Information processing device, information processing method, and program

JP2025133918A5Pending Publication Date: 2025-10-28RICOH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025116285
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-10
Publication Date
2025-10-28

AI Technical Summary

Technical Problem

Conventional systems fail to appropriately control the integration of services when a logged-in user has permission to use only one of two services that can be integrated, leading to improper linkage of services.

Method used

An information processing device with a collaboration function activation unit and a user-specific collaboration function control unit that enables or disables the use of linkage functions based on the user's authority to use both collaboration source and destination services.

Benefits of technology

This approach allows for appropriate control of linking functions for logged-in users, ensuring that services are integrated only when the user has the necessary authority, thereby preventing unauthorized access and enhancing service management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To properly control use of a cooperative function to another service by a user who has logged in to use one service when the user wants to use a service and there is another service cooperative with the service that the user is going to use.SOLUTION: The information processor includes: a cooperative function validation unit for validating a cooperative function from a service of a cooperation source to a service of a cooperation destination when a contract user can use both the services; and a user-specific cooperative function control unit for disabling use of a cooperative function by a user who has logged in when the user managed by the contract user is not authorized to use the service of the cooperation destination.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device, an information processing system, an information processing method, and a program. [Background technology]

[0002] The following Patent Document 1 discloses a technology relating to a service providing system that provides multiple services, in which a user can log in to the service providing system using login information including an organization ID, thereby allowing the user to use services that are available under a contract and that are associated with the organization ID. Summary of the Invention [Problem to be solved by the invention]

[0003] However, with conventional technology, even if it is possible to present services that can be used under a contract, there is a problem in that it is not possible to properly control the integration of services in cases where, for example, a logged-in user has permission to use only one of two services that can be integrated with each other.

[0004] In order to solve the problems of the conventional technology described above, the present invention aims to appropriately control the use of linkage functions by a logged-in user to other services when there are other services that can be linked to the service when the logged-in user uses the service. [Means for solving the problem]

[0005] In order to solve the above-mentioned problems, an information processing device according to one embodiment includes a collaboration function activation unit that activates the collaboration function from the collaboration source service to the collaboration destination service when the contracted user can use both the collaboration source service and the collaboration destination service, and a user-specific collaboration function control unit that disables the use of the collaboration function by the logged-in user managed by the contracted user when the logged-in user does not have the authority to use the collaboration destination service. [Effects of the Invention]

[0006] According to one embodiment, when a logged-in user uses a service, if there are other services that can be linked to that service, the logged-in user's use of linking functions to other services can be appropriately controlled. [Brief explanation of the drawings]

[0007] [Figure 1] FIG. 1 is a diagram showing an overview of an integrated service providing system according to an embodiment of the present invention. [Figure 2] FIG. 1 is a diagram showing the configuration of an information processing system according to an embodiment of the present invention. [Figure 3] Hardware configuration diagram of the electronic whiteboard [Figure 4] MFP hardware configuration diagram [Figure 5] Management server hardware configuration diagram [Figure 6] Management terminal hardware configuration diagram [Figure 7] FIG. 1 is a diagram showing the functional configuration of a management server according to an embodiment of the present invention. [Figure 8] FIG. 1 is a diagram showing a specific example of a contract information DB according to an embodiment of the present invention. [Figure 9] FIG. 10 is a diagram showing a specific example of an association definition information DB according to an embodiment of the present invention. [Figure 10] FIG. 10 is a diagram showing a specific example of a user authority information DB according to an embodiment of the present invention. [Figure 11] FIG. 1 is a diagram showing a specific example of a linked usage information DB according to an embodiment of the present invention. [Figure 12] 1 is a flowchart showing a procedure for processing a new contract by a management server according to an embodiment of the present invention. [Figure 13] 1 is a flowchart showing a procedure for processing an additional contract by a management server according to an embodiment of the present invention. [Figure 14] 10 is a flowchart showing the procedure of a contract cancellation process performed by a management server according to an embodiment of the present invention. [Figure 15]FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when making an additional service contract according to an embodiment of the present invention. [Figure 16] FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when making an additional service contract according to an embodiment of the present invention. [Figure 17] FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when making an additional service contract according to an embodiment of the present invention. [Figure 18] FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when canceling a service contract according to an embodiment of the present invention. [Figure 19] FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when canceling a service contract according to an embodiment of the present invention. [Figure 20] FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when canceling a service contract according to an embodiment of the present invention. [Figure 21] FIG. 10 is a diagram showing an example of a display screen displayed on the management terminal when canceling a service contract according to an embodiment of the present invention. [Figure 22] A diagram showing a first example of the linkage function of the service provided to the contracted user. [Figure 23] A diagram showing a first example of the linkage function of the service provided to the contracted user. [Figure 24] A diagram showing a second specific example of the linkage function of the service provided to the contracted user. [Figure 25] A diagram showing a second specific example of the linkage function of the service provided to the contracted user. [Figure 26] FIG. 1 is a sequence diagram illustrating a procedure for user authentication processing by an information processing system according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0008] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0009] (Overview of Integrated Service Provision System 20) First, an overview of an integrated service providing system 20 according to one embodiment of the present invention will be described with reference to Fig. 1. Fig. 1 is a diagram showing an overview of an integrated service providing system 20 according to one embodiment of the present invention.

[0010] The integrated service providing system 20 shown in FIG. 1 enables the integrated management of everything related to an office (e.g., users, equipment, documents, conference rooms, etc.) using multiple services 200.

[0011] As shown in FIG. 1, the integrated service providing system 20 includes, as examples of the plurality of services 200, a resource management service 200A, a report service 200B, a wireless management service 200C, a document management service 200D, a print service 200E, and a workflow service 200F.

[0012] The integrated service providing system 20 also includes a management server 300. The management server 300 is similar to that described in FIG. 2 and subsequent figures, and functions as a platform for integrated management of multiple services 200A-200F. For example, as shown in FIG. 1, the management server 300 has a user management function, a device management function, a print service function, an activity log function, and the like. The print service function, for example, provides an end user 19 (an example of a "contracted user") with a printing function that allows the end user 19 to print using a printing device 31 (such as an MFP or printer) manufactured by the management server 300 and managed by the management server 300. The activity log function, for example, obtains a log of the number of pages printed or scanned by the device, and obtains a log of the number of contracts with the dealer 18 (sales agent). Customer users 17 and dealers 18 can access the management server 300 using any terminal device (such as the smartphone 34 or PC 35 shown in FIG. 1) to use the management functions that are permitted to them among the multiple management functions provided by the management server 300.

[0013] The resource management service 200A provides a resource management function for managing office resources (e.g., electronic whiteboards, conference rooms, etc.). For example, the end user 19 can use the resource management service 200A to manage conference room reservations, etc.

[0014] The report service 200B provides a report creation function and an output function, and the wireless management service 200C provides a wireless device management function for managing various wireless devices.

[0015] The document management service 200D provides the end user 19 with a document management function for managing multiple documents. The print service 200E provides the end user 19 with a print function for printing using a printing device 32 (MFP, printer, etc.) made by another company that is connected to the print service 200E.

[0016] The workflow service 200F provides the end user 19 with a workflow creation function and an execution function. For example, the workflow provided by the workflow service 200F can perform character recognition by performing OCR processing on an image formed by the scanner function of an image reading device 33 (e.g., an MFP, etc.), and store the recognition results in a predetermined folder. Also, for example, the workflow provided by the workflow service 200F can perform a review and approval process for any internal document.

[0017] Among these multiple services 200A-200F, some have a function of linking with other services 200 (for example, a linking function with the print service 200E in the workflow service 200F). Furthermore, the end user 19 can subscribe to and use only the necessary services 200 from these multiple services 200A-200F. For this reason, the management server 300 has a function (hereinafter referred to as the "enablement / disablement function") that can enable and disable the linking function of each service 200 depending on the contract status of the service 200 by the end user 19, as will be specifically described in FIG. 2 and subsequent figures.

[0018] The following describes application examples 1 to 8 of the activation / inactivation function in the integrated service providing system 20 shown in FIG.

[0019] (Application example 1) An enable / disable function is applied to the cooperation between the resource management service 200A and the report service 200B. For example, a report may be output on the usage status (e.g., utilization rate, number of users, etc.) of conference rooms managed by the resource management service 200A. In this case, on the setting screen of the report service 200B, each conference room managed by the resource management service 200A is displayed (enabled) or hidden (disabled) as an option (an example of a "GUI component") from which to obtain data to be output in the report, depending on whether a contract with the resource management service 200A exists and whether usage rights are available.

[0020] (Application example 2) The enable / disable function is applied to the cooperation between the wireless management service 200C and the report service 200B. For example, a report may be output on the concentration of access to a specific wireless LAN device. In this case, on the setting screen of the report service 200B, as an option (an example of a "GUI component") for obtaining data to be output in the report, each wireless device managed by the wireless management service 200C is displayed (enabled) or hidden (disabled) depending on whether or not there is a contract for the wireless management service 200C and whether or not there is usage authority.

[0021] (Application example 3) An enable / disable function is applied to the cooperation between the document management service 200D and the print service 200E. For example, when periodically printing documents managed by the document management service 200D, a print request may be periodically sent from the document management service 200D to the print service 200E. In this case, on the setting screen of the document management service 200D, the print service 200E is displayed (enabled) or hidden (disabled) as an option for the output destination of the print request (an example of a "GUI component") depending on whether or not there is a contract for the print service 200E and whether or not there is usage authority.

[0022] (Application example 4) The enable / disable function is applied to the cooperation between the print service 200E and the report service 200B. For example, the number of printed sheets managed by the print service 200E may be periodically tallied and a report output may be performed. In this case, on the setting screen of the report service 200B, the print service 200E is displayed (enabled) or hidden (disabled) as an option (an example of a "GUI component") for obtaining data to be output to the report, depending on whether a contract for the print service 200E exists and whether usage rights are available.

[0023] (Application example 5) The enable / disable function is applied to the collaboration between the workflow service 200F and the report service 200B. For example, there may be cases where the number of executions, success / failure results, etc. of workflows managed by the workflow service 200F are tallied and output as a report. In this case, on the setting screen of the report service 200B, the workflow service 200F is displayed (enabled) or hidden (disabled) as an option for the source of data to be output to the report (an example of a "GUI component") depending on whether there is a contract for the workflow service 200F and whether there is usage authority.

[0024] (Application Example 6) The enable / disable function is applied to the collaboration between the workflow service 200F and the document management service 200D. For example, as a result of executing the workflow service 200F, PDF or form information may be saved in the document management service 200D. In this case, on the settings screen for the workflow service 200F, the document management service 200D is displayed (enabled) or hidden (disabled) as an option for the save destination of the data to be saved (an example of a "GUI component"), depending on whether there is a contract for the document management service 200D and whether there is usage authority for the document management service 200D.

[0025] (Application Example 7) The enable / disable function is applied to the collaboration between the resource management service 200A and the print service 200E that performs printing. For example, by selecting a collaboration button with the print service 200E displayed on an electronic whiteboard managed by the resource service, data displayed on the electronic whiteboard may be printed by a printing device available from the print service 200E. In this case, the collaboration button with the print service 200E is displayed (enabled) or hidden (disabled) on the electronic whiteboard under control from the resource service, depending on whether a contract with the print service 200E exists and whether usage rights are available.

[0026] (Application Example 8) The enable / disable function is applied to the collaboration between the resource management service 200A and the workflow service 200F. For example, by selecting a collaboration button with the workflow service 200F displayed on an electronic whiteboard managed by the resource service, data displayed on the electronic whiteboard may be input into the workflow of the workflow service 200F (a workflow for review and approval). In this case, the collaboration button with the workflow service 200F (for example, the "review request" button shown in FIG. 25) is displayed (enabled) or hidden (disabled) on the electronic whiteboard under control from the resource service, depending on whether a contract with the workflow service 200F exists and whether usage rights exist.

[0027] Hereinafter, the information processing system 10 capable of realizing the integrated service providing system 20 shown in FIG. 1 will be specifically described with reference to FIGS.

[0028] (Configuration of information processing system 10) Fig. 2 is a diagram showing the configuration of an information processing system 10 according to one embodiment of the present invention. As shown in Fig. 2, the information processing system 10 of this embodiment includes an electronic whiteboard 100, an MFP 900, a plurality of services 200, a management server 300, and a management terminal 500. These multiple devices can communicate with each other via a communication network 12.

[0029] The multiple services 200 are provided in the cloud system 14. The multiple services 200 are provided to multiple terminal devices including the electronic whiteboard 100 and the MFP 900 via the communication network 12, and are thereby available to the multiple terminal devices including the electronic whiteboard 100 and the MFP 900. Examples of the services 200 include various services such as a print service, a document management service, a workflow service, and a contract management service. The multiple services 200 may include not only services 200 provided by the company that provides the management server 300 (i.e., the company that is the main company that manages the multiple services 200), but also services 200 provided by other companies.

[0030] The interactive whiteboard 100 is a device used by meeting participants in a conference room or the like in an office. For example, the interactive whiteboard 100 is capable of displaying images, writing on images, and the like. The interactive whiteboard 100 can also use a plurality of services 200 (e.g., a print service, a document management service, a workflow service, etc.) provided by a cloud system 14 via a communication network 12. For example, the interactive whiteboard 100 can use the print service to print an image displayed on a display 180 (see FIG. 3 ) using a printing device connected to the print service. For example, the interactive whiteboard 100 can use the document management service to save an image file representing an image displayed on the display 180 to a file server or the like. For example, the interactive whiteboard 100 can use a workflow service to execute a workflow using an image file representing an image displayed on the display 180.

[0031] The MFP 900 is a device used by employees in an office or the like. For example, the MFP 900 has a scanner function, a printer function, a copy function, a document box function, a facsimile function, and the like. The MFP 900 can also use a plurality of services 200 (e.g., a print service, a document management service, a workflow service, and the like) provided by the cloud system 14 via the communication network 12. For example, the MFP 900 can use the print service to print an image scanned by the scanner function on a printing device connected to the print service. For example, the MFP 900 can use the document management service to store an image file formed by scanning an image with the scanner function on a file server or the like. For example, the MFP 900 can also use the workflow service to execute a workflow using an image file formed by scanning an image with the scanner function.

[0032] In this embodiment, the electronic whiteboard 100 and the MFP 900 are used as examples of a "terminal device" that can use a plurality of services 200. However, the present invention is not limited to this, and a PC, a tablet terminal, a smartphone, a video conference terminal, a camera, a scanner, a projector, a handy printer, etc. can also be used as a "terminal device" that can use a plurality of services 200.

[0033] The management server 300 is an example of an "information processing device." The management server 300 is provided within the cloud system 14. The management server 300 functions as a platform for integrated management of multiple services 200. For example, the management server 300 can perform various management operations related to the services 200, such as management of contracted users of the services 200, management of the services 200, and contract management for the services 200. For example, the management server 300 manages login information, contract information, and the like for each contracted user of the services 200. This allows a contracted user to log in to the cloud system 14 using their own login information from the electronic whiteboard 100, the MFP 900, or another terminal device, and use the service 200 to which they have subscribed, among the multiple services 200 provided by the cloud system 14.

[0034] In this system, a "contracted user" refers to a user who has been granted the authority to sign a contract for a service (to sign a new contract or cancel a contract). A "contracted user" is not limited to an individual, but may be a group consisting of multiple individuals, such as an organization or company. If a "contracted user" is an individual, that user may also be an administrator. On the other hand, a "logged-in user" refers to a user who can use a service provided by this system by logging in with a user ID and password. In this system, for each service contracted by a "contracted user," the administrator of that service grants and manages usage authority to one or more "logged-in users."

[0035] The management terminal 500 is a terminal device used by the contract manager 16 (an example of a "contract user's related party"; for example, the dealer 18 shown in FIG. 1) who manages the contract. In this embodiment, a PC is used as the management terminal 500, but other terminal devices may also be used. For example, the management terminal 500 is used by the contract manager 16 when signing a new contract for a specific contract user, signing an additional contract, or canceling a contract for the service 200. For example, by logging in to the management server 300 from the management terminal 500, the contract manager 16 can sign a new contract for a specific service 200 (i.e., activate the service 200), sign an additional contract (i.e., activate the service 200), and cancel a contract (i.e., disable the service 200) for the specific contract user.

[0036] (Hardware configuration of the electronic whiteboard 100) Fig. 3 is a hardware configuration diagram of the interactive whiteboard 100. As shown in Fig. 3, the interactive whiteboard 100 includes a CPU (Central Processing Unit) 101, a ROM (Read Only Memory) 102, a RAM (Random Access Memory) 103, an SSD (Solid State Drive) 104, a network I / F 105, and an external device connection I / F (Interface) 106.

[0037] Of these, the CPU 101 controls the overall operation of the interactive whiteboard 100. The ROM 102 stores the CPU 101 and programs used to drive the CPU 101, such as an IPL (Initial Program Loader). The RAM 103 is used as a work area for the CPU 101. The SSD 104 stores various data, such as programs for the interactive whiteboard 100. The network I / F 105 controls communication with the communication network 12. The external device connection I / F 106 is an interface for connecting various external devices. In this case, the external devices are, for example, a USB (Universal Serial Bus) memory 130 and external devices (a microphone 140, a speaker 150, and a camera 160).

[0038] The electronic whiteboard 100 also includes a capture device 111, a GPU (Graphics Processing Unit) 112, a display controller 113, a contact sensor 114, a sensor controller 115, an electronic pen controller 116, a short-range communication circuit 119, an antenna 119a of the short-range communication circuit 119, a power switch 122, and selection switches 123.

[0039] Of these, the capture device 111 displays video information as still images or moving images on the display of an external PC (Personal Computer) 170. The GPU 112 is a semiconductor chip that specializes in graphics. The display controller 113 controls and manages screen display to output an image output from the GPU 112 to a display 180 or the like. The contact sensor 114 detects contact of the display 180 with an electronic pen 190, a user's hand H, or the like. The sensor controller 115 controls the processing of the contact sensor 114. The contact sensor 114 inputs and detects coordinates using an infrared blocking method. This coordinate input and coordinate detection method involves two light receiving and emitting devices installed at both ends of the upper side of the display 180 emitting multiple infrared rays parallel to the display 180, which are reflected by reflecting members installed around the periphery of the display 180 and return along the same optical path as the light emitted by the light receiving element. The contact sensor 114 outputs the ID of the infrared light emitted by the two light receiving and emitting devices that has been blocked by an object to the sensor controller 115, and the sensor controller 115 identifies the coordinate position of the contact position of the object. The electronic pen controller 116 communicates with the electronic pen 190 to determine whether the pen tip or the pen tail has touched the display 180. The short-range communication circuit 119 is a communication circuit such as NFC (Near Field Communication) or Bluetooth (registered trademark). The power switch 122 is a switch for turning the power of the electronic whiteboard 100 ON / OFF. The selection switches 123 are a group of switches for adjusting, for example, the brightness and color of the display 180.

[0040] Furthermore, the interactive whiteboard 100 includes a bus line 110. The bus line 110 is an address bus, a data bus, or the like for electrically connecting the components such as the CPU 101 shown in FIG.

[0041] The contact sensor 114 is not limited to an infrared blocking type, and various detection means may be used, such as a capacitance type touch panel that identifies the contact position by detecting a change in capacitance, a resistive film type touch panel that identifies the contact position by a change in voltage between two opposing resistive films, or an electromagnetic induction type touch panel that identifies the contact position by detecting electromagnetic induction caused by a contacting object coming into contact with the display unit. Also, the electronic pen controller 116 may determine whether or not the part of the electronic pen 190 that the user grips or other parts of the electronic pen have been touched, in addition to the pen tip and pen butt.

[0042] (MFP900 hardware configuration) 4 is a hardware configuration diagram of the MFP 900. As shown in FIG. 4, the MFP (Multifunction Peripheral / Product / Printer) 900 includes a controller 910, a short-range communication circuit 920, an engine control unit 930, an operation panel 940, and a network I / F 950.

[0043] Of these, the controller 910 has a CPU 901, which is the main part of the computer, a system memory (MEM-P) 902, a north bridge (NB) 903, a south bridge (SB) 904, an ASIC (Application Specific Integrated Circuit) 906, a local memory (MEM-C) 907, which is a storage unit, an HDD controller 908, and an HD 909, which is also a storage unit, and is configured such that the NB 903 and the ASIC 906 are connected by an AGP (Accelerated Graphics Port) bus 921.

[0044] Of these, the CPU 901 is a control unit that performs overall control of the MFP 900. The NB 903 is a bridge that connects the CPU 901 with the MEM-P 902, the SB 904, and the AGP bus 921, and includes a memory controller that controls reading and writing to the MEM-P 902, a PCI (Peripheral Component Interconnect) master, and an AGP target.

[0045] The MEM-P 902 comprises a ROM 902a, which is memory for storing programs and data that realize the functions of the controller 910, and a RAM 902b, which is used for expanding the programs and data and as a drawing memory during memory printing. The programs stored in the RAM 902b may be provided by being recorded in an installable or executable file format on a computer-readable recording medium such as a CD-ROM, CD-R, or DVD.

[0046] The SB 904 is a bridge for connecting the NB 903 with PCI devices and peripheral devices. The ASIC 906 is an integrated circuit (IC) for image processing applications that has hardware elements for image processing and serves as a bridge connecting the AGP bus 921, PCI bus 922, HDD controller 908, and MEM-C 907. The ASIC 906 includes a PCI target and AGP master, an arbiter (ARB) that forms the core of the ASIC 906, a memory controller that controls the MEM-C 907, multiple direct memory access controllers (DMACs) that perform image data rotation using hardware logic, and a PCI unit that transfers data between the scanner unit 931 and printer unit 932 via the PCI bus 922. A USB (Universal Serial Bus) interface or an IEEE 1394 (Institute of Electrical and Electronics Engineers) interface may also be connected to the ASIC 906.

[0047] The MEM-C907 is a local memory used as an image buffer for copying and a code buffer. The HD909 is a storage for storing image data, font data used during printing, and forms. The HD909 controls the reading and writing of data from and to the HD909 under the control of the CPU901. The AGP bus 921 is a bus interface for a graphics accelerator card proposed to speed up graphics processing, and direct high-throughput access to the MEM-P902 enables the graphics accelerator card to operate at high speed.

[0048] The short-range communication circuit 920 is also provided with an antenna 920a. The short-range communication circuit 920 is a communication circuit such as NFC or Bluetooth.

[0049] Furthermore, the engine control unit 930 is made up of a scanner unit 931 and a printer unit 932. The operation panel 940 is equipped with a panel display unit 940a, such as a touch panel, that displays current setting values, selection screens, etc. and accepts inputs from the operator, and an operation panel 940b that includes a numeric keypad that accepts setting values ​​for image formation conditions such as density setting conditions and a start key that accepts a copy start instruction. The controller 910 controls the entire MFP 900, and controls, for example, drawing, communication, input from the operation panel 940, etc. The scanner unit 931 or the printer unit 932 includes an image processing unit that performs error diffusion, gamma conversion, etc.

[0050] The MFP 900 can sequentially switch among the document box function, copy function, printer function, and facsimile function using the application switching key on the operation panel 940. When the document box function is selected, the MFP 900 enters document box mode, when the copy function is selected, the MFP 900 enters copy mode, when the printer function is selected, the MFP 900 enters printer mode, and when the facsimile mode is selected, the MFP 900 enters facsimile mode.

[0051] The network I / F 950 is an interface for performing data communication using the communication network 12. The short-range communication circuit 920 and the network I / F 950 are electrically connected to the ASIC 906 via a PCI bus 922.

[0052] (Hardware configuration of management server 300) Fig. 5 is a hardware configuration diagram of the management server 300. As shown in Fig. 5, the management server 300 is constructed by a computer, and includes a CPU 301, a ROM 302, a RAM 303, an HD 304, an HDD (Hard Disk Drive) controller 305, a display 306, an external device connection I / F (Interface) 308, a network I / F 309, a bus line 310, a keyboard 311, a pointing device 312, a DVD-RW (Digital Versatile Disk Rewritable) drive 314, and a media I / F 316.

[0053] Of these, the CPU 301 controls the overall operation of the management server 300. The ROM 302 stores programs used to drive the CPU 301, such as the IPL. The RAM 303 is used as a work area for the CPU 301. The HD 304 stores various data, such as programs. The HDD controller 305 controls the reading and writing of various data from and to the HD 304 under the control of the CPU 301. The display 306 displays various information, such as a cursor, menu, window, text, or image. The external device connection I / F 308 is an interface for connecting various external devices. In this case, the external device is, for example, a USB (Universal Serial Bus) memory or a printer. The network I / F 309 is an interface for data communication using the communication network 12. The bus line 310 is an address bus, a data bus, or the like, for electrically connecting the components, such as the CPU 301, shown in FIG. 5.

[0054] The keyboard 311 is a type of input means having multiple keys for inputting characters, numbers, various instructions, etc. The pointing device 312 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The DVD-RW drive 314 controls reading and writing of various data from a DVD-RW 313, which is an example of a removable recording medium. Note that this is not limited to a DVD-RW, and may be a DVD-R, etc. The media I / F 316 controls reading and writing (storing) of data from a recording medium 315, such as a flash memory.

[0055] (Hardware configuration of management terminal 500) Fig. 6 is a hardware configuration diagram of the management terminal 500. As shown in Fig. 6, the management terminal 500 is constructed by a computer, and includes a CPU 501, a ROM 502, a RAM 503, an HD 504, an HDD (Hard Disk Drive) controller 505, a display 506, an external device connection I / F (Interface) 508, a network I / F 509, a bus line 510, a keyboard 511, a pointing device 512, a DVD-RW (Digital Versatile Disk Rewritable) drive 514, and a media I / F 516.

[0056] Of these, the CPU 501 controls the overall operation of the management terminal 500. The ROM 502 stores programs used to drive the CPU 501, such as the IPL. The RAM 503 is used as a work area for the CPU 501. The HD 504 stores various data, such as programs. The HDD controller 505 controls the reading and writing of various data from and to the HD 504 under the control of the CPU 501. The display 506 displays various information, such as a cursor, menu, window, text, or image. The external device connection I / F 508 is an interface for connecting various external devices. In this case, external devices include, for example, USB (Universal Serial Bus) memory and a printer. The network I / F 509 is an interface for data communication using the communication network 12. The bus line 510 is an address bus, a data bus, or the like, for electrically connecting the components, such as the CPU 501, shown in FIG. 6.

[0057] The keyboard 511 is a type of input means having multiple keys for inputting characters, numbers, various instructions, etc. The pointing device 512 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The DVD-RW drive 514 controls reading and writing of various data from a DVD-RW 513, which is an example of a removable recording medium. Note that this is not limited to a DVD-RW, and may be a DVD-R, etc. The media I / F 516 controls reading and writing (storing) of data from a recording medium 515, such as a flash memory.

[0058] (Functional configuration of management server 300) 7 is a diagram showing the functional configuration of a management server 300 according to an embodiment of the present invention. As shown in FIG. 7, the management server 300 includes a storage unit 320, a contract information receiving unit 331, a service enabling unit 332, a linked service identifying unit 333, a linked function enabling unit 334, a contract user notifying unit 335, a contract user confirming unit 336, a user authenticating unit 340, and a user-specific linked function control unit 341.

[0059] The storage unit 320 stores various databases. Specifically, the storage unit 320 stores a contract information DB321, a collaboration definition information DB322, a collaboration usage information DB323, a user information DB324, and a user authority information DB325. The contract information DB321 stores contract information indicating which services each contracted user has subscribed to (i.e., which services are available). The collaboration definition information DB322 stores collaboration definition information indicating which services each service is linked with. The collaboration usage information DB323 stores collaboration usage information indicating which service collaboration each contracted user is actually using. The user information DB324 stores user information for each logged-in user. The user information includes at least a user ID and password required for user authentication processing. The user authority information DB325 stores information regarding the usage authority of each service for each logged-in user (e.g., whether or not the user has user authority or whether or not the user has administrator authority). Specific examples of the contract information DB 321, the cooperation definition information DB 322, the cooperation usage information DB 323, and the user authority information DB 325 will be described later with reference to FIGS.

[0060] The contract information receiving unit 331 receives service contract information transmitted from the management terminal 500. For example, the contract information receiving unit 331 receives contract information for a new contract, contract information for an additional contract, or contract information for contract cancellation.

[0061] The contract information for a new contract is sent from the management terminal 500 when the contract manager 16 makes a new contract for a service 200 for a specific contract user from the management terminal 500, and includes at least the contract user ID of the contract user making the new contract and the service ID of the service 200 for which the new contract has been made.

[0062] The contract information for the additional contract is transmitted from the management terminal 500 when the contract manager 16 makes an additional contract for the service 200 for a specific contract user from the management terminal 500, and includes at least the contract user ID of the contract user making the additional contract and the service ID of the service 200 for which the additional contract has been made.

[0063] The contract information for contract termination is sent from the management terminal 500 when the contract manager 16 terminates a contract for a service 200 for a specific contract user from the management terminal 500, and includes at least the contract user ID of the contract user performing the contract termination and the service ID of the service 200 for which the contract has been terminated.

[0064] The service activation unit 332 activates or deactivates the service 200 based on the contract information received by the contract information receiving unit 331 .

[0065] For example, when the contract information receiving unit 331 receives contract information for a new contract, the service activation unit 332 sets "valid" in the contract information DB 321 for the combination of the contract user ID of the contract user making the new contract and the service ID of the service 200 for which the new contract has been made, which are indicated in the contract information. This activates the service 200 for which the new contract has been made.

[0066] Furthermore, for example, when the contract information receiving unit 331 receives contract information for an additional contract, the service activation unit 332 sets "valid" in the contract information DB 321 for the combination of the contract user ID of the contract user making the additional contract and the service ID of the service 200 for which the additional contract has been made, which are indicated in the contract information. This activates the service 200 for which the additional contract has been made.

[0067] Furthermore, for example, when contract information for contract cancellation is received by the contract information receiving unit 331, the service activation unit 332 sets "invalid" in the contract information DB 321 for the combination of the contract user ID of the contract user canceling the contract and the service ID of the service 200 whose contract has been cancelled, which are indicated in the contract information. As a result, the service 200 whose contract has been cancelled is invalidated.

[0068] When the service 200 is enabled or disabled by the service enabling unit 332, the linked service identifying unit 333 identifies other services 200 that are to be linked to the service 200 based on the linkage definition information DB 322.

[0069] When the linked service identification unit 333 identifies another service 200 that links with the activated service 200, the linked function activation unit 334 notifies the link source service 200, of the activated service 200 and the other service 200 identified by the linked service identification unit 333, to activate a link function with the linked service 200. For example, in response to this notification, the link source service 200 activates a GUI component (e.g., a selection button) of the link function with the linked service 200.

[0070] Furthermore, when the linked service identification unit 333 identifies another service 200 that links with the disabled service 200, the linked function activation unit 334 notifies the other service 200 to disable the linked function with the disabled service 200. For example, in response to this notification, the other service 200 disables a GUI component (e.g., a selection button) of the linked function with the disabled service 200.

[0071] When a contracted user makes an additional contract for a certain service 200, and the additional service 200 (service 200 that becomes the cooperation destination) can be used in cooperation with another service 200 (service 200 that becomes the cooperation source), the contracted user notification unit 335 notifies the contracted user who made the additional contract that the service 200 that becomes the cooperation destination can now be used from the service 200 that becomes the cooperation source. For example, this notification is realized by sending a message to the terminal device used by the contracted user who made the additional contract.

[0072] When a contract for a certain service 200 is terminated by a contract user, and the terminated service 200 (the coordinated service 200) cannot be used in coordination with another service 200 (the coordinated service 200), the contracted user confirmation unit 336 confirms with the contracted user whether or not it is OK to disable the terminated service 200. For example, this confirmation is realized by sending a message to the terminal device used by the contracted user who terminated the contract.

[0073] The user authentication unit 340 acquires login information transmitted from various terminal devices used by the login user and performs authentication processing of the login user based on the login information. Specifically, if the combination of user ID and password included in the login information transmitted from various terminal devices matches a combination of user ID and password previously stored in the user information DB 324, the user authentication unit 340 determines the result of the authentication processing of the login user as "successful." In this case, for example, the user authentication unit 340 notifies the service 200 subscribed to by the contracted user to which the login user who performed the login processing belongs of the user authentication processing result indicating that the authentication processing of the login user was successful, along with the user ID. The user authentication unit 340 also notifies the login user who performed the login processing of the user authentication processing result indicating that the authentication processing of the login user was successful. As a result, the login user who performed the login processing can use the service 200 subscribed to by the contracted user to which the login user belongs from various terminal devices. On the other hand, if the combination of user ID and password included in the login information transmitted from the various terminal devices does not match the combination of user ID and password stored in advance in the user information database, the user authentication unit 340 determines that the result of the authentication process for the login user is "failed." In this case, for example, the user authentication unit 340 notifies the login user who performed the login process that the login process has failed.

[0074] The functions of the above-described embodiments can be realized by one or more processing circuits. Here, the term "processing circuit" in this specification includes a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, as well as devices such as an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and conventional circuit modules designed to execute each of the above-described functions.

[0075] The user-specific collaboration function control unit 341 controls enabling and disabling of collaboration functions of services for each login user. Specifically, when a login user uses a collaboration source service 200, the user-specific collaboration function control unit 341 determines whether the login user has the authority to use the collaboration destination service 200 based on the user authority information DB 325. If the user-specific collaboration function control unit 341 determines that the login user does not have the authority to use the collaboration destination service 200, it causes the collaboration source service 200 to disable the collaboration function (e.g., GUI components) that the collaboration source service 200 has for the collaboration destination service 200.

[0076] (Specific example of contract information DB321) FIG. 8 is a diagram illustrating a specific example of the contract information DB 321 according to an embodiment of the present invention. As illustrated in FIG. 8, the contract information DB 321 associates, for each contract user ID for identifying a contract user of the service 200, information indicating whether each of a plurality of services ("Service A," "Service B," and "Service C") provided by the cloud system 14 is valid or invalid ("valid" or "invalid"). For example, in the example illustrated in FIG. 8, "valid" is associated with the contract user ID "Company1" for each of the service IDs "Service A," "Service B," and "Service C." This indicates that a contract user having the contract user ID "Company1" can use each of the three services "Service A," "Service B," and "Service C." Also, in the example illustrated in FIG. 8, "valid" is associated with the contract user ID "Company2" for each of the service IDs "Service A" and "Service B," but "invalid" is associated with the service ID "Service C." This indicates that a contract user having the contract user ID "Company2" can use each of the services "ServiceA" and "ServiceB" (i.e., has signed a contract), but cannot use the service "ServiceC" (i.e., has not signed a contract). For example, a contract user ID is set for each organization within a company called a tenant. However, this is not a limitation, and a contract user ID may be set for other units (e.g., for each individual within a company). Furthermore, while the contract information DB321 shown in FIG. 8 indicates whether a contract is valid or invalid for each tenant and for each service, this is not a limitation, and for example, whether a contract is valid or invalid may be indicated for each user belonging to a tenant and for each service. Furthermore, the contract information DB321 may store only combinations of validated contract user IDs and service IDs.

[0077] (Specific example of the linkage definition information DB 322) 9 is a diagram showing a specific example of the collaboration definition information DB 322 according to an embodiment of the present invention. As shown in FIG. 9, the collaboration definition information DB 322 stores, in association with each other, a collaboration definition information ID for identifying the collaboration of the service 200, a service ID for identifying the collaboration source service 200, and a service ID for identifying the collaboration destination service 200 that can collaborate with the service 200. For example, in the example shown in FIG. 9, the service ID "ServiceA" of the collaboration source service 200 is associated with the service IDs "ServiceB" and "ServiceC" of the collaboration destination service 200. This indicates that the service 200 having the service ID "ServiceA" can use two services 200 having the service IDs "ServiceB" and "ServiceC" in collaboration with each other.

[0078] In the cooperation definition information DB 322, a combination of two services 200 can define one-way cooperation use and two-way cooperation use.

[0079] 9, for example, in the combination of "Service A" and "Service B," the collaboration definition information DB 322 stores collaboration definition information (collaboration definition information ID "1") in which "Service A" is the collaboration source and "Service B" is the collaboration destination, and collaboration definition information (collaboration definition information ID "3") in which "Service B" is the collaboration source and "Service A" is the collaboration destination. This indicates that two-way collaboration is possible between "Service A" and "Service B."

[0080] 9, for the combination of "Service A" and "Service C," only the collaboration definition information (collaboration definition information ID "2") in which "Service A" is the collaboration source and "Service C" is the collaboration destination is stored in the collaboration definition information DB 322. In other words, it is indicated that one-way collaboration is possible between "Service A" and "Service C."

[0081] (Example of user authority information DB325) Fig. 10 is a diagram showing a specific example of the user authority information DB 325 according to one embodiment of the present invention. As shown in Fig. 10, the user authority information DB 325 stores, for each of a plurality of login users who can use the service 200, a user ID for identifying the login user, a contract user ID of a contract user (e.g., a company, a department, etc.) to which the login user belongs, and the presence or absence of administrator authority and user authority for each service 200, in association with each other.

[0082] 10, "True" indicates that the user has the authority, "False" indicates that the user does not have the authority, and "Null" indicates that the user has not subscribed to the service 200.

[0083] For example, in the example shown in FIG. 10, the user authority information DB325 indicates that a login user with user ID "User1" belongs to a contract user with contract user ID "Company1" and has administrator authority and user authority for each of "ServiceA", "ServiceB", and "ServiceC".

[0084] In addition, in the example shown in Figure 10, the user authority information DB325 indicates that the login user with the user ID "User2" belongs to the contract user with the contract user ID "Company1", and does not have administrator authority for each of "ServiceA", "ServiceB", and "ServiceC", but has user authority.

[0085] In addition, in the example shown in Figure 10, the user authority information DB325 indicates that the login user with user ID "User3" belongs to the contract user with contract user ID "Company1", does not have administrator authority for each of "ServiceA" and "ServiceC", but has user authority, and does not have administrator authority or user authority for "ServiceB".

[0086] In addition, in the example shown in Figure 10, the user authority information DB325 indicates that the login user with user ID "User4" belongs to the contract user with contract user ID "Company2", has administrator authority and user authority for each of "ServiceA" and "ServiceB", and has no contract for "ServiceC" (see Figure 8).

[0087] The contract manager 16 can change various settings in the user authority information DB 325 from the management terminal 500 as needed (for example, adding a logged-in user, deleting a logged-in user, or changing the authority of a logged-in user).

[0088] (Example of linked usage information DB323) FIG. 11 is a diagram showing a specific example of the collaboration information DB 323 according to an embodiment of the present invention. As shown in FIG. 11, the collaboration information DB 323 stores, in association with each other, a contract user ID for identifying a contract user of a service 200 and a collaboration definition information ID for identifying the collaboration of the service 200 that the contract user is actually using. The collaboration definition information ID set in the collaboration information DB 323 corresponds to the collaboration definition information ID set in the collaboration definition information DB 322 shown in FIG. 9. For example, in the example shown in FIG. 11, collaboration definition information IDs "1" and "3" are associated with the contract user ID "Company1." This indicates that the contract user having the contract user ID "Company1" is actually using the collaboration of the service 200 having the collaboration definition information ID "1" shown in FIG. 9 (collaboration source="ServiceA", collaboration destination="ServiceB") and the collaboration of the service 200 having the collaboration definition information ID "3" shown in FIG. 9 (collaboration source="ServiceB", collaboration destination="ServiceA"). In addition, the registration of information in the collaborative usage information DB323 (i.e., whether or not the collaborative function of the service 200 is being used) may be set manually by the contract manager 16 from the management terminal 500, for example, or may be set automatically by the management server 300 depending on the usage status of the collaborative function of the service 200.

[0089] (Procedure for processing new contracts) FIG. 12 is a flowchart showing the procedure of a new contract processing by the management server 300 according to an embodiment of the present invention.

[0090] First, the contract information receiving unit 331 receives contract information of a new contract transmitted from the management terminal 500 via the communication network 12 (step S1001). The contract information of the new contract includes at least a contract user ID for identifying the contracting user and a service ID for identifying the service 200 for which the new contract has been made. Note that when a new contract has been made for multiple services 200, the contract information of the new contract includes the service IDs of each of the multiple services 200.

[0091] Next, the service activation unit 332 activates the service 200 for which the new contract has been made for the contract user who has made the new contract, based on the contract information of the new contract received in step S1001 (step S1002). Specifically, the service activation unit 332 sets "valid" in the contract information DB 321 for the combination of the contract user ID of the contract user who has made the new contract and the service ID of the service 200 for which the new contract has been made.

[0092] Next, the interlocking service identifying unit 333 identifies services 200 that will be interlocked with the newly contracted service 200 (step S1003). Specifically, by referring to the interlocking definition information DB 322, the interlocking service identifying unit 333 identifies the service IDs of other services 200 that are associated with the service ID of the newly contracted service 200 as services 200 that will be interlocked with the newly contracted service 200. For example, if the newly contracted service 200 is "Service A," the interlocking service identifying unit 333 identifies "Service B" and "Service C" as the interlocking services 200, based on the interlocking definition information DB 322 shown in FIG. 9.

[0093] Next, the linked function activation unit 334 determines whether or not a service 200 that links with the service 200 for which a new contract has been made in step S1003 has been identified (step S1004).

[0094] If it is determined in step S1004 that the linked service 200 has not been identified (step S1004: No), the management server 300 ends the series of processes shown in FIG.

[0095] On the other hand, if it is determined in step S1004 that the linked service 200 has been identified (step S1004: Yes), the linked function activation unit 334 notifies the linking service 200, which is the link source service among the newly contracted service 200 and the linked service 200, that it can use the linked service 200 (step S1005).Then, the management server 300 ends the series of processes shown in FIG.

[0096] For example, in step S1005, when the newly contracted service 200 "Service A" is the source service of the link and the linked services 200 "Service B" and "Service C" are the destination services of the link, the link function enabling unit 334 notifies "Service A" so that the contracted user who made the new contract can use "Service B" and "Service C" in a linked manner from "Service A." Upon receiving this notification, "Service A" enables, for example, a function in the GUI of "Service A" provided to the contracted user who made the new contract for using "Service B" and "Service C" in a linked manner. This allows the contracted user who made the new contract to use "Service B" and "Service C" in a linked manner from the GUI of "Service A" using a terminal device such as the IWB 100.

[0097] Also, for example, in step S1005, when the newly contracted service 200 "Service A" is the linked service and the linked service 200 "Service B" is the linked service, the linked function enabling unit 334 notifies "Service B" so that the contracted user who made the new contract can use "Service A" in a linked manner from "Service B." Upon receiving this notification, "Service B" enables, for example, a function in the GUI of "Service B" provided to the contracted user who made the new contract for using "Service A" in a linked manner. As a result, the contracted user who made the new contract can use "Service A" in a linked manner from the GUI of "Service B" using a terminal device such as the IWB 100.

[0098] (Procedure for processing additional contracts) FIG. 13 is a flowchart showing the procedure of the additional contract processing by the management server 300 according to an embodiment of the present invention.

[0099] First, the contract information receiving unit 331 receives the contract information of the additional contract transmitted from the management terminal 500 via the communication network 12 (step S1101). The contract information of the additional contract includes at least a contract user ID for identifying the contract user and a service ID for identifying the service 200 for which the additional contract has been made. Note that if additional contracts have been made for multiple services 200, the contract information of the additional contract includes the service IDs of each of the multiple services 200.

[0100] Next, the service activation unit 332 activates the service 200 for which the additional contract has been made for the contract user who made the additional contract, based on the contract information of the additional contract received in step S1101 (step S1102). Specifically, the service activation unit 332 sets "valid" in the contract information DB 321 for the combination of the contract user ID of the contract user who made the additional contract and the service ID of the service 200 for which the additional contract has been made.

[0101] Next, the interlocking service identifying unit 333 identifies services 200 that are to be interlocked with the service 200 for which an additional contract has been made (step S1103). Specifically, by referring to the interlocking definition information DB 322, the interlocking service identifying unit 333 identifies the service IDs of other services 200 that are associated with the service ID of the service 200 for which an additional contract has been made as services 200 that are to be interlocked with the service 200 for which an additional contract has been made. For example, if the service 200 for which an additional contract has been made is "Service C," the interlocking service identifying unit 333 identifies "Service A" as the service 200 to be interlocked with, based on the interlocking definition information DB 322 shown in FIG. 9.

[0102] Next, the linked function enabling unit 334 determines whether or not a service 200 that links with the service 200 for which an additional contract has been made in step S1103 has been identified (step S1104).

[0103] If it is determined in step S1104 that the linked service 200 has not been identified (step S1104: No), the management server 300 ends the series of processes shown in FIG.

[0104] On the other hand, if it is determined in step S1104 that a linked service 200 has been identified (step S1104: Yes), the linking function activation unit 334 notifies the linking service 200, which is the source of the link, of the service 200 for which an additional contract has been made and the linked service 200, that it can use the linked service 200 (step S1105).

[0105] For example, in step S1105, when the service 200 for which an additional contract has been made, "Service C," is the linked service and the linked service 200, "Service A," is the linked service, the linked function enabling unit 334 notifies "Service A" so that the contracted user who has made the additional contract can use "Service C" in a linked manner from "Service A." Upon receiving this notification, "Service A" enables, for example, a function in the GUI of "Service A" provided to the contracted user who has made the additional contract for using "Service C" in a linked manner. This allows the contracted user who has made the additional contract to use "Service C" in a linked manner from the GUI of "Service A" using a terminal device such as the IWB 100.

[0106] Thereafter, the contracted user notification unit 335 notifies the contracted user that the linkage destination service can now be used from the linkage source service (step S1106). Then, the management server 300 ends the series of processes shown in FIG.

[0107] For example, in step S1106, when "Service C" is added to the contract and thus "Service A" can be used in conjunction with "Service C," the contract user notification unit 335 sends a message such as "Thank you for subscribing to Service C. The settings for linking with this service can also be found on the setting screen for Service A," to the terminal device used by the contract user who added the contract, and causes the message to be displayed on the display of the terminal device used by the contract user who added the contract. However, the method is not limited to this, and other notification methods may be used, such as sending the message to a specified email address.

[0108] (Procedure for handling contract termination) FIG. 14 is a flowchart showing the procedure of the contract cancellation process by the management server 300 according to an embodiment of the present invention.

[0109] First, the contract information receiving unit 331 receives contract information for contract cancellation transmitted from the management terminal 500 via the communication network 12 (step S1201). The contract information for contract cancellation includes at least a contract user ID for identifying the contract user and a service ID for identifying the service 200 for which the contract has been terminated. Note that if contracts for multiple services 200 have been terminated, the contract information for contract cancellation includes the service IDs of each of the multiple services 200.

[0110] Next, the interlocking service identification unit 333 identifies services 200 that are to be interlocked with the service 200 whose contract has been terminated (step S1202). Specifically, by referring to the interlocking definition information DB 322, the interlocking service identification unit 333 identifies the service IDs of other services 200 that are associated with the service ID of the service 200 whose contract has been terminated as services 200 that are to be interlocked with the service 200 whose contract has been terminated. For example, if the service 200 whose contract has been terminated is "Service B," the interlocking service identification unit 333 identifies "Service A" as the service 200 to be interlocked with, based on the interlocking definition information DB 322 shown in FIG. 9.

[0111] Next, the linked function activation unit 334 determines whether or not a service 200 linked to the service 200 for which the contract was terminated in step S1202 has been identified (step S1203).

[0112] If it is determined in step S1203 that a linked service 200 has not been identified (step S1203: No), the service activation unit 332 disables the service 200 whose contract has been terminated for the contracted user who terminated the contract, based on the contract information for contract termination received in step S1201 (step S1208). Specifically, the service activation unit 332 sets "invalid" in the contract information DB 321 for the combination of the contracted user ID of the contracted user who terminated the contract and the service ID of the service 200 whose contract has been terminated. Thereafter, the management server 300 ends the series of processes shown in FIG. 14.

[0113] On the other hand, if it is determined in step S1203 that the linked service 200 has been identified (step S1203: Yes), the service activation unit 332 refers to the linked usage information DB 323 to determine whether the link between the service 200 whose contract has been terminated and the linked service 200 is actually being used by the contracted user who terminated the contract (step S1204).

[0114] In step S1204, if it is determined that the cooperation between the service 200 whose contract has been terminated and the cooperative service 200 is actually being used by the contract user who terminated the contract (step S1204: Yes), the contract user confirmation unit 336 confirms with the contract user whether or not it is OK to disable the service 200 whose contract has been terminated (step S1205). For example, if the contract for "Service B" is terminated and therefore "Service A" cannot use "Service B" in cooperation with "Service B," the contract user confirmation unit 336 transmits a message such as "You will no longer be able to use functions on Service A that can be cooperated with Service B. Do you really want to cancel?" to the terminal device used by the contract user, and causes the message to be displayed on the display of the terminal device used by the contract user.

[0115] Then, the contracted user confirmation unit 336 determines whether or not to invalidate the service 200 whose contract has been terminated, based on the result of confirmation with the contracted user in step S1205 (step S1206).

[0116] If it is determined in step S1204 that the link between the terminated service 200 and the linked service 200 is not actually used by the contracted user who terminated the contract (step S1204: No), or if it is determined in step S1206 that the terminated service 200 should be disabled (step S1206: Yes), the link function activation unit 334 notifies the services 200 that link with the terminated service 200 to disable their link with the terminated service 200 (step S1207). Then, the service activation unit 332 disables the terminated service 200 for the terminated contracted user (step S1208). Specifically, the service activation unit 332 deletes the association between the contracted user ID of the terminated contracted user and the service ID of the terminated service 200 from the contract information DB 321. The management server 300 then terminates the series of processes illustrated in FIG. 14 .

[0117] On the other hand, if it is determined in step S1206 that the service 200 for which the contract has been terminated should not be invalidated (step S1206: No), the management server 300 ends the series of processes shown in Fig. 14. In this case, since the contracted user does not want the linkage of the service 200 to be invalidated, the contract termination of the service 200 is canceled or put on hold.

[0118] (Example of the display screen when signing up for additional service 200) 15 to 17 are diagrams showing examples of display screens displayed on the management terminal 500 according to an embodiment of the present invention when making an additional contract for the service 200. FIG.

[0119] A display screen 1300 shown in FIGS. 15 to 17 is a display screen displayed on the display of the management terminal 500. This display screen 1300 is a display screen of an application that manages a contract for a service 200 of a certain contract user A. This display screen 1300 becomes available from the management terminal 500 when the contract manager 16, who manages the contract, logs in to the management server 300 from the management terminal 500. From this display screen 1300, the contract manager 16 can check the currently contracted services 200 for contract user A, check the uncontracted services 200, sign an additional contract for a service 200, cancel the contract for a service 200, and the like. As shown in FIG. 15, the display screen 1300 includes a check box 1301 and a check box 1302.

[0120] The check box 1301 is displayed with the text "Deployed" attached. When the check box 1301 is selected by the contract manager 16, a list of the services 200 for which the contract user A has a contract, out of the services 200 provided by the cloud system 14, is displayed on the display screen 1300 based on the contract information of the contract user A set in the contract information DB 321 of the management server 300.

[0121] The check box 1302 is displayed with the text "Not Deployed." When the check box 1302 is selected by the contract manager 16, the display screen 1300 displays a list of multiple services 200 for which the contract user A has not yet signed up, out of the multiple services 200 provided by the cloud system 14, based on the contract information of the contract user A set in the contract information DB 321 of the management server 300.

[0122] The contract manager 16 can make an additional contract for a service 200 from this display screen 1300. For example, in the example shown in FIGS. 15 and 16, the display screen 1300 displays three services 200, "Service B," "Service D," and "Service E," for which contract user A has not yet made a contract. On the display screen 1300, an install button 1303 labeled "Install" is provided for each service 200. Note that the two services 200, "Service A" and "Service C," that are not displayed on the display screen 1300 are services 200 for which contract user A has an existing contract. For example, the contract manager 16 can make an additional contract for "Service B" by pressing the install button 1303 for "Service B," as shown in FIG. 16.

[0123] At this time, contract information relating to the additional contract for "Service B" is sent to the management server 300. Upon receiving this contract information, the management server 300 performs the additional contract processing already explained, and adds "Service B" to the contract user ID of contract user A in the contract information DB 321, thereby enabling contract user A to use "Service B." This allows contract user A to use the three services 200, "Service A," "Service B," and "Service C."

[0124] As already explained, "Service B" can be used in conjunction with "Service A." Therefore, the management server 300 sends a message to the management terminal 500, such as, "Thank you for subscribing to Service B. The settings for linking with Service B are also available on the settings screen for Service A. Please make use of this." The management terminal 500 can notify the contract manager 16 of this message by displaying the message on a pop-up screen 1310, as shown in FIG. 17.

[0125] (Example of a display screen when canceling a contract for service 200) 18 to 21 are diagrams showing examples of display screens displayed on the management terminal 500 according to one embodiment of the present invention when canceling the contract for the service 200. FIG.

[0126] In the example shown in Fig. 18, a check box 1301 is selected by the contract manager 16 on a display screen 1300 similar to those in Figs. 15 to 17. As a result, a list of three services 200, "Service A," "Service B," and "Service C," for which contract user A has subscribed, is displayed on the display screen 1300. On the display screen 1300 shown in Fig. 18, instead of the install button 1303 shown in Figs. 15 to 17, an invalid button 1304 labeled "Installed" is displayed for each service 200, indicating that the service has already been subscribed to.

[0127] 18, a drop-down button 1305 is displayed for each service 200. By selecting the drop-down button 1305 for any service 200 on the display screen 1300, the contract manager 16 can display a drop-down list 1306 and select any action from the drop-down list 1306.

[0128] 19, the contract manager 16 selects the drop-down button 1305 for "Service B" on the display screen 1300, causing a drop-down list 1306 for "Service B" to be displayed. The contract manager 16 then selects the action indicated as "Go to application" in this drop-down list 1306. As a result, a service details screen 1800 showing the detailed content of "Service B" is displayed on the display of the management terminal 500, as shown in FIG.

[0129] The contract manager 16 can cancel the contract for "Service B" from this service details screen 1800. Specifically, as shown in FIG. 20, the service details screen 1800 displays a link 1801 labeled "uninstall." The contract manager 16 can cancel the contract for "Service B" by clicking this link 1801. At this time, contract information related to the contract cancellation for "Service B" is sent to the management server 300.

[0130] As already explained, "Service B" can be used in conjunction with "Service A." Therefore, the management server 300 sends a message to the management terminal 500, such as, "You will no longer be able to use functions on Service A that can be used in conjunction with Service B. Do you really want to cancel this?" The management terminal 500 can notify the contract manager 16 of this message by displaying the message on a pop-up screen 1810, as shown in FIG. 21.

[0131] 21, a cancel button 1811 and an OK button 1812 are displayed on the pop-up screen 1810. The contract manager 16 can cancel the contract cancellation for "Service B" by selecting the cancel button 1811. On the other hand, the contract manager 16 can confirm the contract cancellation for "Service B" by selecting the OK button 1812. The cancellation or confirmation of the contract cancellation for "Service B" is then notified to the management server 300 from the management terminal 500.

[0132] When the management server 300 receives the notification of cancellation of the contract termination for "Service B," it performs the contract termination process described above and deletes "Service B" associated with the contract user ID of contract user A from the contract information DB 321, thereby invalidating contract user A's use of "Service B." As a result, contract user A becomes able to use the remaining two services 200, "Service A" and "Service C."

[0133] (First specific example of the cooperation function of the service 200) 22 and 23 are diagrams showing a first specific example of the linking function of the service 200 provided to a contracted user. A display screen 2000 shown in FIGS. 22 and 23 is a display screen displayed on the display of a terminal device (for example, a PC, a tablet terminal, a smartphone, etc.) used by a contracted user A. This display screen 2000 is a workflow creation screen provided by a workflow service (an example of the above-mentioned "Service A"). Contracted user A can create a workflow from this display screen 2000.

[0134] Fig. 22 shows a display screen 2000 before contracting with "Service B" and "Service C" by contract user A. On the other hand, Fig. 23 shows a display screen 2000 after contracting with "Service B" and "Service C" by contract user A.

[0135] In the display screen 2000 shown in FIG. 23, the link function with "Service B" and "Service C" has been enabled, and therefore distribution buttons 2002 and 2004 for using the link function with "Service B" and "Service C" are displayed.

[0136] For example, contracted user A can distribute the workflow created on display screen 2000 to "Service B" by selecting distribution button 2002. Also, for example, contracted user A can distribute the workflow created on display screen 2000 to "Service C" by selecting distribution button 2004.

[0137] 23 illustrates an example in which user authority for each of "Service B" and "Service C" is granted to a login user managed by contract user A in user authority information DB 325. For example, even if contract user A can use "Service B" and "Service C" (i.e., has signed a contract), if user authority for either "Service B" or "Service C" is not granted to the login user managed by contract user A, either of delivery buttons 2002 and 2004 will not be displayed on display screen 2000 used by the login user.

[0138] (Second specific example of the cooperation function of the service 200) 24 and 25 are diagrams showing a second specific example of the linking function of the service 200 provided to the contracted users. 24 and 25 show an example of a display on the display 180 of the electronic whiteboard 100 when a contracted user A uses a certain service (an example of the above-mentioned "Service A") from the electronic whiteboard 100. The contracted user A can write any content on the display 180.

[0139] Fig. 24 shows an example of the display before contract user A enters into a contract with "Service B" and "Service C." On the other hand, Fig. 25 shows an example of the display after contract user A enters into a contract with "Service B" and "Service C." Here, "Service B" is a print service that can be used in conjunction with "Service A," and "Service C" is a workflow service that can be used in conjunction with "Service A."

[0140] On the display 180 shown in FIG. 25, the collaboration function with "Service B" (print service) and "Service C" (workflow service) has been enabled, and therefore a print button 2302 and a review request button 2304 are displayed for utilizing the collaboration function with "Service B" and "Service C."

[0141] For example, contracted user A can distribute the display content of display 180 to "Service B" (print service) and print it by selecting print button 2302. Also, for example, contracted user A can distribute the display content of display 180 to "Service C" (workflow service) and request an examination by selecting review request button 2304.

[0142] 25 illustrates an example in which user authority for each of "Service B" and "Service C" is granted to a login user managed by contract user A in user authority information DB 325. For example, even if contract user A can use "Service B" and "Service C" (i.e., has signed a contract), if user authority for either "Service B" or "Service C" is not granted to the login user managed by contract user A, either the print button 2302 or the review request button 2304 will not be displayed on display screen 2000 used by the login user.

[0143] (Procedure for user authentication processing by information processing system 10) FIG. 26 is a sequence diagram showing the procedure of user authentication processing by the information processing system 10 according to one embodiment of the present invention.

[0144] First, a terminal device such as the IWB 100 or the MFP 900 accepts input of login information from a login user managed by a contract user (step S2401). For example, the login information includes a user ID and a password. The terminal device transmits the input login information to the management server 300 via the communication network 12 (step S2402).

[0145] In the management server 300, the user authentication unit 340 acquires the login information sent from the terminal device (step S2403), and performs authentication processing of the logged-in user based on the login information and the user information DB 324 provided in the management server 300 (step S2404).

[0146] If the authentication process for the logged-in user is successful, the user authentication unit 340 transmits a user authentication process result indicating that the authentication process for the logged-in user was successful to the terminal device (step S2405). Upon receiving the authentication process result for the logged-in user (step S2406), the terminal device notifies the logged-in user that the login was successful (step S2407). In this case, the management server 300 proceeds to step S2408.

[0147] On the other hand, although not shown, if the authentication process for the login user fails in step S2404, the user authentication unit 340 transmits a user authentication process result indicating that the authentication process for the login user has failed to the terminal device (step S2405). Upon receiving the authentication process result for the login user (step S2406), the terminal device notifies the login user that the login has failed (step S2407). In this case, the management server 300 does not proceed to step S2408 and ends the series of processes.

[0148] In step S2408, the user-specific collaboration function control unit 341 of the management server 300 refers to the contract information DB 321 to identify the services 200 (i.e., the services 200 under contract) that can be used by the contracted user to which the login user who successfully logged in belongs.

[0149] Then, the user-specific cooperative function control unit 341 refers to the user authority information DB 325 to confirm the authority to use the service 200 identified in step S2408 by the login user who has successfully logged in (step S2409).

[0150] Here, if a contracted user to which the logged-in user belongs has subscribed to multiple services 200, the user authentication unit 340 checks the login user's usage authority for each of the multiple subscribed services 200. For example, if the user ID of the logged-in user who successfully logged in is "User1," the contracted user ID of the contracted user to which the logged-in user belongs is "Company1." Therefore, the user authentication unit 340 checks whether the logged-in user has usage authority for each of the services "ServiceA," "ServiceB," and "ServiceC" subscribed to by "Company1" by referring to the user authority information DB 325. For example, according to the user authority information DB 325 illustrated in FIG. 10, the logged-in user with the user ID "User1" has usage authority for all of the services "ServiceA," "ServiceB," and "ServiceC."

[0151] Then, the user authentication unit 340 of the management server 300 transmits the user authentication processing result indicating that the authentication processing of the logged-in user was successful and the confirmation result of the usage authority of the service 200, together with the user ID of the logged-in user, to the service 200 under contract with the contracted user to which the logged-in user belongs (step S2410). Here, if the contracted user to which the logged-in user belongs has contracted with multiple services 200, the user authentication unit 340 transmits the user authentication processing result and the confirmation result of the usage authority of the service to each of the multiple services 200. For example, if the user ID of the logged-in user is "User1", the user authentication unit 340 transmits the user authentication processing result and the confirmation result of the usage authority of the service to each of the services "ServiceA", "ServiceB", and "ServiceC".

[0152] When the service 200 receives the user authentication processing result and the service usage authority confirmation result (step S2411), if the received service usage authority confirmation result indicates that the user has authority to use its own service 200, it enables use of its own service 200 for the user ID included in the received user authentication processing result (i.e., the logged-in user who successfully logged in) (step S2412).

[0153] Furthermore, if the received service usage authority confirmation result indicates that the user does not have the authority to use the linked service 200, the service 200 disables the use of the linkage function to the linked service 200 for the user ID included in the received user authentication processing result (i.e., the user who successfully logged in) (step S2413).

[0154] For example, if the user ID of the logged-in user is "User3", the own service 200 is "ServiceA", and the linked services are "ServiceB" and "ServiceC", a user with the user ID "User3" has the authority to use "ServiceC" but does not have the authority to use "ServiceB" (see Figure 10), and therefore the own service 200 ("ServiceA") disables the logged-in user's ("User3") use of the linking function from the own service 200 ("ServiceA") to "ServiceB".

[0155] Thereafter, when the terminal device transmits a usage request to the service 200 in response to an operation by the logged-in user (step S2414), the service 200 determines whether or not its own service 200 is available based on the user ID included in the usage request transmitted from the terminal device, and if it determines that its own service 200 is available, provides its own service 200 to the terminal device (step S2415). This allows the logged-in user to use the service 200 from the terminal device (step S2416).

[0156] For example, the service 200 may determine whether or not the logged-in user is allowed to use the service 200 by making an inquiry to the management server 300. Alternatively, the service 200 may hold synchronization information synchronized with the contract information DB 321, and determine whether or not the logged-in user is allowed to use the service 200 based on the synchronization information.

[0157] Note that Figure 26 shows a case where service 200 determines that "the logged-in user can use its own service 200," but if service 200 determines that "the logged-in user cannot use its own service 200," it does not provide its own service 200 to the terminal device and notifies the terminal device that its own service 200 cannot be used.

[0158] The user authentication process may be performed by the service 200 when a contracted user uses the service 200 from a terminal device. In this case, the service 200 may hold synchronization information synchronized with the user information DB 324, and perform the user authentication process based on the synchronization information.

[0159] Furthermore, the service 200 may hold synchronization information synchronized with the user authority information DB 325, and enable or disable the linking function of the service for each logged-in user based on the synchronization information.

[0160] As described above, the management server 300 according to one embodiment of the present invention includes a collaboration function activation unit 334 that activates the collaboration function from the collaboration source service 200 to the collaboration destination service 200 when the contracted user can use both the collaboration source service 200 and the collaboration destination service 200, and a user-specific collaboration function control unit 341 that disables the use of the collaboration function by the logged-in user when the logged-in user managed by the contracted user does not have the authority to use the collaboration destination service 200.

[0161] As a result, the management server 300 according to an embodiment can disable the coordination function from the coordination source service 200 to the coordination destination service 200 if the contracted user does not have the authorization to use the coordination destination service 200, even if the contracted user is contractually entitled to use both the coordination source service 200 and the coordination destination service 200. As a result, the management server 300 according to an embodiment can prevent problems such as an error message being displayed when a logged-in user attempts to use a coordination destination service 200 that the logged-in user does not have the authorization to use. Therefore, according to the management server 300 according to an embodiment, when a logged-in user uses a service, if there is another service that can be coordinated with that service, the management server 300 can appropriately control the logged-in user's use of the coordination function with the other service.

[0162] Although the preferred embodiments of the present invention have been described in detail above, the present invention is not limited to these embodiments, and various modifications and changes are possible within the scope of the gist of the present invention described in the claims.

[0163] The devices described in the example are merely one of several computing environments for implementing the embodiments disclosed herein. In one embodiment, management server 300 includes multiple computing devices, such as a server cluster, configured to communicate with each other via any type of communication link, including a network, shared memory, etc., and to perform the processes disclosed herein.

[0164] The "information processing device" is not limited to a server, as long as it has the functions of the above-described embodiments. The "information processing device" may be, for example, a PJ (Projector), an IWB (Interactive White Board: a white board with an electronic blackboard function that allows mutual communication), an output device such as digital signage, a HUD (Head Up Display) device, industrial machinery, an imaging device, a sound collection device, a medical device, a network home appliance, an automobile (Connected Car), a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game console, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, a desktop PC, or the like.

[0165] In the above embodiment, the "information processing system" is constructed using a cloud system, but the present invention is not limited to this and the "information processing system" may be constructed using other systems constructed on a communication network. For example, the "information processing system" may be constructed using an on-premise system. [Explanation of symbols]

[0166] 10 Information Processing Systems 12. Communication Networks 14 Cloud Systems 16 Contract Manager 20 Integrated Service Delivery System 100 Electronic Whiteboard 200 Services 200A Resource Management Services 200B Reporting Services 200C Radio Management Service 200D Document Management Services 200E Print Service 200F Workflow Services 300 Management server (information processing device) 320 Storage section 321 Contract Information DB 322 Linkage definition information DB 323 Collaborative Use Information DB 324 User Information DB 325 User authority information DB 331 Contract Information Receiving Department 332 Service Enablement Department 333 Collaborative Service Specific Department 334 Collaboration Function Activation Unit 335 Contract User Notification Department 336 Contract User Verification Department 340 User authentication section 341 User-specific linkage function control unit 400 smartphones 500 Management terminal 700 video conferencing terminals 900 MFP [Prior art documents] [Patent documents]

[0167] [Patent Document 1] Patent No. 645188

Claims

1. An information processing device that manages a user's authorization to use a first service and an authorization to use a second service, comprising: The information processing device includes: referencing user authority information that manages the user's authority to use the first service and the second service, and determining whether or not the login user who has successfully logged in has authority to use the first service and whether or not the login user has authority to use the second service; when it is determined that the login user has the authority to use the first service and the authority to use the second service, a first GUI component for using the second service is displayed on a display screen of the first service that is displayed when the login user uses the first service; When it is determined that the login user has the authority to use the first service but does not have the authority to use the second service, the first GUI component for using the second service is not displayed on a display screen of the first service that is displayed when the login user uses the first service.

1. An information processing device comprising:

2. The usage rights of the first service and the usage rights of the second service managed by the user permission information can be changed by an administrator who manages the user permission information.

2. The information processing apparatus according to claim 1, wherein:

3. The user authority information further manages the user's authority to use a third service, when it is determined that the login user has the authority to use the first service and the authority to use the third service, a second GUI component for using the third service is displayed on a display screen of the first service that is displayed when the login user uses the first service; when it is determined that the login user has the authority to use the first service but does not have the authority to use the third service, the second GUI component for using the third service is not displayed on a display screen of the first service that is displayed when the login user uses the first service; 2. The information processing apparatus according to claim 1, wherein:

4. An information processing method for managing a user's authorization to use a first service and an authorization to use a second service, comprising: The information processing method includes: referencing user authority information that manages the user's authority to use the first service and the second service, and determining whether or not the login user who has successfully logged in has authority to use the first service and whether or not the login user has authority to use the second service; when it is determined that the login user has the authority to use the first service and the authority to use the second service, a first GUI component for using the second service is displayed on a display screen of the first service that is displayed when the login user uses the first service; When it is determined that the login user has the authority to use the first service but does not have the authority to use the second service, the first GUI component for using the second service is not displayed on a display screen of the first service that is displayed when the login user uses the first service.

1. An information processing method comprising:

5. A program that causes a computer to manage a user's authorization to use a first service and a user's authorization to use a second service, The program The computer referencing user authority information that manages the user's authority to use the first service and the second service, and determining whether or not the login user who has successfully logged in has authority to use the first service and whether or not the login user has authority to use the second service; when it is determined that the login user has the authority to use the first service and the authority to use the second service, a first GUI component for using the second service is displayed on a display screen of the first service that is displayed when the login user uses the first service; When it is determined that the login user has the authority to use the first service but does not have the authority to use the second service, the first GUI component for using the second service is not displayed on a display screen of the first service that is displayed when the login user uses the first service. A program that makes it work like this.