Information processing device, information processing method and information processing program
The information processing device and method enforce user-specific permissions to restrict and lock functions in ERP systems, addressing security and control issues in code-dependent functions, ensuring authorized usage and preventing unauthorized modifications.
Patent Information
- Application Number
- JP2024063738
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-11
- Publication Date
- 2025-10-24
AI Technical Summary
In ERP systems, users can modify and share functions using queries, but ensuring security and IT control for code-dependent functions is difficult due to the lack of no-code implementation, leading to potential misuse and operational risks.
An information processing device and method that restricts function and table item usage based on user permissions, allowing only authorized items and functions to be displayed and modified, with separate security settings for functions and table items, and locking functions once in operation to prevent unauthorized changes.
Enhances security and control over function outputs by ensuring only authorized items and functions are used, preventing misuse and maintaining operational integrity.
Smart Images

Figure 2025160964000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, an information processing method, and an information processing program. [Background technology]
[0002] In today's known centralized management systems (ERP: Enterprise Resource Planning), users can save and use extraction conditions created using no-code or low-code application development methods as definitions.
[0003] In addition, users can use queries to process table items and share them among users (hereinafter referred to as functions).
[0004] Patent Document 1 (JP Patent Publication No. 2022-020487) discloses a technology for processing the output of system calls, which are instructions and functions (e.g., instructions and functions for providing or utilizing functionality for processes (tasks)) by the OS (kernel) (paragraph 0038, etc.), a technology for checking user permissions when a program is executed (paragraph 0122, etc.), and a technology for executing system call processing that improves processing efficiency without lowering the security level (paragraph 0228, etc.). [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Publication No. 2022-020487 Summary of the Invention [Problem to be solved by the invention]
[0006] In an ERP system, users can use queries to modify table items and share them among users (hereafter referred to as functions). Functions cannot be implemented using no-code, so they are defined and registered by directly writing queries. However, it is difficult to ensure sufficient security and IT control for code-dependent functions.
[0007] The present invention has been made in consideration of the above-mentioned problems, and aims to provide an information processing device, an information processing method, and an information processing program that make it possible to ensure the security and strengthen the control of functions set as output items of definitions. [Means for solving the problem]
[0008] In order to solve the above-mentioned problems and achieve the object, the information processing device of the present invention comprises an item display control unit that displays the item names of data items stored in a memory unit on a display unit, and a function description area display control unit that displays the selected item name in the function description area when an operation is performed to select a desired item name from the displayed item names and place it in a function description area, which is an area for describing functions, provided on the display unit, and each item is stored with usage permission information indicating whether it can be used when describing a function for each user, and the item display control unit refers to the memory unit when displaying the item names, thereby extracting the item names of items that the user is permitted to use and displaying them on the display unit.
[0009] In addition, in order to solve the above-mentioned problems and achieve the object, the information processing method of the present invention comprises an item display control step in which an item display control unit displays on a display unit the item names of items of data stored in a memory unit, and a function description area display control step in which a function description area display control unit displays on a display unit the selected item name in the function description area when an operation is performed to select a desired item name from the displayed item names and place it in the function description area, which is an area for describing functions, and each item is stored with usage permission information indicating whether it can be used when describing a function for each user, and in the item display control step, by referring to the memory unit when displaying the item names, the item names of items that the user is permitted to use are extracted and displayed on the display unit.
[0010] In addition, in order to solve the above-mentioned problems and achieve the object, the information processing program of the present invention causes a computer to function as an item display control unit that displays the item names of data items stored in a memory unit on a display unit, and as a function description area display control unit that displays the selected item name in the function description area when an operation is performed to select a desired item name from the displayed item names and place it in a function description area, which is an area for describing functions, provided on the display unit, and each item is stored with usage permission information indicating whether it can be used when describing a function for each user, and the item display control unit refers to the memory unit when displaying the item names, thereby extracting the item names of items that the user is permitted to use and displaying them on the display unit. [Effects of the Invention]
[0011] The present invention can ensure security and strengthen control of functions set as output items of definitions. [Brief explanation of the drawings]
[0012] [Figure 1] FIG. 1 is a diagram showing the roles of each person, jobs used, and authority to items required for explaining an information processing apparatus according to an embodiment. [Figure 2] FIG. 2 is a diagram showing an example of setting table field usage permissions that can be used for functions. [Figure 3] FIG. 3 is a diagram showing how the items displayed on the function registration screen are restricted according to the item use authority of each function setter. [Figure 4] FIG. 4 is a diagram showing the modification authority for each function set for each function setter. [Figure 5] FIG. 5 is a diagram showing how functions displayed on the function selection screen are restricted depending on the modification authority of each function setter. [Figure 6] FIG. 6 is a diagram for explaining the item usage authority of extraction definition users. [Figure 7] FIG. 7 is a diagram showing an example in which the creator of the extraction definition sets the operation flag of the sales information extraction definition to "ON" when the creator of the extraction definition starts to use the sales information extraction definition. [Figure 8] Figure 8 is a diagram to explain the behavior of a function that is launched only in inquiry mode and cannot have any items on the screen modified when the function setter selects a function whose in-operation flag is "ON." [Figure 9] FIG. 9 is a block diagram illustrating a hardware configuration of the information processing apparatus according to the embodiment. [Figure 10] FIG. 10 is a diagram showing an example of the user group master, the user group member master, and the user master. [Figure 11] FIG. 11 is a diagram showing an example of the item group master, the item group member master (for item dictionary), the item dictionary master, the item group member master (for function), the function master, and the function parameter master 19. [Figure 12] FIG. 12 is a diagram illustrating an example of an extraction definition header storage unit and an extraction definition output detail data storage unit. [Figure 13] FIG. 13 is a diagram showing an example of assumed operation for each user. [Figure 14] FIG. 14 is a diagram illustrating an example of the item security setting master. [Figure 15] FIG. 15 is a diagram illustrating an example of the system administrator master. [Figure 16]FIG. 16 is a diagram showing how a security administrator registers item groups to which table items and function items belong. [Figure 17] FIG. 17 is a diagram showing how a user group to which a user belongs is registered by a security administrator. [Figure 18] FIG. 18 is a diagram showing an example of registration that grants the user group "sales function setter G" authority to use table items and functions belonging to an item group and authority to modify the functions. [Figure 19] FIG. 19 is a diagram showing how a new function is created and registered by a function setter. [Figure 20] FIG. 20 is a diagram showing an example of the function registration screen. [Figure 21] FIG. 21 is a diagram for explaining the operation of assigning the newly created "adjustment rate" function to the "general sales item group" item group. [Figure 22] FIG. 22 is a diagram showing an example in which the sales amount, adjustment amount, and sales analysis index are displayed as output items already registered in the "sales information extraction definition," and the adjustment rate is displayed as an output item to be newly registered. [Figure 23] FIG. 23 is a diagram for explaining an example in which the in-operation flag is changed to "ON (true)." [Figure 24] FIG. 24 shows a state in which an extraction definition creator is prohibited from modifying an extraction definition in inquiry mode when using Extraction Definition Creation if the operation flag in the extraction definition header is "true," and a state in which a function setter is prohibited from modifying a function in inquiry mode when using Function Set if a function is used in an extraction definition whose operation flag in the extraction definition header is "true." [Figure 25] FIG. 25 is a diagram showing an example in which extraction definition users refer to information within the scope of their respective authority. [Figure 26] FIG. 26 is a flowchart showing the flow of the authority decision logic in the information processing device according to the embodiment. [Figure 27] FIG. 27 is a diagram showing an example of authority determination in the determination unit 32. In FIG. DETAILED DESCRIPTION OF THE INVENTION
[0013] An information processing device according to an embodiment of the present invention will be described in detail below with reference to the accompanying drawings, although the present invention is not limited to the following embodiment.
[0014] (overview) The information processing apparatus according to the embodiment aims to maintain security and strengthen control by restricting the operation of functions set as output items of definitions according to the authority of each user.
[0015] FIG. 1 is a diagram showing the roles of each person, the jobs they use, and the permissions they have for items, which are necessary for explaining an information processing device according to an embodiment. As shown in FIG. 1, the security setter is responsible for setting appropriate permissions for each person involved. Specifically, the security setter sets function modification permissions and table item usage permissions for function setters. The security setter also sets table item and function usage permissions for extraction definition creators and extraction definition users. The security setter also performs item group registration, user group registration, and item security registration as usage jobs.
[0016] The function configurer understands the table structure and codes the functions used in the extraction definition. The job of this function configurer is function configuration. This function configurer also has function modification authority. This function modification authority is granted by the security configurer. This indicates whether the function creator can modify any function. The function configurer also has field usage authority. This field usage authority is granted by the security configurer. This indicates whether any table field can be selected in the query when creating a function. In addition, function configurers can be controlled using the in operation flag. This control using the in operation flag is applied by the extraction definition creator's batch extraction definition operation setting. When a function is used in an extract definition that is in operation, all function configurers can only launch that function in query mode.
[0017] The extraction definition creator is responsible for creating extraction definitions. The jobs used by this extraction definition creator are creating extraction definitions and batch setting up extraction definition operations. Extraction definition creators have field usage authority. This field usage authority is granted by the security administrator. When creating an extraction definition, this indicates whether or not a table field or function can be specified as an output column for the extraction definition. Extraction definition creators can also control operation by using the in operation flag. Control by the in operation flag is applied by the extract definition creator's batch setting up extraction definition operations. When the in operation flag is set to "ON", all extraction definition creators can only launch the definition in query mode.
[0018] The extraction definition user is responsible for using the extraction definition to actually perform output. The job used by this extraction definition user is extraction definition output. They also have field usage authority, which is granted by the security administrator. When outputting using an extraction definition, this indicates whether or not table fields or functions can be obtained as output results.
[0019] (Task 1) Functions that incorporate queries directly into extraction definitions allow the function creator to freely write queries. However, if the function creator is allowed to write functions using table items without any restrictions, it becomes possible to create functions using table items that the function creator does not need to reference, such as employee personal information, which can cause control problems.
[0020] (solution) For this reason, the information processing device of the embodiment limits the table items that the function setter can use in a function to the item usage rights granted by the security setter. That is, on the function registration screen, registration is possible by writing a query in a text box, but table items to be used in a function are selected from a list displayed on the screen and placed in the text box. In this way, by limiting the table items displayed in the table item list on the function registration screen to the item usage rights granted to the function setter by the security setter, the table items that the function setter can use can be restricted.
[0021] FIG. 2 is a diagram showing an example of setting table field usage permissions that can be used in functions. In the example of FIG. 2, function configurator A has field usage permissions set for all fields, including voucher number, sales amount, and adjustment amount, while function configurator B has field usage permissions set for only voucher number. In this case, as shown in FIG. 3(a), all fields, including voucher number, sales amount, and adjustment amount, are displayed on the function registration screen for function configurator A. In contrast, as shown in FIG. 3(b), only the voucher number field is displayed on the function registration screen for function configurator B.
[0022] In Figure 3, when you drag and drop an item from the table item list, the item name is displayed on the function registration screen. To prevent the user from manually entering unavailable items and to check when registering, the item is stored in the usage list in memory at the time of drag and drop.
[0023] (Task 2) We want to prevent function creators from operating functions outside of their scope of work. If no permissions are set for currently registered functions, there is a risk that functions outside of their scope of work will be modified. Also, if a large number of functions are registered, a mistaken operation may result in the wrong function being modified, which could lead to malfunctions.
[0024] (solution) For this reason, the information processing device of the embodiment provides a function that grants function modification authority to a function setter. In other words, when the function setter launches the function selection screen, only functions for which the function setter has function modification authority are displayed. To modify a function, the function selection screen must be launched, and only by selecting the function to be modified from this function selection screen can the function registration screen be displayed. For this reason, functions that are not displayed on the function selection screen (functions for which the function setter does not have function modification authority) be made unmodifiable.
[0025] Figure 4 is a diagram showing the modification authority for each function set for each function setter. In the example of Figure 4, function setter A is given modification authority for each of the functions Sales Amount (Adjusted), Sales Analysis Index, and Sales Analysis Index, while function setter B is given modification authority only for the function Sales Amount (Adjusted).
[0026] In this case, when a function selection screen for selecting a function to modify is displayed to function setter A, as shown in Figure 5(a), the names of the functions for sales amount, sales analysis index, and sales analysis index are displayed. In contrast, when a function selection screen is displayed to function setter B, as shown in Figure 5(b), only the function name for sales amount (adjusted), which he or she has modification authority over, is displayed. This makes it possible to set modification authority for each function for each function setter.
[0027] (Assignment 3) When considering security, functions should be considered as completely separate items, different from the table items they contain. When referencing business data using extraction definitions, security for functions should be set on a function-by-function basis, independent of the security settings for the table items included in the function. For example, consider the requirements of "when an extraction definition user wants to output a function even though they do not have permission to use the table items included in the function," and "when an extraction definition user does not want to output a function even though they have permission to use all the table items included in the function."
[0028] (solution) In cases like this, it is possible to grant permission to use items not only on a table item basis but also on a function basis. This allows the permission to use table items and functions to be managed separately, enabling flexible security settings such as allowing or prohibiting the viewing of only the processing results of functions.
[0029] Figure 6(a) shows an example in which extraction definition user A is not given permission to use the fields voucher number, sales amount, and adjustment amount, but is given permission to use only the function sales amount (adjusted). In this case, as shown in Figure 6(b), extraction definition user A can only view the definition execution results of the function sales amount (adjusted). Figure 6(a) also shows an example in which extraction definition user B is given permission to use the fields voucher number, sales amount, and adjustment amount. In this case, extraction definition user B can view the definition execution results of the fields voucher number, sales amount, and adjustment amount, but cannot view the function sales amount (adjusted), as shown in Figure 6(c).
[0030] (Assignment 4) Once an extraction definition containing a function begins to be used, the person who set the function may not want the function to be changed, even if they have the authority to modify that function. For example, if the function's description is changed due to an operational error by the person who set the function, the extraction results of the extraction definition that uses that function may change, which could cause problems. Also, when modifying a function that is used in multiple definitions, problems may arise, such as the function working properly in one definition but not in the other definitions.
[0031] Although it is possible to grant permission to make changes whenever the function content is revised, or to revoke permission after use has begun, this would impose an operational burden on the security administrator and would likely be intolerable from an operational standpoint. For the same reason, even the creator of an extraction definition should not be allowed to modify an extraction definition once it has begun to be used.
[0032] (solution) An extraction definition lock function is provided for cases where you want to prohibit modifications to functions included in an extraction definition after the definition has been put into operation. Functions in a locked extraction definition cannot be modified even if you have modification authority; you can only query their contents. Furthermore, functions in an unlocked extraction definition can be modified if you have function modification authority.
[0033] For example, the definition creator sets the operation flag for the "Sales Information Extraction Definition," an extraction definition currently in use, to "ON" on the Extraction Definition Operation Bulk Settings screen, as shown in Figure 7. As a result, when the function "Sales Amount (Adjusted)" included in the extraction definition "Sales Information Extraction Definition," as shown in Figure 8(a), is selected, it will be launched in inquiry mode only for all function creators, as shown in Figure 8(b), and modifications will be prohibited. Note that launching in inquiry mode is permitted so that the contents of the function description can be confirmed.
[0034] Additionally, if a function needs to be modified due to an item revision or malfunction, the extraction definition can be unlocked. By setting the operational flag to "OFF," the function setter who has the authority to modify the functions included in the extraction definition can modify the functions.
[0035] (Hardware configuration) As shown in FIG. 9, an information processing device 1 according to an embodiment includes a storage unit 2, a control unit 3, a communication interface unit 4, and an input / output interface unit 5. An input device 6 and an output device 7 are connected to the input / output interface unit 5. The output device 7 may be a display unit such as a monitor (including a home television), a printer, or a speaker. The input device 6 may be a keyboard, a mouse, a microphone, or a monitor that cooperates with a mouse to provide a pointing device function. The communication interface unit 4 is connected to a network, such as a wide area network like the Internet or a private network like a LAN (Local Area Network).
[0036] A storage device such as a ROM (Read Only Memory), a RAM (Random Access Memory), an HDD (Hard Disk Drive), or an SSD (Solid State Drive) can be used as the storage unit 2. The storage unit 2 stores an information processing program that ensures security and strengthens control of functions set as output items of definitions.
[0037] The storage unit 2 also has a user group master 11, a user group member master 12, a user master 13, an item group master 14, an item group member master (for item dictionary) 15, and an item dictionary master 16, each of which is a storage area.
[0038] The storage unit 2 also includes storage areas such as an item group member master (for functions) 17, a function master 18, a function parameter master 19, an item security setting master 20, a system administrator master 21, an extraction definition header storage unit 22, an extraction definition output detail data storage unit 23, and an item usage list 24.
[0039] The user group master 11 stores user group identification information (user group ID) of the sales function setter G, sales definition creator G, sales definition user G (sales department), and sales definition user G (other department), as shown in Figure 10(a).
[0040] The user master 13 stores the user IDs and responsible image descriptions of the function setter, extraction definition creator, extraction definition user (sales department), extraction definition user (accounting department), and security setter, as shown in Figure 10(c).
[0041] As shown in FIG. 10(b), the user group member master 12 stores the above-mentioned user group IDs and user IDs in association with each other.
[0042] As shown in FIG. 11(a), the item group master 14 stores general sales items G and internal sales items G as item group IDs. As shown in FIG. 11(c), the item dictionary master 16 stores table names, item names, item types, and system classifications in association with each other. The example in FIG. 11(c) is an example in which the slip number, product code, quantity, cost, list price, tax classification, sales amount, and adjustment amount are each associated with the table name of the sales data. The item types are "character" for the slip number and product code, and "numeric" for the quantity, cost, list price, tax classification, sales amount, and adjustment amount. Furthermore, the system classifications are all "sales."
[0043] As shown in FIG. 11(b), the item group member master (for item dictionary) 15 stores the above-mentioned item group IDs, table names, and item names in association with each other.
[0044] As shown in Fig. 11(d), item group IDs and function names are associated and stored in the item group member master (for functions) 17. In the example of Fig. 11(d), the item group ID of general sales item G is associated with the function name of sales amount (adjusted), and the item group ID of internal sales item G is associated with the function name of sales analysis index.
[0045] As shown in Figure 11(e), the function master 18 stores the function name, function content, function value type, system classification, and description, each associated with the other. The example in Figure 11(e) is an example in which, for sales amount (adjusted), the function content is "{item: 1}-{item: 2}", the function value type is "numeric", the system classification is "sales", and the description is "expected for use in other departments." Also, the example in Figure 11(e) is an example in which, for a sales analysis index, the function content is "analysis function ({item: 1})", the function value type is "numeric", the system classification is "sales", and the description is "used within the sales department."
[0046] As shown in Figure 11(f), the function parameter master 19 stores function names, item sequence numbers (item SEQ), table names, and item names, each associated with the other. Figure 11(f) shows an example where the item SEQ for sales amount (adjusted) is "1", the table name is "sales data", and the item name is "sales amount". Figure 11(f) also shows an example where the item SEQ for sales amount (adjusted) is "2", the table name is "sales data", and the item name is "adjusted amount". Figure 11(f) also shows an example where the item SEQ for sales analysis indicators is "1", the table name is "sales data", and the item name is "product code".
[0047] Since functions have different primary keys from table items and security management is performed separately from table items, tables for functions are provided as shown in FIGS. 11(d) to 11(f).
[0048] As shown in Fig. 14, the item security setting master 20 stores item group IDs, user group IDs, and security flags in association with each other. Fig. 14 shows an example in which a security flag of "true: permitted" is set for a sales general item G and a sales function setter G, and a security flag of "true: permitted" is set for a sales general item G and a sales definition creator G. Fig. 14 also shows an example in which a security flag of "true: permitted" is set for a sales general item G and a sales definition user G (sales department), and a security flag of "true: permitted" is set for a sales general item G and a sales definition user G (other department).
[0049] Also, Figure 14 shows an example in which a security flag of "true: allowed" is set for the sales internal item G and the sales function setter G, a security flag of "true: allowed" is set for the sales internal item G and the sales definition creator G, and a security flag of "true: allowed" is set for the sales internal item G and the sales definition user G (sales department).
[0050] The system administrator master 21 stores user IDs and system classifications in association with each other, as shown in Fig. 15. Fig. 15 shows an example in which the system classification of "sales" is set for the user ID of a "security administrator."
[0051] The extraction definition header storage unit 22 stores definition names, job IDs, and operation flags, each associated with the other, as shown in Figure 12(a). Figure 12 shows an example in which a job ID of "JobA" and an operation flag of "true (ON)" are set for the definition name of "sales information extraction definition." By setting the operation flag to "ON," it is possible to prevent changes to the items in the search definition and the contents of the function after the search definition begins operation, even if the user has the authority to modify the function.
[0052] As shown in Fig. 12(b), the extraction definition output detail data storage unit 23 stores definition names, sequence numbers (SEQ), table names, item names, and function names, each associated with the other. In Fig. 12(b), the "sales information extraction definition" with sequence number "1" has a table name of "sales data" and an item name of "slip number." In the example of Fig. 12(b), the "sales information extraction definition" with sequence number "2" has a table name of "sales data" and an item name of "product code," and the "sales information extraction definition" with sequence number "3" has a table name of "sales data" and an item name of "quantity."
[0053] In the example of Figure 12(b), the "sales information extraction definition" with sequence number "4" has a table name of "sales data" and an item name of "cost," while the "sales information extraction definition" with sequence number "5" has a table name of "sales data" and an item name of "list price." In the example of Figure 12(b), the "sales information extraction definition" with sequence number "6" has a table name of "sales data" and an item name of "tax category," while the "sales information extraction definition" with sequence number "7" has a function name of "sales amount (adjusted)."
[0054] In the example of Figure 12(b), the "sales information extraction definition" with sequence number "8" has a table name of "sales data" and an item name of "sales amount," while the "sales information extraction definition" with sequence number "9" has a table name of "sales data" and an item name of "adjustment amount." Also, in the example of Figure 12(b), the "sales information extraction definition" with sequence number "10" has a function name of "sales analysis index."
[0055] Figure 13 shows an example of expected operations for each user. Figure 13(a) shows an example of functions that each user is permitted to use in the case of an extraction definition output job. In Figure 13(a), function setters in the sales function setter group are not permitted to use the functions and table items in the sales general item group and the functions and table items in the sales internal item group. Extraction definition creators in the sales definition creator group are permitted to use both the functions and table items in the sales general item group and the functions and table items in the sales internal item group.
[0056] Additionally, extraction definition users in the Sales definition user group (Sales department) are permitted to use both the functions and table items in the Sales general item group and the functions and table items in the Sales internal item group. Extraction definition users in the Sales definition user group (Other departments) (Accounting department) are permitted to use the functions and table items in the Sales general item group, but are not permitted to use the functions and table items in the Sales internal item group. Security administrators are permitted to use both the functions and table items in the Sales general item group and the functions and table items in the Sales internal item group.
[0057] Figure 13(b) shows an example of functions and table items that each user is permitted to use in the case of a function setting job. In Figure 13(b), function setters in the sales function setter group are permitted to use the functions and table items in the sales general item group and the functions and table items in the sales internal item group on the function selection screen (functions only) and function registration screen (items other than functions only) when they are unlocked (see Figure 12(a)).
[0058] In addition, the extraction definition creator in the sales definition creator group, the extraction definition user (sales department) in the sales definition user group (sales department), and the extraction definition user (accounting department) in the sales definition user group (other department) are not granted permission to execute jobs, and therefore cannot execute function settings.
[0059] In addition, security administrators are permitted to use the functions and table items in the general sales items group and the functions and table items in the internal sales items group on the function selection screen (functions only) and function registration screen (items other than functions only).
[0060] 3, the item names selected by the user from the table item list on the function registration screen and dragged and dropped into the function description area are stored in a list in the item usage list 24. This prevents the user from having to manually input unavailable items, and also allows the user to refer to this item usage list when the function registration button is operated to check whether there are any unavailable functions or table items.
[0061] (Functional configuration of information processing device) Next, the control unit 3 executes the information processing program stored in the storage unit 2, thereby functioning as a display control unit 31 and a determination unit 32, as shown in FIG.
[0062] The display control unit 31 functions as an item display control unit 33, a function description area display control unit 34, a definition execution result display control unit 35, a function name display control unit 36, and the like.
[0063] The item display control unit 33 displays the item names of the data items stored in the storage unit on the display unit (see FIGS. 3(a) and 3(b)).
[0064] When a desired item name is selected from the displayed item names and placed in the function description area, which is an area for describing functions provided on the display unit (output device 7), the function description area display control unit 34 displays the selected item name in the function description area (see Figures 3(a) and 3(b)).
[0065] Each item is stored with usage authority information indicating whether it is permitted to use the item when describing a function for each user (see FIG. 2). When displaying the item names, the item display control unit 33 refers to the storage unit to extract the item names of items that the user is permitted to use and displays them on the display unit (see FIGS. 3(a) and 3(b)).
[0066] The memory unit also stores usage permission information for each user for items, as well as usage permission information indicating whether each user can use a function. The item display control unit 33 refers to the memory unit, extracts the item names of items and function names that the user is permitted to use, and displays them on the display unit (see Figure 6(a)).
[0067] The storage unit also stores the function name of each function, with function modification authority information indicating whether the function can be modified for each user (see FIG. 4). When modifying a function, the function name display control unit 36 displays the names of functions on the display unit to allow the user to select the function to be modified, and at this time, references the storage unit and displays on the display unit the function names of functions that the user is permitted to modify (see FIGS. 5(a) and 5(b)).
[0068] The storage unit also stores in-operation flag information that controls ON / OFF of operation of extraction definitions that include desired output items that cannot be modified (see FIG. 7). When a user selects a function name displayed on the display unit and specifies modification of the corresponding function, the determination unit 32 refers to the storage unit and determines whether or not in-operation flag information exists for the function name of the function specified for modification.
[0069] If the discrimination unit 32 obtains a discrimination result indicating that the operation flag information of the extraction definition header that includes the function specified for modification as an output item is "ON", the function name display control unit 36 displays the function specified for modification in the function description area in an unmodifiable but referenceable state (see Figure 8(b)).
[0070] (Operation of information processing device) Next, the information processing device 1 according to the embodiment executes the following business flows 1 to 5. The business flows 1 to 5 are executed by the control unit 3 based on the information processing program stored in the storage unit 2.
[0071] (Business flow 1) First, the security administrator registers the item group to which the table items and function items belong, as shown in Fig. 16. Fig. 16 shows an example of registering items (product code, quantity, sales amount (adjusted)) to the item group "general sales items G." In this case, the item display control unit 33 references the item dictionary master 16 and the function master 18, and displays a list of registration candidates for the item group "general sales items G" on the item group registration screen. The item display control unit 33 also references the item group member master (for item dictionary) 15 and the item group member master (for functions) 17, and displays the item name of "slip number," which has already been registered, in the item member list on the item group registration screen.
[0072] The security administrator can display the desired item in the item member list by operating the "> key (add key)" displayed on the item group registration screen to move the item from the candidate list to the item member list, and the "< key (return key)" to return the item from the item member list to the candidate list. Then, the security administrator operates the registration button on the item group registration screen.
[0073] The control unit 3 newly registers (stores) each item newly added to the item member list in the item group member master (for item dictionary) 15 and the item group member master (for functions) 17. Since the item group member master (for functions) 17 is provided in addition to the item group member master (for item dictionary) 15, it is possible to perform security control on functions separately from items.
[0074] Next, the security setter registers the user group to which the user belongs, as shown in FIG. 17. In the example shown in FIG. 17, a new user group for "Sales Function Setter G" is created and the user "Function Setter A" is added to the group. In this case, the display control unit 31 refers to the user master 13 and displays a list (candidate list) of user IDs that are candidates for registration of user members on the user group registration screen. In addition, the display control unit 31 refers to the user group member master 12 and displays the registered user IDs of user members in the user member list on the user group registration screen. However, in this example, the registered user IDs are not registered in the user group member master 12, so the registered user IDs are not displayed in the user member list.
[0075] The security administrator operates the "> key (add key)" and "< key (back key)" displayed on the user group registration screen to display the desired user ID in the user member list. Then, the administrator operates the registration button on the user group registration screen. The control unit 3 newly registers (stores) the user ID of the user newly added to the user member list in the user group member master 12.
[0076] Next, the security administrator associates the created item groups with user groups, as shown in Figure 18. The user groups associated with the item groups can be set to allow or deny access to table items and functions, controlling the access rights to use the functions and the access rights to modify the functions.
[0077] 18 is a diagram showing an example of registration that grants the user group of "Sales Function Setter G" permission to use table items and functions belonging to an item group and permission to modify the functions. In this case, the display control unit 31 references the user group master 11 and displays user group IDs that are security setting candidates in the candidate list on the item security registration screen. In addition, the display control unit 31 references the item security setting master 20 and displays registered user group IDs in the security setting list on the item security registration screen.
[0078] The security administrator operates the "> key (add key)" and "< key (back key)" displayed on the item security registration screen to display the desired user group ID in the security settings list. In addition, the security administrator sets a security flag indicating "allow" or "deny" the use of "Sales Internal Item G" for each user group ID displayed in the security settings list.
[0079] The security configurator then operates the registration button on the item security registration screen. The control unit 3 newly registers (stores) the item group ID, user group ID, and security flag of the "Sales Function Configurator Group" added to the security settings list in the item security setting master 20. Note that the example in Fig. 18 is an example in which the user group of "Sales Function Configurator G" is granted (true) authority to use table items and functions belonging to the item group and authority to modify the functions.
[0080] (Business flow 2) Next, the function setter creates and registers a new function as shown in Fig. 19. The example in Fig. 19 is an example in which function setter A creates a new function for "adjustment rate." In this case, the function name display control unit 36 references the function master 18 and the item security setting master 20, and displays on the function selection screen the function names of the functions for sales amount (adjusted) and sales analysis indexes for which function modification authority is set for the sales function setter group.
[0081] Furthermore, the function name display control unit 36 refers to the extraction definition header storage unit 22 and the extraction definition output detail data storage unit 23, and functions whose operation flag in the extraction definition header is ON cannot be modified even if selected, and all function setters can only view them in inquiry mode.
[0082] Next, when the function setter selects the function to be operated on this function selection screen and operates the "Next" button, the item display control unit 33 transitions the screen to the function registration screen shown in Fig. 20. This allows the creation or modification of a function.
[0083] The item display control unit 33 refers to the item dictionary master 16 and the item security setting master 20, and displays in the table item list those table items for which the function setter has item usage authority. Therefore, table items for which the function setter does not have item usage authority are not displayed, preventing inconvenience when used to create a function.
[0084] The function setter selects the desired table item from the table item list and places it in the function description area of the function registration screen. That is, the function setter selects the desired table item from the table item list and performs a drag-and-drop operation into the function description area of the function registration screen. As a result, the function description area display control unit 34 displays the table item name on the function registration screen.
[0085] Furthermore, the control unit 3 stores the item in the item use list 24 at the timing of the drag-and-drop operation, and at the time of registration, uses this to check whether the table item to be registered is a table item for which the function setter has item use authority. This prevents the inconvenience of the function setter manually entering and illegally registering a table item that is unavailable to the function setter.
[0086] After writing the function, the function setter operates the registration button on the function registration screen. As a result, in this example, the function content, function value type, and system classification of the function with the function name "adjustment rate" are newly registered (stored) by the control unit 3 in the function master 18. In addition, the control unit 3 newly registers the item sequence, table name, and item name of the function with the function name "adjustment rate" in the function parameter master 19.
[0087] (Workflow 3) Next, when a new function is created, the security administrator must set security again for the function (the same applies when a table item is added: item group registration, item security registration). For this reason, the security administrator registers the item groups to which the table items and function items belong, as shown in Figure 21.
[0088] 21 shows an example in which a newly created function "adjustment rate" is assigned to the item group "general sales item group." In this case, the item display control unit 33 references the item dictionary master 16 and the function master 18, and displays the item names of table items and functions that are candidates to be assigned to the item group "general sales item group" in the candidate list on the item group registration screen.
[0089] In addition, the item display control unit 33 refers to the item group member master (for item dictionary) 15 and the item group member master (for functions) 17, and displays the item names of table items and functions that have already been registered for the item group "General Sales Item Group" in the item member list on the item group registration screen.
[0090] The security administrator operates the "> key (add key)" and "< key (back key)" displayed on the item group registration screen to display the desired table item and function name (in this example, the adjustment rate) in the security setting list. Then, the security administrator operates the registration button on the item group registration screen. As a result, the control unit 3 associates the function name of each function on the item member list with the "sales general item group" and newly registers (stores) it in the item group member master (for functions). As shown in Figure 14, the association between the function administrator and definition user has already been completed in the item security setting master for the sales general item group. Therefore, by assigning a newly created function (adjustment rate) to the sales general item group, it is possible to enable the use of the function (adjustment rate) by users associated with that item group.
[0091] (Workflow 4) Next, the extraction definition creator adds the "adjustment rate" function as an output item of the extraction definition. In this case, the item display control unit 33 references the function master 18 and the item dictionary master 16 as shown in Fig. 22, and displays the output items of the "sales information extraction definition" that correspond to the item usage authority of the extraction definition creator in the candidate list on the extraction definition creation screen. In the example of Fig. 22, the slip number, product code, sales amount, and the item name of the adjustment rate created this time are displayed as the output items of the "sales information extraction definition" that correspond to the item usage authority of the extraction definition creator.
[0092] The item display control unit 33 also references the extraction definition output detail data storage unit 23 and displays the output items that have been registered as output items of the "sales information extraction definition" in the output item list on the extraction definition creation screen. The example in Fig. 22 shows the sales amount, adjustment amount, and sales analysis index displayed as the output items that have been registered for the "sales information extraction definition."
[0093] The extraction definition creator operates the ">" key (add key) and the ">" key (back key) displayed on the extraction definition creation screen to display the item name of the desired function (in this example, adjustment rate) in the output item list. The extraction definition creator then operates the registration button on the extraction definition creation screen. As a result, the control unit 3 registers (stores) the function name "adjustment rate" newly added to the output item list in the extraction definition output detail data storage unit 23 as an output item of the "sales information extraction definition."
[0094] Next, when the extraction definition creator starts using the created "sales information extraction definition," they set the operation flag for the "sales information extraction definition" to "ON" (the default is "OFF"), as shown in Figure 23. This changes the operation flag for the "sales information extraction definition" on the extraction definition header from "false" to "true," as shown in Figure 23.
[0095] If a function modification is specified after the operation flag has been changed to "true," the function name display control unit 36 prohibits modification even by the function setter or extraction definition creator who has the authority to modify the function. Figure 24(a) shows a state in which modification of the extraction definition is prohibited in inquiry mode when the extraction definition creator uses Extraction Definition Creation when the operation flag in the extraction definition header is "true." Figure 24(b) shows a state in which modification of the function is prohibited in inquiry mode when the function setter uses Function Configuration when a function is used in an extraction definition whose operation flag in the extraction definition header is "true."
[0096] (Workflow 5) Next, the extraction definition user uses the extraction definition in operation to output and view data. The extraction definition user references information within the scope of their own authority. Specifically, assume that the extraction definition user specifies the sales information extraction definition in operation, as shown in Figure 25(a), on the extraction definition output screen, as shown in Figure 25(c). The definition execution result display control unit 35 controls the output by determining whether or not the user has permission to use the item for each output column. Items for which the user does not have permission are excluded from the output columns of the output results.
[0097] Figure 25(b) shows an example in which an extraction definition user belonging to the sales definition user group (sales department) has item usage authority for the functions and table items of "general sales items G" and "internal sales items G." In this case, the definition execution result display control unit 35 displays the voucher number, tax category, sales amount (adjusted), and number of vouchers based on the functions and table items of "general sales items G," as shown in Figure 25(d). At the same time, the definition execution result display control unit 35 displays the sales amount, adjustment amount, sales analysis index, and adjustment rate based on the functions and table items of "internal sales items G," as shown in Figure 25(d).
[0098] In contrast, extraction definition users who belong to the sales definition user group (other departments) have item usage authority for the functions and table items of "sales general items G," but do not have item usage authority for the functions and table items of "sales internal items G." Therefore, the definition execution result display control unit 35 displays the voucher number, tax category, sales amount (adjusted), and number of vouchers based on the functions and table items of "sales general items G," as shown in Figure 25(e), and does not display the sales amount, adjustment amount, sales analysis index, and adjustment rate based on the functions of "sales internal items G."
[0099] This allows you to control the table item string to be output based on the item usage permissions (security control can also be performed on functions separately from table items).
[0100] (Permission decision logic) Regardless of the type of function modification authority or item usage authority, the determination method is the same in all of the following cases. 1. When obtaining a list of functions that can be modified on the function selection screen (determining function modification authority) 2. When obtaining table fields that can be used on the function registration screen (determining field usage permissions) 3. When obtaining displayable items when creating an extraction definition (determining item usage permissions) 4. When obtaining items that can be output in the extraction definition output (determining item usage permissions)
[0101] When determining function modification authority or item use authority, in step S1 of the flowchart in Fig. 26, the determination unit 32 determines whether data for the user ID of the logged-in user exists in the system administrator master 21. If the user ID of the logged-in user exists in the system administrator master 21 (step S1: Yes), the determination unit 32 determines that "the logged-in user always has authority over all items in the item dictionary and functions managed by sales."
[0102] On the other hand, if the user ID of the logged-in user does not exist in the system administrator master 21 (step S1: No), the discrimination unit 32 proceeds to step S2. In step S2, the discrimination unit 32 determines whether the number of items that can be acquired from the item security master for the combination of the item group member to which the judgment item belongs and the user group member to which the user ID of the logged-in user belongs is "1 item (number of items = 1)," "less than 1 item, 0 items (number of items = 0)," or "2 items or more (number of items > 1)."
[0103] If the number of records that can be acquired from the item security master is one (number of records = 1), the setting of the security flag for that record is followed. That is, the determination unit 32 determines that the user has authority if the security flag is "true," and determines that the user does not have authority if the security flag is "false."
[0104] Furthermore, if the number of items that can be acquired from the item security master is 0 (number of items=0), the determination unit 32 determines that the user has "no authority" for the check item.
[0105] If the number of records that can be acquired from the item security master is two or more (number of records > 1), the discrimination unit 32 determines that the user is "not authorized" for the judgment item if there is even one record with security flag = Deny. If there are only records with Permit, the discrimination unit 32 determines that the user is "Authorized."
[0106] 27(a) shows a case where the judgment item belongs to multiple item groups. In this case, the security flag for "internal sales item G" is "false," so the discrimination unit 32 determines that the user does not have authority for the judgment item "adjustment rate" (denial priority).
[0107] 27(b) shows a case where a user belongs to multiple user groups. In this case, the security flag for "Sales definition user G (other department)" is "false," so the discrimination unit 32 determines that the user has "no authority" for all items in "Sales general item G" (denial takes precedence).
[0108] (Effects of the embodiment) As is clear from the above description, the information processing device according to the embodiment can achieve the following effects.
[0109] 1. In an embodiment, an information processing device limits the table items that a function setter can use in a function to the item usage rights granted by the security setter. That is, on the function registration screen, a query can be entered in a text box to register the function, but table items to be used in the function are selected from a list displayed on the screen and placed in the text box. In this way, by limiting the table items displayed in the table item list on the function registration screen to the item usage rights granted to the function setter by the security setter, the table items that the function setter can use can be restricted. This ensures security and strengthens control of functions set as output items of definitions.
[0110] 2. Furthermore, the information processing device of the embodiment provides a function that grants function modification authority to a function setter. That is, when the function setter launches the function selection screen, only functions for which the function setter has function modification authority are displayed. To modify a function, the function selection screen must be launched, and the function registration screen can only be accessed by selecting the function to be modified from this function selection screen. Therefore, functions that are not displayed on the function selection screen (functions for which the function setter does not have function modification authority) can be made unmodifiable.
[0111] 3. Furthermore, the information processing device of the embodiment allows item usage authorization to be granted not only on a table item basis but also on a function basis. This allows the usage authorization for table items and functions to be managed separately, enabling flexible security settings such as allowing or prohibiting the viewing of only the processing results of functions.
[0112] 4. The definition creator sets the operation flag information of the extraction definition header that includes the desired function as an output item to "ON." This allows only the launch of inquiry mode even when the function setter selects that function, and makes it impossible to modify any items on the screen. This ensures security and strengthens control of functions set as output items of the definition.
[0113] [Contribution to the United Nations-led Sustainable Development Goals (SDGs)] The present invention can contribute to improving business efficiency and promoting appropriate management decisions by companies, thereby contributing to SDGs Goals "8" and "9."
[0114] Furthermore, the present invention can contribute to reducing waste and promoting paperless and electronic systems, thereby contributing to SDGs Goals 12, 13, and 15.
[0115] Furthermore, the present invention can contribute to strengthening control and governance, thereby contributing to SDG Goal 16.
[0116] [Other embodiments] The present invention can be implemented in various different forms other than the above-described embodiments within the scope of the technical concept described in the claims.
[0117] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically may be performed manually, or all or part of the processes described as being performed manually may be performed automatically using a known method or the like.
[0118] Furthermore, the processing procedures, control procedures, specific names, registered data for each process, information including parameters such as search conditions, screen examples, and database configurations shown in the specification or drawings may be changed as desired unless otherwise specified.
[0119] Furthermore, the components of the information processing device 1 shown in the figures are conceptual functional elements and do not necessarily have to have the physical configuration shown in the figures. For example, all or any part of the processing functions of the information processing device 1, particularly the processing functions performed by the control unit 3, may be realized by a program interpreted and executed by the control unit 3 (CPU: Central Processing Unit), or may be realized by hardware using wired logic.
[0120] The program is recorded on a non-transitory computer-readable recording medium containing programmed instructions for causing the information processing device to execute the processes described in the embodiments, and is mechanically read by the information processing device 1 as needed. That is, a computer program is recorded in the storage unit 2, such as a ROM or HDD, for working with an OS (Operating System) to give instructions to a control unit 3 (CPU) and perform various processes. The computer program is loaded into RAM, expanded, and executed by the control unit 3 as appropriate.
[0121] Furthermore, the information processing program of the information processing device 1 may be stored in another server device connected to the information processing device 1 via any network, and all or part of it may be downloaded and executed as needed.
[0122] Furthermore, the information processing program for executing the processes described in the embodiments may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product.
[0123] Here, the "recording medium" can be any "portable physical medium" such as a memory card, a USB (Universal Serial Bus) memory, an SD (Secure Digital) card, a flexible disk, a magneto-optical disk, a ROM, an EPROM (Erasable Programmable Read Only Memory), an EEPROM (registered trademark) (Electrically Erasable and Programmable Read Only Memory), a CD-ROM (Compact Disk Read Only Memory), an MO (Magneto-Optical Disk), a DVD (Digital Versatile Disk), and a Blu-ray (registered trademark) Disc.
[0124] Furthermore, a "program" is a data processing method written in any language or description method, regardless of the format, such as source code or binary code.
[0125] It should be noted that a "program" is not necessarily limited to a single structure, but includes a structure that is distributed as multiple modules or libraries, and a structure that achieves its function by working together with other programs, such as an OS.
[0126] Furthermore, the specific configuration for reading the recording medium in the information processing device 1 of the embodiment, the reading procedure, and the installation procedure after reading can be realized using well-known configurations or procedures.
[0127] The memory unit 2 is a storage means such as a memory device such as RAM or ROM, a fixed disk device such as a hard disk, a flexible disk, or an optical disk, and stores various programs, tables, databases, web page files, etc. used for various processes or providing websites.
[0128] The information processing device 1 may be configured as an information processing device such as a known personal computer or workstation, or may be configured as an information processing device connected to any peripheral device. The information processing device may also be implemented with software (including programs or data) that realizes the processes described in the embodiments.
[0129] Furthermore, the specific forms of distribution and integration of the devices are not limited to those shown in the drawings, and all or part of them can be functionally or physically distributed or integrated in any unit depending on various additions or functional loads. In other words, the above-mentioned embodiments can be selectively implemented by combining them in any way. [Industrial Applicability]
[0130] The present invention is suitable for application to, for example, application program development work, and is particularly suitable for application to work requiring restrictions on the use and modification of functions. [Explanation of symbols]
[0131] 1. Information processing equipment 2 Storage section 3. Control Unit 4. Communication interface section 5 Input / output interface section 6 Input Devices 7 Output Devices 11 User Group Master 12 User Group Member Master 13 User Master 14 Item Group Master 15 Item group member master (for item dictionary) 16-item dictionary master 17 Item Group Member Master (for functions) 18 Function Master 19 Function Parameter Master 20 Item Security Setting Master 21 System Administrator Master 22 Extraction definition header storage section 23 Extraction definition output detail data storage section 24-item usage list 31 Display control unit 32 Discrimination part 33 Item display control section 34 Function description area display control section 35 Definition execution result display control section 36 Function name display control section
Claims
1. an item display control unit that displays on a display unit the item names of the data items stored in the storage unit; a function description area display control unit that, when an operation of selecting a desired item name from the displayed item names and placing it in a function description area provided on the display unit, displays the selected item name in the function description area, Each of the items is stored with usage authority information indicating whether or not the item can be used when describing a function, for each user. the item display control unit refers to the storage unit when displaying the item names, extracts the item names of the items that the user is permitted to use, and displays the item names on the display unit; An information processing device characterized by:
2. the storage unit stores usage authority information for each user regarding the items, as well as usage authority information indicating whether or not each user is allowed to use the functions; the item display control unit refers to the storage unit, extracts the item names of the items and the function names of the functions that the user is permitted to use, and displays them on the display unit; 2. The information processing device according to claim 1,
3. a function name display control unit that displays, on the display unit, function names for selecting a function to be modified when the function is modified; the function name display control unit, when displaying the function name of the function to be modified on the display unit, refers to the storage unit and displays on the display unit the function names of functions that the user is permitted to modify; 3. The information processing device according to claim 2, wherein:
4. In the storage unit, operation flag information indicating whether the function is in operation is added to the function name of each of the functions, a determination unit that, when the user selects the function name displayed on the display unit and specifies modification of the corresponding function, references the storage unit and determines whether or not the in-operation flag information exists for the function name of the function specified for modification, when a determination result indicating that the in-operation flag information is added to the function name of the function for which modification is specified is obtained, the function name display control unit displays the function for which modification is specified in the function description area in an unmodifiable but referable state; 4. The information processing device according to claim 3,
5. an item display control step in which an item display control unit displays on a display unit the item names of the data items stored in the storage unit; a function description area display control step in which, when an operation is performed in which a desired item name is selected from the displayed item names and placed in a function description area provided on the display unit, the selected item name is displayed in the function description area, Each of the items is stored with usage authority information indicating whether or not the item can be used when describing a function, for each user. In the item display control step, when the item names are displayed, the storage unit is referenced to extract the item names of the items that the user is permitted to use and display them on the display unit; An information processing method comprising:
6. Computer, an item display control unit that displays on a display unit the item names of the data items stored in the storage unit; a function description area display control unit that, when an operation of selecting a desired item name from the displayed item names and placing it in a function description area provided on the display unit, which is an area for writing a function, displays the selected item name in the function description area; Each of the items is stored with usage authority information indicating whether or not the item can be used when describing a function, for each user. the item display control unit refers to the storage unit when displaying the item names, extracts the item names of the items that the user is permitted to use, and displays the item names on the display unit; An information processing program characterized by:
Citation Information
Patent Citations
Information processing device, information processing method, and program
JP2022020487A