Management device, management system, management method, and program
The management device automates data transfer approvals by providing transfer history and confidential information identification, reducing approver workload and minimizing information leaks.
Patent Information
- Application Number
- JP2024036512
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-11
- Publication Date
- 2025-09-25
AI Technical Summary
The workload of approvers increases as the number of data transfer approval requests grows, necessitating careful checks to prevent information leaks.
A management device and method that includes an application receiving unit, transfer history identification, confidential information identification, and approval request generation to automate the approval process, reducing the workload by providing transfer history and confidential information identification results to approvers.
Reduces the workload of approvers by automating the approval process, ensuring efficient data transfer while minimizing the risk of information leaks through automated transfer history and confidential information identification.
Smart Images

Figure 2025137974000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a management device, a management system, a management method, and a program. [Background technology]
[0002] Generally, from the perspective of ensuring security and preventing information leaks, data used in a closed environment such as an organization cannot be transferred to an external environment. Transfer includes both taking out and bringing in data. Taking out is transferring data from a closed environment such as an organization to an external environment. Bringing in is transferring data from a closed environment to an external environment.
[0003] However, there are cases where data transfer is necessary for business reasons. Patent Document 1 discloses a technology for enabling data to be taken out while preventing information leaks in such cases. When a user requests approval to take out a file, the information processing system in Patent Document 1 displays an approval management screen including information on the file name and takeout destination on an administrator terminal. An approver operating the administrator terminal checks the approval management screen and approves or denies the approval request. If the approval request is approved, the information processing system performs processing for data takeout. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-037465 Summary of the Invention [Problem to be solved by the invention]
[0005] In the information processing system of Patent Document 1, the approver needs to carefully check the data for which approval is requested in order to ensure security and prevent information leaks, etc. As the number of approval requests increases, the workload of the approver increases.
[0006] An object of the present disclosure is to provide a management device, a management system, a management method, and a program that can reduce the workload of an approver. [Means for solving the problem]
[0007] A management device of one embodiment of the present disclosure includes an application receiving unit that receives input of an approval application requesting the transfer of transfer-desired data, a transfer history identification unit that uses transfer management information that includes a transfer history of transfer data that has been transferred in the past to identify whether or not there is a transfer history of the transfer-desired data, a confidential information identification unit that identifies whether or not confidential information is included in the transfer-desired data, an approval request generation unit that generates an approval request that includes the approval application, the transfer history identification result, and the confidential information identification result, and a transmission unit that transmits the approval request to an approval terminal operated by an approver.
[0008] In one aspect of the management method disclosed herein, a computer accepts input of an approval request for the transfer of data to be transferred, uses transfer management information containing a transfer history of data that has been transferred in the past, identifies whether there is a transfer history of the data to be transferred, identifies whether the data to be transferred contains confidential information, generates an approval request that includes the approval request, the results of identifying the transfer history, and the results of identifying the confidential information, and transmits the approval request to an approval terminal operated by an approver.
[0009] A program according to one embodiment of the present disclosure causes a computer to perform the following processes: accepting input of an approval request for the transfer of data to be transferred; determining whether or not there is a transfer history of the data to be transferred using transfer management information that includes the transfer history of data that has been transferred in the past; determining whether or not confidential information is included in the data to be transferred; generating an approval request that includes the approval request, the results of identifying the transfer history, and the results of identifying the confidential information; and transmitting the approval request to an approval terminal operated by an approver. [Effects of the Invention]
[0010] According to the present disclosure, it is possible to provide a management device, a management system, a management method, and a program that can reduce the workload of an approver who approves an approval request. [Brief explanation of the drawings]
[0011] [Figure 1] FIG. 1 is a conceptual diagram illustrating a management system according to the present disclosure. [Figure 2] FIG. 2 is a block diagram illustrating an example of a configuration of a management device according to the present disclosure. [Figure 3] FIG. 10 is a diagram illustrating an example of an approval application screen according to the present disclosure. [Figure 4] FIG. 2 is a diagram illustrating an example of a data configuration of transfer management information in the present disclosure. [Figure 5] FIG. 10 is a diagram illustrating an example of masked transfer request data in the present disclosure. [Figure 6] FIG. 10 is a diagram illustrating an example of an approval request in the present disclosure. [Figure 7] FIG. 10 is a diagram illustrating an example of confirmation data in the present disclosure. [Figure 8] 10 is a block diagram illustrating an example of the configuration of an approval / rejection receiving unit in the present disclosure. FIG. [Figure 9] FIG. 10 is a diagram showing an example of an approval request screen displayed on a screen of an approval terminal in the present disclosure. [Figure 10] 10 is a flowchart illustrating an example of an operation of a management device according to the present disclosure. [Figure 11] 10 is a flowchart illustrating an example of an operation of a management device according to the present disclosure. [Figure 12] FIG. 2 is a block diagram illustrating an example of a configuration of a management device according to the present disclosure. [Figure 13] 10 is a flowchart illustrating an example of an operation of a management device according to the present disclosure. [Figure 14] FIG. 2 is a block diagram showing an example of a hardware configuration for executing control and processing in each embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings. The embodiments described below are limited in a manner that is technically preferable for implementing the present disclosure, but the scope of the invention is not limited to the following. In all drawings used to describe the following embodiments, the same reference numerals are used for similar parts unless otherwise specified. In the following embodiments, repeated explanations of similar configurations and operations may be omitted. Furthermore, the UI (User Interface) shown in the drawings is an example and may be replaced with another UI.
[0013] (First embodiment) First, a management system according to a first embodiment will be described with reference to the drawings.
[0014] FIG. 1 is a conceptual diagram illustrating a management system according to the present disclosure. As shown in FIG. 1, the management system 1 includes a management device 10 and an information processing terminal 80. The management system 1 may also include an approval terminal 70. The management device 10 is communicatively connected to the information processing terminal 80, the application terminal 60, and the approval terminal 70. The management device 10, the application terminal 60, and the approval terminal 70 are implemented by information processing devices such as a server, a stationary terminal device, a laptop terminal device, or a portable terminal device. The information processing terminal 80 is implemented by a cloud server, an on-premise server, or the like. The information processing terminal 80 includes a storage unit such as cloud storage or on-premise storage. The information processing terminal 80 is communicatively connected to the application terminal 60.
[0015] The application terminal 60 is an information processing device for transmitting an approval request for data transfer. The application terminal 60 is operated by an applicant who makes an approval request. The application terminal 60 transmits the approval request input by the applicant to the management device 10.
[0016] The management device 10 is an information processing device that requests approval from the approval terminal 70 and transfers the approved data to the information processing terminal 80. When the management device 10 receives an approval request from the application terminal 60, it generates an approval request. The management device 10 transmits the generated approval request to the approval terminal 70. The management device 10 receives input of approval approval information from the approval terminal 70, which is information indicating whether the approval request is approved. When the management device 10 receives input from the approval terminal 70 indicating that the approval request is approved, it transfers the data for which approval is requested to the information processing terminal 80. The management device 10 notifies the application terminal 60 that the data has been transferred or that approval has been denied. The management device 10 also stores transfer management information, which is a table for managing the history of data transfers. When the management device 10 transfers data to the information processing terminal 80, it adds a new entry to the table of transfer management information.
[0017] The information processing terminal 80 stores in a storage unit the data received from the management device 10. When the applicant receives a notification that the data has been transferred, the applicant accesses the information stored in the information processing terminal 80 from the application terminal 60 or another information processing terminal.
[0018] (composition) 2 is a diagram illustrating an example of the configuration of a management device according to the present disclosure. The management device 10 includes an application receiving unit 101, a transfer history identifying unit 102, a secret information identifying unit 103, a masking unit 104, an approval request generating unit 105, an approval / rejection receiving unit 106, a transferring unit 107, an updating unit 108, a storage unit 109, and a notification unit 110.
[0019] The application receiving unit 101 receives an input of an approval request from the application terminal 60. The application receiving unit 101 displays a GUI requesting input of the approval request on a display unit (not shown) of the application terminal 60. The application receiving unit 101 acquires the items input by the application terminal 60 as an approval request.
[0020] 3 is a diagram showing an example of an approval request screen in the present disclosure. The approval request screen is an example of a UI that requests input of an approval request. The approval request screen 200 includes components 201 to 207 for inputting information required for the application. Components 201 to 207 are examples, and the approval request screen 200 may include other components. Furthermore, the approval request screen does not need to include all of components 201 to 207.
[0021] Component 201 is a text box for entering the applicant's identification information. The applicant's identification information is information that can uniquely identify the applicant, such as the applicant's name, employee number, or personal identification number. Component 202 is a drop-down list for selecting an approver. Component 203 is a drop-down list for selecting a transfer type. The transfer type is a type of data transfer. Transfer types include "take-out" and "take-in." Component 204 is a drop-down list for selecting data to be transferred. For example, the drop-down list of data to be transferred includes a list of identification information for data stored in the memory unit (not shown) of the application terminal 60. In the example of FIG. 3, a list of file names is displayed as the identification information, but this is not limited to this. The data to be transferred may also be data stored in a storage device other than the storage unit of the application terminal 60. For example, data stored in another storage device can be registered by pressing the "Register" button included in component 204. Component 205 is a text box for entering the desired transfer destination of the data. The internet address, file server address, file path, etc. of the transfer destination are entered in the text boxes of component 205. Component 206 is a text box for the applicant to specify the date and time when the applicant wishes the transfer to occur. Component 207 is a text box for the applicant to specify the date and time when the applicant wishes the data to be transferred to be deleted, i.e., the date and time when the applicant wishes the data to be destroyed.
[0022] The approval request screen 200 includes a button B1 for making a citation request. When the button B1 is pressed on the approval request screen 200, a screen containing a list of approval requests submitted in the past is displayed. When the approval request to be quoted is selected from the screen containing the list of approval requests, the items entered at the time of the previous approval request, i.e., the items entered via parts 201 to 207 at the time of the previous approval request, are automatically entered. When a citation request is not being submitted, the button B1 may be omitted.
[0023] When the application terminal 60 detects that the input has been completed, it transmits the input information to the management device 10. For example, the application terminal 60 detects that the user's input has been completed when button B2 is pressed on the approval application screen 200. The application receiving unit 101 acquires the information received from the application terminal 60 as an approval application.
[0024] The transfer history identifying unit 102 uses the transfer management information stored in the storage unit 109 to identify whether or not there is a transfer history of the data to be transferred.
[0025] The transfer management information is a table for managing the transfer history of previously transferred transfer data. FIG. 4 is a diagram showing an example of the data configuration of the transfer management information in the present disclosure. The transfer management information 220 is configured to associate the applicant's identification information (applicant's name), transfer type, approver's name, data identification information (file name), transfer destination, number of transfers, transfer date and time, and deletion date and time. The transfer management information 220 is an example and may include information other than the information described above. Furthermore, the transfer management information 220 does not need to include all of the information described above. For example, the transfer management information 220 does not need to include the transfer destination or number of transfers. The transfer management information is updated each time transfer request data is sent to the information processing terminal 80. The update of the transfer management information will be described later.
[0026] The transfer history identification unit 102 searches the transfer management information using the identification information of the data to be transferred that is included in the approval request. If the transfer management information contains an entry for the data to be transferred, the transfer history identification unit 102 determines that there is a transfer history for the data to be transferred. If the transfer management information does not contain an entry for the data to be transferred, the transfer history identification unit 102 determines that there is no transfer history for the data to be transferred.
[0027] The confidential information identification unit 103 identifies whether the transfer request data for which approval has been requested contains confidential information. Confidential information is information that is prohibited from being used outside a closed environment such as a workplace. Confidential information may also be information that is not recommended for use outside a closed environment. For example, confidential information includes personal information, confidential information, contract information, customer information, etc.
[0028] The secret information identification unit 103 identifies whether or not the transfer request data contains secret information. For example, the secret information identification unit 103 identifies secret information by analyzing text information contained in the transfer request data using natural language processing. For example, the secret information identification unit 103 may identify secret information by inputting the transfer request data into a machine-learned trained model. The secret information identification unit 103 may also identify a location where the secret information is included. For example, if the transfer request data is document data, the location is the page number or line number where the secret information is included in the document.
[0029] When the secret information identification unit 103 identifies that the transfer request data contains secret information, it identifies whether all information contained in the transfer request data is secret information. In other words, the secret information identification unit 103 identifies whether the transfer request data contains information other than secret information. If all information contained in the transfer request data is secret information, the approval request is rejected. In other words, if the transfer request data does not contain information other than secret information, the approval request is rejected. If the transfer history identification unit 102 identifies that the transfer request data has a transfer history, the secret information identification unit 103 does not need to identify whether secret information is contained.
[0030] The masking unit 104 masks confidential information included in the transfer request data. Fig. 5 is a diagram showing an example of masked transfer request data in the present disclosure. For example, the masking unit 104 masks the confidential information included in the transfer request data by redacting the confidential information with a marker M1. The data in the portion redacted with the marker M1 is not transferred.
[0031] The approval request generation unit 105 generates an approval request including the approval application received by the application receiving unit 101 as input, the identification result of the secret information identification unit 103, and the identification result of the transfer history identification unit 102. Fig. 6 is a diagram showing an example of an approval request in the present disclosure. The approval request 210 includes information shown in areas 211 to 218 in Fig. 6.
[0032] Areas 211 to 216 are areas for displaying items included in the approval request received by the application receiving unit 101. Area 211 is an area for displaying the name of the applicant. The information displayed in area 211 is the information entered in component 201 of FIG. 3. Area 212 is an area for displaying the transfer type. The information displayed in area 212 is the information entered in component 203 of FIG. 3. Area 213 is an area for displaying the data transfer destination. The information displayed in area 213 is the information entered in component 205 of FIG. 3. Area 214 is an area for displaying the date and time at which the applicant desires the transfer. The information displayed in area 214 is the information entered in component 206 of FIG. 3. Area 215 is an area for displaying the date and time at which the applicant desires the data to be discarded. The information displayed in area 215 is the information entered in component 207 of FIG. 3. Area 216 is an area for displaying a component for confirming the data to be transferred. For example, when a "Confirm" button included in the area 216 is pressed using the input unit of the approval terminal 70, the transfer request data registered by the applicant is displayed.
[0033] Area 217 is an area that displays information generated using the identification result of transfer history identification unit 102. Area 217 is an area for displaying whether or not the data to be transferred has a transfer history. If there is a transfer history, area 217 may display the date and time of approval by the approver. If there are multiple transfer histories, area 217 may display only the most recent date and time of approval. Furthermore, if there are multiple transfer histories for the data to be transferred, area 217 displays a "Check History" button for displaying a list of multiple histories. If there is only a single transfer history for the data to be transferred, area 217 does not need to display a "Check History" button for displaying a list of multiple histories.
[0034] Area 218 is an area that displays information generated using the identification result of secret information identification unit 103. Area 218 includes areas 2181 and 2182. Area 2181 is an area for displaying whether or not secret information is included in the transfer request data. If the location of the secret information has been identified by secret information identification unit 103, area 2181 may also display the location of the secret information. Area 2182 is an area for displaying whether or not there is masked transfer request data. If there is masked transfer request data, area 2182 may include a component for confirming the masked transfer request data. When a confirmation button is pressed by the input unit of approval terminal 70, the transfer request data masked by masking unit 104 is displayed.
[0035] The approval request generation unit 105 may generate confirmation data that clearly indicates the confidential information included in the transfer request data. For example, the approval request generation unit 105 may generate confirmation data in which a marker is attached to the confidential information included in the transfer request data, using the position of the confidential information identified by the confidential information identification unit 103. The approval request generation unit 105 may also include the generated confirmation data in the approval request. FIG. 7 is a diagram illustrating an example of confirmation data in the present disclosure. For example, the approval request generation unit 105 generates confirmation data in which a marker M2 is superimposed on the confidential information. The approval request generation unit 105 may change the color and thickness of the marker M2 depending on the type of confidential information. For example, a red marker may be superimposed on an area containing personal information, and a yellow marker may be superimposed on an area containing confidential information. The confirmation data may be confirmed by, for example, pressing a “Confirm” button included in area 216 in FIG. 6.
[0036] The approval / rejection receiving unit 106 transmits the generated approval request to the approval terminal 70 and receives input of whether to approve the approval request. Fig. 8 is a block diagram showing an example of the configuration of the approval / rejection receiving unit 106 in the present disclosure. The approval / rejection receiving unit 106 includes a transmitting unit 1061 and a receiving unit 1062. The transmitting unit 1061 causes a display unit (not shown) of the application terminal 60 to display an approval request screen including the approval request generated by the approval request generating unit 105 and a component requesting input of whether to approve.
[0037] FIG. 9 is a diagram showing an example of an approval request screen displayed on the screen of an approval terminal according to the present disclosure. The approval request transmitted from the transmission unit 1061 is received by the approval terminal 70. The display unit of the approval terminal 70 displays an approval request screen 230 as shown in FIG. 9. The approver viewing the approval request screen 230 displayed on the display unit of the approval terminal 70 can check the approval request, the transfer history identification results, and the confidential information identification results all together. Because the approval request includes the transfer history identification results, the approver can know, when entering whether or not to approve, that the transfer-requested data is data that has been approved for transfer in the past. This reduces the approver's burden of checking the transfer-requested data with a transfer history. Furthermore, because the approval request includes the confidential information identification results, the approver can know, when entering whether or not to approve, whether or not to approve. This reduces the approver's burden of checking the transfer-requested data that does not contain confidential information. Therefore, the method of the present embodiment reduces the approver's workload when approving a request.
[0038] The approval request screen 230 includes the approval request 210. The approval request screen 230 includes buttons B3 and B4, which are components for receiving input regarding whether to approve the approval request. Button B3 is a component for receiving input for approving the approval request. Button B4 is a component for receiving input for denying the approval request.
[0039] When the approval terminal 70 detects that the input has been completed, it transmits the input information to the management device 10. For example, the approval terminal 70 detects that the user's input has been completed when button B3 or button B4 is pressed on the approval request screen 230. The receiving unit 1062 of the approval / rejection receiving unit 106 acquires the information received from the approval terminal 70 as approval / rejection information.
[0040] The transfer unit 107 transmits the approved transfer request data to the information processing terminal 80. When the transfer unit 107 receives the input of approval from the approval / non-approval receiving unit 106, the transfer unit 107 transmits the transfer request data for which approval has been requested to the information processing terminal 80. If the transfer request data has been masked by the masking unit 104, the transfer unit 107 transmits the masked transfer request data to the information processing terminal 80.
[0041] The update unit 108 updates the transfer management information stored in the storage unit 109. When the transfer unit 107 transfers data, the update unit 108 adds a new entry to the transfer management information. The update unit 108 adds the same values as those in the approval request to the transfer management information in the fields of applicant name, transfer type, approver name, file name, transfer destination, transfer date and time, and deletion date and time. The update unit 108 calculates the number of transfers as follows. The update unit 108 searches the transfer management information using the identification information of the data to be transferred as a search key. If a corresponding transfer history is found, the update unit 108 acquires the number of transfers of the data to be transferred. The update unit 108 adds 1 to the acquired number of transfers to set the number of transfers as the number of transfers. If there is no transfer history corresponding to the data to be transferred, the update unit 108 sets the number of transfers to 1. The update unit 108 adds the number of transfers calculated as described above to the transfer management information.
[0042] The storage unit 109 stores information required for processing by the management device 10. The storage unit 109 stores transfer management information and a trained model for identifying confidential information. The storage unit 109 may store information other than the above-mentioned information, such as information temporarily required for processing by the management device 10.
[0043] The notification unit 110 issues a notification to the application terminal 60. If the confidential information identification unit 103 identifies that the transfer request data contains confidential information and that all of the information in the transfer request data is confidential information, the notification unit 110 issues a notification that the approval request is rejected. Furthermore, if the notification unit 110 receives an input from the approval terminal 70 to deny the approval request, the notification unit 110 issues a notification that the approval request has been denied. For example, the notification unit 110 issues a notification by displaying an alert message on the display unit of the application terminal 60 indicating that the approval request has been rejected or denied.
[0044] (operation) Next, the operation of the management device 10 in this embodiment will be described with reference to Fig. 10 and Fig. 11. The operation of the management device is roughly divided into an approval request generation process and a transfer process. Fig. 10 and Fig. 11 are flowcharts for explaining an example of the operation of the management device 10 in the present disclosure.
[0045] [Approval request generation process] First, the approval request generation process will be described with reference to Fig. 10. First, the application receiving unit 101 receives an input of an approval request from the application terminal 60 (step S101).
[0046] Next, the transfer history identifying unit 102 identifies whether or not there is a transfer history of the transfer request data for which approval has been requested, using the transfer management information stored in the storage unit 109. The transfer history identifying unit 102 identifies whether or not there is a transfer history by searching the transfer management information using identification information of the transfer request data included in the approval request.
[0047] If there is a transfer history of the data to be transferred (Yes in step S102), the process proceeds to step S107.
[0048] If there is no transfer history of the transfer desired data (No in step S102), the confidential information identification unit 103 identifies whether or not confidential information is included in the transfer desired data for which approval has been requested (step S103).
[0049] If the transfer request data does not include confidential information (No in step S103), the process proceeds to step S107.
[0050] If the transfer request data includes confidential information (Yes in step S103), the confidential information identification unit 103 identifies whether all information included in the transfer request data is confidential information (step S104).
[0051] If all the information included in the transfer request data is confidential information (Yes in step S104), the notification unit 110 issues a notification to the effect that the approval request is rejected (step S105), and the process ends.
[0052] If all the information contained in the transfer request data is not confidential information (No in step S104), that is, if the transfer request data includes information other than confidential information, the masking unit 104 masks the confidential information in the transfer request data (step S106).
[0053] Next, the approval request generating unit 105 generates an approval request including the approval application received by the application receiving unit 101, the identification result of the secret information identifying unit 103, and the identification result of the transfer history identifying unit 102 (step S107).
[0054] Next, the transmitting unit 1061 of the approval / non-approval receiving unit 106 transmits the generated approval request to the approval terminal 70 (step S108). After completing the process of step S108, the management device 10 ends the series of approval request generation processes described above.
[0055] [Transfer Processing] Next, the transfer process will be described with reference to Fig. 11. The transfer process is a process that is performed after the approval request generation process. First, the approval possibility receiving unit 106 receives input of approval possibility information for the approval request (step S109). The receiving unit 1062 of the approval possibility receiving unit 106 receives the approval possibility information input from the approval terminal 70.
[0056] When a denial input is received from the approval terminal 70 (No in step S110), the notification unit 110 issues a notification that the approval request has been denied (step S111), and the process ends.
[0057] When the input of approval is received from the approval terminal 70 (Yes in step S110), the transfer unit 107 transmits the transfer request data (step S112).
[0058] After step S112, the update unit 108 updates the transfer management information (step S113). The update unit 108 updates the transfer management information by adding an entry related to the transfer data to the transfer management information. After completing the process of step S113, the management device 10 ends the series of transfer processes described above.
[0059] As described above, the management device of this embodiment includes an application receiving unit, a transfer history identification unit, a secret information identification unit, an approval request generation unit, and an approval / rejection receiving unit. The application receiving unit receives input of an approval request requesting the transfer of transfer-desired data. The transfer history identification unit identifies whether or not there is a transfer history of the transfer-desired data using transfer management information including the transfer history of the transfer data. The secret information identification unit identifies whether or not the transfer-desired data includes secret information. The approval request generation unit generates an approval request including the approval request, the transfer history identification result, and the secret information identification result. The transmission unit of the approval / rejection receiving unit transmits the approval request to an approval terminal operated by the person who approves the approval request.
[0060] The management device of this embodiment, having the above-described configuration, can reduce the workload of an approver who approves an approval request. The approval request transmitted to the approval terminal operated by the approver includes the approval request, the transfer history identification result, and the confidential information identification result. Because the approval request includes the transfer history identification result, the approver can know, when entering whether or not to approve, that the transfer-requested data is data that has been approved for transfer in the past. This reduces the approver's burden of checking the transfer-requested data that has a transfer history. Furthermore, because the approval request includes the confidential information identification result, the approver can know, when entering whether or not to approve, whether or not to approve. This reduces the approver's burden of checking the transfer-requested data that does not contain confidential information. In other words, the management device of this embodiment can reduce the workload of an approver who approves an approval request.
[0061] Furthermore, the management device of this embodiment, having the above-described configuration, can reduce the risk of information leakage. This is because the approval request sent to the approval terminal operated by the approver includes the result of identifying confidential information. This allows the approver to know whether the transfer request data contains information that may be at risk of information leakage when inputting whether or not to approve.
[0062] In a management device according to one aspect of this embodiment, a confidential information identification unit identifies confidential information included in the transfer request data. Furthermore, an approval request generation unit generates confirmation data in which the confidential information is explicitly stated and includes the confirmation data in the approval request. By including the confirmation data in which the confidential information is explicitly stated in the approval request, the approver can identify areas that require careful review. In other words, the management device according to one aspect of this embodiment can reduce the workload of the approver who approves approval requests.
[0063] In a management device according to one aspect of this embodiment, an approval request generation unit generates confirmation data with a marker indicating confidential information contained in the transfer request data. The approval request generation unit also includes the generated confirmation data in the approval request. This allows the approver to intuitively grasp the areas that require careful review. In other words, the management device according to one aspect of this embodiment can reduce the workload of the approver who approves approval requests.
[0064] In a management device according to an aspect of the present embodiment, the transfer management information includes the number of transfers of the same transfer data as the transfer request data and the transfer date and time of the same transfer data as the transfer request data. Furthermore, the approval request generation unit generates an approval request including at least one of the number of transfers of the same transfer data as the transfer request data or the transfer date and time of the same transfer data as the transfer request data. By including the number of transfers in the approval request, the approver can confirm the purpose of the transfer with the applicant if the number of transfers of the transfer request data is abnormally high. This prevents unnecessary transfers, thereby ensuring security and preventing information leaks. Furthermore, by including the transfer date and time of the transfer request in the approval request, the approver can prioritize the confirmation workload. For example, the confirmation workload can be reduced for data that was recently transferred because it is less likely to have been altered. Furthermore, the confirmation workload can be increased for data that has been transferred a long time ago because it is more likely to have been altered. According to the management device according to an aspect of the present embodiment, the workload of the approver who approves approval requests can be reduced while ensuring security and preventing information leaks.
[0065] In one aspect of this embodiment, if the secret information identification unit identifies that the transfer request data contains secret information, it determines whether all information included in the transfer request data is secret information. Furthermore, if all information included in the transfer request data is secret information, the secret information identification unit rejects the approval request. This allows the management device of one aspect of this embodiment to reject an approval request for data for which all information is prohibited from being taken out before requesting approval from the approver. In other words, the management device of one aspect of this embodiment can reduce the workload of the approver who approves the approval request.
[0066] The management device of one aspect of this embodiment further includes a transfer unit that transmits the transfer-requested data to the transfer destination specified in the approval request when the approval request is approved. The management device also includes an update unit that adds an entry of the transfer-requested data to the transfer management information when the transfer of the transfer-requested data is performed. The transfer management information is information for managing the transfer history of the transfer-requested data. In local governments and the like, management of data take-out and take-in is generally performed manually, resulting in a heavy workload. According to the management device of one aspect of this embodiment, the transfer management information is updated each time the transfer-requested data is transferred, thereby reducing the workload required for data transfer management.
[0067] A management device according to an aspect of the present embodiment further includes a masking unit that masks the confidential information included in the transfer request data using the confidential information identified by the confidential information identification unit. The approval request generation unit generates an approval request that further includes the masked transfer request data. The transfer unit transmits the transfer request data in which the confidential information has been masked. Among data handled by local governments and the like, some information is prohibited from being taken out, while other information is allowed to be taken out. Such data can be taken out if the area containing the prohibited information can be made invisible. A management device according to an aspect of the present embodiment masks the confidential information and transmits the masked transfer request data. By including the masked transfer request data in the approval request, the approver can confirm whether there is a risk of information leakage or the like even if the transfer request data is transferred. The management device according to an aspect of the present embodiment enables data transfer while ensuring security and preventing information leakage.
[0068] In one aspect of this embodiment, the secret information identification unit does not identify secret information when there is a transfer history of the transfer-desired data, thereby reducing the processing load on the management device.
[0069] (Second embodiment) In this embodiment, a management device 20 will be described, which has a simplified configuration of the management device in the first embodiment. In the following description, the same parts as in the first embodiment will be omitted as appropriate.
[0070] (composition) Next, the configuration of a management device according to this embodiment will be described with reference to the drawings. Fig. 12 is a block diagram showing an example of the configuration of a management device according to the present disclosure. The management device 20 includes an application receiving unit 21, a transfer history identifying unit 22, a secret information identifying unit 23, an approval request generating unit 25, and a transmitting unit 26.
[0071] The application receiving unit 21 receives an input of an approval request for the transfer of data to be transferred. The transfer history identifying unit 22 identifies whether or not there is a transfer history of the data to be transferred, using transfer management information including the transfer history of data transferred in the past. The confidential information identifying unit 23 identifies whether or not confidential information is included in the data to be transferred. The approval request generating unit 25 generates an approval request including the approval request, the identification result of the transfer history, and the identification result of the confidential information. The transmitting unit 26 transmits the approval request to an approval terminal operated by the approver.
[0072] (operation) Next, an example of the operation of the management device in this embodiment will be described with reference to Fig. 13. Fig. 13 is a diagram showing an example of the operation of the management device in the present disclosure.
[0073] First, the application receiving unit 21 receives an input of an approval application for requesting the transfer of transfer-desired data (step S21).
[0074] Next, the transfer history specifying unit 22 uses transfer management information that includes the transfer history of transfer data that has been transferred in the past to specify whether or not there is a transfer history of the data to be transferred (step S22).
[0075] Next, the confidential information identification unit 23 identifies whether or not confidential information is included in the transfer request data (step S23).
[0076] Next, the approval request generating unit 25 generates an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information (step S24).
[0077] Next, the transmitting unit 26 transmits an approval request to the approval terminal operated by the approver (step S25).
[0078] The approval request sent to the approval terminal operated by the approver includes the approval request, the identification result of the transfer history, and the identification result of the confidential information. In other words, the management device of this embodiment can reduce the workload of the approver who approves the approval request.
[0079] (Hardware configuration) The functions of each of the components according to the embodiments of the present disclosure described above can be realized not only as hardware but also as a computer device or firmware under program control.
[0080] 14 is a diagram showing an example of a hardware configuration in which a management device according to the present disclosure is realized by a computer device 90 including a processor. The management device of each embodiment is realized by the computer device 90. As shown in FIG. 14, the computer device 90 includes a processor 91, memory 92, a storage device 93 such as a hard disk for storing programs, an input / output interface 94 for connecting input devices and output devices, and a communication interface 95 for connecting to a network.
[0081] The processor 91 loads a program (instructions) stored in a storage device 93 or the like into the memory 92. For example, the program is a software program for executing the control and processing in the present disclosure. The processor 91 executes the program loaded into the memory 92. The processor 91 executes the program to execute the control and processing in the present disclosure.
[0082] The storage device 93 may be, for example, an optical disk, a flexible disk, a magneto-optical disk, an external hard disk, or a semiconductor memory. Some storage media in the storage device are non-volatile storage devices, and the programs are recorded therein. The programs may also be downloaded from an external computer (not shown) connected to a communication network.
[0083] The input device connected to the input / output interface 94 is realized by, for example, a mouse or a keyboard, and is used for input operations. Similarly, the output device connected to the input / output interface 94 is realized by, for example, a display, and is used for displaying and checking output results.
[0084] Although the present disclosure has been described above with reference to the embodiments, the present disclosure is not limited to the above-described embodiments. Various modifications that can be understood by those skilled in the art can be made to the configuration and details of the present disclosure within the scope of the present disclosure. Furthermore, each embodiment can be combined with other embodiments as appropriate.
[0085] Some or all of the above embodiments can also be described as follows:
[0086] (Appendix 1) an application receiving means for receiving an input of an approval application for requesting the transfer of the data to be transferred; a transfer history identifying means for identifying whether or not there is a transfer history of the data to be transferred, using transfer management information including a transfer history of data that has been transferred in the past; a secret information identifying means for identifying whether or not the transfer request data includes secret information; an approval request generating means for generating an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information; a transmitting means for transmitting the approval request to an approval terminal operated by an approver. (Appendix 2) The secret information identification means Identifying the confidential information included in the transfer request data; The approval request generating means generating confirmation data in which the confidential information included in the transfer request data is clearly indicated; 2. The management device of claim 1, wherein the confirmation data is included in the approval request. (Appendix 3) The management device according to claim 2, wherein the approval request generating means generates confirmation data to which a marker indicating the confidential information included in the transfer request data is attached, and includes the confirmation data in the approval request. (Appendix 4) the transfer management information includes the number of transfers of the transfer data that is the same as the transfer desired data and the transfer date and time of the transfer data that is the same as the transfer desired data, The approval request generating means The management device according to claim 1, wherein the approval request is generated including at least one of the number of transfers of the transfer data that is the same as the transfer request data or the transfer date and time of the transfer data that is the same as the transfer request data. (Appendix 5) The management device described in Appendix 1, wherein, when the secret information identification means identifies that the transfer request data contains the secret information, it identifies whether all information included in the transfer request data is the secret information, and if all information included in the transfer request data is the secret information, it rejects the approval request. (Appendix 6) a transfer means for transmitting the transfer request data to a transfer destination designated in the approval request when the approval request is approved; 2. The management device according to claim 1, further comprising: an update unit that, when the transfer request data is transferred, adds an entry of the transfer request data to the transfer management information. (Appendix 7) further comprising a masking means for masking the confidential information included in the transfer request data; The secret information identification means Identifying the confidential information included in the transfer request data; The masking method is masking the confidential information included in the identified transfer request data; The approval request generating means generating an approval request including the masked transfer request data; The transfer means The management device according to claim 6, wherein the management device transmits the transfer request data with the confidential information masked. (Appendix 8) 7. The management device according to claim 6, wherein the secret information identification means does not identify secret information when the transfer management information contains an entry for the transfer request data. (Appendix 9) A management device according to any one of Supplementary Notes 6 to 8; an information processing terminal that stores the transfer request data sent from the management device in response to approval of the approval request, and accepts access to the transfer request data from an application terminal used by an applicant for the approval request. (Appendix 10) The computer Accept the input of an approval request for the transfer of the data you wish to transfer, Using transfer management information including a transfer history of previously transferred data, it is determined whether or not there is a transfer history of the data to be transferred; Identifying whether the transfer request data includes confidential information; generating an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information; An output method for transmitting the approval request to an approval terminal operated by the approver. (Appendix 11) On the computer, A process of accepting an input of an approval request for the transfer of the data to be transferred; A process of identifying whether or not there is a transfer history of the data to be transferred, using transfer management information including a transfer history of data that has been transferred in the past; A process of determining whether or not confidential information is included in the transfer request data; a process of generating an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information; and a program for executing a process of transmitting the approval request to an approval terminal operated by the approver.
[0087] In addition, in the above appendices, some or all of the configurations described in appendices 2 to 8 that are dependent on appendices 1 may also be dependent on appendices 10 and 11 in the same dependent relationship as appendices 2 to 8. Furthermore, not limited to appendices 1, 10, and 11, but within the scope of each of the above-mentioned embodiments, some or all of the configurations described as appendices may be similarly made dependent on various hardware, software, various recording means for recording software, or systems. [Explanation of symbols]
[0088] 10, 20 Management device 101, 21 Application Reception Department 102, 22 Transfer history identification part 103, 23 Confidential Information Identification Department 104 Masking section 105, 25 Approval request generation unit 106 Approval Reception Department 1061, 26 Transmitter 1062 Receiver 107, 27 Transfer section 108 Update section 109 Storage section 110 Notification Department 60 Application Terminals 70 Approval terminal 80 Information processing terminal 90 Computer Equipment 91 processors 92 memory 93 Storage device 94 Input / Output Interface 95 Communication Interface
Claims
1. an application receiving means for receiving an input of an approval application for requesting the transfer of the data to be transferred; a transfer history identifying means for identifying whether or not there is a transfer history of the data to be transferred, using transfer management information including a transfer history of data that has been transferred in the past; a secret information identifying means for identifying whether or not the transfer request data includes secret information; an approval request generating means for generating an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information; a transmitting means for transmitting the approval request to an approval terminal operated by an approver.
2. The secret information identification means Identifying the confidential information included in the transfer request data; The approval request generating means generating confirmation data in which the confidential information included in the transfer request data is clearly indicated; The management device of claim 1 , wherein the confirmation data is included in the approval request.
3. The approval request generating means 3. The management device according to claim 2, wherein confirmation data is generated with a marker indicating the confidential information included in the transfer request data, and the confirmation data is included in the approval request.
4. the transfer management information includes the number of transfers of the transfer data that is the same as the transfer desired data and the transfer date and time of the transfer data that is the same as the transfer desired data, The approval request generating means The management device according to claim 1 , wherein the approval request is generated to include at least one of the number of transfers of the transfer data that is the same as the transfer desired data and the transfer date and time of the transfer data that is the same as the transfer desired data.
5. The secret information identification means The management device of claim 1, wherein if it is determined that the transfer request data contains the confidential information, it determines whether all information contained in the transfer request data is the confidential information, and if all information contained in the transfer request data is the confidential information, it rejects the approval request.
6. a transfer means for transmitting the transfer request data to a transfer destination designated in the approval request when the approval request is approved; The management device according to claim 1 , further comprising: an update unit that, when the transfer of the transfer request data is completed, adds an entry of the transfer request data to the transfer management information.
7. further comprising a masking means for masking the confidential information included in the transfer request data; The secret information identification means Identifying the confidential information included in the transfer request data; The masking method is masking the confidential information included in the identified transfer request data; The approval request generating means generating the approval request including the masked transfer request data; The transfer means The management device according to claim 6 , wherein the transfer request data is transmitted with the confidential information masked.
8. a management device according to claim 6 or 7; an information processing terminal that stores the transfer request data sent from the management device in response to approval of the approval request, and accepts access to the transfer request data from an application terminal used by an applicant for the approval request.
9. The computer Accept the input of an approval request for the transfer of the data you wish to transfer, Using transfer management information including a transfer history of previously transferred data, it is determined whether or not there is a transfer history of the data to be transferred; Identifying whether the transfer request data includes confidential information; generating an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information; The management method includes transmitting the approval request to an approval terminal operated by an approver.
10. On the computer, A process of accepting an input of an approval request for the transfer of the data to be transferred; A process of identifying whether or not there is a transfer history of the data to be transferred, using transfer management information including a transfer history of data that has been transferred in the past; A process of determining whether or not confidential information is included in the transfer request data; a process of generating an approval request including the approval application, the identification result of the transfer history, and the identification result of the confidential information; and a program for executing a process of transmitting the approval request to an approval terminal operated by the approver.
Citation Information
Patent Citations
Information processing system, information processing device, information processing method, and program
JP2013037465A