User authentication system

TWI931593BActive Publication Date: 2026-07-11FANUC LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TW111137525
Authority / Receiving Office
TW · TW
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-10-03
Publication Date
2026-07-11
Estimated Expiration
2042-10-02

Smart Images

  • Figure IMG-2_DRAW_111137525-A0304-14-0001-1
    Figure IMG-2_DRAW_111137525-A0304-14-0001-1
  • Figure IMG-2_DRAW_111137525-A0304-14-0002-2
    Figure IMG-2_DRAW_111137525-A0304-14-0002-2
  • Figure IMG-2_DRAW_111137525-A0304-14-0003-3
    Figure IMG-2_DRAW_111137525-A0304-14-0003-3
Patent Text Reader

Abstract

Users who wish to utilize services individually provided by multiple service systems can improve convenience by using a single user account to access the services of each service system. A user account information management device centrally manages user account information of users utilizing multiple service systems. The device includes: a user account information management unit that manages user account information; and an authentication processing unit that obtains user account information entered by the user through at least one of the multiple service systems. The authentication processing unit compares the user account information entered by the user with the user account information managed by the user account information management unit to determine the validity of the user's authentication and sends the determination result back to at least one of the multiple service systems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Invention Field This invention relates to a user account information management device and a user authentication system that centrally manages user account information. Prior Technology

[0002] Background of the Invention When a company allows its customers to use ICT (Information and Communication Technology) services, the company only manages information about its own customers (hereinafter referred to as customer information). Furthermore, customers include not only direct users of the service, but also, for example, the company, organization, or deployment to which the user belongs.

[0003] Patent Document 1 describes a login device for logging ID mapping information using an ID mapping table. The aforementioned ID mapping table records the ID mapping information between a common authentication ID and a login ID used for information services in an environment where multiple information services can be accessed with an individual ID through a single authentication. Specifically, Patent Document 1 describes an ID mapping information login device that can utilize multiple information services through a single authentication. The information service unit has an ID mapping instruction mechanism that outputs an ID mapping information login instruction for its own information service login ID and common ID. The authentication infrastructure includes: an ID mapping table that records the mapping information between the common ID and the login ID; and a secure ID mapping editing mechanism that logs the ID mapping information into the ID mapping table when the authentication of the common ID and the login ID, and when the authentication of other information service login IDs already logged in the ID mapping table is successful. Prior technology documents Patent documents

[0004] Patent Document 1: Japanese Patent Application Publication No. 2012-234435 Summary of the Invention

[0005] Invention Summary The problem the invention aims to solve When multiple companies in a specific industry provide ICT services to customers in the industry, customers must maintain user account information for each ICT service used or for each company. This can be a burden on customers as a whole and is inconvenient. Therefore, the goal is to centrally manage information about customers in specific industries, allowing customers to use a single user account to access ICT services from multiple companies within the industry, thereby enhancing convenience. The means to solve the problem

[0006] (1) The first aspect disclosed herein is a user account information management device that centrally manages user account information of users from a plurality of service systems. The aforementioned user account information management device includes: The User Account Information Management Department manages the aforementioned user account information; and The authentication processing unit obtains the user account information entered by the aforementioned user through at least one of the aforementioned service systems. The aforementioned authentication processing unit verifies the aforementioned user account information entered by the aforementioned user with the aforementioned user account information managed by the aforementioned user account information management unit to determine whether the aforementioned user's authentication is valid, and sends the determination result back to at least one of the aforementioned plurality of service systems.

[0007] (2) The second aspect disclosed herein is a user authentication system, which includes: a plurality of service systems; and a user account information management device, which centrally manages the user account information of users utilizing the plurality of service systems. The aforementioned user account information management device has: The User Account Information Management Department manages the aforementioned user account information; and The authentication processing unit obtains the user account information entered by the aforementioned user through at least one of the aforementioned service systems. The aforementioned authentication processing unit verifies the aforementioned user account information entered by the aforementioned user with the aforementioned user account information managed by the aforementioned user account information management unit to determine whether the aforementioned user's authentication is valid, and sends the determination result and at least one of the user information or related information linked to the aforementioned user account information back to at least one of the aforementioned plurality of service systems. Invention Effects

[0008] According to the various embodiments disclosed herein, users who wish to utilize services provided individually by multiple service systems can use the services of each of the multiple service systems with a single user account, thereby improving convenience. Furthermore, according to the various embodiments disclosed herein, the multiple service systems do not require each service system to have a device for managing customer information, which can reduce system development / operation and maintenance costs. Simple Explanation of the Diagram

[0009] Figure 1 is a block diagram showing a user authentication system according to a first embodiment of this disclosure. Figure 2 is a flowchart illustrating the operation of the user authentication system in the first implementation. Figure 3 is a block diagram showing the user authentication system of the second embodiment of this disclosure. Figure 4 is a block diagram showing the user authentication system of the third embodiment of this disclosure. Figure 5 is a block diagram showing the user authentication system of the fourth embodiment of this disclosure. Figure 6 is a block diagram showing the user authentication system of the fifth embodiment of this disclosure. Figure 7 is a block diagram showing the user authentication system of the sixth embodiment of this disclosure. Figure 8 is a block diagram showing the user authentication system of the seventh embodiment of this disclosure. Figure 9 is a block diagram showing the user authentication system of the eighth embodiment of this disclosure. Figure 10 is a block diagram showing the user authentication system of the ninth embodiment of this disclosure. Figure 11 is a block diagram showing the service management system of a machine tool including the user authentication system of the first embodiment. Implementation

[0010] Forms used to implement inventions The following diagrams are used to illustrate in detail the embodiments disclosed herein.

[0011] (First Implementation) Figure 1 is a block diagram showing a user authentication system according to a first embodiment of this disclosure. The user authentication system 10 includes a communication terminal 100, a service system 200, a service system 300, and a user account information management device 400. The communication terminal 100, service system 200, service system 300, and user account information management device 400 are connected via communication lines. These communication lines can be, for example, a LAN (Local Area Network), the Internet, a public telephone network, or a combination thereof. There are no particular limitations regarding the specific communication method of the communication line, or whether a wired or wireless connection is used.

[0012] Service System 200 and Service System 300 are managed by the company, organization, or deployments within the company or organization. The number of service systems providing ICT services is not specifically limited to two, and may include three or more. For example, service system 200 is managed by BBB Corporation and provides ICT services to users of operating communication terminal 100. Service system 300 is managed by CCC Corporation and provides ICT services to users of operating communication terminal 100. Furthermore, in the first embodiment, for example, service system 200 (BBB's ICT service system) and service system 300 (CCC's ICT service system) are ICT service systems as described below. The aforementioned ICT service systems can be used as long as the user's user account information is logged into the user account information management device 400 and can be authenticated by the authentication processing unit 401 of the user account information management device 400. The user account information management device 400 centrally manages user account information, which is used in the authentication of users using service system 200 and service system 300.

[0013] The communication terminal 100 is composed of a fixed personal computer, a laptop personal computer, a tablet personal computer, or a smartphone. Users access the service system 200 or service system 300 through the communication terminal 100, logging in by entering user account information such as user ID and password. Once user authentication is performed based on the user account information, the user can utilize service system 200 or service system 300.

[0014] The user account information is common user account information used in both service system 200 and service system 300 (hereinafter referred to as common user account information). Although the common user account information used is such as user ID and password, in addition to user ID and password, a fixed PIN code or one-time password can also be entered.

[0015] Service system 200 is constructed using a computer. Service system 200 includes a user authentication unit 201. User authentication unit 201 receives a user authentication query from communication terminal 100, containing common user account information, and sends it to user account information management device 400. Furthermore, user authentication unit 201 receives the user's authentication determination result from user account information management device 400. When the determination result is authenticable, it prepares the service provision functions provided by service system 200, screen information to be displayed on communication terminal 100, etc., and sends the service provision functions and screen information to be displayed on communication terminal 100. When the determination result is unauthenticable, it sends an unauthentication message to communication terminal 100.

[0016] The service system 300 is constructed using a computer. The service system 300 includes a user authentication unit 301. The user authentication unit 301 receives a user authentication query from the communication terminal 100, containing common user account information, and sends it to the user account information management device 400. Furthermore, the user authentication unit 301 receives the user's authentication determination result from the user account information management device 400. When the determination result indicates successful authentication, it prepares the service provision functions provided by the service system 300, screen information to be displayed on the communication terminal 100, etc., and sends these information to the communication terminal 100. When the determination result is that authentication is not possible, an authentication not possible message will be sent to communication terminal 100.

[0017] The user account information management device 400 is a computer comprising an authentication processing unit 401 and a user account information management unit 402. The authentication processing unit 401 receives common user account information from service system 200 or service system 300 and compares it with the common user account information stored in the user account information management unit 402. Based on whether the two match, it determines whether user authentication can proceed and sends the determination result to service system 200 or service system 300. The user account information management unit 402 pre-stores the common user account information using a login method described later.

[0018] The operation of the communication terminal 100, service system 200, service system 300 and user account information management device 400 is illustrated below using Figure 2. Figure 2 is a flowchart illustrating the actions of the user authentication system. The following description uses an example of a user utilizing service system 200 to illustrate the situation. In step S11, the communication terminal 100 accesses the service system 200 through the user's operation, and enters common user account information such as user ID and password to perform login processing.

[0019] In step S21, the user authentication unit 201 of the service system 200 receives common user account information from the communication terminal 100 and sends a user authentication query to the authentication processing unit 401 of the user account information management device 400 to inquire whether the received common user account information is correct.

[0020] In step S31, the authentication processing unit 401 of the user account information management device 400 receives common user account information, such as the user ID and password, entered by the user from the service system 200. The authentication processing unit 401 performs the following check: whether the received common user account information matches the user's common user account information stored in the user account information management unit 402. Then, the authentication processing unit 401 determines whether user authentication can be performed based on the check result. In step S32, the authentication processing unit 401 sends the determination result back to the service system 200.

[0021] In step S22, the user authentication unit 201 of the service system 200 receives the user's determination result from the user account information management device 400. In step S23, determine whether the determination result is authenticable. If it is authenticable, move to step S24; if it is not authenticable, move to step S25. In step S24, when the determination result is authenticable, the user authentication unit 201 causes the service system 200 to prepare the service provision function, the screen information to be displayed on the communication terminal 100, etc., and the service system 200 sends the service provision function, the screen information to be displayed on the communication terminal 100, etc. to the communication terminal 100. In step S25, when the determination result is that authentication is not possible, the user authentication unit 201 sends an authentication failure message to the communication terminal 100.

[0022] When the authentication result is deemed authenticable, the communication terminal 100 receives the service provision functions provided by the service system 200, as well as screen information to be displayed on the communication terminal 100. Conversely, when the authentication result is deemed unauthenticable, the communication terminal 100 receives an unauthentication message. In step S12, the communication terminal 100 determines whether user authentication is possible based on the received information. If user authentication is possible, the process proceeds to step S13.

[0023] In step S13, when the determination result is authenticable, the communication terminal starts to use the service system 200 through the user's operation. When the determination result is that authentication is not possible, the communication terminal 100 can also return to step S11 to log in again.

[0024] Although the above description describes the actions performed by the user using service system 200, the user can also perform the same actions using service system 300.

[0025] Login to the User Account Information Management Department 402 using common user account information is performed as follows. When a user accesses service system 200 to log in to common user account information, service system 200 obtains login screen information for common user account information from authentication processing unit 401 of user account information management device 400 and sends it to communication terminal 100. The user enters common user account information on the login screen displayed on communication terminal 100 and sends it to service system 200.

[0026] When the service system 200 receives common user account information, it sends the common user account information to the user account information management device 400. The user account information management unit 402 of the user account information management device 400 logs (saves) the received common user account information as the user's common user account information.

[0027] (Second Implementation) Figure 3 is a block diagram showing the user authentication system of the second embodiment of this disclosure. The difference between the user authentication system 10A shown in Figure 3 and the user authentication system 10 in the first embodiment is that the user account information management device 400 shown in Figure 1 is replaced by the user account information management device 400A, and it has a customer information management unit 403.

[0028] Specifically, the user account information management device 400A has the same authentication processing unit 401 and user account information management unit 402 as the user account information management device 400, and further has a customer information management unit 403.

[0029] Customer Information Management Department 403 has subordinate Information Management Department 4031 and User Information Management Department 4032. The Information Management Department 4031 stores user information linked to user account information, including the user's company name, company address, organization name, and contact information (phone number, fax, etc.). The User Information Management Department 4032 stores user information such as name, gender, address, and contact information (phone number, email address, etc.) of users who are linked to user account information.

[0030] When a user has been authenticated (the authentication result indicates that authentication is possible), the authentication processing unit 401 reads at least one of the ownership information stored in the ownership information management unit 4031 and the user information stored in the user information management unit 4032, appends the read ownership information and / or user information to the authentication result, and replies to the service system 200 or service system 300 that requested the user's authentication. The service system 200 or service system 300, having obtained the ownership information or user information, can grasp the user's usage preferences by obtaining, for example, at least one of the ownership information and user information of the user using the service.

[0031] Furthermore, the login of affiliated information to the affiliated information management department 4031 and the login of user information to the user information management department 4032 can be performed in the same way as the login of common user account information to the user account information management department 402. Detailed explanation is omitted.

[0032] (Third Implementation) Figure 4 is a block diagram showing the user authentication system of the third embodiment of this disclosure. The difference between the user authentication system 10B shown in Figure 4 and the user authentication system 10 in the first embodiment is that the user account information management device 400 shown in Figure 1 is replaced by the user account information management device 400B, the service system 200 is replaced by the service system 200B, and the service system 300 is replaced by the service system 300B.

[0033] Specifically, the user account information management device 400B has the same authentication processing unit 401 and user account information management unit 402 as the user account information management device 400, and further has an authorization processing unit 404 and an ICT service system utilization information management unit 405.

[0034] Furthermore, in service system 200B, the user authentication unit 201 of service system 200 shown in Figure 1 is replaced by a user authentication / authorization unit 201B. In addition to the functions of the user authentication unit 201 shown in Figure 1, the user authentication / authorization unit 201B also has the functions of an authorization unit.

[0035] Regarding service system 300B, similarly to service system 200B, the user authentication unit 301 of service system 300 shown in Figure 1 is replaced by user authentication / authorization unit 301B. In addition to the functions of user authentication unit 301, user authentication / authorization unit 301B also functions as an authorization unit.

[0036] The ICT service system uses the Information Management Department 405 to link and store the users who can use the service system 200B or the service system 300B, and the access rights required by the users when using the service system 200B or the service system 300B, with common user account information. The aforementioned access rights are, for example, administrator rights, user rights, operator rights, etc.

[0037] When the authentication processing unit 401 has authenticated a user, the authorization processing unit 404 uses the common user account information obtained from the authentication processing unit 401 to refer to the information stored in the ICT service system utilization information management unit 405 to confirm whether the user who has been authenticated can use the service system 200B or the service system 300B, and to confirm the utilization permissions required when using the service. The authentication processing unit 401 will reply to the service system 200B or the service system 300B with the determination of whether the service system 200B or the service system 300B can be used and the access rights, together with the determination result of the authentication processing unit 401.

[0038] The user authentication / authorization unit 201B of the service system 200B receives the authentication result and access rights of the user from the user account information management device 400. If the authentication result is valid and the user has access rights, the service system 200B prepares the service provision function and the screen information to be displayed on the communication terminal 100, and sends the service provision function and the screen information to be displayed on the communication terminal 100 to the communication terminal 100. Furthermore, when the determination result is unauthentication, the user authentication / authorization unit 201B sends an unauthentication message to the communication terminal 100. Also, when the user can be authenticated but does not have the right to use the service, the user authentication / authorization unit 201B sends a message to the communication terminal 100 indicating that the user does not have the right to use the service.

[0039] The user authentication / approval unit 301B of service system 300B also has the same functions as the user authentication / approval unit 201B of service system 200B.

[0040] A variation of the third embodiment will be explained (furthermore, the illustrations are omitted). (First variation) A first variation of the user account information management device 400B is as follows: The user account information management device 400B includes an authentication processing unit 401, a user account information management unit 402, an authorization processing unit 404, and an ICT service system utilization information management unit 405, and further includes a customer information management unit 403 as shown in FIG. 3, which includes a subordinate information management unit 4031 and a user information management unit 4032. In this variation, the authentication processing unit 401 can refer to the information stored in the ICT service system utilization information management unit 405 and the information stored in the customer information management unit 403, which are linked to the user account information.

[0041] (Second variation) A second variation of the user account information management device 400B is an example in which the ICT service system information management unit 405 is moved into the customer information management unit 403 of the first variation. In this variation, information stored separately in the affiliated information management unit 4031, the user information management unit 4032, and the ICT service system information management unit 405 can be collectively stored in the memory of the customer information management unit 403.

[0042] (Fourth Implementation) Figure 5 is a block diagram showing the user authentication system of the fourth embodiment of this disclosure. The difference between user authentication system 10C and user authentication system 10B in the third embodiment is that it has service system 200C and service system 300C. The aforementioned service system 200C separates the user authentication / authentication unit 201B of service system 200B shown in FIG4 into user authentication unit 201 and user authentication unit 202. The aforementioned service system 300C separates the user authentication / authentication unit 301B of service system 300B into user authentication unit 301 and user authentication unit 302.

[0043] The authentication processing unit 404 is connected to the user authentication units 202 of service system 200C and 302 of service system 300C via communication lines. In the user authentication system 10B of the third embodiment shown in FIG. 4, although the authentication processing unit 404 obtains common user account information from the authentication processing unit 401, in this embodiment, the authentication processing unit 404 obtains the common user account information from either the user authentication unit 202 of service system 200C or the user authentication unit 302 of service system 300C. Then, the authentication processing unit 404 can reply to the user authentication unit 202 of service system 200C or the user authentication unit 302 of service system 300C regarding the availability and access permissions of service system 200C or service system 300C. This allows for the separate processing of user authentication (determining whether the result of the service system 200C and 300C is authentic) and user approval (determining whether the user has the right to use the service).

[0044] A variation of the fourth embodiment will be explained (furthermore, the illustrations are omitted). (First variation) This section describes a variation of the user account information management device 400B shown in Figure 5. A first variation of the user account information management device 400B is as follows: The user account information management device 400B includes an authentication processing unit 401, a user account information management unit 402, an authorization processing unit 404, and an ICT service system utilization information management unit 405, and further includes a customer information management unit 403 as shown in FIG. 3, which includes a subordinate information management unit 4031 and a user information management unit 4032. In this variation, the authentication processing unit 401 can read information that is linked to user account information and stored in the ICT service system utilization information management unit 405, and information stored in the customer information management unit 403.

[0045] (Second variation) A second variation of the user account information management device 400B is an example in which the ICT service system information management unit 405 is moved into the customer information management unit 403 of the first variation. In this variation, information stored separately in the affiliated information management unit 4031, the user information management unit 4032, and the ICT service system information management unit 405 can be collectively stored in the memory of the customer information management unit 403.

[0046] (Fifth Implementation) Figure 6 is a block diagram showing the user authentication system of the fifth embodiment of this disclosure. The difference between user authentication system 10D and user authentication system 10C in the fourth embodiment is that the user account information management device 400B of user authentication system 10C shown in FIG5 is replaced by user account information management device 400C.

[0047] The user account information management device 400C is configured as shown in Figure 5, and further includes the customer information management unit 403 shown in Figure 3, which includes the subordinate information management unit 4031 and the user information management unit 4032. Furthermore, the user account information management device 400C is configured to separate the ICT service system shown in Figure 5 into two ICT service systems using information management units 405-1 and 405-2, respectively.

[0048] The ICT service system uses Information Management Department 405-1 to link and store the users who can use the service system 200C, and the access permissions required by those users when using the service system 200C, with common user account information. The aforementioned access permissions include, for example, administrator permissions, user permissions, operator permissions, etc.

[0049] The ICT service system uses Information Management Department 405-2 to link and store the users who can use the service system 300C, and the access permissions required by those users when using the service system 300C, with common user account information. The aforementioned access permissions include, for example, administrator permissions, user permissions, operator permissions, etc.

[0050] (Sixth Implementation) Figure 7 is a block diagram showing the user authentication system of the sixth embodiment of this disclosure. The difference between user authentication system 10E and user authentication system 10D in the fifth embodiment is that the user account information management device 400C of user authentication system 10D shown in FIG. 6 is replaced by the user account information management device 400A shown in FIG. 3. Furthermore, the difference between user authentication system 10E and user authentication system 10D in the fifth embodiment is that the service system 200C shown in FIG. 6 is replaced by the service system 200D, and the service system 300C is replaced by the service system 300D.

[0051] <Service System 200D> In addition to the user authentication unit 201 and the user authorization unit 202, the service system 200D also includes an ICT service system utilization information management unit 203. The user authorization unit 202 has the functions of the authorization processing unit 404 in the fifth embodiment shown in FIG6.

[0052] The ICT service system uses the Information Management Department 203 to link and store the users who can use the service system 200D, and the access permissions required by those users when using the service system 200D, with common user account information. The aforementioned access permissions include, for example, administrator permissions, user permissions, operator permissions, etc.

[0053] The user authentication unit 201 receives the authentication result of the user from the user account information management device 400A. When the result is that the user has been authenticated, it outputs a query to the user approval unit 202 to confirm whether the authenticated user can use the service system 200D and the required access permissions. Furthermore, when the result is that authentication is not possible, the user authentication unit 201 sends an authentication failure message to the communication terminal 100. The User Recognition Department 202 uses the common user account information obtained from the User Authentication Department 201 to refer to the information stored in the ICT Service System Utilization Information Management Department 203 to confirm whether a user who has been authenticated can use the service system 200D, and to confirm the usage permissions required when using the service. The User Approval Department 202 outputs the permission and authorization to the User Authentication Department 201 to determine whether the service system 200D can be used.

[0054] If the authentication result is that the user is authenticable and has the right to use the service, the user authentication unit 201 prepares the service provision function provided by the service system 200D, the screen information to be displayed on the communication terminal 100, etc., and sends the service provision function and the screen information to be displayed on the communication terminal 100 to the communication terminal 100. Furthermore, if the user is authenticable but does not have the right to use the service, the user authentication unit 201 sends a message to the communication terminal 100 indicating that the user does not have the right to use the service. <Service System 300D> In addition to the user authentication unit 301 and the user authorization unit 302, the service system 300D also has an ICT service system utilization information management unit 303. The user authorization unit 302 has the functions of the authorization processing unit 404 in the fifth embodiment shown in FIG6.

[0055] The ICT service system uses the information management department 303 to link and store the users who can use the service system 300D, and the access permissions required by the users when using the service system 300D, with common user account information. The aforementioned access permissions are, for example, administrator permissions, user permissions, operator permissions, etc.

[0056] The user authentication unit 301 receives the authentication result of the user from the user account information management device 400A. When the result is that the user is authenticated, it outputs the query to the user approval unit 302 to confirm whether the user who has been authenticated can use the service system 300D and the access permissions required to use the service. The User Recognition Unit 302 uses the common user account information obtained from the User Authentication Unit 301 to refer to the information stored in the ICT Service System Utilization Information Management Unit 303 to confirm whether a user who has been authenticated can use the service system 300D, and to confirm the utilization permissions required when using the service. The User Approval Department 302 outputs the permission and authorization to the User Authentication Department 301 to determine whether the service system 300D can be used.

[0057] If the authentication result is deemed authentic and the user has the right to use the service, the user authentication unit 301 prepares the service provision function provided by the service system 300D, the screen information to be displayed on the communication terminal 100, etc., and sends the service provision function and the screen information to be displayed on the communication terminal 100 to the communication terminal 100. Furthermore, if the user is authenticable but does not have the right to use the service, the user authentication unit 301 may also send a message to the communication terminal 100 indicating that the user does not have the right to use the service.

[0058] (Seventh Implementation) Figure 8 is a block diagram showing the user authentication system of the seventh embodiment of this disclosure. The difference between user authentication system 10F and user authentication system 10E in the sixth embodiment is that the user account information management device 400A shown in FIG7 is replaced by user account information management device 400D.

[0059] The user account information management device 400D has the same authentication processing unit 401 and user account information management unit 402 as the user account information management device 400A shown in Figure 7, and further has customer information management units 403-1 and 403-2.

[0060] The Customer Information Management Department 403-1 manages information about users using the Service System 200D, and includes its subordinate Information Management Department 4031-1 and User Information Management Department 4032-1. Customer Information Management Department 403-2 manages information of users using Service System 300D, and has subordinate Information Management Department 4031-2 and User Information Management Department 4032-2. The description of the structure of Customer Information Management Unit 403-1 and Customer Information Management Unit 403-2 is the same as that of Customer Information Management Unit 403 in the second embodiment of the user account information management device 400A described in Figure 3, except that it is divided into two components: one for service system 200D and one for service system 300D.

[0061] When a user has been authenticated, the authentication processing unit 401 receives a user authentication query from the service system 200D. It reads at least one of the ownership information stored in the ownership information management unit 4031-1 and the user information stored in the user information management unit 4032-1 from the customer information management unit 403-1 used by the service system 200D. It then appends the read ownership information and / or user information to the authentication result and replies to the service system 200D that requested the user authentication.

[0062] Furthermore, when a user has been authenticated, the authentication processing unit 401, upon receiving a user authentication request from the service system 300D, reads at least one of the ownership information stored in the ownership information management unit 4031-2 and the user information stored in the user information management unit 4032-2 from the customer information management unit 403-2 used by the service system 300D, appends the read ownership information and / or user information to the authentication result, and replies to the service system 300D that requested the user authentication.

[0063] (Eighth Implementation) Figure 9 is a block diagram showing the user authentication system of the eighth embodiment of this disclosure. The difference between user authentication system 10G and user authentication system 10F in the seventh embodiment is that the user account information management device 400D shown in FIG8 is replaced by user account information management device 400E, service system 200D is replaced by service system 200C, and service system 300D is replaced by service system 300C.

[0064] The user account information management device 400E includes: a customer information management unit 403-1E, which adds an ICT service system utilization information management unit 4033-1 to the customer information management unit 403-1 of the user account information management device 400D; and a customer information management unit 403-2E, which adds an ICT service system utilization information management unit 4033-2 to the customer information management unit 403-2 of the user account information management device 400D. In this variation, information stored separately in the subordinate information management department 4031-1, the user information management department 4032-1, and the ICT service system utilization information management department 4033-1 can be collectively stored in the customer information management department 403-1E. Furthermore, information stored separately in the subordinate information management department 4031-2, the user information management department 4032-2, and the ICT service system utilization information management department 4033-2 can be collectively stored in the memory of the customer information management department 403-2E.

[0065] (Ninth Implementation) Figure 10 is a block diagram showing the user authentication system of the ninth embodiment of this disclosure. The difference between user authentication system 10H and user authentication system 10G in the eighth embodiment is that the user account information management device 400E shown in FIG9 is replaced by user account information management device 400, the service system 200C is replaced by service system 200E, and the service system 300C is replaced by service system 300E.

[0066] Service system 200E includes a user authentication department 201, a user approval department 202, and a customer information management department 210. Service system 300E includes a user authentication department 301, a user approval department 302, and a customer information management department 310.

[0067] Customer Information Management Unit 210 has the same structure as Customer Information Management Unit 403-1E in the 8th embodiment. Subordinate Information Management Unit 211, User Information Management Unit 212 and ICT Service System Utilization Information Management Unit 213 correspond to Subordinate Information Management Unit 4031-1, User Information Management Unit 4032-1 and ICT Service System Utilization Information Management Unit 4033-1, respectively. Customer Information Management Unit 310 has the same structure as Customer Information Management Unit 403-2E in the 8th embodiment. Its subordinate Information Management Unit 311, User Information Management Unit 312 and ICT Service System Utilization Information Management Unit 313 correspond to subordinate Information Management Unit 4031-2, User Information Management Unit 4032-2 and ICT Service System Utilization Information Management Unit 4033-2.

[0068] The user authentication unit 201 receives the authentication result of the user from the user account information management device 400. When the result is that the user has been authenticated, it outputs a query to the user approval unit 202 to confirm whether the authenticated user can use the service system 200E and the access permissions required to use the service. Furthermore, when the result is that authentication is not possible, the user authentication unit 201 sends an authentication failure message to the communication terminal 100. When the determination result is that of an authenticated user, the user authentication unit 201 reads at least one of the ownership information stored in the ownership information management unit 211 and the user information stored in the user information management unit 212, and obtains the read ownership information and / or user information. Having obtained the ownership information and / or user information, the user authentication unit 201 can grasp the user's usage preferences by obtaining at least one of the user's ownership information and user information.

[0069] The User Approval Unit 202 uses the common user account information obtained from the User Authentication Unit 201 to refer to the information stored in the ICT Service System Utilization Information Management Unit 213 to confirm whether a user who has been authenticated can use the service system 200E, and to confirm the utilization information required when using the service. The User Approval Department 202 outputs the information on whether the service system 200E can be used and the information on its use to the User Authentication Department 201. If the authentication result is deemed authentic and the user has the right to use the service, the user authentication unit 201 prepares the service provision function provided by the service system 200E, the screen information to be displayed on the communication terminal 100, etc., and sends the service provision function and the screen information to be displayed on the communication terminal 100 to the communication terminal 100. Furthermore, if the user is authenticable but does not have the right to use the service, the user authentication unit 201 may also send a message to the communication terminal 100 indicating that the user does not have the right to use the service.

[0070] Since the operations of User Authentication Department 301, User Approval Department 302 and Customer Information Management Department 310 are the same as those of User Authentication Department 201, User Approval Department 202 and Customer Information Management Department 210, the explanation is omitted.

[0071] The above describes the functional blocks included in the user account information management device and the two service systems in each implementation form.

[0072] To implement these functional modules, the user account information management device and the various systems of the two service systems can be implemented by hardware, software, or a combination thereof. Here, implementation by software means implementation by reading and executing programs on a computer.

[0073] Programs can be stored and supplied to a computer using various types of non-transitory computer-readable media. Non-transitory computer-readable media includes various types of tangible storage media. Examples of non-transitory computer-readable media include magnetic recording media (e.g., hard disk drives), optical-magnetic recording media (e.g., magneto-optical discs), optical discs (e.g., CD-ROM (Read Only Memory), CD-R, CD-R / W), semiconductor memory (e.g., masked read-only memory, PROM (Programmable ROM), EPROM (Erasable PROM), flash memory, RAM (random access memory)). Furthermore, programs can also be supplied to a computer using various types of transient computer-readable media.

[0074] To realize the functional blocks contained in the user account information management device and the two service systems in various implementations, specifically, the user account information management device and the two service systems each have a computing processing unit such as a CPU (Central Processing Unit). Furthermore, the user account information management device and the two service systems also have auxiliary memory devices such as HDDs (Hard Disk Drives) that store various control programs such as application software or OS (Operating System), and main memory devices such as RAM (Random Access Memory) that store data temporarily required by the computing processing unit's execution programs.

[0075] Then, in each of the user account information management device and the two service systems, the processing unit reads application software or operating system from the auxiliary memory, deploys the read application software or operating system on the main memory, and performs calculations based on these application software or operating system. Furthermore, based on the results of these calculations, it controls the various hardware components of each device. This is how the functional blocks of this embodiment are implemented.

[0076] (Example of a user authentication system) The user authentication systems described above in various implementations can be applied to the service management system of machine tools. The following describes an example of applying the user authentication system of the first embodiment to the service management system of a machine tool. Figure 11 is a block diagram showing the service management system of a machine tool including the user authentication system of the first embodiment.

[0077] The machine tool service management system includes a communication terminal 100, a user account information management device 400, a system X1 managed by company B (the machine tool user), a system X2 managed by company C (the machine tool manufacturer), a system X3 managed by company D (the machine tool manufacturer), a system X4 managed by company E (the machine tool peripheral device manufacturer), and a system X5 managed by company F (the machine tool parts manufacturer).

[0078] System X1 includes an asset information storage unit 50 and a service system 51. Service system 51 includes an inherent unit 511 and a user authentication unit 512. Service system 51 corresponds to service system 200 shown in FIG1, and user authentication unit 512 corresponds to user authentication unit 201 included in service system 200.

[0079] As described in the first embodiment, when the communication terminal 100 logs into the service system 51 through the user's operation, the service system 51 queries the user account information management device 400 for user authentication. The user account information management device 400 determines whether the user's authentication is valid, and the service system 51 sends the service provision functions, screen information to be displayed on the communication terminal 100, etc., to the communication terminal 100.

[0080] If the determination result is that of an authenticated user, the inherent part 511 of the service system 51 confirms the asset information of the machine tool that the user can view, and queries the asset information from the service system 61 of system X2, the service system 71 of system X3, the service system 81 of system X4, and the service system 91 of system X5.

[0081] The inherent unit 611 of the service system 61 uses the user authentication unit 612 to confirm whether Company B, which manages the system X1 containing the service system 51, can be authenticated. If it can be authenticated, the asset information of the machine tool of Company C, which is stored in the asset information memory unit 60, is sent to the inherent unit 511.

[0082] The inherent unit 711 of the service system 71 uses the user authentication unit 712 to confirm whether Company B, which manages the system X1 containing the service system 51, can be authenticated. If it can be authenticated, the asset information of the machine tool of Company D, which is stored in the asset information memory unit 70, is sent to the inherent unit 511.

[0083] The inherent unit 811 of the service system 81 uses the user authentication unit 812 to confirm whether Company B, which manages the system X1 containing the service system 51, can be authenticated. If it can be authenticated, the asset information of the peripheral devices of the machine tool of Company E, which is stored in the asset information memory unit 80, is sent to the inherent unit 511.

[0084] The inherent unit 911 of the service system 91 uses the user authentication unit 912 to confirm whether Company B, which manages the system X1 containing the service system 51, can be authenticated. If it can be authenticated, the asset information of the machine tool parts of Company F, which is stored in the asset information memory unit 90, is sent to the inherent unit 511.

[0085] When the inherent unit 511 of the service system 51 receives asset information from the inherent units of the service systems 61, 71, 81, and 91, it prepares screen information, etc., to be displayed on the communication terminal 100 based on the asset information. If the determination result is that the user is certified, the user operates the communication terminal 100 and begins to provide services using the asset information of the service system 51.

[0086] While the above illustrates an example of applying the user authentication system of the first embodiment to the service management system of a machine tool, any of the user authentication systems of the second to ninth embodiments can also be applied to the service management system of a machine tool.

[0087] While the above-described embodiments are preferred embodiments of the present invention, the scope of the present invention is not limited to the above-described embodiments. It can be implemented in various modified forms without departing from the spirit of the present invention.

[0088] The user account information management device and user authentication system disclosed herein include the above-described embodiments and can take various embodiments with the following configurations. (1) A user account information management device (e.g., user account information management device 400, 400A, 400B, 400C, 400E) that centrally manages user account information of users using a plurality of service systems, the aforementioned user account information management device comprising: The user account information management department (e.g., user account information management department 402) manages the aforementioned user account information; and The authentication processing unit (e.g., authentication processing unit 401) obtains the user account information entered by the aforementioned user through at least one of the aforementioned plurality of service systems. The aforementioned authentication processing unit verifies the aforementioned user account information entered by the aforementioned user with the aforementioned user account information managed by the aforementioned user account information management unit to determine whether the aforementioned user's authentication is valid, and sends the determination result back to at least one of the aforementioned plurality of service systems. With this user account information management device, users who wish to utilize services provided individually by multiple service systems can use a single user account to access the services of each service system, thus improving convenience. Furthermore, according to the various embodiments disclosed herein, the multiple service systems do not need to have their own devices for managing customer information, which reduces system development / operation and maintenance costs.

[0089] (2) The user account information management device described in (1) above has a customer information management department (e.g., customer information management department 403, 403-1, 403-2), which includes a family information management department that manages information about the user’s family unit. Based on this user account information management device, the service system can understand the user's usage preferences by obtaining information about the users using the service.

[0090] (3) The user account information management device as described in (2) above, wherein the aforementioned customer information management unit is provided in multiple ways corresponding to multiple service systems.

[0091] (4) The user account information management device described in any of (1) to (3) above, comprising: The service system utilizes an information management department (e.g., ICT service system information management departments 405, 405-1, 405-2), which manages the access permissions of at least one of the aforementioned service systems used by the user; and The authorization processing unit (e.g., authorization processing unit 404) confirms the aforementioned access rights to determine whether the authorization of at least one of the aforementioned service systems is valid. Based on this user account information management device, it can be confirmed whether a user who has been authenticated can use the service system, and confirm the access permissions required when using the service.

[0092] (5) The user account information management device as described in (2) or (3) above, wherein the aforementioned customer information management unit has a service system utilization information management unit, which manages the user's access rights to at least one of the aforementioned plurality of service systems.

[0093] (6) The user account information management device as described in (4) above, wherein the aforementioned service system utilizes an information management unit that is configured in multiple ways corresponding to multiple service systems.

[0094] (7) The user account information management device as described in (3) above, wherein each of the plurality of aforementioned customer information management units has a service system utilization information management unit, and the aforementioned service system utilization information management unit manages the utilization rights of at least one of the plurality of service systems used by the aforementioned user.

[0095] (8) The user account information management device described in any of (1) to (7) above, wherein the aforementioned plurality of service systems are managed by their respective companies, organizations or deployments.

[0096] (9) A user authentication system comprising: a plurality of service systems (e.g., service system 200, 200A, 200B, 200C or 200D, and service system 300, 300A, 300B, 300C or 300D); and User account information management devices (e.g., user account information management devices 400, 400A, 400B, 400C, 400E) centrally manage the user account information of users from the aforementioned plurality of service systems. The aforementioned user account information management device has: The user account information management department (e.g., user account information management department 402) manages the aforementioned user account information; and The authentication processing unit (e.g., authentication processing unit 401) obtains the user account information entered by the aforementioned user through at least one of the aforementioned plurality of service systems. The aforementioned authentication processing unit verifies the aforementioned user account information entered by the aforementioned user with the aforementioned user account information managed by the aforementioned user account information management unit to determine whether the aforementioned user's authentication is valid, and sends the determination result back to at least one of the aforementioned plurality of service systems. With this user authentication system, users who wish to utilize services provided individually by multiple service systems can use a single user account to access the services of each service system, thus improving convenience. Furthermore, according to the various embodiments disclosed herein, the multiple service systems do not require each service system to have its own device for managing customer information, thereby reducing system development / operation and maintenance costs.

[0097] (10) The user authentication system described in (9) above, wherein at least one of the aforementioned plurality of service systems has a customer information management department (e.g., customer information management department 210, 310), the aforementioned customer information management department including an affiliated information management department that manages information about the unit to which the aforementioned user belongs. Based on this user authentication system, the service system can understand the user's preferences by obtaining information about the user's affiliation.

[0098] (11) The user authentication system described in (10) above, wherein the aforementioned customer information management department is provided in multiple ways corresponding to multiple service systems.

[0099] (12) A user authentication system as described in any of (9) to (11) above, wherein each of the aforementioned plurality of service systems has: The service system utilizes the Information Management Department (e.g., ICT service systems utilize Information Management Department 203, 303), which manages the access permissions of the service system; and The user approval department confirms the aforementioned usage rights to determine whether the aforementioned service system is approved. Based on this user authentication system, it can be confirmed whether a user who has been authenticated can use the service system, and confirm the access permissions required when using the service.

[0100] (13) The user authentication system as described in (10) or (11) above, wherein the aforementioned customer information management department has a service system utilization information management department, and the aforementioned service system utilization information management department manages the user’s access rights to at least one of the aforementioned plurality of service systems.

[0101] (14) The user authentication system described in (12) above, wherein the aforementioned service system utilizes an information management department that is configured in multiple ways corresponding to multiple service systems. (15) The user authentication system described in (11) above, wherein each of the aforementioned customer information management departments has a service system utilization information management department, and the aforementioned service system utilization information management department manages the user’s access rights to at least one of the aforementioned plurality of service systems. (16) The user authentication system described in any of (9) to (15) above, wherein the aforementioned plurality of service systems are managed by their respective companies, organizations or deployments.

[0102] 10, 10A, 10B, 10C, 10D, 10E, 10F, 10G, 10H: User Authentication System 50, 60, 70, 80, 90: Asset Information Memory Department 51,61,71,81,91,200,200A,200B,200C,200D,200E: Service System 100: Communication Terminal 201: User Authentication Department 201B: User Authentication / Accreditation Department 202: User Approval Department 203: ICT Service System Utilization Information Management Department 210: Customer Information Management Department 211: Belongs to the Information Management Department 212: User Information Management Department 213: ICT service system utilizes the Information Management Department 300, 300A, 300B, 300C, 300D, 300E: Service System 301: User Authentication Department 301B: User Certification / Accreditation Department 302: User Approval Department 303: ICT Service System Utilization Information Management Department 310: Customer Information Management Department 311: Belongs to the Information Management Department 312: User Information Management Department 314: ICT service system utilizes the Information Management Department 400, 400A, 400B, 400C, 400D, 400E: User Account Information Management Device 401: Certification Processing Department 402: User Account Information Management Department 403, 403-1, 403-2, 403-1E, 403-2E: Customer Information Management Department 404: Approval Processing Department 405, 405-1, 405-2: ICT service system utilizes the Information Management Department 511,611,711,811,911:Inherent parts 512, 612, 712, 812, 912: User Authentication Department 4031, 4031-1, 4031-2: Belong to the Information Management Department 4032, 4032-1, 4032-2: User Information Management Department 4033-1, 4033-2: ICT service system utilizes the Information Management Department S11~S13, S21~S24, S25, S31, S32: Steps X1~X5: System

Claims

1. A user authentication system comprising a plurality of service systems and a user account information management device, wherein the user account information management device centrally manages user account information of users utilizing the plurality of service systems, the user account information management device comprising: a user account information management unit that manages the aforementioned user account information; an authentication processing unit that obtains user account information input by the aforementioned user through at least one of the plurality of service systems; and a customer information management unit that includes a belonging information management unit that manages information about the user's belonging unit, wherein the aforementioned user account information is common user account information used across the plurality of service systems, the authentication processing unit verifies the aforementioned user account information input by the aforementioned user with the aforementioned user account information managed by the aforementioned user account information management unit to determine whether the user's authentication is valid, and sends the determination result back to at least one of the plurality of service systems, each of the plurality of service systems comprising: a service system utilization information management unit that manages the utilization permissions of the service system; The user approval department confirms the aforementioned access rights to determine whether the aforementioned service system is authorized; and the user authentication department receives the aforementioned determination result from the aforementioned authentication processing department. When the aforementioned determination result is the result of authenticating the user, it outputs a query to confirm the aforementioned access rights to the aforementioned user approval department.

2. As in Request 1, the user authentication system, wherein the aforementioned customer information management department is set up in multiple ways corresponding to multiple service systems.

3. The user authentication system as described in request item 1 or 2, wherein the aforementioned plurality of service systems are managed by their respective companies, organizations or deployments.