Device management apparatus, control method of device management apparatus, and program
The device management system addresses the challenge of managing region-less devices and cross-region tasks by enabling them to operate like region-bound devices and providing flexible access control, thus reducing administrative burdens and enhancing management efficiency.
Patent Information
- Application Number
- JP2020200942
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-12-03
- Publication Date
- 2025-06-30
- Estimated Expiration
- 2040-12-03
AI Technical Summary
Conventional device management systems struggle with managing devices not belonging to a region and tasks executed across regions, leading to administrative burdens due to the need for special operations and restrictive access controls.
A device management system that allows devices not belonging to a region to be operated like region-bound devices, with access control enabled through a free combination of regions using setting means for users, devices, and tasks, and control means for managing access based on predetermined set values.
Enables seamless operation of region-less devices and flexible access control across regions, reducing administrative burdens and enhancing management efficiency in multi-region environments.
Smart Images

Figure 0007699921000001 
Figure 0007699921000002 
Figure 0007699921000003
Abstract
Description
Technical Field
[0001] The present invention relates to a device management apparatus, a control method for the device management apparatus, and a program.
Background Art
[0002] Conventionally, there has been a device management system including a management apparatus that manages devices connected to a network arranged at a plurality of sites. Patent Document 1 describes a management apparatus that manages monitoring apparatuses for monitoring devices at each site by attributes such as regions. In order to avoid duplicate monitoring in the installation environment of the monitoring apparatuses, there has been a concept of region management conventionally.
[0003] Patent Document 2 proposes a technique of hierarchically configuring regions, granting access rights to users, and providing an exceptional process to permit access to devices belonging to regions outside the hierarchy.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the conventional technology, regarding devices not belonging to a region and tasks executed across regions, how to apply region management has not been considered. Further, when hierarchically configuring regions as in Patent Document 2, a special operation for applying exceptional control to devices belonging to regions outside the hierarchy has been required. For this reason, a burden has been imposed on administrators and the like.
[0006] The present invention has been made to solve the above problems. The object of the present invention is to provide a mechanism that enables a device not belonging to a region to be operated in the same manner as a device belonging to the region, and enables access control by a free combination of regions.
Means for Solving the Problems
[0007] The present invention Device management device includes first setting means for setting an attribute for a region, second setting means for setting a region for a user from among one or more regions whose attributes have been set by the first setting means, third setting means for setting a region for a device from among one or more regions whose attributes have been set by the first setting means, fourth setting means for setting a task that defines an operation on a device to be managed, And a predetermined set value and control means for controlling access by the user to the device and the task in accordance with the set regions, and is characterized in that As, from among one or more regions whose attributes are set by the first setting means, set a region for the task the control means s does the following. The predetermined set value is a set value for enabling access to all the devices and the task regardless of the region. The user for whom the predetermined set value is set as the region by the control means Can access the device and the task without any restrictions This is the gist of the invention.
Effects of the Invention
[0008] According to the present invention, it is possible to operate a device not belonging to a region in the same manner as a device belonging to the region, and to provide an access control function by a free combination of regions.
Brief Description of the Drawings
[0009]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10A
Figure 10B
Figure 11
Figure 12
Mode for Carrying Out the Invention
[0010] Hereinafter, embodiments for carrying out the present invention will be described with reference to the drawings. 〔First Embodiment〕 FIG. 1 is a diagram showing an example of the overall configuration of a network device management system showing an embodiment of the present invention.
[0011] The device management system of this embodiment is composed of one device management application 101 and a plurality of agent applications (hereinafter referred to as “agents”) 102 and 103, etc. With such a device management system, network devices (hereinafter referred to as “devices”) 104 to 107 are managed.
[0012] The device management application 101, agent applications 102 and 103, and devices 104 to 107 are communicably connected to each other by a network 108. The device management application 101 manages devices on the network by attributes such as regions. The network 108 may be a combination of the Internet and a LAN. Here, the agent applications 102 and 103 and the devices 104 to 107 are associated according to the addresses of the devices, etc. In this embodiment, for example, it is assumed that the agent application 102 is associated with the devices 104 and 105, and the agent 103 is associated with the devices 106 and 107.
[0013] Hereinafter, the agent application 102 will be used as a representative of the agents, and the device 104 will be used as a representative of the devices for explanation, but the same applies to the agent 103, the devices 105 or 106.
[0014] The device management application 101 instructs the agent application 102 to perform an operation on the device 104 as a task. In accordance with this instruction, the agent application 102 performs operations such as sending a request to the device 104, and sends the result of the operation to the device management application 101. Examples of the above operations include operations such as acquiring information from the device 104, changing the set value of the device 104, and instructing the installation of an application on the device 104.
[0015] Note that the device management application 101 is realized by a CPU of a computer loading and executing a program stored in a ROM, an external storage device, etc. or downloaded from a network into a RAM as needed. This computer may be composed of a plurality of computers, or may be a configuration realized by using a cloud service, etc. The device on which the device management application 101 operates may also be called a device management device.
[0016] In addition, the agent applications 102 and 103 are realized by the CPU of a computer, such as shown in FIG. 2, loading and executing a program stored in a ROM, an external storage device, etc. or downloaded from a network into a RAM as necessary. Note that the device on which the agent application 102 or 103 operates may also be referred to as a monitoring device.
[0017] In the example of FIG. 1, there are two agents and four devices, but the number of agents may be one or three or more, and the number of devices may be three or less or five or more. For example, even when managing tens of thousands of devices via a dozen or so agents, the configuration and operation are the same as the description of this embodiment.
[0018] FIG. 2 is a block diagram showing an example of the hardware configuration of a host computer on which the device management application 101, the agent applications 102 and 103 operate.
[0019] As shown in FIG. 2, the host computer includes a CPU 201, a RAM 202, a ROM 203, and an external storage device 207. The CPU 201 loads and executes software (program) stored in the ROM 203 or the external storage device 207 or downloaded from the network 210 into the RAM 202 as necessary, and comprehensively controls each device connected to the system bus 209.
[0020] The RAM 202 functions as the main memory or work area of the CPU 201. The external storage device 207 consists of a hard disk (HD), a solid state drive (SSD), etc. The external storage device 207 stores various applications including a boot program, an operating system (OS), an authentication server, an authentication client, etc., database data, various data such as user files.
[0021] KBDC204 is a keyboard controller. KBDC204 sends input information from input devices such as a keyboard and a pointing device (not shown) to CPU201. VC205 is a video controller. VC205 controls the display of a display device composed of an LCD or the like.
[0022] DC206 is a disk controller that controls access to an external storage device 207. NIC208 is a communication controller. The host computer is connected to network 210 via NIC208.
[0023] Figure 3(a) is a diagram showing an example of the functional configuration of the device management application 101. The agent management unit 301 manages information regarding agent applications 102 and 103. The device management unit 302 manages information regarding devices 104 to 107. The information regarding a device includes information on the agent associated with the device and information on the region associated with the device.
[0024] The region management unit 303 stores information regarding regions defined by the user. The task management unit 304 manages the content and results of operations on devices, or instructs the agent application 102 to operate on the device 104. These management information and various management information such as a device group (not shown) are stored in a database (not shown).
[0025] The HTTP / HTTPS server 305 receives requests from the agent application 102 and the device 104. Also, the HTTP / HTTPS server 305 provides a WEB UI for the user to operate the device management application 101.
[0026] Figure 3(b) is a diagram showing an example of the functional configuration of the agent application 102. The task execution unit 310 executes an operation on the device 104 according to the instruction of the device management application 101, and then transmits the result to the device management application 101. The HTTP / HTTPS server 311 receives requests from the device management application 101 and the device 104.
[0027] FIG. 4 is a diagram showing an example of a screen for setting a region. Note that the screens shown in FIG. 4 and FIGS. 5 to 8 described later are provided as a WEB UI by the HTTP / HTTPS server 305. That is, in response to a user operation or the like, a web browser or the like of a client computer (not shown) requests the HTTP / HTTPS server 305, and these screens are displayed on the web browser or the like and can be operated by the user.
[0028] FIG. 4(a) shows an example of a screen for displaying a list of set regions. The region list 401 shows a list of created regions. In the example of FIG. 4(a), as information for each region, the region name defined by the user, the date and time when the region was last edited, and the number of devices belonging to the region are displayed. Each device that is the management target of the device management application 101 has a region. For each device that is the management target, one of the regions displayed in the region list 401, or "unassigned" that does not belong to any region, is set.
[0029] The "delete" button 402 is a button for deleting a specified region. When the device management application 101 detects that the user presses the "delete" button 402, it displays a dialog for deletion confirmation (not shown), and when it detects the user's deletion confirmation, it deletes the region from the database. Simultaneously with the deletion, the device management application 101 changes the region information set in the device to "no region" (unassigned).
[0030] When the device management application 101 detects a click on a row (region) in the region list 401 by the user or a press of the "New Creation" button 403, it changes the screen to a region editing screen as shown in Fig. 4(b).
[0031] Fig. 4(b) shows an example of a screen for performing detailed settings for each region. This screen is displayed when the user clicks on a row (region) in the region list 401 in Fig. 4(a) or clicks the "New Creation" button 403.
[0032] The region name 410 is a text box for entering the name of the region. The IP address range 411 is a text box for entering the range of IP V4 addresses of the devices belonging to the region. The address range is entered in the form of "address" or "start address - end address". Multiple lines of input are possible for the range of IP V4 addresses. If the input of the address range is incorrect, the device management application 101 sets the save button 413 to be disabled.
[0033] The FQDN name suffix match 412 is a text box for entering the suffix match string of the FQDN names of the devices belonging to the region. Multiple lines of input are possible for the suffix match string of the FQDN. Note that FQDN is the abbreviation of Fully Qualified Domain Name.
[0034] When transitioning to this screen by clicking on a row (region) in the region list 401, the device management application 101 sets the values set for the clicked region to 410, 411, and 412 respectively.
[0035] When the device management application 101 detects a press of the "Cancel" button 414 by the user, it discards the input to the screen shown in Fig. 4(b) and changes the screen to the region list screen in Fig. 4(a).
[0036] When the device management application 101 detects that the user has pressed the "Save" button 413, it checks whether the IP V4 address ranges set in other regions overlap with the address range entered in the IP address range 411. If such an overlap is detected, the device management application 101 displays a warning indicating the same on the screen (not shown). On the other hand, if no such overlap is detected, the device management application 101 saves the settings entered on the screen of Fig. 4(b) to the database. Thereafter, the device management application 101 creates or changes the region of the device that satisfies the information entered on the screen of Fig. 4(b) and switches the screen to the region list screen of Fig. 4(a).
[0037] As described above, attributes can be set for each of a plurality of regions. Also, based on the attributes (such as the IP address range) of the regions set in this way, regions will be set for the devices.
[0038] FIG. 5 is a diagram showing an example of a screen for adding or editing a user of the device management application. The user name 501 is a text box for entering the user name used for logging in to the system and the like. The role 502 is a drop-down list for selecting the role of the user. As the role of the user, "system administrator" and "device administrator" can be selected. A user with the "system administrator" role can add, edit, and delete users, and add, edit, and delete regions. A user with the "device administrator" role cannot perform these processes.
[0039] The region setting 503 is a drop-down list for selecting the user's region setting. In the region setting 503, "region-independent" and "select region" can be selected. When "select region" is selected in the region setting 503, the user will select the region to which they belong using the checkbox 504. The checkbox 504 is a checkbox for selecting the region to which the user belongs. On the other hand, when "region-independent" is selected in the region setting 503, the checkbox 504 for region selection becomes unavailable.
[0040] If no region is set in the device management application 101, these UI components (503, 504) are not displayed. In this case, the user's region setting is the same as when "region-independent" described below is selected.
[0041] Note that for users with the "system administrator" role, only options other than "region-independent" can be selected in the region setting 503. When "region-independent" is set in the region setting 503, the user can access all devices, device groups, and tasks regardless of the region. Hereinafter, such a user is also referred to as a "region-independent" user.
[0042] Also, when "Select Region" is selected in the region setting 503, the user is set as a user belonging to the regions checked in the checkbox 504. The user can belong to one or more regions. A user belonging to a region can access devices belonging to the region to which the user belongs, device groups and tasks associated only with a part of the region to which the user belongs. For example, in the case of the user set on the screen of FIG. 5, the user can access device groups and tasks associated with the regions of "France" and "Spain", "France" only, and "Spain" only. The user cannot access device groups and tasks that include even one region to which the user does not belong, such as "France" and "Italy", "Germany", etc. Hereinafter, a user belonging to a region is also referred to as a "region-specified" user.
[0043] When the device management application 101 detects that the user presses the "Save" button 505, it saves the user information in the database according to the settings on the screen. When the device management application 101 detects that the user presses the "Delete" button 506, it displays a dialog for confirming the deletion of the user displayed on the screen, and when it detects the user's confirmation of deletion, it deletes the user from the database. The "Delete" button 506 is not displayed when a new user is added.
[0044] When the device management application 101 detects that the user presses the "Cancel" button 507, it discards the input on this screen by the user and transitions to a user list screen (not shown). In the above manner, a region can be set for the user.
[0045] Figure 9 is a flowchart showing an example of a process (device list acquisition process) when the device management application 101 acquires a list of devices that can be managed by a user. The process of this flowchart is executed by the device management application 101. That is, the process of this flowchart is realized by the CPU of a computer loading and executing a program (device management application 101) stored in an external storage device or the like into the RAM as necessary, as shown in FIG. 2. The device management application 101 starts the process of this flowchart when acquiring a list of devices that can be managed by a target user (for example, a user who has logged in to the device management application 101 and is performing a predetermined operation).
[0046] Note that a query for filtering the devices to be acquired is passed as an argument to this process. An example of a filter described in JSON format is shown in FIG. 12(a). FIG. 12 is a diagram showing an example of a filter described in JSON format. The filter example shown in FIG. 12(a) means that 200 devices starting with "H1" in "Device Name" are sorted in descending order of "Product Name" and the 201st to 200th are acquired.
[0047] First, in S901, the device management application 101 checks whether the target user (hereinafter simply referred to as "user") is "region-independent". As a result of this check, if the user is "region-independent" (Yes in S901), since the user can access all devices, the device management application 101 proceeds to S904. In this case, in S904, the device management application 101 executes the query passed as the above argument and proceeds to S905. In S905, the device management application 101 returns the query execution result of S904 to the caller and ends the process of this flowchart.
[0048] On the other hand, as a result of the inspection in S901, if the user selects "Region Specified" (when the answer in S901 is No), the device management application 101 proceeds to S902 for processing. In S902, the device management application 101 obtains a list of identifiers of the regions to which the user belongs. Here, the identifier is a numerical value or a character string assigned to each region by the device management application 101 for identifying each region, separate from the name set by the user. For simplicity of explanation, numerical values are used here.
[0049] Next, in S903, the device management application 101 merges the identifiers of the regions to which the user belongs, obtained in S902 above, into the query passed as the above argument. For example, when the identifiers (numerical values) of the regions to which the user belongs are "101" and "103", the result of the above merging is shown in Fig. 12(b). The example shown in Fig. 12(b) means that a condition "Region Identifier (RegionId) is included in (In) the list '101', '103'" is added to the query passed to the process.
[0050] After S903 above, the device management application proceeds to S904 for processing. In this case, in S904, the device management application executes the query merged with the above filter and proceeds to S905 for processing. In S905, the device management application 101 returns the query execution result in S904 above to the caller and ends the processing of this flowchart.
[0051] Here, for example, assume that the query passed as an argument to the device list acquisition process already includes a filter condition by region as shown in Fig. 12(c). In the case of the example shown in Fig. 12(c), in the merge result of the filter in S903 above, in order to further narrow down the specified "101" by the argument to "101" and "103", which are the regions to which the user belongs, only the common "101" between the two remains. As a result, in S903 above, the same filter as the original (Fig. 12(c)) will be generated.
[0052] Through the above processing, a list of devices that can be managed by the user can be obtained. Then, the device management application 101 can appropriately control the user's access to the device according to the set region using the list obtained in this way. Thereby, when the user belongs to one or more regions, access to devices belonging to regions to which the user does not belong can be restricted.
[0053] Fig. 6 is a diagram showing an example of a screen for creating or editing a device group. Devices belonging to a device group are specified by individually specifying the devices or by specifying the conditions for device selection. The conditions that can be specified include, for example, that the specified character string is included in the product name of the device, the IPv4 address of the device is within the specified range, and so on.
[0054] Fig. 6(a) corresponds to an example of a screen when specifying devices individually. The group name 601 is a text box for entering the device name.
[0055] The region settings 602 and 603 are UI components for specifying the regions to which the device group belongs. The configuration and display of these UI components change according to the region information set in the device management application 101 and the region settings of the user operating the screen. When no region is set in the device management application 101, these UI components are not displayed. In this case, the region setting of the device group is the same as when "region-independent" described below is selected.
[0056] When the region setting of the operating user is "region-independent", the dropdown 602 allows "region-independent" and "select region" to be selectable. On the other hand, when the region setting of the operating user is not "region-independent", that is, when it belongs to one or more specified regions, only "select region" is selectable in the dropdown 602. When "select region" is selected in the dropdown 602, the checkbox 603 for region selection becomes enabled. The regions selectable by the checkbox 603 are all the regions set in the device management application 101 when the user is "region-independent", and are the regions to which the user belongs when the user belongs to one or more regions.
[0057] Table 604 is a table for selecting the devices belonging to the device group here. The devices displayed in the table 604 change according to the selections of the region settings 602 and 603 of the device group. When "region-independent" is selected in the dropdown 602, all devices are displayed in the table 604. Also, when "select region" is selected in the dropdown 602, the devices belonging to the region selected by the checkbox 603 are displayed in the table 604.
[0058] When the device management application 101 detects the user pressing the "Save" button 605, it saves the content of each input (group name, region setting, list of selected devices) as device group information in the database. Then, the device management application 101 causes the screen to transition to a device group list screen (not shown).
[0059] When the device management application 101 detects that the user presses the "Delete" button 606, it deletes the device group from the database and causes the screen to transition to a device group list screen (not shown). Note that the "Delete" button 606 is not displayed when creating a new device group.
[0060] When the device management application 101 detects that the user presses the "Cancel" button 607, it discards the input on the screen and causes the screen to transition to a device group list screen (not shown).
[0061] FIG. 6(b) corresponds to an example screen of the device selection part when specifying devices belonging to a device group according to conditions. The device selection part (the part of table 604) in FIG. 6(a) is replaced with the content shown in FIG. 6(b). When creating a device group by specifying conditions, the device management application 101 selects devices that meet the conditions when the devices belonging to the device group are needed.
[0062] The filter 610 is a drop-down for selecting filter items, and the items that can be specified as filters are listed. When the device management application 101 detects that the user presses the "Add" button 611, it adds the filter setting of the filter selected in the filter 610 to the top of the list of the currently specified filter settings indicated by 612 to 613.
[0063] 612 to 613 are a list of the currently specified filter settings. The filter setting is composed of a filter item, a filter operation, and a filter value. In the case of the filter setting 612, the filter item, the filter operation, and the filter value are "Device Name", "Starts with the specified value", and "HQ", respectively. In the case of the filter setting 613, the filter item, the filter operation, and the filter value are "Product Name", "Contains the specified value", and "LBP", respectively. Note that in the example of FIG. 6(b), two filter settings of 612 and 613 are described, but one or three or more filter settings may also be used.
[0064] The above filter operation dropdown has different selectable values depending on the type of filter item. For example, when the filter item is a string such as "device name" or "product name", "equal to the specified value", "not equal to the specified value", "starting with the specified value", "ending with the specified value", or "including the specified value" can be selected. Also, when the filter item is "IP address", only "within the specified range" can be selected. And for the filter value, it is possible to specify a range of addresses such as "172.29.60.0 - 172.29.61.255" or a single address such as "172.29.62.10".
[0065] When detecting a click on the "×" at the right end of the filter setting, the device management application 101 deletes the filter setting from the list of currently specified filter settings.
[0066] When detecting a press of the "Apply" button 614 by the user, the device management application 101 displays, in the table 616, the devices that match the region settings 602 and 603 in Fig. 6(a) and the currently specified filter settings 612 - 613 in Fig. 6(b).
[0067] For example, when "Region - independent" is selected in the dropdown 602 in Fig. 6(a), the table 616 displays the devices that satisfy both the conditions of the filter settings 612 and 613 among all the devices. Or, when "Select region" is selected in the dropdown 602, the table 616 displays the devices that satisfy both the conditions of the filter settings 612 and 613 among the devices belonging to the region selected by the checkbox 603.
[0068] When detecting a press of the "Cancel" button 615 by the user, the device management application 101 deletes all the filter settings (612 and 613 in the example of Fig. 6(b)) and updates the device list 616.
[0069] When the device management application 101 detects that the user presses the "Save" button 605, it saves the content of each input (group name, region setting, filter setting) as information of the device group in the database. Then, the device management application 101 causes the screen to transition to a device group list screen (not shown).
[0070] Existing device groups that can be selected and edited by the user depend on the user's region setting. When the user is "region-independent", all device groups can be selected and edited. When the user belongs to one or more regions, only the device groups belonging to the regions to which the user belongs can be selected and edited. That is, the user cannot select and edit device groups that include even one region to which the user does not belong or "region-independent" device groups. In the above manner, a region can be set for the device group.
[0071] FIG. 10A is a flowchart showing an example of a process (device group list acquisition process) when the device management application 101 acquires a list of device groups that can be managed by the user. The processes shown in the flowcharts of FIGS. 10A and 10B are executed by the device management application 101. That is, the processes shown in the flowcharts of FIGS. 10A and 10B are realized by the CPU of a computer such as that shown in FIG. 2 loading a program (device management application 101) stored in an external storage device or the like into the RAM as needed and executing it. The device management application 101 starts the process of this flowchart when acquiring a list of device groups that can be managed by the target user.
[0072] First, in S1001, the device management application 101 acquires a list of device groups set in the device management application 101.
[0073] Next, in S1002, the device management application 101 checks whether the target user (hereinafter referred to as "user") is "region-independent". If the user's region setting is "region-independent", this means having access rights to all device groups. Therefore, if the result of the check is "region-independent" (Yes in S1002), the device management application 101 transitions the process to S1005. In this case, in S1005, the device management application 101 returns the device group list obtained in S1001 to the caller and ends the processing of this flowchart.
[0074] On the other hand, if the result of the check in S1002 is "region specified" (No in S1002), the device management application 101 proceeds to S1003. In S1003, the device management application 101 obtains a list of regions to which the user belongs. Next, in S1004, the device management application 101 deletes device groups that are not under management from the device group list obtained in S1001 according to the region list to which the user belongs and the region settings of the device groups. Details are shown in Figure 10B. Finally, in S1005, the device management application 101 returns the device group list obtained in S1004 to the caller and ends the processing of this flowchart.
[0075] Figure 10B is a flowchart showing an example of a process for determining whether a device group can be deleted in the process of deleting unmanaged groups in S1004 of Figure 10A. Note that in S1004 of Figure 10A, the device management application 101 deletes device groups that are not under management from the device group list according to the result of the determination process shown in Figure 10B for each device group in the device group list obtained in S1001.
[0076] First, in S1010, the device management application 101 acquires the region setting of the device group to be inspected.
[0077] Next, in S1011, the device management application 101 inspects whether the region setting acquired in S1010 is "independent of region". A user with a specified region cannot manage a device group that is "independent of region". Therefore, when the region setting of the device group is "independent of region" (when Yes in S1011), the device management application 101 transfers the process to S1013. And in S1013, the device management application 101 returns to the caller that the device group is not subject to management, and ends the process of this flowchart.
[0078] On the other hand, when the region setting of the device group is region-specified (when No in S1011), the device management application 101 proceeds to S1012. In S1012, the device management application 101 inspects the inclusion relationship between the region group to which the user belongs and the region group to which the device group belongs. When the region group to which the user belongs includes the region group to which the device group belongs, the user can manage the device group. Therefore, in this case (when Yes in S1012), the device management application 101 transfers the process to S1014. In S1014, the device management application 101 returns to the caller that the device group is subject to management, and ends the process of this flowchart.
[0079] On the other hand, when the region group to which the user belongs does not include the region group to which the device group belongs, the device management application 101 transfers the process to S1013. In S1013, the device management application 101 returns to the caller that the device group is not under management, and ends the process of this flowchart.
[0080] Through the above processing, a list of device groups that can be managed by the user can be obtained. Then, the device management application 101 can appropriately control the user's access to the device group according to the set region using the list thus obtained. Thereby, when the user belongs to one or more regions, access to the device groups belonging to the regions to which the user does not belong can be restricted.
[0081] Hereinafter, with reference to FIGS. 7 and 8, a screen for creating and editing tasks will be described. Here, a task is a set of settings for executing a specified process on a selected device. By creating a task, it becomes possible to repeatedly execute the same process. Examples of tasks include distributing an address book including the fax destination and the transmission destination of the scanned image to a digital multifunction machine (device), and obtaining the total number of printed sheets after shipment for each attribute such as color, monochrome, printing, and copying of the digital multifunction machine.
[0082] FIG. 7 is a diagram showing an example of a screen for creating and editing a task of distributing a CA certificate to a digital multifunction machine. Although FIG. 7 takes the creation and editing of a task of distributing a CA certificate to a digital multifunction machine as an example, it is not limited thereto. Further, the device management application 101 can manage the state of each certificate installed in each of the devices to be managed, including the CA certificate distributed to the devices to be managed. Specifically, the device management application 101 collects information such as information on installed certificates, expiration dates, and status (valid / invalid) from each of the devices to be managed at a predetermined schedule. Furthermore, the device management application 101 also has a function of providing information in order to display the collected information on a web browser.
[0083] In FIG. 7, the task type 701 is a character string indicating the type of task. Note that the task type may be made selectable and editable by the user as a drop-down. In this example, when creating a new task, it is assumed that the user has selected the task type before the screen in FIG. 7 is displayed.
[0084] The task name 702 is a text box for entering the name of the task. The region settings 703 and 704 are UI components for specifying the region to which the task belongs. The configuration and display of these UI components change according to the region information set in the device management application 101 or the region settings of the user operating the screen. Note that when no region is set in the device management application 101, these UI components are not displayed. In this case, the region setting of the task is the same as when "region-independent" described below is selected.
[0085] When the region setting of the user operating is "region-independent", "region-independent" and "select region" can be selected in the drop-down 703. On the other hand, when the region setting of the user operating is not "region-independent", that is, when belonging to one or more specified regions, only "select region" can be selected in the drop-down 703.
[0086] When "select region" is selected in the drop-down 703, the check box 704 for region selection becomes effective. The regions selectable by the check box 704 are all the regions set in the device management application when the user is "region-independent", and the regions to which the user belongs when the user belongs to one or more regions. The operation in this regard is the same as that of 602 and 603 in the device group in FIG. 6(a).
[0087] Schedule settings 705 and 706 are UI components for specifying the execution schedule of tasks. Drop-down 705 is a drop-down for selecting the type of schedule. Examples of schedule types include "Specify Date and Time", "Every Day", "Every Week", "Every Month", etc.
[0088] The part for specifying the execution date and time of drop-down 706 changes according to the type of schedule selected in drop-down 705. When "Specify Date and Time" is selected in drop-down 705, as shown in the figure, a component for selecting the date and time is displayed in drop-down 706. For example, when "Every Week" is selected in drop-down 705, although not shown in the figure, a checkbox for selecting the day of the week and a component for setting the execution time are displayed in drop-down 706.
[0089] Table 707 is a table for selecting the CA certificate to be distributed by the task from the CA certificates managed by the device management application 101. Table 708 is a table for selecting the devices to which the task distributes the CA certificate. The devices displayed in table 708 change according to the selections of the region settings 703 and 704 of the task. For example, when "Region-Independent" is selected in drop-down 703, all devices are displayed in table 708. Also, when "Select Region" is selected in drop-down 703, the devices belonging to the region selected in checkbox 704 are displayed in table 708.
[0090] Table 709 is a table for selecting a device group to which the device that distributes the CA certificate belongs. The device groups displayed in Table 709 change according to the selection of region settings 703 and 704 of the task. For example, when "Region-independent" is selected in the drop-down 703, all device groups are displayed in Table 709. Also, when "Select Region" is selected in the drop-down 703, only the device groups belonging to the region selected with the checkbox 704 are displayed. In this case, the "Region-independent" device group and the device groups including regions other than the region selected with the checkbox 704 are not displayed.
[0091] When the device management application 101 detects that the user presses the "Save" button 710, it saves the task settings on the screen as task information in the database and transitions to a task list screen (not shown). At the same time, the device management application 101 determines the next execution date and time of the task according to the schedule settings of the saved task, and makes settings to execute the task at the next execution date and time.
[0092] When the device management application 101 detects that the user presses the "Delete" button 711, it deletes the task from the database and transitions to a task list screen (not shown). The "Delete" button 711 is not displayed when creating a new task.
[0093] When the device management application 101 detects that the user presses the "Cancel" button 712, it discards the input on the screen and transitions to a task list screen (not shown).
[0094] FIG. 8 is a diagram showing an example of an editing screen for a task to delete a CA certificate installed on a device. In FIG. 8, creation and editing of a task to delete a CA certificate installed on a device are taken as an example, but it is not limited thereto. Details of the elements on the same screen as FIG. 7 will not be described in detail. For example, 801 to 806 correspond to 701 to 706 in FIG. 7, and the detailed description is omitted.
[0095] Table 807 is a table for the user to select the CA certificate to be deleted by the task. The device management application 101 manages the CA certificates installed on each device in a database. That is, the device management application 101 manages a list of CA certificates installed on each device and a list of devices on which each CA certificate is installed. Usually, the relationship between a device and a CA certificate is a many-to-many relationship.
[0096] The certificates displayed in Table 807 change according to the selection status of the regions in Region Settings 803 and 804. When "Region-independent" is selected in the drop-down 803, all CA certificates installed on one or more devices are displayed in Table 807. On the other hand, when "Select Region" is selected in the drop-down 803, the CA certificates installed on the devices belonging to the region selected in the checkbox 804 are displayed in Table 807. As described above, a region can be set for a task that defines an operation on a device to be managed.
[0097] Note that the device management application 101 has a function of displaying on the screen the execution result of the task set as described above, and a function of displaying on the screen the execution result (processing result) of the task for each device that is the execution target of the task. Hereinafter, the above "execution result of the task" is referred to as "execution result of the task itself". Also, the "execution result of the task for each device that is the execution target of the task" is referred to as "processing result of the task for each device that is the execution target of the task". Regarding the display of the execution result of the task itself and the processing result of the task for each device, the device management application 101 performs the following control.
[0098] 1. Regarding the execution result of the task itself, it is displayed regardless of the user's region setting. That is, regarding the execution result of the task itself, unlike the device list, device group list, etc., the result of a task that includes a region to which the user himself does not belong is also acquired and provided to the user via the screen by the device management application 101. 2. For users with "region-independent" in the user's region setting in FIG. 5, the processing results of tasks for all devices are displayed. 3. For users with "select region" set in the user's region setting in FIG. 5, the processing results of tasks for devices belonging to a region to which the user does not belong are not displayed. That is, as the "execution result of the task itself", all tasks are displayed, but regarding the "processing result of the task for each device", only the devices belonging to the region to which the user belongs are displayed.
[0099] For example, the device management application 101 provides, as a WEB UI by the HTTP / HTTPS server 305, a screen for displaying the execution result of the task itself and a screen for displaying the processing result of the task for each device that is the execution target of the task. That is, when a Web browser or the like of a client computer (not shown) requests the HTTP / HTTPS server 305 in response to a user operation or the like, these screens are displayed on the Web browser or the like and can be browsed by the user.
[0100] Figure 11 is a flowchart showing an example of a process (a process for obtaining a list of processing results for each device for which the device management application 101 was the execution target of a task) for obtaining a list of processing results for each device for which the device management application 101 was the execution target of a task. The process shown in this flowchart is executed by the device management application 101. That is, the process shown in this flowchart is realized by the CPU of a computer loading the device management application 101 stored in an external storage device or the like into the RAM and executing it as needed as shown in FIG. 2. The device management application 101 starts the process of this flowchart when obtaining a list of processing results for each device that was the execution target of a task and was viewable by the target user.
[0101] First, in S1101, the device management application 101 checks whether the region setting of the target user (hereinafter referred to as "user") is "independent of region". As a result of the check, if it is "independent of region" (Yes in S1101), the device management application 101 transitions to step S1108. In S1108, the device management application 101 obtains a list of each processing result (execution result) for all devices that were the execution target of the task, returns this to the caller, and ends the process.
[0102] On the other hand, as a result of the check, if it is not "independent of region" (No in S1101), the device management application 101 proceeds to S1102. In S1102, the device management application 101 obtains a list of regions to which the user belongs. Next, in S1103, the device management application 101 obtains the region setting of the task.
[0103] Next, in S1104, the device management application 101 checks whether the region setting of the task obtained in S1103 is "independent of regions". If the region setting of the task is "independent of regions" (Yes in S1104), it is necessary to limit the processing result of the task to the devices belonging to the region to which the user belongs. Therefore, in that case (Yes in S1104), the device management application 101 transitions the process to S1106.
[0104] In S1106, the device management application 101 obtains a list of devices belonging to the region to which the user belongs. After that, in S1107, the device management application 101 obtains, from the respective processing results for all the devices that were the execution targets of the task, only those execution target devices that are included in the devices obtained in S1106. Further, the device management application 101 returns the obtained processing results as a list of processing results (execution results) for the devices to the caller and ends the process.
[0105] On the other hand, if the region setting of the task is "region specified" (No in S1104), the device management application 101 proceeds with the process to S1105. In S1105, the device management application 101 checks the inclusion relationship between the region group to which the user belongs and the region group to which the task belongs. As a result of the check, if the region group to which the user belongs includes the region group to which the task belongs (Yes in S1105), the device management application 101 transitions the process to S1108. The following is the same, so it is omitted.
[0106] On the other hand, if the region group to which the user belongs does not include the region group to which the task belongs (No in S1105), the device management application 101 transitions the process to S1106. The following is the same, so it is omitted.
[0107] Through the above processing, a list of processing results (execution results) for each device of tasks that can be viewed by the user can be obtained. Then, using the list thus obtained, the device management application 101 can appropriately control the user's access to tasks according to the set region. Thereby, when the user belongs to one or more regions, access to tasks belonging to regions to which the user does not belong can be restricted.
[0108] 〔Second Embodiment〕 In a digital multifunction device, scanned images and the like can be transmitted to various destinations using functions such as facsimile, e-mail, and FTP. In the second embodiment, a function for managing destinations to be distributed to a device will be described. When distributing a destination to a device, instead of managing a single destination list including a large number of destinations, a plurality of destination lists may be prepared according to use cases and purposes, and the destinations to be distributed to the device may be managed by combining these.
[0109] For example, create destination lists such as "Sales Department Customer Facsimile Number", "Personnel Department Customer Facsimile Number", "National Sales Office Facsimile Number", "Head Office E-mail Address", and "Sales Department E-mail Address". Then, for the device installed in the sales department, a combination of "Sales Department Customer Facsimile Number", "National Sales Office Facsimile Number", and "Sales Department E-mail Address" is distributed. Also, for the device installed in the head office, a combination of "Personnel Department Customer Facsimile Number", "National Sales Office Facsimile Number", and "Head Office E-mail Address" is distributed.
[0110] To achieve this, a "destination list" including one or more destinations and a "destination list set" combining one or more destination lists are created, and the destinations of the device are managed by associating the "destination list set" with the device.
[0111] Here, regarding a user for whom "Select Region" is set in the region setting of the user in FIG. 5, the device management application 101 prohibits the following operations. 1. Modification and deletion of combinations of destination table sets associated with devices belonging to regions to which the device itself does not belong. 2. Deletion of destination tables included in destination table sets associated with devices belonging to regions to which the device itself does not belong. 3. Association of destination table sets with devices belonging to regions to which the device itself does not belong. Through the above controls, the device management application 101 can appropriately control the user's access to destination tables and destination sets according to the set regions.
[0112] Also, in the above tasks, not only can address book distribution (exemplified in the second embodiment) and certificate distribution (exemplified in the first embodiment) be performed on the devices selected from the devices to be managed, but also application distribution and setting value distribution are possible. That is, in the above tasks, it is defined that at least one of the operations of address book distribution, certificate distribution, application distribution, and setting value distribution is executed on the devices selected from the devices to be managed. Also, in the above tasks, it may be configured such that operations other than distribution (such as shutdown, restart, instructions for a predetermined operation (such as a maintenance operation), and other operations) can be executed on the devices selected from the devices to be managed.
[0113] As described above, according to each embodiment, attributes (region-independent) that are not restricted by region management are provided for devices that do not belong to a region and for management targets (users, device groups, tasks, etc.). This makes it possible to operate devices that do not belong to a region in the same way as devices that belong to a region. Also, multiple regions are associated with management objects (users, device groups, tasks), and access control is performed according to the inclusion relationship of the associated regions. This makes it possible to provide an access control function with a free combination of regions.
[0114] For example, in a large-scale environment with multiple bases, there is a device administrator for each base. The device management application of the present embodiment controls so that a device administrator cannot operate on devices other than the bases for which he or she is in charge by managing devices on the network with attributes such as regions. Hereinafter, Europe will be taken as an example for explanation. The device management application controls so that a device administrator in Germany cannot manage devices in Spain (such as setting changes and monitoring). Also, the device management application controls so that an administrator in Europe can manage both German devices and Spanish devices. Also, the device management application controls so that an administrator of the head office integration department can manage all devices. According to the above, access by a user to devices, device groups, and tasks can be appropriately controlled according to the set region. Therefore, in a large-scale network-connected device management application, devices that do not belong to a region and tasks that are executed across regions can also be appropriately managed.
[0115] Note that the configurations and contents of the various data described above are not limited to this, and it goes without saying that they can be configured with various configurations and contents according to the use and purpose. Although one embodiment has been shown above, the present invention can take an embodiment as, for example, a system, device, method, program, or storage medium. Specifically, it may be applied to a system composed of a plurality of devices, or may be applied to a device composed of a single device. Also, configurations combining the above embodiments are all included in the present invention.
[0116] (Other Embodiments) The present invention can also be realized by supplying a program that implements one or more functions of the above-described embodiments to a system or apparatus via a network or a storage medium and causing one or more processors in a computer of the system or apparatus to read and execute the program. It can also be realized by a circuit (e.g., ASIC) that implements one or more functions. Further, the present invention may be applied to a system composed of a plurality of devices or to an apparatus composed of a single device. The present invention is not limited to the above-described embodiments, and various modifications (including organic combinations of the respective embodiments) are possible based on the gist of the present invention, and they are not excluded from the scope of the present invention. That is, all configurations combining the above-described respective embodiments and their modified examples are also included in the present invention.
Claims
1. first setting means for setting attributes for regions; second setting means for setting a region for a user from among one or more regions whose attributes have been set by the first setting means and a predetermined setting value; third setting means for setting a region for a device from among one or more regions whose attributes have been set by the first setting means; fourth setting means for setting a region for a task from among one or more regions whose attributes have been set by the first setting means, as a setting of a task defining an operation on a device to be managed; control means for controlling access by a user to the device and the task in accordance with the set region; and the predetermined setting value is a setting value for enabling access to all the devices and the task regardless of the region, A device management apparatus, wherein a user for whom the predetermined setting value is set as the region can access the device and the task without being restricted by the control means.
2. The device management apparatus according to claim 1, wherein the control means restricts access to a device belonging to a region to which the user does not belong.
3. The device management apparatus according to claim 1 or 2, wherein the control means restricts access to a task belonging to a region to which the user does not belong.
4. The device management apparatus according to any one of claims 1 to 3, wherein, with respect to the processing result of each device of the task, the processing result of a device belonging to a region to which the user does not belong is not provided to the user.
5. The device management apparatus according to any one of claims 1 to 4, wherein the control means provides the execution result of the task to the user regardless of the region to which the user belongs.
6. The second setting means can set for the user not to belong to any region, The device management apparatus according to claim 5, wherein, with respect to the processing result of each device of the task, the processing result of all devices is provided to a user who does not belong to any region.
7. In the task, it is defined that at least one of the operations of distributing an address book, distributing a certificate, distributing an application, and distributing setting values is to be executed on a device selected from among devices to be managed. The device management apparatus according to any one of claims 1 to 6, characterized in that.
8. A first setting means for setting an attribute for a region, a second setting means for setting a region for a user from among one or more regions for which an attribute has been set by the first setting means and a predetermined setting value, and a third setting means for setting a region for a device from among one or more regions for which an attribute has been set by the first setting means, and a fourth setting means for setting a region for a task from among one or more regions for which an attribute has been set by the first setting means, as a setting of a task defining an operation on a device to be managed. A control method for a device management apparatus, comprising: A control step of controlling access by a user to the device and the task according to a set region. The predetermined setting value is a setting value for enabling access to all the devices and the task regardless of the region. A user for whom the predetermined setting value is set as the region can access the device and the task without limitation in the control step. A control method for a device management apparatus, characterized in that.
9. A program for causing a computer to function as the means according to any one of claims 1 to 7.
10. A first setting means for setting an attribute for a region. A second setting means for setting a region for a user from among one or more regions for which an attribute has been set by the first setting means. A third setting means for setting a region for a device from among one or more regions for which an attribute has been set by the first setting means. A fourth setting means for setting a task defining an operation on a device to be managed. A control means for controlling access by a user to the device and the task according to a set region. While the execution result of the task is provided to the user regardless of the region to which the user belongs, the control means controls so that the processing result for each device of the task is not provided to the user for the processing result for a device belonging to a region to which the user does not belong. A device management apparatus characterized by this.
11. A computer, A first setting means for setting an attribute for a region, A second setting means for setting a region for a user from among one or more regions whose attributes are set by the first setting means, A third setting means for setting a region for a device from among one or more regions whose attributes are set by the first setting means, A fourth setting means for setting a task that defines an operation on a device to be managed, A program for causing a computer to function as a control means for controlling access by a user to the device and the task according to the set region, While the execution result of the task is provided to the user regardless of the region to which the user belongs, the control means controls so that the processing result for each device of the task is not provided to the user for the processing result for a device belonging to a region to which the user does not belong. A program characterized by this.
Citation Information
Patent Citations
Print device
JP2005322031A
Service function provision system, management server, service function provision device, service function provision method, program for management server, and program for service function provision device
JP2017135467A
Monitoring apparatus, control method therefor and program
JP2018082329A
Apparatus management server, apparatus management system and apparatus management method
JP2019175056A
Image formation apparatus, electrical equipment, control method of image formation apparatus, control method and program of electrical equipment
JP2020100038A