Information Processing System, Method, and Program Product

By linking people, roles, functions, properties and equipment in the information processing system, the complexity of permission management in the existing technology is solved, and convenient permission management is achieved.

CN114846472BActive Publication Date: 2025-06-17DAIKIN INDUSTRIES LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080089271.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-27
Filing Date
2020-10-23
Publication Date
2025-06-17
Estimated Expiration
2040-10-23

AI Technical Summary

Technical Problem

The prior art causes permission management to become very complicated when the access rights of object access rights and access control rules change.

Method used

An information processing system is designed to manage access to functions and information that can be used in each person's property by linking people, roles, functions, properties and equipment, etc., using the association database and permission management components.

Benefits of technology

It realizes a system that facilitates permission management, can independently manage each person's property functions and information access rights, avoiding the complexity of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114846472B_ABST
    Figure CN114846472B_ABST
Patent Text Reader

Abstract

An information processing system, comprising: an association database that associates a person with a property; a person database that associates a person, the role of the person, and the functions that the person can use; a property database that associates a property with the functions used in the property; a first authority management unit that manages, for each person, the functions that can be used in the property by using the person database and the property database; and a second authority management unit that manages, for each person, the properties to which information can be accessed by using the association database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing system, method, and program product. Background Art

[0002] A technique for setting access authority in units of objects is disclosed in the prior art. Specifically, for example, a technique for using a first access control rule and a second access control rule in association is disclosed. The first access control rule is used to define the access authority for an object, and the second access control rule is used to define the access authority for the first access control rule (Patent Document 1).

[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2002-91816 Summary of the Invention

[0004] [Technical Problem to be Solved]

[0005] In the above prior art, when the access authority for an object and the access authority for an access control rule change, the change will spread to the whole, and the authority management will become very complicated.

[0006] An object of the present disclosure is to provide an information processing system, information processing apparatus, method, and program that facilitate authority management.

[0007] [Technical Solution]

[0008] The information processing system according to the first aspect of the present disclosure includes: an association database that associates a person (i.e., a human) with a property; a person database that associates a person, the role of the person, and the functions that the person can use; a property database that associates a property with the functions that can be used in the property; a first authority management unit that manages the functions that can be used in the property for each person using the person database and the property database; and a second authority management unit that manages the properties to which information can be accessed for each person using the association database.

[0009] According to the first aspect of the present disclosure, authority management can be easily performed.

[0010] The information processing system according to the second aspect of the present disclosure includes: a first server having the person database and the property database; and a second server having the association database.

[0011] According to the second aspect of the present disclosure, the functions that can be used in the property of each person and the properties to which information of each person can be accessed can be managed by independent devices.

[0012] In the information processing system according to the third aspect of the present disclosure, properties in the association database are associated with devices provided in the properties. The second server includes: a storage unit storing device identification information for determining devices provided in a property; a collection unit that collects status information indicating the status of the devices from the devices set in each property; and an association unit that associates the status information, a person, and a property with each other based on the device identification information included in the status information, the association database, and the storage unit.

[0013] According to the third aspect of the present disclosure, the status information of a device can be stored in association with a person and a property.

[0014] The information processing system according to the fourth aspect of the present disclosure includes a plurality of the first servers, and each of the plurality of first servers communicates with the second server.

[0015] According to the fourth aspect of the present disclosure, each of the plurality of first servers can manage functions that can be used in a property for each person, and at the same time, the second server can manage whether a property can be accessed for each person. Therefore, even if there are a plurality of first servers, permission management can be implemented so that permission management is not randomly scattered to each first server.

[0016] In the information processing system according to the fifth aspect of the present disclosure, the person database includes a user information database in which user identification information for determining a person and a role assigned to the person are associated. After receiving an input of the user identification information included in the authentication information, the second permission management unit refers to the association database and extracts a list of properties corresponding to the person determined by the user identification information. The first permission management unit extracts the role of the determined person by referring to the user information database, and extracts a list of functions that the determined person can use from the functions that can be used in the properties included in the list of properties by referring to the person database.

[0017] According to the fifth aspect of the present disclosure, each of the plurality of first servers can extract a list of functions that can be used in a property for each person.

[0018] In the information processing system according to the sixth aspect of the present disclosure, the function is related to the operation of a device provided in a property included in the list of properties.

[0019] According to the sixth aspect of the present disclosure, an instruction for operating a device provided in a property can be given.

[0020] The information processing system according to the seventh aspect of the present disclosure includes an output unit that displays an operation screen for operating the device on a terminal device.

[0021] According to the seventh aspect of the present disclosure, an instruction for operating a device provided in a property can be given.

[0022] In the information processing system according to the eighth aspect of the present disclosure, in the association database, four types of information are associated: user identification information for identifying a person, property identification information for identifying a property, device identification information for identifying a device provided in the property, and area identification information for identifying an area in the property where the device is installed.

[0023] According to the eighth aspect of the present disclosure, a device provided in a property and the area where the device is installed can be associated with a person.

[0024] In the information processing system according to the ninth aspect of the present disclosure, the first authority management unit determines whether the functions that the identified person can use include the registration of a new property. When the functions that the identified person can use include the registration of a new property, the second authority management unit issues property identification information for identifying the new property and stores the property identification information in the association database in association with the user identification information of the identified person.

[0025] According to the ninth aspect of the present disclosure, a new property can be associated with a person. In addition, according to the ninth aspect of the present disclosure, when registering a property as an object of new authority management, the second server side has the authority to issue property identification information. Therefore, authority management can be performed by both the first server and the second server, and unified authority management can be achieved.

[0026] In the information processing system according to the tenth aspect of the present disclosure, after receiving a request for issuing new user identification information, the second authority management unit issues the new user identification information and stores the new user identification information in the association database in association with the property identification information of the properties included in the list of properties.

[0027] According to the tenth aspect of the present disclosure, when registering a user as an object of new authority management, the second server side has the authority to issue user identification information. Therefore, authority management can be performed by both the first server and the second server, and unified authority management can be achieved.

[0028] The information processing apparatus according to the 11th aspect of the present disclosure includes: an association database that associates a person with a property; a person database that associates a person, the role of the person, and the functions that the person can use; a property database that associates a property with the functions that can be used in the property; a first authority management unit that manages the functions that can be used in the property for each person using the person database and the property database; and a second authority management unit that manages the properties to which information can be accessed for each person using the association database.

[0029] The method according to the 12th aspect of the present disclosure is a method executed by an information processing system, and the information processing system performs the following processing: using a person database that associates a person, the role of the person, and the functions that the person can use, and a property database that associates a property with the functions that can be used in the property, managing the functions that can be used in the property for each person; and using an association database that associates a person with a property, managing the properties to which information can be accessed for each person.

[0030] The program according to the 13th aspect of the present disclosure causes a computer to perform the following processing: using a person database that associates a person, the role of the person, and the functions that the person can use, and a property database that associates a property with the functions used in the property, managing the permissions of the functions that can be used in the property for each person; and using an association database that associates a person with a property, managing the properties to which information can be accessed for each person. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 Schematic diagram of an example of the system configuration of the information processing system.

[0032] Figure 2 Schematic diagram of an example of the hardware configuration of the server.

[0033] Figure 3 Schematic diagram of an example of the property database.

[0034] Figure 4 Schematic diagram of an example of the person database.

[0035] Figure 5 Schematic diagram of an example of the authentication database.

[0036] Figure 6 Schematic diagram of an example of the association database.

[0037] Figure 7 ​​​​​​​Schematic diagram of an example of the device information database.

[0038] Figure 8 Explanation diagram of the functions of the devices included in the information processing system.

[0039] Figure 9A First timing diagram (part 1) for explaining the operation of the information processing system.

[0040] Figure 9B First timing diagram (part 2) for explaining the operation of the information processing system.

[0041] Figure 10 First diagram showing a display example of the terminal device.

[0042] Figure 11 Second timing diagram for explaining the operation of the information processing system.

[0043] Figure 12 Second diagram showing a display example of the terminal device.

[0044] Figure 13 Third timing diagram for explaining the operation of the information processing system.

[0045] Figure 14 Third diagram showing a display example of the terminal device. DETAILED DESCRIPTION

[0046] The system configuration (structure) of the information processing system according to the present embodiment will be described below with reference to the accompanying drawings. Figure 1 Schematic diagram of an example of the system configuration of the information processing system.

[0047] The information processing system 100 according to the present embodiment includes a server 200 and a server 300. The server 200 and the server 300 according to the present embodiment communicate via a network or the like.

[0048] The terminal device 400 according to the present embodiment communicates with the server 200 via a network or the like. In addition, in the present embodiment, when the terminal device 400 communicates with the server 300, the communication is achieved via the server 200. In the present embodiment, when describing the communication related to the terminal device 400 and the server 300, there are cases where the description of achieving the communication via the server 200 is omitted.

[0049] In addition, the server 300 according to the present embodiment communicates with, for example, control devices 500, 600, etc. provided in a building B such as a building, which are devices in the building. In the following description, the building may sometimes be referred to as a property.

[0050] ​​​​​​​​The control device 500 is connected to devices 510, 520, etc. provided in the property B, and acquires status information indicating the status of devices 510, 520, etc. The control device 600 is connected to devices 610, 620, 630, etc. provided in the property B, and acquires status information indicating the status of devices 610, 620, 630, etc. Devices 510, 520, devices 610, 620, 630, etc. are, for example, air conditioners. In the following description, the air conditioner is sometimes also referred to as an air-conditioning machine.

[0051] The information processing system 100 of the present embodiment is used, for example, by an operator who manages devices provided in a property, an employee of a sales company that sells devices, etc. In the following description, the user of the information processing system 100 is sometimes also referred to as a user.

[0052] The information processing system 100 responds to a request from a user, enables the user to view property-related information associated with the user, sends an operation instruction for a device provided in the property, etc.

[0053] The property-related information includes information related to the control device provided in the property, information for determining the devices provided in the property, the status information of these devices, information indicating the address of the property, and information indicating the manager who manages the property. In the following description, the property-related information is sometimes also referred to as property-related information.

[0054] In addition, the information processing system 100 of the present embodiment can, in response to a request from a user, associate the user with a new property, enable the user to view new property-related information, send an operation instruction for a device provided in the new property, etc. Further, the information processing system 100 can also, according to a request from a user, associate a new user with a property, enable the new user to view property-related information, send an operation instruction for a device, etc.

[0055] Next, the servers 200 and 300 included in the information processing system 100 will be described.

[0056] The server 200 of the present embodiment has a property database 210, a person database 220, and an authentication database 230. These databases are preset in the server 200. The server 200 of the present embodiment is an example of the first server in the information processing system 100.

[0057] In addition, the server 200 also has a first privilege management unit 270 that performs various processes described later by referring to the above-mentioned respective databases.

[0058] The property database 210 stores property information used by the information processing system 100 to determine a property. The property information in this embodiment includes information representing functions that can be used in the property. In addition, the property information can be a part of property-related information.

[0059] In this embodiment, the functions that can be used in the property refer to, for example, the function of viewing property-related information, the remote operation function of sending operation instructions for devices installed in the property, the power suppression control / power demand control function for devices installed in the property, the scheduled operation function, etc., which are functions assigned (allocated) to each property.

[0060] Therefore, the functions that can be used in the property can also be said to be processes executed by referring to property-related information.

[0061] The person database 220 stores information associating a user, the user's role, and the functions allowed for the role.

[0062] Specifically, the person database 220 has a user information database 250 and a role database 260. The user information database 250 stores user information including information representing the role of the user. The role database 260 stores role information associating a role with the functions that can be used by the user of that role. In other words, in the role database 260, a role and the functions of the role are associated.

[0063] In this embodiment, the functions of a role refer to functions defined according to the role in addition to the functions allowed to be used in the property, and are functions that can be used by the user of that role.

[0064] As described above, in this embodiment, information representing the association between a property and the functions that can be used in the property, and information representing the association between a role and the functions allowed for the role are maintained independently. For this reason, in this embodiment, even if the functions that can be used in the property change, the change will not affect the functions allowed for the role. In addition, in this embodiment, even if the functions allowed for the role change, the change will not affect the functions that can be used in the property.

[0065] Therefore, in this embodiment, the functions that can be used in the property and the functions allowed for the role can be freely changed separately.

[0066] The authentication database 230 stores authentication information referred to when a user logs in to the information processing system 100.

[0067] The first authority management unit 270 uses the property database 210 and the person database 220 to manage the functions that can be used in the property for each user (person). In other words, the first authority management unit 270 uses the property information stored in the property database 210 and the user information and role information stored in the user information database 250 and the role database 260 included in the person database 220 respectively to manage the functions that can be used in the property for each user. The management performed by the first authority management unit 270 will be described in detail later.

[0068] The server 300 of the present embodiment has an association database 310, a device information database 320, a second authority management unit 330, and a status information management unit 340. The server 300 of the present embodiment is an example of the second server in the information processing system 100.

[0069] The association database 310 and the device information database 320 are pre-configured in the server 300.

[0070] The association database 310 stores association information that associates the property and the user. The device information database 320 stores the status information collected from the control devices 500 and 600.

[0071] The second authority management unit 330 uses the association database 310 to manage the properties to which information can be accessed for each user. In the present embodiment, the information that can be accessed refers to, for example, property-related information. Therefore, in other words, the second authority management unit 330 manages the properties for which the reference to the property-related information is permitted for each user. The management performed by the second authority management unit 330 will be described in detail later.

[0072] The status information management unit 340 collects the status information indicating the status of the devices connected to the control devices 500 and 600 from the control devices 500 and 600 that communicate with the server 300, and stores it in the device information database 320.

[0073] At this time, the status information management unit 340 refers to the association database 310 and stores the status information as device information associated with the property and the user in the device information database 320.

[0074] The terminal device 400 has a control unit 410. The control unit 410 is implemented by a Web application (hereinafter simply referred to as a Web app) executed on a Web browser or the like. The control unit 410 performs various communications, information acquisition, display, etc. according to instructions from the servers 200 and 300 respectively.

[0075] It should be noted that the application program for implementing the control unit 410 may also be an application program other than a Web application.

[0076] As described above, in the present embodiment, the server 200 manages the functions that can be used in the property for each person, and the server 300 manages the properties to which the information of each person can be accessed. For this reason, in the present embodiment, the management of the functions that can be used in the property for each person and the management of the properties to which the information of each person can be accessed can be performed independently of each other.

[0077] In other words, in the present embodiment, the server 200 associates a person with the processes that are allowed to be executed among the processes executed by referring to the property-related information. In addition, in the present embodiment, the server 300 associates a person with the property to which the reference to the property-related information is allowed.

[0078] Therefore, according to the present embodiment, the processes that are allowed to be executed by referring to the property-related information and the properties to which the reference to the property-related information is allowed can be managed independently of each other for each person.

[0079] In addition, in the present embodiment, for example, in the case where the functions that can be used in the property change for a certain person, the change can be reflected only in the server 200, and the server 300 is not affected by the change.

[0080] In addition, in the present embodiment, the association between people and properties can be managed in a unified (aggregated) manner by the server 300 having the association database 310.

[0081] Therefore, according to the present embodiment, the management of the association among a person, the functions that the person can use in the property, and the property to which the access to the information is allowed can be easily performed.

[0082] In addition, Figure 1 In the example of, it is assumed that the information processing system 100 includes the server 200 and the server 300, but it is not limited thereto. The server 200 and the server 300 may be implemented by a plurality of servers respectively. In addition, the information processing system 100 may also include a plurality of servers 200. In addition, the number of properties provided with the control devices that communicate with the information processing system 100, the number of control devices provided in the properties, and the number of devices connected to the control devices are not limited to Figure 1 the example of. In addition, the number of terminal devices 400 that communicate with the information processing system 100 may also be any number.

[0083] The functions of the respective databases and functional units of the server 200 and the server 300 will be described in detail later.

[0084] Next, refer to Figure 2 The hardware configurations (structures) of the servers 200 and 300 of the present embodiment will be described. Figure 2 It is a schematic diagram of an example of the hardware configuration of a server.

[0085] In the present embodiment, the hardware configurations of the servers 200 and 300 are the same, so only the hardware configuration of the server 200 will be described.

[0086] The server 200 of the present embodiment is a computer including an input device 21, an output device 22, a drive device 23, an auxiliary storage device 24, a storage device 25, an arithmetic processing device 26, and an interface device 27 that are respectively connected to each other via a bus.

[0087] The input device 21 is a device for inputting various information, and can be implemented by, for example, a keyboard, a pointing device, etc. The output device 22 is a device for outputting various information, and can be implemented by, for example, a display, etc. The interface device 27 includes a LAN card, etc., and is used to connect to a network.

[0088] The program for implementing the first authority management unit 270 is at least a part of various programs for controlling the server 200. The program can be provided, for example, by the distribution of a storage medium 28, downloading from a network, etc. The storage medium 28 recording the program can use various types of storage media such as a CD-ROM, a floppy disk, a magneto-optical disk, etc. that record information in a light, electric, or magnetic manner, and semiconductor storage such as a ROM, a flash memory, etc. that record information in an electric manner.

[0089] In addition, the storage medium 28 recording the program is placed in the drive device 23, and the program can be installed from the storage medium 28 to the auxiliary storage device 24 via the drive device 23. The analysis object determination program downloaded from the network can be installed to the auxiliary storage device 24 via the interface device 27.

[0090] The auxiliary storage device 24 is used to implement each storage unit, etc. of the server 200, can save the programs installed in the server 200, and can save various files, data, etc. required by the server 200. When the server 200 is started, the storage device 25 can read and save the analysis object determination program from the auxiliary storage device 24. In addition, the arithmetic processing device 26 is, for example, a CPU (Central Processing Unit), a microcomputer, a processor, etc., and can implement various processes as described later according to the program saved in the storage device 25.

[0091] In addition, the terminal device 400 of the present embodiment is a computer having an arithmetic processing device and a storage device. Specifically, the terminal device 400 may be, for example, a portable tablet terminal, a smart phone, or the like.

[0092] Next, refer to Figures 3 to 6 Each database included in the servers 200 and 300 of the present embodiment will be described. Each database described below may be implemented by an auxiliary storage device, a storage device, or the like included in the servers 200 and 300.

[0093] Figure 3 FIG. is a schematic diagram of an example of a property database. The property database 210 of the present embodiment has a property ID, a function list, an attribute ID, and a list of tenant IDs as items of information, and the value of the item "property ID" is associated with other items. In the present embodiment, the information including the value of the item "property ID" and the values of other items in the property database 210 is property information.

[0094] The value of the item "property ID" is property identification information for identifying a property. The value of the item "function list" represents a list of functions used in the property determined by the property ID. Specifically, the value of the item "function list" is a list of function IDs (function identification information) for identifying the functions used in the property determined by the property ID.

[0095] The value of the item "attribute ID" is identification information for identifying a user's attribute. The value of the item "list of tenant IDs" represents a list of tenant IDs for identifying the tenants staying in the property determined by the property ID.

[0096] For Figure 3 example, in the property determined by the property ID "B1", there are functions determined by function IDs "F1" and "F2", respectively, and tenants determined by tenant IDs "Ta" and "Tb", respectively, are staying. In addition, in the property determined by the property ID "B1", it is associated with a user having the attribute ID "A1".

[0097] It should be noted that the property database 210 may also have items other than the above items as items of information. For example, the property database 210 may further include information indicating the address of each property. The property database 210 only needs to include at least Figure 3 the items shown.

[0098] Figure 4 FIG. is a schematic diagram of an example of a person database. The person database 220 of the present embodiment has a user information database 250 and a role database 260.

[0099] The user information database 250 has a user ID, role ID, attribute ID, group ID, organization ID, tenant ID, and operation scope as items of information. In the user information database 250, the item "user ID" is associated with other items. In this embodiment, the information including the value of the item "user ID" and the values of other items in the user information database 250 is user information.

[0100] The value of the item "user ID" is user identification information for identifying a user. The value of the item "role ID" is role identification information (role ID) for determining the role assigned to the user determined by the user identification information (user ID).

[0101] In this embodiment, the roles assigned to users include managers who manage the property, installers who set up control devices and equipment in the property, managers who manage the system, owners of the property, service providers (maintainers) who maintain control devices, equipment, etc. set in the property, sellers of control devices and equipment, etc.

[0102] The value of the item "attribute ID" is the same as that of the property database 210. The value of the item "group ID" is identification information for determining the group to which the user determined by the user ID belongs. The groups in this embodiment can be, for example, departments of an organization, or groups set according to each region (geographical area), etc.

[0103] The value of the item "organization ID" is identification information for determining the organization to which the user determined by the user ID belongs. The organization to which the user belongs refers to, for example, an enterprise, a store (shop), etc.

[0104] The value of the item "operation scope" indicates the setting scope of the devices operated by the user determined by the user ID. Specifically, the value of the item "operation scope" indicates whether it is in units of the property, in units of the control devices connected to the devices, or in units of the areas within the property. The areas within the property refer to each area when the inside of the property is divided into multiple areas.

[0105] From Figure 4 the user information database 250, it can be seen that the user determined by the user ID "U1" is assigned the role determined by the role ID "R1", and belongs to the group determined by the group ID "G1" and the organization determined by the organization ID "C1".

[0106] The role database 260 has a role ID, a menu list, and a component list as items of information, and the item "role ID" is associated with other items. In the present embodiment, the information including the values of the item "role ID" and other items in the role database 260 is role information.

[0107] The value of the item "role ID" is the same as that in the user information database 250. The value of the item "menu list" represents the menu (function overview) corresponding to the role ID. In other words, the value of the item "menu list" represents an overview of the functions defined by the role determined by the role ID.

[0108] The value of the item "component list" represents an overview of the display components (operation buttons, etc.) displayed in the menu corresponding to the role ID.

[0109] Figure 4 In the shown role database 260, the role ID "R1" is associated with the menu list "M1".

[0110] Figure 5 It is a schematic diagram of an example of the authentication database. The authentication database 230 of the present embodiment includes items of information such as email, password, and user ID, and the items are associated with each other.

[0111] In the present embodiment, the information including the values of the items in the authentication database 230 is authentication information. The authentication information is referred to when the user logs in to the information processing system 100.

[0112] The value of the item "email" represents the user's email, the value of the item "password" represents the user's password, and the value of the item "user ID" is the same as that in the user information database 250.

[0113] The above are the databases possessed by the server 200. Next, the databases possessed by the server 300 will be described.

[0114] Figure 6 It is a schematic diagram of an example of the association database. The association database 310 of the present embodiment includes items of information such as user ID, property ID, device ID, equipment ID, and area ID. In the association database 310, the item "user ID" and the item "property ID" are associated with each other, and the item "user ID" and the item "property ID" are associated with other items.

[0115] In the present embodiment, the information including the value of the item "user ID", the value of the item "property ID", and the values of other items in the association database 310 is association information.

[0116] The value of the item "User ID" is the same as that in the user information database 250, and the value of the item "Property ID" is the same as that in the property database 210.

[0117] The value of the item "Device ID" is device identification information (Device ID) for identifying the control device installed in the property determined by the Property ID. The value of the item "Equipment ID" is equipment identification information (Equipment ID) for identifying the equipment connected to the control device determined by the Device ID.

[0118] The value of the item "Area ID" is identification information for identifying the area within the property determined by the Property ID.

[0119] From Figure 6 the example, it can be seen that the user determined by the User ID "U1" is associated with the property determined by the Property ID "B1", and the control device determined by the Device ID "S1" is installed in the property determined by the Property ID "B1". In addition, from Figure 6 the example, it can be seen that the equipment determined by the Equipment ID "K1" and the equipment determined by the Equipment ID "K2" are connected to the control device determined by the Device ID "S1". Further, from Figure 6 the example, it can be seen that the equipment determined by the Equipment ID "K1" and the equipment determined by the Equipment ID "K2" are installed in the area determined by the Area ID "Z1" within the property.

[0120] Figure 7 is a schematic diagram of an example of the equipment information database. The equipment information database 320 of the present embodiment includes, as items of information, Equipment ID, User ID, Property ID, Device ID, and status information. In the equipment information database 320, the item "Equipment ID" is associated with other items.

[0121] In the present embodiment, the information including the value of the item "Equipment ID" and the values of other items in the equipment information database 320 is equipment information.

[0122] The values of the items "Equipment ID", "User ID", "Property ID", and "Device ID" are the same as those in the association database 310.

[0123] The value of the item "Status Information" represents the status information of the equipment collected from the equipment determined by the item "Equipment ID". The status information includes, for example, various setting information for operating the equipment, environmental information of the equipment installation location, and the operating condition of the equipment.

[0124] The above are the various databases possessed by the server 300. It should be noted that in this embodiment, it is assumed that in the servers 200 and 300, property information, role information, user information, authentication information, function information, association information, and device information are respectively maintained in the form of being stored in the database, but it is not limited thereto. For each of the property information, role information, user information, authentication information, function information, association information, and device information, as long as the items included in each information are associated with the values of the items, and the manner of being maintained in each of the servers 200 and 300 may not be the form of being stored in the database.

[0125] Next, referring to Figure 8 The functional configurations of the various devices possessed by the information processing system 100 will be described. Figure 8 It is an explanatory diagram of the functions of the devices possessed by the information processing system.

[0126] First, the functions of the server 200 will be described. The server 200 of this embodiment has a first authority management unit 270. The first authority management unit 270 has an input reception (acceptance or reception) unit 271, an authentication unit 272, a user information acquisition unit 273, a role determination unit 274, a role function determination unit 275, a property function determination unit 276, a user function determination unit 277, an output unit 278, and an update unit 279.

[0127] The input reception unit 271 receives the input of information from the terminal device 400. Specifically, the input reception unit 271 receives the input of a part of the authentication information from the terminal device 400.

[0128] The authentication unit 272 authenticates the user of the terminal device 400 based on the input received by the input reception unit 271, that is, a part of the authentication information, and the authentication database 230. Specifically, when there is authentication information including a part of the input authentication information in the authentication database 230, the authentication unit 272 allows the user of the terminal device 400 to log in to the information processing system 100.

[0129] The user information acquisition unit 273 refers to the user information database 250 and acquires the user information associated with the user ID included in the authentication information.

[0130] The role determination unit 274 determines the role ID included in the user information acquired by the user information acquisition unit 273.

[0131] The role function determination unit 275 refers to the role database 260 and determines a list (menu list) of functions corresponding to the role ID.

[0132] The property function determination unit 276 determines a function list of the property corresponding to the user ID included in the authentication information based on the property list received from the terminal device 400 by the input reception unit 271 and the property database 210.

[0133] The user function determination unit 277 determines the functions that the user can use in the property based on the list of functions determined by the role function determination unit 275 and the list of functions determined by the property function determination unit 276.

[0134] The output unit 278 outputs various requests, notifications, etc. to the terminal device 400.

[0135] The update unit 279 updates each database set in the server 200. Specifically, for example, when the functions that can be used in the property of each role change, the update unit 279 causes the first permission management unit 270 to reflect the change in the role database 260. In addition, for example, when the role of each user changes, the update unit 279 causes the first permission management unit 270 to reflect the change in the user information database 250.

[0136] As described above, the first permission management unit 270 of the present embodiment authenticates the user through the functions of the above-mentioned various functional units, and then, for the user who has successfully passed the authentication, determines the functions that the user can use in the property by referring to the property database 210 and the person database 220.

[0137] Therefore, the management performed by the first permission management unit 270 of the present embodiment includes authenticating the user, determining the role of the user for the user who has successfully passed the authentication, obtaining a list of properties associated with the user, determining the functions that the user of the role can use in the property, and updating each database possessed by the server 200.

[0138] In addition, the functions that a person (user) can use in the property refer to the functions that the person has the use permission for in the property. Therefore, the functions that a person can use in the property can also be said to be the permissions that the person has for the functions that can be used in the property.

[0139] Accordingly, the management performed by the first permission management unit 270 can also be said to be the management of the permissions of each person related to the functions that can be used in the property.

[0140] In other words, the functions that a person can use in the property refer to the processes in the processes executed by referring to the property-related information for which the execution permission has been granted to the person. Therefore, the functions that a person can use in the property can also be said to be the permissions granted to the person to execute the processes executed by referring to the property-related information.

[0141] Accordingly, the management performed by the first authority management unit 270 can be said to be management of the authority of each person to perform processing by referring to the property-related information.

[0142] Next, the server 300 will be described. The server 300 includes a second authority management unit 330 and a state information management unit 340 .

[0143] The second authority management unit 330 includes an input receiving unit 331 , a property list extraction unit 332 , a device list extraction unit 333 , a device identification unit 334 , a device information extraction unit 335 , an output unit 336 , a user ID issuing unit 337 , a property ID issuing unit 338 , and an ID storage unit 339 .

[0144] The input receiving unit 331 receives input of various information from the terminal device 400. Specifically, the input receiving unit 331 receives user IDs, user IDs, property ID issuance requests, etc. (Note: the original Japanese word for issuance is "発行", which also includes generation, for example, the issuance of a property ID refers to the generation and issuance of a property ID) from the terminal device 400.

[0145] The property list extraction unit 332 extracts a list of properties associated with the user ID based on the user ID received by the input acceptance unit 331 and the associated database 310. In the following description, the list of properties may also be referred to as a property list.

[0146] The device list extraction unit 333 refers to the related database 310 and extracts a list of control devices associated with the properties included in the property list. In the following description, the list of control devices may also be referred to as a device list.

[0147] The device identification unit 334 extracts the device list corresponding to the user ID received by the input receiving unit 331 by referring to the association database 310, and identifies the control device that is consistent with the device list extracted by the device list extraction unit 333. That is, the device identification unit 334 identifies the control device associated with both the property and the user.

[0148] The device information extraction unit 335 refers to the device information database 320 and extracts the device information of the device connected to the control device specified by the device specification unit 334. The output unit 336 outputs various information to the terminal device 400.

[0149] The user ID issuing unit 337 issues a new user ID upon receiving a request for issuing a new user ID from the terminal device 400. The property ID issuing unit 338 issues a new property ID upon receiving a request for issuing a new property ID from the terminal device 400.

[0150] The ID storage unit 339 stores the user ID issued by the user ID issuing unit 337 and the property ID in the associated database 310 in an associated manner.

[0151] As described above, the second authority management unit 330 of the present embodiment extracts the property list associated with the user and the device list of the control devices provided in the properties included in the property list through the functions of the above respective functional units, and determines the control devices associated with both the property and the user. In addition, the second authority management unit 330 extracts the device information of the devices connected to the determined control devices and outputs it to the terminal device 400.

[0152] In addition, after receiving a request for issuing a new user ID and a property ID, the second authority management unit 330 of the present embodiment issues the new user ID and the property ID and stores them in the associated database 310.

[0153] Therefore, the management performed by the status information management unit 340 of the present embodiment includes extracting the property list corresponding to the user, determining the control devices associated with both the property and the user among the control devices provided in the property, outputting the device information of the devices connected to the determined control devices, and updating the associated database 310.

[0154] In short, the second authority management unit 330 manages the association between the properties for which the reference to the person and property related information is permitted.

[0155] In addition, a property for which the reference to the property related information is permitted indicates that the person has the authority to refer to the property related information of the property. For this reason, a property for which the reference to the property related information is permitted can also be said to be a property for which the person has the authority to refer to the property related information.

[0156] Accordingly, the management performed by the second authority management unit 330 can also be said to be the management of the authority given to the person to refer to the property related information.

[0157] In addition, for a property for which the reference to the property related information is not permitted, of course, the operation authority such as remote control performed by using the property related information is not given. Accordingly, the management performed by the second authority management unit 330 can also be said to be the management of the operation authority of the devices provided in the property given to the person.

[0158] The status information management unit 340 of the server 300 of the present embodiment includes a storage unit 341, a collection unit 342, an association unit 343, and a storage unit 344.

[0159] The device IDs of the devices connected to the control devices that communicate with the server 300 are stored in the storage unit 341. In the present embodiment, the storage unit 341 can be pre-configured in the server 300.

[0160] The collection unit 342 collects the status information of the devices connected to the control device via the control device connected to the server 300. Specifically, the collection unit 342 can extract the device IDs included in the status information and save them in the storage unit 341. In addition, the collection unit 342 can collect the status information from the devices corresponding to the device IDs included in the device ID group 345 of the storage unit 341 by referring to the device ID group 345 of the storage unit 341.

[0161] The association unit 343 refers to the association database 310 and extracts the property ID and user ID corresponding to the device ID of the device for which the status information has been collected. After that, the association unit 343 associates the status information with the extracted property ID and user ID as device information.

[0162] The storage unit 344 saves the device information associated by the association unit 343 to the device information database 320.

[0163] Next, refer to Figure 9A and Figure 9B The operation of the information processing system 100 of the present embodiment will be described.

[0164] Figure 9A It is the first timing chart (Part 1) for explaining the operation of the information processing system. Figure 9B It is also the first timing chart (Part 2) for explaining the operation of the information processing system. Figure 9A and Figure 9B show the processing when the user of the terminal device 400 views the device information of the property associated with the user.

[0165] In the present embodiment, the control unit 410 of the terminal device 400 displays the login screen (step S901). After the user inputs the email and password (step S902), the email and password are sent to the server 200 (step S903).

[0166] After the server 200 receives the email and password through the input receiving unit 271 of the first permission management unit 270, it refers to the authentication database 230 through the authentication unit 272 and authenticates the user (step S904).

[0167] Specifically, when there is authentication information consistent with the email and password in the authentication database 230, the result of the authentication of the user by the authentication unit 272 is successful authentication.

[0168] After the user authentication is successful, the authentication department 272 obtains the user ID from the authentication information that matches the email and password, and sends a notification including the user ID and a send request for requesting to send the user ID to the server 300 to the terminal device 400 through the output department 27 (step S905).

[0169] In the terminal device 400, after the control unit 410 receives the notification, it sends the user ID to the server 300 (step S906).

[0170] After the server 300 receives the user ID through the input receiving unit 331 of the second authority management department 330, it refers to the associated database 310 through the property list extraction unit 332 to obtain a list of property IDs corresponding to the user ID (property list) (step S907).

[0171] Next, the second authority management department 330 sends a notification including the property list and a send request for requesting to send the user ID to the server 200 to the terminal device 400 through the output department 336 (step S908).

[0172] It should be noted that in this embodiment, when there is no property associated with the user ID in the associated database 310, this situation can be notified to the terminal device 400.

[0173] In the terminal device 400, after the control unit 410 receives the above notification, it sends the user ID to the server 200 (step S909).

[0174] In the server 200, after the first authority management department 270 receives the user ID, it refers to the user information database 250, and the user information acquisition unit 273 acquires the user information including the user ID (step S910).

[0175] Next, the server 200 sends a notification including the acquired user information and a send request for requesting to send the role ID to the server 200 to the terminal device 400 through the output department 278 (step S911). It should be noted that at this time, the server 200 can determine the role ID included in the user information through the role determination unit 274 of the first authority management department 270, and include the determined role ID in the notification.

[0176] In the terminal device 400, after the control unit 410 receives the notification, it sends the role ID included in the user information to the server 200 (step S912).

[0177] In server 200, the first permission management unit 270 refers to the role database 260 through the role function determination unit 275 to obtain a menu list corresponding to the role ID (step S913). In other words, the role function determination unit 275 obtains a list of functions allowed to be used by the role determined by the role ID.

[0178] Next, the first permission management unit 270 sends, via the output unit 278, a notification including the obtained menu list, the completion of the login process (i.e., information indicating that the login process is completed), and a request for sending a property list to the server 200 to the terminal device 400 (step S914).

[0179] In the terminal device 400, after the control unit 410 receives this notification, it completes the login (step S915).

[0180] Next, it proceeds to Figure 9B Upon receiving the request for sending the property list, the control unit 410 of the terminal device 400 sends the property list to the server 200 (step S916).

[0181] In server 200, the first permission management unit 270 refers to the property database 210 through the property function determination unit 276 to determine a function list corresponding to each property ID included in the property list. After that, for each property, the first permission management unit 270 determines, through the user function determination unit 277, the functions in the function list corresponding to the property ID that correspond to the functions included in the menu list obtained in step S914 (step S917).

[0182] That is, in step S917, for each property ID included in the property list, the user function determination unit 277 determines the functions allowed to be used by the role of the user of the terminal device 400 among the functions used in the property determined by the property ID.

[0183] After that, the user function determination unit 277 sends, for each property, the list of functions determined in step S917 as the list of functions that the user of the terminal device 400 can use in each property to the terminal device 400 (step S918).

[0184] The list of functions that the user of the terminal device 400 can use in each property refers to the list of functions allowed to be used according to the user's role in the properties that the user can access.

[0185] Next, the first permission management unit 270 displays, via the output unit 278, the list of functions that the user can use (step S919).

[0186] Here, in the list of functions shown, it may include the functions that are permitted to be used in the properties accessible by the user determined in step S917, as well as the functions defined for the user's role regardless of the functions of the property.

[0187] Specifically, the functions defined for the user's role regardless of the functions of the property refer to, for example, the property registration function, the user registration function, etc. Whether the user can use such functions is determined only by the menu list obtained in step S914.

[0188] Figure 9A and Figure 9B In the example of, it is assumed that on the side of the terminal device 400, the list of functions displayed by step S919 includes the remote management function, and the remote monitoring function is selected (step S920).

[0189] After receiving this selection, the control unit 410 of the terminal device 400 displays a list of properties in which the remote monitoring function is included among the functions that can be used in the property (step S921).

[0190] Next, the control unit 410 of the terminal device 400 sends the property ID of the property selected as the object of remote monitoring from the list of properties to the server 300 (step S922).

[0191] In the server 300, the second permission management unit 330 refers to the association database 310 through the device list extraction unit 333, thereby extracting a list of device IDs associated with the property ID (device list) (step S923).

[0192] Next, the server 300 sends a notification including the device list and a send request for requesting the sending of the user ID to the server 300 to the terminal device 400 through the output unit 336 (step S924).

[0193] In the terminal device 400, after the control unit 410 receives this notification, it sends the user ID to the server 300 (step S925).

[0194] In the server 300, the second permission management unit 330 extracts the device list corresponding to the user ID through the device determination unit 334, and determines the control device that is consistent with the device list extracted by the device list extraction unit 333 (step S926).

[0195] Next, the second permission management unit 330 sends the device ID of the determined control device to the terminal device 400 through the output unit 336 (step S927).

[0196] In the terminal device 400, after the control unit 410 selects a certain device ID from the sent device IDs (step S928), the selected device ID is sent to the server 300 (step S929).

[0197] In the server 300, the second authority management unit 330 refers to the device information database 320 through the device information extraction unit 335, and extracts the status information of the device associated with the device ID (step S930).

[0198] Next, the server 300 sends a display instruction of the extracted status information to the terminal device 400 through the output unit 336 (step S931).

[0199] In the terminal device 400, after the control unit 410 receives the display instruction, a remote monitoring screen including the device information of the devices connected to the control device determined by the selected device ID is displayed (step S932).

[0200] It should be noted that in the example of FIG. 9, it is assumed that the process of determining the control device having consistency between the device list corresponding to the user ID and the device list corresponding to the property ID performed by the device determination unit 334 is executed in the server 300, but it is not limited thereto. The process performed by the device determination unit 334 may also be executed within the control unit 410.

[0201] Next, referring to Figure 10 An example of the remote monitoring screen displayed on the terminal device 400 in step S932 of FIG. 9 will be described.

[0202] Figure 10 It is the first figure showing a display example of the terminal device. Figure 10 The shown screen 411 is an example of the remote monitoring screen displayed by the control unit 410 of the terminal device 400.

[0203] The screen 411 has display areas 412, 413, and 414.

[0204] In the display area 412, information for indicating the selected property and information for indicating the control device are displayed.

[0205] It should be noted that Figure 10 in the example of, the property ID as the information for indicating the property is displayed, and the device ID as the information for indicating the control device is also displayed, but the information that can be displayed is not limited thereto. For example, in the display area 412, the name, address, etc. of the property as the information for indicating the property can be displayed. In addition, in the display area 412, for example, the model number, name, etc. of the control device as the information for indicating the control device can also be displayed.

[0206] The functions that can be used by the logged-in user are displayed in the display area 413. That is, the functions displayed in the display area 413 are a list of the functions displayed on the terminal device 400 in step S919 of FIG. 9.

[0207] Figure 10 In the example, the functions that can be used by the logged-in user are remote monitoring possible, device information viewing function, time setting function, power control function, property registration function, and user registration function. In addition, Figure 10 In the example, the remote monitoring function in the display area 413 is selected.

[0208] It should be noted that the time setting function can be, for example, a function for setting the operation start time and operation stop time of the device. In addition, the power control function can be, for example, a function for performing control such as controlling power consumption by setting the temperature of the device.

[0209] Figure 10 In the example, the property registration function and the user registration function among the functions displayed in the display area 413 are functions of the user's role defined independently of the functions of the property. In addition, the device information viewing function, the time setting function, and the power control function among the functions displayed in the display area 413 are functions determined based on the menu list obtained in step S914 of FIG. 9 and the function list of each property obtained in step S917.

[0210] As described above, in the present embodiment, the functions that can be used by the user's role and the functions that can be used in the property can be managed separately, and the functions that can be used by the user's role and the functions that can be used by the user in the property that the user can access can be displayed simultaneously.

[0211] Therefore, according to the present embodiment, the user does not need to care about the user's own role, the property that the user can access, etc. That is to say, the functions that the user can use, the property that the user can access, etc. can be presented to the user through simple operations.

[0212] The display area 414 includes display bars 415 and 416. A list of control devices is displayed in the display bar 415. The list of control devices displayed in the display bar 415 refers to, for example, a list of control devices determined by the device ID selected in step S927 of FIG. 9.

[0213] Figure 10 In the example, since the number of device IDs selected in the display area 412 is one, the name (control device 500) of the control device determined by the device ID displayed in the display area 412 can be displayed in the display bar 415, etc.

[0214] The status information of the device connected to the control device whose name and the like are displayed in the display column 415 is displayed in the display column 416. Specifically, for example, when a plurality of devices are connected to the control device, the status information can be displayed for each device in the display column 416.

[0215] Figure 10 In the example of, the display column 416 includes display columns 416a, 416b, 416c, and 416d, and the status information of the device is displayed in each of the display columns 416a, 416b, 416c, and 416d. From this, it can be seen that four devices are connected to the control device 500.

[0216] Next, refer to Figure 11 The other operations of the information processing system 100 will be described. Figure 11 This is the second timing chart for explaining the operations of the information processing system. Figure 11 The processing when the user of the terminal device 400 registers a new property is shown.

[0217] Figure 11 In, after the processing of steps S901 to S915 in FIG. 9 is completed, the execution continues from step S915.

[0218] Figure 11 The processing of steps S1101 to S1104 in is the same as the processing of steps S916 to S919 in FIG. 9, so the description thereof is omitted.

[0219] Figure 11 In, it is assumed that the list of functions available to the user displayed on the terminal device 400 in step S1104 includes the new property registration function, and the property registration function is selected (step S1105).

[0220] In the terminal device 400, after the property registration function is selected, the control unit 410 sends a request for issuing a new property ID to the server 300 (step S1106).

[0221] In the server 300, after the second authority management unit 330 receives the request, the new property ID is issued by the property ID issuing unit 338 (step S1107). Then, the second authority management unit 330 sends a notification indicating the display of the input screen including the newly issued property ID and property information to the terminal device 400 through the output unit 336 (step S1108).

[0222] In the terminal device 400, after the control unit 410 receives the notification, it displays an input screen for property information and accepts the input of property information implemented by the user (step S1109). After the control unit 410 receives a registration instruction for property information from the user, it sends the property information to the server 200 (step S1110).

[0223] In the server 200, after the first permission management unit 270 receives the property information, the update unit 279 saves (registers) the property information to the property database 210 (step S1111). Then, the first permission management unit 270 sends, via the output unit 278, a notification including the completion of the registration of the property information (i.e., information indicating that the registration of the property information is completed) and a transmission request for requesting the transmission of the new property ID and the user ID to the server 300 to the terminal device 400 (step S1112).

[0224] In the terminal device 400, after the control unit 410 receives the notification, it sends the new property ID and the user ID to the server 300 (step S1113).

[0225] In the server 300, the second permission management unit 330 associates the received new property ID and user ID through the ID storage unit 339 and saves (registers) them to the association database 310.

[0226] Then, the second permission management unit 330 sends, via the output unit 336, the completion of the registration of the new property ID and the user ID (i.e., information indicating that the registration of the new property ID and the user ID is completed) and a display request for requesting the display of the registration completion notification to the terminal device 400 (step S1115).

[0227] In the terminal device 400, after the control unit 410 receives the notification, it displays a notification indicating that the association between the user and the new property is completed (step S1116).

[0228] Then, referring to Figure 12 to Figure 11 an example of the input screen for property information displayed on the terminal device 400 in step S1109 will be described.

[0229] Figure 12 It is the second figure showing a display example of the terminal device. Figure 12 The shown screen 121 is an example of the input screen for property information displayed by the control unit 410 of the terminal device 400.

[0230] The screen 121 has display areas 122, 123, 124 and operation buttons 125.

[0231] The input fields including the property address in the display area 122, the input fields of the list of functions that can be used in the property, etc.

[0232] The input fields including the information for determining the control devices set in the property in the display area 123, etc. The input fields including the information for determining the users associated with the property in the display area 124, etc.

[0233] In this embodiment, after the operation button 125 in the screen 121 is operated, the property information input to the display area 122 is sent to the server 200 and saved in the property database 210 in association with the newly issued property ID.

[0234] In addition, after the saving of the property information to the property database 210 is completed, the information input to the display areas 123 and 124 is sent to the server 300 and stored in the association database 310 in association with the new property ID.

[0235] It should be noted that Figure 12 In, the input screen when registering a new property is taken as an example for illustration. However, for example, it can also be the screen when updating the property information of a property for which the property information has already been registered.

[0236] In this case, the already logged-in property information is displayed in the display area 122, and the operation button 125 is displayed as an update button.

[0237] After that, after performing the operation of updating the property information displayed in the display area 122 and operating the update button, the information associated with the existing (already existing) property ID can be updated. In addition, after the update button is operated, in the association database 310, the association is made between the existing property ID and the user for whom the information for determination in the display area 124 is displayed.

[0238] As described above, in this embodiment, the information used when the first permission management unit 270 of the server 200 manages and the information used when the second permission management unit 330 of the server 300 manages can be input through one input screen. For this reason, in this embodiment, the time and effort for newly registering property information can be reduced.

[0239] Next, referring to Figure 13 Other operations of the information processing system 100 will be described. Figure 13 It is the third timing diagram for explaining the operation of the information processing system. Figure 13 It shows the processing when a user of the terminal device 400 registers a new user.

[0240] Figure 13After the processing of steps S901 to S915 in FIG. 9 is completed, the execution continues from step S915. Figure 13 The processing of steps S1301 to S1304 is the same as the processing of steps S916 to S919 in FIG. 9, so the description thereof is omitted.

[0241] Figure 13 In the example of Figure 13 , it is assumed that the user registration function in the list of functions available to the user displayed on the terminal device 400 in step S1304 is selected (step S1305).

[0242] In the terminal device 400, after the user registration function is selected, the control unit 410 sends a request for issuing a new user ID to the server 300 (step S1306).

[0243] In the server 300, after the second authority management unit 330 receives the request, it issues a new user ID through the user ID issuing unit 337 (step S1307). Then, the second authority management unit 330 sends a notice indicating a display instruction of an input screen including the newly issued user ID and user information to the terminal device 400 through the output unit 336 (step S1308).

[0244] In the terminal device 400, after the control unit 410 receives the notice, it displays an input screen for user information and accepts the input of user information by the user (step S1309).

[0245] After the control unit 410 receives an instruction to register the user information input by the user, it sends the input user information to the server 200 (step S1310).

[0246] In the server 200, after the first authority management unit 270 receives the user information including the newly issued user ID, it saves (registers) the user information to the user information database 250 through the update unit 279 (step S1311).

[0247] Then, the first authority management unit 270 sends a notice indicating the completion of the registration of the user information to the terminal device 400 through the output unit 278 (step S1312).

[0248] In the terminal device 400, after the control unit 410 receives an instruction to register the new user ID from the user (step S1313), it sends the newly issued user ID and the property ID included in the property list obtained in step S908 of FIG. 9 to the server 300 (step S1314).

[0249] In server 300, the second authority management department 330 saves (registers) the newly issued user ID and property ID received in association with each other to the association database 310 through the ID saving department 339 (step S1315).

[0250] Next, the second authority management department 330 sends, via the output department 336, the completion of the registration of the newly issued user ID and property ID (i.e., information indicating that the registration is completed) and a display request for a notification indicating the completion of the registration to the terminal device 400 (step S1316).

[0251] In the terminal device 400, after receiving this notification, the control department 410 causes a notification indicating the completion of the association between the new user and the property to be displayed (step S1317).

[0252] Figure 14 It is the third figure showing an example of the display of the terminal device. Figure 14 The shown screen 141 is an example of an input screen for user information displayed by the control department 410 of the terminal device 400.

[0253] Input fields corresponding to the items of information possessed by the user information database 250 are provided on the screen 141.

[0254] In addition, for example, an operation button 152 is displayed on the screen 141. After the operation button 142 is operated, the user information input in the input field can be sent to the user information database 250.

[0255] As described above, in the information processing system 100 of the present embodiment, the server 200 manages the authorities for the functions that can be used in the property for each person, and the server 300 manages the authorities for referring to the property-related information for each person.

[0256] Therefore, in the present embodiment, the management of the authorities (usage authorities) for the functions that can be used in the property for each person and the management of the authorities (reference authorities) for referring to the property-related information for each person can be performed independently of each other, and thus the management of the authorities can be easily performed.

[0257] For this reason, if the present embodiment is applied, for example, multiple servers 200 for managing the authorities for the functions that can be used in the property for each person can be provided, and in each server 200, the management of the authorities for the functions that can be used in the property for each person can also be performed separately.

[0258] In this way, for example, in a certain server 200, the permissions of the functions that can be used in the property can be managed according to each person who maintains the equipment, while in other servers 200, the permissions of the functions that can be used in the property can be managed according to each person who sells the equipment.

[0259] In this case, the permissions of each person to refer to the property-related information are also comprehensively (unified) managed in the server 300. Therefore, even when the permissions managed by the server 200 change, the permissions indicating whether each person can access the property can be maintained without changing them.

[0260] The present invention has been described based on the embodiments, but the present invention is not limited to the above embodiments, and various modifications and changes can be made within the technical scope described in the claims.

[0261] In addition, this international application claims the priority based on Japanese Patent Application No. 2019-238426 filed on December 27, 2019, and incorporates all the contents of Japanese Patent Application No. 2019-238426 into this international application.

[0262] [Description of Reference Numerals]

[0263] 100 Information processing system

[0264] 200, 300 Servers

[0265] 210 Property database

[0266] 220 Person database

[0267] 230 Authentication database

[0268] 250 User information database

[0269] 260 Role database

[0270] 270 First permission management department

[0271] 310 Association database

[0272] 320 Equipment information database

[0273] 330 Second permission management department

[0274] 340 Status information management department

[0275] 400 Terminal device

[0276] 410 Control section.

Claims

1. An information processing system, comprising: An associated database that associates people with properties; A person database that associates a person, the role of the person, and the functions that the person can use; A property database that associates properties with the functions used in the properties; A first authority management unit that manages the functions that can be used in the properties according to each person by using the person database and the property database; And A second authority management unit that manages the properties to which information can be accessed according to each person by using the association database, The person database includes a user information database that associates user identification information for determining a person with the role assigned to the person; After receiving the input of the user identification information included in the authentication information, the second authority management unit refers to the association database and extracts a list of properties corresponding to the person determined by the user identification information; The first authority management unit extracts the role of the determined person by referring to the user information database, and extracts a list of functions that the determined person can use from the functions used in the properties included in the list of properties by referring to the person database.

2. The information processing system according to claim 1, comprising: A first server having the person database and the property database; and A second server having the associated database.

3. The information processing system according to claim 2, wherein, In the association database, properties are associated with the devices installed in the properties; The second server has: A storage unit that stores device identification information for determining the devices installed in the properties; A collection unit that collects status information indicating the status of the devices from the devices configured in each property; And An association unit that associates the status information, the person, and the property based on the device identification information included in the status information, the association database, and the storage unit.

4. The information processing system according to claim 2 or 3, comprising: A plurality of the first servers, wherein, Each of the plurality of first servers communicates with the second server.

5. The information processing system according to claim 1, wherein, The function is a function related to the operation of the devices installed in the properties included in the list of properties.

6. The information processing system according to claim 5, comprising: An output unit that displays an operation screen for operating the device on a terminal device.

7. The information processing system according to any one of claims 1 to 3, wherein, In the association database, the user identification information for determining a person, the property identification information for determining a property, the device identification information for determining the devices installed in the property, and the area identification information for determining the area where the devices are configured in the property are associated.

8. The information processing system according to any one of claims 1 to 3, wherein, The first authority management unit determines whether the functions that the determined person can use include the registration of a new property; When the functions that the determined person can use include the registration of a new property, the second authority management unit issues property identification information for determining the new property and stores the property identification information in association with the user identification information of the determined person in the association database.

9. The information processing system according to any one of claims 1 to 3, wherein, After receiving a request for issuing new user identification information, the second authority management unit issues new user identification information and stores the new user identification information in association with the property identification information of the properties included in the list of properties in the association database.

10. A method performed by an information processing system, wherein, The information processing system performs the following processing: Using a person database that associates a person, the role of the person, and the functions that the person can use, and a property database that associates properties with the functions used in the properties, manage the functions that can be used in the properties according to each person; and Using an associated database that associates people with properties, manage the properties to which information can be accessed for each person. The person database includes a user information database that associates user identification information used to identify a person with the roles assigned to the person. The information processing system also performs the following processing: After accepting the input of the user identification information included in the authentication information, refer to the associated database and extract a list of properties corresponding to the person determined by the user identification information; and By referring to the user information database, extract the role of the determined person, and by referring to the person database, extract a list of functions that the determined person can use from the functions used in the properties included in the list of properties.

11. A program product that causes a computer to perform the following processing: Using a person database that associates a person, the role of the person, and the functions that the person can use, and a property database that associates a property and the functions used in the property, manage the permissions for the functions that can be used in the property for each person; and Using an association database that associates a person and a property, manage the properties to which information can be accessed for each person, The person database includes a user information database that associates user identification information for determining a person and the role assigned to the person, Cause the computer to further perform the following processing: After accepting the input of the user identification information included in the authentication information, refer to the association database and extract a list of properties corresponding to the person determined by the user identification information; and By referring to the user information database, extract the role of the determined person, and by referring to the person database, extract a list of functions that the determined person can use from the functions used in the properties included in the list of properties.

Citation Information

Patent Citations

  • Access control system

    JP2002091816A

  • Connected device rights management administration

    US20180063150A1