Portable information terminal and control method thereof
By implementing an application-exclusive locking function and user authentication, the problem of functional restrictions on portable information terminals when used by others is solved, protecting personal information and property security while maintaining ease of operation.
Patent Information
- Application Number
- CN201880063547.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2018-02-26
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2038-02-26
AI Technical Summary
When existing portable information terminals are given to others for use, it is impossible to effectively restrict operations other than specific applications, leading to the leakage of personal information and financial losses. Moreover, existing technologies cannot achieve the ideal ease of use.
Employing an application-exclusive lockout feature, this feature allows or restricts access to specific applications through user authentication. Combining facial recognition and PIN input ensures that only authorized users can unlock and operate the designated applications.
It restricts the functionality of portable information terminals, protecting personal information and property security while maintaining ease of use for registered users.
Smart Images

Figure CN111149102B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a portable information terminal and a control method thereof. BACKGROUND
[0002] A portable information terminal such as a smartphone or a tablet terminal has been popularized. The portable information terminal is capable of storing a large amount of personal information and also has a function of money transaction, various settlement processing, and the like. Therefore, in a case where the portable information terminal is used by a third person without authorization, a loss of personal information leakage, a loss of money, and the like can occur.
[0003] In order to prevent the loss, the portable information terminal has a terminal lock function of restricting a terminal function, and generally, the restriction of the terminal function is temporarily released after an authentication of an authorized user is performed at the time of power ON, at the time of recovery from a sleep state, and the like so that an operation can be performed. In addition, there is a technology as described in the following Patent Literature 1 in which even after an authentication of the authorized user is performed by a fingerprint authentication process and the computer is logged in, the authentication of the authorized user is repeatedly performed by a periodic face authentication process, and in a case where the comparison is not consistent, the computer is automatically logged out, thereby restricting an operation performed by a person other than the authorized user to improve security.
[0004] PRIOR ART DOCUMENT
[0005] PATENT LITERATURE
[0006] Patent Literature 1: Japanese Patent Application Publication No. 2011-13855 SUMMARY
[0007] A portable information terminal such as a smartphone or a tablet terminal has a camera function, and an image captured using the camera function is recorded to a storage device portion of the portable information terminal. In a case where an authorized user of the portable information terminal wants to share a view of the image recorded to the storage device portion with a friend or the like, the portable information terminal is sometimes handed over to the friend or the like in a state where an application for image viewing is started so that the friend or the like operates the application for image viewing.
[0008] In this case, the official user of the portable information terminal desires to allow the operation of the image viewing application program to friends and the like, but does not desire to allow other operations. That is, it is desirable that the portable information terminal has a designated application (APP) lock function in addition to the terminal lock function, and controls the portable information terminal in such a manner that the official user selects a predetermined application program (the image viewing application program in the above example) to be allowed to operate for all operators by the designated APP lock function, but restricts other operations except when the official user is the operator. However, in the patent document 1, there is no description of a control such as allowing a part of the terminal functions to operate regardless of the operator and restricting other operations of the terminal functions according to the operator.
[0009] Further, there is a portable information terminal having an access guide function that restricts operations other than one application program displayed on a screen. In the portable information terminal having the access guide function, it is possible to restrict operations other than the image viewing application program by using the access guide function in a state where the image viewing application program is started. However, in the state where the access guide function is used, not only friends and the like but also the official user of the portable information terminal is restricted from other operations. In order to perform other operations, the operator, even if the official user of the portable information terminal, needs to end the use of the access guide function through an authentication process, and if the use of the access guide function is ended, even a person other than the official user of the portable information terminal can perform other operations and the like, and thus desired use convenience cannot be achieved.
[0010] An object of the present application is to provide a portable information terminal and a control method thereof that can restrict terminal functions according to an operator.
[0011] As a means for solving the problem, the technology recited in the claims is used.
[0012] If one example is given, a control method of a portable information terminal is adopted, characterized by receiving an operation for restricting operations of an application program of the portable information terminal by a user other than an official user of the portable information terminal, authenticating whether the official user of the portable information terminal, and allowing the operation of the application program of the portable information terminal in a case where the official user is authenticated, and restricting the operation of the application program of the portable information terminal in a case where the official user is not authenticated.
[0013] According to the present application, it is possible to provide a portable information terminal and a control method thereof that can restrict terminal functions according to an operator. BRIEF DESCRIPTION OF DRAWINGS
[0014] Figure 1A is a hardware configuration diagram of the portable information terminal of Example 1.
[0015] Figure 1B is an appearance diagram of the portable information terminal of Example 1.
[0016] Figure 1C is a software configuration diagram of the portable information terminal of Example 1.
[0017] Figure 2A is an action state transition diagram of the portable information terminal of Example 1.
[0018] Figure 2B is a flowchart of the terminal lock function temporary release processing of the portable information terminal of Example 1.
[0019] Figure 2C is a screen display diagram of a PIN input screen at the time of the user authentication processing of Example 1.
[0020] Figure 2D is a screen display diagram of a main screen in a normal action state of Example 1.
[0021] Figure 3A is a flowchart of the specified application outside lock function of the portable information terminal of Example 1.
[0022] Figure 3B is a screen display diagram of an image viewing application execution screen of Example 1.
[0023] Figure 3C is an operation concept diagram explaining the range of the operation instruction for the specified application of Example 1.
[0024] Figure 3D is a flowchart of the specified application outside lock function of the portable information terminal of Example 1.
[0025] Figure 4 is an appearance diagram of the HMD type portable information terminal of Example 1.
[0026] Figure 5 is a flowchart of the specified application outside lock function of the portable information terminal of Example 2.
[0027] Figure 6 is a flowchart of the specified application outside lock function of the portable information terminal of Example 3.
[0028] Figure 7 is a flowchart of the specified application outside lock function of the portable information terminal of Example 4.
[0029] (Symbol Explanation)
[0030] 100: portable information terminal; 101: main control section; 102: system bus; 103: ROM; 104: RAM; 110: storage device section; 120: operation input section; 121: operation key; 122: touch sensor; 123: touch panel; 130: image processing section; 131: display section; 132: image signal processing section; 133: first image input section; 134: second image input section; 140: sound processing section; 150: sensor section; 160: communication section; 170: expansion interface section; 180: touch screen; 1101: basic operation function section; 1102: lock control function section; 1102T: terminal lock function section; 1102A: designated application outside lock function section; 1103: user authentication function section; 1103P: PIN input processing section; 1103F: face authentication processing section; 1103H: fingerprint authentication processing section. DETAILED DESCRIPTION
[0031] Hereinafter, an example of the embodiment will be described with reference to the drawings.
[0032] Embodiment 1
[0033] The portable information terminal 100 of this embodiment has a designated application outside lock function in which, with respect to the operation of a predetermined application program selected by an official user, all operators are allowed, but with respect to other operations, appropriate restrictions are made except when the official user is the operator. The portable information terminal 100 can be a portable telephone, a smartphone, a tablet terminal, or the like. It can also be a PDA (Personal Digital Assistants), a notebook PC (Personal Computer), an electronic book reader, or the like. In addition, it can be a still camera, a video camera capable of taking moving pictures, a portable game machine, or the like, or other digital devices.
[0034] [Hardware structure example of portable information terminal]
[0035] Figure 1A is a hardware structure diagram showing one example of the internal structure of the portable information terminal 100. The portable information terminal 100 includes a main control section 101, a system bus 102, a ROM 103, a RAM 104, a storage device section 110, an operation input section 120, an image processing section 130, a sound processing section 140, a sensor section 150, a communication section 160, and an expansion interface section 170.
[0036] The main control section 101 is a microprocessor unit that controls the entire portable information terminal 100 in accordance with a predetermined operation program. The system bus 102 is a data communication path for transmitting and receiving various commands and data between the main control section 101 and each operation block in the portable information terminal 100.
[0037] The ROM (Read Only Memory) 103 is a memory that stores basic action programs such as an operating system, other action programs (application programs, the same hereinafter), and the like, and is, for example, a rewritable ROM such as an EEPROM (Electrically Erasable Programmable ROM), a flash ROM. The RAM (Random Access Memory) 104 is a work area at the time of execution of the basic action programs, the other action programs. The ROM 103 and the RAM 104 can also be integrally constituted with the main control section 101. In addition, the ROM 103 can also not be a separate structure as shown, but can use a part of the storage area in the storage device section 110. Figure 1A
[0038] The storage device section 110 stores action programs, action setting values, personal information of the official user of the portable information terminal 100, authentication information, and the like of the portable information terminal 100. In addition, it is possible to store action programs downloaded from a network, various data made with the action programs, and the like. In addition, it is possible to store contents such as animation, still images, sounds, and the like downloaded from a network. In addition, it is possible to store animation, still images, and the like taken using a camera function. It is also possible to use a part of the area of the storage device section 110 instead of all or a part of the function of the ROM 103. In addition, the storage device section 110 needs to retain stored information even in a state where the portable information terminal 100 is not supplied with power from the outside. Therefore, for example, a semiconductor element memory such as a flash ROM, an SSD (Solid State Drive), a magnetic disk drive such as an HDD (Hard Disc Drive), and the like are used.
[0039] In addition, the respective action programs stored in the ROM 103, the storage device section 110 can be updated and functionally extended by a download process from each server device on a network.
[0040] The operation input unit 120 is an instruction input unit for inputting operation instructions for the portable information terminal 100. The operation input unit 120 includes operation keys 121 arranged with push-button switches, a touch sensor 122 that detects the operator's finger touch based on changes in electrostatic capacitance, and a touch panel 123 superimposed on the display unit 131. Other operating devices may also be included. The portable information terminal 100 can also be operated using a keyboard or the like connected to the expansion interface unit 170. The portable information terminal 100 can also be operated using a separate portable terminal device connected via wired or wireless communication. Furthermore, the touch sensor 122 has the function of detecting fingerprints or palm prints of the fingers touching the sensor unit.
[0041] The image processing unit 130 includes a display unit 131, an image signal processing unit 132, a first image input unit 133, and a second image input unit 134. The display unit 131 is, for example, a display device such as a liquid crystal panel, providing the user of the portable information terminal 100 with image data processed by the image signal processing unit 132. The image signal processing unit 132 includes a video RAM (not shown). The display unit 131 is driven based on the image data input to the video RAM. Furthermore, the image signal processing unit 132 has functions such as decoding encoded image signals, format conversion processing, menu processing, and overlay processing of other OSD (On Screen Display) signals as needed. The first image input unit 133 and the second image input unit 134 are camera units that input image data of surrounding objects by converting light input from a lens into electrical signals using electronic devices such as CCD (Charge Coupled Device) and CMOS (Complementary Metal Oxide Semiconductor) sensors.
[0042] The sound processing unit 140 includes a sound output unit 141, a sound signal processing unit 144, and a sound input unit 145. The sound output unit 141 is a speaker that provides the sound signal processed by the sound signal processing unit 144 to the operator of the portable information terminal 100. Specifically, the mono speaker 142 outputs mono sound during voice calls, etc., and the stereo speaker 143 outputs stereo sound during music playback, etc. The sound signal processing unit 144 has functions such as decoding encoded sound signals as needed. The sound input unit 145 is a microphone that converts the operator's voice, etc., into sound data for input.
[0043] The sensor unit 150 is a group of sensors used to detect the status of the portable information terminal 100. The sensor unit 150 includes a GPS (Global Positioning System) receiver 151, a gyroscope sensor 152, a geomagnetic sensor 153, an accelerometer 154, an illuminance sensor 155, and a proximity sensor 156. Through this group of sensors, the position, tilt, angle, movement, ambient brightness, and proximity of surrounding objects of the portable information terminal 100 can be detected. Additionally, the portable information terminal 100 may also include other sensors such as a barometric pressure sensor.
[0044] The communication unit 160 includes a LAN (Local Area Network) communication unit 161, a telephone network communication unit 162, and an NFC (Near Field Communication) unit 163. The LAN communication unit 161 connects to a network such as the Internet via an access point, and transmits and receives data with various server devices on the network. The connection to the access point can also be made wirelessly using Wi-Fi or other wireless connections. The telephone network communication unit 162 performs telephone communication (calls) and transmits and receives data via wireless communication with base stations of mobile phone communication networks. Communication with the base stations can also be made using W-CDMA (Wideband Code Division Multiple Access) or LTE (Long Term Evolution) methods. The NFC unit 163 performs wireless communication when it is near a corresponding reader / writer. Each of the LAN communication unit 161, the telephone network communication unit 162, and the NFC unit 163 includes an encoding circuit, a decoding circuit, and an antenna. In addition, the communication processing unit 160 may also include other communication units such as Bluetooth (a registered trademark in Japan) communication unit and infrared communication unit.
[0045] The expansion interface section 170 is a group of interfaces used to expand the functionality of the portable information terminal 100. The expansion interface section 170 includes an image / audio interface, a USB (Universal Serial Bus) interface, a memory interface, etc. The image / audio interface handles input of external images / image signals / audio signals from audio output devices, and output of external images / image signals / audio signals to audio input devices. The USB interface connects to a PC or similar device for data transmission and reception. It can also connect to a keyboard or other USB devices. Additionally, it can be used when charging the built-in battery (not shown). The memory interface connects to a memory card or other memory media for data transmission and reception.
[0046] also, Figure 1A The illustrated portable information terminal 100 includes many structures that are not essential in this embodiment, but the absence of these structures will not impair the effectiveness of this embodiment. Furthermore, structures not shown, such as digital broadcast receiving functionality and electronic currency settlement functionality, can be added.
[0047] [Example of the appearance of a portable information terminal]
[0048] Figure 1B This is an example of the appearance of the portable information terminal 100. Furthermore, this figure illustrates examples of a front view (front view) and a rear view (back view) of the portable information terminal 100 when it is a smartphone or the like; the left and right sides, top and bottom, etc., are omitted from the illustration.
[0049] The front surface of the portable information terminal 100 includes an action indicator 124, a first image input unit 133, a mono speaker 142, and a touch screen 180. The action indicator 124 reports the operating status of the portable information terminal 100 based on the presence or absence of an LED (Light Emitting Diode). The touch screen 180 includes a touch panel 123 and a display unit 131.
[0050] On the back of the portable information terminal 100, there is a touch sensor 122, a second image input unit 134, an auxiliary light emitter 135, and a stereo speaker 143. The auxiliary light emitter 135 can emit auxiliary light to compensate for insufficient light when an image is input from the second image input unit 134.
[0051] The upper surface of the portable information terminal 100 has a power button 121p, which is one of the operation keys 121. The lower surface of the portable information terminal 100 has a voice input unit 145 and a μ-USB input unit 170u, which is one of the expansion interface units 170.
[0052] Furthermore, as shown in the figure, the first image input unit 133 is disposed on the front surface, and the second image input unit 134 is disposed on the back surface, which is a different surface from the first image input unit 133. Hereinafter, the first image input unit 133 is sometimes referred to as the "in-camera," and the second image input unit 134 is sometimes referred to as the "out-camera." Additionally, the touch sensor 122 may not be disposed on the back of the portable information terminal 100, but rather on the side, the lower part of the front surface (the part that does not overlap with the touch screen 180), etc. Furthermore, the touch panel 123 constituting the touch screen 180 may also function as the touch sensor 122. In this case, the function of the touch sensor 122 (e.g., fingerprint authentication function) can be performed at any location on the touch screen 180.
[0053] [Example of software architecture for portable information terminals]
[0054] Figure 1C This is a software structure diagram of the portable information terminal 100, showing an example of the software structure in the storage device unit 110 (or ROM 103, hereinafter the same) and RAM 104. The storage device unit 110 stores a basic operation program 1001, a lock control program 1002, a user authentication program 1003, and other operation programs 1009. In addition, the storage device unit 110 has an authentication information storage area 1011 for storing authentication information of the registered users of the portable information terminal 100, and various information storage areas 1019 for storing other information.
[0055] The basic operation program 1001 stored in the storage device unit 110 is expanded in the RAM 104, and then the main control unit 101 executes the expanded basic operation program to form the basic operation function unit 1101. Similarly, the lock control program 1002, the user authentication program 1003, and other operation programs 1009 are expanded in the RAM 104, and then the main control unit 101 executes each of the expanded operation programs to form the lock control function unit 1102, the user authentication function unit 1103, and other operation function units 1109. In addition, the RAM 104 has a temporary storage area 1200 for temporarily storing data created during the execution of each operation program as needed.
[0056] Furthermore, for the sake of simplicity, the following description will focus on the process by which the main control unit 101 expands and executes the basic operation program 1001 stored in the storage device unit 110 in the RAM 104 to control each operation block, and the basic operation function unit 1101 controls each operation block. Other operation programs will be described in the same way.
[0057] The lock control function unit 1102 has two lock control functions. The first is a terminal lock function, which controls the operation state of the portable information terminal 100 to either a terminal lock state where the operation of various functions of the portable information terminal 100 is restricted in batches, or a terminal unlock state where the operation of various functions of the portable information terminal 100 is appropriately permitted. The terminal lock state refers to a state in which operation instructions such as turning the power on / off of the portable information terminal 100, turning the sleep mode on / off, and user authentication processing for unlocking the terminal lock state are accepted, but other operation instructions are not accepted. However, functions automatically performed by the terminal system, such as searching for access points, base stations, etc., and checking emails, can be appropriately permitted. The second is a designated application lock function, which, in the terminal unlock state, performs lock control on each function of the portable information terminal 100, so that operation on a predetermined application selected by the registered user is permitted for all operators, but other operations are appropriately restricted when the registered user is not the operator.
[0058] The user authentication function unit 1103 mainly controls the user authentication process to confirm whether the operator of the portable information terminal 100 is a legitimate user. User authentication methods include PIN (Personal Identification Number) input, password input, pattern input, facial recognition, iris recognition, fingerprint recognition, palm print recognition, voiceprint recognition, etc., or any other method can be used. Furthermore, in this embodiment, when controlling the terminal locking function unit 1102T, PIN input is used as the user authentication method; when controlling the designated application lock function unit 1102A, facial recognition and fingerprint recognition are used.
[0059] Furthermore, the aforementioned operation programs may be pre-stored in the storage device unit 110 and / or ROM 103 at the time the product is manufactured. They may also be obtained from various server devices on the network via LAN communication unit 161 or telephone network communication unit 162 after the product is manufactured. Additionally, the aforementioned operation programs stored on memory cards, optical discs, etc., may be obtained via expansion interface unit 170, etc.
[0060] [Example of action state transition in a portable information terminal]
[0061] Figure 2A This is an example of an operation state transition diagram illustrating the transition of the operation state of a portable information terminal 100. The operation state transition shown in this diagram mainly involves the terminal locking function controlled by the terminal locking function unit 1102T.
[0062] The portable information terminal 100 can set (enable) / deactivate (disable) the terminal lock function according to operation instructions such as those for the function menu. That is, according to the operation instructions for setting / deactivating the terminal lock function, the portable information terminal 100 can switch between a normal operation state T100 when the terminal lock function is deactivated and a normal operation state T110 when the terminal lock function is enabled. At this time, user authentication processing can also be requested.
[0063] Furthermore, when the terminal lock function is disabled, if the portable information terminal 100 in normal operation state T100 remains inactive for a predetermined period of time or if the operator instructs it to transition to sleep state, it transitions to sleep state T101. Additionally, if the operator instructs the power to be OFF in normal operation state T100 or sleep state T101, the portable information terminal 100 transitions to power OFF state T102. If the operator instructs the user to release from sleep state T101 or in power OFF state T102, the portable information terminal 100 transitions to normal operation state T100.
[0064] On the other hand, when the terminal lock function is enabled, if the portable information terminal 100 in normal operation state T110 remains inactive for a predetermined period of time or if the operator instructs it to transition to sleep state, it transitions to sleep state T111. Additionally, if the operator instructs the power to be OFF in normal operation state T110 or sleep state T111, the portable information terminal 100 transitions to power OFF state T112. If the operator instructs the user to deactivate sleep state in sleep state T111 or in power OFF state T112, the portable information terminal 100 performs user authentication processing (T113). If the user authentication is successful in user authentication processing (T113), the portable information terminal 100 temporarily unlocks the terminal lock function and transitions to normal operation state T110. In other words, normal operation state T110 is an operation state where the terminal lock function is enabled and temporarily unlocked. Additionally, if the operator's authentication fails during the user authentication process (T113), the portable information terminal 100 transitions to a sleep state T111. Alternatively, the user authentication process (T113) may be repeated.
[0065] Furthermore, in this embodiment, the control of the specified application external locking function is effective in the normal operating state T110. It is also possible to specify that the control of the specified application external locking function is effective in the normal operating state T100 as well. Details of the operation of the specified application external locking function will be described later.
[0066] Figure 2B This is a flowchart of an example of a temporary unlocking process for a terminal lockout function based on user authentication processing (T113).
[0067] When the operator gives an instruction to unlock from sleep state T111 or when the operator gives an instruction to turn on power in power OFF state T112, the terminal lock function unit 1102T requests the activation of the PIN input processing unit 1103P of the user authentication function unit 1103, and the basic operation function unit 1101 activates the PIN input processing unit 1103P.
[0068] Next, the PIN input processing unit 1103P displays the PIN input screen 180a on the touchscreen 180 (display unit 131) (S101). Next, the PIN input processing unit 1103P checks whether an operator has entered a PIN into the touchscreen 180 (touch panel 123) via touch (S102). If no PIN input is entered into the touchscreen 180, or if the touch operation is confirmed not to be a PIN input (S102: "No"), the PIN input processing unit 1103P repeatedly performs the S102 process. If the PIN input processing unit 1103P confirms that the touch operation is a PIN input cancellation instruction (S102: Cancel), authentication fails and transitions to sleep state T111 (S108). If there is a touch operation on the touchscreen 180 and the touch operation is confirmed to be a PIN input (S102: "Yes"), the PIN input processing unit 1103 proceeds to the S103 process. Next, the PIN input processing unit 1103P compares the PIN information entered in the processing of S102 with the authentication information that the official user has preset and stored in the authentication information storage area 1011, and sends the result to the terminal locking function unit 1102T of the locking control function unit 1102 (S103).
[0069] The terminal locking function unit 1102T determines, based on the comparison result sent, whether the PIN information entered during the processing in S102 matches the authentication information preset by the registered user and stored in the authentication information storage area 1011. If the two match (S104: "Yes"), authentication is successful and the terminal locking function of the portable information terminal 100 is temporarily released (S105), transitioning to the normal operation state T110 (S106), and the main screen 180b is displayed on the touch screen 180 (S107). On the other hand, if the terminal locking function unit 1102T determines that the PIN information entered during the processing in S102 does not match the authentication information preset by the registered user and stored in the authentication information storage area 1011 (S104: "No"), authentication fails and transitions to the sleep state T111 (S108). In addition, in the event of authentication failure, the process can be changed to power-off state T112 instead of the process of changing the operation state of the portable information terminal 100 to sleep state T111, or it can return to the process of S101.
[0070] Figure 2C Is Figure 2B The flowchart shown is an example of a PIN input screen display.
[0071] The PIN input screen 180a includes a numeric keypad area 180a1, an input result display area 180a2, and a other information display area 180a3. The numeric keypad area 180a1 is the valid area for touch operations during PIN input. The input result display area 180a2 displays the result of the operator's touch operation on the numeric keypad area 180a1. When the operator performs a touch operation on the numeric keypad area 180a1, characters such as "·" and "*" are displayed to indicate that the portable information terminal 100 has received the operator's operation instruction. The other information display area 180a3 displays general information such as time and weather information.
[0072] Figure 2D Is Figure 2B The flowchart shown is an example of a main screen display during the processing.
[0073] The main screen 180b includes a main function icon display area 180b1, a general icon display area 180b2, a other information display area 180b3, and a control key area 180b4. The main function icon display area 180b1 displays icons associated with the main applications frequently used in the portable information terminal 100. The general icon display area 180b2 displays icons associated with other applications. The other information display area 180b3 displays general information such as time and weather information. The control key area 180b4 displays the "back key," "main screen key," and "application history key."
[0074] [Example of action control for specifying application-external locking function]
[0075] The following example illustrates the action control processing of the designated application lock function, using a scenario where a regular user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other user to share and view images captured by the camera in various information storage areas 1019 of the storage device unit 110, while an image viewing application is selected and launched. Furthermore, the application selected by the regular user is not limited to the image viewing application.
[0076] Figure 3A This is a flowchart illustrating an example of the motion control processing for a specified application external locking function. The processing shown in the flowchart primarily involves the specified application external locking function controlled by the specified application external locking function unit 1102A. Furthermore, the control of the specified application external locking function unit 1102A can also be performed independently of the control of the terminal locking function unit 1102T described above.
[0077] When using an image viewing application in the portable information terminal 100 during normal operation (T110), the operator operates the touchscreen 180, which displays the main screen 180b, to instruct the launch of the image viewing application (S201). This can be done by tapping an icon associated with the image viewing application displayed in the main function icon display area 180b1 or the general icon display area 180b2. Then, the basic operation function unit 1101, according to the operator's instruction, launches the image viewing application function unit (without illustrations) of the other operation function units 1109. The image viewing application function unit displays the image viewing application execution screen 180c on the touchscreen 180. Figure 3B (S202).
[0078] Next, while the image viewing application execution screen 180c is displayed on the touchscreen 180, the operator instructs the designated application external locking function control to start (S203). Then, the basic operation function unit 1101, according to the operator's instruction, activates the designated application external locking function unit 1102A of the locking function control unit 1102 (S204). The designated application external locking function unit 1102A, according to the operator's instruction, stores (registers) the running application (in this embodiment, the image viewing application) as a designated application that can be operated by both the registered user and other users besides the registered user (S205), and then requests the activation of the internal camera 133 and the activation of the face authentication processing unit 1103F. Hereinafter, the description assumes that the running application is registered as a designated application, but it is also possible to identify and register the user from an application other than the running application specified by the operation input unit 120 as a designated application. The basic operation function unit 1101, according to the request, activates the internal camera 133 and activates the face authentication processing unit 1103F (S206). The facial authentication processing unit 1103F begins facial authentication processing based on the image acquired by the internal camera 133.
[0079] Furthermore, the instruction to start the application lock function control can be initiated by double-clicking or triple-clicking the "Home Screen Key" while the image viewing application execution screen 180c is displayed on the touchscreen 180. Other possible actions include simultaneously touching the "Home Screen Key" and the "Back Key," lightly tapping the "Home Screen Key" while the finger is in contact with the touch sensor 122, or double-clicking the execution screen of the running application (in this embodiment, the image viewing application) while the finger is in contact with the touch sensor 122. Other predetermined operations are also possible.
[0080] In addition, to prevent an operator other than the official user of the portable information terminal 100 from instructing the start of the designated application lock function control, the process in S203 can also confirm whether the operator is the official user of the portable information terminal 100 (authentication process).
[0081] Next, the basic operation function unit 1101 checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If the basic operation function unit 1101 confirms that no operation instruction has been input to the touch screen 180 (S207: "No"), it repeats the process of S207. On the other hand, if the basic operation function unit 1101 confirms that an operation instruction has been input to the touch screen 180 (S207: "Yes"), it checks whether the operation instruction specifies the end of the application lock function control (S208). If the basic operation function unit 1101 confirms that the operation instruction input in the process of S207 is a specified instruction to end the application lock function control (S208: "Yes"), it proceeds to the process of S212. In addition, if the basic operation function unit 1101 confirms that the operation instruction input in the process of S207 is not a specified instruction to end the application lock function control (S208: "No"), it proceeds to the process of S209.
[0082] Furthermore, the indication that the specified application lock function control has ended can be obtained by double-clicking or triple-clicking the "Home Screen Key" while the specified application lock function control is in effect. Other possible actions include simultaneously touching the "Home Screen Key" and the "Back Key," lightly tapping the "Home Screen Key" while the finger is in contact with the touch sensor 122, or double-clicking the execution screen of the running application (in this embodiment, an image viewing application) while the finger is in contact with the touch sensor 122. Other predetermined operations are also possible.
[0083] In the process of S209, the designated application lock function unit 1102A confirms whether the operation instruction input in the process of S207 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the process of S205, or an operation instruction targeting something other than the designated application (S209). If the designated application lock function unit 1102A confirms that the operation instruction input in the process of S207 is an operation instruction targeting the designated application (S209: Designated Application), the image viewing application function unit returns to the process of S207 after executing each process based on the operation instruction (S211). On the other hand, if the designated application lock function unit 1102A confirms that the operation instruction input in the process of S207 is an operation instruction targeting something other than the designated application (S209: Other than Designated Application), then confirms whether the operator is a formal user of the portable information terminal 100 (S210). If the designated application lockout function unit 1102A confirms in the S210 process that the operator is a registered user of the portable information terminal 100 (S210: "Yes"), after each application function unit of the other action function unit 1109 executes the respective processes based on the operation instructions entered in the S207 process (S211), it returns to the S207 process. Conversely, if the designated application lockout function unit 1102A does not confirm that the operator is a registered user of the portable information terminal 100 (S210: "No"), it does not execute the operation instructions entered in the S207 process and returns to the S207 process.
[0084] In this embodiment, the confirmation of whether the operator is a legitimate user of the portable information terminal 100 during the S210 process is performed using a facial authentication method controlled by the facial authentication processing unit 1103F. Specifically, the facial authentication processing unit 1103F analyzes the image acquired from the internal camera 133 and extracts the operator's facial image. This extracted facial image is compared with facial images of legitimate users pre-stored in the authentication information storage area 1011. If the comparison result has a consistency value higher than a predetermined value, the operator is considered a legitimate user of the portable information terminal 100. Furthermore, the S210 process can be executed whenever an operator's operation instruction input is received during the specified application lockout function control period, or it can be executed continuously, or it can be repeatedly executed at predetermined intervals. Additionally, the facial images of legitimate users pre-stored in the authentication information storage area 1011 can be a number corresponding to multiple individuals. In this case, there are multiple legitimate users of the portable information terminal 100.
[0085] In the S212 process, the designated application lockout function unit 1102A requests the activation of the PIN input processing unit 1103P to confirm whether the instruction to end the designated application lockout function control entered in the S207 process was issued by a legitimate user of the portable information terminal 100. Then, the basic operation function unit 1101 activates the PIN input processing unit 1103P of the user authentication function unit 1103.
[0086] Next, the PIN input processing unit 1103P displays the PIN input screen 180a on the touchscreen 180 (display unit 131) (S212). Next, the PIN input processing unit 1103P checks whether an operator has entered a PIN into the touchscreen 180 (touch panel 123) via touch (S213). If the PIN input processing unit 1103P confirms that no PIN has been entered into the touchscreen 180 or that the touch operation is not a PIN entry (S213: "No"), the process in S213 is repeated. If the PIN input processing unit 1103P confirms that the touch operation is a cancellation instruction for PIN entry (S213: Cancel), authentication fails and the process returns to S207. In this case, the application-external lock function control does not end. If the PIN input processing unit 1103P confirms that there has been a touch operation into the touchscreen 180 and that the touch operation is a PIN entry (S213: "Yes"), the process proceeds to S214. Next, the PIN input processing unit 1103P compares the PIN information entered in the processing of S213 with the authentication information preset by the official user and stored in the authentication information storage area 1011, and sends the result to the designated application-external locking function unit 1102A (S214).
[0087] The designated application-external locking function unit 1102A determines, based on the comparison result sent, whether the PIN information entered in the S213 process matches the authentication information preset by the official user and stored in the authentication information storage area 1011. If the two are determined to be inconsistent (S215: "No"), authentication fails and returns to the S207 process. In this case, the designated application-external locking function control does not end. If the designated application-external locking function unit 1102A determines that the PIN information entered in the S213 process matches the authentication information preset by the official user and stored in the authentication information storage area 1011 (S215: "Yes"), authentication succeeds and requests the invalidation of the internal camera 133 and the termination of the operation of the face authentication processing unit 1103F. The basic operation function unit 1101, based on the request, invalidates the internal camera 133 and terminates the operation of the face authentication processing unit 1103F (S216). Then, the designated application external locking function unit 1102A releases the storage of the designated application in the process of S205 (S217) and ends the operation of the designated application external locking function control (S218).
[0088] Figure 3B Is Figure 3A The flowchart shown is an example of an application execution screen display for viewing images during the processing.
[0089] The image viewing application execution screen 180c includes an image viewing area 180c1, a report area 180c2, and a control key area 180c3. The image viewing area 180c1 is the main screen of the image viewing application execution screen 180c. It displays thumbnails of multiple images, a zoomed-in screen for selected images, etc. The report area 180c2 reports radio wave intensity, time, remaining battery level, and other information. The control key area 180c3 displays the "Back" button, "Home" button, and "Application History" button.
[0090] [Operation instructions targeting a specified application and operation instructions targeting other applications]
[0091] exist Figure 3A In the processes S209 to S211 of the flowchart shown, the processing flow differs depending on whether the operation instruction input in process S207 is an operation instruction targeting a specified application or an operation instruction targeting something other than the specified application. Specifically, if the operation instruction input in process S207 is an operation instruction targeting a specified application, process S210 is not executed; if the operation instruction input in process S207 is an operation instruction targeting something other than the specified application, process S210 is executed.
[0092] Figure 3CThis is an operation concept diagram illustrating which operation instructions for the portable information terminal 100 are for a specific application and which are for applications other than the specified application. In this diagram, the upper left image is a thumbnail display screen, an example of an image viewing application's execution screen. The upper right image is a selection image display screen, an example of an image viewing application's execution screen. The lower left image is the main screen. The lower right image is an email creation screen, an example of an email application's execution screen.
[0093] Consider a scenario where the specified application's external locking function control is initiated while displaying a thumbnail screen of an image viewing application. In this case, the image viewing application is saved as the specified application.
[0094] First, all operation instructions within the image viewing application, which is the designated application, are of course operation instructions targeting the designated application. For example, these include operations such as selecting / zooming in on an image in the thumbnail view of the image viewing application to display the selected image screen, returning from the selected image screen to the thumbnail view, and changing the sorting order in the thumbnail view. Additionally, tapping the "Home Screen Key" to display the home screen from the state of the thumbnail view or the selected image screen, and tapping the "Application History Key" to display the application history (illustrated but not shown) are also operation instructions targeting the designated application. Furthermore, tapping icons to restart the image viewing application from the home screen or application history is also an operation instruction targeting the designated application.
[0095] On the other hand, the icon tap operation for launching the email application (and other applications) from the home screen or application history screen as an application other than the specified application is an operation instruction for applications other than the specified application.
[0096] That is, in Figure 3C In the diagram, operation instructions performed within the dashed line are operation instructions targeting a specified application, while operation instructions performed beyond the dashed line and those performed outside the dashed line are operation instructions targeting an application other than the specified application.
[0097] [Variation Example 1]
[0098] The confirmation process for the official user performed in S210 is not limited to the facial authentication method described above. For example, it could also be fingerprint authentication. In this case, in the S206 process, instead of activating the internal camera 133 and starting the facial authentication processing unit 1103F, the basic operation function unit 1101 can simply activate the touch sensor 122 and start the fingerprint authentication processing unit 1103H. Furthermore, in the S210 process, the fingerprint authentication processing unit 1103H detects the fingerprint data of the operator's finger touching the touch sensor 122, compares the detected fingerprint data with the fingerprint data of the official user pre-stored in the authentication information storage area 1011, and if the comparison result has a consistency value of more than a predetermined value, then the operator is considered an official user of the portable information terminal 100, and control can be performed in this manner. Additionally, in this case, in the S216 process, the touch sensor 122 can be deactivated and the operation of the fingerprint authentication processing unit 1103H can be terminated according to the instruction to end the control of the specified application lock function.
[0099] In addition, the formal user confirmation process in S210 can also be performed using different authentication methods such as iris authentication or palmprint authentication.
[0100] Furthermore, the confirmation process for formal users performed in S212 to S215 is not limited to the PIN input method mentioned above. For example, it can also be different authentication methods such as password input, pattern input, facial recognition, iris recognition, fingerprint recognition, palm print recognition, and voiceprint recognition.
[0101] Furthermore, the confirmation process for formal users performed in S212-S215 can be combined with... Figure 2A User authentication processing (T113) can be a common authentication process or different authentication processes. Different authentication information can also be used for a common authentication process.
[0102] [Variation Example 2]
[0103] Figure 3D This is a flowchart illustrating an example of the motion control process for a designated application lockout function. However, in this example, no application is stored (registered) as a designated application. In this case, to restrict operations on applications of the portable information terminal 100 performed by users other than the official user of the portable information terminal 100 while the main screen 180b is displayed on the touchscreen 180, the operator only needs to instruct the designated application lockout function control to begin. With this instruction, all applications of the portable information terminal 100 are recognized by the portable information terminal 100 as applications other than the designated application.
[0104] WillFigure 3D Flowcharts and Figure 3A A comparison reveals that processes S201, S202, S205, S209, and S217 are not executed. Specifically, the designated application-external locking function unit 1102A processes all operation instructions input in process S207 that are operation instructions targeting applications other than the designated application, and performs confirmation (S210) as to whether the operator is a legitimate user of the portable information terminal 100. If the designated application-external locking function unit 1102A confirms in process S210 that the operator is a legitimate user of the portable information terminal 100 (S210: "Yes"), it returns to the process of S207 after executing each process based on the operation instructions input in process S207 (S211). Conversely, if the designated application-external locking function unit 1102A does not confirm that the operator is a legitimate user of the portable information terminal 100 (S210: "No"), it does not execute the operation instructions input in process S207 and returns to the process of S207.
[0105] Therefore, all operation instructions for the portable information terminal 100 are only permitted to the official users of the portable information terminal 100.
[0106] [Variation Example 3]
[0107] Figure 4 This is an example of the appearance of the portable information terminal 100g. Furthermore, this figure illustrates examples of the front, top, and left and right side views of the portable information terminal 100g when it is an eyeglass-type information terminal device such as an HMD (Head Mount Display), omitting the rear and bottom views, etc.
[0108] In the portable information terminal 100g, a display unit 131L / 131R is disposed in a lens portion shaped like glasses. The display unit 131L / 131R is a transmissive display, allowing the wearer (operator) to visually recognize the scenery in front of them through the display unit 131L / 131R, and to view the image data processed by the image signal processing unit 132 on the display unit 131L / 131R. Furthermore, a first image input unit 133L / 133R is provided on the back of the portable information terminal 100g, and a second image input unit 134L / 134R is provided on the front of the portable information terminal 100g.
[0109] Additionally, on the left side of the portable information terminal 100g, there is a touch sensor 122g and a stereo speaker 143L. On the right side of the portable information terminal 100g, there is a cursor key 121c, which is one of the operation keys 121, and a stereo speaker 143R. Furthermore, on either the left or right side of the portable information terminal 100g, there may be a μ-USB input unit 170u for power supply (not shown in the illustration).
[0110] When performing motion control processing for a specified application-specific locking function using a portable information terminal 100g, which is an eyeglass-type information terminal device as shown in the figure, as long as... Figure 3A The user verification process in S210 of the flowchart can be performed using iris authentication. In this case, it is sufficient to activate the internal camera 133L / 133R (or either one) and the iris authentication processing unit of the user authentication processing unit 1103 (not shown in the diagram) in S206. Furthermore, in S210, the iris authentication processing unit parses the image acquired from the internal camera 133L / 133R, extracts the iris image of the wearer (operator), and compares the extracted iris image with the iris image of the registered user pre-stored in the authentication information storage area 1011. If the comparison result has a certain degree of consistency, the wearer (operator) is considered a registered user of the portable information terminal 100, and control can be performed in this manner. Alternatively, in this case, it is sufficient to deactivate the internal camera 133L / 133R and terminate the operation of the iris authentication processing unit in S216 according to the instruction to end the control of the specified application lock function.
[0111] As explained above, the portable information terminal 100 of this embodiment can perform the following application-exclusive locking function control: Operations on predetermined applications selected by the registered user are allowed for all operators, but other operations are appropriately restricted when the registered user is not the operator. That is, a portable information terminal and its control method that provide good usability by appropriately restricting terminal functions according to the operator are provided.
[0112] Example 2
[0113] Hereinafter, Example 2 will be described. Furthermore, the basic structure of Example 2 is the same as that of Example 1. Hereinafter, the differences between this example and Example 1 will be mainly described, and common parts will be omitted as much as possible to avoid repetition.
[0114] [Example of action control for specifying application-external locking function]
[0115] The following example illustrates the action control processing of the designated application lock function, where a user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other person while selecting and launching an image viewing application, in order to share and view images captured by the camera in the various information storage areas 1019 of the storage device unit 110.
[0116] Figure 5 This is a flowchart illustrating an example of the motion control processing for a specified application external locking function. The processing shown in the flowchart primarily involves the specified application external locking function controlled by the specified application external locking function unit 1102A. Furthermore, the control of the specified application external locking function unit 1102A can also be performed independently of the control of the terminal locking function unit 1102T described above.
[0117] First, in the processing of S301 to S304, the following steps are performed: Figure 3A The same process applies to S201 to S204 of the flowchart. That is, according to the operator's operation instructions, the startup process of the image viewing application and the start process of the designated application lock function control are performed. In addition, the designated application lock function unit 1102A stores the running application (in this embodiment, the image viewing application) as a designated application according to the operator's instructions (S305).
[0118] Next, the basic operation function unit 1101 checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If the basic operation function unit 1101 confirms that no operation instruction has been input to the touch screen 180 (S306: "No"), it repeats the process of S306. If the basic operation function unit 1101 confirms that an operation instruction has been input to the touch screen 180 (S306: "Yes"), it checks whether the operation instruction specifies the end of the application lock function control (S307). If the basic operation function unit 1101 confirms that the operation instruction input in the process of S306 is a specified instruction to end the application lock function control (S307: "Yes"), it proceeds to the process of S312. In addition, if the basic operation function unit 1101 confirms that the operation instruction input in the process of S306 is not a specified instruction to end the application lock function control (S307: "No"), it proceeds to the process of S308.
[0119] In the process of S308, the designated application lock function unit 1102A confirms whether the operation instruction input in the process of S306 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the process of S305, or an operation instruction targeting an application other than the designated application (S308). If the designated application lock function unit 1102A confirms that the operation instruction input in the process of S306 is an operation instruction targeting the designated application (S308: Designated Application), after the image viewing application function unit executes each process based on the operation instruction (S311), it returns to the process of S306. If the designated application lock function unit 1102A confirms that the operation instruction input in the process of S306 is an operation instruction targeting an application other than the designated application (S308: Other Than Designated Application), it further confirms whether the operation instruction is a launch instruction for any application other than the designated application (S309).
[0120] In the processing of S309, if the designated application lock function unit 1102A confirms that the operation instruction entered in the processing of S306 is a launch instruction for any application other than the designated application (S309: "Yes"), it requests the operator to input a designated application launch license code (S310). Specifically, according to the request of the designated application lock function unit 1102A, the PIN input processing unit 1103P displays a PIN input screen 180a on the touch screen 180. Here, if the operator inputs a pre-set designated application launch license code stored in the authentication information storage area 1011 as PIN information, the designated application lock function unit 1102A processes the process as confirming the official designated application launch license code (S310: OK), and performs the processing based on the operation instruction, that is, launching any application other than the designated application (S311). On the other hand, if the operator fails to enter the pre-set designated external application launch license code stored in the authentication information storage area 1011 as PIN information, the designated external application lock function unit 1102A processes it as an unconfirmed formal designated external application launch license code (S310: NG), does not perform the processing based on the operation instruction, that is, the launch of any application other than the designated application, and returns to the processing of S306. The confirmation processing of the designated external application launch license code in S310 only needs to be performed with... Figure 3A The same processing can be applied to S212 to S215 of the flowchart.
[0121] In the S309 process, if the designated application lock function unit 1102A confirms that the operation instruction entered in the S306 process is not a launch instruction for any application other than the designated application (S309: "No"), it returns to the S306 process after executing each process based on the operation instruction (S311). That is, any application other than the designated application that has been launched performs the designated application launch license code verification process in the S310 process when it is launched, and is therefore determined to have obtained permission from the official user of the portable information terminal 100 and launched. In addition, any application other than the designated application launched via the designated application launch license code verification process can be allowed to operate by all operators without performing new authentication processing until the operation of the application ends.
[0122] The processing of S312 to S317 only requires performing the steps with... Figure 3A The same processing can be applied to S212-S215 and S217-S218 of the flowchart.
[0123] [Variation Example 1]
[0124] The verification process for the specified external application launch license code performed in S310 is not limited to the PIN input method mentioned above. For example, it can also be a password input method, pattern input method, facial recognition method, iris recognition method, fingerprint recognition method, palm print recognition method, voiceprint recognition method, etc.
[0125] In addition, the formal user confirmation process in S312 to S315 can be any authentication method such as PIN input, password input, pattern input, facial recognition, iris recognition, fingerprint recognition, palm print recognition, or voiceprint recognition.
[0126] [Variation Example 2]
[0127] In the action control processing of the designated application lock function in this embodiment, it is also possible to prevent any application from being stored (registered) as a designated application. In this case, the operator only needs to instruct the designated application lock function control to start while the main screen 180b is displayed on the touch screen 180.
[0128] In this case, do not execute. Figure 5The processes S301, S302, S305, S308, and S316 are performed respectively. That is, as long as all operation instructions input in the process of S306 are operation instructions targeting applications other than the specified application, the processes of S309 to S311 are performed. Thus, the launch instructions for all applications of the portable information terminal 100 are controlled to determine whether they can be executed based on the result of the confirmation process of the launch license code of the specified application.
[0129] As explained above, the portable information terminal 100 of this embodiment can perform the following designated application lockout function control: it allows operation of all predetermined applications selected by the operator and authorized users, but for other operations, it appropriately allows them based on the result of the confirmation process of the designated application launch permission code pre-set by the authorized user. That is, it can provide a portable information terminal and its control method that are convenient to use and can appropriately restrict the terminal functions according to the operator.
[0130] Example 3
[0131] Hereinafter, Example 3 will be described. Furthermore, the basic structure of Example 3 is the same as that of Example 1. Hereinafter, the differences between this example and Example 1 will be mainly described, and common parts will be omitted as much as possible to avoid repetition.
[0132] [Example of action control for specifying application-external locking function]
[0133] The following example illustrates the action control processing of the designated application lock function, where a user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other person while selecting and launching an image viewing application, in order to share and view images captured by the camera in the various information storage areas 1019 of the storage device unit 110.
[0134] Figure 6 This is a flowchart illustrating an example of the motion control processing for a specified application external locking function. The processing shown in the flowchart primarily involves the specified application external locking function controlled by the specified application external locking function unit 1102A. Furthermore, the control of the specified application external locking function unit 1102A can also be performed independently of the control of the terminal locking function unit 1102T described above.
[0135] First, in the processing of S401 to S406, the following steps are performed: Figure 3AThe same process applies to S201 to S206 of the flowchart. That is, according to the operator's operation instructions, the startup process of the image viewing application and the start process of the specified application lock function control are performed. In addition, according to the operator's instructions, the running application (in this embodiment, the image viewing application) is stored (registered) as the specified application, and the internal camera 133 is validated and the face authentication processing unit 1103F is started.
[0136] Next, the basic operation function unit 1101 checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If the basic operation function unit 1101 confirms that no operation instruction has been input to the touch screen 180 (S407: "No"), it repeats the process of S407. If the basic operation function unit 1101 confirms that an operation instruction has been input to the touch screen 180 (S407: "Yes"), it checks whether the operation instruction specifies the end of the application lock function control (S408). If the basic operation function unit 1101 confirms that the operation instruction input in the process of S407 is a specified instruction to end the application lock function control (S408: "Yes"), it proceeds to the process of S414. In addition, if the basic operation function unit 1101 confirms that the operation instruction input in the process of S407 is not a specified instruction to end the application lock function control (S408: "No"), it proceeds to the process of S409.
[0137] In the processing of S409, the designated application lock function unit 1102A confirms whether the operation instruction input in the processing of S407 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the processing of S405, or an operation instruction targeting something other than the designated application (S409). If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S407 is an operation instruction targeting the designated application (S409: Designated Application), after the image viewing application function unit performs each process based on the operation instruction (S413), it returns to the processing of S407. If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S407 is an operation instruction targeting something other than the designated application (S409: Other than Designated Application), it further confirms whether the operator is a formal user of the portable information terminal 100 (S410).
[0138] In the processing of S410, if the designated application lockout function unit 1102A confirms that the operator is a legitimate user of the portable information terminal 100 (S410: "Yes"), after each application function unit of the other action function unit 1109 executes the processing based on the operation instruction input in the processing of S407 (S413), it returns to the processing of S407. Alternatively, if the designated application lockout function unit 1102A does not confirm that the operator is a legitimate user of the portable information terminal 100 (S410: "No"), it checks whether the operation instruction input in the processing of S407 is a launch instruction for any application other than the designated application (S411).
[0139] In the process of S411, if the designated application lockout function unit 1102A confirms that the operation instruction input in the process of S407 is a launch instruction for any application other than the designated application (S411: "Yes"), it performs the confirmation process for the designated application launch license code (S412). If the designated application lockout function unit 1102A confirms the input of the designated application launch license code in the process of S412 (S412: OK), it executes the process based on the operation instruction, that is, the launch of any application other than the designated application (S413). On the other hand, if the designated application lockout function unit 1102A does not confirm the input of the designated application launch license code in the process of S412 (S412: NG), it does not execute the process based on the operation instruction, that is, the launch of any application other than the designated application, and returns to the process of S407. The confirmation process for the designated application launch license code in S412 can be related to... Figure 3A The same processing is applied to S212 to S215 of the flowchart.
[0140] In the process of S411, if the designated application lock function unit 1102A confirms that the operation instruction entered in the process of S407 is not a launch instruction for any application other than the designated application (S411: "No"), it returns to the process of S407 after executing each process based on the operation instruction (S413). That is, any application other than the designated application that has been launched performs the designated application launch license code confirmation process in the process of S412 when it is launched, and is therefore determined to have obtained the permission of the official user of the portable information terminal 100 and is launched. In addition, any application other than the designated application launched via the designated application launch license code confirmation process can be allowed to operate by all operators without performing new authentication processing until the operation of the application ends.
[0141] The processing of S414 to S420 only requires performing the following steps: Figure 3AThe same processing can be applied to S212 to S218 of the flowchart.
[0142] The action control processing for the specified application external locking function in this embodiment is a combination of the action control processing for the specified application external locking function in Embodiment 1 and the action control processing for the specified application external locking function in Embodiment 2.
[0143] As explained above, the portable information terminal 100 of this embodiment can perform the following designated application lockout function control: it restricts the operation of all predetermined applications that the operator is allowed to select as a formal user, but appropriately restricts other operations when the formal user is not the operator, or appropriately allows them based on the result of the confirmation process of the designated application launch permission code pre-set by the formal user. That is, it can provide a portable information terminal and its control method that are convenient to use and can appropriately restrict the terminal functions according to the operator.
[0144] Example 4
[0145] Hereinafter, Example 4 will be described. Furthermore, the basic structure of Example 4 is the same as that of Example 1. Hereinafter, the differences between this example and Example 1 will be mainly described, and common parts will be omitted as much as possible to avoid repetition.
[0146] [Example of action control for specifying application-external locking function]
[0147] In Embodiment 1, all operation instructions stored (registered) within an application designated as a specific application are allowed for all operators (i.e., even if the operator is not a formal user of the portable information terminal 100). However, even among operation instructions stored (registered) within an application designated as a specific application, there are operation instructions that should not be allowed if the operator is not a formal user of the portable information terminal 100. For example, in the case of the image viewing application described above, even among operation instructions within the image viewing application, instructions such as instructions to delete image data or move image data between folders should not be allowed if the operator is not a formal user of the portable information terminal 100.
[0148] In this case, Figure 3A In the flowchart shown, as long as the use of Figure 7 The processing of S501 to S506 can replace the processing of S207 to S211 for the action control processing of the designated application lock function. Hereinafter, the action control processing of the designated application lock function of this embodiment will be explained as follows: the user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other person in order to share and view the images captured by the camera in the various information storage areas 1019 of the storage device unit 110. The user has selected and started the image viewing application.
[0149] Figure 7 This is part of a flowchart illustrating an example of motion control processing for specifying an external locking function. Prior to the processing shown in this diagram, [the following steps are performed]... Figure 3A The same processes as S201 to S206 in the flowchart shown are performed. Additionally, after the processes shown in the figure, the same process is performed... Figure 3A The same processing is applied to S212 to S218 of the flowchart shown, but the description is omitted.
[0150] In execution and Figure 3A After processing the same steps as S201 to S206 in the flowchart, the basic operation function unit 1101 then checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touchscreen 180. If no operation instruction has been input to the touchscreen 180 (S501: "No"), the process of S501 is repeated. If the basic operation function unit 1101 checks whether an operation instruction has been input to the touchscreen 180 (S501: "Yes"), the operation instruction is checked to see if it is an instruction to end the application lock function control (S502). If the basic operation function unit 1101 checks whether the operation instruction input in the process of S502 is an instruction to end the application lock function control (S502: "Yes"), the process continues as before. Figure 3A The same processing is applied to S212 to S218 of the flowchart. In addition, if the basic operation function unit 1101 confirms that the operation instruction input in the processing of S501 is not an instruction to end the control of the external lock function (S502: "No"), it proceeds to the processing of S503.
[0151] In the processing of S503, the designated application lock function unit 1102A confirms whether the operation instruction input in the processing of S501 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the processing of S205, or an operation instruction targeting something other than the designated application (S503). If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S501 is an operation instruction targeting the designated application (S503: Designated Application), then it confirms whether the operation instruction input in the processing of S501 is a license command (S504). The license command will be described later. If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S501 is a license command targeting the designated application (S504: "Yes"), after the image viewing application function unit executes each process based on the operation instruction (S506), it returns to the processing of S501.
[0152] The designated application lockout function unit 1102A confirms whether the operator is a registered user of the portable information terminal 100 if it confirms that the operation instruction entered in the process of S501 is not a license command targeting the designated application (S504: "No") or if it confirms that the operation instruction entered in the process of S501 is an operation instruction targeting an application other than the designated application (S503: "Application other than the designated application").
[0153] If the designated application lockout function unit 1102A confirms in the S505 process that the operator is a legitimate user of the portable information terminal 100 (S505: "Yes"), after the image viewing application function unit and other application function units have executed the respective processes based on the operation instructions input in the S501 process (S506), it returns to the S501 process. Conversely, if the designated application lockout function unit 1102A does not confirm that the operator is a legitimate user of the portable information terminal 100 (S505: "No"), it does not execute the operation instructions input in the S501 process and returns to the S501 process.
[0154] In the example of the image viewing application described above, the permission commands are groups of commands that can be executed even when the operator is not a registered user of the portable information terminal 100, in addition to instructions for deleting image data and instructions for moving image data between folders. Permission commands can also be managed using a permission command table for each application installed on the portable information terminal 100. The permission command table can also be pre-set by registered users of the portable information terminal 100 and stored in various information storage areas 1019 of the storage device unit 110. Furthermore, each application installed on the portable information terminal 100 can be automatically generated based on the security level of each command.
[0155] In the S504 process, based on the name of the application stored as the designated application in the S205 process, the designated application external locking function unit 1102A reads the corresponding license command table from the various information storage areas 1019, and then determines whether the operation instruction entered in the S501 process is the operation instruction described in the license command table.
[0156] Through the above processing, all operators are allowed to store (register) operation instructions within applications designated as specified applications and operation instructions described in the license command table. Even operation instructions stored (registered) within applications designated as specified applications but not described in the license command table, and operation instructions for applications not stored (registered) as specified applications, are only allowed if the operator is a registered user of the portable information terminal 100. In other words, a portable information terminal and its control method can be provided that offer good ease of use by appropriately limiting terminal functions according to the operator.
[0157] In addition, it can also be done in Figure 3D , Figure 6 The flowchart shown also applies the same control as above to whether the operator's input of operation instructions to the portable information terminal 100 via touch operation on the touch screen 180 corresponds to a permission command.
[0158] The above examples of embodiments 1 to 4 illustrate implementation methods, but of course, the structure of the technology for implementing this embodiment is not limited to the embodiments described, and various modifications can be considered. The above structures can also be partially or entirely implemented in hardware, for example, using integrated circuit design. Alternatively, they can be implemented in software by a microprocessor unit or the like interpreting and executing programs that implement various functions. Hardware and software can also be used together. The software can be pre-stored in the ROM 103, storage device unit 110, etc., of the portable information terminal 100 at the time of product shipment. It can also be obtained from various server devices on the Internet after the product is shipped. Alternatively, the software provided by a memory card, optical disc, etc., can also be obtained.
Claims
1. A control method for a portable information terminal, characterized in that, Register applications that can be operated by official users of the portable information terminal, as well as applications that can be operated by users other than the official users, as designated applications. In the case of the unlocked state, where the operation of various functions of the portable information terminal is restricted in batches. Accepts restriction instructions for limiting operations of applications on the portable information terminal performed by users other than the official users of the portable information terminal. The authentication process determines whether the user is a legitimate user of the portable information terminal. If the user is verified to be a legitimate user, operation of the application on the portable information terminal is permitted. If the user is not identified as a legitimate user, operation of applications other than the designated application on the portable information terminal is restricted.
2. The control method for a portable information terminal according to claim 1, characterized in that, The portable information terminal is controlled by registering the specified application through the operation of the official user.
3. The control method for a portable information terminal according to claim 2, characterized in that, Register the running application as the specified application.
4. The control method for a portable information terminal according to claim 2, characterized in that, If it is confirmed that the operation of the application on the portable information terminal is an operation on an application other than the specified application, input is requested as information for the operator to authorize the operation, specifying the out-of-application permission information.
5. The control method for a portable information terminal according to claim 2, characterized in that, If it is confirmed that the operation on the portable information terminal's application is an operation on the specified application, then it is confirmed that the operation is a licensed command operation. If it is confirmed that the operation is based on the command with the permission stated above, then the processing based on that command is performed.
6. A portable information terminal, characterized in that, have: The operation input unit, in the case of a locked-out state where the operation of various functions of the portable information terminal is restricted in batches, accepts restriction instruction operations for restricting the operation of the application program of the portable information terminal performed by users other than the official users of the portable information terminal. The user authentication department authenticates whether the user is a legitimate user of the portable information terminal. as well as The locking control unit registers applications that can be operated by the official user of the portable information terminal and other users as designated applications. When the lock is unlocked, if the user is identified as an official user, operation of the applications on the portable information terminal is allowed; if the user is not identified as an official user, operation of applications on the portable information terminal other than the designated applications is restricted.
7. The portable information terminal according to claim 6, characterized in that, The lock control unit registers the designated application through the operation of the registered user.
8. The portable information terminal according to claim 7, characterized in that, The locking control unit registers the executing application as the designated application.
9. The portable information terminal according to claim 7, characterized in that, When the locking control unit confirms that the operation of the application on the portable information terminal is an operation on an application other than the specified application, it requests input of the specified application-out-of-application permission information as information for the operator to authorize the operation.
10. The portable information terminal according to claim 7, characterized in that, If the locking control unit confirms that the operation on the portable information terminal's application is an operation on the specified application, it confirms that the operation is an operation based on a licensed command. If it confirms that the operation is an operation based on a licensed command, it executes processing based on that command.
Citation Information
Patent Citations
Information processing apparatus, authentication control method, and program
JP2011013855A
Mobile terminal and method of controlling the mobile terminal
CN104052866A
Sharing by children on mobile devices
JP2015528674A