Authority management device
The authority management device addresses the challenge of managing access rights for groups by enabling bulk changes through a management unit and control unit, reducing the workload on administrators by allowing efficient revocation and restoration of rights.
Patent Information
- Application Number
- JP2024044606
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-10-03
AI Technical Summary
Existing systems face challenges in efficiently managing and revoking access rights for groups within organizations, particularly when contracts expire or are renegotiated, leading to a heavy workload for administrators due to the need for meticulous contract examination.
An authority management device with a management unit and control unit that manages and changes access rights for groups by updating flag information in a management table in response to change requests, reducing the workload by enabling bulk invalidation or restoration of rights.
Facilitates efficient management of access rights by allowing administrators to collectively disable or restore rights without detailed contract review, thereby reducing administrative burden and improving processing efficiency.
Smart Images

Figure 2025144766000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to a rights management device. [Background technology]
[0002] Patent Document 1 discloses a system for managing multiple projectors using a computer network. Patent Document 1 also discloses that, in implementing a multiplex management service, a user who monitors projectors for each building is set by assigning user authority to each server, and that a network administrator limits the access rights of selected users to one or more specific servers. In the system disclosed in Patent Document 1, users of the system are classified into three hierarchies: users who assign user authority to other users (the network administrator mentioned above), users who are assigned user authority by the network administrator, and general users who use the projectors. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-191972 Summary of the Invention [Problem to be solved by the invention]
[0004] Access rights to a projector may be set not only for an individual user, but also for a department or section within a company, or for an organization unit within a company, etc. For example, when organization B that owns a projector entrusts the operation of a management device to organization A, which is different from organization B, access rights may be granted to each group, with organization B as the unit.
[0005] However, when managing access rights on a group-by-group basis, the following problem can arise. When organization B, which owns a projector, entrusts organization A, which is different from organization B, with the operation of a management device, some kind of contract is concluded between organization A, which operates the management device, and organization B, which owns the projector. When the contract expires, or when a breach of contract occurs and contract negotiations need to be renegotiated during the contract period, organization A needs to suspend organization B's access rights. One method for suspending organization B's access rights is to delete organization B's access rights. However, if a contract is re-signed after deleting organization B's access rights, organization B's access rights must be restored in accordance with the contract terms. This restoration process may impose a heavy workload on the person in organization A who operates the management device, as the person in question must carefully examine the terms of the contract with organization B. [Means for solving the problem]
[0006] One aspect of the authority management device disclosed herein includes a management unit and a control unit, wherein the management unit manages first authority information, linked to first identification information for identifying a first group to which a user who can access a projector belongs, which represents one or more types of authority initially set for the first group and represents authority that has been disabled after the initial setting, and the control unit obtains a request to change the first authority information and changes the first authority information in response to the change request. [Brief explanation of the drawings]
[0007] [Figure 1] 1 is a diagram illustrating a configuration example of an information system 1A including a right management device 10A according to an embodiment of the present disclosure. [Figure 2] FIG. 2 is a diagram showing an example of the configuration of a right management device 10A. [Figure 3] FIG. 10 is a diagram showing an example of a management table TBLA. [Figure 4] 10 is a flowchart showing the flow of processing in an authority management method executed by a processing device 110 in accordance with a program PRA. [Figure 5] FIG. 10 is a diagram showing an example of a management screen G1. [Figure 6] FIG. 10 is a diagram showing an example of a management table TBLA after a change. [Figure 7] FIG. 10 is a diagram illustrating an example of the configuration of a right management device 10B according to a second embodiment of the present disclosure. [Figure 8] FIG. 10 is a diagram illustrating an example of a management table TBLB. [Figure 9] FIG. 10 is a diagram showing an example of a management table TBLB after a change. [Figure 10] FIG. 10 is a diagram illustrating an example of the configuration of a right management device 10C according to a third embodiment of the present disclosure. [Figure 11] FIG. 10 is a diagram illustrating an example of a management table TBLC. [Figure 12] FIG. 10 is a diagram showing an example of a management table TBLC after a change. DETAILED DESCRIPTION OF THE INVENTION
[0008] The embodiments described below are subject to various technically preferable limitations, but the embodiments of the present disclosure are not limited to the following embodiments. 1. First embodiment FIG. 1 is a diagram illustrating a configuration example of an information system 1A including an authority management device 10A according to an embodiment of the present disclosure. As illustrated in FIG. 1, the information system 1A includes the authority management device 10A, a terminal device 20A, and a terminal device 20B. Each of the authority management device 10A, the terminal device 20A, and the terminal device 20B is connected to a network NW such as the Internet. The authority management device 10A communicates with each of the terminal device 20A and the terminal device 20B via the network NW.
[0009] Terminal device 20B is a computer device used by a system manager in organization B, which owns electronic devices that are the subject of authority management (hereinafter referred to as managed devices). In this embodiment, the managed devices are projectors. Note that the managed devices are not shown in FIG. 1. Terminal device 20A is a computer device used by a system manager in organization A, which is different from organization B. Organization A in this embodiment is an organization that has been contracted by organization B to operate and manage the managed devices. In this embodiment, organizations such as organization A and organization B (hereinafter also referred to as groups) are used as units, and authorities for the managed devices are set for each group. Authority management device 10A is a computer device for managing the authorities set for each group for the managed devices, and is operated by organization A.
[0010] As described above, when the contract between organization A and organization B expires, or when new contract negotiations are required due to reasons such as organization B violating the terms of the contract, organization A needs to revoke organization B's authority. Restoring organization B's authority after revoking its authority requires work such as carefully examining the contract details to identify the authority to be restored, which can impose a heavy workload on the system administrator of organization A. The authority management device 10A is a device that enables the authority set for each group of devices to be managed to be changed while reducing the workload on the system administrator of organization A. The following description focuses on the authority management device 10A.
[0011] 2 is a diagram showing an example of the configuration of the right management device 10 A. As shown in FIG. 2, the right management device 10 A includes a processing device 110, a communication device 120, and a storage device 130.
[0012] The processing device 110 is one or more processors. The processing device 110 is, for example, a CPU (Central Processing Unit). The processing device 110 functions as the control center of the authority management device 10A by operating in accordance with a program PRA stored in the storage device 130. The communication device 120 is a device that performs wireless or wired communication with other devices, and includes, for example, an interface circuit. Specific examples of other devices that communicate with the communication device 120 include a terminal device 20A and a terminal device 20B.
[0013] The storage device 130 is a recording medium readable by the processing device 110. The storage device 130 includes, for example, a nonvolatile memory and a volatile memory. The nonvolatile memory is, for example, a ROM (Read Only Memory), an EPROM (Erasable Programmable Read Only Memory), or an EEPROM (Electrically Erasable Programmable Read Only Memory). The volatile memory is, for example, a RAM (Radom Access Memory). Various programs and a management table TBLA are stored in the nonvolatile memory of the storage device 130.
[0014] 3 is a diagram showing an example of a management table TBLA. As shown in FIG. 3, the management table TBLA stores address information and authority information indicating the authority set for the organization, linked to identification information for uniquely identifying the organization for which the authority is set. In this embodiment, the identification information includes an ID assigned to the organization and a character string representing the name of the organization, but the identification information may be composed of either a character string representing the ID or a character string representing the name. The address information stores the email address of the system manager in the organization indicated by the identification information stored in the management table TBLA in association with the address information.
[0015] The authority information includes initial setting information indicating authority initially set for the organization indicated by the identification information stored in the management table TBLA in association with the authority information, and flag information indicating whether the authority indicated by the initial setting information is valid or invalid. One or more of the letters "A," "B," and "C" are set in the initial setting information. The letter "A" in the initial setting information indicates that authority "A" is initially set. The letter "B" in the initial setting information indicates that authority "B," which is different from authority "A," is initially set. The letter "C" in the initial setting information indicates that authority "C," which is different from authority "A" and also different from authority "B," is initially set. For example, in the example shown in FIG. 3, the initial setting information corresponding to organization A is "A, B, C," so authority "A," authority "B," and authority "C" are set for organization A. In the example shown in FIG. 3, the initial setting information corresponding to organization B is "A, B," so authority "A" and authority "B" are set for organization B. The letter "Y" or the letter "N" is set in the flag information. The letter "Y" in the flag information indicates that all the permissions indicated by the initial setting information corresponding to the flag information are disabled. The letter "N" in the flag information indicates that all the permissions indicated by the initial setting information corresponding to the flag information are valid. At the time of initial setting of permissions, the flag information is set to "N".
[0016] Examples of various programs stored in nonvolatile memory include a kernel program and a program PRA. The kernel program is not shown in FIG. 2 . When the authority management device 10A is powered on, the processing device 110 reads the kernel program from the nonvolatile memory to the volatile memory and starts executing the read kernel program. The processing device 110, which operates according to the kernel program, starts executing another program when instructed to do so. For example, when instructed to start executing the program PRA, the processing device 110 reads the program PRA from the nonvolatile memory to the volatile memory and starts executing the program PRA read into the volatile memory.
[0017] Processing device 110 operating in accordance with program PRA functions as management unit 111 and control unit 112A shown in Fig. 2. In other words, each of management unit 111 and control unit 112A shown in Fig. 2 is a software module realized by operating processing device 110 in accordance with program PRA. The roles of management unit 111 and control unit 112A shown in Fig. 2 are as follows.
[0018] The management unit 111 uses the management table TBLA to manage authority information linked to identification information and to manage whether access to the devices to be managed is permitted. When a change request requesting a change of the authority stored in the management table TBLA is received by the communication device 120, the control unit 112A acquires the change request from the communication device 120 and changes the stored contents of the management table TBLA in accordance with the change request.
[0019] In this embodiment, a change request is a signal requesting the invalidation of all the privileges granted to a certain organization or the restoration of all the invalidated privileges, and this change request includes the identification information of the organization whose privileges are to be modified in a batch. When the control unit 112A receives a change request instructing invalidation, it updates the flag information stored in the management table TBLA, which is associated with the same identification information as the identification information included in the change request, from “N” to “Y,” thereby invalidating all the privileges granted to the organization. On the other hand, when the control unit 112A receives a change request instructing restoration, it updates the flag information stored in the management table TBLA, which is associated with the same identification information as the identification information included in the change request, from “Y” to “N,” thereby restoring all the invalidated privileges.
[0020] In addition, when the control unit 112A changes the authority information in response to a change request, it notifies the user that the authority has been changed by sending an email with the email body and subject line stating that the authority has been changed to the email address indicated by the address information stored in the management table TBLA and linked to the same identification information as the identification information included in the change request as the destination address. The above is the configuration of the right management device 10A.
[0021] Furthermore, the processing device 110 operating in accordance with the program PRA executes an authority management method embodying the features of the present disclosure. FIG. 4 is a diagram showing the flow of processes included in this authority management method. As shown in FIG. 4, the authority management method of this embodiment includes display control processing SA100, change processing SA110, and notification processing SA120. Below, the contents of the processes executed by the authority management device 10A in the authority management method of the present disclosure will be described using an example in which the authorities initially set for organization B are collectively revoked when the contents stored in the management table TBLA are as shown in FIG. 3. Organization B in this embodiment is an example of a first group in the present disclosure. Identification information indicating organization B is an example of first identification information in the present disclosure, and authority information indicating the authority of organization B is an example of first authority information in the present disclosure.
[0022] When a system administrator in organization A wishes to change the authority set for another organization, the system administrator logs in to the authority management device 10A using the terminal device 20A. When the processing device 110 detects the login of the user of the terminal device 20A, it executes a display control process SA100. In the display control process SA100, the processing device 110 references the stored contents of the management table TBLA and generates screen data representing the management screen G1 shown in Fig. 5. Then, the processing device 110 transmits the generated screen data to the terminal device 20A, thereby causing the terminal device 20A to display the management screen G1.
[0023] As shown in FIG. 5, the management screen G1 displays the identification information, address information, and permission information of each organization in a list format for each organization. By referring to the management screen G1 displayed on the terminal device 20A, the system administrator of organization A can understand the permissions initially set for each organization and whether the permissions are valid. Furthermore, the system administrator of organization A can select any of the identification information displayed on the management screen G1 and perform an operation to instruct the collectively invalidation of the permissions or the restoration of the invalidated permissions, thereby instructing a change of the permissions of the organization indicated by the selected identification information. When the above operation is performed on the terminal device 20A, the terminal device 20A generates a change request in response to the user's operation and transmits the generated change request to the permission management device 10A. For example, suppose that organization B is selected by the terminal device 20A and an operation to instruct the collectively invalidation of the permissions of organization B is performed. In this case, the terminal device 20A transmits a change request to the permission management device 10A, including the identification information of organization B and indicating that the permissions set for organization B are to be collectively invalidated.
[0024] The change process SA110, which is executed following the display control process SA100, is a process that is executed in response to the reception of a change request from the communication device 120. In the change process SA110, the processing device 110 functions as the control unit 112A. That is, in the change process SA110, the processing device 110 changes the value corresponding to the identification information stored in the management table TBLA based on the change request acquired from the communication device 120. If the change request acquired from the communication device 120 indicates that the authorities set for organization B should be invalidated all at once, the processing device 110 updates the flag information stored in the management table TBLA in association with the identification information indicating organization B from "N" to "Y." This update causes the contents stored in the management table TBLA to become as shown in FIG. 6, and all of the authorities "A" and "B" initially set for organization B are invalidated.
[0025] In notification processing SA120 following change processing SA110, the processing device 110 functions as the control unit 112A. In notification processing SA120, the processing device 110 notifies the user that the authority has been changed by sending an e-mail with the body and title indicating that the authority has been changed to an e-mail address indicated by address information stored in the management table TBLA and associated with the same identification information as the identification information included in the change request as the destination address. As described above, in this operational example, the organization indicated by the identification information included in the change request acquired by the processing device 110 is organization B. Therefore, the processing device 110 reads out the address information stored in the management table TBLA in association with the identification information of organization B, and sends an e-mail indicating that the authority has been changed to the e-mail address indicated by the address information as the destination address. A system administrator at organization B can receive and view the e-mail using terminal device 20B to understand that the authority set for the organization to which he or she belongs has been changed.
[0026] According to this embodiment, a system administrator in organization A can change the authority of an organization indicated by the selected identification information by referring to the management screen G1 displayed on the terminal device 20A and performing an operation to instruct the system administrator to collectively disable or restore the disabled authority. Therefore, when restoring authority for an organization whose authority has been disabled, there is no need to check the contents of the contract between the organization and the administrator's own organization, thereby reducing the workload of the system administrator. In other words, according to this embodiment, when disabling authority, there is no need to record the settings before the disablement in preparation for restoration, thereby facilitating the process of disabling authority that is scheduled to be restored to some extent. As such, the authority management device 10A of this embodiment makes it possible to change the authority set for each group of managed devices while reducing the workload on the system administrator in organization A. Furthermore, according to this embodiment, when access to a managed device occurs and the flag information stored in the management table TBLA associated with the identification information of the access source is “Y,” the processing device 110 can reject the access without checking the consistency between the access content and the authority set for the access source, thereby reducing the processing load related to access management.
[0027] 2. Other embodiments 2-1: Second embodiment FIG. 7 is a diagram showing an example of the configuration of an authority management device 10B according to a second embodiment of the present disclosure. In FIG. 7, the same components as those in FIG. 2 are assigned the same reference numerals as those in FIG. 2. As is clear from comparing FIG. 7 with FIG. 2, the hardware configuration of the authority management device 10B is the same as the hardware configuration of the authority management device 10A. The configuration of the authority management device 10B differs from the configuration of the authority management device 10A in that a management table TBLB is stored in the storage device 130 instead of the management table TBLA, and that a program PRB is stored in the storage device 130 instead of the program PRA. The following description will focus on the management table TBLB and the program PRB, which are differences from the authority management device 10A.
[0028] Fig. 8 is a diagram showing an example of a management table TBLB. As is clear from comparing Fig. 8 with Fig. 3, the management table TBLB is the same as the management table TBLA in that it stores address information and access right information linked to identification information. As shown in Fig. 8, this embodiment differs from the first embodiment in that the authority information is composed of valid information indicating valid authorities among the initially set authorities and invalid information indicating invalid authorities among the initially set authorities. Note that at the stage of initial setting of the authorities, Null (0x00) is set for the invalid information.
[0029] This embodiment differs from the first embodiment in that the user of the terminal device 20A can specify, on the management screen G1, the organization whose authority is to be changed, the change mode of the authority such as invalidation or restoration, and the authority to be changed. In this embodiment, the change request sent from the terminal device 20A to the authority management device 10B includes identification information of the organization whose authority is to be changed, information indicating the change mode of the authority, and information indicating the authority to be changed. In other words, this embodiment differs from the first embodiment in that, when multiple authorities are set for an organization, invalidation and restoration are possible on an authority-by-authority basis.
[0030] The processing device 110, operating in accordance with the program PRB, functions as a management unit 111 and a control unit 112B. In this embodiment, the management unit 111 uses a management table TBLB to manage authority information by linking it to identification information and to manage whether access to managed devices is permitted. The control unit 112B updates the management table TBLB in response to a change request received from the communication device 120. More specifically, if the received change request includes information indicating the invalidation of authority, the control unit 112B deletes from the validity information the character representing the authority designated as the authority to be changed by the information included in the change request, among the characters representing the authority registered in the validity information in association with the same identification information as the identification information included in the change request, and moves the character to the invalidation information, thereby invalidating only the authority. For example, if the organization to be changed is organization B and the authority to be invalidated is authority "B," the control unit 112B updates the contents of the management table TBLB as shown in FIG. 9. Note that, when the authority is changed, the control unit 112B notifies the system administrator of the organization whose authority has been changed by email, in the same manner as the control unit 112A in the first embodiment. Also, the processing device 110 operating in accordance with the program PRB is the same as in the first embodiment in that it executes the authority management method described above, but differs from the first embodiment in that it functions as the control unit 112B in the change processing SA110 and the notification processing SA120.
[0031] According to this embodiment, if a system administrator at organization A wishes to restore a disabled authority, he or she simply moves the character indicating the relevant authority from the disabled information to the valid information. Therefore, according to this embodiment, the authority that was valid before the authority was disabled for each customer can be identified, which reduces the workload of the system administrator compared to registering a new authority that has been deleted. Furthermore, according to this embodiment, when multiple authorities are set for an organization, the effect is achieved in that each authority can be disabled and restored individually.
[0032] 2-2: Third embodiment FIG. 10 is a diagram illustrating an example configuration of an authority management device 10C according to a third embodiment of the present disclosure. In FIG. 10, the same components as those in FIG. 2 are assigned the same reference numerals as those in FIG. 2. As is clear from comparing FIG. 10 with FIG. 2, the hardware configuration of the authority management device 10C is the same as the hardware configuration of the authority management device 10A. The configuration of the authority management device 10C differs from the configuration of the authority management device 10A in that a management table TBLC is stored in the storage device 130 instead of a management table TBLA, and that a program PRC is stored in the storage device 130 instead of a program PRA. The following description will focus on the management table TBLC and the program PRC, which are differences from the authority management device 10A.
[0033] FIG. 11 is a diagram showing an example of a management table TBLC. As is clear from comparing FIG. 11 with FIG. 3, management table TBLC is the same as management table TBLA in that it stores address information and authority information in association with identification information, but differs from management table TBLA in that it also stores a parent ID in association with identification information. The parent ID stores the ID of an organization higher than the organization indicated by the identification information associated with the parent ID (hereinafter referred to as a parent group). An organization in which the ID of another organization is set as a parent ID is referred to as a child group. Note that Null is stored in the parent ID of an organization that does not have a parent group. The example shown in FIG. 11 indicates that organization D is a child group of organization B (in other words, organization B is the parent group of organization D). Organization D in this embodiment is an example of a second group in the present disclosure. The identification information indicating organization D is an example of second identification information in the present disclosure, and the authority information indicating the authority of organization D is an example of second authority information in the present disclosure. In management table TBLC of this embodiment, parent groups and child groups are linked by parent IDs.
[0034] In this embodiment, the user of the terminal device 20A can specify, on the management screen G1, the organization whose permissions are to be changed and the change mode of the permissions, such as invalidation or restoration, which is the same as in the first embodiment. The change request transmitted from the terminal device 20A to the permission management device 10C includes identification information of the organization whose permissions are to be changed and information indicating the change mode of the permissions. This embodiment is the same as the first embodiment in that all permissions of the organization specified in the change request are changed collectively in the change mode specified in the change request. Additionally, this embodiment differs from the first embodiment in that, when permissions are set for another organization (i.e., a child group) that has the organization specified in the change request as its parent group, the permissions of the child group are changed collectively in accordance with the change request. The relationship between a parent group and a child group is not limited to the relationship between an organization and its department, but may also be the relationship between a parent company and a subsidiary, or the relationship between a distributor and an agency. When the relationship between a parent group and a child group is the relationship between a distributor and an agency, the authority set for the child group (proxy point) includes the distributor authority set by the distributor for the agency.
[0035] The processing device 110, operating in accordance with the program PRC, functions as a management unit 111 and a control unit 112C. The management unit 111 in this embodiment uses a management table TBLC to manage permission information by linking it to identification information and to manage whether access to devices to be managed is permitted. When a change request instructing invalidation is received, the control unit 112C updates flag information stored in the management table TBLC in association with the same identification information included in the change request from “N” to “Y,” thereby invalidating all permissions set for the organization. This is the same as the control unit 112A in the first embodiment. If permissions are set for a child group whose parent group is the organization whose permissions are instructed to be invalidated by the change request, the control unit 112C also invalidates the child group's permissions in a lump. For example, if the identification information included in the change request indicates “organization B,” the control unit 112C invalidates all permissions for organization D, whose parent ID is set to the ID of organization B. As a result, the contents of the management table TBLC are changed as shown in FIG. 12. Note that, when the control unit 112C changes the authority, it notifies the system administrator of the organization whose authority has been changed by email of the change in authority, similar to the control unit 112A in the first embodiment. For example, when the authority of each of organizations B and D is invalidated, the control unit 112C sends the above email to the system personnel of each of organizations B and D. Also, the processing device 110 operating in accordance with the program PRC is the same as in the first embodiment in that it executes the above-mentioned authority management method, but differs from the first embodiment in that it functions as the control unit 112C in the change processing SA110 and the notification processing SA120.
[0036] According to this embodiment, the system administrator of organization A does not need to check the contents of the contract when restoring the authority that was once revoked, thereby reducing the workload of the system administrator. Furthermore, according to this embodiment, an effect is achieved in that the authority of a child group can be changed in conjunction with a change in the authority set for a parent group.
[0037] 3. Transformation The above embodiment can be modified as follows. (1) In the first embodiment, the management unit 111 and the control unit 112A are software modules. However, either one or all of the management unit 111 and the control unit 112A may be hardware modules such as an ASIC (Application Specific Integrated Circuit). Even if at least one of the management unit 111 and the control unit 112A is a hardware module, the same effects as those of the first embodiment can be achieved. Similarly, the control unit 112B in the second embodiment may be a hardware module, and the control unit 112C in the third embodiment may be a hardware module.
[0038] (2) The program PRA may be manufactured separately or provided free of charge or for a fee. Specific examples of providing the program PRA include providing the program PRA by writing it to a computer-readable recording medium such as a flash ROM, or by downloading it via a telecommunications line such as the Internet. Operating a general computer in accordance with the program PRA provided in these ways enables the computer to execute the display method of the present disclosure. Similarly, the program PRB may be manufactured or provided separately, and the program PRC may be manufactured or provided separately.
[0039] (3) In each of the above embodiments, the managed device was a projector. However, the managed device for which permissions are changed according to the present disclosure is not limited to a projector, and may be a digital signage, an electronic whiteboard, a personal computer, a printer, or a scanner.
[0040] 4. Summary of this disclosure The present disclosure is not limited to the above-described embodiments and modifications, and can be realized in various forms without departing from the spirit thereof. For example, the present disclosure can also be realized in the following forms. The technical features in the above embodiments corresponding to the technical features in each form described below can be replaced or combined as appropriate to solve some or all of the problems of the present disclosure or to achieve some or all of the effects of the present disclosure. Furthermore, if a technical feature is not described as essential in this specification, it can be deleted as appropriate. A summary of this disclosure is provided below.
[0041] (Appendix 1) The authority management device of the present disclosure includes a management unit and a control unit. The management unit manages first authority information, which is associated with first identification information for identifying a first group to which users who may access a managed device for which authority is to be managed belong, and represents one or more types of authority initially set for the first group and represents authorities that have been revoked after the initial setting. The control unit acquires a request to change the first authority information and changes the first authority information in response to the change request. According to this aspect, it is possible to change the authority set for each group of managed devices while reducing the burden on a system administrator who manages authority.
[0042] (Appendix 2) In a more preferred embodiment of the authority management device, the first authority information includes flag information indicating whether the initially set authority is valid or invalid. According to this embodiment, it becomes possible to collectively invalidate or restore the authority set for each group of devices to be managed.
[0043] (Appendix 3) In another preferred embodiment of the rights management device, the control unit further notifies that the first rights information has been changed. According to this embodiment, the group whose rights have been changed can understand the change in rights.
[0044] (Appendix 4) In a further preferred embodiment of the authority management device, the management unit manages second authority information, linked to second identification information for identifying a second group that is a child group of the first group, which indicates one or more types of authority for the managed device that was initially set for the second group and indicates authorities that were disabled after the initial setting, and manages the first identification information and the second identification information in association with each other, and the control unit further executes the following: changing the second authority information in response to a change in the first authority information. According to this embodiment, the authority of a child group can be changed in conjunction with a change in the authority of a parent group.
[0045] (Appendix 5) In a further preferred embodiment of the right management device, the control unit further notifies that the second right information has been changed. According to this embodiment, a child group whose right has been changed in conjunction with a change in the right of a parent group can grasp the change in the right.
[0046] (Appendix 6) In yet another preferred embodiment of the right management device, the first right information includes valid information indicating valid rights among the one or more initially set rights and invalid information indicating invalid rights, and changing the first right information in response to the change request means changing the valid information and the invalid information in response to the change request. According to this embodiment, the one or more initially set rights can be changed individually for each right.
[0047] (Appendix 7) In yet another preferred embodiment of the right management device, changing the validity information in response to the change request is performed by deleting, from the validity information, information indicating the rights that have been instructed to be invalid by the change request. According to this embodiment, one or more initially set rights can be changed individually for each right. [Explanation of symbols]
[0048] 1A...information system, 10A, 10B, 10C...authority management device, 20A, 20B...terminal device, NW...network, 110...processing device, 111...management unit, 112A, 112B, 112C...control unit, 120...communication device, 130...storage device, PRA...program, TBLA, TBLB, TBLC...management table, NW...network.
Claims
1. The system includes a management unit and a control unit, The management unit managing first authority information that is associated with first identification information for identifying a first group to which a user who may access a management target device that is a target of authority management belongs, the first authority information representing one or more types of authority that are initially set for the first group and representing authority that has been invalidated after the initial setting; The control unit obtaining a request to change the first authority information; and changing the first authority information in response to the change request. Authority management device.
2. 2. The authority management device according to claim 1, wherein the first authority information includes flag information indicating whether the initially set authority is valid or invalid.
3. The control unit further notifies the user that the first authority information has been changed. The authority management device according to claim 2 .
4. The management unit managing second authority information, which is associated with second identification information for identifying a second group that is a child group of the first group, and which represents one or more types of authority for the device to be managed and indicates authorities that have been invalidated after the initial setting, and managing the first identification information and the second identification information in association with each other; The control unit and further changing the second authority information in response to a change in the first authority information. The authority management device according to claim 2 .
5. The control unit and notifying the user that the second authorization information has been changed. The authority management device according to claim 4 .
6. The first authority information is The one or more initially set authorities include valid information indicating valid authorities and invalid information indicating invalid authorities, Changing the first authority information in response to the change request includes: changing the valid information and the invalid information in response to the change request; The authority management device according to claim 1 .
7. Changing the validity information in response to the change request includes: and deleting information indicating the authority that has been instructed to be invalidated by the change request from the validity information. The authority management device according to claim 6.
Citation Information
Patent Citations
Projector device network management system
JP2010191972A