Important item management apparatus
The user authority setting unit in the key management device enables loaning operation authority, addressing the inconvenience of administrator absence by allowing authorized users to perform critical operations, thus enhancing convenience.
Patent Information
- Application Number
- JP2024118643
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-07-24
- Publication Date
- 2026-02-05
Smart Images

Figure 2026017719000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a valuable item management device. [Background technology]
[0002] An example of a valuable item management device is a key management device for managing various keys used in financial institutions, distribution institutions, etc. The key management device manages a plurality of key holders that hold keys in a detachable manner from the device body, and a technology has been disclosed in which, when an approval operation by an administrator other than the operator is required to remove a selected key holder, a message prompting approval from the administrator is displayed on a display unit (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2017-227010 Summary of the Invention [Problem to be solved by the invention]
[0004] In the key management device described above, some operations, such as retrieving important keys and changing registration details and settings, can be restricted to administrators only. In particular, storing or retrieving important keys may require not only authentication of the operating staff but also administrator approval. In this case, the administrator must perform the approval operation each time administrator approval is required. However, if an authorized administrator is out of the office or on vacation, these operations cannot be performed. In this way, when an authorized administrator is absent, users without the operating authority cannot perform the necessary operations, reducing convenience.
[0005] An object of the present invention is to provide a valuable item management device that can improve convenience. [Means for solving the problem]
[0006] One aspect of the present invention is characterized in that it includes a user authority setting unit that sets operation authority for each user identification information or for each authority category that includes at least one user identification information, and the user authority setting unit is capable of granting loan authority to the user identification information to be set, allowing the user identification information to be loaned operation authority to other user identification information, when setting operation authority. Another aspect of the present invention is characterized in that when an operating authority to be loaned to another user identification information is selected by an operation based on one user identification information, the system has an authority loan setting unit that loans the selected operating authority to the other user identification information. Yet another aspect of the present invention is characterized in that it has an authority lending setting unit that, when an operating authority to be loaned to an authority category is selected by an operation based on a certain user identification information, loans the selected operating authority to the user identification information included in that authority category. [Effects of the Invention]
[0007] According to the present invention, it is possible to provide a valuable item management device that can improve convenience. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a perspective view of an important item management device according to an embodiment of the present invention; [Figure 2] 1 is a front view showing an important item management device according to an embodiment of the present invention with a front cover open. [Figure 3] 1 is a perspective view showing a key and storage unit of an important item management device according to an embodiment of the present invention; [Figure 4] 1 is a block diagram of a main part of an important item management device according to an embodiment of the present invention. [Figure 5] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 6] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 7] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 8] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 9] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 10] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 11] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 12] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 13] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 14] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 15] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 16] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 17] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 18] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 19] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 20] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 21] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 22] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 23] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 24] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 25] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 26] 10 is a diagram for explaining the lending of operation authority of the important item management device according to the embodiment of the present invention. FIG. [Figure 27] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; [Figure 28] 1 is a front view showing an example of a display screen of an operation display unit of an important item management device according to an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION
[0009] An important item management device according to an embodiment of the present invention will be described below with reference to the drawings. In the following description, "front" refers to the front side in the front-to-rear direction, i.e., the front side as seen from the user, "rear" refers to the rear side in the front-to-rear direction, i.e., the back side as seen from the user, "left" refers to the left side as seen from the user, and "right" refers to the right side as seen from the user.
[0010] The important item management device 11 of this embodiment is used in, for example, the branches of financial institutions such as banks, and as shown in Fig. 1, is made up of a main unit 12 and a sub-unit 13. The sub-unit 13 is disposed on the right side of the main unit 12 and is fixed to the main unit 12. The main unit 12 has a unit body 21 and a front cover 22 that opens and closes the front side of the unit body 21.
[0011] As shown in FIG. 2, the lower front portion of the unit main body 21 constitutes an opening / closing section 31 that is opened and closed by the front cover 22. The portion of the unit main body 21 above the opening / closing section 31 constitutes an upper front surface component 32 that is not opened or closed by the front cover 22 and is always exposed, and the portion to the right of the opening / closing section 31 constitutes a right front surface component 33 that is not opened or closed by the front cover 22 and is always exposed. One end of the front cover 22 is rotatably connected to the unit main body 21 via a hinge 34 provided on the left edge of the unit main body 21, and opens and closes the front of the opening / closing section 31. A handle 35 for carrying is provided on the top surface of the unit main body 21, making the important item management device 11 portable.
[0012] The unit body 21 is provided with an IC card reader 41 on the left side of the upper front face component 32, which reads data (authentication information) from the IC chip of an IC card. The unit body 21 is provided with an operation display unit 42 (authentication unit, notification unit) on the right side of the upper front face component 32, which accepts operation inputs from the user and displays information to the user. The operation display unit 42 is a touch-panel liquid crystal display, and displays the date and time, operation status, alarm information, guidance, etc. The unit body 21 is provided with an audio output unit 43 on the right side of the operation display unit 42 on the upper front face component 32, which outputs audio to the outside. The unit body 21 is provided with a magnetic card reader 45 on the right front face component 33, which reads data (authentication information) from a magnetic card.
[0013] The subunit 13 is provided with a biometric reader 51 at its top that reads the user's biometric information. In this embodiment, finger vein information (authentication information) is read as the user's biometric information. The subunit 13 is provided with a printer unit 56 (printing unit) at its vertically middle portion that prints necessary information on paper and discharges it from a paper discharge port 55. The IC card and magnetic card are individually prepared for each person authorized to use the valuable item management device 11, and store a user ID (user identification information) or the like, which is individual user identification information for identification and authentication from others. In the following, an example will be described in which the important item management device 11 manages the key 61, but the important item management device 11 does not have to manage the key 61.
[0014] The opening / closing section 31, which is opened and closed by the front cover 22 of the unit main body 21, is provided at its front position with a plurality of storage sections 62 for storing keys 61 shown in Fig. 3, which are items to be managed, so that they can be taken out and returned. As shown in Fig. 2, the storage sections 62 are arranged in multiple positions in the left-right direction, specifically ten positions, and these ten storage sections 62 are arranged in multiple rows, specifically three rows, in the vertical direction.
[0015] The unit main body 21 is provided with a control unit 65 (user authority setting unit, authority lending setting unit, authentication unit, control unit, validity condition determination unit) shown in Figure 4 that controls the IC card reader 41, operation display unit 42, audio output unit 43, magnetic card reader 45, biometric reader 51, printer unit 56 and multiple storage units 62, and a memory unit 66 that stores various information.
[0016] As shown in Figure 3, the key 61 has a key body 71 that is inserted into a locking or unlocking target to lock or unlock it, and a key holder 72 that holds at least one key body 71. The key holder 72 is made up of a detachable member 75 and a connecting member 76 that connects the key body 71 to the detachable member 75. Each detachable member 75 has a different shape from the other detachable members 75. In other words, each of the multiple key holders 72 has a different shape from the other key holders 72. The storage unit 62 holds the detachable members 75 of the key holders 72 that correspond to each other in a locked state so that they cannot be removed.
[0017] Here, the uses of key body 71 are for opening and closing the door of a conference room, for opening and closing the door of a safe installed in a financial institution, for opening and closing the door of a cash processing machine, for opening and closing the door of a cash storage cabinet inside the door of a cash processing machine, for opening and closing the door of a collection cabinet inside the door of a cash processing machine, for switching on and off the main power supply of the cash processing machine, etc. Storage unit 62 holds key holders 72, i.e., keys 61, as storage target items (in other words, managed items).
[0018] The unit body 21 is provided with an electromagnetically driven cover lock mechanism 81 (see FIG. 2) on the right end side of the opening / closing unit 31. The cover lock mechanism 81 locks an engagement portion (not shown) of the front cover 22 when the front cover 22 is in the closed state (closing the opening / closing unit 31) as shown in FIG. 1. The cover lock mechanism 81 is controlled by the control unit 65 (see FIG. 4). The unit body 21 is provided with a full-closure detection sensor 82 (see FIG. 4) that detects whether the front cover 22 is in the fully closed state by detecting a detection portion (not shown) of the front cover 22 when the front cover 22 is in the closed state (see FIG. 1). The cover lock mechanism 81 locks (engages) the front cover 22 (locked state) (unopenable state) by, for example, locking (engaging) with an engagement portion (not shown) of the front cover 22. When the control unit 65 releases the locked state of the cover lock mechanism 81, the lock of the engagement portion of the front cover 22 by the cover lock mechanism 81 is released. As a result, the front cover 22 can be opened from the unit body 21 as shown in FIG. 2. In this embodiment, the cover lock mechanism 81 uses a spring mechanism to always keep the front cover 22 in a locked state except when the control unit 65 releases the locked state of the cover lock mechanism 81. Therefore, except when the control unit 65 releases the locked state of the cover lock mechanism 81, the cover lock mechanism 81 locks the engaging portion of the front cover 22, and as a result, the front cover 22 is locked to the unit body 21 in a closed state as shown in FIG.
[0019] As shown in FIG. 3 , each of the storage units 62 has an individual insertion hole 85 into which the detachable member 75 of the key holder 72 connected to the key body 71 is inserted and removed. The detachable member 75 is detachably attached to the storage unit 62 and locked in the attached state. Each of the storage units 62 has a sensor (not shown) that detects when the detachable member 75 is inserted into the insertion hole 85 to a predetermined attachment position, and an electromagnetically driven key lock mechanism 86 (shown in FIG. 4 ) that locks and unlocks the detachable member 75 inserted into the insertion hole 85 to the predetermined attachment position so that it cannot be removed. Each insertion hole 85 is shaped so that only the detachable member 75 that corresponds to it can be inserted to the predetermined attachment position. Therefore, even if a detachable member 75 other than the one that corresponds to it is inserted, the insertion hole 85 restricts insertion and stops the detachable member 75 before the predetermined attachment position. That is, only the insertion holes 85 and the detachable members 75 that correspond one to one can be inserted mechanically up to a predetermined mounting position (a position that can be locked by the key lock mechanism 86).
[0020] As shown in FIG. 3 , each of the storage units 62 has an operation button with lamp 91 integrated with an indicator lamp. The operation button with lamp 91 is positioned vertically adjacent to the insertion hole 85 of the same storage unit 62 and aligned with the insertion hole 85 in the left-right direction. The operation button with lamp 91 is an operation button that is pressed to release the lock by the key lock mechanism 86 shown in FIG. 4 that also constitutes the same storage unit 62. The operation button with lamp 91 shown in FIG. 3 guides operations by, for example, the color and lighting state of the lamp. Here, the lighting state of the lamp includes the lamp being off, on, and flashing. For example, the operation button with lamp 91 can be lit and flashing in blue, yellow, light blue, or white. The color of the lamp of the operation button with lamp 91 is not limited to the above. As a result, multiple operations can be guided by the color and lighting state of the lamp of the operation button with lamp 91. In the storage unit 62, for example, when an operation button 91 with a lamp that is lit in a specific color is pressed, the control unit 65 unlocks the key lock mechanism 86 of the storage unit 62 in which the operation button 91 with a lamp is provided, allowing the key holder 72 to be removed from the storage unit 62.
[0021] As shown in FIG. 3 , each of the storage units 62 has a display unit 95 that displays the storage unit identification information of the storage unit 62. The display unit 95 is provided above the lamp-equipped operation button 91 and the insertion hole 85, aligning with the insertion hole 85 of the same storage unit 62 in the left-right direction. The display unit 95 may be a recess for affixing a sticker displaying the identification information of the key 61, for example. Here, instead of displaying the identification information of the key 61 on the display unit 95, the identification information may be displayed on the surface of the lamp-equipped operation button 91. As a method for displaying the identification information on the surface of the lamp-equipped operation button 91, for example, a sticker displaying the identification information may be affixed to the surface of the lamp-equipped operation button 91. The identification information may be, for example, a number as shown in the figure, or may be, for example, a name. In the lamp-equipped operation button 91 of this embodiment, identification information (an identification number in the illustrated example) is displayed on the surface, and the lit and flashing portion of the lamp-equipped operation button 91 is provided in a frame shape surrounding the lamp-equipped operation button 91.
[0022] Each of the multiple storage units 62 has a sensor (not shown) that detects whether the detachable member 75 is present or absent in a predetermined attachment position and detects the removal and return of the key holder 72, i.e., the key 61. The important item management device 11 manages the removal and return of the keys 61 as managed items based on the detection of the sensor (not shown). That is, in one storage unit 62, when the sensor (not shown) changes from a state of detecting the detachable member 75 corresponding to that storage unit 62 one-to-one to a state of not detecting the detachable member 75, it detects that the stored key 61 including the detachable member 75 corresponding to that storage unit 62 one-to-one has been removed from the important item management device 11. Furthermore, in this storage unit 62, when the sensor (not shown) changes from this state to a state of detecting the detachable member 75 corresponding to that storage unit 62 one-to-one, it detects that the stored key 61 corresponding to that storage unit 62 one-to-one has been returned to the important item management device 11.
[0023] The control unit 65 controls the retrieval of the key 61 from the storage unit 62 and the return of the key 61 to the storage unit 62. The control unit 65 also performs a retrieval process in which related information is stored in the memory unit 66 when the key 61 is retrieved from the storage unit 62, and a return process in which related information is stored in the memory unit 66 when the key 61 is returned to the storage unit 62.
[0024] Next, the main operation of the important item management device 11 will be described.
[0025] When the important item management device 11 is in a standby state, the control unit 65 causes the operation display unit 42 to display an "operation standby screen" 100 as shown in FIG. 5. In this embodiment, the standby screen is an authentication screen for performing authentication processing using a pre-set authentication method. The important item management device 11 can perform authentication using a combination of a password and at least one of an IC card user ID, a magnetic card user ID, finger vein information (biometric information), and an input number, as authentication information, by setting the operation of the operation display unit 42. It is also possible to set the password so that it is not required to be entered. Authentication can also be performed using a combination of finger vein information (biometric information) and at least one of an IC card user ID, a magnetic card user ID, and an input number. The following description will be given taking as an example a case where authentication is performed using an account consisting of a combination of a number and a password as authentication information.
[0026] On the "operation standby screen" 100, which is a number input screen serving as an authentication screen, when a numeric input display unit 101 including a numeric keypad is touched, i.e., input, to input a number, and a "Next" button 102 is touched, i.e., input, the control unit 65 reads out an individual user ID corresponding to the input number for distinguishing the user from other users. The control unit 65 compares the read-out user ID with a list of user IDs of users who can use the important item management device 11, which is pre-stored in the storage unit 66. If the read-out user ID is not found in the list of user IDs, the authentication fails. The control unit 65 then causes the operation display unit 42 to display a message indicating that the important item management device 11 is unavailable, and the audio output unit 43 to emit an alarm for a predetermined period of time, thereby terminating the authentication process and returning the important item management device 11 to a standby state. When authentication is performed using an IC card or a magnetic card as authentication information, a guide screen (authentication screen) that prompts the user to bring the card (IC card or magnetic card) close to the IC card reader 41 or the magnetic card reader 45 may be displayed as a standby screen on the operation display unit 42. When authentication is performed using finger vein information as authentication information, a vein input screen that guides the user to input finger vein information may be displayed as a standby screen on the operation display unit 42. Here, the control unit 65, if necessary, displays a "home" button H on the display screen displayed on the operation display unit 42, which, when touched, returns the important item management device 11 to a standby state and causes the operation display unit 42 to display an "operation standby screen" 100.
[0027] If the user ID in the user ID list matches the read user ID, the control unit 65 causes the operation and display unit 42 to display a password entry screen for accepting entry of a password (authentication information). If authentication is performed using finger vein information instead of password entry, a vein entry screen for guiding the user to enter their finger vein information may be displayed. When a password is entered into the password entry screen, if the entered password corresponds one-to-one with a user ID stored in the storage unit 66, the control unit 65 authenticates the account of this user ID and password as valid, resulting in an authentication success state, and stores this user ID and authentication date and time information, which is date and time information at that time, in the storage unit 66. If the entered password does not correspond one-to-one with a user ID stored in the storage unit 66, the account authentication fails, and the control unit 65 causes the operation and display unit 42 to display a password re-entry screen to prompt the user to enter their password again. If an incorrect password is entered a predetermined number of times, the control unit 65 causes the operation display unit 42 to display a message indicating that the important item management device 11 is unusable, and causes the audio output unit 43 to emit an alarm sound for a predetermined period of time, thereby terminating the authentication process and returning the important item management device 11 to a standby state. In such an authentication failure state, the control unit 65 does not store authentication date and time information in the storage unit 66, and does not update the last operation date of the user ID. Note that there may be no limit to the number of times an incorrect password can be entered, and in this case, the important item management device 11 does not have to be unusable due to the entry of an incorrect password.
[0028] If the user ID authenticated as valid in the authentication process is a user ID capable of performing the storage unit use process, the control unit 65 may display, as a storage unit use process screen, a screen including a "Holder removal / return" button that is selected when performing either the removal process or the return process of the key 61 to the storage unit 62. When the "Holder removal / return" button is selected by touch operation on this storage unit use process screen, the control unit 65 starts the storage unit use process. If the only process that the authenticated user ID is capable of at the time of authentication is either the holder removal process or the return process, the screen including the Holder removal / return button does not need to be displayed. Note that the user IDs and the processes that each user ID is capable of are associated and stored in the memory unit.
[0029] In the storage unit use process, the control unit 65 unlocks the cover lock mechanism 81 to enable opening of the front cover 22, and reads from the memory unit 66 storage unit identification information of the storage unit 62 that is permitted to be used in the storage unit use process for the user ID that was authenticated as valid in the authentication process at the start of the storage unit use process. At the same time, the control unit 65 displays on the operation display unit 42 a storage unit use display screen that prompts input of whether to perform the process of retrieving the key 61 from the storage unit 62 or the process of returning the key 61 to the storage unit 62, and waits for selection input. If the authenticated user ID is only capable of either the holder retrieval process or the return process, the screen including the holder retrieval / return button is not displayed, and the control unit 65 does not have to wait for selection input. In this embodiment, the screen displayed during the storage unit usage process (storage unit usage display screen) includes a "Take Out" button that is touched when selecting the take-out process and a "Return" button that is touched when selecting the return process. Here, this storage unit usage display screen also includes a "Back" button. When the "Back" button is selected by touch on the storage unit usage display screen, the control unit 65 displays the previous screen, the above-mentioned "Operation Standby Screen" 100, on the operation display unit 42 and enters a state of waiting for authentication. Furthermore, when the "Home" button is touched on the operation display unit 42 while this storage unit usage display screen is displayed, the control unit 65 cancels the authentication success state at that point and returns the important item management device 11 to a standby state in which the "Operation Standby Screen" 100 is displayed on the operation display unit 42.
[0030] In addition, for all display screens displayed on the operation display unit 42, if there is a previous screen on that screen, when the ``Back'' button is selected by touch operation, the control unit 65 will display the previous screen, and if there is a next screen, when the ``Next'' button is selected by touch operation, if there is an input on that screen, the next screen will be displayed while remembering that input, and if the ``Home'' button is touched, the authentication success state will be canceled at that point and the important item management device 11 will return to the standby state.
[0031] [Removal process] The take-out operation is an operation that the user performs on the important item management device 11 when taking-out processing is performed. On the storage unit usage display screen, the "Remove" button is selected by touch operation. Then, the control unit 65 performs the removal process. If the only process available to the authenticated user ID is the holder removal process, the screen including the remove button does not need to be displayed, and the removal process may be performed without touching the "Remove" button. In the removal process, when the full-closure detection sensor 82 detects that the front cover 22 has been opened, the control unit 65 causes the lamp-equipped operation button 91 of the storage unit 62 having storage unit identification information that is permitted for use by the user ID authenticated as valid in the authentication process at the start of the removal process to flash. Then, when the lamp-equipped operation button 91 of the storage unit 62 with the key 61 is pressed among the lamp-equipped operation buttons 91 of the storage units 62 that are permitted for use and are flashing, the control unit 65 activates the key lock mechanism 86 of the storage unit 62 to unlock it. Of course, even if the operation button with lamp 91 is pressed while the light is off, the control unit 65 will not unlock the key lock mechanism 86 of the storage unit 62 to which the operation button with lamp 91 is provided.
[0032] In addition, in the removal process, if the only process that the authenticated user ID can perform is the holder removal process, the control unit 65 will drive the key lock mechanism 86 of this storage unit 62 to unlock it when the flashing operation button 91 with lamp of the storage unit 62 that has the key 61 is pressed among the operation buttons with lamps 91 of the storage units 62 that are permitted to be used, even if the ``Remove'' button on the storage unit usage display screen is not touched.
[0033] When a sensor (not shown) detects that the key holder 72, i.e., the key 61, has been removed from the storage unit 62, the control unit 65 associates operation name information indicating that a removal operation has been input, the user ID and authentication date and time information authenticated as valid in the authentication process performed at the start of the removal process, authentication identification information indicating the authentication method, and the storage unit identification information of the storage unit 62, and stores these in the storage unit 66 as removal history information, which is log information related to the current removal process. The control unit 65 stores the removal history information in the storage unit 66 as operation history, device information, and user information. The operation history is information on an operation unit basis that cumulatively records the details of each operation, and is a chronological record of the operation details. The device information is a history on an object unit basis that records the last operator and the last date and time of use for each object, such as a holder or cover. The user information is information that manages the operation authority and the last date and time of the last operation for each user. Here, when the keys 61 are retrieved from the multiple storage units 62 in one retrieval process, the control unit 65 stores the retrieval history information for each of the multiple storage units 62 in the storage unit 66 .
[0034] After storing the removal history information in the memory unit 66, when the full-closure detection sensor 82 detects that the front cover 22 has been closed, the control unit 65 cancels the authentication success state, turns off the blinking operation button 91 with lamp, and drives the cover lock mechanism 81 to lock the front cover 22 in the closed position, ending the removal process and returning the important item management device 11 to the standby state. Even during the removal process, if the "Home" button on the storage unit usage display screen is touched, the control unit 65 cancels the authentication success state at that point, turns off the blinking operation button 91 with lamp, and ends the removal process. Thereafter, when the full-closure detection sensor 82 detects that the front cover 22 has been closed, the control unit 65 drives the cover lock mechanism 81 to lock the front cover 22 in the closed position and returns the important item management device 11 to the standby state. The control unit 65 may cancel the authentication success state, for example, after a certain period of time has elapsed or by a cancel operation such as pressing the "back" button, turn off the flashing operation button 91 with lamp, and drive the cover lock mechanism 81 to lock the front cover 22 in the closed position, thereby ending the removal process and returning the important item management device 11 to the standby state.
[0035] [Return Processing] The return operation is an operation that the user performs on the important item management device 11 when the return process is performed. On the storage unit usage display screen, the "Return" button is selected by touch operation. Then, the control unit 65 performs the return process. If the return process is the only process available to the authenticated user ID, the screen including the return button does not need to be displayed, and the removal process may be performed without touching the "Remove" button. During the return process, when the full-closure detection sensor 82 detects that the front cover 22 has been opened, the control unit 65 causes the lamp-equipped operation button 91 of the storage unit 62 having the storage unit identification information of the storage unit 62 that is authorized for use by the user ID authenticated as valid in the authentication process at the start of the return process to flash. When the control unit 65 detects that a key holder 72 for a key 61 has been inserted into a storage unit 62 that does not contain a key 61 and that is permitted for use and has an operation button 91 with a lamp flashing, by a sensor (not shown) detecting the detachable member 75 of the key holder 72, the control unit 65 drives the key lock mechanism 86 of the storage unit 62 to lock the key holder 72.
[0036] In addition, when the only process that the authenticated user ID can perform is the return process, even if the ``Return'' button on the storage unit usage display screen is not touched, when a sensor (not shown) of a storage unit 62 that does not have a key 61 detects the detachable member 75 of the key holder 72, the control unit 65 drives the key lock mechanism 86 of this storage unit 62 to lock the key holder 72, even if the ``Return'' button is not touched on the storage unit usage display screen and the lamp-equipped operation button 91 is flashing.
[0037] The control unit 65 then associates the operation name information indicating that a return operation has been input, the user ID and authentication time information authenticated as valid in the authentication process at the start of the return process, the authentication identification information indicating the authentication method, and the storage unit identification information of the storage unit 62, and stores this together with the retrieval history information of a series of retrieval processes performed on the same storage unit 62 as the return process as return history information, which is log information related to the current return process, in the memory unit 66. Here, when keys 61 are returned to multiple storage units 62 in a single return process, the control unit 65 stores the return history information for each of the multiple storage units 62 in the memory unit 66.
[0038] Furthermore, even if an attempt is made to insert the detachable member 75 of the key holder 72 into an incompatible insertion hole 85 of the storage section 62, the insertion is mechanically prevented, and the control section 65 does not lock the key holder 72 to this storage section 62.
[0039] After storing the return history information in the memory unit 66, when the full-closure detection sensor 82 detects that the front cover 22 has been closed, the control unit 65 cancels the authentication success state, turns off the flashing operation button 91 with lamp, and drives the cover lock mechanism 81 to lock the front cover 22 in the closed position, ending the return process and returning the important item management device 11 to the standby state. Even during the return process, if the "Home" button on the display screen is touched, the control unit 65 cancels the authentication success state at that point, turns off the flashing operation button 91 with lamp, and ends the return process. Thereafter, when the full-closure detection sensor 82 detects that the front cover 22 has been closed, the control unit 65 drives the cover lock mechanism 81 to lock the front cover 22 in the closed position and returns the important item management device 11 to the standby state. The control unit 65 may cancel the authentication success state, for example, after a certain period of time has elapsed or by a cancel operation such as pressing the "back" button, turn off the flashing operation button 91 with lamp, and drive the cover lock mechanism 81 to lock the front cover 22 in the closed position, thereby ending the removal process and returning the important item management device 11 to the standby state.
[0040] As described above, the important item management device 11 is configured so that the key holder 72 of the key 61, which has a key body 71 and a key holder 72 to which the key body 71 is attached, can be locked and unlocked, and manages the removal and return of the key 61.
[0041] [Loan authorization process] In the important item management device 11, the control unit 65 sets operation authority, i.e., operable items, for each user ID or for each authority category including at least one user ID, based on operations on the operation display unit 42, etc. This setting of operation authority includes a lending authority granting process that grants the user ID to be set or a user ID included in the authority category to be set the operating authority to lend it to another user ID. This lending authority granting process will now be described.
[0042] Here, as an example, in the case where there are two authority categories, a higher-level administrator category and a lower-level general category, all user IDs with an authority category of administrator are given the following: an operational authority for registering and changing user IDs for the important item management device 11; an operational authority for deleting user IDs; an operational authority for various settings for the important item management device 11; an operational authority for printing the take-out history information, return history information, etc. stored in the memory unit 66 onto paper by the printer unit 56; an operational authority for opening and closing the front cover 22; and an operational authority for removing the detachable member 75 of the key holder 72 from the storage unit 62. In this case, all user IDs with a general authority category have been granted the operational authority to open and close the front cover 22 and the operational authority to remove the detachable member 75 of the key holder 72 from the storage section 62 and return it to the storage section 62, and in this case, loan authority is now granted to all user IDs with an administrator authority category, allowing them to selectively loan operational authority (operational authority to change registration, operation authority to delete, etc.) that is not normally possessed by all user IDs with a general authority category.
[0043] The operational authority for retrieving the detachable member 75 of the key holder 72 from the storage unit 62 that can be granted to all user IDs whose authority category is the general category is one that is a single-party authentication operation authority for retrieval from the storage unit 62 that is permitted with authentication by only one of the user IDs in the general category, and two-party authentication operation authority for retrieval from the storage unit 62 that is permitted with authentication by two of the user IDs in the general category and the user IDs in the administrator category, provided that the user IDs are paired with one of all user IDs whose authority category is the administrator category. The operational authority for retrieval of the detachable member 75 of the key holder 72 from the storage unit 62 that can be granted to all user IDs whose authority category is the administrator category is one that is a single-party authentication operation authority for retrieval from the storage unit 62 that is permitted with authentication by only one of the user IDs in the administrator category (including the user IDs in the general category), two-party authentication operation authority for retrieval from the storage unit 62 that is permitted with authentication by two of the user IDs in the general category and the user IDs in the administrator category, and two-party authentication operation authority for retrieval from the storage unit 62 that is permitted with authentication by two of the user IDs in the administrator category.
[0044] The loan authority granting operation is permitted, for example, to a user ID of a maintenance worker category that performs maintenance on the important item management device 11, whose authority category is different from the administrator category and the general category. It is also possible to loan all operation authorities granted to a user ID of the administrator category or the general category to other user IDs without performing the loan authority granting operation using a user ID of the maintenance worker category, or to loan all operation authorities to other user IDs using a user ID of the administrator category.
[0045] When the above-mentioned authentication process is performed with the "operation standby screen" 100 as shown in Figure 5 displayed on the operation display unit 42, and the user ID and password of the maintenance personnel category with the authority category that can perform the loan authority granting operation are authenticated as appropriate and the authentication is successful, the control unit 65 reads from the memory unit 66 the operable items that the user ID of the maintenance personnel category that has been authenticated as appropriate this time has the authority to operate and is permitted to use.
[0046] Next, the control unit 65 causes the operation display unit 42 to display a "Settings" screen 110 as shown in Fig. 6. Here, if a previous screen is present on the display screen displayed on the operation display unit 42, the control unit 65 causes a "Back" button R to be displayed as necessary, similar to the "Home" button H described above, which, when selected by a touch operation, causes the previous screen to be displayed.
[0047] When a "Category Setting" button 111 is touched, i.e., an input operation is performed, on the "Settings" screen 110 of the operation display unit 42, the control unit 65 causes the operation display unit 42 to display a "Category Setting" screen 120 as shown in Fig. 7. When an "Authority Lending Setting" button 121 is touched, i.e., an input operation is performed, on the "Category Setting" screen 120, the control unit 65 causes the operation display unit 42 to display a first screen 130 of "Authority Lending Setting" as shown in Fig. 8. The first screen 130 of "Authority Lending Setting" has a "Set from Category" button 131 for first selecting a category to set the authority lending, and a "Set from Authority" button 132 for first selecting an authority to set the authority lending.
[0048] When the "Set by Category" button 131 is touched, i.e., input, on the first screen 130 of "Authority Lending Settings," the control unit 65 displays the second screen 140 of "Authority Lending Settings" as shown in FIG. 9 on the operation display unit 42. In this example, since lending authority is to be uniformly granted to all user IDs whose authority category is the administrator category, the "Set" button 141 for "Administrator" is touched, i.e., input. Then, the control unit 65 displays the third screen 150 of "Authority Lending Settings" as shown in FIG. 10 on the operation display unit 42. On this third screen 150 of "Authority Lending Settings," when the authority category is the administrator category, it is possible to select the operation authority to which lending authority can be granted. In this example, all user IDs with an authority category of administrator can be granted the operation authority to register and change user IDs, the operation authority to delete user IDs, the operation authority to change the time, the operation authority to confirm / print, the operation authority to set, etc., and the operation authority selected from these is set as the operation authority to be granted.
[0049] Here, as a specific example, a case will be described in which the lending authority to lend the operation authority to register and change a user ID, the lending authority to lend the operation authority to delete a user ID, the lending authority to lend the operation authority to change the time, the lending authority to lend the operation authority to confirm / print, and the lending authority to lend the operation authority to set will be explained. To grant the lending authority to lend the operation authority to change the registration, the "Register Change" button 151 is touched, i.e., an input operation is performed. The control unit 65 then displays a check mark that was not there before on the "Register Change" button 151. Furthermore, to grant the lending authority to lend the operation authority to delete a user ID, the "Delete" button 152 is touched, i.e., an input operation is performed. The control unit 65 then displays a check mark that was not there before on the "Delete" button 152. Furthermore, to grant the lending authority to lend the operation authority to change the time, the "Time Change" button 153 is touched, i.e., an input operation is performed. Then, the control unit 65 causes a check mark that was not there before to appear on the "Change Time" button 153. Also, since the lending authority to lend the operation authority for confirmation / printing is granted, the "Confirm / Print" button 154 is touched, i.e., an input operation is performed. Then, the control unit 65 causes a check mark that was not there before to appear on the "Confirm / Print" button 154. Also, since the lending authority to lend the operation authority for settings is granted, the "Settings" button 155 is touched, i.e., an input operation is performed. Then, the control unit 65 causes a check mark that was not there before to appear on the "Settings" button 155.
[0050] When the operation authority to grant the loan authority is selected on the third screen 150 of the "Authority Lending Settings" and the "Next" button 156 is touched, i.e., input, the control unit 65 causes the operation display unit 42 to display the fourth screen 160 of the "Authority Lending Settings" as shown in FIG. 11. The fourth screen 160 of the "Authority Lending Settings" is a screen for confirming and confirming the settings, and displays a content display field 161 for confirming the settings. In this example, the content display field 161 indicates that the loan authority is "Authorized" for "Register Change," "Delete," "Time Change," "Confirm / Print," and "Set" based on the input on the third screen 150 of the "Authority Lending Settings." Then, when the "Complete" button 162 is touched, i.e., input, on the fourth screen 160 of the "Authority Lending Settings," the control unit 65 causes the operation display unit 42 to display the fifth screen 170 of the "Authority Lending Settings" as shown in FIG. 12, which indicates that the settings are complete. When the "OK" button 171 is pressed in response to the explanation that the settings have been completed on the fifth screen 170 of "Authority Lending Settings," the control unit 65 associates the setting contents, in this example, that the setting is to grant loan authority to lend the operation authorities for "Register Change," "Delete," "Time Change," "Confirm / Print," and "Settings" to all user IDs whose authority category is the administrator category, with the date and time when the setting was made and the user ID of the maintenance worker category who made the setting, and stores them in the memory unit 66 as log information, and also displays the second screen 140 of "Authority Lending Settings" shown in Figure 9 on the operation display unit 42.
[0051] When the “Set from Authority” button 132 on the first screen 130 of the “Authority Lending Settings” shown in FIG. 8 is touched, i.e., inputted, the control unit 65 causes the operation display unit 42 to display a sixth screen 180 of the “Authority Lending Settings” as shown in FIG. 13 . The sixth screen 180 of the “Authority Lending Settings” displays multiple operation authorities for which lending authority can be granted, similar to the third screen 150 of the “Authority Lending Settings” shown in FIG. 10 , and allows the user to select the operation authority to grant the lending authority from among these. In a specific example, the lending authorities for “Register Change,” “Delete,” “Time Change,” “Confirm / Print,” and “Set” are granted. Therefore, on the sixth screen 180 of the “Authority Lending Settings,” for example, the “Set” button 181 for “Register Change” is first touched, i.e., inputted. Then, the control unit 65 causes the operation display unit 42 to display a seventh screen 190 of the “Authority Lending Settings” as shown in FIG. 14 . In this case, the operating authority for "Register Change" is granted to all user IDs whose authority category is the administrator category, and therefore the "Administrator" button 191 is touched, i.e., inputted. Then, the control unit 65 displays a check mark on the "Administrator" button 191, which was not there before.
[0052] When the "Next" button 192 is touched, i.e., an input operation is performed, on the seventh screen 190 of the "Authority Lending Settings," the control unit 65 causes the operation display unit 42 to display the eighth screen 200 of the "Authority Lending Settings" as shown in FIG. 15. The eighth screen 200 of the "Authority Lending Settings" is a screen for confirming and confirming the settings, and displays a content display field 201 for confirming the settings. In a specific example, the content display field 201 indicates that "Administrator" has "Authorized" for the lending authority. Then, when the "Complete" button 202 is touched, i.e., an input operation is performed, on the eighth screen 200 of the "Authority Lending Settings," the control unit 65 causes the operation display unit 42 to display the fifth screen 170 of the "Authority Lending Settings" as shown in FIG. 12, which indicates that the settings have been completed. When the "OK" button 171 is pressed in response to the explanation that the settings have been completed on the fifth screen 170 for "Authority Lending Settings," the control unit 65 associates the setting contents, in this specific example, that the setting is to grant the operating authority for "Registration Change" to all user IDs whose authority category is the administrator category, with the date and time when the setting was made and the user ID of the maintenance worker category who made the setting, and stores the associated setting contents in the memory unit 66 as log information.
[0053] Next, the control unit 65 returns the operation display unit 42 to the sixth screen 180 of the "authority lending setting", and when, for example, the "setting" button 181 of "delete" is touched, i.e., an input operation is performed, the same as the setting for granting the lending authority to lend the operation authority of "registration change", the lending authority to lend the operation authority of "delete" is set to be granted to all user IDs whose authority category is the administrator category, and next, the control unit 65 returns the operation display unit 42 to the sixth screen 180 of the "authority lending setting", and when, for example, the "setting" button 181 of "time change" is touched, i.e., an input operation is performed, the same as the setting for granting the lending authority to lend the operation authority of "registration change", the lending authority to lend the operation authority of "time change" is set to be granted to all user IDs whose authority category is the administrator category. Next, the operation display unit 42 is returned to the sixth screen 180 of the "Authority Lending Settings", and for example, when the "Settings" button 181 for "Confirm / Print" is touched, i.e., input operated, the setting is similar to the setting of granting the lending authority to lend the operation authority for "Register / Change", and the setting is such that the lending authority to lend the operation authority for "Confirm / Print" is granted to all user IDs whose authority category is the administrator category; and next, the operation display unit 42 is returned to the sixth screen 180 of the "Authority Lending Settings", and for example, when the "Settings" button 181 for "Settings" is touched, i.e., input operated, the setting is similar to the setting of granting the lending authority to lend the operation authority for "Register / Change", and the setting is such that the lending authority to lend the operation authority for "Setting" is granted to all user IDs whose authority category is the administrator category.
[0054] In the above description, the control unit 65 grants, when setting operation authority, all user IDs included in the authority category (administrator category) to grant operation authority to other user IDs. However, when setting operation authority, an individual user ID may be specified on the operation display unit 42, and the specified user ID to be set may be granted operation authority to grant operation authority to other user IDs. Furthermore, the control unit 65 and the operation display unit 42 may be capable of both setting operation authority for each authority category including at least one user ID and setting operation authority for each user ID. Furthermore, the control unit 65 and the operation display unit 42 may be capable of setting operation authority for each authority category including at least one user ID, or for each user ID.
[0055] In addition, the operating authority to be granted as loan authority may be limited to the range of operating authority granted to the user ID to which the loan authority is granted, and in addition to the granted operating authority, it may also be possible to grant operating authority that has not been granted.
[0056] [Operation authority lending process] When the authentication is successful for the user ID to which lending authority has been granted in the above-mentioned lending authority granting process (in the above-mentioned specific example, the user ID is in the administrator category), the control unit 65 can select an operation authority to lend to another user ID from the operation authorities to which lending authority has been granted based on operations on the operation display unit 42, etc., and then perform an operation authority lending process to lend the selected operation authority to the other user ID. This operation authority lending process will be described.
[0057] When the "Submenu" button 103 is touched, i.e., an input operation is performed, with the operation display unit 42 displaying the "Operation Standby Screen" 100 shown in Fig. 5 , the control unit 65 causes the operation display unit 42 to display a "Submenu" screen 210 as shown in Fig. 16 . When the "Transition to Management Mode" button 211 on this "Submenu" screen 210 is touched, i.e., an input operation is performed, the control unit 65 causes the operation display unit 42 to display a first screen 220 of the "Management Mode" as shown in Fig. 17 , which prompts the user to enter a user ID. When the numeric input display unit 221 including a numeric keypad is touched, i.e., an input operation is performed, on this first screen 220 of the "Management Mode" screen, which prompts the user to enter a user ID, and when the "Next" button 222 is touched, i.e., an input operation is performed, the control unit 65 causes the operation display unit 42 to display a second screen 230 of the "Management Mode" as shown in Fig. 18 , which prompts the user to enter a password, if the input user ID is a user ID that can be operated in the management mode. On the second screen 230 of this "Management Mode" screen, when the numeric input display section 231 including the numeric keypad is touched, i.e., an input operation is performed to input a password, and the "Next" button 232 is touched, i.e., an input operation is performed, the control section 65 enters an authentication success state if the input password corresponds to the user ID input on the first screen 220 of the "Management Mode" screen, and causes the operation display section 42 to display the "Management Mode Main Menu" screen 240 as shown in FIG. 19.
[0058] When the "Authority Lending" button 241, which is displayed when a user ID that has been successfully authenticated has been granted authorization to operate the "Management Mode Main Menu" screen 240, is touched, i.e., input, the control unit 65 causes the operation display unit 42 to display the first "Authority Lending" screen 250 shown in FIG. 20. The first "Authority Lending" screen 250 is a screen for inputting the user ID of the user to whom the operation authority is to be lent, i.e., the user to whom the operation authority is to be lent. When the numeric input display unit 251 including a numeric keypad is touched, i.e., input, to input the user ID of the user to whom the operation authority is to be lent, and the "Next" button 252 is touched, i.e., input, the control unit 65 causes the operation display unit 42 to display the second "Authority Lending" screen 260 shown in FIG. 21. Here, it is assumed that "0001" is input as the user ID on the first "Authority Lending" screen 250. In addition, instead of requiring the user to input the numerical user ID of the person to whom the operating authority is to be lent, i.e., the user to whom the operating authority is to be lent, on the operation display unit 42, a list of registered user IDs may be displayed, and the user may select and input the user ID of the user to whom the operating authority is to be lent from this list.
[0059] The second screen 260 for "authority lending" has a list display field 261 for operation authorities in which a user ID that has been successfully authenticated on the first screen 220 and second screen 230 in "management mode" can select operation authorities that have loan authority and can be loaned to other user IDs, and the operation authority to be loaned is selected from this list display field 261. As with the above, the list display field 261 displays operation authorities for registering and changing user IDs, operation authorities for deleting user IDs, operation authorities for changing time, operation authorities for confirming / printing, operation authorities for other settings, etc., and from these, only operation authorities that have been granted loan authority in the above-mentioned loan authority granting process for the user ID that is performing the current operation authority lending process can be selected.
[0060] Here, as a specific example, a case will be described in which, as described above, a user ID in the administrator category that has been successfully authenticated in the current operation authority lending process has been granted the operation authority for "Register Change," "Delete," "Time Change," "Confirm / Print," and "Settings" in the lending authority granting process, and the operation authority for "Register Change" is lent to a specified user ID among other user IDs in the general category. Since the operation authority for "Register Change" is selected, the "Register Change" button 262 in this list display field 261 is touched, i.e., inputted. Then, the control unit 65 displays a check mark that was not there before on the "Register Change" button 262.
[0061] When the operating authority to be lent is selected on the second screen 260 for "Authority Lending" and the "Next" button 263 is touched, i.e., inputted, the control unit 65 displays the third screen 270 for "Authority Lending" as shown in FIG. 22 on the operation display unit 42. The third screen 270 for "Authority Lending" is a screen for inputting the start date of the "Authority Lending." The third screen 270 for "Authority Lending" displays the current "year," "month," and "day" by default. The third screen 270 for "Authority Lending" includes a start date input section 271 that allows the user to input the start date of the "Authority Lending" by incrementing or decrementing the "year," "month," and "day" by one from this date onward, or to select the start date from a calendar. In addition to the start date, the start time of the loan may also be input. Here, it is assumed that "August 31, 20XX" is input as the start date of the "Authority Lending" on the third screen 270 for "Authority Lending."
[0062] When the appropriate loan start date is entered in the loan start date input field 271 on the third screen 270 for "Authority Lending" and the "Next" button 272 is touched, i.e., inputted, the control unit 65 displays the fourth screen 280 for "Authority Lending" on the operation display unit 42, as shown in FIG. 23. The fourth screen 280 for "Authority Lending" is a screen for entering the end date of the "Authority Lending." By default, the fourth screen 280 for "Authority Lending" displays the "year," "month," and "day" of the "Authority Lending" start date entered in the third screen 270 for "Authority Lending." The fourth screen 280 for "Authority Lending" includes a loan end date input field 281 that allows the user to enter the end date of the "Authority Lending" by adding or subtracting one from the "year," "month," and "day" as appropriate, or to select the end date from a calendar. In addition to the loan end date, the user may also be able to enter the loan end time. Here, it is assumed that "September 1, 20XX" has been entered as the end date of "Authority Lending" on the fourth screen 280 of "Authority Lending."
[0063] On the fourth screen 280 for "Authority Lending," when an appropriate loan end date is entered in the loan end date input field 281 and the "Next" button 282 is touched, i.e., an input operation is performed, the control unit 65 causes the fifth screen 290 for "Authority Lending" as shown in Fig. 24 to be displayed on the operation display unit 42. The fifth screen 290 for "Authority Lending" has a loan confirmation display field 291 that displays a list of the user ID of the person to whom the authority is to be lent, i.e., the person to whom the authority is to be lent, their name, the name of the loan authority which is the name of the operating authority to be lent, the loan start date and time, and the loan end date and time. In this example, according to the above input, the loan confirmation display field 291 displays that the user ID of the recipient is "0001", the name is "Taro Xyama", the name of the loan authority is "Registration Change", the start date of the "authority loan" is "August 31, 20XX", and the end date of the "authority loan" is "September 1, 20XX".
[0064] When the "Complete" button 292 is touched, i.e., input, on the fifth screen 290 for "Authority Lending," the control unit 65 causes the operation display unit 42 to display the sixth screen 300 for "Authority Lending" as shown in Fig. 25. When the "OK" button 301 is operated in response to the explanation that the authority lending has been completed on the sixth screen 300 for "Authority Lending," the control unit 65 associates the setting contents, including the user ID for which authentication was successful on the first screen 220 and the second screen 230 for "Management Mode," i.e., the user ID of the authority lender who lent the authority, the date and time of the "authority lending," the user ID of the authority lender to whom the authority is being lent, the name of the authority lender, the name of the operating authority lent, the lending start date, and the lending end date, with the setting contents stored in the storage unit 66 as log information, and also causes the operation display unit 42 to display the "Management Mode Main Menu" screen 240 shown in Fig. 19.
[0065] Here, when authentication is successful with the user ID of the person to whom the authority is to be lent, that is, the person to whom the authority is to be lent, the control unit 65 can read out from the storage unit 66 the setting contents including the operation authority name of the operation authority lent to the user ID, the loan start date, and the loan end date based on an operation on the operation display unit 42, and display them on the operation display unit 42. This allows the person to whom the authority is to be lent to confirm that the operation authority has been lent and the loan contents.
[0066] In addition, when performing an operation authority lending process based on an approval operation by the user ID of one administrator category, approval operations may be required by the user ID of that one administrator category and the user ID of another administrator category or the user ID of the person to whom the authority is being lent.
[0067] Furthermore, the operation authority lending process may be remotely controlled from a higher-level system or the like.
[0068] As described above, when the user ID of the person to whom the operation authority is to be lent, that is, the authorized lender (the authorized lender who does not normally have the lent operation authority) is successfully authenticated, the control unit 65 allows the operation authority lent to this user ID to be executed only if the time is between the loan start date and the loan end date. Note that if the time is before the loan start date or after the loan end date, the control unit 65 will not allow the operation authority lent to this user ID to be executed. When the authentication is successful for a user ID other than the authorized lender to whom the operation authority is to be lent, who does not normally have this operation authority, the control unit 65 will not allow this user ID to be executed.
[0069] In the above specific example, the control unit 65 allows the user ID "0001", who does not normally have the operation authority for "registration change", to register and change the user ID, etc., on the important item management device 11 only when the authentication is successful and the date and time is between "August 31, 20XX" and "September 1, 20XX". On the other hand, even if the user ID "0001" is authenticated successfully, the control unit 65 does not allow the user ID, who normally does not have the operation authority for registration change and is not a loan recipient of the operation authority, to register and change the user ID, etc., on the important item management device 11. Furthermore, even if the authentication is successful for a user ID "0001", who does not normally have the operation authority for registration change and is not a loan recipient of the operation authority, the control unit 65 does not allow the user ID, who normally has the operation authority for registration change, to register and change the user ID, etc., on the important item management device 11.
[0070] In the above example, there are two authority categories, a higher-level administrator category as shown in FIG. 26(a) and a lower-level general category as shown in FIG. 26(b) and FIG. 26(c), and all user IDs whose authority category is the administrator category are given the following operational rights: "registration change" for registering and changing user IDs and the like for the important item management device 11; various "setting" operational rights for the important item management device 11; "print" operational rights for printing the take-out history information, return history information, and the like stored in the memory unit 66 on paper by the printer unit 56; and operational rights for opening and closing the front cover 22, as shown in FIG. 26(a). , and the operation authority to remove the key holder 72 from the storage unit 62 (one-party authentication and two-party authentication). As shown in Figures 26(b) and 26(c), all user IDs in the general authority category are granted the operation authority to open and close the front cover 22 and the operation authority to remove the key holder 72 from the storage unit 62 (one-party authentication), but do not have the operation authority for "registration change." In the [operation authority lending process], for user IDs in the general category that have been granted the operation authority for "registration change," the "registration change" operation can be performed during the period between the loan start date and the loan end date, as shown in Figure 26(d). In contrast, for user IDs in the general category that have not been granted the operation authority for "registration change," the "registration change" operation remains inoperable, as shown in Figure 26(e). Furthermore, even for user IDs in the general category that have been granted the operation authority for "registration change," the "registration change" operation cannot be performed unless it is during the period between the loan start date and the loan end date, as shown in Figure 26(f).
[0071] In the above, an example has been explained in which the control unit 65 allows the loaned operating authority to be executed if it is within the period specified in the operating authority loaning process, but the specified condition for allowing the loaned operating authority to be executed may also be other conditions.
[0072] For example, as a specified condition for enabling the loaned operating authority to be executed, the loaned operating authority may be executable if the number of operations performed with the loaned operating authority is within the number of times specified in advance at the time of the operating authority loaning process.
[0073] Also, for example, when the authentication success state is not achieved for the user ID of the lender who has lent the operation authority, the lent operation authority may be made executable. In other words, when the authentication success state is achieved for the user ID of the lender who has lent the authority, the control unit 65 automatically cancels the lending of the operation authority, and the lent operation authority until then is made executable.
[0074] In addition, for example, if the user ID of the lender who lent the operation authority has not released the operation authority, the lent operation authority may be made executable. In other words, if the user ID of the lender has released the operation authority once lent, the operation authority cannot be lent again.
[0075] Also, for example, if the loan of the operation authority has not been released by a predetermined user ID that is permitted to release the loan, the loaned operation authority may be made executable. In other words, once loaned, the operation authority can be released by a predetermined user ID that is permitted to release the operation authority, for example, a user ID of an administrator category, even by a user ID other than the original user, and if this release operation is performed, the operation authority will not be loaned.
[0076] At least one of the above is set as a predetermined condition for enabling the execution of the loaned operating authority, and when the control unit 65 determines that the predetermined conditions are met and that all of the set predetermined conditions are met based on the results of judging each of the set predetermined conditions, the loaned operating authority is made executable.
[0077] The predetermined conditions under which the lent operation authority can be executed may be set each time the operation authority is lent, or may be set in advance during the lent authority granting process.
[0078] In the above operation authority lending process, when the operation authority to be loaned to one other specified user ID is selected by an operation based on the user ID of the lending source to which the loan authority has been granted, the operation display unit 42 and the control unit 65 loan the selected operation authority to the other specified user ID. However, when the operation authority to be loaned to multiple other specified user IDs is selected, the selected operation authority may be loaned to all of the multiple other specified user IDs at once. Furthermore, when the operation authority to be loaned to a specified authority category (e.g., the general category) is selected by an operation based on the user ID of the lending source to which the loan authority has been granted, the operation display unit 42 and the control unit 65 may be configured to loan the selected operation authority to all of the user IDs included in the specified authority category at once.
[0079] [Revoke loan authority] When the authentication is successful for the user ID of the lender who is able to lend the operation authority, the lending authority cancellation process is selected on the operation display unit 42, and the user ID or authority category of the lender to whom the operation authority has been lent is entered, the control unit 65 will cancel the lending of all operation authorities that have been lent to this user ID or authority category. Note that when multiple operation authorities have been lent, it is also possible to selectively cancel the lending of operation authorities from among them.
[0080] [Lending authority execution process] In the above-mentioned [operation authority lending process], when the authentication of the user ID of the person to whom the authority has been lent, i.e., the lending destination, is successful and the predetermined conditions for enabling the execution of the lent operation authority are met, the important item management device 11 is capable of executing the lent operation authority, in which the control unit 65 executes the lent operation authority based on the operation on the operation display unit 42, etc. This lent authority execution process will be explained.
[0081] When the "Submenu" button 103 is touched, i.e., an input operation is performed, with the operation display unit 42 displaying the "Operation Standby Screen" 100 shown in Fig. 5 , the control unit 65 causes the operation display unit 42 to display a "Submenu" screen 210 as shown in Fig. 16 . When the "Transition to Management Mode" button 211 on this "Submenu" screen 210 is touched, i.e., an input operation is performed, the control unit 65 causes the operation display unit 42 to display a first "Management Mode" screen 220 as shown in Fig. 17 , which prompts the user to enter a user ID. When the numeric input display unit 221 including a numeric keypad is touched, i.e., an input operation is performed, to input a user ID on this first "Management Mode" screen 220, and the "Next" button 222 is touched, i.e., an input operation is performed, the control unit 65 causes the operation display unit 42 to display a second "Management Mode" screen 230 as shown in Fig. 18 , which prompts the user to enter a password, if the input user ID is a user ID with operation authority for the management mode, including the loaned operation authority. On the second screen 230 of this "Management Mode" screen, when the numeric input display section 231 including the numeric keypad is touched, i.e., an input operation is performed to input a password, and the "Next" button 232 is touched, i.e., an input operation is performed, the control section 65 enters an authentication success state if the input password corresponds to the user ID input on the first screen 220 of the "Management Mode" screen, and causes the operation display section 42 to display the "Management Mode Main Menu" screen 240 as shown in FIG. 19.
[0082] Here, as a specific example, we will explain the case where, as described above, in the [Operation Authority Lending Process], the operation authority for "Registration Change" is lent to user ID "0001" with a general authority category, and the operation authority for "Registration Change" is executed when authentication is successful for user ID "0001" during the period between the loan start date and loan end date, which are the specified conditions for executing the loaned operation authority.
[0083] On the "Management Mode Main Menu" screen 240, the user ID "0001" is granted the "Registration Change" operation authority, which is not normally granted, and therefore the "Register / Delete" button 242 for performing the "Registration Change" operation is displayed so that it can be touched, i.e., input. Note that on the "Management Mode Main Menu" screen 240, operation authorities that are not set to be selectable for the user ID "0001" are hidden. When the "Register / Delete" button 242 is touched, i.e., input, the control unit 65 causes the operation display unit 42 to display a pop-up screen 310, as shown in FIG. 27 , including a notification display 311 indicating that the operation will be performed with the granted operation authority and including the loan period. That is, when the operation display unit 42 authenticates the user ID to which the operation authority has been granted, the control unit 65 causes the operation display unit 42 to notify that the granted operation authority is the granted operation authority when executing the granted operation authority.
[0084] 28, which allows registration and change operations such as registering and changing a general-category user ID for the important item management device 11. When the "Register / Delete" button 321 on the "Register / Delete" screen 320 is touched, i.e., input, and a registration change operation is performed appropriately on the operation display unit 42, the control unit 65 associates the user ID for which authentication was successful on the first screen 220 and the second screen 230 of the "management mode," i.e., the user ID of the authorized person who exercised the lent operating authority, information that the lent operating authority was exercised, the fact that a "registration change" was made, the date and time of the "registration change," and the content of the "registration change" including the user ID of the person who is the target of the "registration change," with each other, and stores these as log information in the storage unit 66. That is, the control unit 65 associates the user ID of the authorized user who executed the granted operation authority, information indicating that the operation authority was executed, the executed operation authority, the execution date and time of the operation authority, and the operation performed with the operation authority, and stores these as log information in the storage unit 66. On the other hand, when an operation is executed with normal operation authority other than the granted operation authority, the control unit 65 associates the user ID of the user who executed the operation authority, the executed operation authority, the execution date and time of the operation authority, and the operation performed with the operation authority, and stores these as log information in the storage unit 66. In this way, the control unit 65 records operations performed with the granted operation authority in a format different from operations performed with normal operation authority other than the granted operation authority in the storage unit 66. Note that the log information stored in the storage unit 66 as described above may also include the user ID of the user who lent the operation authority. In this way, it is possible to later confirm which user ID's authority was granted and the operation was performed.
[0085] The log information stored in memory unit 66 in this way can be displayed on operation display unit 42 or printed on paper by printer unit 56 based on operations on operation display unit 42, but even in this case, log information for operations performed with the lent operating authority and log information for operations performed with normal operating authority other than the lent operating authority are displayed or printed in different formats to distinguish them from each other. It is also possible to display or print only the log information for operations performed with the lent operating authority.
[0086] The important item management device 11 described above includes an operation display unit 42 and a control unit 65 that set operation authority for each user ID or for each authority category that includes at least one user ID. When setting operation authority for each user ID, the operation display unit 42 and the control unit 65 can grant loan authority to each user ID to grant operation authority to other user IDs. When setting operation authority for each authority category, the operation display unit 42 and the control unit 65 can grant loan authority to each user ID included in the authority category to grant operation authority to other user IDs. This allows operation authority to be loaned to other user IDs based on the granted loan authority. Therefore, even if someone with operation authority is not present, a user without operation authority can perform necessary operations using the loaned operation authority, improving convenience.
[0087] Furthermore, when the operation display unit 42 and the control unit 65 select the operation authority to be loaned to another designated user ID through an operation based on the user ID to which the loan authority has been granted, the important item management device 11 loans the selected operation authority to the other user ID. Therefore, even a user who does not have the operation authority can perform the necessary operations with the loaned operation authority, thereby improving convenience.
[0088] Furthermore, when the operation display unit 42 and the control unit 65 select the operation authority to be loaned to a designated authority category (for example, the general category) through an operation based on the user ID to which the loan authority has been granted, the important item management device 11 loans the selected operation authority to all user IDs included in the designated authority category. Therefore, even a user without operation authority can perform the necessary operations with the loaned operation authority, improving convenience.
[0089] Furthermore, the important item management device 11 has a memory unit 66 that records operation history, and the control unit 65 records operations performed with the loaned operating authority in the memory unit 66 separately from operations performed with normal operating authority other than the loaned operating authority, so that it is possible to later confirm whether or not the operation was performed with the loaned operating authority.
[0090] Furthermore, when the control unit 65 of the important item management device 11 executes the loaned operating authority, it determines whether the specified conditions for enabling the execution of the loaned operating authority are met. The specified conditions are at least one of the following: within a specified period, the number of operations performed with the loaned operating authority is within a specified number of times, no authentication operation has been performed using the user identification information of the lender who loaned the authority, the loan of the operating authority has not been released using the user identification information of the lender who loaned the authority, and the loan of the operating authority has not been released using the specified user identification information. If it is determined that the specified conditions are met, the loaned operating authority is made executable. Therefore, the loaned operating authority can be strictly made executable under appropriate conditions.
[0091] In addition, the important item management device 11 may be configured so that, after lending the operation authority, the control unit 65 first authenticates the user ID of the recipient to whom the operation authority has been lent, and then causes the operation display unit 42 to notify the user that the operation authority has been lent and the lent operation authority. This allows the user to recognize that the operation authority has been lent. Furthermore, after the lending of the operation authority has ended, the control unit 65 may be configured so that, when the control unit 65 first authenticates the user ID of the recipient to whom the operation authority has been lent, the operation display unit 42 to notify the user that the lending of the operation authority has ended and the lent operation authority. This allows the user to recognize that the lending of the operation authority has ended. Whether or not to make these notifications may be set by an input operation on the operation display unit 42.
[0092] In the above embodiment, a key management device that manages keys has been used as an example of the important item management device 11, but the present invention can also be applied to important item management devices that manage important items other than keys, such as bankbooks and seals. [Explanation of symbols]
[0093] 11...important item management device, 42...operation display unit (authentication unit, notification unit), 65...control unit (user authority setting unit, authority lending setting unit, authentication unit, control unit, validity condition determination unit), 66...storage unit.
Claims
1. a user authority setting unit that sets operation authority for each user identification information or for each authority category including at least one user identification information; The user authority setting unit can grant, when setting the operation authority, a lending authority for lending the operation authority to other user identification information to the user identification information to which the operation authority is to be set. An important item management device characterized by:
2. The device further includes an authority lending setting unit that, when an operation authority to be lent to another user identification information is selected by an operation based on the user identification information to which the lending authority has been granted, lends the selected operation authority to the other user identification information.
2. The important item management device according to claim 1.
3. The system further includes an authority lending setting unit that, when an operation authority to be lent for an authority category is selected by an operation based on user identification information to which the lending authority has been granted, lends the selected operation authority to the user identification information included in the authority category.
2. The important item management device according to claim 1.
4. an authentication unit that authenticates user identification information; a control unit that notifies a notification unit that the operation authority has been lent the first time the authentication unit authenticates the user identification information to which the operation authority has been lent by the authority lending setting unit; 4. The important item management device according to claim 2 or 3.
5. a storage unit for recording an operation history; a control unit that records operations performed with the lent operation authority in the storage unit separately from operations performed with normal operation authority other than the lent operation authority.
4. The important item management device according to claim 2 or 3.
6. The device further includes a validity condition determination unit that determines whether a predetermined condition that allows the lent operation authority to be executed is met, The predetermined condition is: Within a specified period, The operations performed with the loaned operating privileges are within the specified number of times, The user identification information of the person who lent the authority has not been used for authentication. The user identification information of the lender of the operating authority has not been used to cancel the loan of the operating authority, and The operating authority has not been released using the specified user identification information. At least one of When it is determined that the predetermined condition is met based on the result of the determination by the validity condition determination unit, the lent operation authority is made executable.
4. The important item management device according to claim 2 or 3.
7. an authority lending setting unit that lends the selected operation authority to another user identification information when the operation authority to be lent to another user identification information is selected by an operation based on one user identification information; An important item management device characterized by:
8. an authority lending setting unit that lends the selected operation authority to the user identification information included in the authority category when the operation authority to be lent to the user identification information is selected by an operation based on one user identification information; An important item management device characterized by:
Citation Information
Patent Citations
Device, method and program for managing important object
JP2017227010A