ID Management System, Registration Device, Program, and ID Registration Method
The ID management system addresses the challenge of secure user ID access by implementing consent, age, and business attribute verification, along with unauthorized log storage, to manage content and development system access effectively.
Patent Information
- Application Number
- JP2021167380
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-12
- Publication Date
- 2025-07-30
- Estimated Expiration
- 2041-10-12
AI Technical Summary
Existing systems lack effective management of user IDs to ensure secure access to content and system development environments, particularly in managing content with monetary value and restricting access based on user age, business attributes, and consent expiration.
An ID management system with consent confirmation, age verification, business attribute confirmation, and user ID registration mechanisms to manage user access to content and development systems, along with unauthorized log storage and expiration date management.
Enables secure and appropriate management of user IDs, ensuring access to restricted content and system development environments based on user consent, age, and business attributes, while logging and managing unauthorized operations.
Smart Images

Figure 0007714994000001 
Figure 0007714994000002 
Figure 0007714994000003
Abstract
Description
Technical Field
[0001] The present disclosure relates to an ID management system, a registration device, a program, and an ID registration method.
Background Art
[0002] Conventionally, for using services using a computer, authority settings using a user ID have been performed. By setting who can use and who cannot use for each user ID, only specific persons can access important information. Regarding the use of services using a computer, various services have been proposed (see, for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] Generally, system developers perform various developments and maintenance so that the computer system operates normally. In such a system, content including images and videos may be managed. Many contents have monetary value, and there is a desire that they should not be shown to system developers either.
[0005] Therefore, an object of the present disclosure is to provide an ID management system, a registration device, a program, and an ID registration method capable of appropriately managing user IDs when using a system for managing content.
Means for Solving the Problems
[0006] To solve the above problems, the present disclosure A content management system for managing content, a development system which is a system for system development, and a registration device for registering a user ID for logging in to the content management system and the development system, wherein the ID management system has: The registration device has: Consent confirmation means for confirming a consent form regarding the registration of the user ID; Age confirmation means for confirming the age of the user corresponding to the user ID; Business attribute confirmation means for confirming the business attribute of the user corresponding to the user ID; User ID registration means for making a registration request for the user ID to at least one of the content management system and the development system based on the confirmation result by the business attribute confirmation means; The content management system sets the user ID for which the registration request has been made to be login-enabled; The development system sets the user ID for which the registration request has been made to be login-enabled. An ID management system is provided.
[0007] Also, in the ID management system of the present disclosure, The content management system Manages restricted content which is content restricted to viewers, and Based on the business attribute corresponding to the user ID during login, may present the restricted content in a processed state.
[0008] Also, in the ID management system of the present disclosure, The content management system records an access log at the time of login using the user ID, and The registration device may have unauthorized log storage means for analyzing the access log acquired from the content management system and storing unauthorized operations as unauthorized logs.
[0009] Also, in the ID management system of the present disclosure, The registration device manages the expiration date of the consent form corresponding to each user ID, and when the expiration date has passed, it sends a request to invalidate the user ID corresponding to the consent form with the expired expiration date to the content management system and the development system. The content management system and the development system may each set the user ID that has received the invalidation request as unavailable.
[0010] Also, the present disclosure A registration device that is communicably connected to a content management system for managing content and a development system that is a system for system development, and registers user IDs for logging in to the content management system and the development system, The registration device A consent form confirmation means for confirming a consent form regarding the registration of the user ID, An age confirmation means for confirming the age of the user corresponding to the user ID, A business attribute confirmation means for confirming the department to which the user corresponding to the user ID belongs, Based on the confirmation result by the business attribute confirmation means, a user ID registration means for making a registration request for the user ID to at least one of the content management system and the development system is provided.
[0011] Also, the present disclosure A computer communicably connected to a content management system for managing content and a development system that is a system for system development, A consent form confirmation means for confirming a consent form regarding the registration of a user ID for logging in to the content management system and the development system, An age confirmation means for confirming the age of the user corresponding to the user ID, A business attribute confirmation means for confirming the department to which the user corresponding to the user ID belongs, Based on the confirmation result by the business attribute confirmation means, a program is provided that causes the user ID registration means, which requests the registration of the user ID to at least one of the content management system and the development system, to function.
[0012] Also, the present disclosure An ID registration method using a content management system for managing content, a development system which is a system for system development, and a registration device for registering a user ID for logging in to the content management system and the development system, comprising: a step in which the registration device confirms a consent form regarding the registration of the user ID; a step in which the registration device confirms the age of the user corresponding to the user ID; a step in which the registration device confirms the business attribute of the user corresponding to the user ID; a step in which the registration device requests the registration of the user ID to at least one of the content management system and the development system based on the confirmation result in the step of confirming the business attribute; and a step in which the content management system and the development system each set the user ID for which the registration request has been made to be loggable. An ID registration method is provided.
Advantages of the Invention
[0013] According to the present disclosure, it becomes possible to appropriately manage user IDs when using a system for managing content.
Brief Description of the Drawings
[0014]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Mode for Carrying Out the Invention
[0015] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the drawings. <1. System Configuration> FIG. 1 is a configuration diagram of an ID management system according to an embodiment of the present disclosure. In FIG. 1, 110 is a registration device, 120 is a user terminal, 130 is a content management system, 140 is a development system, 150 is a personnel management system, and 160 is a network. The content management system 130 and the development system 140 are connected to a public network 160 such as the Internet and can communicate with each other. The registration device 110 is connected to the content management system 130 and the development system 140, requests the registration of a user ID to the content management system 130 and the development system 140, and registers the set user ID. The personnel management system 150 is connected to the registration device 110 so as to be able to communicate data, and can provide the employee information it manages to the registration device. In the example of FIG. 1, for the sake of convenience of explanation, only one user terminal 120 is shown. However, in reality, a large number of user terminals 120 are connected, and it is a system that can be used by many users.
[0016] The registration device 110 plays a central role in the ID registration system. It is a device that registers IDs available for use in the content management system 130 and the development system 140 while referring to the information managed by the personnel management system 150. That is, the registration device 110 is communicably connected to the content management system 130, the development system 140, and the personnel management system 150.
[0017] Figure 2 is a diagram showing the details of the registration device 110. Among them, Figure 2(a) is a hardware configuration diagram of the registration device 110. The registration device 110 can be realized by a general-purpose computer. As shown in Figure 2, the registration device 110 includes a CPU (Central Processing Unit) 110a, a RAM (Random Access Memory) 110b which is the main memory of the computer, a large-capacity storage device 110c (for example, a hard disk, a flash memory, etc.) for storing programs and data executed by the CPU, an input I / F (interface) 110d for receiving inputs from input devices such as a keyboard and a mouse, a data input / output I / F (interface) 110e for data communication with an external device (such as a data storage medium), a display unit 110f such as a display device (a liquid crystal display, etc.), and a communication unit 110g for performing network communication with other computers such as the content management system 130, the development system 140, and the personnel management system 150 via the network 160. Each element in the registration device 110 is connected to each other via a bus.
[0018] Figure 2(b) is a functional block diagram of the registration device 110. In the hardware configuration shown in Figure 2(a), when the CPU 110a reads the program stored in the storage device 110c into the RAM 110b and executes it, the registration device 110 can function each means shown in Figure 2(b). As shown in Figure 2(b), the registration device 110 has a user ID storage means 111, an unauthorized log storage means 112, an input data acquisition means 113, a consent form confirmation means 114, an age confirmation means 115, an operation attribute confirmation means 116, and a user ID registration means 117.
[0019] The registration device 110 reads the program stored in the storage device 110c into the RAM 110b, which is executed by the CPU 110a to issue commands to other components, thereby realizing the functions of the user ID storage means 111, unauthorized log storage means 112, input data acquisition means 113, consent form confirmation means 114, age confirmation means 115, business attribute confirmation means 116, and user ID registration means 117. In addition, the storage device 110c also serves as a data storage area for the user ID storage means 111 and the unauthorized log storage means 112.
[0020] The user ID storage means 111 is a storage means for storing information related to the user ID registered in at least one of the content management system 130 and the development system 140. When a pair of user ID and password is stored in the user ID storage means 111, it means that the user ID has been registered. FIG. 3 is a diagram showing an example of the user ID information stored in the user ID storage means 111. As shown in FIG. 3, in the user ID storage means 111, as user ID information, a password and an expiration date are stored in association with the user ID. Note that information other than the information shown in FIG. 3 may be stored in association with the user ID.
[0021] The unauthorized log storage means 112 is a storage means for storing unauthorized logs, which are records of unauthorized operations. The unauthorized log includes information such as the user ID, the name of the target content, and the date and time of unauthorized implementation. The unauthorized log storage means 112 is realized in a storage area where the stored content cannot be deleted. For example, it can be realized by setting a part of the storage device 110c as a non-deletable storage area.
[0022] The input data acquisition means 113 is a means for acquiring input data input by the ID administrator. When the ID administrator causes a scanner to read information described on a paper medium, the input data acquisition means 113 acquires it as image data from the data input / output I / F 110e connected to the scanner. The input data acquisition means 113 can also perform text conversion on the acquired image data by character recognition and acquire it as text data. Also, for data input using an input device such as a keyboard, the input data acquisition means 113 acquires it as text data from the input I / F 110d connected to the keyboard or the like.
[0023] The consent form confirmation means 114 is a means for confirming the consent form, which is part of the input data acquired by the input data acquisition means 113. Specifically, it checks whether the consent form is attached and the expiration date of the consent form. Even when the consent form is captured as image data, the input data acquisition means 113 can convert it into text data. Therefore, the consent form confirmation means 114 can acquire part of the content described in the consent form as text data. The consent form confirmation means 114 also acquires the expiration date of the consent form from the input data acquisition means 113. The expiration date of the consent form may be directly acquired as date data from the input data acquisition means 113. Also, when the expiration date is included in the content described in the consent form, after the input data acquisition means 113 converts it into text data, it is converted into date data. Then, the current date is acquired from the internal clock of the registration device 110 and compared. Thereby, it is possible to check whether the expiration date has passed. If the expiration date has not passed, information on the remaining expiration period can be acquired.
[0024] The age confirmation means 115 is a means for determining whether the age of the user is equal to or greater than a predetermined age. When the age of the user is directly stored in the personnel management system 150, the age confirmation means 115 can directly obtain it. Also, when the date of birth of the user is stored in the personnel management system 150, the age confirmation means 115 can calculate the current age of the user using the date of the day obtained from the internal clock of the registration device 110. As will be described later, in this embodiment, the date of birth is stored in the employee information storage means 151 of the personnel management system 150. For this reason, the age confirmation means 115 calculates the age of the user.
[0025] The business attribute confirmation means 116 is a means for confirming the business attribute of the user and specifying the registration target system. The correspondence relationship between the business attribute and the registration target system is stored as a correspondence table in a predetermined storage area in the registration device 110. Therefore, by referring to this correspondence table, the business attribute confirmation means 116 can specify the registration target system.
[0026] The user ID registration means 117 is a means for registering the user ID in the registration target system specified by the business attribute confirmation means 116. Specifically, the user ID is transmitted to the content management system 130 and the development system 140 respectively to request the registration of the user ID. Then, the passwords corresponding to the user ID are received from the content management system 130 and the development system 140 and stored in the user ID storage means 111.
[0027] The registration device 110 also executes various processes not included in the above means by the CPU 110a reading the program stored in the storage device 110c into the RAM 110b and executing it. The registration device 110 may be physically realized by one computer or by a plurality of computers.
[0028] The user terminal 120 is a terminal device used by the user. FIG. 4 is a hardware configuration diagram of the user terminal 120. The user terminal 120 is realized by a general-purpose computer such as a personal computer. As shown in FIG. 4, the user terminal 120 includes a CPU (Central Processing Unit) 120a, a RAM (Random Access Memory) 120b which is the main memory, a non-volatile storage device 120c (for example, a hard disk, a flash memory, etc.) for storing programs and data executed by the CPU, an instruction input unit 120d such as a keyboard and a touch panel, a data input / output I / F (interface) 120e for data communication with an external device (data storage medium, etc.), a display unit (such as a liquid crystal display) 120f, and a communication unit 120g for network communication with other computers such as the registration device 110 via the network 160. These elements are connected to each other via a bus.
[0029] As the user terminal 120, as long as it is equipped with an arithmetic processing unit such as a CPU and has an information processing function, a display function, a network communication function, etc., it is also possible to use something other than a general-purpose computer such as a notebook PC, a tablet, a smartphone, etc.
[0030] FIG. 5 is a diagram showing details of the content management system 130. Among them, FIG. 5(a) is a hardware configuration diagram of the content management system 130. The content management system 130 can be realized by a general-purpose computer, similar to the registration device 110. As shown in FIG. 5, the content management system 130 includes a CPU (Central Processing Unit) 130a, a RAM (Random Access Memory) 130b which is the main memory of the computer, a large-capacity storage device 130c (for example, a hard disk, a flash memory, etc.) for storing programs and data executed by the CPU, an input I / F (interface) 130d for receiving inputs from input devices such as a keyboard and a mouse, a data input / output I / F (interface) 130e for data communication with an external device (such as a data storage medium), a display unit 130f such as a display device (a liquid crystal display, etc.), and a communication unit 130g for performing network communication with other computers such as the registration device 110, the user terminal 120, and the development system 140 via the network 160. Each element in the content management system 130 is connected to each other via a bus.
[0031] FIG. 5(b) is a functional block diagram of the content management system 130. In the hardware configuration shown in FIG. 5(a), when the CPU 130a reads the program stored in the storage device 130c into the RAM 130b and executes it, the content management system 130 can function each means shown in FIG. 5(b). As shown in FIG. 5(b), the content management system 130 has a content storage means 131, a processed content storage means 132, a user ID storage means 133, and a user ID setting means 134.
[0032] The content management system 130 reads the program stored in the storage device 110c into the RAM 110b, and the CPU 130a executes it and issues commands to other components, thereby realizing the functions of the content storage means 131, the processed content storage means 132, the user ID storage means 133, and the user ID setting means 134. Further, the storage device 130c also serves as a data storage area for the content storage means 131, the processed content storage means 132, and the user ID storage means 133. The content management system 130 has various functions other than those shown in the figure. For example, it has a function of performing a content sales / purchase procedure based on access from general consumers, but since this is not a characteristic part of the present embodiment, detailed description thereof is omitted.
[0033] The content storage means 131 is a storage means that stores the content managed by the content management system 130. In the present embodiment, the content management system 130 manages two types of content: restricted content that restricts the users who can view it, and normal content that does not restrict the users who can view it. Both restricted content and normal content are stored in the content storage means 131. Restricted content is content for which viewers are restricted, such as particularly expensive content or adult-oriented content such as horror movies. Normal content is content other than restricted content.
[0034] The processed content storage means 132 is a storage means that stores the restricted content processed by the content management system 130. Since restricted content should not be viewed in its original state, some kind of processing is required. Therefore, in the present embodiment, the processed content storage means 132 stores the processed content that has been processed and part of which has become unviewable. The method of processing is not particularly limited, but in the present embodiment, AI (artificial intelligence) is used to detect the faces of the people shown in the restricted content, and a processing is performed to make only the faces of the people viewable and replace other parts with a single color. This processing may be performed by the content management system 130 or by other computers or the like.
[0035] The user ID storage means 133 is a storage means that stores the user ID that can log in to the content management system 130. When a pair of a user ID and a password is stored in the user ID storage means 111, it means that the user ID has been registered. In this embodiment, furthermore, for each user ID, the occupation of the user corresponding to the user ID is also stored.
[0036] The user ID setting means 134 is a means for setting the user ID received from the registration device 110 to be available in the content management system 130. Specifically, a password is set for the user ID received from the registration device 110, and the user ID and the password are associated and stored in the user ID storage means 133. Also, the occupation information of the user acquired from the registration device 110 is stored in association with the user ID.
[0037] FIG. 6 is a diagram showing the details of the development system 140. Among them, FIG. 6(a) is a hardware configuration diagram of the development system 140. The development system 140 can be realized by a general-purpose computer, similar to the registration device 110 and the content management system 130. As shown in FIG. 6, the development system 140 includes a CPU (Central Processing Unit) 140a, a RAM (Random Access Memory) 140b which is the main memory of the computer, a large-capacity storage device 140c (for example, a hard disk, a flash memory, etc.) for storing programs and data executed by the CPU, an input I / F (interface) 140d for receiving inputs from input devices such as a keyboard and a mouse, a data input / output I / F (interface) 140e for data communication with an external device (data storage medium, etc.), a display unit 140f such as a display device (liquid crystal display, etc.), and a communication unit 140g for network communication with other computers such as the registration device 110 and the user terminal 120 via the network 160. Each component in the development system 140 is connected to each other via a bus.
[0038] Figure 6(b) is a functional block diagram of the development system 140. In the hardware configuration shown in Figure 6(a), when the CPU 140a reads the program stored in the storage device 140c into the RAM 140b and executes it, the development system 140 can function each means shown in Figure 6(b). As shown in Figure 6(b), the development system 140 has a user ID storage means 141 and a user ID setting means 142.
[0039] The development system 140 reads the program stored in the storage device 140c into the RAM 110b, which is executed by the CPU 140a to issue commands to other components, thereby realizing the functions of the user ID storage means 141 and the user ID setting means 142. Also, the storage device 140c also serves as a data storage area for the user ID storage means 141. The development system 140 has various functions other than those shown in Figure 6(b). Specifically, it has a function of performing system development based on access from the user terminal 120, etc., but since it is not a characteristic part of this embodiment, detailed description is omitted.
[0040] The personnel management system 150 is a system for a predetermined business entity such as a company to manage the personnel information of its employees. The personnel management system 150 is realized as a computer system in which a program for personnel management is incorporated into a computer. Usually, it is a computer that manages the personnel of a company, stores and manages employee information. The personnel management system 150 is connected to the registration device 110 in a data communicable manner, and can provide the personnel information it manages to the registration device 110. Figure 7 is a diagram showing an example of the employee information managed by the personnel management system 150. As shown in Figure 7, the employee information includes information such as user ID, name, date of birth, job type, department, and email address. Also, as shown in Figure 7, the information of the supervisor is also included. The supervisor information may include contact information to the supervisor such as the supervisor's email address.
[0041] <2. Processing Operations> Next, the ID registration method according to the present embodiment will be described together with the processing operations of the ID registration system shown in FIG. 1. FIG. 8 is a flowchart showing the ID registration method according to the present embodiment. The ID registration method according to the present embodiment is executed centering around the registration device 110 which is a computer.
[0042] In the present embodiment, user IDs are issued and managed for two types of users, namely, content management users and system development users. The content management users are users who upload sales content to the content management system 130 or perform preparations for viewing, selling the content. The system development users are users who log in to server systems constituting services such as the content management system 130 and the development system 140 and perform maintenance of the OS and application software. Also, it is assumed that the work necessary for the registration device 110 is performed by the ID administrator. When belonging to one company, it is assumed that the content management users belong to departments such as sales and planning, the system development users belong to departments such as engineering, and the ID administrator belongs to departments such as general affairs. Also, in terms of job types, the content management users correspond to content management, and the system development users correspond to system development. Note that in the present embodiment, it is assumed that the content management system 130 also sells restricted content.
[0043] A user who wishes to have a user ID issued for accessing either the content management system 130 or the development system 140 registers predetermined information such as the user's job type, department, date of birth, age, etc. in the registration application form and submits the registration application form to the ID administrator.
[0044] When the content management system 130 and the development system 140 handle restricted content, the user prepares a consent form indicating consent to handle the restricted content. Then, the user submits the consent form to the ID administrator. The registration application form and the consent form may be in paper or in data. When the registration application form and the consent form are in paper, they are directly handed over from the user to the ID administrator. When the registration application form and the consent form are in data, they are transmitted from the user terminal 120 used by the user to the ID administrator terminal (not shown) used by the ID administrator using, for example, e-mail.
[0045] The ID administrator inputs the registration application form and the consent form obtained from the user into the registration device 110. Specifically, the ID administrator operates an input device such as a keyboard or a mouse and inputs them into the registration device 110 via the input I / F (interface) 110d. When the registration application form is in paper, the ID administrator inputs the described content using a keyboard or the like. When the consent form is in paper, it is read by a scanner connected to the data input / output I / F (interface) 110e.
[0046] In the registration device 110, the input data acquisition means 113 acquires the input data input by the ID administrator (step S1). Specifically, the content of the registration application form is acquired as text data. Regarding the consent form, it may be acquired as text data, or may be acquired as image data obtained from the scanner. The image data may be subjected to character recognition and acquired as text data. The input data acquired from the registration application form includes information such as user ID, name, date of birth, age, and department affiliation. Also, regarding the consent form, information on the expiration date of the consent form is also acquired.
[0047] Once the input data is acquired, in the registration device 110, the consent form confirmation means 114 checks whether the consent form is proper (step S2). Specifically, it checks whether the consent form is attached and the expiration date of the consent form. Regarding the consent form, since the ID administrator has confirmed the content at the time of registration, it is only necessary to check whether the consent form is attached. If the consent form is image data, the consent form confirmation means 114 checks the existence of the image data of the consent form. Also, it acquires the expiration date of the consent form and determines whether there is a period of a predetermined length or more from the current time to the expiration date. This is because if the period until the expiration date is too short, a renewal procedure must be carried out again immediately, which becomes complicated.
[0048] If the consent form is not proper (step S3: NO), the registration process ends. In this case, the consent form confirmation means 114 displays a message such as "The consent form is not proper." on the display unit 110f and ends the registration process without registering the user ID.
[0049] On the other hand, if the consent form is proper (step S3: YES), the age confirmation means 115 confirms the age of the user (step S4). Specifically, the age confirmation means 115 accesses the personnel management system 150 via the communication unit 110g and makes a request to acquire employee information using the user ID included in the input data. At this time, the acquisition request is made using the user ID as the employee ID. In the personnel management system 150, the employee information storage unit is referred to using the user ID acquired from the age confirmation means 115, and the employee information specified by that user ID is acquired. Then, the acquired employee information is transmitted to the registration device 110 that is the request source. As the employee information, as shown in FIG. 7, it includes information on the employee ID (user ID), name, date of birth, job type, and affiliated department.
[0050] In the registration device 110, employee information is acquired from the personnel management system 150 via the communication unit 110g. Then, the age confirmation means 115 checks whether each piece of information such as name, date of birth, job type, and department affiliation in the employee information matches the information acquired by the input data acquisition means 113. If all match, the age confirmation means 115 checks whether the user's age is equal to or greater than a predetermined age (step S5). The user's age is calculated by the age confirmation means 115 using the date of birth obtained from the employee information and the current date obtained from the internal clock of the registration device 110. The predetermined age can be set as appropriate. For example, it can be 18 years old or 20 years old, which indicates the age of adulthood.
[0051] If the user's age is not equal to or greater than the predetermined age (step S5: NO), the registration process ends. In this case, the age confirmation means 115 displays a message such as "You have not reached the predetermined age." on the display unit 110f and ends the registration process without registering the user ID.
[0052] On the other hand, if the user's age is equal to or greater than the predetermined age (step S5: YES), the business attribute confirmation means 116 confirms the user's business attribute (step S6). The business attribute is an attribute that identifies the user's business. As the business attribute, various things can be used as long as they can identify the user's business. In this embodiment, the job type and department affiliation are used as the business attributes. The business attribute confirmation means 116 may only confirm either the job type or the department affiliation, but for stricter confirmation, both the job type and the department affiliation may be confirmed. In this embodiment, only the job type is confirmed. The business attribute of the user is determined by the business attribute confirmation means 116 (step S7).
[0053] Based on the confirmation result by the business attribute confirmation means 116, the user ID registration means 117 registers the user ID in the corresponding system (steps S8, S9). Specifically, based on the confirmation result by the business attribute confirmation means 116, a pre-set corresponding table is referred to determine the registration target system. In this embodiment, in this corresponding table, when the job type is content management, only the content management system 130, and when the job type is system development, both the content management system 130 and the development system 140 are set as the registration target systems.
[0054] When the job type is system development, since both the content management system 130 and the development system 140 are determined, the user ID is registered in both the content management system 130 and the development system 140 (step S8). When the job type is content management, since only the content management system 130 is determined, the user ID is registered only in the content management system 130 (step S9).
[0055] In step S8, the user ID registration means 117 first sends the acquired user ID to the content management system 130 and the development system 140 respectively to make a registration request. In the content management system 130 and the development system 140, the received user ID is registered respectively, and a password corresponding to the registered user ID is set. The registration device 110 also sends the job type (business attribute) together with the user ID to the content management system 130. In this case, the job type is "system development".
[0056] In the content management system 130, when receiving a registration request from the registration device 110, the user ID setting means 134 issues a password. Then, the user ID, password, and job type are associated and stored in the user ID storage means 133. Thereby, the registration of the user ID to the content management system 130 is performed. Subsequently, the registered user ID and password are transmitted to the registration device 110. Also, in the development system 140, when receiving a registration request from the registration device 110, the user ID setting means 142 issues a password. Then, the user ID and password are associated and stored in the user ID storage means 141. Thereby, the registration of the user ID to the development system 140 is performed. Subsequently, the registered user ID and password are transmitted to the registration device 110.
[0057] In step S9, the user ID registration means 117 first transmits the acquired user ID only to the content management system 130 and makes a registration request. When receiving a registration request from the registration device 110, the user ID setting means 134 issues a password. Then, the user ID and password are associated and stored in the user ID storage means 133. Thereby, the registration of the user ID to the content management system 130 is performed. Subsequently, the registered user ID and password are transmitted to the registration device 110.
[0058] In either case of steps S8 and S9, the user ID registration means 117 of the registration device 110 registers the user ID and password received from the content management system 130 and the development system 140. Specifically, the received user ID and password are associated and stored in the user ID storage means 111. Further, the registration device 110 transmits the issued password together with the user ID to the user terminal 120. The specific method of transmitting the password to the user terminal 120 is not particularly limited, but it can be performed using e-mail, short message, etc. In addition, when the user specified by the user ID is not using the user terminal 120, the ID administrator notifies the user of the password orally or in writing.
[0059] In step S7, if the corresponding system is not identified, the registration process ends. In this embodiment, if the job type is other than content management or system development, it is not registered in any system. In this case, the business attribute confirmation means 116 displays a message such as "This job type (department) cannot use any system." on the display unit 110f, and ends the registration process without registering the user ID.
[0060] <3. Processing at the time of accessing each system> Next, the processing of each system that requires registration of the user ID will be described. Both the content management system 130 and the development system 140 can be accessed from the user terminal 120. When there is an access from the user terminal 120, the content management system 130 performs login authentication using the user ID and password. As described above, the user ID storage means 133 of the content management system 130 stores the user ID for both the content management user and the system development user. Therefore, both the content management user and the system development user can log in to the content management system 130. Other users who have not registered the user ID and have not obtained the password cannot log in to the content management system 130.
[0061] When there is an access from the user terminal 120, the development system 140 also performs login authentication using the user ID and password. As described above, only the system development user is registered in the user ID storage means 141 of the development system 140. For this reason, only the system development user can log in to the development system 140.
[0062] <4. Viewing restricted content> The content management system 130 manages restricted content, which is content restricted for viewers, and presents the processed restricted content based on the business attribute corresponding to the user ID of the logged-in user. Specifically, for the restricted content, pre-processing is performed in advance to generate processed restricted content with some parts being unviewable, and it is stored in the processed content storage means 132. Then, when a request for restricted content is made while logged in with a user ID whose job type (business attribute) is system development, the processed content is presented from the processed content storage means 132. Specifically, the processed content is transmitted to the user terminal 120 of the access source.
[0063] Content management users can only log in to the content management system 130. As part of their job, content management users must check the content managed by the content management system 130. Therefore, even restricted content needs to be viewable on the user terminal 120 used by content management users. For this reason, when logged in with the user ID of a content management user, the content management system 130 presents the restricted content in its unprocessed form to the user terminal 120 of the access source. That is, the unprocessed restricted content stored in the content storage means 131 is presented. In this way, although content management users can only log in to the content management system 130, they can view the content without viewing restrictions.
[0064] The system development user can log in to both the content management system 130 and the development system 140. It is the business of the system development user to conduct system development so that the content management system 130 and other systems function properly. Therefore, there is no need to check the actual content of the content managed by the content management system 130 and the development system 140. Thus, especially in the case of restricted content, it is not necessary to be displayable on the user terminal 120 handled by the system development user. For this reason, when logged in with the user ID of the system development user, the content management system 130 and the development system 140 present the restricted content to the user terminal 120 of the access source in a processed state where part of it cannot be viewed. Whether it is the user ID of the system development user or not can be determined by referring to the job type (business attribute) stored in association with the user ID in the user ID storage means 133. In this way, although the system development user can log in to both the content management system 130 and the development system 140, the restricted content can only be viewed in a restricted state.
[0065] The viewing restriction of the restricted content can be carried out by various methods. As long as the restricted content can be presented in a restricted manner in some way, the manner is not particularly limited. In this embodiment, AI (artificial intelligence) is used to detect the faces of the people shown in the restricted content. Then, a processing operation is performed to make only the faces of the people viewable and replace other parts with a single color. In this embodiment, each time the restricted content is registered in the content management system 130, the processing operation is performed to generate the processed restricted content, which is stored in the processed content storage means 132. And when there is a request for the restricted content during the login with the user ID of the system development user, the processed restricted content is transmitted to the user terminal 120 of the requester.
[0066] FIG. 9 is a diagram showing the processing of restricted content. Among these, FIG. 9(a) shows the original restricted content before processing, and FIG. 9(b) shows the processed content after the processing. For example, in the case of image content as shown in FIG. 9(a), the face is detected by AI and the parts other than the face are processed. As a result, as shown in FIG. 9(b), processed content in which the parts other than the face cannot be viewed is obtained.
[0067] FIG. 10 is a flowchart showing the processing when the content management system 130 presents restricted content. First, when there is a content acquisition request during login (step S11: Yes), the content management system 130 refers to the user ID storage means 133 and acquires the job type of the logged-in user ID (step S12).
[0068] And when the job type of the user ID is system development (step S12; YES), the content management system 130 refers to the content storage means 131 and determines whether the content is restricted content (step S13). And when the content is restricted content (step S13: YES), the content management system 130 acquires the processed content from the processed content storage means 132 (step S14).
[0069] On the other hand, when the job type of the user ID is not system development (step S12: NO), or when the content for which the acquisition request was made is not restricted content (step S13: NO), the content management system 130 acquires the unprocessed content from the content storage means 131 (step S15). The content management system 130 transmits the content acquired in either step S14 or S15 to the requesting user terminal 120 (step S16).
[0070] Note that in the content management system 130, when a request for restricted content is received from a system development user without previously generating pre-processed restricted content, real-time processing may be performed to generate processed restricted content. In this case, real-time processing is performed on the restricted content extracted from the content storage means 131 to generate processed restricted content, which is then transmitted to the user terminal 120 of the requester. When the development system 140 handles restricted content, the development system 140 also performs the same processing as the content management system 130 to generate processed restricted content and transmit it to the user terminal 120 of the requester. In this way, browsing can be restricted for system development users who do not need to view the content of the content.
[0071] <5. Access Log> The content management system 130 and the development system 140 record access logs when logging in using the user ID. Then, they are periodically transmitted to the registration device 110. In this way, all access logs to the content management system 130 and the development system 140 are accumulated in the registration device 110. The registration device 110 analyzes the access logs and detects if an unauthorized operation is being performed on the content. An unauthorized operation is an operation of taking out the content, such as storing the content in an unauthorized storage area or transmitting it to another computer.
[0072] In this embodiment, when an unauthorized operation is detected as a result of the analysis, the registration device 110 sends an email to the email address of the registered ID administrator. The content of the email notifies of the unauthorized operation and includes the user ID, name, etc. of the person who committed the unauthorized act. Additionally, the email address of the user's supervisor may be obtained by referring to the employee information in the personnel management system 150, and an email may be sent to the supervisor.
[0073] Furthermore, the registration device 110 stores records of unauthorized operations as unauthorized logs in the unauthorized log storage means 112. The unauthorized logs include user ID, target file name, and implementation date and time information. The unauthorized log storage means 112 is realized in a storage area where deletion of stored content is impossible.
[0074] <6. Consent form expiration management> The registration device 110 also manages the expiration dates of the registered consent forms. Specifically, the registration device 110 compares the expiration date of the consent form corresponding to each user ID with the date of the current day every day. If the date of the current day exceeds the expiration date, it is determined that the expiration date has passed. Then, the user ID corresponding to the consent form with the expired expiration date is invalidated. Specifically, a request for invalidation is sent to the content management system 130 and the development system 140 together with the corresponding user ID. In the content management system 130 and the development system 140, the user ID that has received the invalidation request is set to be unavailable.
[0075] As described above, the ID management system according to the present embodiment includes a content management system 130 that manages content, a development system 140 that is a system for system development, and a registration device 110 that registers user IDs for logging in to the content management system 130 and the development system 140. The registration device 110 includes a consent form confirmation means 114 that confirms a consent form regarding the registration of a user ID, an age confirmation means 115 that confirms the age of the user corresponding to the user ID, a business attribute confirmation means 116 that confirms the business attribute of the user corresponding to the user ID, and a user ID registration means 117 that requests registration of the user ID to at least one of the content management system 130 and the development system 140 based on the confirmation result by the business attribute confirmation means 116. The content management system 130 sets the user ID for which a registration request has been made to be loggable, and the development system 140 sets the user ID for which a registration request has been made to be loggable. Therefore, it is possible to appropriately manage user IDs when using the system for managing content.
[0076] Although the preferred embodiments of the present disclosure have been described above, the present disclosure is not limited to the above embodiments, and various modifications are possible. For example, in the above embodiment, the user information is obtained from the employee information managed by the personnel management system, but the registration device may have a user information storage means and manage the user information independently.
Explanation of Signs
[0077] 100 ··· ID management system 110 ··· Registration device 111 ··· User ID storage means 112 ··· Illegal log storage means 113 ··· Input data acquisition means 114 ··· Consent form confirmation means 115 ··· Age confirmation means 116 ··· Business attribute confirmation means 117 ··· User ID registration means 120 ··· User terminal 130 ··· Content management system 140 ··· Development system 150 ··· Personnel management system 160 ··· Network
Claims
1. An ID management system having a content management system for managing content, a development system which is a system for system development, and a registration device for registering a user ID for logging in to the content management system and the development system, wherein the registration device includes a consent confirmation means for confirming a consent form regarding the registration of the user ID; an age confirmation means for confirming the age of the user corresponding to the user ID; an occupation attribute confirmation means for confirming whether the occupation as the business attribute of the user corresponding to the user ID is content management or system development; a user ID registration means for, based on the confirmation result by the occupation attribute confirmation means, when the occupation is content management, requesting registration of the user ID only to the content management system, and when the occupation is system development, requesting registration of the user ID to both the content management system and the development system; the content management system sets the user ID for which the registration request has been made to be login-enabled; the development system sets the user ID for which the registration request has been made to be login-enabled. An ID management system.
2. The content management system manages restricted content which is content restricted to viewers, and presents the restricted content in a processed state based on the business attribute corresponding to the user ID during login. The ID management system according to Claim 1.
3. The content management system records an access log at the time of login using the user ID, and the registration device has an unauthorized log storage means for analyzing the access log acquired from the content management system and storing unauthorized operations as unauthorized logs. The ID management system according to Claim 1 or Claim 2.
4. The registration device manages the expiration date of the consent form corresponding to each user ID, and when the expiration date has passed, transmits a request to invalidate the user ID corresponding to the consent form whose expiration date has passed to the content management system and the development system, and the content management system and the development system each set the user ID that has received the invalidation request to be unusable. The ID management system according to any one of Claims 1 to 3.
5. A registration device that is communicably connected to a content management system for managing content and a development system that is a system for system development, and registers a user ID for logging in to the content management system and the development system, wherein the registration device has consent confirmation means for confirming a consent form regarding the registration of the user ID, age confirmation means for confirming the age of the user corresponding to the user ID, job attribute confirmation means for confirming whether the job type as the job attribute of the user corresponding to the user ID is content management or system development, and user ID registration means for, based on the confirmation result by the job attribute confirmation means, when the job type is content management, requesting registration of the user ID only to the content management system, and when the job type is system development, requesting registration of the user ID to both the content management system and the development system.
6. A computer communicably connected to a content management system for managing content and a development system that is a system for system development, consent confirmation means for confirming a consent form regarding the registration of a user ID for logging in to the content management system and the development system, age confirmation means for confirming the age of the user corresponding to the user ID, job attribute confirmation means for confirming whether the job type as the job attribute of the user corresponding to the user ID is content management or system development, and a program that functions as user ID registration means for, based on the confirmation result by the job attribute confirmation means, when the job type is content management, requesting registration of the user ID only to the content management system, and when the job type is system development, requesting registration of the user ID to both the content management system and the development system.
7. An ID registration method using a content management system for managing content, a development system that is a system for system development, and a registration device for registering a user ID for logging in to the content management system and the development system, wherein the registration device confirms a consent form regarding the registration of the user ID, and the registration device confirms the age of the user corresponding to the user ID. A step of checking whether the occupation, as the business attribute of the user corresponding to the user ID, is either content management or system development; Based on the check result in the step of checking the business attribute, when the occupation is content management, the registration device requests registration of the user ID only to the content management system, and when the occupation is system development, the registration device requests registration of the user ID to both the content management system and the development system; A step in which the content management system and the development system each set the user ID for which the registration request has been made to be loggable. An ID registration method having these steps.
Citation Information
Patent Citations
Intermediary device and method for business negotiation, and computer-readable storage medium with business negotiation intermediary program stored therein
JP2002169986A
Network device and authentication server
JP2004302907A
Business information protection device
JP2008117317A
Authority transfer device, authority transfer system, authority transfer method and authority transfer program
JP2009169594A
Id management method, id management system, and id management program
JP2011198109A