Information management system, information management method

The information management system addresses the challenge of balancing security and convenience by detecting illegal usage situations and reducing access privileges while maintaining access to critical information, ensuring both security and user convenience.

JP7691524B2Active Publication Date: 2025-06-11HITACHI HIGH TECH CORP
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2023570712
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-12-27
Filing Date
2022-11-07
Publication Date
2025-06-11
Estimated Expiration
2042-11-07

AI Technical Summary

Technical Problem

In information management systems for automatic analyzers, there is a challenge in balancing information security and user convenience, especially when illegal usage situations of remote terminals occur, leading to potential security risks and inconvenience due to automatic logout or communication disconnects.

Method used

The system detects communication disconnects or illegal usage situations and responds with either a warning to the administrator or a decrease in the access authority level, while still allowing access to certain information, thereby maintaining user convenience and ensuring information security.

Benefits of technology

This approach effectively achieves both information security and user convenience by allowing continued access to essential information even when access privileges are reduced, thus minimizing the impact of unauthorized usage situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007691524000001
    Figure 0007691524000001
  • Figure 0007691524000002
    Figure 0007691524000002
  • Figure 0007691524000003
    Figure 0007691524000003
Patent Text Reader

Abstract

The objective of the present invention is to achieve both information security and user convenience in an information management system that manages information related to an automated analyzer, even if conditions of unauthorized use from a remote terminal occur. An information management system according to the present invention, upon detecting a communication disconnection or conditions of unauthorized use from a remote terminal, performs one or both of issuing a warning to an administrator or lowering the level of access rights, and enables access to at least a portion of the information even if the level of access rights is lowered (see FIG. 3).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information management system that provides data describing information about an automatic analyzer to a remote terminal.

Background Art

[0002] An automatic analyzer is a device that analyzes components contained in a sample. Information about the automatic analyzer (e.g., personal information of the subject who provided the specimen, and other information exemplified in the embodiments described later) can be accessed from a remote terminal such as a mobile terminal via, for example, a system that manages the information. In such an information management system, it is necessary to ensure information security so that personal information such as patient information cannot be accessed by a third party.

[0003] As a conventional technique, when accessing a system using a mobile terminal, even when the terminal logs out from the system due to a timeout or a disconnection, there is a known technique that enables continued access to the system with a low access privilege level. For example, Patent Document 1 describes a technique related to this point, although it is not a technique related to an automatic analyzer. When the access privilege level automatically decreases due to a timeout or the like, it is normal to log out the user and lose the access privilege of the user. However, in this document, even in this case, a technique is shown to maintain the lowest level of access privilege so that the user can continue to access the data.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] In the inspection room where an automatic analyzer is installed, the introduction of mobile terminals such as smartwatches is progressing. Along with this, security risks are increasing, and information management is being required more strictly.

[0006] The communication situation in the inspection room and the work content of the person in charge vary depending on the facility and the person in charge. The inspection technician may leave the communication range where they can communicate with the information management system due to work in places where radio waves do not reach, such as a reagent cold storage, or other interrupting work, or may automatically log out from the information management system due to timeout without operating the mobile terminal for a certain period of time.

[0007] In Patent Document 1, even when logging out from the system in this way, by classifying and managing personal information and the like in advance for each level, it is possible to continue providing only the accessible information. A similar situation is considered to occur even when the usage status of the user terminal is illegal. For example, when the information management system detects the possibility that the usage status of the user terminal is illegal, it is normal to revoke the access authority level of that user. However, if this is done, even when it is not an illegal access, it is necessary to go through the trouble of re-authentication to access the information again, and the same problem situation as in Patent Document 1 occurs.

[0008] The present invention has been made in view of the above problems, and in an information management system that manages information related to an automatic analyzer, an object is to achieve both information security and user convenience even when an illegal usage situation of a remote terminal occurs.

Means for Solving the Problems

[0009] When the information management system according to the present invention detects a communication disconnect or an illegal usage situation of a remote terminal, it performs at least one of a warning to the administrator or a decrease in the access authority level, and even when the access authority level is decreased, access to at least some information is possible.

Advantages of the Invention

[0010] According to the information management system of the present invention, even when an unauthorized use situation of a remote terminal occurs, by maintaining a certain level of access privilege level while reducing the access privilege level, it is possible to achieve both information security and user convenience.

Brief Description of the Drawings

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5A

Figure 5B

Figure 5C

Figure 6

Figure 7

Figure 8

Figure 9

Modes for Carrying Out the Invention

[0012] <Embodiment 1> FIG. 1 is a schematic overall configuration diagram of an automatic analyzer 100 according to Embodiment 1 of the present invention. The sample container 1 houses a sample to be analyzed by the automatic analyzer 100. The sample transfer mechanism 2 moves the sample container 1 by rotating it while the sample container 1 is placed thereon. The sample ID reader 19 reads the sample ID printed on the surface of the sample container 1. The sample dispenser 5 dispenses the sample contained in the sample container 1 into the reaction vessel 11. The reagent container 10 houses a reagent to react with the sample. The reagent storage 17 holds the reagent container 10. The reagent dispenser 7 dispenses the reagent into the reaction vessel 11. The liquid level detector 9 detects the liquid level in the reagent container 10. The reagent ID reader 14 reads the reagent ID printed on the surface of the reagent container 10. The liquid level detector 6 detects the liquid level in the reaction vessel 11. The reaction vessel 11 houses the sample and the reagent to react them. The reaction vessel transfer mechanism 8 moves the reaction vessel 11 by rotating it while the reaction vessel 11 is placed thereon.

[0013] The microcomputer 3 controls the operation of the automatic analyzer 100 by controlling each part provided in the automatic analyzer 100. The display device 12 displays the results processed by the microcomputer 3 and the like. The input device 13 is a device for inputting operation instructions from a user, such as a mouse or a keyboard. The storage medium 15 stores data used by the microcomputer 3 and the like. The memory area 16 stores data temporarily used by the microcomputer 3 and the like. The printer 18 prints the results processed by the microcomputer 3 and the like on a paper medium. The interface 4 interconnects each functional part.

[0014] The memory medium 15 stores information on patient specimens registered in the automatic analyzer 100 and device maintenance information such as device alarms, maintenance, and reagents. This information includes (a) personal information such as the patient's name, gender, age, specimen ID, and measurement results, and (b) non-patient information such as reagents, maintenance, and alarms. The displayability of this information is controlled according to the access privilege level of the logged-in user. When accessing personal information and patient information, a higher access privilege is required compared to non-patient information.

[0015] Figure 2 is a configuration diagram of the information management system 200. The information management system 200 is a system that provides information regarding the automatic analyzer 100 to the mobile terminal 300 (remote terminal). The information management system 200 may be configured as a part of the automatic analyzer 100, or may be configured as a separate system from the automatic analyzer 100 and communicate with the automatic analyzer 100. In Figure 2, an example configured as a separate system is shown. The information management system 200 can be configured by a server computer or the like having each part shown in Figure 2.

[0016] The information management system 200 includes a device information acquisition unit 210, a user input reception unit 220, a service provision unit 230, an access management unit 240, and a storage medium 250. The device information acquisition unit 210 acquires information stored in the storage medium 15 of the automatic analysis device 100. The user input reception unit 220 receives user inputs such as, for example, a user ID, a password, a specification of a service requested from the information management system 200, and an operation instruction on a screen interface described later. The service provision unit 230 provides a service to the mobile terminal 300. The service here is, for example, (a) presenting information about the state of the automatic analysis device 100, (b) presenting personal information about the provider (patient, subject, etc.) of the specimen analyzed by the automatic analysis device 100, and other functions, and specific examples thereof will be described later. The access management unit 240 manages access to the information provided by the information management system 200 through the service. Details of the access management procedure will be described later. The storage medium 250 stores data describing the information held by the information management system 200.

[0017] The mobile terminal 300 includes a computer 310, a storage medium 320, a display device 330, an access management unit 340, and a user input reception unit 350. The access management unit 340 can be implemented as, for example, a software module. The computer 310 manages access to the information on the mobile terminal 300 by executing the access management unit 340. The computer 310 also controls each unit included in the mobile terminal 300. The storage medium 320 stores data describing the information held by the mobile terminal 300. The display device 330 presents information about the automatic analysis device 100 to the user by displaying the information acquired from the information management system 200. The access management unit 340 manages access to the information held by the mobile terminal 300. The user input reception unit 350 receives an operation instruction from the user for the mobile terminal 300.

[0018] FIG. 3 is a diagram showing a processing procedure of a service in which the information management system 200 provides information about the automatic analysis device 100 to the mobile terminal 300. Each step of FIG. 3 will be described below.

[0019] (Figure 3: Step S301) The administrator registers information about the user who uses the information management system 200 via the user input reception unit 220. The user information registered in this step is stored in the storage medium 250. Examples of user information include the following:

[0020] (a) Login-related information such as the user ID and password used when the user logs in to the information management system 200; (b) Information (check rules described later) used to determine whether the situation when the user uses the mobile terminal 300 and the situation when the user uses the information management system 200 via the mobile terminal 300 are legitimate; (c) The type of service provided to the user registered in this step; (d) The work schedule of the user registered in this step.

[0021] (Figure 3: Step S302) The user performs a login operation via the user input reception unit 350 of the mobile terminal 300. The access management unit 240 performs login authentication using the user ID and password entered by the user.

[0022] (Figure 3: Step S303) The access management unit 240 stores in the storage medium 250 information associating the ID of the mobile terminal 300 with the ID of the user who logged in in S302. Thereby, the information management system 200 can grasp which user is using which mobile terminal 300.

[0023] (Figure 3: Step S303: Supplementary) The information associating the user saved in this step with the mobile terminal 300 is retained in the storage medium 250 until events such as the administrator manually deleting it (specific examples will be described later), logging out via the user input reception unit 350, or the mobile terminal 300 powering off occur. That is, the user remains logged in to the information management system 200.

[0024] (Fig. 3: Step S304) The service providing unit 230 notifies the mobile terminal 300 of the service types that can be provided to the logged-in user according to the user information registered in S301. The computer 310 of the mobile terminal 300 displays a service menu screen on the display device 330 according to the notification. The user can access information regarding the automatic analysis device 100 provided by the information management system 200 via this service menu screen.

[0025] (Fig. 3: Step S304: Supplementary) The service providing unit 230 presents only the information items permitted by the access authority table (or information item table) described in Fig. 4 below to the mobile terminal 300 in this step. That is, even for services permitted to be provided to the user, the service providing unit 230 does not present to the mobile terminal 300 those information items among the information items to be referred to in the service for which the user does not have access authority.

[0026] (Fig. 3: Step S305) The information management system 200 waits to receive the usage status of the terminal from the mobile terminal 300. The mobile terminal 300 (computer 310) periodically transmits the usage status to the information management system 200, and the access management unit 240 receives this. Examples of the usage status include the following:

[0027] When the mobile terminal 300 connects to the information management system 200 via wireless communication (e.g., WiFi), the identifier of the connection source area, i.e., the identifier of the WiFi connection point; (b) The communication state between the mobile terminal 300 and the information management system 200 (whether communication is established, signal strength, etc.); (c) The operation history on the mobile terminal 300.

[0028] (Figure 3: Step S306) The access management unit 240 determines whether the usage state of the mobile terminal 300 received in S305 is legitimate. The check rules used for the determination will be described later. If the usage state is legitimate, it returns to S305. If the usage state is illegitimate, it proceeds to S307. If the usage state is legitimate, the user can continue to use the service while maintaining the access privilege level.

[0029] (Figure 3: Steps S307 - S309) The access management unit 240 performs at least one of sending a warning to the administrator (S308) or lowering the access privilege level of the corresponding user (S309) according to the check rules (S307), either by manual operation or automatic processing by the administrator. When automatically lowering the access privilege level, the administrator may be notified accordingly. After lowering the access privilege level, only the information accessible to the mobile terminal 300 according to the access privilege level is provided. Until the user re - logs in to the information management system 200, the access privilege level is not restored (in other words, it is restored when re - logging in). After S308 or S309, it returns to S305.

[0030] (Figure 3: Step S309: Supplementary) A decrease in the access authority level means that the range of accessible information becomes narrower. However, even after the access authority level is decreased in this step, it is not necessary to prohibit access to all services provided by the information management system 200 (i.e., all information related to the automatic analysis device 100). For example, the access authority level may be decreased to a level where access is only possible to information that does not include the personal information of the subject. As a result, even if the user does not re-login, at least some information can still be accessed, thus maintaining the convenience of the user.

[0031] (Figure 3: Step S310) When the user logs out on the mobile terminal 300 or turns off the power of the mobile terminal 300, the access management unit 240 deletes the information for association saved in S303 from the storage medium 250. As a result, the user is in a state of logging out from the information management system 200.

[0032] Figure 4 shows the configuration and data example of the data table held by the storage medium 250. The storage medium 250 stores a login information table, a mobile terminal table, an information item table, and an access authority table.

[0033] The login information table is a data table that holds the login-related information and the user's management authority in S301. As authentication information, in addition to passwords, face, voiceprint authentication, etc. may be used. It is also possible for multiple people to use the same user ID. The user ID and password used when logging in to the automatic analysis device 100 may be diverted in this table or defined separately.

[0034] The mobile terminal table is a data table that holds the usage status of the mobile terminal 300 in S305. The mobile terminal table associates the ID of the mobile terminal 300 with the user ID using the terminal and holds it as one record. As a result, the association information in S303 can be held.

[0035] The information item table is a data table that manages which information items are provided to each user. The information items provided to each user are generally defined according to the access authority table described below. However, in the case where access authority is granted only for information related to a specific model or a specific inspection room of the automatic analysis device 100, this is defined in this table. In the figure, the ○ mark indicates an information item that can be provided, and the × mark indicates an information item that cannot be provided. The service providing unit 230 provides only the information items permitted by this table to the mobile terminal 300 (that is, the user using the terminal). Information that can be derived from the access authority table does not necessarily have to be held on this table, but for the convenience of processing, the accessible information items are aggregated and defined on this table.

[0036] The access authority table is a data table that defines the access authority (the range of information items that can be accessed) for each information item. In one service provided by the information management system 200, multiple information items may be provided. The access authority for each information item is defined by this table separately from the type of service provided to the user. The access authority is defined, for example, for each management authority (role of the user) of the user. The accessible range for each information item differs for each access authority. For example, in the condition editing service, only the administrator can edit the conditions of all users, while other users can only view their own conditions. Thus, the usage of the mobile terminal 300 differs depending on the person in charge.

[0037] Although not shown in FIG. 4, a provided service table that lists the types of services provided to each user, a user schedule table that records the business schedules of each user, etc. may be stored in the storage medium 250.

[0038] FIG. 5A shows an example of determination conditions and their options that constitute a check rule used to determine whether the usage status of the mobile terminal 300 in S306 is legitimate. When the usage status of the mobile terminal 300 matches what is specified from the options as a determination condition, it can be determined that the usage status is illegal. As the determination conditions, any one or more of the following can be specified:

[0039] (Online condition) Whether a connection between the mobile terminal 300 and the information management system 200 is established, and the duration for which the offline state continues; (Access status) The continuous time elapsed without the mobile terminal 300 accessing information on the information management system 200 (or information downloaded from the information management system 200 to the mobile terminal 300); (Area condition) The area number indicating from which of the communication areas formed in the space where the automatic analyzer 100 is installed the mobile terminal 300 accessed the information management system 200, for example, the identifier of a WiFi access point; (Terminal condition) The ID that individually identifies the mobile terminal 300, and optionally, whether only one of the terminals is in a position away from other terminals after a user logs in using multiple terminals; (User condition) The ID that individually identifies the user; (User status) The user's work schedule, that is, the work assumed to be performed by the user; (Operation status) The service of the information management system 200 used using the mobile terminal 300, that is, the type of information regarding the automatic analyzer 100 provided by the information management system 200 to the mobile terminal 300. In the example shown in FIG. 5A, services that provide the information items themselves described in FIG. 4, services in which the information items are presented during the process of providing the service, etc. are mixed, but any service corresponds to the type of information item.

[0040] For example, assume a check rule that for a specific user, regardless of which terminal is used, connection to the information management system 200 is permitted only from a specific WiFi area. In this case, as the area condition, list the IDs of the prohibited areas other than the permitted areas, as the terminal condition, list the IDs of all terminals, and as the user condition, specify the ID of that specific user.

[0041] FIG. 5B shows an example of options for processing to be performed when an unauthorized use situation of the mobile terminal 300 is detected. Actions upon unauthorized detection include processing performed on the mobile terminal 300 and processing performed in the information management system 200 (and further notifying the administrator terminal of the result). Examples of processing performed on the mobile terminal 300 will be described later. Examples of processing performed in the information management system 200 include the warning display on the administrator terminal or the reduction of the user's access privilege level (automatic reduction and reduction by manual operation) described in S307 to S309. Additionally, it is also conceivable to notify a warning to the mobile terminal 300.

[0042] FIG. 5C shows an example of an actually configured check rule using each of the options in FIGS. 5A to 5B. The rule of Facility A is an example of completely prohibiting the use of the information management system 200 via the mobile terminal 300 in the offline state. In this rule, when the offline state is entered, the access privilege level is unconditionally reduced. The rule of Facility B is an example of a rule that maintains the access privilege level when legitimate operations continue, although there are many communication-inaccessible areas within the range where the inspection engineer operates. The rule of Facility C is an example of applying strict rules only to the mobile terminal 300 used by employees other than the inspection engineer in a facility where various employees such as part-time workers work in addition to the inspection doctor.

[0043] The example rule of Facility A is a strict rule that prohibits access to all offline terminals. Imposing such strict access restrictions may not match the actual situation of the facility's operation. In such cases, a rule with a slightly relaxed strictness, like the example rules of Facility B and C, may be used.

[0044] In addition to the above, for specific users, detailed rules according to the usage purpose can be specified, such as not allowing patient information operations other than checking specimen information when an alert occurs. When it is possible for one person to use multiple mobile terminals 300, if the usage areas of the multiple terminals are different from each other, an alert may be issued. This makes it possible to take measures when any of the simultaneously used mobile terminals 300 is forgotten. For example, when using a smartwatch and a smartphone, if only the smartphone is forgotten, an abnormal situation can be detected because the usage status between the worn smartwatch and the smartphone deviates from each other beyond the threshold value.

[0045] The information management system 200 receives an instruction input for specifying these check rules via the user input reception unit 220 and stores the content in the storage medium 250. The access management unit 240 determines whether the usage status of the mobile terminal 300 is legitimate in S306 according to the check rules.

[0046] FIG. 6 is an example of a screen interface for inputting check rules. The user input reception unit 220 receives the check rules described with reference to FIGS. 5A to 5C via the screen interface of FIG. 6. The rule name 601 is a field for inputting the name of the check rule. The online condition 602, the area condition 603, the terminal condition 604, the restricted operation 606 (operation state), and the processing at conflict (processing at abnormal detection) correspond to the check rules described with reference to FIGS. 5A to 5C. Although FIG. 6 shows an example in which only some of the rule items described with reference to FIGS. 5A to 5C are used, the items constituting the rule may be arbitrarily added or deleted.

[0047] FIG. 7 shows the management screen of the information management system 200. The access management unit 240 presents the management screen of FIG. 7 on a display device such as a display. The management screen presents the following information for each ID of the mobile terminal 300:

[0048] (Online Status) Whether the mobile terminal 300 is connected to the information management system 200, and if so, the ID of the connection source area (Login Status) The ID of the user using the terminal, and the business content that the user is assumed to be performing at that time (Access Authority) The access authority level of the user (Last Usage History) The last operation history of the user using the information management system 200 (i.e., information about the automatic analysis device 100 that was last accessed).

[0049] When the access management unit 240 detects an unauthorized usage situation according to the check rules, it alerts the administrator by, for example, highlighting the mobile terminal 300 on the management screen (the thick line frame in Fig. 7). When the administrator selects the highlighted item, the access management unit 240 can prompt the administrator to give specific instructions by presenting the screen in Fig. 8.

[0050] Fig. 8 is an example of a screen interface for instructing measures for the mobile terminal 300 with unauthorized usage. If it is set in the check rules to send a warning to the administrator when unauthorized access is detected, the access management unit 240 displays the usage status of the mobile terminal 300 on the administrator terminal through a notification screen as shown in the example of Fig. 8. Furthermore, when the administrator selects "Yes", the access authority level of the terminal is lowered, and the information of the terminal is deleted from the mobile terminal table. As a result, the terminal is in a state of logging out from the information management system 200. Depending on the setting of the check rules, at least either forcibly lowering the access authority level of the terminal or logging it out may be performed when an unauthorized situation occurs without the administrator's manual operation.

[0051] <Summary of Embodiment 1> When the information management system 200 according to Embodiment 1 detects an unauthorized use situation of the mobile terminal 300, it performs at least one of transmitting a warning to that effect or reducing the access privilege level of the mobile terminal 300. Even when reducing the access privilege level, it is not necessary to prohibit access to all services of the information management system 200 (that is, all information related to the automatic analysis device 100), and some services may continue to be available. Thereby, it is possible to achieve both ensuring the security of information related to the automatic analysis device 100 and maintaining the convenience of the user.

[0052] As a check rule used when the information management system 200 according to Embodiment 1 detects an unauthorized use situation of the mobile terminal 300, as exemplified in FIGS. 5A to 5C, it is possible to set judgment criteria suitable for the actual situation such as the facility where the automatic analysis device 100 is installed and countermeasures at the time of unauthorized detection. Thereby, security management suitable for the facility becomes possible.

[0053] <Embodiment 2> In Embodiment 1, an example in which the information management system 200 maintains information security by reducing the access privilege level of the user has been described. On the other hand, in order to be able to continue using the mobile terminal 300 even if the communication between the mobile terminal 300 and the information management system 200 is disconnected, the information held by the information management system 200 is downloaded to the mobile terminal 300 so that the downloaded information can continue to be used even when the mobile terminal 300 goes offline. At this time, how to ensure the security of the information downloaded to the mobile terminal 300 becomes an issue. In Embodiment 2 of the present invention, an example of a countermeasure against this security issue will be described. The configurations of the information management system 200, the mobile terminal 300, and the automatic analysis device 100 are the same as those in Embodiment 1.

[0054] FIG. 9 is a diagram for explaining a processing procedure when communication between the mobile terminal 300 and the information management system 200 is disconnected. For steps similar to those in FIG. 3, the same step numbers are assigned and the explanations are omitted. It is assumed that S301 has been executed.

[0055] (FIG. 9: Step S901) The access management unit 240 transmits information for identifying the user (e.g., user ID) and information for determining whether the usage status of the mobile terminal 300 is legitimate (the check rules described in FIGS. 5A to 5C) to the mobile terminal 300. The access management unit 340 stores these in the storage medium 320.

[0056] (FIG. 9: Step S902) This step is generally the same as S304, but the processing in the mobile terminal 300 is different from that in the first embodiment. Each time the computer 310 acquires information about the automatic analysis device 100 from the information management system 200, it stores that information in the storage medium 320. Thereby, even when the communication between the mobile terminal 300 and the information management system 200 is disconnected, the user can continue operations while remaining in the offline state.

[0057] (FIG. 9: Step S903) When the communication between the mobile terminal 300 and the information management system 200 is disconnected, the information management system 200 detects this. For example, if communication from the mobile terminal 300 to the information management system 200 does not occur continuously for a predetermined time or more, it can be determined that the communication has been disconnected. The service providing unit 230 does not provide services to the mobile terminal 300 (does not provide information about the automatic analysis device 100) while the communication with the mobile terminal 300 is disconnected.

[0058] (FIG. 9: Steps S904 to S906) The user refers to the information obtained from the information management system 200 on the mobile terminal 300 (S904). The access management unit 340 determines whether the usage status of the mobile terminal 300 is legitimate according to the check rule obtained from the information management system 200 in S902 (S905). If an unauthorized usage status is detected, the access management unit 340 reduces the access privilege level of the user in the same way as in S309, and deletes all data that requires access rights from the storage medium 320 (S906).

[0059] (Fig. 9: Step S906: Supplementary) By deleting the data that requires access rights from the storage medium 320, the access privilege level of the user on the mobile terminal 300 becomes substantially the same as when the access privilege level is reduced on the information management system 200. This is because the range of information items accessible to the user becomes narrower. Regarding which range of information items to delete, it may be determined according to the check rule obtained from the information management system 200, in accordance with the accessible range after reducing the access privilege level on the information management system 200.

[0060] (Fig. 9: Step S907) When the mobile terminal 300 and the information management system 200 are reconnected, the access management unit 340 transmits the current access privilege level of the user and the operation history of the mobile terminal 300 during the offline period to the information management system 200. The access management unit 240 detects that the mobile terminal 300 has been reconnected by that notification. The access management unit 240 reflects the access privilege level received by the notification. If the access privilege level was not reduced in S905 - S906, the user can continue to use the service with the same access privilege level as before the communication was disconnected. If the access privilege level was reduced in S905 - S906, the reduced access privilege level remains until the user logs in again to the information management system 200.

[0061] (Fig. 9: Step S907: Supplementary) When the communication between the mobile terminal 300 and the information management system 200 is disconnected, the access management unit 240 may lower the access privilege level of the user according to the check rules. On the other hand, if the access privilege level is not lowered in S905 to S906, the original access privilege level is notified from the mobile terminal 300 to the information management system 200 in S907, so that the access privilege level will not be lowered. That is, the access privilege level on the information management system 200 side and the access privilege level on the mobile terminal 300 side are different from each other. For the information management system 200, since it trusts the access privilege level reported by the mobile terminal 300, there are certain security concerns. However, since the information management system 200 is operated in an environment where the automatic analysis device 100 is installed, such concerns are considered to be limited as long as it operates within that closed environment. Therefore, in the present invention, it is decided to process as in S907 with priority given to convenience.

[0062] <Embodiment 2: Summary> The information management system 200 according to the second embodiment enables the mobile terminal 300 to continue to view information even when it is offline by downloading information related to the automatic analysis device 100 onto the mobile terminal 300. When an unauthorized use situation is detected during offline operation, the access management unit 340 substantially reduces the access privilege level on the terminal by deleting the information downloaded to the mobile terminal 300. Thereby, while considering the convenience during offline operation, the information security of the automatic analysis device 100 via the mobile terminal 300 can be maintained.

[0063] When an unauthorized usage situation occurs on the mobile terminal 300 while the mobile terminal 300 is offline, the information management system 200 according to the second embodiment reduces the access privilege level on the mobile terminal 300, and when the communication is restored, notifies the information management system 200 of the reduced access privilege level. The information management system 200 reflects the received access privilege level on the terminal. Thereby, even when there is no check rule for reducing the access privilege level in the information management system 200 at the time of communication disconnection, the mobile terminal 300 can autonomously detect an unauthorized usage situation, and information security can be maintained.

[0064] When an unauthorized usage situation does not occur on the mobile terminal 300 while the mobile terminal 300 is offline, the information management system 200 according to the second embodiment maintains the access privilege level on the mobile terminal 300 as it was at the time of login, and when the communication is restored, notifies the information management system 200 of the access privilege level. The information management system 200 reflects the received access privilege level on the terminal. Thereby, even when the access privilege level is reduced in the information management system 200 at the time of communication disconnection, as long as the mobile terminal 300 is being used properly, the user can be spared the trouble of re-logging in to restore the access privilege level.

[0065] <Regarding a modification of the present invention> In the above embodiments, the device information acquisition unit 210, the user input reception unit 220, the service provision unit 230, the access management unit 240, and the access management unit 340 can be configured by hardware such as a circuit device that implements these functions, or can be configured by a computing device executing software that implements these functions. The access management unit 340 is a dedicated module that implements processing for transmitting and receiving data between the mobile terminal 300 and the information management system 200 according to the above embodiments ( It can be implemented (either as hardware / software is acceptable).

[0066] In the above embodiments, as an example of the automatic analyzer 100, a multi-item chemical analyzer that analyzes a plurality of requested items of a specimen by a photometry method can be mentioned. However, the present invention is not limited to this, and the present invention is applicable to various automatic analyzers that handle samples such as patient specimens.

Explanation of Signs

[0067] 100: Automatic analyzer 1: Specimen container 2: Specimen transfer mechanism 3: Microcomputer 4: Interface 5: Specimen dispenser 6: Liquid level detector 7: Reagent dispenser 8: Reaction vessel transfer mechanism 9: Liquid level detector 10: Reagent container 11: Reaction vessel 12: Display device 13: Input device (such as a mouse, keyboard, etc.) 14: Reagent ID reader 15: Storage medium 16: Memory area 17: Reagent storage 18: Printer 19: Specimen ID reader 200: Information management system 210: Device information acquisition unit 220: User input reception unit 230: Service provision unit 240: Access management unit 250: Storage medium 300: Mobile terminal 310: Computer 320: Storage medium 330: Display device 340: Access management unit 350: User input reception unit

Claims

1. An information management system that provides data describing information about an automatic analyzer for analyzing samples to a remote terminal, comprising a server that manages the access rights of a user who accesses the information using the remote terminal, wherein the server includes an access management unit that detects a communication disconnection between the remote terminal and the server or a situation of unauthorized use of the remote terminal, and when the access management unit detects the communication disconnection or the unauthorized use situation, it issues a warning to the administrator of the information management system, and reduces the access right to the information from the first access right level before the communication disconnection or the unauthorized use situation occurs to a second access right level lower than that, and at least one of the above is implemented, wherein the second access right level is configured such that the range of access to the information is narrower than the first access right level, and the second access right level is configured to be able to access at least a part of the information, the server includes a storage unit that stores access right data defining a first range of the information that can be accessed according to the first access right level and a second range of the information that can be accessed according to the second access right level, when the access management unit detects the communication disconnection, it reduces the access right of the remote terminal from the first access right level to the second access right level, and when the remote terminal requests access to the information without re-logging in to the server after the access management unit detects the communication disconnection, it rejects access to the first range and permits access to the second range An information management system characterized by the above.

2. When the remote terminal requests access to the information after re-logging in to the server after the access management unit detects the communication disconnection, the access management unit permits access to the first range The information management system according to Claim 1, characterized by the above.

3. The access right data defines access rights for each combination of the role of the user and the type of information provided by the server, When the user logs in to the server using the remote terminal, the access management unit grants access rights corresponding to the user's role for each combination. The information management system according to claim 2, characterized in that.

4. The server further includes an input reception unit that receives a designation input for designating a check rule describing a determination criterion for detecting the occurrence of the unauthorized use situation. The input reception unit provides a check rule input screen used for inputting the designation input. The check rule input screen includes, as determination conditions constituting the check rule, Whether a connection between the remote terminal and the server is established. The elapsed duration during which the remote terminal has passed without accessing the information. From which of the areas formed in the space where the automatic analysis device is installed the remote terminal has accessed the server. An ID for individually identifying the remote terminal. An ID for individually identifying the user. The user's work schedule. The type of the information provided by the server. is configured to be able to input at least any one of them. The information management system according to claim 1, characterized in that.

5. The check rule input screen is configured to be able to input the designation input for designating to perform at least any one of transmitting the warning or reducing the access right for each combination of the determination conditions. The access management unit performs at least any one of transmitting the warning or reducing the access right according to the designation by the designation input. The information management system according to claim 4, characterized in that.

6. When the same user is logged in to the server using the first remote terminal and the second remote terminal at the same time, if the distance between the position of the first remote terminal and the position of the second remote terminal exceeds a threshold value, the access management unit determines that an unauthorized use situation has occurred. The information management system according to claim 1, characterized in that.

7. The access management unit presents, on the server, a list indicating for each user whether the user who is logged in to the server using the remote terminal and the communication disconnection or the unauthorized use situation has occurred. The access management unit provides a measure input screen for inputting measures to be implemented by designating those among the users on the list who have caused the communication disconnection or the unauthorized use situation. The access management unit implements the measures input on the measure input screen for the users designated on the list. The information management system according to claim 1, characterized in that.

8. The access management unit, as the state of the remote terminal, The connection source area of the remote terminal when the remote terminal accesses the server by wireless communication, The communication state between the remote terminal and the server, The operation history of the remote terminal, At least any one of which is obtained from the remote terminal, The access management unit detects the unauthorized use situation according to the obtained state of the remote terminal. The information management system according to claim 1, characterized in that.

9. The remote terminal downloads the information from the server and stores it in the remote terminal. The remote terminal presents the information downloaded from the server on the remote terminal even while the communication between the remote terminal and the server is disconnected. The information management system according to claim 1, characterized in that.

10. The remote terminal includes a terminal access management unit for detecting the unauthorized use situation. When the terminal access management unit detects the unauthorized use situation while the communication between the remote terminal and the server is disconnected, the terminal access management unit deletes at least a part of the information downloaded from the server from the remote terminal, thereby reducing the access right to the information from the remote terminal to be equivalent to the second access right level. The information management system according to claim 9, characterized in that.

11. The terminal access management unit obtains a check rule for detecting the occurrence of the unauthorized use situation from the server. The terminal access management unit detects the unauthorized use situation according to the check rule. The information management system according to claim 10, characterized in that.

12. The remote terminal includes a terminal access management unit for detecting the unauthorized use situation. When the terminal access management unit detects the unauthorized use situation while the communication between the remote terminal and the server is disconnected, it reduces the access authority for the information downloaded into the remote terminal from the server to the level equivalent to the second access authority level. When the communication between the remote terminal and the server is restored, the terminal access management unit notifies the server of the reduced access authority level. The access management unit controls the access authority for the information from the remote terminal according to the access authority level received by the notification. The information management system according to claim 9, characterized in that.

13. The remote terminal includes a terminal access management unit that detects the unauthorized use situation. When the terminal access management unit does not detect the unauthorized use situation while the communication between the remote terminal and the server is disconnected, it maintains the access authority for the information downloaded into the remote terminal from the server at the same level as before the disconnection of the communication. When the communication between the remote terminal and the server is restored, the terminal access management unit notifies the server of the maintained access authority level. The access management unit controls the access authority for the information from the remote terminal according to the access authority level received by the notification. The information management system according to claim 9, characterized in that.

14. An information management method for managing the information by using an information management system that provides data describing information related to an automatic analyzer for analyzing a sample to a remote terminal, comprising a step of managing the access authority of a user who accesses the information by using the remote terminal, The step of managing the access authority includes a step of detecting a disconnection of communication between the remote terminal and the information management system or an unauthorized use situation of the remote terminal. In the detecting step, when the disconnection of communication or the unauthorized use situation is detected, sending a warning to the administrator of the information; reducing the access authority for the information from the remote terminal from a first access authority level before the occurrence of the disconnection of communication or the unauthorized use situation to a second access authority level lower than that; performing at least any one of them. The second access authority level is configured such that the range of access to the information is narrower than the first access authority level. The second access authority level is configured to be able to access at least a part of the information. The information management system includes a storage unit that stores access authority data defining a first range of the information that can be accessed by the first access authority level and a second range of the information that can be accessed by the second access authority level. In the step of managing the access authority, when the communication disconnection is detected, the access authority of the remote terminal is lowered from the first access authority level to the second access authority level. In the step of managing the access authority, when the remote terminal requests access to the information without re-logging in to the information management system after the communication disconnection is detected, access to the first range is denied and access to the second range is permitted. An information management method characterized by the above.

Citation Information

Patent Citations

  • Information processor

    JP2006185113A

  • Security management method and apparatus and program for security management

    JP2006251932A

  • Portable device management system

    JP2008090469A

  • Access authority control system

    JP2009080560A

  • Program, method and apparatus for controlling access

    JP2010055297A