Portable information terminal and control method thereof
By designating an external application lock function, the operation of portable information terminals can be allowed or restricted based on operator authentication, solving the problem of the inability to effectively restrict operation in existing technologies and achieving a balance between security and convenience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- MAXELL LTD
- Filing Date
- 2018-02-26
- Publication Date
- 2026-05-01
AI Technical Summary
When existing portable information terminals are given to others for use, it is impossible to effectively restrict operations other than specific applications, leading to the leakage of personal information and financial losses. Moreover, existing technologies cannot achieve the ideal ease of use.
It employs an application-exclusive lockout feature, which allows operation of specific applications and restricts other operations, including facial recognition and PIN input processing, by authenticating authorized users.
It enables flexible control of portable information terminal functions based on the operator's restrictions, ensuring the security of personal information and property while maintaining convenience.
Smart Images

Figure CN121959533A_ABST
Abstract
Description
Portable information terminal and its control method
[0001] This application is a divisional application of the invention patent application with application number 201880063547.2 (PCT / JP2018 / 006839), application date February 26, 2018 (file date March 30, 2020), and invention title "Portable Information Terminal and Control Method Thereof". Technical Field
[0002] This invention relates to a portable information terminal and its control method. Background Technology
[0003] Smartphones, tablets, and other portable information devices have become widespread. These devices can store a great deal of personal information and also have functions such as monetary transactions and various settlement processing. Therefore, if a portable information device is used without authorization by a third party, there is a possibility of loss of personal information and financial losses.
[0004] To prevent such losses, the portable information terminal has a terminal locking function that restricts terminal functions. Generally, this restriction is temporarily lifted after authorized user authentication, such as when the power is on or when resuming from sleep mode, to allow operation. Furthermore, as described in Patent Document 1 below, there is a technology that, even after authorized user authentication via fingerprint verification and login to the computer, repeatedly verifies the authorized user through periodic facial recognition. If the facial recognition fails, the user is automatically logged out of the computer, thereby restricting operations performed by anyone other than the authorized user and improving security.
[0005] Existing technical documents
[0006] Patent documents
[0007] Patent Document 1: Japanese Patent Application Publication No. 2011-13855 Summary of the Invention
[0008] Smartphones, tablets, and other portable information terminals have camera functions, and images taken using these cameras are recorded to the storage device of the portable information terminal. Considering that the user of the portable information terminal may want to share and view the images recorded on the storage device with friends, the portable information terminal is sometimes given to a friend with an image viewing application running so that the friend can operate the application.
[0009] In this scenario, the user of the portable information terminal, while allowing operation of the image viewing application for friends, does not wish to allow other operations. That is, it is preferable that the portable information terminal, in addition to the aforementioned terminal locking function, also possesses a designated application (APP) external locking function. This function restricts operation on all predetermined applications (in the above example, the image viewing application) selected by the user, but restricts other operations when the user is not the operator, thereby controlling the portable information terminal. However, Patent Document 1 does not describe a control that allows some terminal functions to operate independently of the operator while simultaneously restricting other terminal functions based on the operator's actions.
[0010] Furthermore, there are portable information terminals equipped with an access guidance function that restricts access in ways other than those displayed on the screen. In such terminals, by using the access guidance function while an image viewing application is running, operations other than those within the image viewing application can be restricted. However, while using this access guidance function, not only friends but also authorized users of the portable information terminal are restricted from other operations. To perform other operations, even authorized users must undergo authentication to terminate the access guidance function. Furthermore, if the access guidance function is terminated, others other than authorized users can perform other operations, thus failing to achieve ideal ease of use.
[0011] The purpose of this invention is to provide a portable information terminal and its control method that can restrict terminal functions according to the operator.
[0012] As a means of solving the aforementioned problem, the technology described in the claims is used.
[0013] To give an example, a control method for a portable information terminal is characterized by accepting operations for restricting operations on the portable information terminal's application performed by users other than the official users of the portable information terminal, authenticating whether the user is an official user of the portable information terminal, allowing operations on the portable information terminal's application if the user is authenticated as an official user, and restricting operations on the portable information terminal's application if the user is not authenticated as an official user.
[0014] According to the present invention, a portable information terminal and its control method can be provided that can limit the terminal functions according to the operator. Attached Figure Description
[0015] Figure 1A is a hardware structure diagram of the portable information terminal of Embodiment 1.
[0016] Figure 1B is an external view of the portable information terminal of Embodiment 1.
[0017] Figure 1C is a software structure diagram of the portable information terminal of Embodiment 1.
[0018] Figure 2A is a diagram showing the operational state transition of the portable information terminal in Embodiment 1.
[0019] Figure 2B is a flowchart of the temporary unlocking process of the terminal lock function of the portable information terminal in Embodiment 1.
[0020] Figure 2C is a screenshot of the PIN input screen during user authentication processing in Example 1.
[0021] Figure 2D is a screenshot of the main screen in the normal operating state of Embodiment 1.
[0022] Figure 3A is a flowchart of the designated application lock function of the portable information terminal in Embodiment 1.
[0023] Figure 3B is a screenshot of the image viewing application execution screen of Embodiment 1.
[0024] Figure 3C is an operational concept diagram illustrating the scope of operational instructions for a specified application in Embodiment 1.
[0025] Figure 3D is a flowchart of the designated application lock function of the portable information terminal in Embodiment 1.
[0026] Figure 4 is an appearance diagram of the HMD type portable information terminal of Embodiment 1.
[0027] Figure 5 is a flowchart of the designated application lock function of the portable information terminal in Embodiment 2.
[0028] Figure 6 is a flowchart of the designated application lock function of the portable information terminal in Embodiment 3.
[0029] Figure 7 is a flowchart of the designated application lock function of the portable information terminal in Embodiment 4.
[0030] (Symbol Explanation)
[0031] 100: Portable information terminal; 101: Main control unit; 102: System bus; 103: ROM; 104: RAM; 110: Storage device unit; 120: Operation input unit; 121: Operation key; 122: Touch sensor; 123: Touch panel; 130: Image processing unit; 131: Display unit; 132: Image signal processing unit; 133: First image input unit; 134: Second image input unit; 140: Sound processing unit; 150: Sensor unit; 160: Communication unit; 170: Expansion interface unit; 180: Touch screen; 1101: Basic operation function unit; 1102: Lock control function unit; 1102T: Terminal lock function unit; 1102A: Designated application external lock function unit; 1103: User authentication function unit; 1103P: PIN input processing unit; 1103F: Facial authentication processing unit; 1103H: Fingerprint authentication processing unit. Detailed Implementation
[0032] Hereinafter, examples of embodiments are described using the accompanying drawings.
[0033] Example 1
[0034] The portable information terminal 100 of this embodiment has the following application-exclusive locking function: Operations on predetermined applications selected by the registered user are allowed for all operators, but other operations are appropriately restricted when the registered user is not the operator. The portable information terminal 100 can be a mobile phone, smartphone, tablet, etc. It can also be a PDA (Personal Digital Assistant), a laptop PC (Personal Computer), an e-book reader, etc. Additionally, it can be a still digital camera, a video camera capable of recording video, a portable game console, or other digital devices.
[0035] [Example of hardware structure for a portable information terminal]
[0036] Figure 1A is a hardware structure diagram showing an example of the internal structure of a portable information terminal 100. The portable information terminal 100 includes a main control unit 101, a system bus 102, a ROM 103, a RAM 104, a storage device unit 110, an operation input unit 120, an image processing unit 130, a sound processing unit 140, a sensor unit 150, a communication unit 160, and an expansion interface unit 170.
[0037] The main control unit 101 is a microprocessor unit that controls the entire portable information terminal 100 according to a predetermined action program. The system bus 102 is a data communication path used for sending and receiving various commands and data between the main control unit 101 and the various action blocks within the portable information terminal 100.
[0038] ROM (Read Only Memory) 103 is a memory that stores basic operating programs such as the operating system, as well as other operating programs (application programs, the same below). For example, it can be a rewritable ROM such as EEPROM (Electrically Erasable Programmable ROM) or flash memory ROM. RAM (Random Access Memory) 104 is the working area when the basic operating programs and other operating programs are executed. ROM 103 and RAM 104 can also be integrated with the main control unit 101. Alternatively, ROM 103 may not be a separate structure as shown in FIG. 1A, but may use a portion of the storage area within the storage device unit 110.
[0039] The storage device unit 110 stores the operating program, operating settings, personal information of the registered user of the portable information terminal 100, authentication information, etc. It can also store operating programs downloaded from the network and various data created using those operating programs. Furthermore, it can store content such as animations, still images, and sounds downloaded from the network. Additionally, it can store animations and still images captured using the camera function. A portion of the storage device unit 110 can replace all or part of the functions of the ROM 103. Moreover, the storage device unit 110 needs to maintain the stored information even when the portable information terminal 100 is not powered externally. Therefore, devices such as flash memory ROM, SSD (Solid State Drive), and HDD (Hard Disc Drive) disk drives are used.
[0040] Furthermore, the various operating programs stored in ROM 103 and storage device 110 can be updated and have their functions expanded by downloading from various server devices on the network.
[0041] The operation input unit 120 is an instruction input unit for inputting operation instructions for the portable information terminal 100. The operation input unit 120 includes operation keys 121 arranged with push-button switches, a touch sensor 122 that detects the operator's finger touch based on changes in electrostatic capacitance, and a touch panel 123 superimposed on the display unit 131. Other operating devices may also be included. The portable information terminal 100 can also be operated using a keyboard or the like connected to the expansion interface unit 170. The portable information terminal 100 can also be operated using a separate portable terminal device connected via wired or wireless communication. Furthermore, the touch sensor 122 has the function of detecting fingerprints or palm prints of the fingers touching the sensor unit.
[0042] The image processing unit 130 includes a display unit 131, an image signal processing unit 132, a first image input unit 133, and a second image input unit 134. The display unit 131 is, for example, a display device such as a liquid crystal panel, providing the user of the portable information terminal 100 with image data processed by the image signal processing unit 132. The image signal processing unit 132 includes a video RAM (not shown). The display unit 131 is driven based on the image data input to the video RAM. Furthermore, the image signal processing unit 132 has functions such as decoding encoded image signals, format conversion processing, menu processing, and overlay processing of other OSD (On Screen Display) signals as needed. The first image input unit 133 and the second image input unit 134 are camera units that input image data of surrounding objects by converting light input from a lens into electrical signals using electronic devices such as CCD (Charge Coupled Device) and CMOS (Complementary Metal Oxide Semiconductor) sensors.
[0043] The sound processing unit 140 includes a sound output unit 141, a sound signal processing unit 144, and a sound input unit 145. The sound output unit 141 is a speaker that provides the sound signal processed by the sound signal processing unit 144 to the operator of the portable information terminal 100. Specifically, the mono speaker 142 outputs mono sound during voice calls, etc., and the stereo speaker 143 outputs stereo sound during music playback, etc. The sound signal processing unit 144 has functions such as decoding encoded sound signals as needed. The sound input unit 145 is a microphone that converts the operator's voice, etc., into sound data for input.
[0044] The sensor unit 150 is a group of sensors used to detect the status of the portable information terminal 100. The sensor unit 150 includes a GPS (Global Positioning System) receiver 151, a gyroscope sensor 152, a geomagnetic sensor 153, an accelerometer 154, an illuminance sensor 155, and a proximity sensor 156. Through this group of sensors, the position, tilt, angle, movement, ambient brightness, and proximity of surrounding objects of the portable information terminal 100 can be detected. Additionally, the portable information terminal 100 may also include other sensors such as a barometric pressure sensor.
[0045] The communication unit 160 includes a LAN (Local Area Network) communication unit 161, a telephone network communication unit 162, and an NFC (Near Field Communication) unit 163. The LAN communication unit 161 connects to a network such as the Internet via an access point, and transmits and receives data with various server devices on the network. The connection to the access point can also be made wirelessly using Wi-Fi (a Japanese registered trademark). The telephone network communication unit 162 performs telephone communication (calls) and transmits and receives data via wireless communication with base stations of mobile phone communication networks. Communication with the base stations can also be made using W-CDMA (Wideband Code Division Multiple Access) (a Japanese registered trademark), LTE (Long Term Evolution), or other methods. The NFC unit 163 performs wireless communication when it is near a corresponding reader / writer. Each of the LAN communication unit 161, the telephone network communication unit 162, and the NFC unit 163 has an encoding circuit, a decoding circuit, and an antenna. In addition, the communication processing unit 160 may also include other communication units such as Bluetooth (a registered trademark in Japan) communication unit and infrared communication unit.
[0046] The expansion interface unit 170 is a group of interfaces used to expand the functionality of the portable information terminal 100. The expansion interface unit 170 includes an image / audio interface, a USB (Universal Serial Bus) interface, a memory interface, etc. The image / audio interface handles input of external images / image signals / audio signals from audio output devices, and output of external images / image signals / audio signals to audio input devices. The USB interface connects to a PC or similar device for data transmission and reception. It can also connect to a keyboard or other USB devices. Additionally, it can be used when charging the built-in battery (not shown). The memory interface connects to a memory card or other memory media for data transmission and reception.
[0047] Furthermore, the structural example of the portable information terminal 100 shown in Figure 1A also includes many structures that are not essential in this embodiment, but the effect of this embodiment will not be impaired even if these structures are not present. In addition, structures not shown, such as digital broadcast receiving function and electronic money settlement function, can be further added.
[0048] [Example of the appearance of a portable information terminal]
[0049] Figure 1B is an appearance diagram showing an example of the appearance of the portable information terminal 100. Furthermore, this figure illustrates examples of a front view (front view) and a rear view (back view) of the portable information terminal 100 when the portable information terminal 100 is a smartphone or the like; the left and right sides, top and bottom, etc., are omitted from the diagram.
[0050] The front surface of the portable information terminal 100 includes an action indicator 124, a first image input unit 133, a mono speaker 142, and a touch screen 180. The action indicator 124 reports the operating status of the portable information terminal 100 based on the presence or absence of an LED (Light Emitting Diode). The touch screen 180 includes a touch panel 123 and a display unit 131.
[0051] On the back of the portable information terminal 100, there is a touch sensor 122, a second image input unit 134, an auxiliary light emitter 135, and a stereo speaker 143. The auxiliary light emitter 135 can emit auxiliary light to compensate for insufficient light when an image is input from the second image input unit 134.
[0052] The upper surface of the portable information terminal 100 has a power button 121p, which is one of the operation keys 121. The lower surface of the portable information terminal 100 has a voice input unit 145 and a μ-USB input unit 170u, which is one of the expansion interface units 170.
[0053] Furthermore, as shown in the figure, the first image input unit 133 is disposed on the front surface, and the second image input unit 134 is disposed on the back surface, which is a different surface from the first image input unit 133. Hereinafter, the first image input unit 133 is sometimes referred to as the "in-camera," and the second image input unit 134 is sometimes referred to as the "out-camera." Additionally, the touch sensor 122 may not be disposed on the back of the portable information terminal 100, but rather on the side, the lower part of the front surface (the part that does not overlap with the touch screen 180), etc. Furthermore, the touch panel 123 constituting the touch screen 180 may also function as the touch sensor 122. In this case, the function of the touch sensor 122 (e.g., fingerprint authentication) can be performed at any location on the touch screen 180.
[0054] [Example of software architecture for portable information terminals]
[0055] Figure 1C is a software structure diagram of the portable information terminal 100, showing an example of the software structure in the storage device unit 110 (or ROM 103, hereinafter the same) and RAM 104. The storage device unit 110 stores a basic operation program 1001, a lock control program 1002, a user authentication program 1003, and other operation programs 1009. In addition, the storage device unit 110 has an authentication information storage area 1011 for storing authentication information of the official user of the portable information terminal 100, and various information storage areas 1019 for storing other information.
[0056] The basic operation program 1001 stored in the storage device unit 110 is expanded in the RAM 104, and then the main control unit 101 executes the expanded basic operation program to form the basic operation function unit 1101. Similarly, the lock control program 1002, the user authentication program 1003, and other operation programs 1009 are expanded in the RAM 104, and then the main control unit 101 executes each of the expanded operation programs to form the lock control function unit 1102, the user authentication function unit 1103, and other operation function units 1109. In addition, the RAM 104 has a temporary storage area 1200 for temporarily storing data created during the execution of each operation program as needed.
[0057] Furthermore, for the sake of simplicity, the following description will focus on the process by which the main control unit 101 expands and executes the basic operation program 1001 stored in the storage device unit 110 in the RAM 104 to control each operation block, and the basic operation function unit 1101 controls each operation block. Other operation programs will be described in the same way.
[0058] The lock control function unit 1102 has two lock control functions. The first is a terminal lock function, which controls the operation state of the portable information terminal 100 to either a terminal lock state where the operation of various functions of the portable information terminal 100 is restricted in batches, or a terminal unlock state where the operation of various functions of the portable information terminal 100 is appropriately permitted. The terminal lock state refers to a state in which operation instructions such as turning the power on / off of the portable information terminal 100, turning the sleep mode on / off, and user authentication processing for unlocking the terminal lock state are accepted, but other operation instructions are not accepted. However, functions automatically performed by the terminal system, such as searching for access points, base stations, etc., and checking emails, can be appropriately permitted. The second is a designated application lock function, which, in the terminal unlock state, performs lock control on each function of the portable information terminal 100, so that operation on a predetermined application selected by the registered user is permitted for all operators, but other operations are appropriately restricted when the registered user is not the operator.
[0059] The user authentication function unit 1103 mainly controls the user authentication process to confirm whether the operator of the portable information terminal 100 is a legitimate user. User authentication methods include PIN (Personal Identification Number) input, password input, pattern input, facial recognition, iris recognition, fingerprint recognition, palmprint recognition, voiceprint recognition, etc., or any other method can be used. Furthermore, in this embodiment, when controlling the terminal locking function unit 1102T, PIN input is used as the user authentication method; when controlling the designated application lock function unit 1102A, facial recognition and fingerprint recognition are used.
[0060] Furthermore, the aforementioned operation programs may be pre-stored in the storage device unit 110 and / or ROM 103 at the time the product is manufactured. They may also be obtained from various server devices on the network via LAN communication unit 161 or telephone network communication unit 162 after the product is manufactured. Additionally, the aforementioned operation programs stored on memory cards, optical discs, etc., may be obtained via expansion interface unit 170, etc.
[0061] [Example of action state transition in a portable information terminal]
[0062] Figure 2A is an operation state transition diagram illustrating an example of the operation state transition of the portable information terminal 100. The operation state transition shown in this figure mainly involves the terminal locking function controlled by the terminal locking function unit 1102T.
[0063] The portable information terminal 100 can set (enable) / deactivate (disable) the terminal lock function according to operation instructions such as those for the function menu. That is, according to the operation instructions for setting / deactivating the terminal lock function, the portable information terminal 100 can switch between a normal operation state T100 when the terminal lock function is deactivated and a normal operation state T110 when the terminal lock function is enabled. At this time, user authentication processing can also be requested.
[0064] Furthermore, when the terminal lock function is disabled, if the portable information terminal 100 in normal operation state T100 remains inactive for a predetermined period of time or if the operator instructs it to transition to sleep state, it transitions to sleep state T101. Additionally, if the operator instructs the power to be OFF in normal operation state T100 or sleep state T101, the portable information terminal 100 transitions to power OFF state T102. If the operator instructs the user to release from sleep state T101 or in power OFF state T102, the portable information terminal 100 transitions to normal operation state T100.
[0065] On the other hand, when the terminal lock function is active, if the portable information terminal 100 in normal operation state T110 remains inactive for a predetermined period of time or if the operator instructs it to transition to sleep state, it transitions to sleep state T111. Additionally, if the operator instructs the power to be OFF in normal operation state T110 or sleep state T111, the portable information terminal 100 transitions to power OFF state T112. If the operator instructs the user to deactivate sleep state in sleep state T111 or in power OFF state T112, the portable information terminal 100 performs user authentication processing (T113). If the user authentication is successful in user authentication processing (T113), the portable information terminal 100 temporarily unlocks the terminal lock function and transitions to normal operation state T110. In other words, normal operation state T110 is an operation state where the terminal lock function is active and temporarily deactivated. Additionally, if the operator's authentication fails during the user authentication process (T113), the portable information terminal 100 transitions to a sleep state T111. Alternatively, the user authentication process (T113) may be repeated.
[0066] Furthermore, in this embodiment, the control of the specified application external locking function is effective in the normal operating state T110. It is also possible to specify that the control of the specified application external locking function is effective in the normal operating state T100 as well. Details of the operation of the specified application external locking function will be described later.
[0067] Figure 2B is a flowchart of an example of a temporary unlocking process for a terminal lock function based on user authentication processing (T113).
[0068] When the operator gives an instruction to unlock from sleep state T111 or when the operator gives an instruction to turn on power in power OFF state T112, the terminal lock function unit 1102T requests the activation of the PIN input processing unit 1103P of the user authentication function unit 1103, and the basic operation function unit 1101 activates the PIN input processing unit 1103P.
[0069] Next, the PIN input processing unit 1103P displays the PIN input screen 180a on the touchscreen 180 (display unit 131) (S101). Next, the PIN input processing unit 1103P checks whether an operator has entered a PIN into the touchscreen 180 (touch panel 123) via touch (S102). If no PIN input is entered into the touchscreen 180, or if the touch operation is confirmed not to be a PIN input (S102: "No"), the PIN input processing unit 1103P repeatedly performs the S102 process. If the PIN input processing unit 1103P confirms that the touch operation is a PIN input cancellation instruction (S102: Cancel), authentication fails and transitions to sleep state T111 (S108). If there is a touch operation on the touchscreen 180 and the touch operation is confirmed to be a PIN input (S102: "Yes"), the PIN input processing unit 1103 proceeds to the S103 process. Next, the PIN input processing unit 1103P compares the PIN information entered in the processing of S102 with the authentication information that the official user has preset and stored in the authentication information storage area 1011, and sends the result to the terminal locking function unit 1102T of the locking control function unit 1102 (S103).
[0070] The terminal locking function unit 1102T determines, based on the comparison result sent, whether the PIN information entered during the processing in S102 matches the authentication information preset by the registered user and stored in the authentication information storage area 1011. If the two match (S104: "Yes"), authentication is successful and the terminal locking function of the portable information terminal 100 is temporarily released (S105), transitioning to the normal operation state T110 (S106), and the main screen 180b is displayed on the touch screen 180 (S107). On the other hand, if the terminal locking function unit 1102T determines that the PIN information entered during the processing in S102 does not match the authentication information preset by the registered user and stored in the authentication information storage area 1011 (S104: "No"), authentication fails and transitions to the sleep state T111 (S108). In addition, in the event of authentication failure, the process can be changed to power-off state T112 instead of the process of changing the operation state of the portable information terminal 100 to sleep state T111, or it can return to the process of S101.
[0071] Figure 2C is a screenshot of an example of the PIN input screen shown in the flowchart of Figure 2B.
[0072] The PIN input screen 180a includes a numeric keypad area 180a1, an input result display area 180a2, and a other information display area 180a3. The numeric keypad area 180a1 is the valid area for touch operations during PIN input. The input result display area 180a2 displays the result of the operator's touch operation on the numeric keypad area 180a1. When the operator performs a touch operation on the numeric keypad area 180a1, characters such as "・" and "*" are displayed to report that the portable information terminal 100 has received the operator's operation instruction. The other information display area 180a3 displays general information such as time and weather information.
[0073] Figure 2D is a screenshot of an example of the main screen displayed during the processing of the flowchart shown in Figure 2B.
[0074] The main screen 180b includes a main function icon display area 180b1, a general icon display area 180b2, a other information display area 180b3, and a control key area 180b4. The main function icon display area 180b1 displays icons associated with the main applications frequently used in the portable information terminal 100. The general icon display area 180b2 displays icons associated with other applications. The other information display area 180b3 displays general information such as time and weather information. The control key area 180b4 displays the "back key," "main screen key," and "application history key."
[0075] [Example of action control for specifying application-external locking function]
[0076] The following example illustrates the action control processing of the designated application lock function, using a scenario where a regular user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other user to share and view images captured by the camera in various information storage areas 1019 of the storage device unit 110, while an image viewing application is selected and launched. Furthermore, the application selected by the regular user is not limited to the image viewing application.
[0077] Figure 3A is a flowchart of an example of the motion control processing for a specified application external locking function. The processing shown in the flowchart mainly involves the specified application external locking function controlled by the specified application external locking function unit 1102A. Furthermore, the control of the specified application external locking function unit 1102A can also be performed independently of the control of the terminal locking function unit 1102T described above.
[0078] When using an image viewing application in the portable information terminal 100 during normal operation (T110), the operator operates the touchscreen 180, which displays the main screen 180b, to instruct the user to launch the image viewing application (S201). This can be done by tapping an icon associated with the image viewing application displayed in the main function icon display area 180b1 or the general icon display area 180b2. The basic operation function unit 1101 then launches the image viewing application function unit (not shown) of the other operation function unit 1109 according to the user's instruction. The image viewing application function unit displays the image viewing application execution screen 180c (Fig. 3B) on the touchscreen 180 (S202).
[0079] Next, while the screen displaying the image viewing application execution screen 180c on the touchscreen 180, the operator instructs the designated application external locking function control to begin (S203). Then, the basic operation function unit 1101, according to the operator's instruction, activates the designated application external locking function unit 1102A of the locking function control unit 1102 (S204). The designated application external locking function unit 1102A, according to the operator's instruction, stores (registers) the running application (in this embodiment, the image viewing application) as a designated application operable by both the registered user and other users (S205), and then requests the activation of the internal camera 133 and the activation of the face authentication processing unit 1103F. Hereinafter, the description assumes that the running application is registered as a designated application, but it is also possible to identify and register the user from an application other than the running application specified by the operation input unit 120 as a designated application. The basic operation function unit 1101, according to the request, activates the internal camera 133 and activates the face authentication processing unit 1103F (S206). The facial authentication processing unit 1103F begins facial authentication processing based on the image acquired by the internal camera 133.
[0080] Furthermore, the indication to start the application lock function control can be initiated by double-clicking or triple-clicking the "Home Screen Key" while the image viewing application execution screen 180c is displayed on the touchscreen 180. Other possible actions include simultaneously touching the "Home Screen Key" and the "Back Key," lightly tapping the "Home Screen Key" while the finger is in contact with the touch sensor 122, or double-clicking the execution screen of the running application (in this embodiment, the image viewing application) while the finger is in contact with the touch sensor 122. Other predetermined operations are also possible.
[0081] In addition, in order to prevent an operator other than the official user of the portable information terminal 100 from instructing the start of the designated application lock function control, the confirmation (authentication process) of whether the operator is the official user of the portable information terminal 100 can also be performed in the process of S203.
[0082] Next, the basic operation function unit 1101 checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If the basic operation function unit 1101 confirms that no operation instruction has been input to the touch screen 180 (S207: "No"), it repeats the process of S207. On the other hand, if the basic operation function unit 1101 confirms that an operation instruction has been input to the touch screen 180 (S207: "Yes"), it checks whether the operation instruction specifies the end of the application lock function control (S208). If the basic operation function unit 1101 confirms that the operation instruction input in the process of S207 is a specified instruction to end the application lock function control (S208: "Yes"), it proceeds to the process of S212. In addition, if the basic operation function unit 1101 confirms that the operation instruction input in the process of S207 is not a specified instruction to end the application lock function control (S208: "No"), it proceeds to the process of S209.
[0083] Furthermore, the indication that the specified application lock function control has ended can be obtained by double-clicking or triple-clicking the "Home Screen Key" while the specified application lock function control is in effect. Other possible actions include simultaneously touching the "Home Screen Key" and the "Back Key," lightly tapping the "Home Screen Key" while the finger is in contact with the touch sensor 122, or double-clicking the execution screen of the running application (in this embodiment, an image viewing application) while the finger is in contact with the touch sensor 122. Other predetermined operations are also possible.
[0084] In the processing of S209, the designated application lock function unit 1102A confirms whether the operation instruction input in the processing of S207 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the processing of S205, or an operation instruction targeting something other than the designated application (S209). If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S207 is an operation instruction targeting the designated application (S209: Designated Application), the image viewing application function unit returns to the processing of S207 after executing each process based on the operation instruction (S211). On the other hand, if the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S207 is an operation instruction targeting something other than the designated application (S209: Other than Designated Application), then confirms whether the operator is a formal user of the portable information terminal 100 (S210). If the designated application lockout function unit 1102A confirms in the S210 process that the operator is a registered user of the portable information terminal 100 (S210: "Yes"), after each application function unit of the other action function unit 1109 executes the respective processes based on the operation instructions entered in the S207 process (S211), it returns to the S207 process. Conversely, if the designated application lockout function unit 1102A does not confirm that the operator is a registered user of the portable information terminal 100 (S210: "No"), it does not execute the operation instructions entered in the S207 process and returns to the S207 process.
[0085] In this embodiment, the confirmation of whether the operator is a legitimate user of the portable information terminal 100 during the S210 process is performed using a facial authentication method controlled by the facial authentication processing unit 1103F. Specifically, the facial authentication processing unit 1103F analyzes the image acquired from the internal camera 133 and extracts the operator's facial image. This extracted facial image is compared with facial images of legitimate users pre-stored in the authentication information storage area 1011. If the comparison result has a consistency value higher than a predetermined value, the operator is considered a legitimate user of the portable information terminal 100. Furthermore, the S210 process can be executed whenever an operator's operation instruction input is received during the specified application lockout function control period, or it can be executed continuously, or it can be repeatedly executed at predetermined intervals. Additionally, the facial images of legitimate users pre-stored in the authentication information storage area 1011 can be a number corresponding to multiple individuals. In this case, there are multiple legitimate users of the portable information terminal 100.
[0086] In the S212 process, the designated application lockout function unit 1102A requests the activation of the PIN input processing unit 1103P to confirm whether the instruction to end the designated application lockout function control entered in the S207 process was issued by a legitimate user of the portable information terminal 100. Then, the basic operation function unit 1101 activates the PIN input processing unit 1103P of the user authentication function unit 1103.
[0087] Next, the PIN input processing unit 1103P displays the PIN input screen 180a on the touchscreen 180 (display unit 131) (S212). Next, the PIN input processing unit 1103P checks whether an operator has entered a PIN into the touchscreen 180 (touch panel 123) via touch (S213). If the PIN input processing unit 1103P confirms that no PIN has been entered into the touchscreen 180 or that the touch operation is not a PIN entry (S213: "No"), the process in S213 is repeated. If the PIN input processing unit 1103P confirms that the touch operation is a cancellation indication for PIN entry (S213: Cancellation), authentication fails and the process returns to S207. In this case, the application-external lock function control does not end. If the PIN input processing unit 1103P confirms that there has been a touch operation into the touchscreen 180 and that the touch operation is a PIN entry (S213: "Yes"), the process proceeds to S214. Next, the PIN input processing unit 1103P compares the PIN information entered in the processing of S213 with the authentication information that the official user has preset and stored in the authentication information storage area 1011, and sends the result to the designated application-external locking function unit 1102A (S214).
[0088] The designated application-external locking function unit 1102A determines, based on the comparison result sent, whether the PIN information entered in the S213 process matches the authentication information pre-set by the official user and stored in the authentication information storage area 1011. If the two are determined to be inconsistent (S215: "No"), authentication fails and returns to the S207 process. In this case, the designated application-external locking function control does not end. If the designated application-external locking function unit 1102A determines that the PIN information entered in the S213 process matches the authentication information pre-set by the official user and stored in the authentication information storage area 1011 (S215: "Yes"), authentication succeeds and requests the invalidation of the internal camera 133 and the termination of the operation of the face authentication processing unit 1103F. The basic operation function unit 1101, based on the request, invalidates the internal camera 133 and terminates the operation of the face authentication processing unit 1103F (S216). Then, the designated application external locking function unit 1102A releases the storage of the designated application in the process of S205 (S217) and ends the operation of the designated application external locking function control (S218).
[0089] Figure 3B is a screenshot of an example of an application execution screen for image viewing shown in the flowchart of Figure 3A.
[0090] The image viewing application execution screen 180c includes an image viewing area 180c1, a report area 180c2, and a control key area 180c3. The image viewing area 180c1 is the main screen of the image viewing application execution screen 180c. It displays thumbnails of multiple images, a zoomed-in screen for selected images, etc. The report area 180c2 reports radio wave intensity, time, remaining battery level, and other information. The control key area 180c3 displays the "Back" button, "Home" button, and "Application History" button.
[0091] [Operation instructions targeting a specified application and operation instructions targeting other applications]
[0092] In the processes S209 to S211 of the flowchart shown in Figure 3A, the processing flow differs depending on whether the operation instruction input in process S207 is an operation instruction targeting a specified application or an operation instruction targeting something other than the specified application. Specifically, if the operation instruction input in process S207 is an operation instruction targeting a specified application, process S210 is not executed; if the operation instruction input in process S207 is an operation instruction targeting something other than the specified application, process S210 is executed.
[0093] Figure 3C is an operation concept diagram illustrating which operation instructions for the portable information terminal 100 are for a specific application and which are for applications other than the specified application. In this figure, the upper left image is a thumbnail display screen, an example of an execution screen for an image viewing application. The upper right image is a selection image display screen, an example of an execution screen for an image viewing application. The lower left image is the main screen. The lower right image is an execution screen of an email creation screen, an example of an execution screen for an email application.
[0094] Consider a scenario where the specified application's external locking function control is initiated while displaying a thumbnail screen of an image viewing application. In this case, the image viewing application is saved as the specified application.
[0095] First, all operation instructions within the image viewing application, which is the designated application, are of course operation instructions targeting the designated application. For example, these include operations such as selecting / enlarging an image in the thumbnail display screen of the image viewing application to display the selected image display screen, returning from the selected image display screen to the thumbnail display screen, and changing the sorting order in the thumbnail display screen. Additionally, tapping the "Home Screen Key" to display the home screen from the state of the thumbnail display screen or the selected image display screen, and tapping the "Application History Key" to display the application history screen (illustrated but not shown) are also operation instructions targeting the designated application. Furthermore, tapping icons to restart the image viewing application from the home screen or application history screen are also operation instructions targeting the designated application.
[0096] On the other hand, the icon tap operation for launching the email application (which is an application other than the specified application) from the home screen or application history screen is an operation instruction for applications other than the specified application.
[0097] That is, in Figure 3C, the operation instructions performed within the dashed lines are operation instructions targeting a specified application, while the operation instructions performed across the dashed lines and the operation instructions performed outside the dashed lines are operation instructions targeting something other than the specified application.
[0098] [Variation Example 1]
[0099] The confirmation process for the official user performed in S210 is not limited to the facial authentication method described above. For example, it could also be fingerprint authentication. In this case, in the S206 process, instead of activating the internal camera 133 and starting the facial authentication processing unit 1103F, the basic operation function unit 1101 can simply activate the touch sensor 122 and start the fingerprint authentication processing unit 1103H. Furthermore, in the S210 process, the fingerprint authentication processing unit 1103H detects the fingerprint data of the operator's finger touching the touch sensor 122, compares the detected fingerprint data with the fingerprint data of the official user pre-stored in the authentication information storage area 1011, and if the comparison result has a consistency value of more than a predetermined value, then the operator is considered an official user of the portable information terminal 100, and control can be performed in this manner. Additionally, in this case, in the S216 process, the touch sensor 122 can be deactivated and the operation of the fingerprint authentication processing unit 1103H can be terminated according to the instruction to end the control of the specified application lock function.
[0100] In addition, the formal user confirmation process in S210 can also be performed using different authentication methods such as iris authentication or palmprint authentication.
[0101] Furthermore, the confirmation process for formal users performed in S212-S215 is not limited to the PIN input method mentioned above. For example, it can also be different authentication methods such as password input, pattern input, facial recognition, iris recognition, fingerprint recognition, palm print recognition, and voiceprint recognition.
[0102] Furthermore, the formal user authentication process performed in S212~S215 can be a common authentication process with the user authentication process (T113) in Figure 2A, or it can be a different authentication process. Alternatively, different authentication information can be used for the common authentication process.
[0103] [Variation Example 2]
[0104] Figure 3D is a flowchart of an example of the motion control process for the designated application lockout function. However, in this example, no application is stored (registered) as a designated application. In this case, in order to restrict operations on applications of the portable information terminal 100 performed by users other than the official user of the portable information terminal 100 while the main screen 180b is displayed on the touchscreen 180, the operator only needs to instruct the designated application lockout function control to begin. With this instruction, all applications of the portable information terminal 100 are recognized by the portable information terminal 100 as applications other than the designated application.
[0105] Comparing the flowchart in Figure 3D with that in Figure 3A, it can be seen that processes S201, S202, S205, S209, and S217 are not executed. That is, the designated application-external locking function unit 1102A processes all operation instructions input in process S207 that are operation instructions targeting applications other than the designated application, and performs confirmation (S210) as to whether the operator is a legitimate user of the portable information terminal 100. If the designated application-external locking function unit 1102A confirms in process S210 that the operator is a legitimate user of the portable information terminal 100 (S210: "Yes"), it returns to the process in S207 after executing each process based on the operation instructions input in process S207 (S211). Conversely, if the designated application-external locking function unit 1102A does not confirm that the operator is a legitimate user of the portable information terminal 100 (S210: "No"), it does not execute the operation instructions input in process S207 and returns to the process in S207.
[0106] Therefore, all operation instructions for the portable information terminal 100 are only permitted to the official users of the portable information terminal 100.
[0107] [Variation Example 3]
[0108] Figure 4 is an exterior view showing an example of the appearance of the portable information terminal 100g. Furthermore, this figure illustrates examples of the front, top, and left and right side views of the portable information terminal 100g when it is an eyeglass-type information terminal device such as an HMD (Head Mount Display), omitting views of the back and bottom, etc.
[0109] In the portable information terminal 100g, a display unit 131L / 131R is disposed in a lens portion shaped like glasses. The display unit 131L / 131R is a transmissive display, allowing the wearer (operator) to visually recognize the scenery in front of them through the display unit 131L / 131R, and to view the image data processed by the image signal processing unit 132 on the display unit 131L / 131R. In addition, a first image input unit 133L / 133R is provided on the back of the portable information terminal 100g, and a second image input unit 134L / 134R is provided on the front of the portable information terminal 100g.
[0110] Additionally, on the left side of the portable information terminal 100g, there is a touch sensor 122g and a stereo speaker 143L. On the right side of the portable information terminal 100g, there is a cursor key 121c, which is one of the operation keys 121, and a stereo speaker 143R. Furthermore, on either the left or right side of the portable information terminal 100g, there may be a μ-USB input unit 170u for power supply (not shown in the illustration).
[0111] When performing motion control processing for a designated application lock function using the portable information terminal 100g, which is an eyeglass-type information terminal device as shown in the figure, it is sufficient to make the formal user confirmation process in S210 of the flowchart in Figure 3A use iris authentication. In this case, it is sufficient to activate the internal camera 133L / 133R (or either one) and the iris authentication processing unit of the user authentication processing unit 1103 (not shown) in the S206 process. In addition, in the S210 process, the iris authentication processing unit analyzes the image acquired from the internal camera 133L / 133R, extracts the iris image of the wearer (operator), and compares the extracted iris image with the iris image of the formal user pre-stored in the authentication information storage area 1011. If the comparison result has a consistency of more than a predetermined value, the wearer (operator) is considered to be a formal user of the portable information terminal 100, and control can be performed in this manner. Alternatively, in this case, it is sufficient to disable the internal camera 133L / 133R and end the operation of the iris authentication processing unit in the S216 process according to the instruction to end the specified application external locking function control.
[0112] As explained above, the portable information terminal 100 of this embodiment can perform the following application-exclusive locking function control: Operations on predetermined applications selected by the registered user are allowed for all operators, but other operations are appropriately restricted when the registered user is not the operator. That is, a portable information terminal and its control method that provide good usability by appropriately restricting terminal functions according to the operator are provided.
[0113] Example 2
[0114] Hereinafter, Example 2 will be described. Furthermore, the basic structure of Example 2 is the same as that of Example 1. Hereinafter, the differences between this example and Example 1 will be mainly described, and common parts will be omitted as much as possible to avoid repetition.
[0115] [Example of action control for specifying application-external locking function]
[0116] The following example illustrates the action control processing of the designated application lock function, where a user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other person while selecting and launching an image viewing application, in order to share and view images captured by the camera in the various information storage areas 1019 of the storage device unit 110.
[0117] Figure 5 is a flowchart of an example of the motion control processing for a specified application external locking function. The processing shown in the flowchart mainly involves the specified application external locking function controlled by the specified application external locking function unit 1102A. Furthermore, the control of the specified application external locking function unit 1102A can also be performed independently of the control of the terminal locking function unit 1102T described above.
[0118] First, in the processes S301 to S304, the same processes as S201 to S204 in the flowchart of FIG3A are performed. That is, according to the operator's operation instructions, the startup process of the image viewing application and the start process of the designated application lock function control are performed. In addition, the designated application lock function unit 1102A stores the running application (in this embodiment, the image viewing application) as the designated application according to the operator's instructions (S305).
[0119] Next, the basic operation function unit 1101 checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If the basic operation function unit 1101 confirms that no operation instruction has been input to the touch screen 180 (S306: "No"), it repeats the process of S306. If the basic operation function unit 1101 confirms that an operation instruction has been input to the touch screen 180 (S306: "Yes"), it checks whether the operation instruction specifies the end of the application lock function control (S307). If the basic operation function unit 1101 confirms that the operation instruction input in the process of S306 specifies the end of the application lock function control (S307: "Yes"), it proceeds to the process of S312. Furthermore, if the basic operation function unit 1101 confirms that the operation instruction input in the process of S306 does not specify the end of the application lock function control (S307: "No"), it proceeds to the process of S308.
[0120] In the processing of S308, the designated application lock function unit 1102A confirms whether the operation instruction input in the processing of S306 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the processing of S305, or an operation instruction targeting an application other than the designated application (S308). If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S306 is an operation instruction targeting the designated application (S308: Designated Application), after the image viewing application function unit executes each process based on the operation instruction (S311), it returns to the processing of S306. If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S306 is an operation instruction targeting an application other than the designated application (S308: Other Than Designated Application), it further confirms whether the operation instruction is a launch instruction for any application other than the designated application (S309).
[0121] In the processing of S309, if the designated application lock function unit 1102A confirms that the operation instruction entered in the processing of S306 is a launch instruction for any application other than the designated application (S309: "Yes"), it requests the operator to input a designated application launch license code (S310). Specifically, according to the request of the designated application lock function unit 1102A, the PIN input processing unit 1103P displays a PIN input screen 180a on the touch screen 180. Here, if the operator inputs a pre-set designated application launch license code stored in the authentication information storage area 1011 as PIN information, the designated application lock function unit 1102A processes the process as confirming the official designated application launch license code (S310: OK), and performs the processing based on the operation instruction, that is, launching any application other than the designated application (S311). On the other hand, if the operator fails to enter the pre-set, external application launch permission code stored in the authentication information storage area 1011 as PIN information, the external application lock function unit 1102A processes it as an unconfirmed external application launch permission code (S310: NG), and does not perform the processing based on the operation instruction, i.e., the launch of any application other than the specified application, and returns to the processing in S306. The confirmation processing of the external application launch permission code in S310 only needs to perform the same processing as S212 to S215 in the flowchart of FIG3A.
[0122] In the S309 process, if the designated application lock function unit 1102A confirms that the operation instruction entered in the S306 process is not a launch instruction for any application other than the designated application (S309: "No"), it returns to the S306 process after executing each process based on the operation instruction (S311). That is, any application other than the designated application that has been launched performs the designated application launch license code verification process in the S310 process when it is launched, and is therefore determined to have obtained permission from the official user of the portable information terminal 100 and launched. In addition, any application other than the designated application launched via the designated application launch license code verification process can be allowed to operate by all operators without performing new authentication processing until the operation of the application ends.
[0123] The processing of S312~S317 can be performed in the same way as S212~S215 and S217~S218 in the flowchart of Figure 3A.
[0124] [Variation Example 1]
[0125] The verification process for the specified external application launch license code performed in S310 is not limited to the PIN input method mentioned above. For example, it can also be a password input method, pattern input method, facial recognition method, iris recognition method, fingerprint recognition method, palm print recognition method, voiceprint recognition method, etc.
[0126] In addition, the confirmation process for formal users in S312~S315 can be any authentication method such as PIN input, password input, pattern input, facial recognition, iris recognition, fingerprint recognition, palm print recognition, or voiceprint recognition.
[0127] [Variation Example 2]
[0128] In the action control processing of the designated application lock function in this embodiment, it is also possible to prevent any application from being stored (registered) as a designated application. In this case, the operator only needs to instruct the designated application lock function control to start while the main screen 180b is displayed on the touch screen 180.
[0129] In this case, the processes S301, S302, S305, S308, and S316 of FIG5 are not executed. That is, as long as all operation instructions input in the process of S306 are operation instructions targeting applications other than the specified application, the processes of S309 to S311 are performed. Thus, the launch instructions for all applications of the portable information terminal 100 are controlled to determine whether they can be executed based on the result of the confirmation process of the launch license code of the specified application.
[0130] As explained above, the portable information terminal 100 of this embodiment can perform the following designated application lockout function control: it allows operation of all predetermined applications selected by the operator and authorized users, but for other operations, it appropriately allows them based on the result of the confirmation process of the designated application launch permission code pre-set by the authorized user. That is, it can provide a portable information terminal and its control method that are convenient to use and can appropriately restrict the terminal functions according to the operator.
[0131] Example 3
[0132] Hereinafter, Example 3 will be described. Furthermore, the basic structure of Example 3 is the same as that of Example 1. Hereinafter, the differences between this example and Example 1 will be mainly described, and common parts will be omitted as much as possible to avoid repetition.
[0133] [Example of action control for specifying application-external locking function]
[0134] The following example illustrates the action control processing of the designated application lock function, where a user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other person while selecting and launching an image viewing application, in order to share and view images captured by the camera in the various information storage areas 1019 of the storage device unit 110.
[0135] Figure 6 is a flowchart of an example of the motion control processing for a specified application external locking function. The processing shown in the flowchart mainly involves the specified application external locking function controlled by the specified application external locking function unit 1102A. Furthermore, the control of the specified application external locking function unit 1102A can also be performed independently of the control of the terminal locking function unit 1102T described above.
[0136] First, in the processes S401 to S406, the same processes as S201 to S206 in the flowchart of FIG3A are performed. That is, according to the operator's operation instructions, the startup process of the image viewing application and the start process of the specified application lock function control are performed. In addition, according to the operator's instructions, the running application (in this embodiment, the image viewing application) is stored (registered) as the specified application, and the internal camera 133 is validated and the face authentication processing unit 1103F is started.
[0137] Next, the basic operation function unit 1101 checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If the basic operation function unit 1101 confirms that no operation instruction has been input to the touch screen 180 (S407: "No"), it repeats the process of S407. If the basic operation function unit 1101 confirms that an operation instruction has been input to the touch screen 180 (S407: "Yes"), it checks whether the operation instruction specifies the end of the application lock function control (S408). If the basic operation function unit 1101 confirms that the operation instruction input in the process of S407 is a specified instruction to end the application lock function control (S408: "Yes"), it proceeds to the process of S414. Furthermore, if the basic operation function unit 1101 confirms that the operation instruction input in the process of S407 is not a specified instruction to end the application lock function control (S408: "No"), it proceeds to the process of S409.
[0138] In the processing of S409, the designated application lock function unit 1102A confirms whether the operation instruction input in the processing of S407 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the processing of S405, or an operation instruction targeting something other than the designated application (S409). If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S407 is an operation instruction targeting the designated application (S409: Designated Application), after the image viewing application function unit performs each process based on the operation instruction (S413), it returns to the processing of S407. If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S407 is an operation instruction targeting something other than the designated application (S409: Other than Designated Application), it further confirms whether the operator is a formal user of the portable information terminal 100 (S410).
[0139] In the processing of S410, if the designated application lockout function unit 1102A confirms that the operator is a legitimate user of the portable information terminal 100 (S410: "Yes"), after each application function unit of the other action function unit 1109 executes the processing based on the operation instruction input in the processing of S407 (S413), it returns to the processing of S407. Alternatively, if the designated application lockout function unit 1102A does not confirm that the operator is a legitimate user of the portable information terminal 100 (S410: "No"), it checks whether the operation instruction input in the processing of S407 is a launch instruction for any application other than the designated application (S411).
[0140] In the process of S411, if the designated application lockout function unit 1102A confirms that the operation instruction input in the process of S407 is a launch instruction for any application other than the designated application (S411: "Yes"), it performs the confirmation process for the designated application launch license code (S412). If the designated application lockout function unit 1102A confirms the input of the designated application launch license code in the process of S412 (S412: OK), it executes the process based on the operation instruction, that is, the launch of any application other than the designated application (S413). On the other hand, if the designated application lockout function unit 1102A does not confirm the input of the designated application launch license code in the process of S412 (S412: NG), it does not execute the process based on the operation instruction, that is, the launch of any application other than the designated application, and returns to the process of S407. The confirmation process for the designated application launch license code in S412 can be the same as the processes of S212 to S215 in the flowchart of FIG3A.
[0141] In the process of S411, if the designated application lock function unit 1102A confirms that the operation instruction entered in the process of S407 is not a launch instruction for any application other than the designated application (S411: "No"), it returns to the process of S407 after executing each process based on the operation instruction (S413). That is, any application other than the designated application that has been launched performs the designated application launch license code confirmation process in the process of S412 when it is launched, and is therefore determined to have obtained the permission of the official user of the portable information terminal 100 and is launched. In addition, any application other than the designated application launched via the designated application launch license code confirmation process can be allowed to operate by all operators without performing new authentication processing until the operation of the application ends.
[0142] The processing of S414~S420 can be performed in the same way as S212~S218 in the flowchart of Figure 3A.
[0143] The action control processing for the specified application external locking function in this embodiment is a combination of the action control processing for the specified application external locking function in Embodiment 1 and the action control processing for the specified application external locking function in Embodiment 2.
[0144] As explained above, the portable information terminal 100 of this embodiment can perform the following designated application lockout function control: it restricts the operation of all predetermined applications that the operator is allowed to select as a formal user, but appropriately restricts other operations when the formal user is not the operator, or appropriately allows them based on the result of the confirmation process of the designated application launch permission code pre-set by the formal user. That is, it can provide a portable information terminal and its control method that are convenient to use and can appropriately restrict the terminal functions according to the operator.
[0145] Example 4
[0146] Hereinafter, Example 4 will be described. Furthermore, the basic structure of Example 4 is the same as that of Example 1. Hereinafter, the differences between this example and Example 1 will be mainly described, and common parts will be omitted as much as possible to avoid repetition.
[0147] [Example of action control for specifying application-external locking function]
[0148] In Embodiment 1, all operation instructions within an application designated as a specific application are allowed to be stored (registered) for all operators (i.e., even if the operator is not a formal user of the portable information terminal 100). However, even among operation instructions stored (registered) within an application designated as a specific application, there are operation instructions that should not be allowed if the operator is not a formal user of the portable information terminal 100. For example, in the case of the image viewing application described above, even among operation instructions within the image viewing application, instructions such as instructions to delete image data or move image data between folders should not be allowed if the operator is not a formal user of the portable information terminal 100.
[0149] In this case, in the flowchart shown in FIG3A, the action control processing for the designated application lock function can be performed by replacing the processing of S207-S211 with the processing of S501-S506 in FIG7. Hereinafter, the action control processing for the designated application lock function of this embodiment will be explained using the case where a regular user of the portable information terminal 100 lends the portable information terminal 100 to a friend or other person in order to share and view images captured by the camera in the various information storage areas 1019 of the storage device unit 110, while the image viewing application is selected and launched.
[0150] Figure 7 is a partial flowchart of an example of the motion control process for specifying the external locking function. The same processes as S201-S206 in the flowchart shown in Figure 3A are performed before the process shown in this figure, and the same processes as S212-S218 in the flowchart shown in Figure 3A are performed after the process shown in this figure, but these are omitted from the description.
[0151] After performing the same processes as S201-S206 in the flowchart of FIG3A, the basic operation function unit 1101 then checks whether an operator has input an operation instruction for the portable information terminal 100 via touch operation to the touch screen 180. If it is confirmed that no operation instruction has been input to the touch screen 180 (S501: "No"), the process of S501 is repeated. If it is confirmed that an operation instruction has been input to the touch screen 180 (S501: "Yes"), the basic operation function unit 1101 checks whether the operation instruction is an instruction to end the control of the application external lock function (S502). If it is confirmed that the operation instruction input in the process of S502 is an instruction to end the control of the application external lock function (S502: "Yes"), the basic operation function unit 1101 then performs the same processes as S212-S218 in the flowchart of FIG3A. In addition, if the basic operation function unit 1101 confirms that the operation instruction input in the processing of S501 is not an instruction to end the control of the external locking function (S502: "No"), it enters the processing of S503.
[0152] In the processing of S503, the designated application lock function unit 1102A confirms whether the operation instruction input in the processing of S501 is an operation instruction targeting an application (in this embodiment, an image viewing application) stored as a designated application in the processing of S205, or an operation instruction targeting something other than the designated application (S503). If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S501 is an operation instruction targeting the designated application (S503: Designated Application), then it confirms whether the operation instruction input in the processing of S501 is a license command (S504). The license command will be described later. If the designated application lock function unit 1102A confirms that the operation instruction input in the processing of S501 is a license command targeting the designated application (S504: Yes), after the image viewing application function unit executes each process based on the operation instruction (S506), it returns to the processing of S501.
[0153] The designated application lockout function unit 1102A confirms whether the operator is a formal user of the portable information terminal 100 if it confirms that the operation instruction entered in the process of S501 is not a permission command targeting the designated application (S504: "No") or if it confirms that the operation instruction entered in the process of S501 is an operation instruction targeting something other than the designated application (S503: "Something other than the designated application").
[0154] If the designated application lockout function unit 1102A confirms in the S505 process that the operator is a legitimate user of the portable information terminal 100 (S505: "Yes"), after the image viewing application function unit and other application function units have executed the respective processes based on the operation instructions input in the S501 process (S506), it returns to the S501 process. Conversely, if the designated application lockout function unit 1102A does not confirm that the operator is a legitimate user of the portable information terminal 100 (S505: "No"), it does not execute the operation instructions input in the S501 process and returns to the S501 process.
[0155] In the example of the image viewing application described above, the permission commands are groups of commands that can be executed even when the operator is not a registered user of the portable information terminal 100, in addition to instructions for deleting image data and instructions for moving image data between folders. Permission commands can also be managed using a permission command table for each application installed on the portable information terminal 100. The permission command table can also be pre-set by registered users of the portable information terminal 100 and stored in various information storage areas 1019 of the storage device unit 110. Furthermore, each application installed on the portable information terminal 100 can be automatically generated based on the security level of each command.
[0156] In the S504 process, based on the name of the application stored as the designated application in the S205 process, the designated application external locking function unit 1102A reads the corresponding license command table from the various information storage areas 1019, and then determines whether the operation instruction entered in the S501 process is the operation instruction described in the license command table.
[0157] Through the above processing, all operators are allowed to store (register) operation instructions within applications designated as specified applications and those described in the license command table. Even operation instructions stored (registered) within applications designated as specified applications but not described in the license command table, and operation instructions for applications not stored (registered) as specified applications, are only allowed if the operator is a registered user of the portable information terminal 100. In other words, a portable information terminal and its control method can be provided that offer good ease of use by appropriately limiting terminal functions according to the operator.
[0158] In addition, the same control as described above can also be applied in the flowcharts shown in Figures 3D and 6 to control whether the operator's input of operation instructions to the portable information terminal 100 via touch operation on the touch screen 180 corresponds to a permission command.
[0159] The examples of the implementation method have been described above using Examples 1 to 4. However, the structure of the technology for implementing this implementation method is not limited to the examples described above, and various modifications can be considered. The above structures can also be partially or entirely implemented in hardware, for example, using integrated circuit design. Alternatively, they can be implemented in software by using a microprocessor unit or the like to interpret and execute programs that implement various functions. Hardware and software can also be used together. The software can be pre-stored in the ROM 103, storage device unit 110, etc., of the portable information terminal 100 at the time of product shipment. It can also be obtained from various server devices on the Internet after the product is shipped. Alternatively, the software provided by a memory card, optical disc, etc., can also be obtained.
Claims
1. A control method for a portable information terminal, characterized in that, The system accepts operations to restrict the operation of the portable information terminal's application by users other than the official users of the portable information terminal, authenticates whether the user is an official user of the portable information terminal, allows the operation of the portable information terminal's application if the user is an official user, and restricts the operation of the portable information terminal's application if the user is not an official user.
2. The control method for a portable information terminal according to claim 1, characterized in that, As an operation for the aforementioned restrictions, the designated application is accepted, and the designated application is registered as a designated application that can be operated by the official user and other users besides the official user. If the user is authenticated as the official user, operation is allowed for the registered designated application and other applications besides the designated application. If the user is not authenticated as the official user, operation is allowed for the registered designated application, and operation is restricted for other applications besides the designated application.
3. The control method for a portable information terminal according to claim 2, characterized in that, Register the running application as the specified application.
4. The control method for a portable information terminal according to claim 2, characterized in that, If it is confirmed that the operation is performed on an application other than the specified application, input is requested as information about the operator's permission to perform the operation, specifying the out-of-application permission information.
5. The control method for a portable information terminal according to claim 2, characterized in that, If it is confirmed that the operation is for the specified application, and if it is confirmed that the operation is a command based on the license, then the processing based on that command is executed.
6. A portable information terminal, characterized in that, It includes: an operation input unit for accepting operations that restrict the operation of the portable information terminal's application by users other than the official users of the portable information terminal; and a user authentication unit for authenticating whether the user is an official user of the portable information terminal. The system also includes a locking control unit that, when the user is identified as an official user, allows operation of the application on the portable information terminal, and restricts operation of the application on the portable information terminal when the user is not identified as an official user.
7. The portable information terminal according to claim 6, characterized in that, The operation input unit accepts the designation of the application as an operation for the restriction. The lock control unit registers the designated application as a designated application that can be operated by the official user and other users besides the official user. If the user is identified as the official user, operation is allowed for the registered designated application and other applications besides the designated application. If the user is not identified as the official user, operation is allowed for the registered designated application, and operation is restricted for other applications besides the designated application.
8. The portable information terminal according to claim 7, characterized in that, The locking control unit registers the executing application as the designated application.
9. The portable information terminal according to claim 7, characterized in that, If the locking control unit confirms that the operation is for an application other than the specified application, it requests input of the specified application-out-of-application permission information as information for the operator to authorize the operation.
10. The portable information terminal according to claim 7, characterized in that, If the locking control unit confirms that the operation is for the specified application, it confirms that the operation is based on a licensed command. If it confirms that the operation is based on a licensed command, it executes processing based on that command.
Citation Information
Patent Citations
Information processing apparatus, authentication control method, and program
JP2011013855A