記録媒体に記録された形態で提供される。この場合、コンピュータはその記録媒体からプログラムを読み取って内部記憶装置または外部記憶装置に転送し記憶して実行する。また、そのプログラムを、例えば、磁気ディスク、光ディスク、光磁気ディスク等の記憶装置(記録媒体)に予め記録しておき、その記憶装置から通信回線を介してコンピュータに提供するようにしてもよい。
 以上、本発明の実施形態について説明したが、本発明は上述したこれらの実施形態に限るものではない。また、本発明の実施形態に記載された効果は、本発明から生じる最も好適な効果を列挙したに過ぎず、本発明による効果は、本発明の実施形態に記載されたものに限定されるものではない。
 1 セキュリティ設定提案システム、3 公衆回線網、10 ユーザ端末、200 セキュリティ設定提案サーバ、250 セキュリティセット統計データベース

Claims (6)

  1.  一以上のユーザ端末と通信可能に接続され、セキュリティ統計データベースを備えたコンピュータシステムであって、
     前記ユーザ端末から、少なくとも属性を含むユーザ情報とともに、セキュリティセットの提案要求を取得する提案要求取得手段と、
     前記提案要求とともに取得したユーザ情報を用いて、前記セキュリティセット統計データベースから、当該ユーザ情報と同一、又は所定の範囲で当該ユーザ情報と類似するユーザ情報に関連付けられているセキュリティセットを抽出するセキュリティセット抽出手段と、
     前記抽出した一以上のセキュリティセットを提案セキュリティセットとして、前記ユーザ端末に提供する提案セキュリティセット提供手段と、
     を備えることを特徴とするコンピュータシステム。
  2.  前記ユーザ端末から、利用中の一連のセキュリティ設定に関するパラメータの組み合わせであるセキュリティセットを取得するセキュリティセット取得手段と、
     前記ユーザ端末から、前記取得したセキュリティセットを利用中であるユーザの、少なくとも属性を含むユーザ情報を取得するユーザ情報取得手段と、
     前記取得したセキュリティセットと、前記取得したユーザ情報とを、関連付けて前記セキュリティセット統計データベースに記憶させるセキュリティセット記憶手段と、
     を備えることを特徴とする請求項1に記載のコンピュータシステム。
  3.  前記ユーザ端末から取得する前記ユーザ情報に、当該ユーザ端末のユーザに対して実施された、所定の質問項目に対する回答を含めることを特徴とした、請求項1に記載のコンピュータシステム。
  4.  前記属性とは、前記ユーザ端末のユーザの職務に関する情報である、
     ことを特徴とする請求項1に記載のコンピュータシステム。
  5.  一以上のユーザ端末と通信可能に接続され、セキュリティ統計データベースを備えたコンピュータシステムが実行するセキュリティ設定提案方法であって、
     前記ユーザ端末から、少なくとも属性を含むユーザ情報とともに、セキュリティセットの提案要求を取得するステップと、
     前記提案要求とともに取得したユーザ情報を用いて、前記セキュリティセット統計データベースから、当該ユーザ情報と同一、又は所定の範囲で当該ユーザ情報と類似するユーザ情報に関連付けられているセキュリティセットを抽出するステップと、
     前記抽出した一以上のセキュリティセットを提案セキュリティセットとして、前記ユーザ端末に提供するステップと、
     を備えることを特徴とするセキュリティ設定提案方法。
  6.  一以上のユーザ端末と通信可能に接続され、セキュリティ統計データベースを備えたコンピュータシステムに、
     前記ユーザ端末から、少なくとも属性を含むユーザ情報とともに、セキュリティセットの提案要求を取得するステップ、
     前記提案要求とともに取得したユーザ情報を用いて、前記セキュリティセット統計データベースから、当該ユーザ情報と同一、又は所定の範囲で当該ユーザ情報と類似するユーザ情報に関連付けられているセキュリティセットを抽出するステップ、
     前記抽出した一以上のセキュリティセットを提案セキュリティセットとして、前記ユーザ端末に提供するステップ、
     を実行させるためのコンピュータ読み取り可能なプログラム。
PCT/JP2017/035309 2017-09-28 2017-09-28 コンピュータシステム、セキュリティ設定提案方法及びプログラム Ceased WO2019064458A1 (ja)

Priority Applications (4)

Application Number Priority Date Filing Date Title
PCT/JP2017/035309 WO2019064458A1 (ja) 2017-09-28 2017-09-28 コンピュータシステム、セキュリティ設定提案方法及びプログラム
US16/651,596 US11916961B2 (en) 2017-09-28 2017-09-28 Computer system, security setting suggestion method, and program
CN201780095464.7A CN111164598B (zh) 2017-09-28 2017-09-28 计算机系统、安全性设定提案方法以及程序
JP2019545515A JP6775749B2 (ja) 2017-09-28 2017-09-28 コンピュータシステム、セキュリティ設定提案方法及びプログラム

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/JP2017/035309 WO2019064458A1 (ja) 2017-09-28 2017-09-28 コンピュータシステム、セキュリティ設定提案方法及びプログラム

Publications (1)

Publication Number Publication Date
WO2019064458A1 true WO2019064458A1 (ja) 2019-04-04

Family

ID=65901143

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/JP2017/035309 Ceased WO2019064458A1 (ja) 2017-09-28 2017-09-28 コンピュータシステム、セキュリティ設定提案方法及びプログラム

Country Status (4)

Country Link
US (1) US11916961B2 (ja)
JP (1) JP6775749B2 (ja)
CN (1) CN111164598B (ja)
WO (1) WO2019064458A1 (ja)

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014238675A (ja) * 2013-06-06 2014-12-18 株式会社オプティム セキュリティ設定提案サーバ、ユーザ端末、セキュリティ設定提案方法、セキュリティ設定提案サーバ用プログラム
US20160344544A1 (en) * 2014-07-17 2016-11-24 Garrett Val Biesinger Assisted Improvement of Security Reliance Scores

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002109178A (ja) * 2000-09-28 2002-04-12 Casio Comput Co Ltd 情報収集方法、情報収集システム及び情報収集に用いられる情報記憶媒体
JP3844193B2 (ja) 2001-01-24 2006-11-08 Kddi株式会社 情報自動フィルタリング方法、情報自動フィルタリングシステム及び情報自動フィルタリングプログラム
JP2003316650A (ja) * 2002-04-18 2003-11-07 Internatl Business Mach Corp <Ibm> コンピュータ装置、携帯情報機器、セキュリティ切り替え方法、およびプログラム
US20120226623A1 (en) * 2010-10-01 2012-09-06 Linkedln Corporation Methods and systems for exploring career options
CN102446311B (zh) * 2010-10-15 2016-12-21 商业对象软件有限公司 过程驱动的业务智能
JP5796230B2 (ja) * 2013-07-25 2015-10-21 株式会社マーキュリー Sns型取引システム
CN109889474A (zh) 2014-09-22 2019-06-14 阿里巴巴集团控股有限公司 一种用户身份验证的方法及装置
JP6340358B2 (ja) * 2015-12-25 2018-06-06 株式会社日立ソリューションズ 情報漏洩防止システム及び方法
US10805308B2 (en) * 2017-12-22 2020-10-13 International Business Machines Corporation Jointly discovering user roles and data clusters using both access and side information

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014238675A (ja) * 2013-06-06 2014-12-18 株式会社オプティム セキュリティ設定提案サーバ、ユーザ端末、セキュリティ設定提案方法、セキュリティ設定提案サーバ用プログラム
US20160344544A1 (en) * 2014-07-17 2016-11-24 Garrett Val Biesinger Assisted Improvement of Security Reliance Scores

Also Published As

Publication number Publication date
CN111164598A (zh) 2020-05-15
US20220353294A1 (en) 2022-11-03
JP6775749B2 (ja) 2020-10-28
US11916961B2 (en) 2024-02-27
CN111164598B (zh) 2024-02-09
JPWO2019064458A1 (ja) 2020-07-02

Similar Documents

Publication Publication Date Title
US11955125B2 (en) Smart speaker and operation method thereof
US20180253219A1 (en) Personalized presentation of content on a computing device
JP2013235507A (ja) 情報処理方法、装置、コンピュータプログラムならびに記録媒体
JP6652231B1 (ja) 会話制御プログラム、会話制御方法および情報処理装置
KR20190086126A (ko) 챗봇을 이용한 매뉴얼 검색 서비스 제공 서버 및 그의 매뉴얼 검색 서비스 제공 방법
WO2017160973A1 (en) Systems and methods for virtual interaction
WO2020095776A1 (ja) 知識情報作成支援装置
JP2019057093A (ja) 情報処理装置及びプログラム
CN112598435A (zh) 餐厅的推荐方法和装置、存储介质、电子装置
JP5921490B2 (ja) セキュリティ設定提案サーバ、ユーザ端末、セキュリティ設定提案方法、セキュリティ設定提案サーバ用プログラム
CN115687807A (zh) 信息显示方法、装置、终端及存储介质
US20210271698A1 (en) Computer-readable recording medium recording answering program, answering method, and answering device
JP7623763B1 (ja) 情報処理システムおよび情報処理方法
JP6775749B2 (ja) コンピュータシステム、セキュリティ設定提案方法及びプログラム
JP5957024B2 (ja) 検索装置、検索方法およびプログラム
US20190012335A1 (en) Data sharing system, data sharing method, and program
Holzinger et al. On the development of smart adaptive user interfaces for mobile e-Business applications: Towards enhancing User Experience–some lessons learned
JP6169748B2 (ja) セキュリティセット提案システム、セキュリティセット提案方法、プログラム
KR20200059558A (ko) 사용자 프로파일을 생성하는 장치 및 그 장치를 포함하는 시스템
JP2018067095A (ja) 名刺情報管理システム、名刺情報管理システムにおける検索結果表示方法、および検索結果表示プログラム
JP2019057092A (ja) 情報処理装置及びプログラム
JP7342534B2 (ja) チャットプログラム、装置、及び方法
JP5520259B2 (ja) 質問例提示装置、方法及びプログラム
JP2018067041A (ja) 抽出装置及びコンピュータプログラム
KR20060016633A (ko) 이동통신단말기를 이용한 정보검색 시스템

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17927363

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2019545515

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1) EPC (EPO FORM 1205A DATED 23/07/2020)

122 Ep: pct application non-entry in european phase

Ref document number: 17927363

Country of ref document: EP

Kind code of ref document: A1