Equipment maintenance management system
By adopting the authentication key of the master-slave relationship to limit the communication in the equipment maintenance management system, the equipment information security problem is solved and the flexible provision and security management of information are achieved.
Patent Information
- Application Number
- CN202080103289.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-27
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2040-08-27
AI Technical Summary
In the existing equipment maintenance and management system, the information of multiple devices is centrally managed by the management center, which makes it difficult to ensure information security. Specific device users may view the information of other devices, making it impossible to ensure information security.
A remote processing device is used to limit communication using authentication keys with a master-slave relationship. The scope of information provision is determined according to the type of authentication key and the master-slave relationship, ensuring information security while providing the information required by the communication object.
It achieves the flexibility of providing device information according to the different permissions of the communication object while ensuring information security, thereby improving the confidentiality and security of information.
Smart Images

Figure CN115867911B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an equipment maintenance management system including a remote processing device that aggregates information on a plurality of equipment. Background Art
[0002] Conventionally, equipment maintenance management systems centrally manage information on multiple devices (e.g., air conditioners) and repair or replace them before they fail. In some cases, such systems utilize cloud-based servers to acquire data on power consumption or power waveforms for multiple devices installed in multiple buildings (e.g., see Patent Document 1). The server in the equipment maintenance management system disclosed in Patent Document 1 is configured to evaluate the deterioration of each device based on the acquired data and prioritize repair or replacement.
[0003] Patent Document 1: International Publication No. 2017 / 047721
[0004] In the equipment maintenance management system disclosed in Patent Document 1, information on multiple devices is managed collectively by a management center. Therefore, sometimes people who use information on a specific device, such as device users or maintenance personnel, can view information on other devices, resulting in a problem of not being able to ensure information security. Summary of the Invention
[0005] The present disclosure has been made to solve the above-mentioned problems, and an object of the present disclosure is to provide an equipment maintenance management system that can ensure information security and provide information required by information users of specific equipment.
[0006] The equipment maintenance management system involved in the present disclosure comprises: multiple devices that send information related to their own operation and the presence or absence of abnormalities; and a remote processing device that obtains and stores the above information of each of the multiple devices, the remote processing device uses at least one type of authentication key with a master-slave relationship to limit communication, and the remote processing device uses a first communication device that is pre-assigned with the above authentication key to become the master, and a second communication device that is pre-assigned with the above authentication key to become the slave of the above first communication device as communication objects for communication with at least some of the multiple devices. When communicating, the remote processing device determines the scope of the above information to be provided based on the type of the above authentication key possessed by the above communication object and the above master-slave relationship.
[0007] According to the present disclosure, the device providing information to a communication partner and the level of disclosure of that information can be varied based on the type of authentication key possessed by the communication partner of the remote processing device, the presence or absence of a specific authentication key, and the master-slave relationship of the authentication keys. This allows the communication partner to be provided with the information it needs while ensuring information security. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] Figure 1 This is a diagram schematically showing the configuration of the equipment maintenance management system according to the first embodiment.
[0009] Figure 2 This is a diagram showing an example of the equipment maintenance management system according to the first embodiment.
[0010] Figure 3 This is a functional block diagram showing the functions of the remote processing device of the equipment maintenance management system according to the first embodiment.
[0011] Figure 4 It means in Figure 2 A diagram showing the relationship between the authentication keys and devices owned by the owner and user in the example.
[0012] Figure 5 It means in Figure 2 A diagram showing the range of information that can be obtained using the authentication key in the example.
[0013] Figure 6 This is a diagram showing an example of the equipment maintenance management system according to the second embodiment.
[0014] Figure 7 It means in Figure 6 In the example of , a diagram shows the relationship between the authentication keys of the user, the provider, and the administrator.
[0015] Figure 8 It means in Figure 6 A diagram showing the range of information that can be obtained using the authentication key in the example.
[0016] Figure 9 This is a diagram showing how authentication keys are exchanged in the equipment maintenance management system according to the third embodiment.
[0017] Figure 10 Yes Figure 9 A diagram showing the relationship between the authentication keys and devices owned by the owner and user before and after authentication key exchange.
[0018] Figure 11 This is a diagram showing how authentication keys are replaced in the equipment maintenance and management system according to the third embodiment.
[0019] Figure 12 Yes Figure 11 The diagram shows the relationship between the authentication keys and devices owned by the owner and user before and after the authentication key is replaced.
[0020] Figure 13 This is a flowchart showing the processing of the exchange request involved in the third embodiment.
[0021] Figure 14 This is a flowchart showing the processing of the replacement request involved in the third embodiment.
[0022] Figure 15 This is a diagram for explaining the change permission setting in the equipment maintenance management system according to the fourth embodiment.
[0023] Figure 16 This is a diagram showing an example of a device maintenance management system according to the fifth embodiment.
[0024] Figure 17 Yes Figure 16 A diagram showing an example of a visualization mechanism in an equipment maintenance management system.
[0025] Figure 18 It means in Figure 16 A diagram showing the relationship between search symbols, authentication keys, and various information in an equipment maintenance management system. DETAILED DESCRIPTION
[0026] Implementation method 1.
[0027] Figure 1 This is a schematic diagram showing the structure of the equipment maintenance management system according to the first embodiment. The equipment maintenance management system 100 collects information on a plurality of equipment 1 installed in, for example, a chain of convenience stores with a plurality of stores or a commercial building including a variety of facilities, and provides the collected information under certain conditions. Figure 1 As shown, the equipment maintenance management system 100 includes a plurality of equipment 1 and a remote processing device 2 such as a cloud server. Figure 1 The schematic configuration of the equipment maintenance management system 100 will be described.
[0028] The device 1 is, for example, a household appliance such as an indoor air conditioner, a water heater, a television, and a refrigerator, or a commercial device such as a commercial air conditioner and a refrigerator. Figure 1 In the example shown, the equipment maintenance management system 100 includes multiple types of equipment 1 such as indoor air conditioners and water heaters. Alternatively, the equipment maintenance management system 100 may include multiple devices of a single type.
[0029] The device 1 has a communication mechanism that performs periodic communication to send data to the remote processing device 2 at predetermined intervals. In addition, the device 1 implements communication based on external requests such as the remote processing device 2 and the communication device 20b (such as a smartphone). Specifically, the device 1 sends information related to its own operation and the presence or absence of abnormalities to the remote processing device 2. The communication mechanism of the device 1 is composed of, for example, a communication interface that performs wireless communication based on standards such as Wi-Fi, LTE (Long Term Evolution), 5G or Bluetooth (registered trademark). In addition, the communication mechanism of the device 1 is not limited to the above-mentioned cases, and may also be, for example, a telephone line such as ADSL, a wired LAN (Local Area Network) or a PLC (Programmable Logic Controller).
[0030] Remote processing device 2 collects information from device 1, analyzes it, and provides it. Remote processing device 2 may be, for example, a cloud server providing cloud services. More specifically, remote processing device 2 is comprised of one or more computers. The number of computers comprising remote processing device 2 can be determined based on the required processing and communication load.
[0031] The remote processing device 2 communicates with a plurality of devices 1 and collects information about each device 1. The information about the device 1 includes, for example, operating information about the device 1 and information about whether or not there are any abnormalities in the device 1. In addition, the remote processing device 2 communicates with a communication device 20a ( Figure 6 ) to transmit information about multiple devices 1. Furthermore, the remote processing device 2 communicates with the communication device 20b owned by the owner 3 of the device 1 and the user 4 of the device 1, respectively, and discloses the collected information related to the multiple devices 1 to a provider 5, such as a maintenance practitioner or a service practitioner, under certain restrictions.
[0032] The remote processing device 2 has an authentication function and discloses information collected from multiple devices 1 based on the authentication keys 30 possessed by the administrator 6 of the remote processing device 2, the user 4 of the device 1, the owner 3 of the device 1, and the communication targets 5. The authentication involving the remote processing device 2 can use the authentication keys 30 having a master-slave relationship. The device 1 to be disclosed and the scope of the information to be provided, such as the disclosure level of the information, can be determined based on the type of authentication key 30 previously assigned to the communication targets of the remote processing device 2 and the master-slave relationship. The remote processing device 2 stores information on the administrator 6 of the remote processing device 2, the user 4 of the device 1, the owner 3 of the device 1, and the communication targets 5. When storing the information on the administrator 6 of the remote processing device 2, the user 4 of the device 1, the owner 3 of the device 1, and the communication targets 5, the remote processing device 2 assigns the authentication keys 30 to these persons.
[0033] The remote processing device 2 analyzes the collected information about each device 1 and, based on the analysis results, issues a command to interrupt, restart, or perform an emergency stop on the device 1. For example, if the analysis of the information about a specific device 1 determines that it has a malfunction or failure, the remote processing device 2 issues a command to interrupt the operation of that device 1.
[0034] Owner 3 is the owner of device 1 and may not be located at the location where device 1 is installed. Owner 3 can be the owner of multiple devices 1. Figure 1 In the example shown, owner 3 is the owner of four devices 1 .
[0035] The user 4 is a user of the device 1 and may be the same person as the owner 3. In addition, the user 4 may be a user of a plurality of devices 1 owned by a plurality of owners 3.
[0036] Target 5 is a person who obtains information related to device 1 from remote processing device 2 and utilizes it, such as a maintenance worker or a service provider. A maintenance worker performs maintenance and inspections on device 1. A service provider coordinates device 1 with the service provider's services (e.g., power consumption management services or health-related life support services) based on information related to device 1. Maintenance workers and service providers may each be self-employed individuals, such as gig workers.
[0037] In this disclosure, a communication device 20a or 20b that has been pre-assigned an authentication key 30 and becomes a master with respect to device 1 is referred to as a first communication device, and a communication device 20a or 20b that has been pre-assigned an authentication key 30 and becomes a slave of the first communication device is referred to as a second communication device. Specifically, of the first and second communication devices assigned the same type of authentication key 30, the first communication device has higher authority than the second communication device.
[0038] Generally, the administrator 6 of the remote processing device 2 and the owner 3 of the device 1 are granted higher authority than the user 4 of the device 1 and the information recipient 5. In this case, the communication device 20a owned by the administrator 6 and the communication device 20b owned by the owner 3 can be used as the first communication device, and the communication device 20b owned by the user 4 and the communication device 20b owned by the information recipient 5 can be used as the second communication device.
[0039] However, if user 4 of device 1 uses device 1 for a long time, there may be concerns that user 4's lifestyle or consumption trends may be determined based on information from device 1, and disclosure of some of this information to owner 3 of device 1 and administrator 6 of remote processing device 2 may be undesirable. In such cases, disclosure of information to recipient 5 is also necessary for maintenance purposes. In the present disclosure, since the scope of information to be provided is determined through communication using authentication keys 30 having a master-slave relationship, it is also possible to assign higher permissions to user 4 of device 1 than to owner 3 based on the master-slave relationship of authentication keys 30.
[0040] Authentication keys 30 have a master-slave relationship, and by using authentication keys 30 in communication, communication is restricted based on the type of authentication keys 30 and the master-slave relationship. Specifically, authentication keys 30 are used to restrict communication between device 1 and remote processing device 2, between remote processing device 2 and communication device 20b owned by recipient 5, owner 3, or user 4, and between remote processing device 2 and communication device 20a owned by administrator 6. Furthermore, communication devices 20a and 20b can communicate directly with each other, or with device 1.
[0041] A master-slave relationship refers to a relationship in which the permissions granted by the master authentication key 30 include all permissions granted by the slave authentication key 30. Authentication keys 30 in a master-slave relationship constitute a master and a slave, each with different levels of disclosure and permissions. In the following description, the master authentication key 30 may be referred to as the master key, and the slave authentication key may be referred to as the slave key. Furthermore, the person who possesses the master authentication key 30 may be referred to as the master key owner, and the person who possesses the slave authentication key 30 may be referred to as the slave key owner.
[0042] Figure 2 FIG. 1 is a diagram showing an example of a device maintenance management system according to Embodiment 1. Figure 2 In the example shown, owner 3a owns a device group Ga consisting of two devices 1a, owner 3b owns a device group Gb consisting of two devices 1b, and user 4 uses four devices 1a and 1b of a device group Gt consisting of device group Ga and device group Gb. Figure 2 As shown, the authentication key 30a having a master-slave relationship is given in advance to the owner 3a and the user 4, and the authentication key 30b having a master-slave relationship is given in advance to the owner 3b and the user 4.
[0043] Figure 3 1 is a functional block diagram showing the functions of the remote processing device of the equipment maintenance management system involved in embodiment 1. Figure 3 As shown, the remote processing device 2 includes a communication unit 21 , an information acquisition unit 22 , a communication setting unit 23 , an information management unit 24 , a control unit 25 , and a storage unit 26 .
[0044] The remote processing device 2 is composed of dedicated hardware or a CPU (Central Processing Unit) that executes programs stored in a memory. The CPU is also called a central processing unit, a processing unit, an arithmetic unit, a microprocessor, a microcomputer, or a processor.
[0045] When remote processing device 2 is dedicated hardware, for example, a single circuit, a complex circuit, an ASIC (application specific integrated circuit), an FPGA (field-programmable gate array), or a combination thereof may constitute remote processing device 2. Each functional unit implemented by remote processing device 2 may be implemented by independent hardware or by a single piece of hardware.
[0046] When remote processing device 2 is a CPU, the functions executed by remote processing device 2 are implemented using software, firmware, or a combination of software and firmware. Software and firmware are described as programs and stored in memory. The CPU reads and executes the programs stored in memory to implement the functions of remote processing device 2. Memory, for example, is non-volatile or volatile semiconductor memory such as RAM, ROM, flash memory, EPROM, or EEPROM.
[0047] A part of the functions of the remote processing device 2 may be realized by dedicated hardware, and a part may be realized by software or firmware.
[0048] based on Figure 3 The communication unit 21, information acquisition unit 22, communication setting unit 23, information management unit 24, control unit 25, and storage unit 26 that constitute the functional units of the remote processing device 2 will be described. The control unit 25 controls the operations of the information acquisition unit 22, communication setting unit 23, and information management unit 24. The control unit 25 also analyzes information of a plurality of devices 1 and sends commands to the devices 1 based on the analysis results.
[0049] The communication unit 21 is connected to each of the plurality of devices 1 via a network 10 such as the Internet to transmit and receive data. Similarly, the communication unit 21 is connected to the device group Ga ( Figure 2 ) owner 3a and device group Gb( Figure 2 ) are connected to the respective communication devices 20b (not shown) of the owners 3b of the devices to transmit and receive data. In addition, the communication unit 21 communicates with the device group Gt ( Figure 2 ) of the user 4 having the communication device 20b ( Figure 1 ) is connected to transmit and receive data. In addition, the communication unit 21 communicates with the communication device 20a ( Figure 6 ) connection to send and receive data. Figure 3 For the sake of explanation, the communication devices 20a and 20b are omitted, and the communication partners of the remote processing apparatus 2 are represented as owners 3a and 3b, users 4, recipients 5, or managers 6 who possess them.
[0050] The information acquisition unit 22 acquires information about a plurality of devices 1. The information acquisition unit 22 receives the information about the device 1 transmitted from each device 1 at a predetermined timing via the communication unit 21. Alternatively, the information acquisition unit 22 may be configured to transmit a request to each device 1 to transmit the information about the device 1 via the communication unit 21 at a predetermined timing, and receive the information transmitted from the device 1 in response to the request. The information about the plurality of devices 1 received by the information acquisition unit 22 is stored in the storage unit 26.
[0051] The communication setting unit 23 sets and changes restrictions on communication based on a setting request received from the outside. The storage unit 26 stores restrictions on communication for each communication partner.
[0052] The information management unit 24 manages data sent and received through communication with the outside. For example, when receiving a request for information disclosure from a communication partner, the information management unit 24 manages the data based on the authentication keys 30a and 30b ( Figure 2 ) to determine the scope of information to be disclosed. The information management unit 24 determines the scope of information to be disclosed based on the authentication keys 30a and 30b ( Figure 2 ) to determine the scope of information to be disclosed, the settings pre-stored in the storage unit 26 are referred to. The information management unit 24 extracts the information of the determined scope from the storage unit 26 and transmits it to the communication partner via the communication unit 21.
[0053] The storage unit 26 stores information on a plurality of devices 1 acquired by the information acquisition unit 22 for each device 1. The storage unit 26 also stores a first restriction table 81 and a second restriction table 82 defining restrictions.
[0054] Figure 4 It means in Figure 2 In the example of FIG, the relationship between the authentication key and the device owned by the owner and the user is shown. The owner 3a is the authentication key 30a ( Figure 2 ) is the master of the device 1a. The owner 3b is the authentication key 30b ( Figure 2 ) is the master key owner of device 1b. User 4 is the master key owner of two authentication keys 30a and 30b ( Figure 2 ) has a lower authority than owner 3a for device 1a, and has a lower authority than owner 3b for device 1b. The first restriction table 81 specifies the relationship between the master key owner and the slave key owner and the device 1 whose information is disclosed.
[0055] Figure 5 It means in Figure 2 The following is a diagram showing the range of information that can be obtained by the authentication key in the example of FIG. The following description assumes that the information of device 1 includes multiple information A to information C. For the authentication key 30a ( Figure 2 ) master key, can obtain all the information A to information C related to the device 1a, for the authentication key 30a ( Figure 2 ) can only obtain information C among the information A to C related to the device 1a. Figure 2) master key, can obtain all the information A to C related to the device 1b, for the authentication key 30b ( Figure 2 ) can only obtain information C among the information A to C related to the device 1b. The second restriction table 82 defines the relationship between the master key, the slave key, and the disclosure level of the information.
[0056] Next, refer to Figures 2-3 The operation of the equipment maintenance management system 100 will be described. Figure 3 As shown, device 1 periodically transmits information about its own operation and the presence or absence of abnormalities to remote processing device 2. In addition to periodic communications, device 1 also transmits its own information based on requests from remote processing device 2, owners 3a, 3b, users 4, recipients 5, or administrators 6. Furthermore, device 1 interrupts, restarts, or performs an emergency stop based on its own information or instructions received from remote processing device 2.
[0057] The remote processing device 2 collects information of a plurality of devices 1 connected via a network. Figure 2 As shown, the remote processing device 2 transmits the collected information of the plurality of devices 1 to the owners 3 a and 3 b and the user 4 based on the authentication keys 30 a and 30 b.
[0058] Remote processing device 2 transmits all of information A through C from device 1a to owner 3a, who possesses the master key for authentication key 30a. Furthermore, device 1a's information is not transmitted to owner 3b, who does not possess authentication key 30a. Furthermore, remote processing device 2 transmits all of information A through C from device 1b to owner 3b, who possesses the master key for authentication key 30b. Furthermore, device 1b's information is not transmitted to owner 3a, who does not possess authentication key 30b. Furthermore, remote processing device 2 transmits only information C from device 1a and device 1b to user 4, who possesses authentication key 30a and a slave key for authentication key 30b.
[0059] Among them, Figure 1 In this way, when the authentication key 30 is given to the target 5, the target 5 can also obtain information about the device 1 based on the authentication key 30 it has, and can provide services such as maintenance based on the obtained information. Figure 5 The second restriction table 82 shown is an example. The types and quantities of information (e.g., information A to information C) that are restricted from being disclosed are not limited. Figure 1 Personal information about the user 4 or owner 3 of the device 1 shown can also be the subject of restrictions.
[0060] Although based on Figure 2The case where owners 3a and 3b are master key owners and user 4 is a slave key owner has been described, but the combination of master key owners and slave key owners is not particularly limited to this. Figure 1 As shown, the type and subordinate relationship of the authentication key 30 assigned can be determined according to the type of device 1 or the wishes of the user 4. Figure 2 For example, user 4 can be designated as the master key owner, and owners 3a and 3b as slave key owners. Furthermore, for example, regarding the device group Ga owned by owner 3a, owner 3a can be designated as the master key owner of authentication key 30a, and provision object 5 can be designated as the slave key owner of authentication key 30a. Furthermore, for example, regarding the device group Gt used by user 4, user 4 can be designated as the master key owner of authentication keys 30a and 30b, and provision object 5 can be designated as the slave key owner of authentication keys 30a and 30b. Furthermore, for example, regarding the device group Gt from which information is collected by the remote processing device 2 managed by administrator 6, owner 3, user 4, or provision object 5 can be designated as the slave key owner of authentication keys 30a and 30b.
[0061] As described above, the equipment maintenance management system 100 involved in embodiment 1 includes: multiple devices 1 that transmit information related to their own operation and the presence or absence of abnormalities; and a remote processing device 2 that obtains and stores information about each of the multiple devices 1. The remote processing device 2 uses at least one type of authentication key 30 with a master-slave relationship to limit communication. The remote processing device 2 communicates with a first communication device that is pre-assigned with an authentication key 30a and serves as a master for at least a portion of the multiple devices 1a, and a second communication device that is pre-assigned with an authentication key 30a and serves as a slave of the first communication device as communication partners. During communication, the remote processing device 2 determines the scope of information to be provided based on the type of authentication key 30 possessed by the communication partner and the master-slave relationship.
[0062] Thus, the device to which information is provided to the communication partner and the level of disclosure of the information can be varied depending on the type of authentication key 30 possessed by the communication partner of the remote processing device 2, the presence or absence of a specific authentication key 30, and the master-slave relationship of the authentication keys 30. Therefore, the information required by the communication partner can be provided while ensuring information security.
[0063] The first communication device and the second communication device include at least two of the communication device 20a owned by the manager 6 and the communication device 20b owned by the owner 3, user 4 or maintenance person (provided object 5) of some of the devices 1.
[0064] By assigning authentication keys 30 to two or more communication partners, it is possible to more flexibly configure settings to provide information tailored to the communication partners, compared to conventional configurations that do not require independent configuration depending on the communication partner. For example, in a commercial building with multiple facilities within a single building, multiple owners may own different equipment groups within the building, and regular inspections may be performed for each equipment group. In this case, the target equipment can be restricted for each owner, facilitating management.
[0065] Furthermore, one or more first communication devices (e.g., communication devices 20b of owners 3a and 3b, respectively) are pre-assigned with different authentication keys 30a and 30b, which serve as masters of different device groups Ga and Gb among multiple devices 1a and 1b. Furthermore, one or more second communication devices (e.g., communication device 20b of user 4) are pre-assigned with different authentication keys 30a and 30b, which serve as slaves of different device groups Ga and Gb among multiple devices 1a and 1b. The information of device 1 includes first information (e.g., information C) and second information (e.g., information A and information B). The remote processing device 2 discloses the first information related to the first device group (device group Ga) and the second information to the first communication device (e.g., communication device 20b of owner 3a) that has been assigned the authentication key 30a serving as the master of the first device group (device group Ga). Furthermore, the remote processing device 2 discloses the first information related to the first device group (device group Ga) to a second communication device (e.g., communication device 20b of user 4) assigned the authentication key 30a that makes it a subordinate of the first device group (device group Ga), but does not disclose the second information. Furthermore, the remote processing device 2 discloses the first information and second information of the second device group (device group Gb) to a first communication device (e.g., communication device 20b of owner 3b) assigned the authentication key 30b that makes it a master of the second device group (device group Gb). Furthermore, the remote processing device 2 discloses the first information of the second device group (device group Gb) to a second communication device (e.g., communication device 20b of user 4) assigned the authentication key 30b that makes it a subordinate of the second device group (device group Gb), but does not disclose the second information.
[0066] Implementation method 2.
[0067] Figure 6 This is a diagram showing an example of the equipment maintenance management system according to the second embodiment. Figure 7 It means in Figure 6 In the example of FIG, a diagram shows the relationship between the authentication keys of the user, the recipient, and the administrator. Figure 8 It means in Figure 6A diagram showing the range of information that can be obtained using the authentication key in the example. Figures 6 to 8 The equipment maintenance management system 100 according to the second embodiment will be described.
[0068] The equipment maintenance management system 100 of the second embodiment differs from the first embodiment in that the authentication keys 30 (30a, 30b, 30c) having a master-slave relationship have a hierarchical structure. Since the rest of the configuration and operation are the same as those of the first embodiment, detailed description is omitted here.
[0069] like Figure 6 as well as Figure 7 As shown, for the same device 1, the administrator 6 has an authentication key 30a that serves as the master, the user 4 has an authentication key 30b that serves as the slave of the administrator 6, and the recipient 5 has an authentication key 30c that serves as the slave of the user 4. Specifically, in Embodiment 2, a three-level hierarchical structure is constructed for the authentication keys 30a, 30b, and 30c by combining two sets of authentication keys in a master-slave relationship. Alternatively, a hierarchical structure of four or more levels may be formed by combining three or more sets of authentication keys.
[0070] Here, the public level of the highest authentication key 30a is set to 0, and the levels below it are defined as 1, 2, ..., and as the level increases, the restrictions on information acquisition become stricter. Figure 8 As shown, the second restriction table 82 defines the range of information that can be disclosed for each disclosure level. For authentication key 30a at level 0, all of information A through C can be obtained. For authentication key 30b at level 1, only information B through C can be obtained. For authentication key 30c at level 2, only information C can be obtained.
[0071] also, Figure 8 The second restriction table 82 shown is an example of information that is restricted from being disclosed (in Figure 8 The types and quantities of information A to information C are not limited thereto. Figure 6 In the description, the case where the authentication keys 30a, 30b, and 30c having a hierarchical structure are given to the manager 6, the user 4, and the recipient 5 is described, but the owner 3 can also be treated in the same manner.
[0072] As described above, in the device maintenance management system 100 according to the second embodiment, the authentication keys 30 a , 30 b , and 30 c having a master-slave relationship form a hierarchical structure of three or more levels with different disclosure levels for information related to some devices 1 .
[0073] As a result, the disclosure range of information on the same device 1 can be set for each communication partner in a more detailed manner than before, thereby reducing unnecessary disclosure of information and improving the confidentiality of information security.
[0074] Implementation method 3.
[0075] Figure 9 This is a diagram showing how authentication keys are exchanged in the equipment maintenance management system according to the third embodiment. Figure 10 Yes Figure 9 A diagram showing the relationship between the authentication keys and devices owned by the owner and user before and after authentication key exchange. Figure 11 This is a diagram showing how authentication keys are replaced in the equipment maintenance and management system according to the third embodiment. Figure 12 Yes Figure 11 The diagram shows the relationship between the authentication key and the device owned by the owner and user before and after the authentication key replacement. Figures 9 to 12 The equipment maintenance management system 100 according to the third embodiment will be described.
[0076] The equipment maintenance management system 100 of Embodiment 3 differs from Embodiment 1 in that it is possible to change at least one of the master key owner and the slave key owner of the authentication keys 30a and 30b by obtaining permission from the master key owner, that is, the person who holds the master authentication keys 30a and 30b. Since the rest of the structure is the same as that of Embodiment 1, a detailed description thereof will be omitted here.
[0077] Between owner 3, user 4, provider 5 and manager 6 ( Figure 1 ), the master-slave relationship of being able to exchange authentication keys 30a, 30b. Here, Figure 9 As shown, exchanging the master-slave relationship of the authentication key 30a means exchanging the preset master key owner and slave key owner for the authentication key 30a. Figure 9 In the example shown, the master-slave relationship of the authentication key 30a is exchanged. Specifically, Figure 10 As shown, in the storage unit 26 ( Figure 3 ), the master-slave relationship between the owner 3a, who was the master of the device 1a before the exchange, and the user 4, who was the slave of the device 1a before the exchange, is changed. After the exchange, the master of the device 1a becomes the user 4, and the slave becomes the owner 3a. When the master-slave relationship of the authentication key 30a is exchanged, the first restriction table 81 ( stored in the storage unit 26) is updated by the communication setting unit 23 of the remote processing device 2. Figure 3 ), and according to the changed master-slave relationship, the authentication key 30a is given to the person who changed the setting.
[0078] In addition, it is possible to replace the master key owner, that is, the person who has the authentication keys 30a and 30b that become the master, or the slave key owner, that is, the person who has the authentication keys 30a and 30b that become the slave. Here, replacing the master key owner means changing the pre-set master key owner to another person, and replacing the slave key owner means changing the pre-set slave key owner to another person. Figure 11 In the example shown, the master key owner of the authentication key 30b is replaced. Figure 12 As shown, in the storage unit 26 ( Figure 3 ) in the first restriction table 81 of the device 1b, the master of the device 1b is replaced by the slave owner 3b with another owner 3c. The slave of the device 1b does not change before and after the replacement. After the master key owner of the authentication key 30b is replaced, the master of the device 1b is the owner 3c, and the slave of the device 1b is the user 4. When the master key owner or the slave key owner of the authentication key 30b is replaced by another person, the first restriction table 81 stored in the storage unit 26 is updated by the communication setting unit 23 of the remote processing device 2. Figure 3 ), and assign the authentication key 30b according to the changed master-slave relationship.
[0079] Next, the steps performed by the remote processing device 2 when a request is made from the outside to change the communication settings as described above will be described. Since the other basic operations are the same as those in the first embodiment, detailed descriptions will be omitted here.
[0080] Figure 13 This is a flowchart showing the processing of the exchange request according to the third embodiment. Figure 11 , and based on Figure 13 The following describes the steps that the remote processing device 2 performs when receiving a request to exchange the authentication key 30 a .
[0081] If a request for exchanging the master-slave relationship of the device 1a is received from the outside (for example, a person who becomes a slave or a person other than the slave) (step S1), the remote processing device 2 determines whether the exchange is permitted by the person who becomes the master of the device 1a (owner 3a) (step S2). When determining in step S2, the remote processing device 2 sends an exchange request to the person who becomes the master of the device 1a to whom the exchange request was made, and when receiving the content that the exchange is permitted from the person who becomes the master, it is determined that the exchange request is permitted (step S2: yes). When it is determined that the exchange is permitted (step S2: yes), the remote processing device 2 exchanges the master-slave relationship with respect to the authentication key 30a for the device 1a (step S3). At this time, the remote processing device 2 updates the authentication key 30a stored in the storage unit 26 ( Figure 3 )'s first restriction table 81 ( Figure 10), and grants authentication key 30a in response to the exchange request. On the other hand, if the remote processing device 2 determines in step S2 that the exchange is not permitted (step S2: No), the requested exchange is not performed and the process ends. The remote processing device 2 may be configured to notify the person who sent the exchange request of the result of the permission determination, i.e., whether the exchange request is permitted or denied.
[0082] Figure 14 This is a flowchart showing the replacement request processing according to the third embodiment. Figure 11 , and based on Figure 14 The following describes the steps that the remote processing device 2 performs when receiving a request to replace the authentication key.
[0083] Upon receiving a replacement request to replace the master or slave of device 1b (step S11), remote processing device 2 determines whether the replacement is permitted by the person who is the master of device 1b (step S12). If, during the determination in step S12, the sender of the replacement request is the person who is the master of device 1b (owner 3b), remote processing device 2 determines that the replacement request is permitted by the person who is the master (step S12: Yes). Alternatively, if the sender of the replacement request is not the person who is the master of device 1, remote processing device 2 sends a replacement request to the person who is the master of device 1 and, upon receiving a confirmation that the replacement is permitted, determines that the replacement request is permitted (step S12: Yes). If it is determined that the replacement is permitted by the person who is the master (step S12: Yes), remote processing device 2 replaces the master or slave of device 1 (step S13). At this point, remote processing device 2 updates first restriction table 81 stored in storage unit 26 as described above and assigns authentication key 30b in response to the replacement request. On the other hand, if the sender of the replacement request is not the person who is the owner of the device 1, and if it is determined that the replacement is not permitted by the owner (step S12: No), the remote processing device 2 does not perform the requested replacement and the process ends. The remote processing device 2 may be configured to notify the person who sent the replacement request of the result of the permission determination, i.e., whether the replacement request is permitted or denied.
[0084] like Figure 9 as well as Figure 11 As shown, after the authentication keys 30a and 30b are changed, the information management unit 24 ( Figure 3 ) determines the disclosure range of the information to the communication partner based on the changed authentication keys 30a and 30b. Figure 3 ) is provided to the communication object within the determined disclosure scope.
[0085] As described above, in the maintenance system according to Embodiment 3, when a replacement request for authentication key 30b to replace a preset master key owner or a preset slave key owner is approved by the master key owner, the remote processing device 2 grants authentication key 30b in response to the replacement request. Furthermore, when a swap request for authentication key 30a to swap a preset master key owner or a preset slave key owner is approved by the master key owner, the remote processing device 2 grants authentication key 30a in response to the swap request.
[0086] Thus, when information disclosure becomes more necessary than usual, such as when device 1 fails, for example, a replacement or exchange request can be sent from communication devices 20a and 20b to the owner of the master key for authentication key 30 for device 1, thereby expanding the scope of disclosure with a simple operation. Furthermore, under normal circumstances, the authority can be restored to a lower level, preventing unnecessary leakage of information.
[0087] Implementation method 4.
[0088] Figure 15 This is a diagram for explaining the change permission setting in the equipment maintenance management system according to the fourth embodiment. Figure 15 The equipment maintenance management system 100 according to the fourth embodiment will be described.
[0089] The equipment maintenance management system 100 of the fourth embodiment differs from the third embodiment in that it automatically determines whether a change request is approved based on a predetermined approval setting. Since the rest of the configuration and operation are the same as those of the third embodiment, detailed description is omitted here.
[0090] In the storage unit 26 ( Figure 3 )like Figure 15 As shown in FIG, a third restriction table 83 is stored that specifies whether changes such as exchange and replacement are permitted for each device 1a, 1b. Figure 15 In the example shown, both the exchange request and the replacement request for the device 1a are rejected, while both the exchange request and the replacement request for the device 1b are permitted.
[0091] In progress Figure 13 Step S2 shown and Figure 14 During the determination in step S12 shown, the remote processing device 2 of the fourth embodiment automatically performs the determination based on the predetermined permission setting.
[0092] As described above, in the device maintenance management system 100 according to Embodiment 4, the remote processing device 2 pre-sets, for each device 1, the master key owner's or slave key owner's replacement request for replacing the authentication key 30, and the approval or disapproval of the exchange request for exchanging the master key owner with the slave key owner. When a master or slave replacement request is made for a device 1b for which the replacement request is permitted, the remote processing device 2 grants the authentication key 30 in accordance with the replacement request. In addition, when a master-slave exchange request is made for a device 1b for which the exchange request is permitted, the remote processing device 2 grants the authentication key 30 in accordance with the exchange request. Thus, the remote processing device 2 does not need to inquire about the approval of the change request from the person who is the master of the device 1, and the person who is the master of the device 1 does not need to respond to each change request. Therefore, the communication load and the workload can be reduced.
[0093] Implementation method 5.
[0094] Figure 16 This is a diagram showing an example of a device maintenance management system according to the fifth embodiment.
[0095] Figure 17 Yes Figure 16 A diagram showing an example of a visualization mechanism in an equipment maintenance management system.
[0096] Figure 18 It means in Figure 16 A diagram showing the relationship between search symbols, authentication keys, and various information in the equipment maintenance management system. Figures 16 to 18 The equipment maintenance management system 100 according to the fifth embodiment will be described.
[0097] The equipment maintenance management system 100 of the fifth embodiment differs from the first embodiment in that one or more search symbols SS1 and SS2 can be assigned to an authentication key and that a reporting mechanism is provided for reporting information groups related to the search symbols SS1 and SS2 to the administrator 6. Since the remaining configuration and operation are the same as those of the first embodiment, detailed descriptions thereof will be omitted here.
[0098] like Figure 16 As shown, the equipment maintenance management system 100 includes a communication device 20a (e.g., a smartphone) owned by the manager 6 of the remote processing device 2, which serves as a reporting mechanism for reporting search results to the manager 6. Hereinafter, the communication device 20a owned by the manager 6 is sometimes distinguished from the communication device 20b of the user 4 and is referred to as a management communication device. The communication device 20a obtains information on multiple devices 1 collected by the remote processing device 2 through communication and reports it. Figure 17As shown, the communication device 20a includes a display screen 201 for displaying information. The communication device 20a is not limited to the aforementioned smartphone, and may be any device as long as it has a function of reporting information acquired from the remote processing apparatus 2 to the administrator 6 auditorily or visually.
[0099] exist Figure 16 In the example shown, the administrator 6 has authentication keys 30a to 30e that are the master, and the user 4a has authentication keys 30a to 30c that are the master, and the user 4b has authentication keys 30d to 30e that are the master. For the sake of convenience, there is no master-slave relationship between the administrator 6 and the users 4a and 4b. The administrator 6 has the same authentication keys as the authentication keys 30a to 30c of the user 4a and the same authentication keys as the authentication keys 30d to 30e of the user 4b. In addition, for the three devices 1 used by the user 4a, the owners 3a1, 3a2, and 3a3 each own one. In addition, for the two devices 1 used by the user 4b, the owners 3b1 and 3b2 each own one. The owner 3 (3a1, 3a2, 3a3, 3b1, and 3b2) has an authentication key 30 (30a, 30b, 30c, 30d, or 30e) that is the slave for the device 1 he owns. Therefore, in Figure 16 In the example shown, there is a one-to-one correspondence between the owners 3a1, 3a2, 3a3, 3b1, and 3b2 and the authentication keys 30a to 30e.
[0100] In the storage unit 26 ( Figure 3 ) stores a correspondence table 84, which includes authentication keys 30a to 30e, one or more search symbols SS1 and SS2 associated with each authentication key 30a to 30e, an owner 3, and a plurality of information D1 and D2 related to the device 1 owned by the owner 3. Figure 18 In the example shown, two search symbols SS1 and SS2 are used. Search symbol SS1 is set for each user 4. Specifically, the same search symbol SS1 (e.g., 33a) is assigned to the three authentication keys 30a to 30c owned by user 4a, and the same search symbol SS1 (e.g., 33b) is assigned to the two authentication keys 30d to 30e owned by user 4b. Furthermore, search symbol SS2 is set for each owner 3.
[0101] As described above, search symbols SS1 and SS2 are composed of alphanumeric strings or alphanumeric strings including symbols. Alternatively, search symbols SS1 and SS2 can be used as information related to authentication key 30 itself or owner 3 of authentication key 30. Furthermore, if the plurality of pieces of information D1 and D2 related to device 1 do not contain any data, the search result may be blank.
[0102] Next, when the administrator 6 who has the authentication keys 30a to 30e searches using 33b as the search symbol SS1 through his communication device 20a, the display screen 201 ( Figure 17 If the administrator 6 selects or inputs the search symbol SS1 in the communication device 20a and presses the search button 201a, a request is made to Figure 17 A search request for information related to the transmission of information 33b) is sent to the remote processing device 2 ( Figure 16 The remote processing device 2 retrieves the authentication keys 30a to 30e from the storage unit 26 ( Figure 3 ) extracts the information that becomes the search result and sends it. The communication device 20a receives the search result from the remote processing device 2, such as Figure 17 As shown, the search results are displayed on the display screen 201 of the communication device 20a. Specifically, the display screen 201 of the communication device 20a displays the selected search symbol SS1 (in Figure 17 33b), the authentication key 30 corresponding to the search symbol SS1, the information of the owner 3 related to the authentication key 30, and the information D1 and D2 of the device 1.
[0103] In addition, for the search symbols SS1 and SS2, in addition to being completely consistent, a partial search can also be performed. The result of the search performed by the administrator 6 based on the search symbol SS1 33b is as follows Figure 17 As shown, information about two devices 1 corresponding to authentication keys 30d to 30e owned by user 4b, out of the five devices 1 corresponding to authentication keys 30a to 30e owned by administrator 6, is displayed on display screen 201. Specifically, owner 3b1 of device 1 corresponding to authentication key 30d, along with information D1 (100a(4)) and information D2 (100b(4)) of that device 1, is displayed. Furthermore, owner 3b2 of device 1 corresponding to authentication key 30e, along with information D1 (100a(5)) and information D2 (100b(5)) of that device 1, is displayed.
[0104] In addition, the display items and the number of items are not limited to Figure 17An example of . In addition, input to the search bar 201b can be performed by displaying a list of searchable items and selecting them, or can also be input manually.
[0105] In addition, when using a reporting mechanism that reports by voice or the like, the search terms can be input by voice recognition. Alternatively, the search results can be reported by reading aloud instead of displaying them on the display screen 201. In this case, the language used is not limited to Japanese.
[0106] In addition, if Figure 16 As shown, user 4a can use the authentication keys 30a to 30c that have become the master to communicate with remote processing device 2 through his own communication device 20b (not shown) and obtain information related to authentication keys 30a to 30c. Specifically, user 4a can obtain information D1 (100a(1), 100a(2), and 100a(3)), information D2 (100b(1), 100b(2), and 100b(3)), and information of owners 3 (3a1, 3a2, and 3a3) for the three devices 1 he is using.
[0107] User 4b can use the authentication keys 30d-30e, which have been granted control, to communicate with remote processing device 2 via its own communication device 20b (not shown) and obtain information related to authentication keys 30d-30e. Specifically, user 4b can obtain information D1 (100a(4) and 100a(5)), information D2 (100b(4) and 100b(5)), and information on owners 3 (3b1 and 3b2) for the two devices 1 it is using.
[0108] Furthermore, user 4a can search using search symbol SS2 through his / her communication device 20b (not shown), and only information related to a specific authentication key (e.g., authentication key 30a) among his / her authentication keys 30a to 30c can be displayed on his / her communication device 20b (not shown). Furthermore, user 4b can search using search symbol SS2 through his / her communication device 20b (not shown), and only information related to a specific authentication key among his / her authentication keys 30d to 30e can be displayed on his / her communication device 20b (not shown).
[0109] The owner 3 (3a1, 3a2, 3a3, 3b1, and 3b2) can communicate with the remote processing device 2 via its own communication device 20b (not shown) using the authentication key 30 (30a, 30b, 30c, 30d, or 30e) that has become a slave, and obtain information related to the authentication key 30. For example, the owner 3a1 can obtain information D1 (100a(1)) and information D2 (100b(1)) for one device 1 that it owns.
[0110] As described above, the equipment maintenance management system 100 according to Embodiment 5 includes a management communication device (communication device 20a) that obtains information from a remote processing device 2 and reports it. Remote processing device 2 stores one or more search symbols SS1 and SS2 in association with authentication keys 30a and 30b. When search symbols SS1 and SS2 are input, communication device 20a reports a message group (e.g., message D1 and message D2) including the search symbols SS1 and SS2, the authentication keys 30 corresponding to the search symbols SS1 and SS2, and information related to the authentication keys 30.
[0111] Thus, since information searched from a huge data group is reported, it is possible to avoid workload and easily obtain necessary information, thereby improving the convenience of management and maintenance of the device 1 .
[0112] Furthermore, the respective embodiments may be combined, modified as appropriate, or omitted.
[0113] Description of Reference Numerals
[0114] 1…device; 2…remote processing device; 3…owner; 4…user; 5…provider; 6…administrator; 10…network; 20a, 20b…communication device; 21…communication unit; 22…information acquisition unit; 23…communication setting unit; 24…information management unit; 25…control unit; 26…storage unit; 30…authentication key; 81…first restriction table; 82…second restriction table; 83…third restriction table; 84…correspondence table; 100…device maintenance management system; 201…display screen; 201a…search button; 201b…search bar; A, B, C, D1, D2…information; Ga, Gb, Gt…device group; SS1, SS2…search symbol.
Claims
1. An equipment maintenance management system, characterized in that: have: Multiple devices transmit information related to their own operation and the presence or absence of abnormalities; and A remote processing device obtains and stores the information of each of the plurality of devices. The remote processing device restricts communication using at least one type of authentication key having a master-slave relationship, The remote processing device communicates with a first communication device that has been assigned the authentication key in advance as a master for at least some of the plurality of devices, and a second communication device that has been assigned the authentication key in advance as a slave of the first communication device, respectively, as communication partners. During communication, the remote processing device determines the scope of the information to be provided based on the type of the authentication key possessed by the communication partner and the master-slave relationship. Among the different types of authentication keys, one authentication key that becomes the master of different device groups among the plurality of devices is pre-assigned to one or more of the first communication devices. To one or more second communication devices, among the different types of authentication keys, authentication keys belonging to different device groups among the plurality of devices are assigned in advance. The information of the device includes first information and second information, When communicating with one or more first communication devices and one or more second communication devices respectively, The remote processing device discloses the first information and the second information related to the first device group to the first communication device to which the authentication key for becoming the master of the first device group is assigned, The remote processing device discloses the first information related to the first device group to the second communication device assigned the authentication key to become a subordinate of the first device group, but does not disclose the second information. The remote processing device discloses the first information and the second information of the second device group to the first communication device that is assigned the authentication key that becomes the master of the second device group, The remote processing apparatus discloses the first information of the second device group to the second communication device assigned the authentication key to become a member of the second device group, and does not disclose the second information.
2. The equipment maintenance management system according to claim 1, characterized in that: The first communication device and the second communication device include at least two of the communication device owned by the manager of the remote processing device, the communication device owned by the owner of the part of the equipment, the communication device owned by the user of the part of the equipment, and the communication device owned by the maintenance practitioner of the part of the equipment.
3. The equipment maintenance management system according to claim 1 or 2, characterized in that: The authentication keys having a master-slave relationship form a hierarchical structure of three or more levels with different disclosure levels with respect to the information related to the part of the devices.
4. The equipment maintenance management system according to claim 1 or 2, characterized in that: When a replacement request to replace a master key owner or a slave key owner preset for the authentication key is permitted by the master key owner, the remote processing device assigns the authentication key in accordance with the replacement request. When an exchange request between the master key owner and the slave key owner, which are preset for exchanging the authentication key, is permitted by the master key owner, the remote processing device grants the authentication key in accordance with the exchange request.
5. The equipment maintenance management system according to claim 1 or 2, characterized in that: In the remote processing device, approval of a request to replace a master key owner or a slave key owner of the authentication key, and approval of a request to exchange the master key owner with the slave key owner are preset for each device. When the replacement request is made to the device to which the replacement request is permitted, the remote processing device assigns the authentication key according to the replacement request. When the exchange request is made to the device to which the exchange request is permitted, the remote processing apparatus grants the authentication key according to the exchange request.
6. The equipment maintenance management system according to claim 1 or 2, characterized in that: A management communication device is provided for acquiring the information from the remote processing device and reporting the information. In the remote processing device, one or more search symbols are stored in association with the authentication key. When the search symbol is input, the management communication device reports the search symbol and an information group including the authentication key corresponding to the search symbol and the information related to the authentication key.