Information processing device, information output method, and information output program

By acquiring and comparing the differences between access permission setting data and resume data, suggestions are made to delete redundant access permissions, which solves the problem of users being granted unnecessary access permissions and improves system security and defense capabilities.

CN120883209APending Publication Date: 2025-10-31YOKOGAWA ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202380095002.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-02-28
Filing Date
2023-12-14
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, users are granted excessive access rights, leading to unnecessary resource utilization and excessive access to functions, which affects system security.

Method used

By acquiring access permission setting data and access history data for resources, the system calculates and outputs differential information to help minimize user access rights and proposes suggestions for deleting redundant access rights.

Benefits of technology

It effectively reduces user access rights, improves system security, prevents network attacks, and achieves minimal access rights management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120883209A_ABST
    Figure CN120883209A_ABST
Patent Text Reader

Abstract

An information processing device (10) is provided with: a first acquisition unit (16) that acquires setting data in which access rights for resources are set for each resource of a predetermined system; a second acquisition unit (18) that acquires history data of an access to the resource; and an output unit (19) that outputs resource information corresponding to the difference between the setting data and the history data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to an information processing apparatus, an information output method, and an information output program. Background Technology

[0002] As one of the security functions provided by OS (Operating System), there is an access control function that restricts the use of resources based on the permissions to use various resources shared through the system, also known as access rights.

[0003] Patent Document 1: Japanese Patent Application Publication No. 2016-143211 Summary of the Invention

[0004] However, when setting the aforementioned access rights, access is granted to the maximum number of resources that can perform all functions associated with the user's role. Therefore, there is a problem that users may be unnecessarily granted access rights to resources that they do not actually use.

[0005] The purpose of this invention is to help minimize the user's access rights.

[0006] An information processing apparatus according to one aspect of the present invention includes: a first acquisition unit that acquires setting data for setting access rights of each resource of a defined system; a second acquisition unit that acquires history data of accesses performed for the resource; and an output unit that outputs information about the resource corresponding to the difference between the setting data and the history data.

[0007] In one aspect of the information output method of the present invention, a computer performs the following processing: acquiring setting data for setting access rights of said resource for each resource of a specified system, acquiring history data of access performed for said resource, and outputting information of the resource corresponding to the difference between the setting data and the history data.

[0008] One aspect of the present invention relates to an information output program that causes a computer to perform the following processes: acquiring setting data for setting access rights for each resource of a specified system, acquiring history data of accesses performed for the resource, and outputting information about the resource corresponding to the difference between the setting data and the history data.

[0009] The effects of the invention

[0010] According to one implementation method, it is possible to help minimize the user's access rights. Attached Figure Description

[0011] Figure 1 This is a block diagram illustrating an example of the functional structure of an information processing device.

[0012] Figure 2 It is a flowchart representing the process of information output processing.

[0013] Figure 3 This is a diagram representing an example of access rights setting data.

[0014] Figure 4 This is a schematic diagram illustrating an example of an engineering design result.

[0015] Figure 5 This is a schematic diagram illustrating an example of setting access rights.

[0016] Figure 6 This is a schematic diagram illustrating an example of an operator's access operation.

[0017] Figure 7 This is a diagram illustrating an example of how access history can be retrieved.

[0018] Figure 8 This is a diagram illustrating the comparison between access rights settings and access history.

[0019] Figure 9 This is an example image showing a screen with a deletion suggestion.

[0020] Figure 10 This is an example image showing a screen with a deletion suggestion.

[0021] Figure 11 This is a diagram representing an example of access rights setting data.

[0022] Figure 12 This is a diagram illustrating an example of a hardware structure. Detailed Implementation

[0023] Hereinafter, embodiments of the information processing apparatus, information output method, and information output program related to this application will be described with reference to the accompanying drawings. Each embodiment shows only one example or aspect, and the numerical values, functional range, application scenarios, etc., are not limited by such examples. Moreover, the embodiments can be appropriately combined without contradicting the processing content.

[0024] Example 1

[0025] <Structure of Information Processing Device 10>

[0026] Figure 1 This is a block diagram illustrating an example of the functional structure of the information processing device 10. Figure 1 The information processing device 10 shown provides an information output function, which outputs information such as suggestions to minimize the user's access rights.

[0027] exist Figure 1The diagram schematically illustrates functional blocks associated with the information output function of the information processing device 10. For example... Figure 1 As shown, the information processing device 10 includes an input unit 11, a display unit 12, a storage unit 13, and a control unit 15.

[0028] The input unit 11 is a functional unit for inputting various operations. As an example, if the information processing device 10 is implemented as a desktop or laptop personal computer, the input unit 11 can be implemented as a general peripheral device such as a keyboard or mouse.

[0029] Display unit 12 is a functional unit that displays various information. As an example, display unit 12 can be implemented by liquid crystal display, organic EL (Electro Luminescence) display, etc.

[0030] The aforementioned input unit 11 and display unit 12 can be integrated as a display input unit implemented by a touch panel or the like.

[0031] Storage unit 13 is a functional unit that stores various types of data. As an example, storage unit 13 may be implemented using internal, external, or auxiliary storage devices of the information processing apparatus 10. For example, storage unit 13 stores access object data 13A, access right setting data 13B, and access history data 13C. Access right setting data 13B corresponds to an example of setting data, and access history data 13C corresponds to an example of history data. Furthermore, access object data 13A, access right setting data 13B, and access history data 13C will also be described in the context of performing reference, generation, or registration.

[0032] The control unit 15 is a functional unit that performs overall control of the information processing device 10. For example, the control unit 15 can be implemented by a hardware processor. Figure 1 As shown, the control unit 15 includes a first acquisition unit 16, a control function providing unit 17, a second acquisition unit 18, and an output unit 19.

[0033] As an example, the first acquisition unit 16, the second acquisition unit 18, and the output unit 19 can be implemented as processes by executing an information output program that performs the aforementioned information output function. On the other hand, the control function providing unit 17 can be implemented as a process by executing control software that performs the functions of the process control system described later. Furthermore, the control unit 15 can be implemented using hard-wired logic or the like.

[0034] The first acquisition unit 16 is a processing unit that acquires settings for access rights related to resources possessed by the information processing device 10. Here, "resources" refers to resources shared via any system. An example of such a system is a process control system that controls processes in a workshop. Specifically, resources are documents that implement the functions of the process control system. "Documents" here can include, for example, data files, executable files, libraries, etc. It is not limited to such files; folders used for accessing files, networks, and peripheral instruments that become output targets of files can also be included in the scope of resources. For example, the first acquisition unit 16 can accept input from a user with administrator privileges via the input unit 11 to set access rights for access object data 13A stored in the storage unit 13.

[0035] Here, access object data 13A refers to all the data of the object accessed by the user. This access object data 13A may contain various resources that implement the functions of the process control system provided by the control software. Furthermore, the process control system corresponds to an example of a defined system.

[0036] Below, as an example of an application scenario, an example is given of setting access rights for resources that enable the functions of a process control system provided by control software installed in a multi-user information processing device 10 used by multiple users.

[0037] As an example, control software can package modules corresponding to various functions such as engineering design functions and operation monitoring functions. Here, "engineering design functions" refers to functions that perform engineering design for field instruments set up in the workshop, such as network settings and alarm settings. "Operation monitoring functions" refer to functions that monitor the operation of the workshop via HMI (Human Machine Interface). Furthermore, while examples of engineering design functions and operation monitoring functions have been given here, control software can also package functions that perform form output to perform statistical analysis of process values ​​and output processed data in any form, such as daily reports, monthly reports, batch reports, or simplified batch reports.

[0038] Taking this process control system as an example, access rights settings can be processed via the input unit 11 when logged in by a user with administrator privileges (hereinafter referred to as "administrator").

[0039] In this scenario, as an example, an administrator can grant access to the maximum number of resources associated with the full range of functions for each user role, such as engineers who can perform and utilize engineering design functions, and operators who can utilize operation monitoring functions.

[0040] For example, access rights for engineers are set for resources such as data files and executable files used for engineering design. Additionally, access rights for operators are set for resources such as data files and executable files used for operation monitoring. Furthermore, access rights for engineers and operators are set for shared libraries shared between modules such as engineering design and operation monitoring functions.

[0041] After the administrator performs the access right setting, the first acquisition unit 16 saves the access right setting performed by the administrator as access right setting data 13B in the storage unit 13. Furthermore, while the example given here is the first acquisition unit 16 handling access right settings, it could also be configured to handle access right settings handled by the control function providing unit 17, which will be described later.

[0042] The control function providing unit 17 is a processing unit that provides the functions of various modules packaged in the control software. For example... Figure 1 As shown, the control function providing unit 17 has a first function providing unit 17A and a second function providing unit 17B.

[0043] For example, the first function providing unit 17A provides the engineering design function by executing a module that implements the above-mentioned engineering design function and expanding the process. Similarly, the second function providing unit 17B provides the operation monitoring function by executing a module that implements the above-mentioned operation monitoring function and expanding the process.

[0044] When performing the above-mentioned engineering design functions and operation monitoring functions, access control is performed on the resources contained in the access object data 13A based on the access permissions of the logged-in users contained in the access rights setting data 13B.

[0045] As one aspect, when an engineer logs in, they can perform engineering design for the control software through the engineering design function. As another aspect, when an operator logs in, they can perform operational monitoring of the workshop through the operation monitoring function.

[0046] The second acquisition unit 18 is a processing unit for acquiring access history. As an example, when access is performed to a resource contained in the access object data 13A, the second acquisition unit 18 generates an access log that associates the resource's identification information, the user's account information, and the type of access. This does not preclude the inclusion of other items such as the time of access in this access log. For example, in the case of access to a data file, access types such as read or write are generated. Similarly, in the case of access to an executable file, access types such as read or execute are generated. When an access log is generated in the above manner, the second acquisition unit 18 appends data entries of the access log to the access history data 13C stored in the storage unit 13. Furthermore, while the example given here is of the second acquisition unit 18 generating the log, it is also possible to obtain the access log from software that generates access logs, rather than having the second acquisition unit 18 generate the log.

[0047] Output unit 19 is an output unit that outputs various types of information. As an example of information output by output unit 19 in the manner described above, from the perspective of minimizing user access rights, information about resources for which access rights have been set can be provided, suggesting the deletion of access rights. As an example, when monitoring of workshop operations based on the operation monitoring function is stopped, and a user request for the aforementioned suggestion is received by the input unit 11 during administrator login, output unit 19 can initiate the following process under any other trigger. That is, output unit 19 compares access right setting data 13B and access history data 13C, and outputs the difference between the two. For example, output unit 19 causes display unit 12 to display a suggestion to delete access rights set in access right setting data 13B that do not have a detected access history in access history data 13C. Furthermore, while display output is given as an example of the output method of output unit 19, it could also be configured to perform print output, voice output, etc.

[0048] <Processing Flow>

[0049] Figure 2 It is a flowchart representing the process of information output and processing. For example... Figure 2 As shown, when an instruction to install the control software is received by a user with administrator privileges, i.e., an administrator, via the input unit 11, the control software is installed (step S101). Next, the control function providing unit 17, while logged in by the administrator, receives the setting of access rights for the access object data 13A via the input unit 11 (step S102).

[0050] Then, the first function providing unit 17A performs the engineering design of the control software by accepting instruction input via the input unit 11 while the engineer is logged in (step S103).

[0051] Then, the first acquisition unit 16 acquires the access rights settings obtained in step S102 (step S104). Based on this, the first acquisition unit 16 saves the access rights settings obtained in step S104 as access rights setting data 13B in the storage unit 13 (step S105).

[0052] Figure 3 This is a diagram representing an example of access rights setting data 13B. In Figure 3 The example given is a file, but access permissions can also be set for other resources such as folders. Furthermore, in... Figure 3 The example given is an administrator, engineer, or operator, but access rights can also be granted to other users, such as user groups. The role of a user is not limited to engineers or operators.

[0053] like Figure 3 As shown, access rights are set for different users based on access rights settings data 13B, for each file. For example, in Figure 3 The selected example illustrates the access rights set for the instrument NW (Network) configuration data file 13B1, trend data file 13B2, alarm data file 13B3, NW definition tool execution 13B4, trend data archiving execution 13B5, and inter-process data communication library 13B6 in the resources contained in the access object data 13A.

[0054] The instrument NW setting data file 13B1 is a data file that defines the network settings of field instruments installed in the workshop, such as measuring instruments, operating instruments, and controllers. As one aspect, there is a method for engineering designing the instrument NW setting data file 13B1 using the NW definition tool provided by the aforementioned engineering design function. Access rights for this instrument NW setting data file 13B1 are set as "read" and "write". Access rights for the operator O1 are also set as "read" and "write". Furthermore, access rights for the administrator A1 are set as "full control".

[0055] Trend data file 13B2 is a data file related to the trend, i.e., the time series change, of process values ​​sent from field instruments. As one aspect, there is an HMI (Hybrid Management Interface) such as an operation monitoring screen provided by the aforementioned operation monitoring function that monitors trend data file 13B2. Access rights for this trend data file 13B2 are set to "Read". Access rights for operator O1 are also set to "Read". Access rights for administrator A1 are set to "Full Control".

[0056] Alarm data file 13B3 is a data file that defines alarm settings output based on process values ​​from field instruments. One aspect includes an engineering design that compares the alarm data file 13B3 with the process values ​​using the aforementioned engineering design functions. Access rights for this alarm data file 13B3 are set to "read" and "write". Access rights for operator O1 are also set to "read" and "write". Furthermore, access rights for administrator A1 are set to "full control".

[0057] The NW Definition Tool Execution 13B4 is a program file, or executable file, that assists in defining the network settings of field instruments. The access rights of the engineer E1 who executes this NW Definition Tool 13B4 are set to "Read" and "Execute". The access rights of the operator O1 are also set to "Read" and "Execute". Furthermore, the access rights of the administrator A1 are set to "Full Control".

[0058] Trend data archiving execution 13B5 is an executable file that generates an archive of trend data. The access rights for engineer E1 to this trend data archiving execution 13B5 are set to "read" and "execute". Furthermore, the access rights for operator O1 are also set to "read" and "execute". Finally, the access rights for administrator A1 are set to "full control".

[0059] Inter-process data communication library 13B6 is a library for data communication between processes with engineering design functions and operation monitoring functions. The access rights of engineer E1 to this inter-process data communication library 13B6 are set to "read" and "execute". Furthermore, the access rights of operator O1 are set to "read" and "execute". And the access rights of administrator A1 are set to "full control".

[0060] Return to Figure 2 The process described below, from the start of monitoring the workshop operation in step S105 until the stop of monitoring the workshop operation in step S108, involves performing the following steps S106 and S107.

[0061] That is, the second function providing unit 17B accepts instruction input via the input unit 11 while the operator is logged in, and then performs an access operation for the resource with access rights via the operation monitoring function (step S106).

[0062] Each time such an access operation is performed, the second acquisition unit 18 acquires the access history, which includes the resource identification information, the user's account information, and the type of access, and registers the data entries of the access history with the access history data 13C (step S107).

[0063] Then, after the monitoring of the workshop operation is stopped in step S108, the output unit 19 compares the access right setting data 13B and the access history data 13C (step S109).

[0064] Furthermore, the output unit 19 causes the display unit 12 to display the difference between the access right setting data 13B and the access history data 13C (step S110). At this time, as an example, the output unit 19 can cause the display unit 12 to display a suggestion to delete the access right that was not detected in the access history data 13C from the access rights set in the access right setting data 13B.

[0065] After the difference is displayed in step S110 as described above, the output unit 19 can receive an execution instruction to delete the access right from the administrator (step S301). Based on this, the output unit 19 deletes the access right in the access right setting data 13B for which the deletion execution instruction was received in step S301 (step S302). Furthermore, this example illustrates the deletion of access rights when a user operation has been performed, i.e., when the deletion execution instruction in step S301 has been received, but it is not limited to this. For example, even without a user operation, the access right to the resource corresponding to the difference can be automatically deleted after the difference is extracted. In this case, the information processing device 10 can have a deletion unit that performs the deletion of access rights in place of the output unit 19.

[0066] <Specific example>

[0067] Here, using Figures 4-8 This section describes an example of comparing access permission setting data 13B with access history data 13C. Figure 4 This is a schematic diagram illustrating an example of an engineering design result. Figure 5 This is a schematic diagram illustrating an example of setting access rights. Figure 6 This is a schematic diagram illustrating an example of an access operation by operator O1. Figure 7 This is a diagram illustrating an example of how access history can be retrieved. Figure 8 This is a diagram illustrating the comparison between access rights settings and access history.

[0068] exist Figure 4 The image shows the resources contained in Access Object Data 13A, in... Figure 2 The step S103 shown executes the resource management of the engineering design state of the control software. More specifically, it is shown that... Figure 3The examples shown are of the instrument NW setting data file 13B1, trend data file 13B2, alarm data file 13B3, NW definition tool execution 13B4, trend data archiving execution 13B5, and inter-process data communication library 13B6.

[0069] Then, in Figure 2 In step S104 shown, as Figure 5 As shown, the first acquisition unit 16 acquires the access rights settings related to the instrument NW setting data file 13B1, trend data file 13B2, alarm data file 13B3, NW definition tool execution 13B4, trend data archiving execution 13B5, and inter-process data communication library 13B6.

[0070] Here, in Figure 5 As an example, the first acquisition unit 16 acquires the access rights settings of operator O1, showing the identifiers corresponding to the types of access rights associated with each file labeled 13B1 to 13B6. For example, in the case of a data file, if the "read" access right is set, the identifier "R" is associated with the data file; on the other hand, if both "read" and "write" access rights are set, the identifier "RW" is associated with the data file. Similarly, in the case of an executable file, if the "read" access right is set, the identifier "R" is associated with the executable file; on the other hand, if both "read" and "execute" access rights are set, the identifier "RX" is associated with the executable file.

[0071] The access rights of operator O1 obtained in the above manner are set in Figure 2 In step S104 shown, the access right setting data 13B is saved in the storage unit 13 (see reference). Figure 3 ).

[0072] Moreover, in Figure 2 In step S106 as shown, as Figure 6 As shown, the access operation is performed by operator O1. Here, in Figure 6 The white background with black text indicates the access types that have been accessed and associated with the files numbered 13B1 to 13B6. On the other hand, the black and white reversed display shows the access types that have not been accessed.

[0073] Then, in Figure 2 In step S107 shown, the second acquisition unit 18 acquires the access history of operator O1 for each file labeled 13B1 to 13B6. According to... Figure 7The example shown illustrates that the second acquisition unit 18 acquires the identifiers associated with the files labeled 13B1 to 13B6, and executes the process. Figure 6 The access operation shown corresponds to the access type, i.e., the access history shown in black text on a white background. Examples include: access logs containing the resource "Trend Data File 13B2" and access type "Read In"; access logs containing the resource "Alarm Data File 13B3" and access type "Read In"; access logs containing the resource "Inter-process Data Communication Library 13B6" and access type "Read In"; and access logs containing the resource "Inter-process Data Communication Library 13B6" and access type "Execute".

[0074] Based on this, Figure 2 In step S109 shown, as Figure 8 As shown, the output unit 19 compares the access permission setting data 13B and the access history data 13C. In this case, the unexecuted identifiers associated with each file labeled 13B1 to 13B6 are extracted. Figure 6 The access type of the operator O1's access operation shown, that is, the access right corresponding to the identifier displayed in a black-and-white inverted display mode, is used as the difference. If we take examples separately, the access rights "read" and "write" of the resource "Instrument NW Setting Data File 13B1", the access right "write" of the resource "Alarm Data File 13B3", the access rights "read" and "execute" of the resource "NW Definition Tool Execution 13B4", and the access rights "read" and "execute" of the resource "Trend Data Archive Execution 13B5" are extracted as the difference.

[0075] In the case of extracting this difference, Figure 2 In step S110 shown, the output unit 19 displays... Figure 9 The deletion suggestion screen shown is 20. Figure 10 The deletion suggestion screen shown is 40, etc.

[0076] Figure 9 and Figure 10 This is an example image showing a screen displaying a deletion suggestion. For example... Figure 9 and Figure 10As shown, the deletion suggestion screens 20 and 40 propose deleting the following four access rights. First, it proposes deleting the "Read" and "Write" access rights for the resource "Instrument NW Setting Data File 13B1". Second, it proposes deleting the "Write" access right for the resource "Alarm Data File 13B3". Third, it proposes deleting the "Read" and "Execute" access rights for the resource "NW Definition Tool Execution 13B4". Fourth, it proposes deleting the "Read" and "Execute" access rights for the resource "Trend Data Archive Execution 13B5".

[0077] Through these deletion suggestion screens 20 and 40, access rights to resources used for performing functions that the user does not actually use can be displayed as redundant access rights. Thus, for example, in addition to prompting the deletion of data files and executable files intended for engineers from the access rights of operators who only use the operation monitoring function, it can also prompt the deletion of executable files that the operator does not use from the files related to the operation monitoring function.

[0078] The aforementioned deletion suggestion screens 20 and 40 can approve or reject each deletion suggestion via any GUI (Graphical User Interface) component.

[0079] For example, Figure 9 In the example of the deletion suggestion screen 20 shown, by selecting either radio button 22A or 22R, which is configured to be associated with the first deletion suggestion, the administrator can decide whether to approve the first deletion suggestion. Similarly, by selecting radio buttons 23A or 23R, 24A or 24R, or 25A or 25R, the administrator can decide whether to approve the second to fourth deletion suggestions. If the execute button 26 is pressed while one of the two radio buttons configured for each of the four deletion suggestions has been selected, the output unit 19 will delete the access rights corresponding to the approved deletion suggestion. Furthermore, if the cancel button 27 is pressed, even if the approve radio buttons 22A to 25A are selected, the output unit 19 will not delete the access rights corresponding to the deletion suggestion.

[0080] In addition, Figure 10In the example of the deletion suggestion screen 40 shown, by selecting either the approve button 42A or the reject button 42R, which is configured in association with the first deletion suggestion, the administrator can choose whether to approve the first deletion suggestion. Similarly, by selecting either the approve button 43A or the reject button 43R, the approve button 44A or the reject button 44R, or the approve button 45A or the reject button 45R, the administrator can choose whether to approve the second to fourth deletion suggestions. When either the approved button or the reject button, configured separately for each of the four deletion suggestions, is selected, the output unit 19 deletes the access rights corresponding to the deletion suggestion for which the approve button was selected. Furthermore, when the all-approval button 46 is selected, all access rights corresponding to the four deletion suggestions are deleted. Moreover, when the all-reject button 47 is selected, the output unit 19 does not delete the access rights corresponding to the deletion suggestions.

[0081] As an example, if all four deletion recommendations are approved, then by deleting all the access rights corresponding to the four deletion recommendations, Figure 3 The access permission setting data shown in 13B is directed to... Figure 11 The access rights settings data shown in 13B has been updated.

[0082] Figure 11 This is a diagram representing an example of access rights setting data 13B. (See diagram for example.) Figure 11 As shown, with all four deletion recommendations approved, the shaded portion of the access rights column for access rights setting data 13B is updated. Specifically, the access rights for resource "Instrument NW Setting Data File 13B1" are updated from "Read" and "Write" to "No Access Rights". Furthermore, the access rights for resource "Alarm Data File 13B3" are updated from "Read" and "Write" to "Read". Furthermore, the access rights for resource "NW Definition Tool Execution 13B4" are updated from "Read" and "Execute" to "No Access Rights". Finally, the access rights for resource "Trend Data Archive Execution 13B5" are updated from "Read" and "Execute" to "No Access Rights".

[0083] <One aspect of the effect>

[0084] As described above, the information processing apparatus 10 of this embodiment acquires setting data that sets access rights for each resource of the process control system, acquires access history data for the resource, and outputs the resource corresponding to the difference between the setting data and the history data.

[0085] Therefore, as one aspect, it enables administrators to treat access rights to resources that have not been detected for access in the access rights set for the data as redundant access rights, which in turn promotes the deletion of redundant access rights.

[0086] Therefore, the information processing apparatus 10 according to this embodiment can assist in minimizing the user's access rights. By achieving this minimization of access rights, it can function as one of the robust multi-layered defenses against network attacks.

[0087] <Numerical values, etc.>

[0088] The items described in the above embodiments, such as the number of user accounts, the number of user role types, the number and types of data files, executable files, libraries, and the structure of the GUI components in the deletion suggestion screen, are just examples and can be changed. Furthermore, the flowcharts described in the embodiments can also be changed in terms of processing order without contradiction.

[0089] <System>

[0090] The information, including the processing flow, control flow, specific names, various data, and parameters shown in the above description and accompanying drawings, can be arbitrarily changed except in cases specifically described. For example, any one or more of the functional units, such as the first acquisition unit 16, the control function providing unit 17, the second acquisition unit 18, and the output unit 19, can be composed of different devices. As an example, the above-mentioned information output function can be provided to a client-server system, including a server device that provides the function of the control function providing unit 17 (i.e., the function of a process control system) and client terminals used by each user. In this case, the access object data 13A can be stored in the storage of the server device or in an external device such as a file server. In this case, the functional units corresponding to the above-mentioned information output function, namely the first acquisition unit 16, the second acquisition unit 18, and the output unit 19, can be assembled in the same server device as the server device equipped with the function of the control function providing unit 17, and the server device equipped with the function of the control function providing unit 17 can be assembled in a computer.

[0091] Furthermore, the structural elements of the devices illustrated are functional concepts and do not necessarily have to be physically arranged as shown. That is, the specific methods of distributing and integrating the devices are not limited to the illustrated representation. In other words, all or part of each device can be functionally or physically distributed and integrated in any unit according to various loads, usage conditions, etc. In addition, each structure can be a physical structure.

[0092] Furthermore, all or any part of the processing functions performed by each device can be implemented by a CPU (Central Processing Unit) and the program parsed and executed by the CPU, or can be implemented as wired logic-based hardware.

[0093] <Hardware>

[0094] Next, an example of the computer hardware structure described in the implementation method will be explained. Figure 12 This is a diagram illustrating an example of hardware structure. For example... Figure 12 As shown, the information processing device 10 includes a communication device 10a, an HDD (Hard Disk Drive) 10b, a memory 10c, and a processor 10d. Additionally, Figure 12 The various parts shown are connected to each other by buses, etc.

[0095] Communication device 10a is a network interface card, etc., used for communication with other servers. HDD 10b is used for... Figure 1 The program, database, etc., that perform the functions shown are stored.

[0096] Processor 10d will execute with Figure 1 The same processing program shown is read from HDD100b and expanded in memory 100c, thereby enabling execution. Figure 1 The process performs the functions described in the preceding text. For example, the process performs the same functions as the processing unit of the information processing device 10. Specifically, the processor 10d reads a program from the HDD 10b, etc., which has the same functions as the first acquisition unit 16, the control function providing unit 17, the second acquisition unit 18, and the output unit 19. Moreover, the processor 10d executes a process that performs the same processing as the first acquisition unit 16, the control function providing unit 17, the second acquisition unit 18, and the output unit 19.

[0097] Thus, the information processing device 10 operates as an information processing device that performs an information output method by reading and executing a program. Furthermore, the information processing device 10 can also read the program from a recording medium using a media reading device and execute the read program, thereby achieving the same function as in the above-described embodiment. Moreover, the program described in other embodiments is not limited to execution by the information processing device 10. For example, the present invention can also be applied when other computers or servers execute the program, or when they cooperate in executing the program.

[0098] The aforementioned program can be distributed via networks such as the Internet. Furthermore, the program can be recorded on any recording medium and executed by a computer from that medium. For example, the recording medium can be a hard disk, floppy disk (FD), CD-ROM, MO (Magneto-Optical disk), DVD (Digital Versatile Disc), etc.

[0099] <Other>

[0100] The following are some examples of combinations of publicly disclosed technical features.

[0101] (1) An information processing device, characterized in that,

[0102] The information processing device has:

[0103] The first acquisition unit acquires setting data for setting access rights for each resource of the specified system.

[0104] The second acquisition unit acquires historical data of accesses performed against the resource; and

[0105] The output unit outputs information about the resources corresponding to the difference between the set data and the history data.

[0106] (2) The information processing apparatus according to (1) is characterized in that,

[0107] The output unit outputs a deletion suggestion as information about the resource, which proposes to delete the access rights of the resource that was not detected as being accessed in the history data in the access rights set in the setting data.

[0108] (3) The information processing apparatus according to (2), characterized in that,

[0109] The output unit also performs the process of deleting access rights to the resources corresponding to the deletion suggestions that have been accepted and approved in the deletion suggestions, from the set data.

[0110] (4) The information processing apparatus according to any one of (1) to (3), characterized in that,

[0111] The resources mentioned are the resources that enable the process control system to control the processes in the workshop.

[0112] (5) The information processing apparatus according to any one of (1) to (4), characterized in that,

[0113] The resource can be any file, including data files, executable files, or libraries.

[0114] (6) An information output method, characterized in that,

[0115] The information output method causes the computer to perform the following processing:

[0116] Retrieve configuration data that sets access rights for each resource in the specified system.

[0117] Obtain the access history data performed on the resource.

[0118] Output information about the resources corresponding to the difference between the set data and the history data.

[0119] (7) An information output program, characterized in that,

[0120] The information output program causes the computer to perform the following processes:

[0121] Retrieve configuration data that sets access rights for each resource in the specified system.

[0122] Obtain the access history data performed on the resource.

[0123] Output information about the resources corresponding to the difference between the set data and the history data.

[0124] Explanation of the label

[0125] 10. Information processing device

[0126] 11 Input Section

[0127] 12 Display Section

[0128] 13 Storage Department

[0129] 13A Accessing Object Data

[0130] 13B Access Rights Setting Data

[0131] 13C Access History Data

[0132] 15. Control Department

[0133] 16 First Acquisition Department

[0134] 17. Control Function Provision Department

[0135] 17A First Functional Provision Department

[0136] 17B Second Functional Provision Department

[0137] 18. Second Acquisition Department

[0138] 19 Output Section

Claims

1. An information processing device, characterized in that, The information processing device has: The first acquisition unit acquires setting data for setting access rights for each resource of the specified system. The second acquisition unit acquires the history data of accesses performed against the resource; as well as The output unit outputs information about the resources corresponding to the difference between the set data and the history data.

2. The information processing device according to claim 1, characterized in that, The output unit outputs a deletion suggestion as information about the resource, which proposes to delete the access rights of the resource that was not detected as being accessed in the history data in the access rights set in the setting data.

3. The information processing device according to claim 2, characterized in that, The output unit also performs the following process: it removes the access rights of the resources corresponding to the deletion suggestions in the deletion suggestions that have been accepted and approved from the setting data.

4. The information processing apparatus according to claim 1, characterized in that, The resources mentioned are the resources that enable the process control system to control the processes in the workshop.

5. The information processing apparatus according to any one of claims 1 to 4, characterized in that, The resource can be any file, including data files, executable files, or libraries.

6. An information output method, characterized in that, The information output method causes the computer to perform the following processing: Retrieve configuration data that sets access rights for each resource in the specified system. Obtain the access history data performed on the resource. Output information about the resources corresponding to the difference between the set data and the history data.

7. An information output program, characterized in that, The information output program causes the computer to perform the following processes: Retrieve configuration data that sets access rights for each resource in the specified system. Obtain the access history data performed on the resource. Output information about the resources corresponding to the difference between the set data and the history data.

Citation Information

Patent Citations

  • File management apparatus

    JP2016143211A