Data management program, data management method, and data management apparatus

The data management system automates access right settings by tracing event relationships, reducing manual effort and enhancing data access management efficiency across companies.

JP7701616B2Active Publication Date: 2025-07-02FUJITSU LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2021174135
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-25
Publication Date
2025-07-02
Estimated Expiration
2041-10-25

Smart Images

  • Figure 0007701616000001
    Figure 0007701616000001
  • Figure 0007701616000002
    Figure 0007701616000002
  • Figure 0007701616000003
    Figure 0007701616000003
Patent Text Reader

Abstract

To automate setting of access right to data related to events to be monitored.SOLUTION: In the case where event information 909 regarding a new event W is registered in a global data space GS, a tracking unit 602 records arrival position information regarding the new event W in a tracking target DB 610. The tracking unit 602 refers to the tracking target DB610 and specifies events "A, B, T, X, Y" linked to the new event W. The tracking unit 602 refers to the tracking target DB 610 to determine whether a monitoring target event is included in the specified events. The tracking unit 602 determines, when the monitoring target event is "event T", that the monitoring target event T is included in the specified events. A setting unit 603 sets, for an issuer (another organization #2) of the new event W, an access right to detail data on the monitoring target event T stored in a local data space LS #1.SELECTED DRAWING: Figure 11
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a data management program, a data management method, and a data management device.

Background Art

[0002] In recent years, systems have been developed for utilizing data circulated among companies. The data managed by the system includes, for example, data shared by participating companies and data managed by each company. Whether other companies can access the data managed by each company is controlled, for example, by manually setting an access policy in each company.

[0003] As prior art, for example, there is a technology that checks the access right to traceability information that is the target of an access request, identifies the location where the traceability information for which the access request was made is located, and executes an access request from a user based on the location where the traceability information is located. Also, there is a technology for sharing transmission / reception information with a specific third party that has not directly transmitted or received information. Also, there is a technology for enabling a user, a supplier, and a customer to view data through connection to a server system.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, in the prior art, there is a problem that setting access policies for controlling access from other companies to data managed by individual companies takes time and effort.

[0006] In one aspect, the present invention aims to automate the setting of access rights to data related to monitored events.

Means for Solving the Problems

[0007] In one embodiment, when information about a new event is registered in a first storage that stores information capable of specifying the relationship between events shared by a plurality of data management devices in a data management device included in the plurality of data management devices, the events connected to the new event are specified by tracing the relationship between events based on the information stored in the first storage. When a monitored event is included in the events connected to the specified new event, a data management program is provided that causes the data management device to execute a process of setting access rights to the data related to the monitored event stored in a second storage managed by the device itself for the source of the new event.

Advantages of the Invention

[0008] According to one aspect of the present invention, there is an effect that the setting of access rights to data related to monitored events can be automated.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9A

Figure 9B

Figure 9C

Figure 10A

Figure 10B

Figure 10C

Figure 11

Figure 12

Figure 13

[0010] Hereinafter, with reference to the drawings, embodiments of a data management program, a data management method, and a data management apparatus according to the present invention will be described in detail.

[0011] (Embodiment) FIG. 1 is an explanatory diagram showing an example of a data management method according to an embodiment. In FIG. 1, a data management apparatus 101 is a computer that manages data. The data management apparatus 101 is provided, for example, for each data holder. The holder may be, for example, a company or an individual.

[0012] The first storage 110 is a storage shared by a plurality of data management apparatuses 101 (in the example of FIG. 1, data management apparatuses 101(A), 101(B), 101(C)), and stores data shared by the plurality of data management apparatuses 101. The second storage 120 is a storage managed by each data management apparatus 101, and stores data managed by each data management apparatus 101.

[0013] In the first storage 110, information capable of specifying the relationship between events is stored. An event is, for example, an event occurring within or between companies. Specifically, for example, an event is data processing, transactions, production of goods, processing, transactions, etc. Information capable of specifying the relationship between events is, for example, an event ID (identifier) or a pointer to the ID of a past event related to that event. In the second storage 120, for example, detailed data of events is stored.

[0014] In the example of FIG. 1, the data management apparatus 101 of Company A is denoted as "data management apparatus 101(A)", the data management apparatus 101 of Company B is denoted as "data management apparatus 101(B)", and the data management apparatus 101 of Company C is denoted as "data management apparatus 101(C)". Also, the second storage 120 that stores the data managed by Company A is denoted as "second storage 120(A)", the second storage 120 that stores the data managed by Company B is denoted as "second storage 120(B)", and the second storage 120 that stores the data managed by Company C is denoted as "second storage 120(C)".

[0015] In the first storage 110, for example, information capable of identifying the relationships between events issued by Companies A to C is stored. Here, Events 1 to 3 are issued in the order of "Event 1 ⇒ Event 2 ⇒ Event 3", and in the first storage 110, information capable of identifying the relationship between Events 1 and 2 (corresponding to arrow 111 from Event 2 to Event 1 in FIG. 1) and information capable of identifying the relationship between Events 2 and 3 (corresponding to arrow 112 from Event 3 to Event 2 in FIG. 1) are stored.

[0016] Also, in the second storage 120(A), for example, detailed data 11 of Event 1 issued by Company A is stored, and access from other companies B and C is restricted. In the second storage 120(B), for example, detailed data 12 of Event 2 issued by Company B is stored, and access from other companies A and C is restricted. In the second storage 120(C), for example, detailed data 13 of Event 3 issued by Company C is stored, and access from other companies A and B is restricted.

[0017] Here, whether access to detailed data in individual company management is permitted is determined based on, for example, an access policy. The access policy corresponds to rules for controlling access to data. The access policy is set using, for example, an API (Application Programming Interface).

[0018] However, in the conventional specification, an operator manually calls an API to set the access policy. For example, when permitting access from another company to data managed by a certain company, a person in charge manually calls the API and performs the access policy setting work. Therefore, in the conventional specification, as the transaction volume and the like increase, the labor and time required for the access policy setting work increase, and there is a problem that data management becomes difficult.

[0019] Therefore, in the present embodiment, when a new event is issued, for an event that leads to a monitored event, a data management method for setting an access right to data related to the monitored event for the source of the new event will be described. Here, an example of the processing procedure of the data management apparatus 101 (the following (1) to (3)) will be described.

[0020] (1) When information about a new event is registered in the first storage 110, the data management apparatus 101 identifies an event connected to the new event by tracing the relationship between events based on the information stored in the first storage 110. Registration of information about a new event in the first storage 110 corresponds to the issuance of a new event. Events connected to the new event are, for example, all events identified by sequentially tracing the relationship between events in the direction from the new event (child event) to related past events (parent events) (upward direction).

[0021] In the example of FIG. 1, assume that, as a new event, "Event 3" is issued by a user of Company C. Also, the data management apparatus 101 is referred to as the "data management apparatus 101(A) of Company A", and an example of the processing of the data management apparatus 101(A) will be described.

[0022] In this case, information (corresponding to arrow 112 in FIG. 1) that enables identification of the relationship between the new event 3 and the past event 2 is registered in the first storage 110. Then, the data management apparatus 101(A) identifies events 1 and 2 connected to the new event 3 by tracing the relationship between events (for example, arrows 111 and 112) based on the information stored in the first storage 110.

[0023] (2) The data management apparatus 101 determines whether or not the monitored event is included among the events connected to the identified new event. Here, the monitored event can be arbitrarily set. For example, the monitored event of the data management apparatus 101(A) is an event issued by Company A.

[0024] In the example of FIG. 1, the monitored event of the data management device 101(A) is set as "Event 1". In this case, the data management device 101(A) determines that among Events 1 and 2 that follow the identified new Event 3, the monitored Event 1 is included.

[0025] (3) When the monitored event is included in the events that follow the new event, the data management device 101 sets the access right to the data related to the monitored event stored in the second storage 120 managed by the device itself for the source of the new event. The data related to the monitored event is, for example, the detailed data of the monitored event.

[0026] In the example of FIG. 1, among Events 1 and 2 that follow the new Event 3, the monitored Event 1 is included. In this case, the data management device 101(A) sets the access right to the detailed data 11 of the monitored Event 1 stored in the second storage 120(A) managed by the device itself for the enterprise C, which is the source of the new Event 3.

[0027] Note that when the monitored event is not included in the events that follow the new Event 3, the data management device 101(A) does not set the access right to the data related to the monitored event (for example, the detailed data 11) for the enterprise C, which is the source of the new Event 3.

[0028] In this way, according to the data management device 101, when a new event that leads to the monitored event is issued, the access right to the data related to the monitored event can be automatically set for the source of the new event.

[0029] In the example of FIG. 1, when a new event 3 that leads to the monitored event 1 is issued, the data management device 101(A) can automatically set the access right to the detailed data 11 of the monitored event 1 for the issuer of the new event 3. Thereby, the data management device 101(A) can permit access to the detailed data 11 of its own event 1 for another company (Company C) that has issued an event 3 related to the event 1 of its own company (Company A). Also, the labor and time of the operator required for setting the access policy for the detailed data 11 of the event 1 can be reduced. Also, the user of Company C can access the detailed data 11 of Company A with access restrictions and can check the details of other events 1 related to the new event 3 issued by himself / herself.

[0030] (System configuration example of data management system 200) Next, a system configuration example of a data management system 200 including the data management devices 101 shown in FIG. 1 (for example, data management devices 101(A), 101(B), 101(C)) will be described. Here, the case where the data management device 101 shown in FIG. 1 is applied to a data management server in the data management system 200 will be described as an example. The data management system 200 is applied to, for example, a computer system for ensuring data traceability across companies.

[0031] FIG. 2 is an explanatory diagram showing a system configuration example of the data management system 200. In FIG. 2, the data management system 200 includes data management servers #1 to #n (n: a natural number of 2 or more) and a plurality of user terminals 201. In the data management system 200, the data management servers #1 to #n and the user terminals 201 are connected via a wired or wireless network 210. The network 210 is, for example, the Internet, a LAN (Local Area Network), a WAN (Wide Area Network), or the like.

[0032] In the following description, any one of the data management servers #1 to #n may be referred to as "data management server #i".

[0033] Here, the data management server #i is a computer that has a local data space LS#i and controls access to the data managed by the organization #i. The organization #i is, for example, a company or a union. The local data space LS#i is a storage that stores the data managed by the organization #i.

[0034] The data stored in the local data space LS#i is, for example, detailed data of events issued by the organization #i. An example of the data structure of the detailed data of the event will be described later with reference to FIG. 4. The second storage 120 shown in FIG. 1 corresponds to, for example, the local data space LS#i.

[0035] The data management servers #1 to #n share a global data space GS. The global data space GS is a storage that stores event information shared by the organizations #1 to #n. The event information is information of events issued by each organization #i and includes, for example, information that can identify the relationship with other events. An example of the data structure of the event information will be described later with reference to FIG. 5.

[0036] The global data space GS may be realized, for example, by a blockchain (decentralized ledger system) formed by the data management servers #1 to #n. Also, the global data space GS may be realized by a database server accessible by the data management servers #1 to #n. The first storage 110 shown in FIG. 1 corresponds to, for example, the global data space GS.

[0037] The user terminal 201 is a computer used by the users of organization #i. The user terminal 201 is, for example, a PC (Personal Computer), a tablet terminal, etc. The user can, for example, register event information in the global data space GS or register detailed data in the local data space LS#i by calling an API using the user terminal 201.

[0038] Also, the user can access the detailed data in the local data space LS#i or access the detailed data in the local data space LS#j of another organization #j (j = 1, 2, …, n, j ≠ i) by calling an API using the user terminal 201. However, access to the detailed data in the local data space LS#j is permitted only when organization #i has been set the access right.

[0039] Note that the local data space LS#i may be possessed by another computer accessible by the data management server #i. In this case, the data management server #i controls, for example, another computer to control access to the data in the local data space LS#i.

[0040] (Hardware configuration example of data management server #i) Next, a hardware configuration example of the data management server #i will be described.

[0041] FIG. 3 is a block diagram showing a hardware configuration example of the data management server #i. In FIG. 3, the data management server #i includes a CPU (Central Processing Unit) 301, a memory 302, a disk drive 303, a disk 304, a communication I / F (Interface) 305, a portable recording medium I / F 306, and a portable recording medium 307. Also, each component is connected by a bus 300.

[0042] Here, the CPU 301 controls the overall operation of the data management server #i. The CPU 301 may have multiple cores. The memory 302 includes, for example, a ROM (Read Only Memory), a RAM (Random Access Memory), and a flash ROM. Specifically, for example, the flash ROM stores the OS program, the ROM stores the application program, and the RAM is used as the work area of the CPU 301. The programs stored in the memory 302 are loaded into the CPU 301 to cause the CPU 301 to execute the coded processes.

[0043] The disk drive 303 controls the read / write of data to / from the disk 304 according to the control of the CPU 301. The disk 304 stores the data written under the control of the disk drive 303. Examples of the disk 304 include a magnetic disk and an optical disk.

[0044] The communication I / F 305 is connected to the network 210 through a communication line and is connected to an external computer (for example, the user terminal 201 shown in FIG. 2) via the network 210. Then, the communication I / F 305 serves as the interface between the network 210 and the inside of the device and controls the input / output of data from / to the external computer. For the communication I / F 305, for example, a modem or a LAN adapter can be adopted.

[0045] The portable recording medium I / F 306 controls the read / write of data to / from the portable recording medium 307 according to the control of the CPU 301. The portable recording medium 307 stores the data written under the control of the portable recording medium I / F 306. Examples of the portable recording medium 307 include a CD (Compact Disc)-ROM, a DVD (Digital Versatile Disk), and a USB (Universal Serial Bus) memory.

[0046] Note that, in addition to the components described above, the data management server #i may also have, for example, an input device, a display, etc. Also, the user terminal 201 shown in FIG. 2 can be realized with the same hardware configuration as the data management server #i. However, the user terminal 201 has, in addition to the components described above, for example, an input device, a display, etc.

[0047] (Example of the data structure of detailed data) Next, with reference to FIG. 4, an example of the data structure of the detailed data of the event stored in the local data space LS#i will be described. The detailed data includes information such as, for example, information on the product to be traded and the product itself, which has too large a data volume to be recorded as event information. Also, the detailed data includes information such as, for example, highly confidential information that should not be recorded in the event information.

[0048] FIG. 4 is an explanatory diagram showing an example of the data structure of the detailed data. In FIG. 4, the detailed data 400 includes content, detailed information, and supplementary information. The content is, for example, content such as an image or voice of the product to be sold. The detailed information is, for example, detailed information such as the size, sale date, color, and size of the product. The supplementary information is, for example, information that serves as a supplement although it does not need to be described in the evidence (event information) such as personal information and related information.

[0049] The detailed data 400 is, for example, judged as to whether access is permitted based on the access policy, and is treated as information that can be accessed only by those who have been granted access permission.

[0050] (Example of the data structure of event information) Next, with reference to FIG. 5, an example of the data structure of the event information stored in the global data space GS will be described.

[0051] FIG. 5 is an explanatory diagram showing an example of the data structure of event information. In FIG. 5, the event information 500 includes an event ID, event content, issuer, tag name, tag content, and related event ID. Here, the event ID is identification information that uniquely identifies an event. The event content is the content of the event (an arbitrary character string).

[0052] The issuer is the name of the organization that issued the event. The issuer is, for example, the name of the organization to which the registrant who registered the event information belongs. The tag name is the name of the tag included in the event information. The tag content is the content of the tag (an arbitrary character string). The related event ID is the event ID of a related past event.

[0053] The related past event is, for example, another event directly related to the event identified by the event ID. There may be two or more related past events. Also, there may be no related past events. The related event ID is specified by the registrant, for example, when registering event information in the global data space GS.

[0054] Note that the event information 500 may not include event content, or may include two or more. Also, the event information 500 may not include a tag name and tag content, or may include two or more sets.

[0055] (Functional configuration example of data management server #i) FIG. 6 is a block diagram showing a functional configuration example of the data management server #i. In FIG. 6, the data management server #i includes a detection unit 601, a tracking unit 602, a setting unit 603, and an access control unit 604. The detection unit 601 to the access control unit 604 are functions that serve as a control unit. Specifically, for example, by causing the CPU 301 to execute a program stored in a storage device such as the memory 302, the disk 304, and the portable recording medium 307 shown in FIG. 3, or by means of the communication I / F 305, the functions are realized. The processing results of each functional unit are stored in a storage device such as the memory 302 and the disk 304, for example.

[0056] The detection unit 601 detects that event information about a new event has been registered in the global data space GS. Here, the event information about the new event is information that can identify the relationship between the new event and past events, and is, for example, the event information 500 as shown in FIG. 5.

[0057] The registration of event information in the global data space GS corresponds to the issuance of a new event. For example, when an event such as data processing or transaction occurs in the organization #i, the detailed data of the event is registered in the local data space LS#i, and the event information of the event is registered in the global data space GS.

[0058] Specifically, for example, the detection unit 601 detects that a user of the own organization #i has registered event information in the global data space GS by using the API. In this case, the detection unit 601 transmits an event registration notification to, for example, another data management server #j. The event registration notification indicates that event information about a new event has been registered in the global data space GS.

[0059] In addition, when the detection unit 601 receives an event registration notification from another data management server #j, it detects that event information about a new event has been registered in the global data space GS. Note that an example of registering event information in the global data space GS will be described later with reference to FIGS. 9A to 9C.

[0060] When event information about a new event is registered in the global data space GS, the tracking unit 602 identifies an event consecutive to the new event by tracing the relationship between events based on the information stored in the global data space GS. Specifically, for example, the tracking unit 602 identifies an event consecutive to the new event by tracing the relationship between events in the direction of related past events (the upper direction) from the new event.

[0061] More specifically, for example, each time it is detected that event information about a new event has been registered, the tracking unit 602 records information indicating the relationship between the new event and past events in the tracking target DB (Database) 610. The tracking target DB 610 is an example of a storage unit of the own server that stores information indicating the relationship between events based on the information (event information) stored in the global data space GS. Also, there may be another event (an even more past event) consecutive to the past event related to the new event. In this case, when recording information indicating the relationship between the new event and the past event, the tracking unit 602 records information indicating the other event in the tracking target DB 610 in association with the new event.

[0062] The tracking target DB 610 includes, for example, the arrival position table 700 shown in FIG. 7 described later and the monitoring target table 800 shown in FIG. 8 described later. The tracking target DB 610 is realized by a storage device such as the memory 302 and the disk 304 shown in FIG. 3, for example. Here, the stored content of the arrival position table 700 will be described.

[0063] FIG. 7 is an explanatory diagram showing an example of the stored content of the reach position table 700. In FIG. 7, the reach position table 700 has fields for event ID and reach location, and by setting information in each field, reach position information (for example, reach position information 700-1 to 700-3) is stored as records.

[0064] Here, the event ID is identification information that uniquely identifies an event. The reach location indicates a position reachable from the event identified by the event ID. However, the reach location also includes the event identified by the event ID. The reach location corresponds to information that can identify an event consecutive to the event identified by the event ID.

[0065] Specifically, for example, the tracking unit 602 refers to the event information (for example, event information 500) of a new event stored in the global data space GS, and acquires the event ID of the new event and the related event ID. The related event ID is the event ID of a past event related to the new event.

[0066] Then, the tracking unit 602 records the acquired related event ID in the reach location in the reach position table 700 in association with the event ID of the new event. Also, if there is a past event further related to the past event related to the new event, the tracking unit 602 traces the relationship between the events in the upper direction (child event ⇒ parent event) based on the related event ID to identify the event consecutive to the new event.

[0067] Then, the tracking unit 602 records the event ID of the identified other event in the reach location in the reach position table 700 in association with the event ID of the new event. An example of the update of the stored content of the reach position table 700 updated in response to the registration of the event information of the new event in the global data space GS will be described later with reference to FIGS. 10A to 10C.

[0068] In this way, by tracing the relationship between events, the tracking unit 602 can identify the events that follow a new event. Also, the tracking unit 602 can identify the events that follow a new event by referring to the reach position table 700.

[0069] In the following description, the event with the event ID "$" may be denoted as "event $". For example, the reach position information 700-3 shown in FIG. 7 indicates the reach locations "A, B, C" of event C. According to the reach locations "A, B, C", events A and B that follow event C can be identified.

[0070] Also, the tracking unit 602 determines whether a monitored event is included among the events that follow the identified new event. Specifically, for example, the tracking unit 602 refers to the monitored event table 800 shown in FIG. 8 to determine whether a monitored event is included among the events that follow a new event. Here, the stored content of the monitored event table 800 will be described.

[0071] FIG. 8 is an explanatory diagram showing an example of the stored content of the monitored event table 800. In FIG. 8, the monitored event table 800 has fields for a number and a monitored event ID, and stores the monitored event information 800-1 and 800-2 as records by setting information in each field.

[0072] Here, the number is a number (item number) assigned to the monitored event ID. The monitored event ID is the event ID of the event to be monitored. For example, the monitored event information 800-1 indicates the monitored event ID "T" with the number "1".

[0073] More specifically, for example, the tracking unit 602 refers to the arrival position table 700 to identify the arrival location corresponding to the event ID of the new event. Next, the tracking unit 602 refers to the monitoring target table 800 to determine whether the monitoring target event is included in the identified arrival locations. Taking the monitoring target information 800-1 as an example, the tracking unit 602 determines that the monitoring target event is included when the event ID "T" is included in the identified arrival locations.

[0074] When the monitoring target event is included in the events following the identified new event, the setting unit 603 sets the access right to the data related to the monitoring target event stored in the local data space LS#i managed by the self-server for the source of the new event. Here, the data related to the monitoring target event is the detailed data of the monitoring target event (for example, the detailed data 400).

[0075] Specifically, for example, the setting unit 603 calls the API for setting the access policy and sets the access right to the detailed data of the monitoring target event for the source of the new event, taking the event ID of the monitoring target event and the organization name of the source of the new event (other organization #j) as arguments. The organization name of the source of the new event is identified from, for example, the event information of the new event (for example, the source of the event information 500).

[0076] Thereby, an access policy that permits access to the detailed data of the monitoring target event can be set for the other organization #j that is the source of the new event.

[0077] The access control unit 604 controls access to the local data space LS#i based on the set access rights. For example, assume that there is an access request from a user of another organization #j to the data (target data) in the local data space LS#i. In this case, the access control unit 604 refers to the access policy and permits access to the target data if the other organization #j has been set the access right to the target data. On the other hand, if the other organization #j has not been set the access right to the target data, the access control unit 604 does not permit access to the target data.

[0078] In addition, when the monitoring target event is not included in the events following the specified new event, the setting unit 603 does not set the access right to the data related to the monitoring target event stored in the local data space LS#i managed by its own server for the source of the new event.

[0079] Thereby, it is possible to prevent access to the detailed data of the monitoring target event from the source of the new event that has no relevance to the monitoring target event.

[0080] In addition, when the monitoring target event is included in the events following the specified new event, the setting unit 603 may determine whether the source of the new event is registered in the blacklist. Here, the blacklist is information registering specific persons who are not permitted to access the data managed by its own organization #i. For example, organizations with low reliability regarding data handling are set in the blacklist. The blacklist is, for example, created in advance and stored in a storage device such as the memory 302 and the disk 304.

[0081] Here, when the issuer of the new event is not registered in the blacklist, the self-server sets the access right to the data related to the monitored event stored in the local data space LS#i managed by the self-server for the issuer of the new event. On the other hand, when the issuer of the new event is registered in the blacklist, the setting unit 603 may decide not to set the access right to the data related to the monitored event for the issuer of the new event.

[0082] Thus, even if there is a connection between the event issued by the self-organization #i and the new event, if the issuer of the new event is an organization with low reliability, it is possible to control not to permit access to the detailed data of the monitored event.

[0083] In addition, when the monitored event is not included in the events consecutive to the specified new event, the setting unit 603 may decide whether the issuer of the new event is registered in the whitelist. Here, the whitelist is information registering specific persons who are permitted to access the data managed by the self-organization #i. In the whitelist, for example, organizations with high reliability regarding data handling are set. The whitelist is, for example, created in advance and stored in a storage device such as the memory 302 and the disk 304.

[0084] Here, when the issuer of the new event is registered in the whitelist, the access right to the data related to the monitored event stored in the local data space LS#i may be set for the issuer of the new event. On the other hand, when the issuer of the new event is not registered in the whitelist, the setting unit 603 does not set the access right to the data related to the monitored event for the issuer of the new event.

[0085] Thus, even if there is no connection between the event issued by the self-organization #i and the new event, if the issuer of the new event is an organization with high reliability, it is possible to control to permit access to the detailed data of the monitored event.

[0086] Further, when the monitored event is included in the events following the identified new event, the tracking unit 602 may calculate the distance between the new event and the monitored event by tracing the relationship between the events based on the information stored in the global data space GS. Specifically, for example, the tracking unit 602 may calculate the number of events passed through from the new event to the monitored event as the distance between the new event and the monitored event.

[0087] Also, when the calculated distance is equal to or greater than the threshold value, the setting unit 603 may choose not to set the access right to the data regarding the monitored event for the source of the new event. The threshold value can be set arbitrarily.

[0088] Thereby, even if there is a connection between the event issued by the self-organizing #i and the new event, it is possible to prevent the access right to the detailed data of the monitored event from being set for the source of the new event with a weak relevance to the new event.

[0089] In the above description, it is assumed that the data management server #i of each organization #i sets the access right to the data managed by the self-organizing organization, but it is not limited to this. For example, it is assumed that consent has been obtained from each organization #i for an external computer to set the access right to the data managed by each organization #i. In this case, the functional unit of each data management server #i may be realized by an external computer.

[0090] Specifically, for example, it may be possible to provide an external server that can set the access right to the data managed by each of the organizations #1 to #n. In this case, when information about the new event is registered in the global data space GS, for example, the external server identifies the events following the new event by tracing the relationship between the events based on the information stored in the global data space GS.

[0091] When the external server determines that the monitored event of Organization #i is included in the events following the identified new event, the external server sets the access right to the data related to the monitored event stored in the local data space LS#i managed by Organization #i for the source (another Organization #j) of the new event. As a result, when a new event that leads to an event of Organization #i is issued, the external server can automatically set the access right to the data (e.g., detailed data of the monitored event) managed by Organization #i for another Organization #j.

[0092] In addition, for example, when the external server determines that the monitored event of Organization #i is included in the events following the new event, the external server may set the access right to the data related to the new event stored in the local data space LS#j managed by another Organization #j for the source (Organization #i) of the monitored event. As a result, when a new event that leads to an event of Organization #i is issued, the external server can automatically set the access right to the data (e.g., detailed data of the new event) managed by another Organization #j for Organization #i.

[0093] (Example of registering event information in the global data space GS) Next, with reference to FIGS. 9A to 9C, an example of registering event information in the global data space GS will be described. Also, with reference to FIGS. 10A to 10C, an example of updating the stored content of the reach position table 700 that is updated in response to the registration of the event information of the new event in the global data space GS will be described.

[0094] FIGS. 9A to 9C are explanatory diagrams showing an example of registering event information in the global data space GS. FIGS. 10A to 10C are explanatory diagrams showing an example of updating the stored content of the reach position table 700. In FIGS. 10A to 10C, (10-1) to (10-6) indicate the transition of the stored content of the reach position table 700.

[0095] In FIG. 9A (upper), event information 901 of event A, event information 902 of event B, event information 903 of event C, and event information 904 of event D are registered in the global data space GS. Here, it is assumed that events A, B, C, and D are issued in the order of "A ⇒ B ⇒ C ⇒ D", and event information 901 to 904 are registered in the order of "901 ⇒ 902 ⇒ 903 ⇒ 904".

[0096] (10-1) shown in FIG. 10A shows the stored content of the reach position table 700 when event information 904 is registered in the global data space GS. Reach position information 700-1 to 700-4 are stored in the reach position table 700.

[0097] Here, as shown in FIG. 9A (lower), assume that event information 905 of a new event T is registered in the global data space GS. Also, assume that when issuing the new event T, no past event related to the new event T is specified.

[0098] In this case, as shown in (10-2) of FIG. 10A, the tracking unit 602 records reach position information 700-5 for the new event T in the reach position table 700. Since there is no past event related to the new event T, only "T" is set at the reach location of the reach position information 700-5.

[0099] Next, as shown in FIG. 9B (upper), assume that event information 906 of a new event X is registered in the global data space GS. Also, assume that when issuing the new event X, a past event T related to the new event X is specified.

[0100] In this case, as shown in (10-3) of FIG. 10B, the tracking unit 602 records the arrival position information 700-6 for the new event X in the arrival position table 700. Here, there is a past event T related to the new event X. Therefore, at the arrival location of the arrival position information 700-6, "T,X", which indicates a position reachable by tracing the relationship between events, is set.

[0101] Next, as shown in the lower part of FIG. 9B, assume that the event information 907 of the new event Y is registered in the global data space GS. Also, assume that when issuing the new event Y, past events B,X related to the new event Y are specified.

[0102] In this case, as shown in (10-4) of FIG. 10B, the tracking unit 602 records the arrival position information 700-7 for the new event Y in the arrival position table 700. Here, there are past events B,X related to the new event Y. Therefore, at the arrival location of the arrival position information 700-7, "A,B,T,X,Y", which indicates a position reachable by tracing the relationship between events, is set.

[0103] Next, as shown in the upper part of FIG. 9C, assume that the event information 908 of the new event Z is registered in the global data space GS. Also, assume that when issuing the new event Z, a past event X related to the new event Z is specified.

[0104] In this case, as shown in (10-5) of FIG. 10C, the tracking unit 602 records the arrival position information 700-8 for the new event Z in the arrival position table 700. Here, there is a past event X related to the new event Z. Therefore, at the arrival location of the arrival position information 700-8, "T,X,Z", which indicates a position reachable by tracing the relationship between events, is set.

[0105] Next, as shown in FIG. 9C (bottom), assume a case where event information 909 of a new event W is registered in the global data space GS. Also, assume a case where a past event Y related to the new event W is specified when issuing the new event W.

[0106] In this case, as shown in (10-6) of FIG. 10C, the tracking unit 602 records the arrival position information 700-9 for the new event W in the arrival position table 700. Here, there is a past event Y related to the new event W. Therefore, at the arrival location of the arrival position information 700-9, "A,B,T,X,Y,W" indicating positions reachable by tracing the relationship between events is set.

[0107] Note that the tracking unit 602 may assign the distance from the new event to each event ID included in the arrival location. The distance from the new event is calculated, for example, according to the number of events passed through when tracing the relationship between events in the upper direction from the new event until reaching each event. For example, the distance from the new event W to the event Y is "1 = the number of events passed through (0) from the new event W until reaching the event Y + 1". Also, the distance from the new event W to the event T is "3 = the number of events passed through (2) from the new event W until reaching the event Y + 1". In this case, the arrival location of the arrival position information 700-9 is, for example, "A(3),B(2),T(3),X(2),Y(1),W(0)".

[0108] (Operation example of data management server #i) Next, with reference to FIG. 11, an operation example of the data management server #i will be described.

[0109] FIG. 11 is an explanatory diagram showing an operation example of the data management server #i. Here, the data management server #i of organization #i is referred to as the "data management server #1 of organization #1". Also, an operation example of the data management server #1 when a user of another organization #2 registers event information 909 of a new event W in the global data space GS using the user terminal 201 will be described. The tracking unit 602, the setting unit 603, and the tracking target DB 610 are realized, for example, by an access policy engine 1100 provided for each data management server #i.

[0110] First, when the detection unit 601 detects that the event information 909 about the new event W has been registered in the global data space GS, the tracking unit 602 records the reach position information 700-9 about the new event W in the reach position table 700 in the tracking target DB 610 (see FIG. 10C).

[0111] Then, the tracking unit 602 refers to the reach position table 700 in the tracking target DB 610 to identify the events following the new event W. Here, it is assumed that the events "A, B, T, X, Y" following the new event W are identified from the reach position information 700-9 of the reach position table 700 (see FIG. 10C).

[0112] Next, the tracking unit 602 refers to the monitoring target table 800 (see FIG. 8) in the tracking target DB 610 to determine whether the monitoring target event is included in the identified other events "A, B, T, X, Y". Here, the monitoring target event of the data management server #1 is "event T". In this case, the tracking unit 602 determines that the monitoring target event T is included in the events "A, B, T, X, Y" following the identified new event W.

[0113] When the monitoring target event T is included in the events "A, B, T, X, Y" following the identified new event W, the setting unit 603 sets the access right to the detailed data of the monitoring target event T stored in the local data space LS#1 for the source (another organization #2) of the new event W.

[0114] Specifically, for example, the setting unit 603 calls an API for access policy setting, and uses the event ID "T" of the event T to be monitored and the organization name of another organization #2 as arguments to set, for another organization #2, the access right to the detailed data of the event T to be monitored. As a result, an access policy that permits access to the detailed data of the event T to be monitored is set for another organization #j that is the issuer of the new event W.

[0115] As a result, for example, when the access control unit 604 receives an access request from a user of another organization #2 to the detailed data of the event T in the local data space LS#1, it refers to the access policy and permits access to the detailed data of the event T.

[0116] (Data management processing procedure of data management server #i) Next, the data management processing procedure of the data management server #i will be described.

[0117] FIGs. 12 and 13 are flowcharts showing an example of the data management processing procedure of the data management server #i. In the flowchart of FIG. 12, first, the data management server #i determines whether event information about a new event has been registered in the global data space GS (step S1201).

[0118] Here, the data management server #i waits for event information about a new event to be registered (step S1201: No). When event information about a new event has been registered (step S1201: Yes), the data management server #i obtains the event ID (x) of the new event and the organization name (c) of the issuer of the new event from the event information about the new event (step S1202).

[0119] Next, the data management server #i determines whether the event information about the new event includes the event ID (y) of the past event related to the new event (step S1203). Here, when the event ID (y) of the related past event is not included (step S1203: No), the data management server #i assigns an empty set to the variable a (step S1204) and proceeds to step S1207.

[0120] On the other hand, when the event ID (y) of the related past event is included (step S1203: Yes), the data management server #i acquires the arrival location corresponding to the event ID (y) from the arrival location table 700 (step S1205). Then, the data management server #i assigns the arrival location corresponding to the event ID (y) to the variable a (step S1206).

[0121] Next, the data management server #i adds the event ID (x) of the new event to the variable a (step S1207). Then, the data management server #i registers the arrival location (a) in association with the event ID (x) of the new event in the arrival location table 700 (step S1208) and proceeds to step S1301 shown in FIG. 13.

[0122] In the flowchart of FIG. 13, first, the data management server #i assigns 1 to the variable n (step S1301). Then, the data management server #i acquires the nth monitoring target ID from the monitoring target table 800 (step S1302) and assigns the acquired monitoring target ID to the variable z (step S1303).

[0123] Next, the data management server #i acquires the arrival location corresponding to the event ID (x) of the new event from the arrival location table 700 (step S1304). Then, the data management server #i assigns the acquired arrival location corresponding to the event ID (x) of the new event to the variable a (step S1305).

[0124] Next, the data management server #i determines whether the value of variable z is included in the content of variable a (step S1306). Here, if the value of variable z is not included (step S1306: No), the data management server #i proceeds to step S1308.

[0125] On the other hand, if the value of variable z is included (step S1306: Yes), access rights to the detailed data corresponding to the monitoring target ID (z) in the local data space LS#i are set for the organization name (c) that is the source of the new event (step S1307).

[0126] Next, the data management server #i increments the value of variable n (step S1308) and determines whether the value of variable n is less than or equal to the last item number of the monitoring target IDs in the monitoring target table 800 (step S1309). Here, if it is less than or equal to the last item number of the monitoring target ID (step S1309: Yes), the data management server #i returns to step S1302.

[0127] On the other hand, if it is greater than the last item number of the monitoring target ID (step S1309: No), the data management server #i ends the series of processes according to this flowchart.

[0128] Thereby, when the event information of the new event is registered in the global data space GS, the data management server #i can register information (reach location) indicating the reachable location from the new event in the reach location table 700. Also, if the new event is an event leading to a monitoring target event, the data management server #i can set access rights to the detailed data of the monitoring target event for the source of the new event.

[0129] As described above, according to the data management server #i according to the embodiment, when information about a new event is registered in the global data space GS, by tracing the relationships between events based on the information stored in the global data space GS, an event subsequent to the new event can be identified. The global data space GS stores information that can identify the relationships between events shared by the data management servers #1 to #n. And according to the data management server #i, when a monitored event is included among the events subsequent to the identified new event, the data management server #i can set an access right to the data regarding the monitored event stored in the local data space LS#i managed by itself for the source of the new event. The monitored event is, for example, an event issued from the organization #i.

[0130] Thereby, when a new event leading to an event of the organization #i is issued, the data management server #i can automatically set an access right to the data (for example, detailed data of the event) managed by the organization #i for the source of the new event (another organization #j). For this reason, the labor and time of the operator involved in setting the access policy for the detailed data of the event of the organization #i can be reduced. Also, a user of another organization #j can access the data of the organization #i with access restrictions, and for example, can check the detailed data of other events related to the new event issued by himself / herself.

[0131] Also, according to the data management server #i, when a monitored event is not included among the events subsequent to the new event, the data management server #i can prevent the source of the new event from accessing the data regarding the monitored event.

[0132] Thereby, the data management server #i can prevent the data managed by the organization #i from being accessed by the source of a new event that has no connection with the event issued by the organization #i.

[0133] Also, according to the data management server #i, when a monitored event is included in the events following a new event, it can be determined whether the source of the new event is registered in the blacklist. And according to the data management server #i, when the source of the new event is registered in the blacklist, it can be ensured that the source of the new event is not granted access rights to the data related to the monitored event stored in the local data space LS#i.

[0134] In this way, even if there is a connection between the event issued by the self-organization #i and the new event, when the source of the new event is an organization with low reliability, the data management server #i can control not to permit access to the data managed by the self-organization #i.

[0135] Also, according to the data management server #i, when a monitored event is included in the events following a new event, the distance between the new event and the monitored event can be calculated by tracing the relationship between the events based on the information stored in the global data space GS. And according to the data management server #i, when the calculated distance is equal to or greater than the threshold value, it can be ensured that the source of the new event is not granted access rights to the data related to the monitored event stored in the local data space LS#i.

[0136] In this way, even if there is a connection between the event issued by the self-organization #i and the new event, the data management server #i can prevent the source of the new event with weak relevance to the new event from being granted access rights to the data managed by the self-organization #i.

[0137] Also, according to data management server #i, every time information that can identify the relationship between a new event and past events is registered in the global data space GS, information indicating the relationship between the new event and past events can be recorded in the tracking target DB610 (for example, the monitored table 800). The tracking target DB610 is an example of the storage unit of data management server #i that stores information indicating the relationship between events based on the information stored in the global data space GS. And according to data management server #i, events consecutive to the new event can be identified by referring to the tracking target DB610.

[0138] Thereby, when event information about a new event is registered, data management server #i can, each time, refer to the tracking target DB610 within its own server and identify events consecutive to the new event, without having to trace the relationship between events from scratch by accessing the global data space GS. For example, by holding information so as to easily identify the relationship between events, like the arrival position table 700 shown in FIG. 7, it is possible to reduce the processing load involved in identifying events consecutive to the new event.

[0139] From these, according to data management server #i, it is possible to automate the setting of an access policy for permitting other organization #j, which is the source of the new event, to access the detailed data of the events of its own organization #i. Thereby, for example, it is possible to reduce the workload and working time involved in setting an access policy for ensuring the traceability of data across enterprises.

[0140] The data management method described in this embodiment can be realized by executing a prepared program on a computer such as a personal computer or a workstation. The data management program is recorded on a computer-readable recording medium such as a hard disk, a flexible disk, a CD-ROM, a DVD, or a USB memory, and is executed by being read from the recording medium by the computer. The data management program may also be distributed via a network such as the Internet.

[0141] In addition, the data management device 101 (data management server #i) described in this embodiment can also be realized using application-specific ICs such as standard cells or structured ASICs (Application Specific Integrated Circuits) or PLDs (Programmable Logic Devices) such as FPGAs.

[0142] The following supplementary notes are further disclosed regarding the above-described embodiment.

[0143] (Appendix 1) A data management device included in a plurality of data management devices, when information about a new event is registered in a first storage that stores information capable of identifying a relationship between events shared by the plurality of data management devices, identifying events connected to the new event by tracing the relationship between events based on the information stored in the first storage; when a monitoring target event is included in events connected to the identified new event, setting an access right for a source of the new event to data related to the monitoring target event stored in a second storage managed by the device itself; A data management program that causes a process to be executed.

[0144] (Note 2) If the monitored event is included in events connected to the new event, it is determined whether the source of the new event is registered in a blacklist; When the issuer of the new event is registered in the blacklist, access rights to the data related to the monitored event stored in the second storage are not set for the issuer of the new event. The data management program according to appended note 1, characterized in that the data management apparatus is caused to execute the process.

[0145] (Appended note 3) When the monitored event is included in the events following the new event, the data management apparatus is caused to execute a process of calculating the distance between the new event and the monitored event by tracing the relationship between the events based on the information stored in the first storage. The process of setting is When the calculated distance is equal to or greater than the threshold value, access rights to the data related to the monitored event stored in the second storage are not set for the issuer of the new event. The data management program according to appended note 1 or 2, characterized by this.

[0146] (Appended note 4) The process of setting is When the monitored event is not included in the events following the new event, access rights to the data related to the monitored event are not set for the issuer of the new event. The data management program according to any one of appended notes 1 to 3, characterized by this.

[0147] (Appended note 5) Each time information capable of specifying the relationship between the new event and the past event is registered in the first storage, the data management apparatus is caused to execute a process of recording, in the storage unit of the own apparatus that stores information indicating the relationship between the events based on the information stored in the first storage, the information indicating the relationship between the new event and the past event. The process of specifying is The data management program according to any one of appended notes 1 to 4, characterized in that the events following the new event are specified by referring to the storage unit.

[0148] (Appendix 6) When information about a new event is registered in a first storage that stores information capable of identifying the relationship between events shared by a plurality of data management devices, the data management device included in the plurality of data management devices identifies events consecutive to the new event by tracing the relationship between events based on the information stored in the first storage, and when a monitored event is included in the events consecutive to the identified new event, sets an access right to data related to the monitored event stored in a second storage managed by the own device for the source of the new event. A data management method characterized by executing the processing.

[0149] (Appendix 7) A data management device included in a plurality of data management devices, wherein when information about a new event is registered in a first storage that stores information capable of identifying the relationship between events shared by the plurality of data management devices, the data management device identifies events consecutive to the new event by tracing the relationship between events based on the information stored in the first storage, and when a monitored event is included in the events consecutive to the identified new event, sets an access right to data related to the monitored event stored in a second storage managed by the own device for the source of the new event, and includes a control unit that executes the processing.

Description of Signs

[0150] 101 Data management device 110 First storage 120 Second storage 200 Data management system 201 User terminal 210 Network 300 Bus 301 CPU 302 Memory 303 Disk drive 304 Disk 305 Communication I / F 306 Portable Recording Medium I / F 307 Portable Recording Medium 400 Detailed Data 500 Event Information 601 Detection Unit 602 Tracking Unit 603 Setting Unit 604 Access Control Unit 610 Tracking Target DB 700 Arrival Position Table 800 Monitoring Target Table 1100 Access Policy Engine #1 to #n, #i, #j Data Management Server

Claims

1. In a data management device included in a plurality of data management devices, when information about a new event is registered in a first storage that stores information capable of specifying the relationship between events shared by the plurality of data management devices, by tracing the relationship between events based on the information stored in the first storage, identify an event consecutive to the new event, when a monitored event is included in the events consecutive to the identified new event, set an access right to data related to the monitored event stored in a second storage managed by the own device for the source of the new event, A data management program characterized by causing the above processing to be executed.

2. when the monitored event is included in the events consecutive to the new event, determine whether the source of the new event is registered in a blacklist, when the source of the new event is registered in the blacklist, do not set an access right to data related to the monitored event stored in the second storage for the source of the new event, The data management program according to claim 1, characterized by causing the data management device to execute the above processing.

3. when the monitored event is included in the events consecutive to the new event, cause the data management device to execute a process of calculating the distance between the new event and the monitored event by tracing the relationship between events based on the information stored in the first storage, The above setting process is when the calculated distance is equal to or greater than a threshold value, do not set an access right to data related to the monitored event stored in the second storage for the source of the new event, The data management program according to claim 1 or 2, characterized by this.

4. A data management device included in a plurality of data management devices, when information about a new event is registered in a first storage that stores information capable of specifying the relationship between events shared by the plurality of data management devices, by tracing the relationship between events based on the information stored in the first storage, identify an event consecutive to the new event, When a monitored event is included in the events following the specified new event, access rights to the data related to the monitored event stored in the second storage managed by the own device are set for the source of the new event. A data management method characterized by executing the process.

5. A data management device included in a plurality of data management devices, When information about a new event is registered in the first storage that stores information capable of specifying the relationship between events shared by the plurality of data management devices, the events following the new event are specified by tracing the relationship between events based on the information stored in the first storage. When a monitored event is included in the events following the specified new event, access rights to the data related to the monitored event stored in the second storage managed by the own device are set for the source of the new event. A data management device characterized by having a control unit that executes the process.

Citation Information

Patent Citations

  • Method and device for changing dynamic access right

    JP1995287688A

  • Document use management system and method, document management server and program therefor

    JP2008003846A

  • Traceability system, traceability method, and traceability program

    JP2008139995A

  • Data sharing system, terminal device, server device and program

    JP2008276560A

  • Access method, server and system

    JP2010266908A