Information management control device, information management control system, information management control method, and program
By assigning attribute information to content data and generating role information, user access is controlled based on the association information between the generating source and the providing source, solving the flexibility problem of access control management in multiple systems and achieving more efficient access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- MITSUBISHI ELECTRIC CORP
- Filing Date
- 2023-03-08
- Publication Date
- 2026-05-29
Smart Images

Figure CN120858358B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to information management and control devices, information management and control systems, information management and control methods, and procedures. Background Technology
[0002] As a technology to enhance the security of information systems, role-based access control (RBAC) is known. For example, Patent Document 1 discloses an information system that controls access to information resources based on abstract roles determined by user attributes and access permissions associated with those abstract roles.
[0003] Existing technical documents
[0004] Patent documents
[0005] Patent Document 1: Japanese Patent Application Publication No. 2007-4549 Summary of the Invention
[0006] The problem that the invention aims to solve
[0007] This information system assigns access permissions to each role. However, the information managed by the information system is provided by various sources. Therefore, in the information system of Patent Document 1, it is difficult to flexibly set access permissions, such as setting access permissions based on the source of provision. Furthermore, creating and managing access permissions from scratch in systems that differ based on the source of provision is extremely time-consuming. Therefore, from the viewpoint of properly managing access permissions for information from various sources with less effort, there is room for improvement.
[0008] This disclosure was made in view of the aforementioned problems, and its purpose is to provide an information management control device, information management system, information management method, and program that can properly manage access permissions to information from various sources with less effort.
[0009] Methods for solving problems
[0010] To achieve the above objectives, the information management and control device of this disclosure manages content data, including operational data of the managed object device, and controls access to the content data. The information management and control device comprises: an attribute information assignment unit that assigns attribute information to each piece of content data based on pre-set rules, the attribute information including generation source information for identifying the content data generation source device; a role generation unit that generates role information, the role information including the content data generation source information and indicating the conditions for accessing the content data; an allocation unit that determines the content data provider based on association information and allocates the role information generated by the role generation unit to users of the provider destination permitted by the determined provider source, the association information linking the generation source information contained in the role information generated by the role generation unit to the content data provider generated by the device determined by the generation source information; and a determination unit that determines whether a user can access the content data based on the attribute information assigned to the content data and the conditions of the role information assigned to the user who requested access to the content data.
[0011] Invention Effects
[0012] According to this disclosure, role information representing the conditions for accessing content data is created, and a provider is determined based on the generation source information contained in the role information and the provision source of the content data generated by the device determined by the generation source information. The information management control device assigns this role information to a user of the provision destination permitted by the determined provider. Then, based on the attribute information assigned to the content data and the conditions assigned to the role information of the user who made the access request for the content data, it is determined whether access to the content data is permitted. Therefore, access permissions to information from various provider sources can be appropriately managed with less effort. Attached Figure Description
[0013] Figure 1 This is a diagram showing the structure of the information management control device according to an embodiment of the present disclosure.
[0014] Figure 2 It means Figure 1 The diagram shows an example of attribute management information maintained by the attribute management department.
[0015] Figure 3 It means Figure 1 The diagram shows an example of a combination table maintained by the character generation department.
[0016] Figure 4 yes Figure 1 The diagram shown contains (a) a representation of an example of the user table and (b) a representation of an example of the source table.
[0017] Figure 5 It means in Figure 1 The image shown is an example of a custom character creation screen displayed on a terminal.
[0018] Figure 6 It means Figure 1 The diagram shows an example of a character definition table generated by the character generation department.
[0019] Figure 7 It means by Figure 1 The diagram shown illustrates an example of the overall management of a character group for a custom character created by the character generation department.
[0020] Figure 8 It means Figure 1 The image shown is an example of a screen displaying changed parameter settings on a terminal.
[0021] Figure 9 It means Figure 1 The diagram shows an example of the allocation information generated by the character generation department.
[0022] Figure 10 This is a block diagram illustrating the physical structure of the information management and control device in the implementation method.
[0023] Figure 11 It means Figure 1 The image shown is an example of an input screen displayed on a terminal.
[0024] Figure 12 This is a flowchart representing the access control process of the information management and control device. Detailed Implementation
[0025] Hereinafter, the information management control device, information management control system, information management control method, and program according to embodiments of the present disclosure will be described with reference to the accompanying drawings. Furthermore, the same or corresponding parts in the drawings will be labeled with the same reference numerals.
[0026] Use applicable to Figure 1 The example of the information management and control system 1 shown is used to illustrate the information management and control device of this embodiment.
[0027] Information management and control system 1 is a system that registers information provided by information providers to memory 140 and controls access to the registered information via information management and control device 100, which provides cloud computing services. Access to information is limited to information-providing destination companies authorized by the information-providing source company, and the information that can be accessed is limited to items authorized by the information-providing source company. Specifically, information management and control system 1 is used by multiple end-user companies, devices including FA equipment installed in the factory, and maintenance companies that provide maintenance support for the factory production line. The maintenance company provides remote maintenance support services to the end-user companies by accessing the maintenance target device from the public wide area communication network through a maintenance terminal. In addition, information management and control device 100 is managed by the end-user companies and management companies different from the maintenance companies. When providing maintenance support, the maintenance company needs to access information held by the end-user companies. Therefore, the following explanation will take the case of a maintenance company user accessing information provided by the end-user company as an example.
[0028] The information management and control system 1 stores various content data provided by end-user companies, which are assigned attributes including a confidentiality level, indicating the degree of confidentiality of the data. The content primarily concerns the device 200, which is the object of management, and includes information required for maintenance / repair. For example, the content data includes operational data collected by the device 200 indicating its operating status, output data from various sensors present in the device 200, and data held by the end-user companies such as drawings, task history, maintenance history, component master data, and manuals related to the device 200. Furthermore, when a maintenance company is the information provider, the content data can also be data added to the information management and control system 1 from the maintenance company's user terminal, such as manuals and maintenance history provided by the maintenance company to the end-user company.
[0029] The information management and control system 1 generates custom roles and assigns them to users. Each custom role contains a combination of accessible content data and operation permissions for that content data. Operation permissions, for example, represent permissions to perform operations such as viewing, appending, updating, and deleting data. When a user accesses content data, the information management and control system 1 determines, based on the custom role assigned to that user, whether the user has the necessary permissions to access that content data.
[0030] return Figure 1The information management and control system 1 includes: an information management and control device 100 that controls access to content data stored in a memory 140; and a gateway 300 that sends data collected from a device 200 located in the factory to the information management and control device 100. The information management and control system 1 is communicatively connected via a network 500. Users of the maintenance company or end-user enterprise access the content data from a terminal 400 via the API (Application Programming Interface) 150 of the information management and control device 100. Furthermore, in the illustrated example, only one gateway 300 is shown, but more than two gateways 300 can be connected depending on the number of end-user enterprises utilizing the information management and control system 1.
[0031] The information management and control device 100 includes: an attribute management unit 110 that manages the attributes of content data; a role generation unit 120 that generates custom roles and assigns them to users; an access control unit 130 that controls access to the content data; a memory 140 that stores the content data; and an API 150 that exchanges data bidirectionally between the memory 140 and the terminal 400.
[0032] The attribute management unit 110 manages the attributes of content data stored in the memory 140. Specifically, the attribute management unit 110 maintains attribute management information used to manage the attributes of the content data as parameters.
[0033] like Figure 2 As shown, the attribute management information includes information identifying the device 200 that generated the content data, namely the "data source," the "data category" indicating the output format of the data, "data purpose (for maintenance company)" and "data purpose (for end-user company)" indicating the intended use of the information contained in the content data, and the "confidentiality level" indicating the confidentiality level of the content data. Additionally, the "data source" can also be information indicating the location where the device 200 is installed, the system that generated the content data, or the user who created the content data. When the role generation unit 120 generates a custom role, the attribute management unit 110 provides attribute management information to the role generation unit 120. The data source is an example of the generation source information.
[0034] Furthermore, when the attribute management unit 110 receives content data, including operating data of the device 200, via the gateway 300, it performs processing to attach attribute information to the received content data based on pre-set rules. Details regarding the process of attaching attribute information to content data will be described later. Additionally, the attribute management unit 110 is an example of an attribute information assignment unit.
[0035] return Figure 1The role generation unit 120 creates custom roles based on attribute management information managed by the attribute management unit 110, and assigns these custom roles to users of the maintenance company or end-user enterprise. Custom roles represent information related to conditions for users of the maintenance company authorized by the end-user enterprise to access the end-user enterprise's content data, or conditions for users of the end-user enterprise to access their own enterprise's content data. Specifically, the role generation unit 120 generates and maintains a combination table representing combinations of end-user enterprises as information sources and maintenance companies as information destinations. This combination table is generated, for example, by settings configured by the maintenance company's manager. Figure 3 As shown, the combination table contains items such as "Destination Company" identifying the destination company providing the information, and "Source Company 1," "Source Company 2," "Source Company 3," and so on, identifying the source company providing the information. In the illustrated example, it indicates that the destination company "Maintenance Company 1" receives content data from "End User Company 1" and "End User Company 2." When a custom role for the maintenance company is created, the role generation unit 120 generates a custom role for accessing the content data of the end user companies specified in the combination table. Furthermore, the combination table is an example of combined information.
[0036] Role Generation Department 120 is based on the management of maintenance companies and end-user enterprises. Figure 5 The settings performed on the custom role creation screen 600 shown generate a role definition table that defines the custom roles. Furthermore, to control access to content data provided by the maintenance company, custom roles can be generated to represent either the conditions for end-user companies to access the maintenance company's content data, or the conditions for users of the maintenance company to access their own company's content data.
[0037] like Figure 6As shown, the role definition table is used to manage multiple custom roles that each enterprise can use as a group. The role definition table contains "custom role name" which identifies each custom role, "position parameter" which indicates the job title of the user assigned to each custom role, "source parameter" which indicates the attribute information of the content data to be accessed, and "permission parameter" which indicates the access permissions granted to each custom role. The "source parameter" is based on attribute management information maintained by the attribute management department 110 and includes four parameters: "data source," "data category," "data purpose," and "confidentiality level." In the example shown, the user assigned the custom role "role A1" has the job title of "Production Leader of Department ○○." The content data this user can access is data generated from "Factory XX," is data of the data category "standard format file," has the data purpose of "system management," and is confidentiality level "A." Furthermore, the user assigned the custom role "role A1" has "view, update, delete, and append" permissions for content data with attributes set by the "source parameter." Alternatively, the role definition table can omit the "custom role name" and instead use "job parameters" as identification information for each custom role. The role generation unit 120 generates and maintains a role definition table for each company. The method for users to set custom roles will be described later. Furthermore, the role definition table is an example of role information, and source parameters are an example of attribute conditions.
[0038] The Role Generation Department 120 manages the role definition tables for maintenance companies (the destination of content data) and end-user companies (the source of content data). For example... Figure 7As shown, the role generation unit 120 sets up a first role group representing a collection of role definition tables for multiple maintenance companies, and a second role group representing a collection of role definition tables for multiple end-user companies. Maintenance companies and end-user companies share each other's role definition tables via ports used to access their respective tables. Specifically, in the illustrated example, when content data is provided from end-user company 1 to maintenance company 1, the role generation unit 120 sets up ports for maintenance company 1 to access custom roles of end-user company 1, and ports for end-user company 1 to access custom roles of maintenance company 1. By setting these ports, multiple maintenance companies and end-user companies receiving remote maintenance support services from each maintenance company can be managed as separate groups. The role generation unit 120 manages the role definition tables contained in the first role group in a manner that allows viewing, copying, and modification. Furthermore, the role generation unit 120 manages the role definition tables contained in the second role group so that they can be viewed and copied but cannot be modified. Thus, for example, end-user company 1, as the information source, can view and authorize the role definition table created by maintenance company 1 through the designated port, or set or modify the "source parameters" or "permission parameters" of the role definition table. Furthermore, maintenance company 1, as the information destination, can also copy some custom roles from the role definition table created by end-user company 1 for its own users, and use them as custom roles assigned to users of maintenance company 1.
[0039] return Figure 1 When a content data maintenance company creates a custom role, the role generation unit 120 determines the range of "source parameters" or "permission parameters" that can be set. Specifically, the role generation unit 120 determines the range of "source parameters" or "permission parameters" that can be set based on the screen displayed on the terminal 400 operated by the end-user company's administrator. Figure 8 The parameter setting screen 700, shown here, defines the range of parameters that a maintenance company can set. As shown, the parameter setting screen 700 is for setting "Public Parameter Groups," "Quasi-Public Parameter Groups (General Parameter Groups)," and "Specific Parameter Groups." "Public Parameter Groups" represent parameter groups that can be set by all maintenance companies authorized by the end-user company. "Quasi-Public Parameter Groups (General Parameter Groups)" represent parameter groups that can only be set by a subset of authorized maintenance companies. "Specific Parameter Groups" represent parameter groups that can only be set by the end-user company. In the example shown, the "Data Source," "Data Category," and "Data Purpose" options for the source parameters, as well as the "View" option for the permission parameters, are checked in the Public Parameter Group. Therefore, this means that all maintenance companies authorized by the end-user company can only create custom roles that grant viewing permissions to content data provided by the end-user company.
[0040] return Figure 1When managers of a maintenance company or end-user enterprise assign custom roles to various users, the role generation unit 120 generates assignment information representing the assignment of custom roles to each user. Specifically, the role generation unit 120 maintains... Figure 4 The user table shown in (a) and Figure 4 The source table shown in (b) is in Figure 4 In (a), the user ID that identifies the user is associated with the identification information of the maintenance company to which the user belongs. Figure 4 In (b), the parameter assigned to the "data source" of the custom role is associated with the identification information of the end-user enterprise to which the "data source" belongs. Role Generation Unit 120 refers to... Figure 4 From the user table in (a), the maintenance company to which the user belongs is determined. Next, the role generation department 120... Figure 6 The character definition table reads the "data source" parameter for the custom character to be assigned. Next, the character generation unit 120 refers to... Figure 4 The generation source table of (b) determines the end-user enterprise that provides the data, corresponding to the parameters of the "data generation source". Next, the role generation department 120 refers to... Figure 3 The combined table shown determines whether the maintenance company to which the user belongs received content data from the identified end-user company. When the role generation unit 120 determines that the maintenance company to which the user belongs received content data from the identified end-user company, it assigns a custom role to the user and generates allocation information representing the assignment of custom roles for each user. Details of the allocation information generation process will be described later. Furthermore, the role generation unit 120 is an example of an allocation unit, and the source table for generation is an example of relational information.
[0041] like Figure 9 As shown, the allocation information includes information identifying each user, namely the "User ID," and "Custom Role 1," "Custom Role 2," etc., identifying the custom roles assigned to each user. The User ID, for example, is a pre-assigned login ID used by users of a company or end-user enterprise to access memory 140 via terminal 400. Allocation information is generated for each enterprise.
[0042] return Figure 1 The access control unit 130 controls access to the content data stored in the memory 140 based on the attribute information of the custom role and content data assigned to the user.
[0043] Specifically, when an access request for content data is generated, the access control unit 130 refers to... Figure 9 The allocation information shown determines the custom roles assigned to users. (See Access Control Unit 130 for reference.) Figure 6The role definition table shown retrieves the source parameters and permission parameters set for the determined custom role. The access control unit 130 determines whether the attribute information assigned to the content data matches the source parameters, thereby determining whether the user's operation matches the permission parameters. For example, if a user assigned the custom role "Role A1" views certain content data, the access control unit 130 determines whether the attribute information of the content data matches the source parameters of "Role A1". If the access control unit 130 determines that the attribute information of the content data matches the source parameters of "Role A1", it determines whether "Role A1" has viewing permission parameters. In the illustrated example, since "Role A1" has been assigned viewing permission parameters, the access control unit 130 determines that viewing permission parameters are present and allows the user to view the content data. Furthermore, the access control unit 130 is an example of a determination unit.
[0044] return Figure 1 The memory 140 stores operational data generated by the device 200, as well as various content data created by users of the maintenance company or end-user enterprise. This data is managed by the attribute management department 110 or the user. Figure 2 The attribute information shown is assigned to each content data.
[0045] API 150 is an interface for bidirectional data exchange between memory 140 and terminal 400. Specifically, API 150 sends content data that is authorized for access by access control unit 130 from memory 140 to terminal 400. In addition, API 150 receives content data created by users of the end-user enterprise and authorized by access control unit 130 from terminal 400.
[0046] Device 200 is, for example, a control device that controls actuators, sensors, etc., within a factory. The data collected by the information management and control device 100 includes data obtained from vibration sensors, temperature sensors, pressure sensors, flow sensors, etc., installed in device 200.
[0047] Gateway 300 is a device that collects data from device 200 and sends the collected data to information management and control device 100. Gateway 300 performs processing on the collected data, such as processing, documenting, or assigning uses to the collected data.
[0048] Terminal 400 may be, for example, a desktop PC, a laptop PC, a smartphone, or a tablet. Terminal 400 is used by users of both the maintenance company and the end-user enterprise to access content data registered in memory 140 and to perform operations such as viewing, registering, deleting, and updating that content data. Furthermore, based on instructions from users, terminal 400 accepts login requests for accessing memory 140 from terminal 400. Login requests may include, for example, a user ID and password. Terminal 400 sends the obtained login to information management and control device 100, and if the user is deemed legitimate, grants access to memory 140. Additionally, terminal 400 is used to register content data created by the user into memory 140. Furthermore, users of both the maintenance company and the end-user enterprise control the display screen of terminal 400. Figure 5 The custom character creation screen shown is 600, used to create a custom character.
[0049] Next, refer to Figure 10 The physical structure of the information management and control device 100 will be described. Alternatively, the information management and control device 100 may also exist on a cloud server. The information management and control device 100 includes: a processor 11 that executes program processing; RAM (Random Access Memory) 12 as volatile memory; ROM (Read Only Memory) 13 as non-volatile memory; a storage unit 14 that stores data; an input unit 15 that accepts information input; a display unit 16 that displays information visually; and a communication unit 17 that transmits and receives information. These units are connected via an internal bus 99.
[0050] The processor 11 includes a CPU (Central Processing Unit). The processor 11 performs various processes by reading the program stored in the storage unit 14 into the RAM 12 and executing it. As the main functions provided by the program, the processor 11 performs the processing of the attribute management unit 110, the character generation unit 120, and the access control unit 130.
[0051] RAM 12 is used as the CPU's working area. ROM 13 stores control programs executed by the CPU for the basic operations of the information management and control device 100, BIOS (Basic Input Output System), etc.
[0052] Storage unit 14 has a hard disk drive that stores programs executed by the CPU and various data used during program execution. Storage unit 14 functions as memory 140.
[0053] The input unit 15 is a user interface with a keyboard, mouse, etc. The display unit 16 is a display device such as a liquid crystal display or an organic EL (Electro-luminescence) display that displays information visually.
[0054] The communication unit 17 is a network terminal device or wireless communication device connected to a network, and a serial interface or LAN interface connected to them. The communication unit 17 receives signals from the outside and outputs the data represented by the signals to the processor 11.
[0055] Next, the operation of the information management and control device 100 having the above structure will be explained.
[0056] (Custom character creation process)
[0057] The information management control device 100 controls access to content data based on custom roles assigned to users who access content data provided by end-user companies that are the information providers. Therefore, the process of creating custom roles will be explained. Furthermore, the case where a maintenance company, as the information provider destination, creates a custom role will be explained as an example.
[0058] Specifically, the maintenance company's administrators caused the terminal to display a 400 error. Figure 5 The screen shown is the custom character creation screen 600, which is used to create custom characters. You can create a custom character by operating the creation screen.
[0059] As shown in the figure, the custom role creation screen 600 includes: an input form that accepts input of the custom role name used to identify the custom role; a job title label that sets the job title of the user assigned to each custom role; a source parameter label that sets the attributes of the content data that can be accessed; and a permission parameter label that sets the access permissions granted to each custom role.
[0060] The source parameter labels include multiple labels for setting various source parameters, such as: a "data generation source" identifying the device 200 or location that generated the content data, a "data category" indicating the output format and confidentiality level of the content data, and a "data purpose" indicating the purpose of the information contained in the content data. The maintenance company's manager selects items from pre-defined options for each parameter to create a custom role. The role generation unit 120 generates roles based on the custom roles created by the maintenance company's manager. Figure 6 The role definition table is shown. Additionally, the information displayed as an option for source parameters is based on data maintained by the Attribute Management Department 110. Figure 2The information displayed is attribute management information. Attribute management information can also define combinations of various attributes. In this case, in the custom character creation screen 600, the options can be filtered and displayed by rearranging the order of the labels for the source parameters "Data Source," "Data Category," and "Data Purpose." Furthermore, through... Figure 8 If the parameter setting screen 700 shows a preset range of parameters that the maintenance company can set, then in the maintenance company's custom role creation screen 600, parameters outside the set range can be displayed in a way that cannot be changed.
[0061] The maintenance company's administrator assigns the created custom roles to users. The administrator causes terminal 400 to display an input screen for assigning custom roles, and assigns the custom role name, identifying the custom role, to the user ID that identifies the user. Specifically, the role generation unit 120 maintains... Figure 4 The user table shown in (a) and Figure 4 The source table shown in (b) is in Figure 4 In (a), the user ID that identifies the user is associated with the identification information of the maintenance company to which the user belongs. Figure 4 In (b), the parameter assigned to the "data source" of the custom role is associated with the identification information of the end-user enterprise to which the "data source" belongs. For example, in the assignment of user ID "A0001"... Figure 6 In the case of "Character A1" in the character definition table shown, the character generation unit 120 refers to... Figure 4 From user table (a), user "A0001" is determined to belong to "Maintenance Company 1". Next, the character generation department 120... Figure 6 The role definition table reads that the "Data Source" for "Role A1" is "XX Factory". Next, the role generation department 120 refers to... Figure 4 From the source table of (b), it is deduced that "XX Factory" is a factory of "End User Enterprise 1". Next, the character generation department 120 refers to... Figure 3 The illustrated combination table determines whether "Maintenance Company 1" received content data from "End User Company 1". In the illustrated example, since the source of "Maintenance Company 1" includes "End User Company 1", the role generation unit 120 assigns "Role A1" to user "A0001", generating allocation information representing the assignment of custom roles for each user. The role generation unit 120 generates [the necessary information] based on the operations of the maintenance company's manager. Figure 9 The allocation information is shown and sent to the access control unit 130.
[0062] Furthermore, the maintenance company's administrators can copy role definition information created by end-user companies for their own enterprise users to create custom roles for the maintenance company's users. Specifically, the maintenance company's administrators display a screen on terminal 400 displaying the role definition information and enter the end-user company's identification information in the input form. Role generation unit 120 refers to... Figure 3 The combined table shown determines whether the end-user company identified by the input identification information has granted access from the maintenance company. If access is granted, the role generation unit 120, via a pre-set port, will... Figure 6 The role definition table of the end-user enterprise shown is sent to terminal 400. The maintenance company's administrator selects a custom role from the end-user enterprise's role definition table and appends it to the maintenance company's role definition table. The maintenance company's administrator causes terminal 400 to display an input screen for assigning custom roles, and assigns the custom role name that identifies the custom role to the user ID that identifies the user on the input screen.
[0063] (Content data registration and processing)
[0064] Next, the processing of content data stored in memory 140 by information management and control device 100 will be described. Information management and control device 100 stores content data, including operation data of device 200 generated by device 200 owned by end user company, and content data created by users of end user company, in memory 140.
[0065] First, the processing of the operation data generated by the storage device 200 will be explained. When the attribute management unit 110 of the information management and control device 100 receives the operation data from the device 200 via the gateway 300, it performs processing to add attribute information to the received operation data based on preset rules.
[0066] Specifically, for example, the attribute management unit 110 maintains an association table that defines the association between the address information of device 200 and the device ID that uniquely identifies device 200. Based on the association table, the attribute management unit 110 converts the address information of device 200 contained in the received operation data into a device ID and assigns it to the operation data as attribute information of "data generation source". Furthermore, for example, the attribute management unit 110 adds "data category" attribute information to the received operation data based on a pre-set rule that classifies operation data whose time is recorded in the column information as "standard format file" and other operation data as "general file". Furthermore, for example, the attribute management unit 110 adds "confidentiality level" attribute information to the received content data based on a rule that determines the confidentiality level of the content data according to the parameter combination of attribute information. The attribute management unit 110 stores the operation data with these attribute information attached in association with identification information used to uniquely identify the data in the memory 140.
[0067] Next, the process of storing content data created by users of the end-user company into memory 140 will be described. The user causes terminal 400 to display... Figure 11 The input screen 800 shown is used to assign attribute information to content data. On the input screen 800, attribute information is set for the content data. As shown, the input screen 800 includes: a file path, which accepts input of the storage destination address of the content data registered with the memory 140; and source parameter labels, which are used to set the attributes assigned to the content data. For the content data determined by the input file path address, the user selects each item from the preset options for each source parameter and sets the attribute information to be assigned. The attribute management unit 110 appends the attribute information set by the user to the content data and stores it in the memory 140 along with identification information used to uniquely identify the data.
[0068] (Access control processing)
[0069] Next, refer to Figure 12 This section explains the actions of the access control process, which controls access to content data stored in memory 140. The following explanation uses the example of a user of maintenance company 1 viewing content data registered by end-user company 1.
[0070] When a user issues an access request for content data, the information management control device 100 begins access control processing.
[0071] The access control unit 130 of the information management control device 100 obtains the attribute information of the content data of the accessed object and determines the user's operation content (step S1). Specifically, when the user double-clicks the content data and previews it, the access control unit 130 retrieves the attribute information of "data source", "data category", "data purpose" and "confidentiality level" assigned to the content data from the memory 140. Then, based on the user's double-click operation, the access control unit 130 determines that the operation content is "viewing".
[0072] Next, the access control unit 130 determines the custom role assigned to the user and obtains the permissions set for the determined custom role (step S2). Specifically, the access control unit 130 refers to... Figure 9 The allocation information shown determines the custom roles assigned to the user. In the case where the user ID of the user who has accessed the system is "A0001", the access control unit 130 determines that the user has been assigned the custom roles "role A1" and "role B2".
[0073] Next, the access control unit 130 refers to Figure 6 The access control unit 130 obtains access permissions for "Role A1" and "Role B2" from the role definition table shown. It reads the source parameters and permission parameters defined in each custom role. For "Role A1," the access control unit 130 obtains the following attributes of the accessible content data: "Data Source" is "XX Factory," "Data Category" is "Standard Format File," "Data Purpose" is "System Management," "Confidentiality Level" is "A" or lower, and the user can perform "View, Update, Delete, and Append" operations. The access control unit 130 obtains access permissions for "Role B2" in the same way as for "Role A1."
[0074] return Figure 12Next, the access control unit 130 determines whether the user has permission to access the content data of the target (step S3). Specifically, the access control unit 130 determines whether the user has permission based on the attribute information of the content data obtained in step S1 and the source parameters of "role A1" and "role B2" obtained in step S2. The access control unit 130 determines whether the source parameters of "role A1" and "role B2" contain the attribute information of "data source", "data category", "data purpose" and "confidentiality level" assigned to the content data. If it determines that they contain these attributes (step S3; yes), the process proceeds to step S4. On the other hand, if the access control unit 130 determines that the source parameters of "role A1" and "role B2" do not contain the attribute information of "data source", "data category", "data purpose" and "confidentiality level" assigned to the content data (step S3; no), the user is deemed not to have permission to access the content data, and an "access denied" message is output (step S6), and the process ends.
[0075] Returning to step S4, the access control unit 130 then determines whether the user has the necessary permissions to perform the desired operation. Specifically, the access control unit 130 determines whether the operation content determined in step S1 is included in the permission parameters obtained in step S2. For example... Figure 6 As shown, the operation parameters for "role A1" and "role B2" are "view, update, delete, append". Since "view" is included in step S1, the access control unit 130 determines that it has the operation permission of "view" (step S4; yes) and performs access processing for the view object data (step S5).
[0076] On the other hand, when the access control unit 130 determines that it does not have the operation permission to perform the operation (step S4; no), it outputs a "access denied" message (step S6) and ends the process.
[0077] Returning to step S5, the access control unit 130 then determines whether access to the object data has ended. Specifically, if the user closes the object data, the access control unit 130 determines that access to the object data has ended (step S7) and terminates the access control process.
[0078] On the other hand, if the user performs other operations such as adding or deleting information on the object data, it is determined that the access to the object data has not ended (step S7; no), and the process returns to step S4 to determine whether the user has permission to perform new operations.
[0079] As described above, the information management control device 100 attaches a "data generation source" to the content data, which is used to identify the device 200 that generates the data, and creates a custom role with access permissions set to include conditions related to the "data generation source." The information management control device 100 assigns the custom role to users of maintenance companies licensed by end-user enterprises identified through the "data generation source" as information providers. The information management control device 100 determines whether access is permissible based on the access permissions set for the assigned custom role and the attribute information assigned to the content data. Therefore, access permissions for information from various providers can be appropriately managed.
[0080] Furthermore, the information management control devices 100 share the role definition information created by the end-user companies and the maintenance companies. Therefore, for example, the maintenance company can flexibly utilize the role definition information created by the end-user companies for their own enterprise users to generate custom roles for the maintenance company, thus enabling access control-based information management with less effort.
[0081] The embodiments of this disclosure have been described above, but this disclosure is not limited to the above embodiments.
[0082] In the above embodiment, the content data provided by the end-user company is shared with the maintenance company, but this is not limited to this; the content data of the maintenance company can also be shared with the end-user company. In this case, the role generation unit 120... Figure 3 In the combination table, the end-user company is set as the destination and the maintenance company as the source. Furthermore, the role generation unit 120 only needs to maintain a user table that associates the end-user company's user ID with the end-user company's identification information, and a generation source table that associates the data generation source's identification information with the end-user company's identification information. Additionally, in Figure 7 In the role group management diagram shown, set the custom role for the end-user company in the first role group (representing the information-providing destination company), and set the custom role for the maintenance company in the second role group (representing the information-providing source company). Additionally, for... Figure 6 The source parameters of the role definition table shown, as well as the "data source" attribute information that serves as the content data, can be used to assign identification information to the factory, office, etc. of the identification and maintenance company.
[0083] Furthermore, in the above embodiment, the example described is that the information management and control system 1 is used by a maintenance company of the manufacturing device 200 and an end-user company using the device 200 manufactured by the maintenance company. However, the combination of companies using the system is not limited to this. For example, it could be a finished product manufacturer and a component manufacturer, or a manufacturer and a system integrator that implements and maintains the manufacturing device.
[0084] Furthermore, in the above embodiment, the data stored in the memory 140 is described as including operating data of the device 200, output data from various sensors, drawing data of the device 200, task history, maintenance history, component master data, manuals, and other data related to the device 200, but it is not limited to this. For example, it may also store customer data, sales data, personnel data, marketing data, quality management data, and other data unrelated to the maintenance of the device 200.
[0085] In the above embodiments, it is assumed that the functions of the attribute management unit 110, the role generation unit 120, and the access control unit 130 of the information management control device 100 are performed by one computer, but this is not a limitation; multiple computers may also perform each process. For example, the function of the attribute management unit 110 may be performed by an edge computer located at the manufacturing site. Furthermore, for example, the API 150 may have the function of the access control unit 130, and access control processing may be performed by the API 150.
[0086] Furthermore, the information management and control device 100 may not have a memory 140. The content data stored in the memory 140 can be uniformly managed by a cloud server existing on the network, and the attribute management unit 110 and the access control unit 130 can access the cloud server to read and write information as needed.
[0087] Furthermore, the functions of the information management and control device 100 can be implemented using a conventional computer system without relying on a dedicated device. For example, the programs used to implement the functions of the information management and control device 100 can be stored and distributed on a computer-readable recording medium such as a CD-ROM (Compact Disc Read Only Memory) or DVD-ROM (Digital Versatile Disc Read Only Memory), and the programs can be installed in a computer, thereby constructing a computer capable of implementing the aforementioned functions.
[0088] Alternatively, when the functions are implemented through a sharing of workload between the OS and the application, or through collaboration between the OS and the application, the application may be stored only on the recording medium.
[0089] As long as the spirit of this disclosure is not departed from, the structures listed in the above embodiments can be selected or omitted, or appropriately modified to other structures.
[0090] Furthermore, various embodiments and modifications can be implemented without departing from the broad spirit and scope of this disclosure. Moreover, the above embodiments are illustrative of this disclosure and do not limit its scope. That is, the scope of this disclosure is not shown through the embodiments, but through the claims. Furthermore, various modifications implemented within the scope of the claims and their equivalents are considered to be within the scope of this disclosure.
[0091] Label Explanation
[0092] 1: Information management and control system; 100: Information management and control device; 110: Attribute management unit; 120: Role generation unit; 130: Access control unit; 140: Memory; 150: API; 200: Device; 300: Gateway; 400: Terminal; 500: Network; 600: Custom role creation screen; 700: Parameter setting change screen; 800: Input screen; 11: Processor; 12: RAM; 13: ROM; 14: Storage unit; 15: Input unit; 16: Display unit; 17: Communication unit; 99: Internal bus.
Claims
1. An information management and control device, which manages content data including operational data of the managed device and controls access to the content data, wherein, This information management and control device has the following features: The attribute information assignment unit assigns attribute information to each of the content data based on a pre-set rule. The attribute information includes generation source information for identifying the generation source device of the content data. The allocation unit generates role information, which includes the source information of the content data and indicates the conditions for accessing the content data. The allocation unit also determines the source of the content data based on association information and assigns the generated role information to users of the delivery destinations authorized by the determined source. The association information associates the source information contained in the generated role information with the source of the content data generated by the device determined by the source information. as well as The determination unit determines whether a user can access the content data based on the attribute information assigned to the content data and the role information assigned to the user who made the access request.
2. The information management and control device according to claim 1, wherein, The allocation unit generates multiple role information for each providing source, and the allocation unit also allocates the generated role information to users of multiple providing destinations based on combined information representing the association between the providing source and the providing destination.
3. The information management and control device according to claim 1 or 2, wherein, The allocation section generates role information for users providing the content data as a source and users providing the content data as a destination, and provides the role information assigned to the users providing the content data as a destination based on pre-defined rules. The allocation department will also assign the role information provided to the user providing the destination to the user providing the destination.
4. The information management and control device according to claim 1 or 2, wherein, The role information includes attribute conditions, which are defined by a combination of multiple attributes assigned to the content data that can be accessed.
5. The information management and control device according to claim 1 or 2, wherein, The role information includes operation permissions, which represent the operations that can be performed on the content data. The determination unit further determines whether the operation content of the content data by the user who made the access request is included in the operation permissions of the role information assigned to the user. If it is determined that it is included, the operation content is permitted to be executed on the content data.
6. An information management and control system, wherein, This information management and control system has: The information management and control device according to claim 1 or 2 further comprises a memory for storing the content data; as well as The gateway obtains the content data from the managed object device and sends it to the information management and control device.
7. An information management and control method, wherein, In this information management and control method, the computer performs the following steps: Generate role information, which includes generation source information for identifying the content data generation source device and indicates the conditions for accessing the content data. The content data provider is determined based on the association information, and the generated role information is assigned to the user of the provider destination authorized by the determined provider. The association information associates the generation source information contained in the generated role information with the content data provider generated by the device determined by the generation source information. as well as Based on the attribute information including the source information of the content data and the role information assigned to the user who made the access request for the content data, it is determined whether the user can access the content data.
8. A computer-readable recording medium storing a computer program, wherein, This computer program causes a computer that manages content data, including operational data of the managed objects, and controls access to that content data, to perform the following processes: Generate role information, which includes generation source information for identifying the generation source device of the content data, and indicates the conditions for accessing the content data; The content data provider is determined based on the association information, and the generated role information is assigned to the user of the provider destination authorized by the determined provider. The association information associates the generation source information contained in the generated role information with the content data provider generated by the device determined by the generation source information. as well as Based on the attribute information including the source information of the content data and the role information assigned to the user who made the access request for the content data, it is determined whether the user can access the content data.