An application development environment providing system, an application development environment providing method, a computer-readable nonvolatile recording medium, and a terminal device
By providing a system for identifying and authenticating device nodes through the application development environment, the shortcomings of device node access permission management in cloud computing environments are resolved, enabling secure and efficient device containment and application development, and reducing engineering design time and costs.
Patent Information
- Application Number
- CN201780059835.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2016-09-30
- Filing Date
- 2017-09-01
- Publication Date
- 2026-01-09
- Estimated Expiration
- 2037-09-01
AI Technical Summary
In cloud computing environments, existing technologies cannot efficiently manage access permissions for device nodes, resulting in insufficient security and low efficiency in device containment operations, which increases the time and cost of engineering design.
The system provides an application development environment, which enables the management department to identify and authenticate device nodes, manage device node access, including device node allocation, access rights settings and usage restrictions, provides an application development screen for visual display and editing of applications, and supports functions such as chat and audio communication.
It enables efficient management of device nodes in a cloud computing environment, ensuring security, improving application development efficiency, and reducing engineering design time and costs.
Smart Images

Figure CN109791495B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to an application development environment providing system, an application development environment providing method, a computer-readable nonvolatile recording medium, and a terminal device. BACKGROUND
[0002] In a plant, a factory, or the like, a distributed control system (DCS: Distributed Control System) in which field instruments (measuring instruments, operating instruments) and control devices that control them are connected via communication units is constructed, and advanced automatic operation is realized. In a plant in which advanced automatic operation as described above is realized, in addition to the distributed control system, various systems (engineering design systems) such as a manufacturing execution system (MES: Manufacturing Execution System), a plant information management system (PIMS: Plant Information Management System), a backbone business system (ERP: Enterprise Resource Planning), and the like are often constructed.
[0003] These engineering design systems are, for example, realized using devices such as a PLC (Programmable Logic Controller), an FA (Factory Automation) computer, a general-purpose desktop computer, a server device, or the like that are installed in a plant. In recent years, due to the development of communication technology, a part of these engineering design systems is realized by cloud computing via a network.
[0004] Here, cloud computing can coincide with the definition (definition recommended by the National Institute of Standards and Technology, USA) described in the document determined by the following URL (Uniform Resource Locator).
[0005] http: / / nvlpubs.nist.gov / nistpubs / Legacy / SP / nistspecialpublication800-145.pdf
[0006] https: / / www.ipa.go.jp / files / 000025366.pdf
[0007] In the following Patent Literature 1, cloud computing for industrial automation and production systems is disclosed. In the following Patent Literature 2, one example of a technology for providing a development environment for developing an application program used in a cloud computing environment by cloud computing is disclosed.
[0008] Patent Literature 1: Japanese Patent Application Laid-Open No. 2012-523038
[0009] Patent Literature 2: Japanese Patent No. 5792891 SUMMARY
[0010] The system that provides a development environment disclosed in Patent Literature 2 and the like is utilized by various enterprises (tenants). For example, in a case where development of an engineering design system realized in a plant is performed, the system that provides a development environment is utilized by a customer (for example, an orderer), an engineering design company (for example, an order receiver), and a third party supplier (a third party).
[0011] In the system as described above that is utilized by various tenants, from a viewpoint of security, it is necessary to notify other tenants of existence of a device used in, for example, a plant and the like. Even for the same tenant, it is sometimes desired to restrict access from other divisions (sites) or other company employees (users). On this basis, accommodation (setting) of existing devices has been conventionally performed by manual work, and thus is extremely inefficient, resulting in a request for cost. It is considered that if the accommodation work of devices can be performed efficiently, it is possible to shorten time required for engineering design (setting work of devices and the like), and it is possible to achieve cost reduction.
[0012] The application development environment providing system (1) according to the present application provides a development environment of an application program via a network, in which a management section (55) determines first information that identifies a device node (11) used by the application program in accordance with an instruction by a tenant who utilizes the development environment, and performs association between the determined first information and second information related to the tenant who performed the determination of the first information, and performs management processing that restricts or permits use of the device node.
[0013] The application development environment providing system according to the present application, in which the management section, in a case where the first information is determined, searches a cumulative section (32, 42) in which the first information of the device node connected to the network is accumulated, and in a case where the determined first information is searched, performs association between the first information and the second information.
[0014] The application development environment providing system according to the present application, in which the management section, in a case where authentication information corresponding to the first information exists, performs authentication processing using authentication information accumulated in the cumulative section and authentication information instructed by the tenant together with the first information.
[0015] The application development environment providing system of the present application provides a system, and the management process includes at least one of the following processes: a first process of assigning the device node to a specific site and account among sites and accounts belonging to a tenant determined by the first information; a second process of setting access rights for the device node for each of the sites and the accounts; and a third process of restricting or permitting use of the device node only to a specific application program.
[0016] The application development environment providing system of the present application displays the device node, to which the management process is performed, as a development component on an application development screen.
[0017] The application development environment providing system of the present application includes a development component list display area (E1) that displays the device node to which the management process is performed, and an application design area (E2) that visually displays the configuration of the application program and creates and edits the application program.
[0018] The application development environment providing system of the present application further includes a program development section (51) that provides the application development environment to a user and visually displays the application program.
[0019] The application development environment providing system of the present application includes a program development section that visually displays the application program based on layout information, wiring information, parameter information, and selection area information, the layout information being information indicating the manner of processing of the application program, the wiring information being information related to a guide line connecting an input data item, a logic as a processing content, and an output data item as a processing result, the parameter information being information indicating a set value of a parameter set in the application program, and the selection area information being information indicating a part of processing selected by a user among a series of processing of the application program.
[0020] The application development environment providing system of the present application further includes a communication section (52) that transmits and receives a part or all of the application program including set information.
[0021] The application development environment providing system of the present application includes a communication section that provides at least one of a chat function, an audio communication function, a voice call function, a screen sharing function, and a community function.
[0022] The application development environment providing system of the present application further includes a library (53) that provides a tool used when developing or executing an application program in the program development section.
[0023] The application development environment providing system of the present application provides at least one of a waveform search tool, a regression analysis tool, a multi-regression analysis tool, an MT method analysis tool, an error dispersion analysis tool, a data-driven model tool, a deep learning tool, and a correlation analysis tool.
[0024] The application development environment providing method of the present application provides a development environment for an application program via a network, in which, upon an instruction of a tenant who utilizes the development environment, first information that identifies a device node (11) utilized by the application program is determined (S105, S106), an association between the determined first information and second information related to the tenant who performed the determination of the first information is performed (S109), and a management process that restricts or permits the use of the device node is performed (S112-S114).
[0025] The application development environment providing method of the present application performs a search for the determined first information from a storage unit (32, 42) in which the first information of the device node connected to the network is accumulated (S107), and performs an association between the first information and the second information when the determined first information is searched.
[0026] The application development environment providing method of the present application includes at least one of the following steps: assigning the device node to a specific site and account among sites and accounts of the tenant who performed the determination of the first information; setting access rights for the device node for each of the site and the account; and restricting or permitting the use of the device node only to a specific application program.
[0027] The computer-readable nonvolatile storage medium of the present application stores one or more programs executed by a computer, in which, upon an instruction of a tenant who utilizes a development environment for an application program, first information that identifies a device node (11) utilized by the application program is determined, an association between the determined first information and second information related to the tenant who performed the determination of the first information is performed, and a management process that restricts or permits the use of the device node is performed.
[0028] The terminal device (16) of the present application is communicatively connected with a development environment of an application program provided via a network, and in the terminal device (16) having a display section that displays a device node, the display section displays an association between first information that identifies a device node used by the application program and second information that is related to a tenant who performed the determination of the first information, the association being determined in accordance with an instruction of a tenant who uses the development environment, and performs a management process that restricts or permits use of the device node.
[0029] The terminal device of the present application, the management process includes at least one of a first process that allocates the device node to a specific site and account among sites and accounts of the tenant who performed the determination of the first information, a second process that sets access rights to the device node for each of the sites and the accounts, and a third process that restricts or permits use of the device node only to a specific application program.
[0030] The terminal device of the present application displays the device node on which the management process is performed, as a development component on an application development screen.
[0031] The terminal device of the present application, the application development screen has a development component list display area (E1) that displays the device node on which the management process is performed, and an application design area (E2) that visually displays a configuration of the application program and creates and edits the application program.
[0032] Further features and aspects of the present application will become apparent from the following detailed description of the application with reference to the accompanying drawings.
[0033] Effects of the Invention
[0034] According to the present application, in a case where individual identification information of a device node used by an application program is determined in accordance with an instruction of a tenant who uses an application development environment providing system, an association between the determined individual identification information and the tenant who performed the determination of the individual identification information is performed, and a management process that restricts or permits use of the device node is performed. Therefore, security can be ensured, and efficient development and introduction of an application program used in a cloud computing environment can be achieved. BRIEF DESCRIPTION OF DRAWINGS
[0035] Figure 1 is a diagram that shows a system overview of an application development environment providing system according to an embodiment of the present application.
[0036] Figure 2 is a diagram that shows an example of a connection method between a device node and a smart node via a spine node.
[0037] Figure 3 is a diagram showing an example of a connection method between a device node and a smart node via an IoT cloud.
[0038] Figure 4 is a diagram showing a connection method Figure 2 is a block diagram of a structure involved in the reception and transmission of individual identification information in the connection method shown in
[0039] Figure 5 is a block diagram of a structure involved in the reception and transmission of individual identification information in the connection method shown in Figure 3
[0040] Figure 6 is a functional structure diagram of a Co-innovation space installed in an application development environment providing system according to an embodiment of the present application.
[0041] Figure 7 is a state transition diagram showing a state transition at the time of housing of a device node.
[0042] Figure 8 is a flowchart showing a process at the time of housing of a device node.
[0043] Figure 9A is a diagram showing an example of a sticker attached to a device node.
[0044] Figure 9B is a diagram showing an example of a sticker attached to a device node.
[0045] Figure 10 is a diagram for explaining a first example of a housing operation step of a device node.
[0046] Figure 11 is a timing chart showing the first example of a housing operation step of a device node.
[0047] Figure 12 is a diagram for explaining a second example of a housing operation step of a device node.
[0048] Figure 13 is a diagram showing an example of an application development screen in an embodiment of the present application. DETAILED DESCRIPTION
[0049] Embodiments of the present application are described with reference to preferred embodiments. Those skilled in the art will be able to implement many alternative methods of the present embodiments using the teachings of the present application and the present application is not limited to the preferred embodiments described here.
[0050] One embodiment of the present application provides an application development environment providing system, an application development environment providing method, a non-transitory computer readable medium, and a terminal device that can ensure safety and efficiently develop and introduce an application used in a cloud computing environment.
[0051] An application development environment providing system, an application development environment providing method, an application development environment providing program, and a terminal device according to one embodiment of the present application will be described in detail below with reference to the drawings. The development environment provided by the present embodiment is used for program development of basic software, applications, and solutions for an IoT (Internet Of Things) or an IIoT (Industrial Internet Of Things) that performs operation processing and the like using data transmitted from sensors, devices, systems, and the like connected to a communication network as input values (hereinafter, collectively referred to as "applications").
[0052] < Application Development Environment Providing System >
[0053] Figure 1 is a diagram that schematically shows a system configuration of an application development environment providing system according to one embodiment of the present application. As shown in Figure 1 , the application development environment providing system 1 is a system configured of four layers of a device node 11, a spine node 12, an intelligence node 13, and a socialization node 14 in a cloud computing environment. In the application development environment providing system 1, as shown in Figure 1 , the intelligence node 13 is connected to a thing web 15 and a terminal device 16.
[0054] The device node 11 is configured of various sensors, various devices, and various systems. The various sensors are, for example, a temperature and humidity sensor, a pressure sensor, a flow sensor, and the like. The various devices are, for example, a PLC (Programmable Logic Controller) as a control device, an OBD (On-Board Diagnostics) device connected to a CAN-BUS (Controller Area Network-BUS) in a vehicle, a KPI (Key Performance Indicator) monitor, a display that displays a current value of a specific sensor, a lamp, a buzzer, a valve, a robot arm, and the like. The various systems are, for example, a DCS, an unmanned control system, an intrusion detection system, a security system connected to an entry tag reader, a building automation system connected to lighting, a door lock, an elevator, a sprinkler, and the like.
[0055] In Figure 1The application development environment providing system 1 illustrated in the example includes, at the layer of the device nodes 11, a device node 11a composed of a sensor, a device node 11b composed of an actuator, a device node 11c composed of a sensor, and a device node 11d composed of a sensor. Hereinafter, in the case of collectively referring to these device nodes 11a to 11d without distinguishing them, they are simply referred to as "device nodes 11".
[0056] The device nodes 11 of the application development environment providing system 1 according to the present embodiment are configured by three device nodes 11a, 11c, and 11d composed of sensors, and one device node 11b composed of an actuator, for the sake of simplicity of explanation, but are not limited thereto. The device nodes 11 can be arbitrarily configured by one or more device nodes composed of sensors, devices, or systems.
[0057] Among the sensors, devices, and systems that configure the device nodes 11, there are devices that transmit data, devices that receive data and display it, and devices that cause actions in response to the reception of data. These sensors, devices, and systems are, for example, devices that correspond to plug and play. In addition, these sensors, devices, and systems are, for example, devices that have a function of communicating with multiple applications simultaneously.
[0058] For example, among the device nodes 11, there are devices that are communicatively connected to devices that configure the spine node 12, and devices that are communicatively connected to devices that configure the smart node 13 and devices that configure the IoT cloud 15. The device nodes 11 that are communicatively connected to devices that configure the spine node 12 are, for example, devices that require real-time performance, devices that are used in applications that do not allow delays (delays in data communication), fluctuations (fluctuations in data communication speed), and the like, and devices that are likely to cause a shortage of communication bandwidth if directly connected to the smart node 13 in order to generate a large amount of data.
[0059] On the other hand, the device nodes 11 that are communicatively connected to devices that configure the smart node 13 are, unlike the device nodes 11 that are communicatively connected to devices that configure the spine node 12, for example, devices that are used in applications that are not affected by delays, fluctuations, and the like. The device nodes 11 that are communicatively connected to devices that configure the IoT cloud 15 are, for example, devices that require remote settings via a wireless communication network such as a mobile phone network, a satellite line, and the like, and mobile devices.
[0060] In the example illustrated in FIG. 1, the device node 11a and the device node 11b are connected to devices that configure the spine node 12 via a local area network (LAN), for example. The device node 11c is connected to devices that configure the smart node 13 via the Internet, for example. The device node 11d is connected to devices that configure the IoT cloud 15 via a cellular network, for example. Figure 1 In the example illustrated in FIG. 1, the device node 11a and the device node 11b are connected to devices that configure the spine node 12 via a local area network (LAN), for example. The device node 11c is connected to devices that configure the smart node 13 via the Internet, for example. The device node 11d is connected to devices that configure the IoT cloud 15 via a cellular network, for example.
[0061] The spine node 12 is constituted by a server device that functions as a gateway. The server device constituting the spine node 12 (hereinafter, simply referred to as "spine node 12") is, in a cloud computing environment, a server device that accommodates (i.e., logically connects, manages, or performs input and output of data) at least one device node 11.
[0062] The spine node 12 is generally, for example, a device called a gateway server, a fog computer, or an edge computer. The spine node 12 is provided between the server devices in the cloud computing environment (in the present embodiment, the intelligent node 13 and the socialized node 14) and the sensors, devices, and systems constituting the device nodes 11.
[0063] The spine node 12 receives data from, for example, a device node 11 that communicates in a communication protocol that the intelligent node 13 cannot communicate in. The spine node 12 transmits the received data to the intelligent node 13 in a communication protocol that the intelligent node 13 can communicate in. Thus, the spine node 12 performs forwarding of data from the device node 11 to the intelligent node 13. For example, the spine node 12 receives a signal transmitted from an analog sensor or the like that cannot communicate in communication involving the Internet protocol, in a communication protocol other than the Internet protocol. The spine node 12 normalizes the received signal after digitally converting the signal, and transmits the normalized signal to the server device constituting the intelligent node 13 (hereinafter, also simply referred to as the intelligent node 13) by communication involving the Internet protocol. Thus, the spine node 12 performs forwarding of data from the device node 11 to the intelligent node 13.
[0064] The spine node 12, for example, receives data transmitted from the device node 11, and performs processing such as operation, interpretation, and determination on the received data, and transmits the processing result to the intelligent node 13.
[0065] The spine node 12, for example, acquires data from the device node 11, sets the data as time series data by attaching a time stamp (a mark indicating the time of occurrence) after performing preprocessing on the data, acquires logic, an algorithm, or the like for processing the time series data from the intelligent node 13, and performs processing (processing such as processing, determination, or the like) on the time series data based on the logic, the algorithm, or the like. The spine node 12, for example, transmits the time series data to the intelligent node 13 as needed or based on an instruction from the intelligent node 13. The spine node 12 transmits the time series data and a control signal indicating an action generated based on the logic, the algorithm, or the like to the appropriate device node 11.
[0066] The spine node 12 temporarily stores the time-series data in a time-series database (not shown) provided in the spine node 12. At the same time, the spine node 12 transmits the time-series data to the smart node 13 in response to a request from the smart node 13. Also, the spine node 12 transmits the time-series data temporarily stored in the time-series database to the history recording unit (not shown) via a secure communication path in a non-synchronized manner in order from old data. The history recording unit can be directly connected to the smart node 13. In this case, the smart node 13 can refer to and use the history recording unit as if the history recording unit is present in the local environment.
[0067] The spine node 12 is provided with a device pool area 32 (refer to Figure 4 ) that accumulates information for identifying the initial state of the device node connected to the spine node 12. The device pool area 32 is an area that stores information for identifying the device node that can be newly used among the device nodes connected to the spine node 12. The specific information accumulated in the device pool area 32 is individual identification information uniquely assigned in advance to the device node, or the individual identification information and an inherent password for authentication (authentication information). The information as described above is, for example, automatically transmitted from the device node to the spine node 12 by plug and play at the time when the device node is connected to the spine node 12, and is accumulated in the device pool area 32.
[0068] In the case where the spine node 12 is constituted by a single hardware, in order to cope with a case where a failure or an abnormal operation occurs in the spine node 12, the device node 11 communicatively connected to the spine node 12 can transmit data in parallel to two or more spine nodes 12. In the case where the device node 11 is an apparatus that communicates in accordance with the Internet protocol, the device node 11 sends out data and control signals and the like to the communication network using a technique such as multicast or broadcast, and the plurality of spine nodes 12 can receive the data and the control signals and the like in parallel, whereby redundancy is achieved.
[0069] The smart node 13, the socialized node 14, and the IoT cloud 15 include a server apparatus and a network appliance that provide a cloud computing environment. Here, the cloud computing environment refers to an environment in which various services are provided by a server connected via a network such as the Internet. The smart node 13, the socialized node 14, and the IoT cloud 15 can be physically separated by different apparatuses, or can be logically separated in a single apparatus.
[0070] The apparatus constituting the intelligent node 13 provides a function of enabling a common use of an application development environment and an application execution environment among a plurality of departments, groups, and the like (hereinafter, also referred to as sites) of an application within a co-creation enterprise, and among a plurality of employees (hereinafter, also referred to as accounts). The apparatus constituting the socialization node 14 (hereinafter, also simply referred to as the socialization node 14) provides a function of enabling a common use of an application development environment and an application execution environment among a plurality of enterprises (hereinafter, also referred to as tenants) that co-develop an application, between an enterprise that provides an application and an enterprise customer that uses the application, and between an enterprise and an individual.
[0071] The application development environment refers to a development environment for developing a program of a basic software, an application, and a solution, and the like for IoT or IIoT, which performs an operation process and the like with data transmitted from a sensor, a device, a system, and the like connected to a communication network as an input value, in a cloud computing environment. The application execution environment refers to an environment for executing a program of a basic software, an application, and a solution, and the like for IoT or IIoT, which performs an operation process and the like with data transmitted from a sensor, a device, a system, and the like connected to a communication network as an input value, in a cloud computing environment.
[0072] Hereinafter, the application development environment and the application execution environment, and the like in the present application that can be commonly used among enterprises, between an enterprise and an individual, and among users within an enterprise, which are constituted by the intelligent node 13 and the socialization node 14, will be collectively referred to as a Co-innovation space. The Co-innovation space is a virtual space in a cloud computing environment. In addition, the Co-innovation space is a space for application co-creation that is partitioned in units of enterprises (tenants) or units of organizations (sites), and the like, and is securely isolated from each other.
[0073] By using the architecture of the Co-innovation space, for example, it is possible to perform development of an application such as consultation using big data, various controls, asset management, remote sensing, remote monitoring, KAIZEN (improvement) activity assistance, and development of a system such as MES and DCS. The Co-innovation space can also be installed in a server apparatus in a data center of a local environment instead of being installed in a cloud computing environment.
[0074] The architecture of the Co-innovation space described above can also be provided by one or a plurality of apparatuses constituting the intelligent node 13 and the socialization node 14. The storage area in the architecture of the Co-innovation space can be a storage section of one or a plurality of apparatuses constituting the intelligent node 13 and the socialization node 14, or can also be constituted by combining a plurality of parts of the storage areas of the storage sections of a plurality of apparatuses.
[0075] The intelligent node 13 and the socialized node 14 act in the server device as described above, and the Co-innovation space is installed in the intelligent node 13 and the socialized node 14. The intelligent node 13 has the main functions of the Co-innovation space. On the other hand, the socialized node 14 has functions required in cases where the sharing, buying and selling, and exchange of application programs between enterprises or between enterprises and individuals are performed, among the functions that the Co-innovation space has.
[0076] The intelligent node 13 performs the management of the spine node 12 and the management of the device node 11 that are communicatively connected to the intelligent node 13. A user accesses the intelligent node 13 through a human-machine interface (HMI) and utilizes the Co-innovation space. The human-machine interface can be, for example, a terminal device 16 as shown in the drawing. Figure 1
[0077] In the intelligent node 13, a device pool area (accumulation unit) (omitted from the drawing) that accumulates information (the aforementioned individual identification information or the individual identification information and the inherent password) for identifying device nodes in an initial state connected to the intelligent node 13 is provided. The device pool area is an area that stores information for identifying device nodes that can be newly utilized among the device nodes connected to the intelligent node 13. The information as described above is accumulated in the device pool area by being automatically transmitted from the device nodes to the intelligent node 13 by plug and play at the time of connection of the device nodes to the intelligent node 13.
[0078] The intelligent node 13 has diverse external interfaces for cooperating with various external systems. For example, the intelligent node 13 can cooperate with external IoT and IIoT cloud computing environments, external billing systems, and external database systems, and the like. As described above, the intelligent node 13 can cooperate with a wide range of various external systems, and thus the intelligent node 13 can construct a Co-innovation space and an application on the Co-innovation space that cooperate with a wide range of various external systems in various IoT cloud computing environments.
[0079] The intelligent node 13 has diverse external interfaces for cooperating with various external systems, and thus the intelligent node 13 can effectively use a set of interfaces provided by IoT and IIoT cloud computing environments. Therefore, it is possible to develop a solution for the entire supply chain of a business process in a customer enterprise and for the entire life cycle.
[0080] The IoT cloud 15 provides a service of a platform for connecting the device nodes with the cloud, specifically, the smart node 13. In the IoT cloud 15, there is provided a device pool area 42 (refer to Fig. 1) that accumulates information (the aforementioned individual identification information or the individual identification information and the inherent password) for identifying the initial state of the device nodes connected with the IoT cloud 15. The device pool area 42 is an area that stores information for identifying the device nodes that can be newly used among the device nodes connected with the IoT cloud 15. The information described above is automatically transmitted from the device nodes to the IoT cloud 15 by plug and play at the time when the device nodes are connected with the IoT cloud 15, for example, and is accumulated in the device pool area 42. Figure 5 ). The device pool area 42 is an area that stores information for identifying the device nodes that can be newly used among the device nodes connected with the IoT cloud 15. The information described above is automatically transmitted from the device nodes to the IoT cloud 15 by plug and play at the time when the device nodes are connected with the IoT cloud 15, for example, and is accumulated in the device pool area 42.
[0081] The service of the platform for connecting the device nodes with the cloud (the smart node 13) described above can be provided by one or a plurality of apparatuses that constitute the IoT cloud 15. The device pool area 42 can be a storage section of one or a plurality of apparatuses that constitute the IoT cloud 15, or can be constituted by combining a plurality of storage areas of storage sections of a plurality of apparatuses.
[0082] The terminal apparatus 16 is an apparatus that is communicatively connected with a development environment of an application program provided via a network (a development environment provided by the application development environment providing system 1). The terminal apparatus 16 is realized by, for example, a personal computer that has an input apparatus such as a keyboard, a display apparatus (display section) such as a liquid crystal display apparatus, a CPU (Central Processing Unit), a RAM, and the like. The type of the personal computer can be, for example, any of a desktop type, a notebook type, a tablet type, and the like.
[0083] <Connection between device nodes and smart nodes>
[0084] Figure 2 is a diagram that shows one example of a connection method between the device nodes and the smart nodes via the IoT cloud. As shown in Figure 2 , the device node 11d and the IoT cloud 15 are connected via, for example, a cellular network N21 and a dedicated line N22. The IoT cloud 15 and the smart node 13 are connected via a communication network N23 such as a dedicated line or an Internet VPN. The IoT cloud 15 is managed by a monitoring and management center M2.
[0085] Figure 3 is a diagram that shows one example of a connection method between the device nodes and the smart nodes via the IoT cloud. As shown in Figure 3 , the device node 11d and the IoT cloud 15 are connected via, for example, a cellular network N21 and a dedicated line N22. The IoT cloud 15 and the smart node 13 are connected via a communication network N23 such as a dedicated line or an Internet VPN. The IoT cloud 15 is managed by a monitoring and management center M2.
[0086] Figure 2 The device node 11a and Figure 3 The device node 11a and Figure 2 The device node 11a and Figure 3 The device node 11a and The device node 11a and
[0087] The device node 11a and Figure 4 The device node 11a and Figure 2 The device node 11a and Figure 4 The device node 11a and The device node 11a and
[0088] The device node 11a and The device node 11a and
[0089] The device node 11a and Figure 5 The device node 11a and Figure 3 The device node 11a and Figure 5 The device node 11a and Figure 4The illustrated device node 11a likewise has an individual identification information holding section 21, an activation operation section 22, and an individual identification information transmission section 23. In the device node 11d as described above, based on an instruction of the activation operation section 22, the individual identification information transmission section 23 reads out the individual identification information (or the individual identification information and the inherent password) from the individual identification information holding section 21, and transmits the individual identification information to the outside (for example, the cellular network N21).
[0090] The co-innovation cloud 15 has an individual identification information reception section 41 and a device pool area 42 (accumulation section). The individual identification information reception section 41 receives the individual identification information (or the individual identification information and the inherent password) transmitted from the device node 11d via the cellular network N21 and the dedicated line N22 in order. The device pool area 42 holds the individual identification information (or the individual identification information and the inherent password) received by the individual identification information reception section 41 in a device list.
[0091] 〈Function structure of Co-innovation space〉
[0092] Figure 6 is a function structure diagram of the Co-innovation space installed in the application development environment providing system according to the embodiment of the present application. The function of the Co-innovation space can be realized by either one of the intelligent node 13 and the socialization node 14, or both of the intelligent node 13 and the socialization node 14. In the present embodiment, for the sake of simplicity of explanation, it is assumed that the function of the Co-innovation space is realized by the intelligent node 13.
[0093] As Figure 6 illustrated, the Co-innovation space realized by the intelligent node 13 has an application board 51, an exchange tool 52, a library 53, a storage 54, a device management section 55 (management section, management unit), a tenant management section 56, a site · account management section 57, an application store 58, a charge section 59, and a database section 60.
[0094] The application board 51 (program development section) provides the application development environment and the application execution environment for multiple tenants, multiple sites, and multiple accounts to the user. The application board 51 has a function of compiling, a display section capable of visually displaying the application program to the user, and the like. The display section displays an image representing the Co-innovation space in which the application program is visually displayed based on layout information, wiring information, parameter information, selection area information, and the like.
[0095] Layout information refers to information indicating a processing manner of an application as a development target. For example, the following information is included in the layout information, i.e., indicating whether the application as a development target is an application performing processing of multiple inputs and 2 outputs, or an application performing processing of multiple inputs and multiple outputs, or an application performing processing of 1 input and multiple outputs, and the like.
[0096] Wiring information refers to information defined in association with a guide line when a graph visually indicating a relationship between data items and logics is generated by connecting the data items, the logics as processing contents, and output data items as processing results in an application as a development target by the guide line. Parameter information refers to information indicating a set value of various parameters set in the application as a development target.
[0097] Selection area information refers to information indicating a part of processing selected (designated) by an operation or the like by a user in a series of processing of the application as a development target. For example, with respect to the application visually displayed by the application board 51, the user performs an operation on a mouse or the like to enclose a region of a part of the application, thereby generating selection area information indicating the enclosed region.
[0098] The communication tool 52 provides a chat function, an audio communication function, a voice call function, a screen sharing function, and a community function such as a bulletin board, a social networking service (SNS), and the like, which are utilized among users. For example, the chat function enables not only text data (e.g., source code and the like), image data, and an execution file of a program, but also setting information such as a parameter value to be shared among users by being transmitted and received as a part or all of the application as a development target.
[0099] The library 53 provides a general-purpose processing logic, a template, an analysis tool, a history recording unit (a database storing history information and achievement information), and the like, which are used when the application is developed or executed in the application board 51. For example, the library 53 stores various analysis tools such as a waveform search tool, a regression analysis tool, a multiple regression analysis tool, an MT method analysis tool, an error dispersion analysis tool, a data-driven model tool, a deep learning tool, and a correlation analysis tool.
[0100] The storage 54 distinguishes various information (e.g., developed application programs, analysis result data, etc.) into information for general disclosure, information for tenant sharing, information for site sharing, and information for account personal use, and stores each in a storage area for general disclosure, a storage area for tenant sharing, a storage area for site sharing, or a storage area for account personal use. The user can be controlled in advance by the manager of the tenant based on the authority set for each user with respect to which storage area the various information can be saved. The storage 54 is a storage medium, and can be, for example, a hard disk drive (HDD), a flash memory, an electrically erasable programmable read-only memory (EEPROM), a RAM (readable and writable memory), a ROM (read-only memory), or any combination thereof.
[0101] The device management unit 55 manages information of sensors, devices, and systems that constitute the device nodes 11 housed in the smart node 13. For example, the device management unit 55 manages information in which the identification information given to the device nodes 11 used for housing of the device nodes 11 and the identification information of the accounts, sites, and tenants are associated.
[0102] The device management unit 55 of the smart node 13 can manage information of sensor devices and systems that constitute the device nodes 11 housed in the spine node 12 by acquiring the information from the spine node 12. Alternatively, the spine node 12 can manage the information, and the device management unit 55 of the smart node 13 can acquire the information from the spine node 12.
[0103] The tenant management unit 56 manages various information related to tenants (companies). For example, the tenant management unit 56 sets, changes, deletes, etc. information of basic information, charge information, operation authority, and approval authority of the tenants. For example, the tenant management unit 56 manages, for each tenant, contract information related to a contract associated with use of the Co-innovation space and use of applications, tools, templates, data, etc. with payment or free of charge.
[0104] The site and account management unit 57 manages various information related to sites (organizations) and accounts (users). For example, the site and account management unit 57 sets, changes, deletes, etc. information of basic information, charge information, operation authority, and approval authority of the sites and accounts.
[0105] The application store 58 is a function for users to make a purchase or sale of a part or all of an application program, logic, templates, data, and the like (hereinafter, simply referred to as an application and the like). For the application and the like sold by the application store 58, any charging method can be used, such as monthly charge, annual charge, charge corresponding to the number of uses, or one-time charge. For a specific application and the like among the application and the like sold by the application store 58, a certain period (for example, one month) from the date of use by the user can be set as a free trial period, and no charge can be made.
[0106] The charge unit 59 performs a charge process for a user who has purchased the application and the like sold by the application store 58. The charge unit 59 can perform a charge process for the use of the Co-innovation space. The charge object can be able to be registered in advance for each tenant, site, or account. In a case where the purchased application and the like is an application and the like registered by the user in the application store 58, a charge can be made for the user who has purchased the application and the like, and a part of the amount collected can be paid to the user who has registered the application and the like.
[0107] The database unit 60 holds data such as production management information, plant operation management information, and quality information required for the operation of the application as a database, and provides the required data in response to a request from the application. The database can be a general database such as SQL, or a specific-purpose database other than SQL. The database can be set for each tenant, site, or account, or the access right can be individually set by the administrator in correspondence with the contents of the data. These databases can refer to an external database outside the Co-innovation space.
[0108] 〈Accommodation of device nodes〉
[0109] Next, the accommodation of the device node to the system will be described. Here, the accommodation of the device node to the system means logically connecting, managing, and inputting and outputting the device node to the system. As described using the flowchart of FIG. 7, the device node 11 holds the individual identification information (or the individual identification information and the inherent password) in the individual identification information holding unit 21 inside. The device node 11 transmits the individual identification information and the like to the spine node 12 and the IoT cloud 15 by plug and play. If the individual identification information and the like from the device node 11 are received by the spine node 12 and the IoT cloud 15, they are accumulated in the device pool area 32 and the device pool area 42. Figure 4 、 Figure 5
[0110] At this time, from the viewpoint of security, it is sometimes necessary to know the existence of each device node from other tenants. In addition, it is sometimes desirable to restrict access from other users, other sites. Also, it is important to make the accommodation of devices easy, in the viewpoint of the efficiency of the setting work and the viewpoint of cost reduction. In order to achieve this, in the present embodiment, as shown in Figure 7 five states of an activated state ST1, a registered state ST2, an allocated state ST3, an assigned state ST4, and an app locked state ST5 are defined.
[0111] Figure 7 is a state transition diagram showing the state transition at the time of device node accommodation. First, the device node 11 becomes an initial state at the time of factory shipment. By performing an activation operation from the initial state, the device node 11 is transitioned to the activated state ST1. The activated state ST1 is a state in which the device node 11 for which the activation is completed is recognized by the spine node 12 or the IoT cloud 15.
[0112] At this time, one or a plurality of devices constituting the spine node 12 or the IoT cloud 15 can register or change the state (state information) of the device node 11 for which the activation is completed to the activated state ST1 using a state management file for managing each state of the device node stored in an unillustrated storage or storage area constituted by these devices, thereby managing the state transition of the device node.
[0113] In general, the device node 11 is connected to the network, and if the power is turned on, the activation is completed by plug and play. The connection of the device node 11 to the network is achieved by setting the device node 11 within the range of the radio wave if the accommodation is performed by the cellular network / wireless network. In the case of accommodation by an optical fiber, a twisted pair, the connection of the device node 11 to the network is achieved by connecting the wiring to the device node 11 or the like.
[0114] In the activated state ST1, the individual identification information or the like of the device node 11 for which the activation is completed is accumulated in the device pool area 32 of the spine node 12 or the device pool area 42 of the IoT cloud 15. However, the existence thereof cannot be recognized by any tenant. Thus, the device node 11 is not accidentally invaded, attacked, or recorded.
[0115] Even if set to the state as described above, the individual identification information and the like accumulated in the device pool area 32, 42 are known to a third party in an arbitrary method, there is a risk that the device node 11 is invaded, attacked, or stolen by the registration (an operation of performing the allocation of the device node 11 and the tenant). The inherent password is attached to the individual identification information in order to reduce the risk as described above.
[0116] Next, the device node 11 is converted to the registration state ST2 by performing the registration. The registration state ST2 is a state in which the device node 11 is allocated to a specific tenant. In the smart node 13, the tenant who performs the accommodation of the device node 11 notifies the individual identification information to the spine node 12 or the IoT cloud 15. Thereby, the association of the individual identification information (the 1st information) of the device node 11 held in the device pool area 32, 42 and the tenant (the 2nd information) is performed. The association is performed by the device management section 55 illustrated in the Figure 6 The individual identification information in which the association is performed is copied to the device registration area of the tenant, and is deleted from the device pool area 32, 42.
[0117] At this time, the device management section 55 of the Co-innovation space constituted by the smart node 13 can use a state management file for managing each state of the device node stored in the storage section or the storage area not illustrated, and change the state (the state information) of the device node 11 for which the registration is completed from the activation state ST1 to the registration state ST2, thereby managing the state conversion.
[0118] As described above, the space for each tenant is securely isolated from each other. Therefore, in this state, the third party tenant cannot identify the accommodated device node 11, and cannot allocate the device node 11 to the third party tenant. In the case in which the individual identification information and the inherent password of the device are accumulated in the device pool area 32, 42, the association of the tenant and the individual identification information held in the device pool area 32, 42 is not performed if the smart node 13 does not notify the individual identification information and the inherent password of the device at the same time.
[0119] Next, by performing an Allocation operation (an operation of allocating the device node 11 in the registration state ST2 to the site, the account by the manager of the tenant), the device node 11 transitions to an Allocation state ST3. The Allocation state ST3 is a state in which the device node 11 is allocated to a specific tenant, account. In the Allocation state ST3, if each user logs in to the Co-innovation space of the respective accounts of the smart node 13, the device node 11 is recognized on the Co-innovation space of the respective accounts, and the device node 11 can be used in the application development screen (refer to FIG. 6). Figure 13 ).
[0120] At this time, the device management section 55 of the Co-innovation space constituted by the smart node 13 can change the state (state information) of the registered device node 11 from the registration state ST2 to the Allocation state ST3 using a state management file for managing each state of the device node stored in a storage section or storage area not shown, thereby managing the state transition.
[0121] Next, by performing an Assignment operation (an operation of the manager of the tenant logging in to the tenant by the manager authority, setting the authority to each site, account under the jurisdiction of each tenant), the device node 11 transitions to an Assignment state ST4. The Assignment state ST4 is a state in which the access right is set for each site, account. Here, the device node 11 is in a state in which it can be recognized and used from any site, account under the jurisdiction of the tenant in the initial state. The manager of the tenant logs in by the manager authority, and thus can set the authority such as R / O (Read Only: read only), R / W (Read Write: read and write), X (Execute) for each site, account or each group set additionally.
[0122] At this time, the device management section 55 of the Co-innovation space constituted by the smart node 13 can change the state (state information) of the registered device node 11 from the Allocation state ST3 to the Assignment state ST4 using a state management file for managing each state of the device node stored in a storage section or storage area not shown, thereby managing the state transition.
[0123] Next, the device node 11 is converted to the program lock state ST5 by performing the lock operation (an operation of limiting the authority of changing the settings, stopping, restarting, and the like of the device node 11 to a specific application). The program lock state ST5 is a state in which the use of the device node 11 is limited or permitted only to a specific application. This state is set in order to limit or permit the changing of the settings, stopping, restarting, and the like of the device node 11, and enables the stable use of the device node 11.
[0124] The lock operation can be performed by any account, and the manager of the tenant can forcibly change it. Even if the device becomes the program lock state ST5, it can be read as long as the authority is R / O (read only). If the settings are changed in order to use it from the program of another application, an error is returned, and the user ID and the application ID of the user who performed the lock operation are prompted.
[0125] At this time, the device management unit 55 of the Co-innovation space constituted by the smart node 13 can change the state (state information) of the registered device node 11 from the specified state ST4 to the program lock state ST5 using a state management file for managing each state of the device node stored in a storage unit or a storage area not shown, thereby managing the state transition.
[0126] Figure 8 is a flowchart showing the process at the time of housing the device node. Figure 8 The flowchart shown shows the process until the housed device node 11 is converted to the registration state ST2. Here, in order to make the understanding easy, the case where the device node 11 connected to the spine node 12 is housed is described as an example. However, the same process is performed in the case where the device node 11 connected to the IoT cloud 15 is housed.
[0127] First, the smart node 13 transmits the individual identification information of the device node which attempts to be housed to the spine node 12 (step S1). This process is performed, for example, when the user operating the terminal device 16 inputs the individual identification information of the device node which attempts to be housed. The spine node 12 receives the individual identification information transmitted from the smart node 13 (step S2). Then, the spine node 12 compares the received individual identification information with the device inherent information list of the device pool area 32, and determines whether or not the individual identification information coincides (step S3).
[0128] In a case where it is determined that the individual identification information does not match (in a case where the determination result of step S3 is "NO"), the backbone node 12 transmits a rejection to the smart node 13 (step S4). The smart node 13 receives the rejection transmitted from the backbone node 12 (step S5). Then, in the smart node 13, the registration of the device node 11 fails (step S6).
[0129] On the other hand, in a case where it is determined that the individual identification information matches (in a case where the determination result of step S3 is "YES"), the backbone node 12 determines whether or not there is an inherent password corresponding to the individual identification information (step S7). In a case where it is determined that there is no inherent password (in a case where the determination result of step S7 is "NO"), the backbone node 12 copies the information of the device node 11 in the device registration area of the tenant (step S8). Then, the backbone node 12 deletes the information of the device of the device pool area 32 (step S9).
[0130] Further, the backbone node 12 transmits a registration completion to the smart node 13 (step S10). The smart node 13 receives the registration completion transmitted from the backbone node 12 (step Sll). Then, in the smart node 13, the registration of the device node 11 is completed (step S12). Thus, the device node 11 of which the registration is completed becomes the registered state ST2.
[0131] On the other hand, in step S7, in a case where it is determined that there is an inherent password (in a case where the determination result of step S7 is "YES"), the backbone node 12 transmits a password request to the smart node 13 (step S13). The smart node 13 receives the password request transmitted from the backbone node 12 (step S14). Then, the smart node 13 prepares the inherent password (step S15), and transmits the inherent password to the backbone node 12 (step S16).
[0132] The backbone node 12 receives the inherent password transmitted from the smart node 13 (step S17). Then, the backbone node 12 compares the received inherent password with the inherent password accumulated in the device pool area 32, and determines whether or not the inherent passwords match (step S18).
[0133] In a case where it is determined that the intrinsic passwords are not consistent (in a case where the result of the determination in step S18 is "NO"), the backbone node 12 transmits a rejection to the smart node 13 (step S19). The smart node 13 receives the rejection transmitted from the backbone node 12 (step S20). Then, in the smart node 13, the registration of the device node 11 fails (step S21). On the other hand, in a case where it is determined that the intrinsic passwords are not consistent (in a case where the result of the determination in step S18 is "YES"), the backbone node 12 and the smart node 13 perform the processing of steps S8 to S12 described above, and the registration of the device node 11 is completed. Thus, the device node 11 for which the registration is completed becomes the registered state ST2.
[0134] 〈Registration of Device Node〉
[0135] Next, a specific operation step for housing the device node 11 will be described. As described above, in the present embodiment, in a case where the device node 11 is housed, the device node 11 needs to be constantly set with respect to the five states of the activation state ST1, the registered state ST2, the assigned state ST3, the specified state ST4, and the program lock state ST5. The transition from the initial state to the activation state ST1 can be performed by plug and play. Figure 7
[0136] However, the transition from the registered state ST2 to the program lock state ST5 requires the operation of the manager of the tenant. For example, the manager of the tenant needs to perform the input of the individual identification information of the device node 11 and the input operation of the intrinsic password. Thus, the operation burden of the manager of the tenant is large. Therefore, in the present embodiment, in order to simplify the operation of housing the device, as shown in FIG. 9, a sticker SL on which the individual identification information, the intrinsic password, and the two-dimensional code CD are printed is attached to the device node 11.
[0137] Figure 9A and Figure 9B is a diagram showing one example of a sticker attached to the device node. In Figure 9A The sticker SL shown is printed with a character string ST indicating the individual identification information of the device node and a two-dimensional code CD containing the individual identification information. The character string ST contains "Device Identification" indicating the main theme that it is the individual identification information of the device node and the individual identification information "3201XF5JP3A2S052" of the device node. The two-dimensional code CD contains information in which the individual identification information of the device node 11 is described in XML (Extensible Markup Language) form. Here, the sticker SL printed with the character string ST indicating the individual identification information of the device node and the two-dimensional code CD containing the individual identification information is attached to the device node, but the character string ST and the two-dimensional code CD can be printed or engraved directly on the device node.
[0138] In Figure 9B The sticker SM shown is printed with a character string SU indicating the individual identification information and the inherent password of the device node and a two-dimensional code CE containing the individual identification information and the inherent password. The character string SU contains "Device Identification" indicating the main theme that it is the individual identification information of the device node, the individual identification information "3201XF5JP3A2S052" of the device node, "PASS CODE" indicating the main theme that it is the inherent password, and the inherent password "X_5PxG32LZZQ". The two-dimensional code CE contains information in which the individual identification information and the inherent password of the device node 11 are described in XML form.
[0139] As Figure 9B In the case where the character string SU contains the inherent password as in the sticker SM, there is a risk that the inherent password will be known by others. Therefore, the sticker SL and the sticker SM are usually used together, and the sticker SM is provided so as to be easily peeled off. The two-dimensional code CD printed in the sticker SL exemplified in Figure 9A and the two-dimensional code CE printed in the sticker SM exemplified in Figure 9B are matrix-type two-dimensional codes such as QR codes (registered trademark), and can be stack-type two-dimensional codes. The two-dimensional codes CD and CE are not limited to two-dimensional codes, and can be one-dimensional codes or other codes. Therefore, the two-dimensional code is read at the time of setting, and after the setting of the device node is completed, the sticker SM should be peeled off from the device node and separately stored and managed from the viewpoint of security for preventing a third party from specifically designating the device on the network and taking advantage of this situation.
[0140] "Example 1 of the Housing Operation Step"
[0141] Figure 10 is a diagram for explaining the first example of the housing operation step of the device node, Figure 11 is a timing chart indicating the first example of the operation step. AsFigure 10 As shown, the Co-innovation space implemented by the intelligent node 13 is configured with renter areas R1 to R3 for each renter. These renter areas R1 to R3 are configured using... Figure 6 The information managed by the tenant management department 56 shown is created here. For simplicity, only three tenant areas R1 to R3 are illustrated here. However, the tenant areas are set up in a number corresponding to the number of tenants utilizing the Co-innovation space. To facilitate understanding, the first example of the containment operation procedure will be explained below, focusing on the tenant (hereinafter referred to as "tenant A") who has been assigned to tenant area R1.
[0142] like Figure 10 As shown, within the renter area R1, there is a site area R11 for each site (organization) belonging to renter A. Figure 10 For simplicity, only the site area R11 belonging to one site (hereinafter referred to as "site B") of renter A is shown in the diagram. Within site area R11, there is an account area R12 for each account (user) belonging to site B. Figure 10 For simplicity, only the account area R12 belonging to one account (hereinafter referred to as "Account C") of site B is shown in the diagram. These site areas R11 and account areas R12 are defined using... Figure 6 The information is created by the Account Management Department 57 of the site shown.
[0143] Within the renter area R1, there is a device registration area R13 that allows registration of device nodes shared by sites and accounts belonging to renter A. This device registration area R13 is used by… Figure 6 The information is created by the Equipment Management Department 55 shown. Figure 10 In the example shown, the device nodes registered in the device registration area R13, which is located within the renter area R1, can be shared by renter A, site B, and account C. Sites and accounts belonging to renter A can share data, logic, and applications, except for the device nodes registered in the device registration area R13.
[0144] like Figure 11As illustrated, the manager of the tenant A first sets up the device node 11, and turns on the power of the device node 11 (step S101). If the power of the device node 11 is turned on, the device node 11 is connected to the spine node 12, the smart node 13, or the IoT cloud 15 by plug and play. Here, as an example, it is assumed that the device node 11 is connected to the spine node 12. If the device node 11 is connected to the spine node 12, the device node 11 transmits individual identification information (or individual identification information and an inherent password) of the device node 11 to the spine node 12 (step S102). The individual identification information of the device node 11 is accumulated in the device pool area 32 of the spine node 12. Thus, the state of the device node 11 is changed from the initial state to the active state ST1.
[0145] Next, the manager of the tenant A operates the terminal device 16 to access the smart node 13, and logs in to the Co-innovation space (step S104). Thus, the manager of the tenant A can use the tenant area R1 set in the Co-innovation space implemented by the smart node 13. Next, the manager of the tenant A selects a device registration menu prepared in advance in the Co-innovation space.
[0146] Further, the manager of the tenant A uses the camera 17 connected to the terminal device 16 to take an image of the two-dimensional code CE of the sticker SM attached to the device node 11 (step S105). If the two-dimensional code CE is taken by the camera 17, the individual identification information (or the individual identification information and the inherent password) of the device node 11 is read from the two-dimensional code CE. The terminal device 16 transmits the read individual identification information (or the individual identification information and the inherent password) to the smart node 13 (step S106).
[0147] The camera 17 connected to the terminal device 16 described above can be, for example, a portable terminal device such as a smartphone equipped with a camera function. In the case of using the portable terminal device as described above, when the device node 11 is set outdoors where there is no network or PC (personal computer), the portable terminal device can be connected to the smart node 13 via a wireless telephone line, and thus the work can be efficiently performed.
[0148] Next, the smart node 13 accesses the device pool area 32 of the spine node 12, and searches for the individual identification information identical to the individual identification information transmitted from the terminal device 16 (step S107). In a case where there is an inherent password corresponding to the individual identification information, the smart node 13 compares the inherent password accumulated in the device pool area 32 and the inherent password transmitted from the terminal device 16 to authenticate (step S108: authentication process).
[0149] In a case where the same individual identification information as that transmitted from the terminal device 16 is retrieved (in other words, in a case where the same individual identification information as that transmitted from the terminal device 16 exists in the device pool area 32), the intelligence node 13 performs a process of associating the tenant A and the device node 11 (step S109). This process is performed by the device management section 55 of the intelligence node 13. Then, the spine node 12 transmits the information of the device node 11 accumulated in the device pool area 32 to the intelligence node 13 (step S110). The intelligence node 13 registers the information of the device node 11 in the device registration area R13 of the tenant A (step S111). Thereby, the state of the device node 11 is converted from the active state ST1 to the registered state ST2. The information of the device node 11 forwarded to the intelligence node 13 is deleted from the device pool area 32. Figure 6
[0150] If the device node 11 is registered as the device node of the tenant A, the manager of the tenant A operates the terminal device 16 to allocate the device node 11 to the site B, the account C under the jurisdiction of the tenant A (step S112). Thereby, the intelligence node 13 performs a process of allocating the device node to a specific site and account (for example, the site B, the account C) (1st process). If this process ends, the state of the device node 11 is converted from the registered state ST2 to the assigned state ST3.
[0151] The manager of the tenant A who has logged in by the manager authority operates the terminal device 16 to perform authority setting of R / O (read only), R / W (read and write), X (execution), and the like with respect to the site B, the account C under the jurisdiction of the tenant A (step S113). Thereby, the intelligence node 13 performs a process of setting the access right with respect to the device node 11 for each site and account (2nd process). If this process ends, the state of the device node 11 is converted from the assigned state ST3 to the specified state ST4.
[0152] The manager of the tenant A who has logged in by the manager authority operates the terminal device 16 to perform an operation (locking) of limiting the authority of changing, stopping, restarting, and the like of the device node 11 to a specific application (step S114). Thereby, the intelligence node 13 performs a process of limiting or permitting the use of the device node 11 only to a specific application program (3rd process). If this process ends, the state of the device node 11 is converted from the specified state ST4 to the program lock state ST5.
[0153]
[0154] Figure 12 is a diagram for explaining the second example of the housing operation step of the device node. In this example, by using the application of the portable terminal 18, it is possible to easily perform the process from the activation state ST1 to the designation state ST4. That is, by the application of the portable terminal 18, the process shown in steps S104 to S112 is performed. Figure 11
[0155] In this example, the case where the application of the portable terminal 18 is used is explained, but it is not limited thereto. For example, it is also possible to access the device registration screen (application) on the Co-innovation space from the portable terminal 18 via a browser, and by using the device registration screen (application), the process shown in steps S104 to S112 is performed. Figure 11
[0156] After the setting of the device node 11 is completed, the manager of the tenant A starts the application of the portable terminal 18, and reads the two-dimensional code CD1 displayed on the terminal device 16 using the portable terminal 18. Thereby, the account ID and the password are input to the portable terminal 18. The account ID and the password input to the portable terminal 18 are automatically transmitted to the smart node 13 by the application of the portable terminal 18. Thereby, the manager of the tenant A logs in to the Co-innovation space (step S104).
[0157] Here, in the two-dimensional code CD1 displayed on the terminal device 16, the account ID and the password required for the manager of the tenant A to log in to the Co-innovation space are included. This two-dimensional code CD1 is displayed together with the contract information of the tenant to which the manager of the tenant A belongs, for example, at the time of selecting the "contract information" menu, in a state where the manager of the tenant A has logged in to the Co-innovation space through the terminal device 16.
[0158] As described above in this example, by only the operation of reading the two-dimensional code CD1 by the application of the portable terminal 18, the manager of the tenant A is able to log in to the Co-innovation space. Therefore, at the time of logging in to the Co-innovation space, the input of the account ID and the password is not required, and the manager of the tenant A is able to log in extremely easily. The above-described two-dimensional code CD1 can be printed, and the printed two-dimensional code CD1 can be read by the terminal device 16.
[0159] In the present example, the manager of the tenant A reads the two-dimensional code CD1 displayed at the terminal device 16 by the application of the portable terminal 18, thereby inputting the account ID and the password to the portable terminal 18, and describes an example of logging in to the Co-innovation space, but is not limited thereto. For example, the manager of the tenant A can also input the account ID and the password on the screen of the portable terminal 18 using the keyboard of the portable terminal 18, and log in to the Co-innovation space.
[0160] After completion of the login to the Co-innovation space, the manager of the tenant A uses the portable terminal 18 to take a picture of the two-dimensional code CE of the sticker SM attached to the device node 11 (step S105). Thereby, the individual identification information (or the individual identification information and the inherent password) of the device node 11 is read from the two-dimensional code CE. Then, the processing of steps S106 to S112 is automatically performed by the application of the portable terminal 18 until the processing of the assignment state ST3 is completed. In the processing of step S112, the site and the account to which the device node 11 is assigned need to be set, but the setting information is set in advance in the application of the portable terminal 18.
[0161] The manager of the tenant A can log in to the Co-innovation space of the smart node 13 using the portable terminal 18 by the manager authority by selecting the authority of each site and account through the input screen of the application of the portable terminal 18. In this case, the processing until step S113 is performed by the application of the portable terminal 18 until the processing of the designation state ST4 is completed. Thereby, further simplification of the work can be achieved.
[0162] < Application development screen >
[0163] Figure 13 is a drawing illustrating one example of the application development screen in one embodiment of the present application. After the accommodation of the device nodes (or at the same time as the accommodation of the device nodes), each user (account) can continuously develop the application program through the application development screen illustrated in Figure 13 the network. In the application development screen, a plurality of users (accounts) set for each tenant and site can create, manage, monitor, and execute the application program while sharing the data, the logic, the application, and the state in accordance with the execution authority set in advance by the manager. The application development screen is displayed, for example, on the display device (display section) of the terminal device.
[0164] Figure 13The illustrated application development screen has a development component list display area El and an application design area E2. The development component list display area El is an area in which a list of development components used in development of an application program is displayed. In the development component list display area El, for example, analysis elements, input / output data items (for example, sensor outputs), various logics (operators, functions) in common, and the like are displayed as development components.
[0165] The application design area E2 is an area in which the configuration of an application program that is a development target is visually displayed. In the application design area E2, creation and editing of an application program that is a development target can be performed. A user, for example, selects a desired development component from among the list of development components (for example, analysis elements, data items of input / output data, logics as processing contents, and the like) displayed in the development component list display area El, and drags and drops the selected component to the application design area E2 by a mouse operation or the like. Thereby, an image representing the selected development component can be displayed in the application design area. Further, the development components displayed in the application design area E2 are connected by lines, arrows, and the like, whereby an application program can be created.
[0166] When the device node 11 is housed, if the device node 11 is converted to the assignment state ST3, the housed device node 11 is displayed as a development component in the development component list display area El in the application development screen of the tenant, the site, or the account to which the device node 11 is assigned. Further, the housed device node 11 can be shared by each tenant, site, or account, and creation and editing of a program can be performed.
[0167] If the housed device node 11 is converted to the specified state ST4, access rights are set for each site and account. Therefore, a user who is developing an application program using the application development screen illustrated in FIG. 1 is able to use the device node 11 only within the range of the set rights. Figure 13 A user who is developing an application program using the application development screen illustrated in FIG. 1 is able to use the device node 11 only within the range of the set rights. Figure 13 If the housed device node 11 is converted to the program lock state ST5, use of the device node 11 is limited to a specific application. Therefore, a user who is developing an application program using the application development screen illustrated in FIG. 1 is able to use the device node 11 only in a case where the user is developing the application to which use is permitted.
[0168] As described above, in the present embodiment, according to an instruction of a manager of a tenant who utilizes the application development environment providing system 1, in a case where individual identification information of the device node 11 utilized by the application program is determined, association of the determined individual identification information and the tenant who performed the determination of the individual identification information is performed, and management processing of restricting or permitting use of the device node 11 is performed. Thus, the device node 11 can be accommodated in the system with high security.
[0169] Specifically, the application development environment providing system 1 can be utilized by various enterprises (tenants). For example, in a case where development of an engineering design system implemented by a plant is performed, it can be utilized by a customer (for example, an orderer), an engineering design company (for example, an order receiver), and a third party supplier (a third party). In the system utilized by various tenants as described above, from a security viewpoint, sometimes existence of the device node 11 used in the plant is not notified to other tenants. In addition, even with the same tenant, sometimes it is desired to restrict access from other deployments (sites) or other company employees (users).
[0170] In the above-described embodiment, by performing the management processing of restricting or permitting use of the device node 11, use of the device node 11 is restricted to a specific site and an account belonging to a specific tenant, access rights to the device node 11 are set for each site and account, and utilization of the device node 11 is restricted to only a specific application program. Thus, for example, existence of the device node 11 used in the plant is not known by other tenants, and it is also possible to restrict access from other deployments (sites) or other company employees (users) in the same tenant. As described above, in the present embodiment, the device node 11 can be accommodated in the system with high security.
[0171] The device node 11 operated by the tenant is managed identically, and thus, if observed from the application, it is possible to equally recognize sensors, devices, and systems directly connected to the smart node 13, sensors, devices, and systems connected via the spine node 12, and sensors, devices, and systems connected via the IoT cloud 15. Thus, in each site and each account, it is possible to equally operate the devices and continuously develop and edit the program.
[0172] In the above-described embodiment, the stickers SL, SM on which the two-dimensional codes CD, CE including the individual identification information, the inherent password are printed are attached to the device node 11. Thus, it is possible to efficiently input the individual identification information, the password of the device node 11. Login to the Co-innovation space is performed using the portable terminal 18 to read the two-dimensional code CD1, and the application of the portable terminal 18 performs the accommodation work of the device node 11. Thus, it is possible to efficiently perform the accommodation of the device node 11.
[0173] In the above-described embodiment, the device node 11 connected to the spine node 12 accumulates the individual identification information and the inherent password in the device pool area 32 of the spine node 12 in the initial state. The device node 11 connected to the smart node 13 accumulates the individual identification information and the inherent password in the device pool area not shown of the smart node 13 in the initial state. The device node 11 connected to the IoT cloud 15 accumulates the individual identification information and the inherent password in the device pool area 42 of the IoT cloud 15 in the initial state.
[0174] As described above, in the above-described embodiment, the device pool area is distinguished according to the place (network) to which the device node 11 is connected and the information (individual identification information and inherent password) of the device node 11 is accumulated, but the device pool area can be generalized. For example, if a cellular network is used, the cloud can be accessed from any place, and thus all the device nodes 11 can be connected to the IoT cloud 15 in the initial state, and the information of all the device nodes 11 can be accumulated in the device pool area 42 of the IoT cloud 15.
[0175] The above-described embodiment of the present application has been described in detail, but the present application is not limited to the above-described embodiment, and can be freely changed within the scope of the present application. For example, a part or all of the application development environment providing system 1 in the above-described embodiment can be implemented by a computer. In the case where a part or all of the application development environment providing system 1 is implemented by a computer, a program for implementing the function of a part or all of the application development environment providing system 1 can be recorded in a computer-readable recording medium, a computer system can read the program recorded in the recording medium and execute the program, and thus the implementation can be achieved.
[0176] The "computer system" referred to herein means a computer system built in the application development environment providing system 1 and includes an OS, peripheral instruments, and the like hardware. The "computer-readable recording medium" means a removable medium such as a floppy disk, an optical magnetic disk, a ROM, a CD-ROM, and the like, a storage device such as a hard disk built in a computer system.
[0177] The "computer-readable recording medium" can include a recording medium that stores a program for a short time and dynamically, such as a communication line in the case where the program is transmitted via a network such as the Internet, a telephone line, and the like, and a recording medium that stores a program for a certain time, such as a volatile memory inside a computer system that becomes a server or a client in this case. In addition, the above-described program can be used to implement a part of the above-described function, or can be implemented by further combining with a program that has recorded the above-described function in a computer system.
[0178] The application development environment providing system 1 in the above-described embodiments can be realized as an integrated circuit such as an LSI. Each functional block of the application development environment providing system 1 can be individually processorized, or a part or all of them can be integrated and processorized. The method of integrated circuitization is not limited to an LSI, and can be realized by a dedicated circuit or a general-purpose processor. In the case where a technology that replaces integrated circuitization of an LSI appears due to advancement of semiconductor technology, an integrated circuit obtained by the technology can be used.
[0179] In this specification, words that indicate directions such as front, rear, upper, lower, right, left, vertical, horizontal, bottom, lateral, row, and column refer to the above-described directions in the device of the present application. Therefore, these words in the specification of the present application should be interpreted relatively in the device of the present application.
[0180] The word "comprise" is used to indicate that a function is performed or a structure, an element, a part, or the like is used for the purpose of the present application.
[0181] In the claims, the word "means" for expressing the present application as "method plus function" means that a word that should include all configurations should be included for the purpose of being able to use for performing the function included in the present application.
[0182] The word "unit" is used to indicate a structural element, a unit, hardware, or a part of software that is programmed for the purpose of performing a desired function. Typical examples of hardware are devices and circuits, but are not limited thereto.
[0183] The above-described preferred embodiments of the present application have been described, but the present application is not limited to these embodiments. In a range not departing from the spirit of the present application, addition, omission, substitution, and other changes of the structure can be made. The present application is not limited by the description, but is limited only by the appended claims.
[0184] Explanation of Reference Signs
[0185] 1 Application development environment providing system
[0186] 11 Device node
[0187] 16 Terminal device
[0188] 32 Device pool area
[0189] 42 Device pool area
[0190] 55 Device management section
[0191] E1 Development component list display area
[0192] E2 Application design area
Claims
1. An application development environment providing system that provides a development environment of an application program via a network, in the application development environment providing system, The management unit determines the first information identified by the application program using the device node, and the second information related to the tenant who made the determination of the first information, and performs a management process of limiting or permitting the use of the device node identified by the first information determined by the first instruction based on a second instruction received after the first instruction, wherein the second indication is a second indication of the tenant who made the determination according to the first indication in relation to the second information, the first information includes individual identification information and an inherent password of the device node, a character string indicating the individual identification information and the inherent password of the device node is displayed on the device node together with the first information.
2. The application development environment providing system according to claim 1, wherein the management section, in a case where the first information is determined, searches a cumulative section where the first information of the device node connected to the network is accumulated, and in a case where the determined first information is searched, associates the first information and the second information.
3. The application development environment providing system according to claim 2, wherein the management section, in a case where authentication information corresponding to the first information exists, performs authentication processing using authentication information accumulated in the cumulative section and authentication information indicated by the tenant together with the first information.
4. The application development environment providing system according to any one of claims 1 to 3, wherein the management processing includes at least one of the following processing: first processing that allocates the device node to a specific site and account among sites and accounts of the tenant who made the determination of the first information; second processing that sets access rights to the device node for each of the site and the account; and third processing that restricts or permits use of the device node only to a specific application program.
5. The application development environment providing system according to any one of claims 1 to 3, wherein the device node on which the management processing is performed is displayed as a development component on an application development screen.
6. The application development environment providing system according to claim 5, wherein the application development screen has: a development component list display area that displays the device node on which the management processing is performed; and an application design area that can visually display a structure of the application program and create and edit the application program.
7. The application development environment providing system according to any one of claims 1 to 3, wherein a program development section that provides the application development environment to a user and visually displays the application program is further included.
8. The application development environment providing system according to claim 7, wherein the program development section visually displays the application program based on layout information, wiring information, parameter information, and selection area information, the layout information is information indicating a manner of processing of the application program, the wiring information is information related to a guide line that connects an input data item, a logic as a processing content, and an output data item as a processing result, the parameter information is information indicating a set value of a parameter set in the application program, and the selection area information is information indicating a selection area of the application program. The selection area information is information indicating a part of processing selected by a user in a series of processes of the application program.
9. The application development environment providing system according to any one of claims 1 to 3, wherein Further provided is a communication section that transmits and receives a part or all of the application program including the setting information.
10. The application development environment providing system according to claim 9, wherein The communication section provides at least one of a chat function, an audio communication function, a voice call function, a screen sharing function, and a community function.
11. The application development environment providing system according to claim 7, wherein Further provided is a library that provides a tool used when the application program is developed or executed in the program development section.
12. The application development environment providing system according to claim 11, wherein The library provides at least one of a waveform search tool, a regression analysis tool, a multi-regression analysis tool, an MT method analysis tool, an error dispersion analysis tool, a data-driven model tool, a deep learning tool, and a correlation analysis tool.
13. An application development environment providing method that provides a development environment of an application program via a network, In the application development environment providing method, Upon a first instruction by a tenant who utilizes the development environment, first information that identifies a device node utilized by the application program and that is obtained by capturing a two-dimensional code attached to the device node is determined, An association between the determined first information and second information related to the tenant who performed the determination of the first information is performed, based on a second indication received after the first indication, performing a management process of restricting or permitting use of the device node identified by the first information determined in accordance with the first indication, wherein The second instruction is a second instruction by the tenant who performed the determination according to the first instruction in relation to the second information, The first information includes individual identification information of the device node and an inherent password, A character string that indicates the individual identification information of the device node and the inherent password is displayed on the device node together with the first information.
14. The application development environment providing method according to claim 13, wherein The determined first information is searched for from an accumulation section that accumulates the first information of the device node connected to the network, Upon searching for the determined first information, the association between the first information and the second information is performed.
15. The application development environment providing method according to claim 13 or 14, wherein At least one of the following steps is included: allocating the device node to a specific site and account among sites and accounts of the tenant who performed the determination of the first information; setting access rights to the device node for each of the site and the account; and restricting or permitting utilization of the device node to only a specific application program.
16. A computer-readable nonvolatile storage medium that stores one or more programs executed by a computer, In the computer-readable nonvolatile storage medium, The one or more programs are a development environment of an application program is provided via a network, In a case where first information that identifies a device node used by the application program is determined by capturing a two-dimensional code attached to the device node in accordance with a first instruction by a tenant who uses the development environment, an association between the determined first information and second information related to the tenant who made the determination of the first information is performed, a management process of restricting or permitting use of the device node identified by the first information determined in accordance with the first instruction is performed based on a second instruction received after the first instruction, and The second indication is a second indication of the tenant related to the second information, which is determined according to the first indication, The first information includes individual identification information and an inherent password of the device node, A string representing the individual identification information and the inherent password of the device node is displayed on the device node together with the first information.
Citation Information
Patent Citations
Method of producing electric circuit in printed board
JP1982092891A
Cloud computing for industrial automation and production systems
JP2012523038A
A computing platform for development and deployment of sensor data based applications and services
CN103891201A
Sensor share control device, method, and computer program
CN104685512A
Development-environment system, development-environment device, and development-environment provision method and program
CN105324750A