Data management apparatus, data providing system, data management method, and program

By using data management devices in the facility for data model sharing and access control, the burden of data access control in a multi-user environment under the RBAC approach is resolved, achieving efficient access control management and improved responsiveness.

CN122295666APending Publication Date: 2026-06-26MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
MITSUBISHI ELECTRIC CORP
Filing Date
2023-11-30
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

In access control of data generated in the facility, the existing RBAC approach leads to increased processing load and reduced responsiveness, especially in multi-user environments, where it is difficult to efficiently manage the data access permissions of each user group.

Method used

The data management device receives device information, manages data related to the device information, and performs access control based on the data model corresponding to the group. It uses the access control unit to control the access permissions of entities and supports data model sharing and access control table generation between different groups.

Benefits of technology

It reduces the workload of data access control preparation in the facility, improves the responsiveness and efficiency of the system, and supports flexible access control in multiple environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122295666A_ABST
    Figure CN122295666A_ABST
Patent Text Reader

Abstract

The data management device (10) comprises: a management unit (100) that stores and manages an access control list (102) that indicates whether access is permitted for a combination of roles assigned to multiple entities (41) belonging to a group and attributes of data defined by a data model predetermined for the group; an access control unit (120) that controls access to data from an entity (41) based on the access control list (102) corresponding to the group to which the entity (41) belongs; and a web server unit (140) that accepts registration of usage groups by maintenance entities (41) belonging to a maintenance group. The management unit (100) applies a data model corresponding to the maintenance group as the data model for constructing the access control list (102) corresponding to the usage group.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to data management devices, data provision systems, data management methods, and procedures. Background Technology

[0002] RBAC (Role Based Access Control) is known to control user access to data within the system by assigning roles to users and granting them access permissions corresponding to those roles. As the number of managed objects such as roles increases in RBAC, the processing load increases, and the responsiveness to data access decreases. Therefore, techniques to reduce the processing load of RBAC have been proposed (e.g., see Patent Document 1).

[0003] Patent Document 1 describes an apparatus that determines access permissions based on a user list in access control using extended roles. This apparatus reduces the processing load required for determining access permissions when access to restricted content occurs.

[0004] Existing technical documents

[0005] Patent documents

[0006] Patent Document 1: Japanese Patent Application Publication No. 2010-117885 Summary of the Invention

[0007] The problem that the invention aims to solve

[0008] In RBAC, roles are typically assigned to users belonging to groups such as organizations, companies, or groups. Furthermore, the categories of data that can be accessed are determined according to each role. The same method of RBAC is used in the technology of Patent Document 1.

[0009] When attempting to process data generated within facilities, such as plants and facilities, via RBAC, the facility's administrator corresponds to the aforementioned groups. However, data generated within a facility may also be utilized by users belonging to groups different from the facility's administrator, such as groups producing (including sales) equipment located within the facility, groups utilizing the equipment, or system integrators and maintenance providers. Furthermore, these groups are not necessarily confined to the same enterprise. For operators, determining the categories of accessible data for each role of users belonging to these various groups can become extremely complex. Therefore, there is room to reduce the burden of preparation work for controlling access to data generated within facilities.

[0010] This disclosure was made under the aforementioned circumstances, with the aim of reducing the burden of preparation work for controlling access to data generated in the facility.

[0011] Methods for solving problems

[0012] To achieve the above objectives, the data management device of this disclosure receives device information from a device installed in a facility, manages data related to the device information, and provides the data to an entity via a network, wherein... The data management device includes: The management unit stores and manages a table that shows whether an entity assigned a role is permitted to access data with that attribute, based on a combination of roles assigned to multiple entities belonging to a group and attributes of data defined by a pre-determined data model corresponding to the group. An access control unit, which controls an entity's access to data based on a table corresponding to the group to which the entity belongs; and The acceptance unit accepts registrations from entities belonging to Group 1 that are registered in Group 2, but are different from those in Group 1. The management unit applies the data model corresponding to Group 1 as the data model used to construct the table corresponding to Group 2.

[0013] Invention Effects

[0014] According to this disclosure, the burden of preparation work for controlling access to data generated in the facility can be reduced. Attached Figure Description

[0015] Figure 1 This is a diagram illustrating the structure of the data providing system of Implementation 1.

[0016] Figure 2 This is a diagram showing the hardware structure of the data management device according to Embodiment 1.

[0017] Figure 3 This is a diagram showing the functional structure of the data management device according to Embodiment 1.

[0018] Figure 4 This diagram illustrates how the two groups of Implementation 1 are managed as a set.

[0019] Figure 5 This is a diagram illustrating an example of the data model for Implementation Method 1.

[0020] Figure 6 This is a diagram used to illustrate the access control in Implementation 1.

[0021] Figure 7 This is a diagram used to explain the designation of the security device in Embodiment 1.

[0022] Figure 8Figure 1 shows an example of the presence or absence of disclosed data for each device in Embodiment 1.

[0023] Figure 9 Figure 2 shows an example of the presence or absence of disclosed data for each device in Embodiment 1.

[0024] Figure 10 This is a flowchart illustrating the data management process of Implementation Method 1.

[0025] Figure 11 This is a diagram used to explain the designation of confidential data in Implementation 2.

[0026] Figure 12 This is a diagram showing the access control data of a variant example. Detailed Implementation

[0027] Hereinafter, the data providing system according to embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.

[0028] Implementation method 1.

[0029] like Figure 1 As shown, the data providing system 1000 of this embodiment is a system that manages data related to information sent from facilities 20, such as factories or workshops, in a data management device 10 and provides it to entities 40 via a network NW. The data providing system 1000 implements access control as a cloud service. Specifically, the data providing system 1000 provides data to users with predetermined access permissions and restricts data provision to users without such access permissions. Users are the objects to which data is provided based on the data providing system 1000; hereinafter, users will be referred to as entities 40. However, entities are not limited to users.

[0030] The data providing system 1000 has a device 21 and a gateway device 22 installed in the facility 20, a data management device 10 for access control, and a terminal 30 used by an entity 40 as a user.

[0031] Device 21 can be a control device such as a PLC (Programmable Logic Controller), a controlled device such as a sensor, actuator, robot, or machine tool, a UI (User Interface) device for operators to set control content, or a FA device that constitutes other FA systems. Device 21 only needs to be a transmitting device for sending information.

[0032] The information sent by device 21 may represent, for example, sensing results, the operating status of device 21, the occurrence of an anomaly, or the execution result of a predetermined program. The operating status of device 21 may be, for example, current values, voltage values, speed, acceleration, angular velocity, and angular acceleration measured within device 21, or it may correspond to data stored in the memory of device 21. The transmission of information based on device 21 may be performed periodically at a predetermined cycle, or repeatedly without a cycle, or based on the fulfillment of predetermined trigger conditions. Furthermore, the transmission of information by device 21 may be spontaneous, performed according to operator actions on device 21, or based on requests from data management device 10.

[0033] exist Figure 1 In this example, as information sent from device 21, operation status data 51 indicating the operating status of device 21 and alarm data 52 indicating the occurrence of an abnormality in device 21 are shown. Additionally, in Figure 1 In this example, one device 21 is shown, but multiple devices 21 may also be provided in the facility 20. The information sent by device 21 is equivalent to an example of device information sent from a device provided in the facility.

[0034] Gateway device 22 relays information transmission between device 21 and data management device 10 outside facility 20. Gateway device 22 provides API (Application Protocol Interface) functionality for uploading information from device 21 to data management device 10. Figure 1 The example illustrates that gateway device 22 has the functions of an operation status API 221 for uploading operation status data 51 and an alarm API 222 for uploading alarm data 52.

[0035] Data management device 10 is a server device on a network, such as the Internet. Data management device 10 receives and manages information uploaded via gateway device 22.

[0036] In the data management device 10, the information sent from the device 21 is called the data model standardization of model g, which becomes a data set containing operating status data 51 and alarm data 52. For example... Figure 1 As shown in data model DB101, model g is the data model corresponding to group G, defining data attributes including operating status and alarms. Here, group G is a group to which multiple entities 40, which are provided with data related to information sent from device 21, belong. Furthermore, the API functions of gateway device 22 are pre-determined to correspond to model g and are installed on gateway device 22.

[0037] exist Figure 1In the example shown, for ease of understanding, it is illustrated that information sent from device 21 is provided to entity 40 directly via access control. However, this is not the only possibility; data representing the result of processing information sent from device 21 by gateway device 22 or data management device 10 can also be accessed by entity 40. For example, data representing the result of statistical processing performed on information repeatedly sent from device 21 can also be provided to entity 40.

[0038] Data managed by data management device 10 is appropriately provided to entities 40 belonging to group G under access control based on access control table 102. Access control table 102 is a two-dimensional table that maps a list of attributes of the data defined by model g to the vertical axis and a list of roles assigned to entities 40 of group G to the horizontal axis, indicating whether access to data with that attribute is permitted from the entity 40 assigned that role for each combination of attribute and role. For example, in... Figure 1 In access control table 102, a checkmark indicates that entity 40, which has been assigned "role A", is permitted to access data with the "alarm" attribute. Additionally, access to data with the "operation status" attribute by entity 40, which has been assigned "role B", is restricted and indicated as "NO".

[0039] As described above, the list of attributes of the data constituting access control table 102 is predetermined according to group G. For example, if it is desired to access operation status data 51 and alarm data 52 in group G, the operation status data 51 and alarm data 52 sent from device 21 are added to the list. Here, if it is desired that access to operation status data 51 and access to alarm data 52 are based on different access permissions, the attributes of the data corresponding to operation status data 51 and the attributes of the data corresponding to alarm data 52 become different list elements. On the other hand, if it is not necessary to distinguish between operation status data 51 and alarm data 52, the attributes of the data containing both operation status data 51 and alarm data 52 can become one list element. In this way, the list of data attributes corresponds to the data processing method in the group. Therefore, when controlling access to entities 40 belonging to different groups, the list of attributes of the data constituting access control table 102 differs according to the group.

[0040] Therefore, the data model DB101 manages data by associating the data models that define the attributes of the data with groups.

[0041] exist Figure 1The diagram shows a device 21. Typically, the organization, company, or group that maintains the device 21 after it is in operation corresponds to group G. When the data management device 10 collects information from multiple devices 21 maintained by different groups, it controls access to entities 40 belonging to each group based on the data model corresponding to each group.

[0042] The data management device 10 controls the access based on the access control list 102 to which the entity 40 that accessed the data via the network NW belongs. For example, in Figure 1 In the example, if role A is assigned to entity 40 belonging to group G, the data management device 10 grants entity 40 access to alarm data 52 and provides alarm data 52 to entity 40. Conversely, if role B is assigned to entity 40 belonging to group G, the data management device 10 restricts entity 40's access to operational status data 51 and does not provide operational status data 51 to entity 40. Furthermore, providing data to entity 40 means sending data to the terminal 30 used by entity 40.

[0043] Terminal 30 is a UI device used as user reference data for entity 40, such as an industrial PC (Personal Computer), tablet terminal, or smartphone. Terminal 30 can display a dashboard on a web browser and can use a card-based UI on that dashboard to display data provided from data management device 10. Furthermore, in Figure 1 In the example, terminal 30 and entity 40 are located outside facility 20, but terminal 30 and entity 40 may also be located inside facility 20.

[0044] Next, the data management device 10 that performs access control will be described in more detail. The data management device 10 consists of hardware elements that function as a computer, which receives device information, manages data related to the device information, and provides the data to entities via a network. Specifically, as... Figure 2 As shown, the data management device 10 includes a processor 61, a main storage unit 62, an auxiliary storage unit 63, an input unit 64, an output unit 65, and a communication unit 66. The main storage unit 62, the auxiliary storage unit 63, the input unit 64, the output unit 65, and the communication unit 66 are all connected to the processor 61 via an internal bus 67.

[0045] The processor 61 includes a CPU (Central Processing Unit) as a processing circuit. The processor 61 performs various functions by executing the program P1 stored in the auxiliary storage unit 63, and performs the processing described later.

[0046] The main storage unit 62 includes RAM (Random Access Memory). Program P1 is loaded from the auxiliary storage unit 63 into the main storage unit 62. Furthermore, the main storage unit 62 is used as the operating area of ​​the processor 61.

[0047] The auxiliary storage unit 63 includes non-volatile memory such as EEPROM (Electrically Erasable Programmable Read-Only Memory) and HDD (Hard Disk Drive). In addition to program P1, the auxiliary storage unit 63 stores various data used by the processor 61 for processing. Following instructions from the processor 61, the auxiliary storage unit 63 provides the processor 61 with data for its use. Furthermore, the auxiliary storage unit 63 stores data provided from the processor 61.

[0048] The input unit 64 includes input devices such as hardware switches, input keys, keyboards, and pointing devices. The input unit 64 acquires information input by the user from the data management device 10 and notifies the processor 61 of the acquired information.

[0049] The output unit 65 includes output devices such as LEDs (Light Emitting Diodes), LCDs (Liquid Crystal Displays), and speakers. The output unit 65 displays various information to the user according to the instructions of the processor 61.

[0050] The communication unit 66 includes a communication interface circuit for communicating with external devices. The communication unit 66 receives signals from the outside and outputs data represented by those signals to the processor 61. Furthermore, the communication unit 66 transmits signals representing data output from the processor 61 to external devices. Additionally, in Figure 2 The diagram shows a representative example of a single communication unit 66, but the data management device 10 may also have multiple communication units 66. For example, a communication unit 66 for communicating with the gateway device 22 of the facility 20 and a communication unit 66 for communicating with the terminal 30 via the network NW may also be provided separately.

[0051] Through the aforementioned hardware structure, the data management device 10 performs various functions. Specifically, as... Figure 3As shown, the data management device 10 includes, as part of its functions: a storage unit 110 for storing received information; an access control unit 120 for performing access control on the information stored in the storage unit 110; a management unit 100 for managing a table used for performing access control; a first communication unit 130 for communicating with the facility 20; a web server unit 140 for providing data to the entity 40; and a second communication unit 150 for communicating with the entity 40 via a network NW. The first communication unit 130 and the second communication unit 150 are each implemented in a communication unit 66.

[0052] The management unit 100 is primarily implemented by the processor 61. The management unit 100 has an access control table 102 that specifies the details of access control, and a data model DB101 that maps the data models used to construct the access control table 102 to groups. However, in Figure 3 In the access control table 102 shown, the maintenance group and the user group share common data attributes. Here, the maintenance group is responsible for the maintenance work of the devices 21 constituting the FA system of facility 20, and maintenance entity 41 is equivalent to entity 40, which belongs to the maintenance group. Conversely, the user group is responsible for the operation of the FA system using the devices 21, and user entity 42 is equivalent to entity 40, which belongs to the user group. Hereinafter, maintenance entity 41 and user entity 42 will sometimes be collectively referred to as entity 40. The FA system is a system built using the devices 21 in a facility, such as a production system that manufactures products by controlling multiple devices 21 to process a large number of workpieces.

[0053] As described above, the access control content of entity 40 corresponds to the group to which entity 40 belongs, typically the maintenance group of maintenance device 21. However, regarding the data generated in the FA system, it is sometimes not limited to the maintenance provider of device 21, but is expected to be used by multiple groups such as the operating entity of the FA system containing device 21, the manufacturer of device 21, the OEM of the device group containing device 21, and the system integrator that delivers software to the FA system. For example, if device 21 malfunctions during the operation of the FA system, the following situation may occur: the user group, as the operating entity of the FA system, may entrust the maintenance group to repair or replace device 21. In such a case, if both the maintenance group and the user group's entities 40 can refer to the data of device 21, it is expected that the malfunction can be quickly eliminated. In addition, an example of a maintenance group specifically responsible for maintenance business has been given, but it is not limited to this. The user group can also formulate its own maintenance plan and implement maintenance operations including repair and replacement.

[0054] Here, since multiple groups are responsible for different tasks, different roles are assigned to entities 40 belonging to each group. However, if we try to determine a different data model for each group, the decision-making process can become cumbersome. Therefore, if we set a common data model for these groups, the data model decision-making process can be consolidated into one step, thereby reducing the workload.

[0055] In detail, the management unit 100 applies model g1, which corresponds to the maintenance group, as the data model used to construct the table corresponding to the user group. That is, the management unit 100 uses model g1, which corresponds to the maintenance group, as the data model corresponding to the user group in data model DB101. The data model used to construct the access control table for the maintenance group and the data model used to construct the access control table for the user group are established as the same data model and this correspondence is maintained.

[0056] In addition, when the management department 100 manages multiple groups, including maintenance and user groups, such as Figure 4 As shown, maintenance groups and user groups are managed as a single set. Specifically, management unit 100 manages information representing combinations of maintenance groups and user groups, and for each combination represented by this information, the access control table uses a common data model.

[0057] exist Figure 5 An example of model g1 corresponding to the maintenance group is shown below. Figure 5 As shown, the data model specifies data attributes hierarchically, for example, in XML (Extensible Markup Language) format. Model g1 has three categories: business data related to the maintenance group's business, event data related to events occurring in device 21, and file data representing files provided from device 21. Event data and file data are collected from device 21 via the event API group and file API group of gateway device 22, respectively.

[0058] Business data includes customer information management for customers acting as maintenance providers within the maintenance group, maintenance user management for maintenance entity 41, user management for user entity 42, and other data. Event data includes, for example, operational status, alarms, and other data. Document data includes confidential information at five levels, from confidentiality level 1 to confidentiality level 5, as well as maintenance group-specific information.

[0059] Once the three categories of business data, event data, and file data are identified, preliminary versions of event APIs and file APIs are provided to the maintenance group from the data management device 10 or from the cloud service provider based on the data management device 10. Based on this, the maintenance entity 41, acting as the manager of the maintenance group, creates details for each item belonging to the three categories and the corresponding APIs for each item.

[0060] Furthermore, the correspondence between APIs and items in the data model does not necessarily have to be one-to-one. For example, ... Figure 5 As illustrated in the file data example, file data uploaded via the Standard Time Series File API and the General Device File API can also be categorized into six types of file data based on the ID contained in the data.

[0061] In addition, business data is not collected from facility 20 but is pre-stored in data management device 10 by maintenance entity 41.

[0062] Furthermore, the maintenance entity 41 can determine the roles of the maintenance group and the user group. If the maintenance group is the manufacturer of device 21, flexible role-based access control can be implemented for event data and files sent by device 21 solely by that manufacturer.

[0063] Management unit 100 is an example of a management unit that stores and manages tables that indicate whether an entity assigned a role is permitted to access data with that attribute, based on a combination of roles assigned to multiple entities belonging to a group and attributes of data defined by a pre-determined data model corresponding to that group.

[0064] return Figure 3 The storage unit 110 is primarily implemented by at least one of the main storage unit 62 and the auxiliary storage unit 63. Information sent from the device 21 is stored in the storage unit 110 as data that becomes the access object of the entity 40. However, the data sent from the device 21 is not the direct object accessed by the entity 40, but rather accessed indirectly by the entity 40, based on the premise that access to the data is permitted by the role assigned to the entity 40 in the access control list 102. That is, as... Figure 3 As shown, the access control unit 120 is located between the storage unit 110 and the entity 40.

[0065] Access control unit 120 is mainly implemented by processor 61. Access control unit 120 controls access made by maintenance entity 41 and user entity 42 via web server unit 140 and second communication unit 150. Access control by access control unit 120 is based on access control list 102 and role assignment to each entity 40.

[0066] exist Figure 6The document illustrates information specifying the access control content of the access control unit 120. Specifically, in... Figure 6 The upper side shows the use Figure 5 The access control table 102, which is composed of the data model, shows role data 104 on the bottom, representing the roles assigned to the maintenance entity 41 and the user entity 42, respectively.

[0067] exist Figure 6 In this table, role data 104 is presented as follows: the vertical axis corresponds to a list of entities, and the horizontal axis corresponds to a list of roles identical to those in access control table 102. For combinations of entities and roles, entities possessing that role are indicated by a black circle. For example, role data 104 shows that "Entity 41a," as a maintenance entity, has been assigned the role "SYSTEM_ADMIN" in the maintenance group. Therefore, "Entity 41a" can access "Confidentiality Level 1 Information," for which a checkmark is added in access control table 102 for the combination with "SYSTEM_ADMIN." Furthermore, it is known that "Entity 42b," as a user entity, has been assigned roles such as "XXX" and "YYY" in the user group. However, in access control table 102, neither the combinations of "XXX" and "YYY" with "Confidentiality Level 1 Information" have a checkmark, therefore "Entity 42b" cannot access "Confidentiality Level 1 Information." The access control unit 120 is equivalent to an example of an access control unit, which controls access to data from an entity based on a table corresponding to the group to which the entity belongs.

[0068] return Figure 3 The Web server unit 140 is primarily implemented by the processor 61. The Web server unit 140 provides a management screen to the maintenance entity 41 and the user entity 42 via a second communication unit. In this management screen, the maintenance entity 41 handles the designation of user groups. Specifically, the Web server unit 140 handles the registration of user groups by the maintenance entity 41 as recipients of maintenance services for the device 21. Through this designation of user groups by the maintenance entity 41, such as… Figure 3 As shown, the data model corresponding to the maintenance group is applied as the data model constituting the access control list of the user group. Furthermore, the Web server unit 140 accepts registrations of business data containing information about the manual and consumables of device 21 from the maintenance entity 41. The Web server unit 140 is an example of a processing unit that accepts user group registrations from entities belonging to the maintenance group.

[0069] Furthermore, the Web server unit 140 receives designations from the user entity 42 for confidential devices among the multiple devices 21 used in the user group that transmit confidential information. Data related to information transmitted from confidential devices is kept confidential for groups outside the user group, and access to this data from the maintenance entity 41 is restricted. This access restriction is enforced by the access control unit 120 independently of access control based on access control list 102.

[0070] exist Figure 7 An example of using entity 42 to designate a security device is shown. Figure 7 In the example, the case where device E1, which is device 21, is designated as a secure device is indicated as "NG" in the setting data 105. Therefore, for example, although the access control table 102 specifies that the maintenance group entity 41a has the permission to access data indicating the operating status of device 21, the maintenance group entity 41a cannot access the data indicating the operating status of device E1.

[0071] Access control list 102, which specifies the content of access control, is set by the maintenance group as described above. However, on the user group side, it is sometimes desirable to keep information related to a portion of the device 21 in use confidential to external parties. Therefore, the web server unit 140 accepts the designation of the confidential device from the user entity 42, and the access control unit 120 restricts entities belonging to groups other than the user group from accessing data related to information sent from the confidential device. The data management device 10 provides the user group with a function to designate public and non-public data from the user group side.

[0072] Alternatively, Web server 140 can also be used as a replacement. Figure 7 The designation of the security device shown, and as Figure 8 As shown, for each combination of device 21 and attributes defined by the data model, the user entity 42 handles whether to designate publicly available data outside the user group. Figure 8 In the example, setting the alarm data of "Device E1" to be non-public outside of the user group is represented as "NG" in setting data 105a. Therefore, for example, although access control table 102 specifies that entity 41a of the maintenance group has permission to access the alarm data of device 21, entity 41a of the maintenance group cannot access the alarm data of device E1. Furthermore, in Figure 8 In the setting data 105a, it is not possible to set the public presence or absence of item annotation shadows for entity 42 of the user group.

[0073] In addition, they can also be used together. Figure 7 The setting data 105 shown is Figure 8 The setting data shown is 105a. For example, as... Figure 9As shown, for device 21 that is not designated as a confidential device, it is also possible to specify whether the data is public or not based on each attribute of the data.

[0074] return Figure 3 The second communication unit 150 is equivalent to a communication interface between the Web application used in the terminal 30 and external systems via the network NW, providing an API to external devices.

[0075] Next, use Figure 10 The data management process performed by the data management device 10 having the above-described functions will be described. It begins by turning on the power to the data management device 10. Figure 10 The data management and processing shown.

[0076] In the data management process, the Web server unit 140 receives the settings of the maintenance entity 41, roles, and data model from the maintenance entity 41, which acts as the manager of the maintenance group (step S1). Then, the management unit 100 generates the access control list 102 for the maintenance group based on the information received in step S1 (step S2). The contents of the access control list, i.e., whether access is permitted for each combination of roles and data attributes, can be set by the maintenance entity 41 in step S1, or predetermined initial values ​​can be applied.

[0077] Next, the Web server unit 140 accepts the registration of the user group by the maintenance entity 41, and accepts the settings related to the user entity 42 and roles of that user group (step S3). Thus, for example, settings are made... Figure 6 The information related to the user group in the role data 104 shown.

[0078] Next, the management unit 100 uses the maintenance group's data model as the data model for the access control table 102 that constitutes the user group, and generates the access control table 102 (step S4). The content of this table, i.e., whether access is permitted for each combination of roles and data attributes, can be set by the maintenance entity 41 in step S3, or by the user entity 42 when generating the table, or by applying predetermined initial values. The management unit 100 is an example of a management unit that generates access control tables, which indicate whether an entity assigned a role is permitted to access data with that attribute for each combination of roles assigned to multiple entities belonging to a user group and attributes of data defined by the data model used to constitute the access control table corresponding to the maintenance group.

[0079] Next, the Web server unit 140 accepts the setting from the user entity 42 regarding whether to disclose data to other groups (step S5). Specifically, the Web server unit 140 accepts... Figure 7 Setting data 105 Figure 8 Setting data 105a or Figure 9 The content of setting data 105b.

[0080] Then, the access control unit 120 controls access from the maintenance entity 41 or the user entity 42 according to the access control tables 102 of each group generated in steps S2 and S4, and the user group settings for disclosure accepted in step S5 (step S6).

[0081] Next, the management department 100 determines whether the data model corresponding to the maintenance group has been changed by the maintenance group (step S7). Changes to the data model include, for example: Figure 5 Add or remove any item from the business data, event data, and file data shown.

[0082] If it is determined that the data model has not been changed (step S7; No), the data management device 10 repeats the processing after step S6. On the other hand, if it is determined that the data model has been changed (step S7: Yes), the management unit 100 applies the maintenance group's data model as the data model constituting the access control table 102 for both the maintenance group and the user group, and updates the access control table 102 for both the maintenance group and the user group (step S8). The management unit 100 is an example of a management unit that, when the data model used to constitute the access control table corresponding to the maintenance group is changed by an entity belonging to the maintenance group, updates the table by applying the changed data model to the access control table corresponding to the user group. Afterwards, the processing after step S6 is repeated.

[0083] As explained above, the Web server unit 140 accepts the registration of user groups by the maintenance entity 41, and the management unit 100 applies the data model corresponding to the maintenance group as the data model for constructing the access control list 102 corresponding to the user group. Therefore, the data model becomes a common data model in both the maintenance group and the user group, and the work of creating a data model again is not required after the user group is registered. Thus, the burden of preparation work for controlling access to data generated in the facility can be reduced.

[0084] In detail, the management department 100 manages the maintenance group and the user group as a set, and uses a common data model to generate the access control list 102 for each group within this set. Therefore, the creation of a data model is eliminated when generating the access control list 102 corresponding to the user group, reducing the workload.

[0085] Furthermore, when the data model is changed, the management department 100 also applies the change to the access control table 102 corresponding to the user group, updating the access control table 102 accordingly. Therefore, when the data model of the maintenance group is changed, there is no need to redesign the data model of the user group, reducing the workload.

[0086] Furthermore, the data management device 10 provides a data shielding function set by the user group. Specifically, the web server unit 140 receives the designation of a confidentiality device from the user entity 42 for sending confidential information, and the access control unit 120 restricts access to data related to information sent from the confidentiality device to entities belonging to groups other than the user group. Thus, the maintenance group defines the data model, while the user group can designate confidentiality devices.

[0087] Regarding data related to device 21, it is expected that both the maintenance team, as the manufacturer of device 21, and the user team, which actually uses device 21, are free to process it, sometimes requiring adjustments between the two. However, such adjustments are time-consuming and may not necessarily reach a satisfactory conclusion. Here, in routine maintenance operations, the maintenance team mostly does not distinguish between individual devices 21 but focuses on the categories of data processed across a large number of devices 21. On the other hand, while the user team sometimes wants to conceal information related to a portion of the multiple devices 21 configured in facility 20, it tends to place less emphasis on data categories compared to the maintenance team.

[0088] When there are requirements from both groups, the data management device 10 of this embodiment uses a data model determined by the maintenance group in the access control tables of both the maintenance group and the user group, and restricts access to data according to the settings of the user group regarding the data disclosure of each device. This provides a framework that satisfies the requirements of both groups to a certain extent, eliminates the need for adjustments between the two groups, or helps to shorten the time spent on adjustments.

[0089] In addition, such as Figure 8 As shown, regarding the combination of attributes of device 21 and data, if the user entity 42 determines whether it is disclosed, it is possible to compare... Figure 7 Such a security device specification more precisely meets the expectations of the user group. Figure 8 In the example, the Web server unit 140 corresponds to an example of a receiving unit, which, based on a combination of attributes of each device and data related to information sent from that device, determines whether to allow entities other than the user entity to access data related to information sent from that device and possessing those attributes. Furthermore, the access control unit 120 corresponds to an example of an access control unit, which controls access by entities other than the user entity according to the settings accepted by the receiving unit.

[0090] Furthermore, according to the data management device 10, data generated in facility 20 can be assigned attributes such as confidentiality and source of generation. Secure access control, limited to the responsibilities of each entity 40, can be indirectly implemented based on the definition of the relationship between attributes and roles. By performing this access control at the nearest base layer of management unit 100, access control can be uniformly implemented regardless of data utilization methods such as web interfaces, emails, and APIs. In system architectures where multiple systems operate collaboratively, which have emerged in recent years, data obtained by the data management system 1000 can also be securely provided to surrounding external systems by controlling data access at the base layer.

[0091] Implementation method 2.

[0092] Next, Embodiment 2 will be described focusing on its differences from Embodiment 1 described above. Furthermore, the same reference numerals will be used for structures that are the same as or equivalent to those in Embodiment 1 described above. In Embodiment 1 described above, an example was given of specifying the data that the user group should conceal, considering each device 21. However, we consider the case where the user group determines the data that should be concealed based on different considerations. Hereinafter, we will describe an example where the user group determines the data that should be kept confidential based on the time and region associated with the data and the content of the data.

[0093] The Web server unit 140 in this embodiment is as follows: Figure 11 As shown, examples of data set to be non-public outside of the user group include data with a timestamp attached for the specified confidentiality period, data associated with the specified region, and data containing the specified confidential information.

[0094] Data stored in storage unit 110 is sometimes associated with a timestamp representing a moment. This moment could be the moment information is sent from device 21, the moment data is stored in storage unit 110, or any other moment. User entity 42 specifies the data stored in storage unit 110 that it wants to conceal by time. Specifically, web server unit 140 handles the designation of a confidentiality period for data that should be kept confidential, and access control unit 120 restricts disclosure to users outside the user group for data with timestamps assigned within the designated confidentiality period. Management unit 100 is an example of a management unit that manages data by associating time with it. Web server unit 140 is an example of a receiving unit that receives from user entities the designation of a confidentiality period containing the time associated with the data that should be kept confidential. Access control unit 120 is an example of an access control unit that restricts access from entities other than the user entity to the data associated with the time within the confidentiality period.

[0095] Furthermore, the data stored in storage unit 110 is sometimes associated with a region. This region could be the region where facility 20 is located, the manufacturing region of device 21, the region where the headquarters of the maintenance group or user group is located, or other regions. Additionally, a region could be a country or a country-like region, a region defined by latitude and longitude, a region corresponding to a continent, or other regions. User entity 42 specifies the data stored in storage unit 110 that it wants to conceal by region. Specifically, web server unit 140 handles the designation of confidential regions for data that should be kept confidential, and access control unit 120 restricts the disclosure of data associated with the designated confidential regions to entities outside the user group. Management unit 100 is an example of a management unit that manages data by associating regions with it. Web server unit 140 is an example of a receiving unit that receives designations from user entities for regions associated with confidential data, i.e., confidential regions. Access control unit 120 is an example of an access control unit that restricts access to data associated with confidential regions from entities other than the user entity.

[0096] Furthermore, the data that user entity 42 wants to conceal sometimes contains confidential information used to distinguish it from other data. Here, the object to be kept confidential can be either the data itself or the confidential information. For example, the confidential information can also be an identifier or symbol indicating that the data should be kept confidential. User entity 42 specifies the data it wants to conceal within the data stored in storage unit 110 using confidential information. Specifically, web server unit 140 accepts the specification of confidential information, and access control unit 120 restricts the disclosure of data containing the specified confidential information to entities other than the user group. Web server unit 140 is an example of an acceptance unit that accepts the specification of confidential information contained in data that should be kept confidential from the user entity. Access control unit 120 is an example of an access control unit that restricts access to data containing confidential information from entities other than the user entity.

[0097] As explained above, if the user group's specific expectations can be met by focusing on time, location, and confidentiality information when specifying the data that the user group should keep confidential.

[0098] Furthermore, the designation of confidential data for each device 21 in Embodiment 1 and the designation of confidential data based on time, region, and confidentiality information in this embodiment can be arbitrarily combined, or only one of them can be used.

[0099] The embodiments of this disclosure have been described above, but this disclosure is not limited to the above embodiments.

[0100] For example, the example of entity 40 being equivalent to a user has been given, but it is not limited to this. The data provided by the data providing system 1000 can be provided to devices that have been assigned roles, or to external systems such as customer management systems and component management systems.

[0101] Alternatively, when maintaining entity 41 registers a group, the scope of tables that the user entity 42 can create in the access control table of the user group can be set. Within this scope, the content of the table is determined by the respective entities 40 of the two groups that are managed as a set.

[0102] An example illustrating that access control-related tasks for user groups are primarily performed by maintenance entity 41 has been given. However, if user groups are registered by maintenance entity 41 and managed as a set, user entity 42 can also perform access control-related tasks. For example, user entity 42 can edit the data model corresponding to the maintenance group and reflect the edits in the user group's access control table 102. Furthermore, the permission to perform such edits can be granted to the user entity 42's role in access control table 102.

[0103] Furthermore, an example of specifying a data model for the maintenance group and designating a user group has been described, but this is not a limitation. The maintenance group and the user group can be interchanged, or at least one of them can be changed to another group. The maintenance group in the above implementation is equivalent to an example of Group 1, and the user group is equivalent to an example of Group 2, which is different from Group 1.

[0104] When the maintenance group and the user group are swapped, the data model corresponding to the user group is applied when generating the access control list 102 corresponding to the maintenance group. Therefore, the task of creating a data model for the maintenance group is not required, reducing the workload. Furthermore, when the data model of the user group is changed, the task of redesigning the data model for the maintenance group is not required, further reducing the workload.

[0105] Furthermore, if device 21 has the aforementioned API functions, gateway device 22 can be omitted to form data provision system 1000.

[0106] In addition, roles are not limited to the examples mentioned above and can be defined in layers.

[0107] Furthermore, while an example of the data management device 10 receiving designated confidential data from the user entity 42 has been described, it is also possible to set a parameter for designating confidential data for the user entity 42 on the device 21, and for the data management device 10 to receive this parameter from the device 21. In the case of receiving this parameter, the first communication unit 130 is equivalent to an example of a receiving unit that receives designated confidential data.

[0108] In addition, data related to the information sent from device 21 and Figure 5 The example shown is of business data being used as an object of access control, but other data can also be used as objects of access control. Figure 12 The diagram illustrates how the access control unit 120 controls access to the access-controlled data in the storage unit 110 based on the access control table 102 and the usage group-side setting data 105d. The usage group-side setting data 105d specifies information about data that should be kept confidential based on the usage group, for example, equivalent to... Figure 7 The setting data 105 and Figure 11 The setting data is 105c. Additionally, as access control data, in... Figure 12 The diagram shows device data 111, data model DB 101, and role data 104 based on information sent from device 21. That is, the data model and role data 104 can be used as objects of access control.

[0109] Furthermore, the management unit 100 and the storage unit 110 are described as independent components, but the management unit 100 may also include the storage unit 110, and the management unit 100 and the storage unit 110 may also be integrated.

[0110] Furthermore, an example was described where data sent from device 21 was directly provided to entity 40. In this example, device 21 becomes the source of data generation in the data providing system 1000. However, this is not a limited example; device 21 may also obtain data from other devices that do not have the capability to communicate with gateway device 22 and send it to gateway device 22.

[0111] The functions of the data management device 10 described above can be implemented using dedicated hardware, or they can be implemented using a conventional computer system.

[0112] For example, program P1 can be stored and distributed on computer-readable recording media such as floppy disks, CD-ROMs (Compact Disk Read-Only Memory), DVDs (Digital Versatile Disk), and MOs (Magneto-Optical Disk), and then installed in a computer, thereby constituting a device for performing the above-mentioned processing.

[0113] Alternatively, program P1 can be pre-stored on a disk drive of a server device on a communication network such as the Internet, and then downloaded to a computer, for example, by overlapping with a carrier wave.

[0114] Alternatively, the above processing can also be achieved by transmitting and executing program P1 via a network, such as the Internet.

[0115] Furthermore, the aforementioned processing can also be achieved by executing all or part of program P1 on a server device, and by having a computer execute program P1 while sending and receiving information related to the processing via a communication network.

[0116] In addition, when the above functions are implemented by the OS (Operating System) or through the cooperation of the OS and the application, only the parts other than the OS can be stored on the medium for distribution, or they can be downloaded to the computer.

[0117] Furthermore, the means of realizing the functions of the data management device 10 are not limited to software; some or all of them can also be realized through dedicated hardware or circuits.

[0118] Various embodiments and modifications can be made to this disclosure without departing from its broad spirit and scope. Furthermore, the above-described embodiments are illustrative of this disclosure and do not limit its scope. That is, the scope of this disclosure is not shown by the embodiments, but by the claims. Moreover, various modifications implemented within the scope of the claims and their equivalents are considered to be within the scope of this disclosure.

[0119] Industrial availability

[0120] This disclosure is suitable for controlling network access to data generated in a facility.

[0121] Label Explanation

[0122] 10 Data Management Device; 20 Facility; 21 Device; 22 Gateway Device; 30 Terminal; 40 Entity; 41 Maintenance Entity; 42 User Entity; 51 Operational Status Data; 52 Alarm Data; 61 Processor; 62 Main Storage Unit; 63 Auxiliary Storage Unit; 64 Input Unit; 65 Output Unit; 66 Communication Unit; 67 Internal Bus; 100 Management Unit; 101 Data Model DB; 102 Access Control Table; 104 Role Data; 105, 105a, 105b, 105c Setting Data; 105d User Group Side Setting Data; 110 Storage Unit; 111 Device Data; 120 Access Control Unit; 130 First Communication Unit; 140 Web Server Unit; 150 Second Communication Unit; 221 Operational Status API; 222 Alarm API; 1000 Data Providing System; NW Network; P1 Program.

Claims

1. A data management device that receives device information from a device installed in a facility, manages data related to the device information, and provides the data to an entity via a network, wherein, The data management device includes: The management unit stores and manages a table that, for a combination of roles assigned to multiple entities belonging to a group and attributes of the data defined by a pre-determined data model corresponding to the group, indicates whether the entity assigned the role is permitted to access the data having the attribute. An access control unit controls the entity's access to the data based on the table corresponding to the group to which the entity belongs; as well as The receiving unit accepts registrations from entities belonging to Group 1 that are registered in Group 2, which is different from Group 1. The management unit applies the data model corresponding to the first group as the data model for constructing the table corresponding to the second group.

2. The data management device according to claim 1, wherein, The management unit manages the first group and the second group as a single set.

3. The data management device according to claim 1 or 2, wherein, The acceptance unit accepts registrations from the entity belonging to the first group for the second group as the recipient of maintenance services for the device.

4. The data management device according to any one of claims 1 to 3, wherein, The management unit generates a table that, for each of the entities belonging to the second group, indicates whether an entity assigned a role is permitted to access the data having that attribute, based on a combination of the roles assigned to the entities and the attributes of the data defined by the data model used to constitute the table corresponding to the first group.

5. The data management device according to any one of claims 1 to 4, wherein, If the data model used to constitute the table corresponding to the first group is changed by the entity belonging to the first group, the management unit updates the table by applying the changed data model to the table corresponding to the second group.

6. The data management device according to any one of claims 1 to 5, wherein, The data management device receives device information from multiple devices installed in the facility. The receiving unit accepts the designation of the confidential device from the entity belonging to the second group or from the confidential device itself that sends confidential device information from among the multiple devices. The access control unit restricts entities other than those belonging to the second group from accessing data related to device information sent from the security device.

7. The data management device according to any one of claims 1 to 5, wherein, The data management device receives device information from a plurality of devices installed in the facility. The receiving unit, based on the combination of attributes of each device and the data associated with the device information sent from that device, accepts whether to grant permission for entities other than those belonging to the second group to access the data associated with the device information sent from that device and having that attribute, either from the entity belonging to the second group or from the device. The access control unit controls access to entities other than those belonging to the second group, according to the settings of being accepted by the acceptance unit.

8. The data management device according to any one of claims 1 to 7, wherein, The management unit will constantly associate itself with the data for management. The receiving unit receives, from the entity belonging to the second group or from the device, a designation of a confidentiality period including the time at which the data to be kept confidential should be kept confidential. The access control unit restricts entities other than those belonging to the second group from accessing the data associated with a time during the confidentiality period.

9. The data management device according to any one of claims 1 to 8, wherein, The management unit associates regions with the data for management purposes. The receiving unit receives a designation of a confidential region from the entity belonging to the second group or from the device, the confidential region being a region associated with the data that should be kept confidential. The access control unit restricts entities other than those belonging to the second group from accessing the data associated with the confidential area.

10. The data management device according to any one of claims 1 to 9, wherein, The receiving unit receives the designation of confidential information contained in the data that should be kept confidential from the entity belonging to the second group or from the device. The access control unit restricts entities other than those belonging to the second group from accessing the data containing the confidential information.

11. A data provisioning system comprising: Device, which is installed in the facility; The data management device according to any one of claims 1 to 10, which receives device information from the device and manages data related to the device information; and The terminal receives the data from the data management device via a network.

12. A data management method, performed by a data management device, which receives device information from a device located in a facility, manages data related to the device information, and provides the data to an entity via a network, wherein... The data management method includes: The management unit stores and manages a table that, for each of the entities belonging to a group, displays whether an entity assigned a role is permitted to access the data having that attribute, based on a combination of roles assigned to those entities and attributes defined by a pre-determined data model corresponding to the group. The access control unit controls the entity's access to the data based on the table corresponding to the group to which the entity belongs. The acceptance unit accepts registrations from entities belonging to Group 1 that are registered in Group 2, which is different from Group 1. The management unit applies the data model corresponding to the first group as the data model for constructing the table corresponding to the second group.

13. A program that enables a data management device to function as a unit, wherein, The data management device receives device information from devices installed in the facility, manages data related to the device information, and provides the data to entities via a network. The unit is: The management unit stores and manages a table that, for a combination of roles assigned to multiple entities belonging to a group and attributes of the data defined by a pre-determined data model corresponding to the group, indicates whether the entity assigned the role is permitted to access the data having the attribute. An access control unit controls the entity's access to the data based on the table corresponding to the group to which the entity belongs; as well as The receiving unit accepts registrations from entities belonging to Group 1 that are registered in Group 2, which is different from Group 1. The management unit applies the data model corresponding to the first group as the data model for constructing the table corresponding to the second group.

Citation Information

Patent Citations

  • Access control device, access control method for access control device and access control program

    JP2010117885A