Creation Support Device, Creation Support Method, and Creation Support Program

The creation support apparatus addresses the challenge of creating manuals for security-related items by converting general to specific attribute names, simplifying the process of referencing and setting procedures across different information terminal products.

JP7716628B2Active Publication Date: 2025-08-01NIPPON TELEGRAPH & TELEPHONE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023554224
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-10-22
Publication Date
2025-08-01
Estimated Expiration
2041-10-22

AI Technical Summary

Technical Problem

Conventional methods struggle to create manuals for operating procedures of security-related items across different information terminal products, as they require manual lookup of specific product settings from general-purpose documents, making the process cumbersome.

Method used

A creation support apparatus that includes an attribute name correspondence table and operation procedure correspondence table, enabling conversion of general attribute names in security documents to specific attribute names for individual products, and displaying corresponding operation procedures.

Benefits of technology

Facilitates easy creation of manuals for security-related items by converting general to specific attribute names, allowing straightforward reference and setting procedures for individual information terminal products.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007716628000001
    Figure 0007716628000001
  • Figure 0007716628000002
    Figure 0007716628000002
  • Figure 0007716628000003
    Figure 0007716628000003
Patent Text Reader

Abstract

A storage unit (14) stores an attribute name correspondence table (14a) in which general attribute names of an information terminal and unique attribute names are associated with each other, and an operating procedure correspondence table (14b) in which the unique attribute names and operating procedures relating to attribute values of the unique attribute names are associated with each other. An extraction unit (15b) extracts the unique attribute names corresponding to the general attribute names of a document described using the general attribute names of the information terminal in the attribute name correspondence table (14a). A presentation unit (15c) presents the extracted unique attribute names in correspondence with the general attribute names so as to match the presentation of the document. A specifying unit (15d) specifies an operating procedure corresponding to a selected unique attribute name in the operating procedure correspondence table (14b) among the presented unique attribute names.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a creation support device, a creation support method, and a creation support program. [Background technology]

[0002] Conventionally, there are known technologies such as those that use operation logs to assist in the creation of manuals, those that display manuals in conjunction with operations, and those that generate the table of contents of a configuration manual according to the state of the target device (see Non-Patent Documents 1 and 2). [Prior art documents] [Non-patent literature]

[0003] [Non-Patent Document 1] Hiroki Nakanishi, Nagato Nawa, Ken Masuda, Haruo Oishi, Hiroyuki Nakamura, "Proposal of a Consistency Check Function and Feedback Function Between Operation Logs and Configuration Procedures in Network Configuration Operations," IEICE Technical Journal, Vol. 119, No. 299, ICM2019-29, 2019 [Non-patent document 2] Hiroki Nakanishi, Nagato Nawa, Haruo Oishi, Hiroyuki Nakamura, “A method for creating device configuration procedures for branching using PAD diagrams”, 2020 IEICE Society Conference, B14-6, 2020 Summary of the Invention [Problem to be solved by the invention]

[0004] However, with conventional technology, it was difficult to create a manual of operating procedures for referencing and setting security-related items for individual information terminal products from a security-related document written in a general-purpose format so as not to depend on a specific information terminal product. For example, when creating a manual from a security-related document such as a security policy document, the manual creator had to look up the setting procedures and reference procedures for the OS and browser of a specific product that corresponded to the general attribute names, which was not easy.

[0005] The present invention has been made in view of the above, and an object thereof is to easily create a manual of operation procedures for referring to or setting security-related items according to individual information terminal products from a generally written security upper document.

Means for Solving the Problem

[0006] In order to solve the above-described problems and achieve the object, a creation support apparatus according to the present invention includes an attribute name correspondence table that associates a general attribute name of an information terminal with a unique attribute name, and the unique attribute name and an operation procedure related to an attribute value of the unique attribute name. A storage unit that stores an operation procedure correspondence table associated with each other, an extraction unit that extracts the unique attribute name corresponding to the general attribute name of a document described using the general attribute name of the information terminal in the attribute name correspondence table, and the general attribute name in accordance with the presentation of the document. A presentation unit that presents the extracted unique attribute name corresponding thereto, and a specifying unit that specifies the operation procedure corresponding to the selected unique attribute name in the operation procedure correspondence table among the presented unique attribute names.

Effect of the Invention

[0007] According to the present invention, it becomes possible to easily create a manual of operation procedures for referring to or setting security-related items according to individual information terminal products from a generally written security upper document.

Brief Description of the Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

[0009] Hereinafter, with reference to the drawings, an embodiment of the present invention will be described in detail. Note that the present invention is not limited by this embodiment. Also, in the description of the drawings, the same parts are denoted by the same reference numerals.

[0010] [Outline of Creation Support Device] FIGS. 1 and 2 are diagrams for explaining the outline of the creation support device of the present embodiment. The creation support device of the present embodiment supports the creation of security-related items in the business manual. The business manual shows a specific method for realizing business according to the system environment, products, and business of individual information terminals.

[0011] Here, as shown in FIG. 1, the governance-related documents are defined in a hierarchical structure from top to bottom in the order of the charter, security regulation documents, and business manuals. That is, the security items in the business manual are created based on security upper-level documents such as security regulation documents formulated by the legal department of the company.

[0012] This security agreement document, etc. is defined based on a charter that defines a clear management philosophy and vision presented by the management layer, and shows general business standards that do not depend on a specific system environment, product, or business. In order to create a business manual based on such a security upper-level document, it is necessary to examine the reference procedures and setting procedures for security-related items according to the OS and browser of individual information terminals, etc.

[0013] Therefore, as shown in FIG. 2, the creation support device replaces general attribute names such as the OS and browser in the security upper-level document with specific attribute names such as Windows (registered trademark) 10 and IE (Internet Explore) 11 of individual information terminals, and displays them as annotations. Then, the creation support device supports the creation of security-related items in the business manual by displaying the operation procedures corresponding to the specific attribute names selected by the manual creator.

[0014] In the example shown in FIG. 2, corresponding to the description in the security upper-level document that "the OS and browser of the terminal should use versions with security measures", the confirmation setting procedure for "the method of checking the version of IE11 of Windows10 of the information terminal" is displayed. In this way, the creation support device converts the general attribute names included in the text written in the generally described security upper-level document into specific attribute names unique to each product, and displays the reference procedures and setting procedures for the attribute values. Thereby, the creation support device supports the creation of security-related items in the business manual.

[0015] [Configuration of Creation Support Device] FIG. 3 is a schematic diagram illustrating the schematic configuration of the creation support device of the present embodiment. As illustrated in FIG. 3, the creation support device 10 of the present embodiment is realized by a general-purpose computer such as a personal computer, and includes an input unit 11, an output unit 12, a communication control unit 13, a storage unit 14, and a control unit 15.

[0016] The input unit 11 is realized by using an input device such as a keyboard or a mouse, and inputs various instruction information such as start of processing to the control unit 15 in response to an input operation by an operator. The output unit 12 is realized by a display device such as a liquid crystal display, a printing device such as a printer, and the like. For example, the operation procedure and the like of the result of the creation support process described later are displayed on the output unit 12.

[0017] The communication control unit 13 is realized by a NIC (Network Interface Card) or the like, and controls communication between an external device and the control unit 15 via a telecommunication line such as a LAN (Local Area Network) or the Internet. For example, the communication control unit 13 controls communication between the control unit 15 and a management device that manages a security upper document such as a security protocol document.

[0018] The storage unit 14 is realized by a semiconductor memory element such as a RAM (Random Access Memory) or a flash memory, or a storage device such as a hard disk or an optical disk. The storage unit 14 stores in advance a processing program for operating the creation support device 10, data used during the execution of the processing program, and the like, or temporarily stores them each time processing is performed. Note that the storage unit 14 may be configured to communicate with the control unit 15 via the communication control unit 13.

[0019] In the present embodiment, the storage unit 14 stores an attribute name correspondence table 14a, an operation procedure correspondence table 14b, and the like used for the creation support process described later.

[0020] Here, FIG. 4 is a diagram illustrating the configuration of the attribute name correspondence table. The attribute name correspondence table 14a is information that associates a general attribute name of an information terminal with a unique attribute name. Specifically, as illustrated in FIG. 4, the attribute name correspondence table 14a is a table that associates a general attribute name of components such as the OS, memory, browser, and mailer of the information terminal with specific unique attribute names corresponding to each of the attribute names.

[0021] FIG. 4 exemplifies general-purpose attribute names such as the above-described OS, memory, browser, mailer, security countermeasure software, application, and screen lock. Also, as specific attribute names corresponding to the general-purpose attribute name OS, Windows7, Windows10, and Mac are exemplified.

[0022] FIG. 5 is a diagram exemplifying the configuration of the operation procedure correspondence table. The operation procedure correspondence table 14b is information that associates a specific attribute name with an operation procedure regarding the attribute value of the specific attribute name. For example, the operation procedure correspondence table 14b stores information indicating the transition order of the operation screens as an operation procedure. Also, the operation procedure of the operation procedure correspondence table 14b includes at least either a reference procedure or a setting procedure for the attribute value of the specific attribute name.

[0023] Specifically, as exemplified in FIG. 5(a), the operation procedure correspondence table 14b is a table that associates a specific attribute name with information such as a path indicating the transition order of an operation screen showing an operation procedure such as a reference procedure or a setting procedure for the attribute value of the item of the attribute name.

[0024] In FIG. 5(a), for example, regarding the specific attribute name Windows8 corresponding to the general-purpose attribute name OS, the path "AAA / BBB / CCC" of the operation screen transition is exemplified as an operation procedure for checking the version. With this path "AAA / BBB / CCC", as exemplified in FIG. 5(b), the operation screens are shown in the transition order. Note that the path may be a URL or the like that displays the operation screens in the transition order. Also, these operation procedures are assumed to be preset for each attribute value of the specific attribute name.

[0025] Return to the description of FIG. 3. The control unit 15 is implemented using a CPU (Central Processing Unit) or the like, and executes a processing program stored in a memory. As a result, the control unit 15 functions as an acquisition unit 15a, an extraction unit 15b, a presentation unit 15c, a specification unit 15d, and a display unit 15e as illustrated in FIG. 3. Note that these functional units may be implemented by different hardware, either individually or partially. For example, the acquisition unit 15a and the extraction unit 15b may be implemented by different hardware from the presentation unit 15c and the display unit 15e. Further, the control unit 15 may include other functional units.

[0026] The acquisition unit 15a acquires a security upper document described using a general attribute name of an information terminal. For example, the acquisition unit 15a acquires a security upper document to be used in a creation support process described later via the input unit 11 or via the communication control unit 13 from a management device that manages a security policy document or the like. The acquisition unit 15a may store the acquired security upper document in the storage unit 14 prior to the processes described below.

[0027] Here, FIG. 6 is a diagram for explaining the processing of the creation support device 10. As illustrated in FIG. 6(1), the acquisition unit 15a acquires a security upper document to be used in a creation support process described later. In the example shown in FIG. 6(1), “Applications including the OS and browser used in the client terminal shall use versions with known security hole countermeasures” is acquired as the security upper document.

[0028] Return to the description of FIG. 3. The extraction unit 15b extracts a unique attribute name corresponding to the general attribute name of a document described using the general attribute name of the information terminal in the attribute name correspondence table 14a. Specifically, first, as illustrated in FIG. 6(2), the extraction unit 15b extracts a general attribute name from the acquired security upper document. In the example shown in FIG. 6(2), the general attribute names of OS, browser, and version are extracted.

[0029] Next, as illustrated in FIG. 6(3), the extraction unit 15b refers to the attribute name correspondence table 14a and extracts the specific attribute names corresponding to the extracted general attribute names. In the example shown in FIG. 6(3), a table showing the association between the extracted general attribute names and the corresponding specific attribute names is generated as an information terminal setting item. For example, in the table illustrated in FIG. 6(3), Windows8 and version, Windows10 and version, Android and version are associated as the specific attribute names corresponding to the general attribute name OS.

[0030] Returning to the description of FIG. 3, the presentation unit 15c presents the extracted specific attribute names corresponding to the general attribute names in accordance with the presentation of the security upper-level document. Specifically, as shown in FIG. 6(4), the presentation unit 15c displays a list of the specific attribute names extracted corresponding to each, in association with the display position of the general attribute name of the security upper-level document. For example, in FIG. 6(4), Windows7, Windows10, and Android are listed in association with OS. Also, IE11 and Chrome are listed in association with Browser.

[0031] Then, the presentation unit 15c receives an operation input for selecting the specific attribute name specific to the information terminal to be created in the manual from the list of the presented specific attribute names from the manual creator. For example, in the example shown in FIG. 6(4), Windows10 and IE11 are selected.

[0032] Returning to the description of FIG. 3, the specifying unit 15d specifies the operation procedure corresponding to the selected specific attribute name in the operation procedure correspondence table 14b among the presented specific attribute names. Specifically, first, as shown in FIG. 6(5), the specifying unit 15d narrows down the information terminal setting items using the specific attribute name selected by the manual creator. In the example shown in FIG. 6(5), OS is narrowed down to Windows10 and Browser is narrowed down to IE11.

[0033] Next, as shown in FIG. 6(6), the specifying unit 15d specifies an operation procedure corresponding to the narrowed-down unique attribute name. For example, the specifying unit 15d refers to the operation procedure correspondence table 14b and specifies the operation procedure for the method of checking the version of Windows 10 corresponding to the OS. In the example shown in FIG. 6(6), the operation screen transition path " / AAA / BBB / CCC" is specified as the operation procedure for the method of checking the version of Windows 10.

[0034] The display unit 15e displays the specified operation procedure. Specifically, the display unit 15e displays the operation procedure corresponding to the specified unique attribute name on another device such as a user terminal via the output unit 12 or the communication control unit 13. For example, the display unit 15e displays a path indicating the transition order of the operation screen. Alternatively, the display unit 15e may display the operation screens in the transition order according to the path.

[0035] Also, the display unit 15e may output display data for displaying the operation screens in the transition order to other devices or the like. In that case, it becomes possible to create a manual by processing the output display data in other devices or the like.

[0036] Here, FIG. 7 is a diagram for explaining the processing of the presenting unit and the display unit. As shown in FIGS. 6(4) and 7(1), (2), the presenting unit 15c displays a list of unique attribute names extracted corresponding to the display positions of the general attribute names of the security upper-level document. Further, the presenting unit 15c receives an operation input for selecting a unique attribute name for the information terminal unique to the manual creation target from the list of the presented unique attribute names from the manual creator. In FIG. 7(1), Windows 10 is selected corresponding to the OS, and in FIG. 7(2), IE11 is selected corresponding to the browser.

[0037] Then, as shown in Fig. 7(3), the display unit 15e displays a list of operation procedures specified by the specifying unit 15d in association with the display position of the general-purpose attribute name "Version" of the security upper-level document. In Fig. 7(3), "Method for Checking the Version of Windows 10" and "Method for Checking the Version of IE11" are displayed.

[0038] In addition, the display unit 15e receives an operation input such as a click for selecting an operation procedure to be displayed from the list of displayed operation procedures from the manual creator, and displays the selected operation procedure. In Fig. 7(4), an example shows a path indicating the transition order of the operation screens and the transition order of the operation screens according to the path.

[0039] As a result, it becomes easy for the manual creator to check the operation procedures regarding the attribute values of the attribute names specific to the information processing terminal from the security upper-level document. For example, from "Applications including the OS and browser used on the client terminal should use versions with known security hole countermeasures", it becomes possible to easily check the transition order of the operation screens of "Method for Checking the Version of Windows 10" and "Method for Checking the Version of IE11".

[0040] [Creation Support Process] Next, Fig. 8 is a flowchart showing the creation support process procedure. The flowchart in Fig. 8 starts, for example, at the timing instructed by the inspector in the creation support device.

[0041] First, the acquisition unit 15a receives an input of a security upper-level document described using the general-purpose attribute names of the information terminal (step S1). Also, the extraction unit 15b extracts the general-purpose attribute names from the acquired security upper-level document (step S2). Further, the extraction unit 15b refers to the attribute name correspondence table 14a and extracts the specific attribute names corresponding to the extracted general-purpose attribute names.

[0042] Next, the presentation unit 15c presents the extracted unique attribute names corresponding to the general-purpose attribute names in accordance with the presentation of the security upper-level document. For example, the presentation unit 15c displays a list of unique attribute names extracted corresponding to each of them in association with the display positions of the general-purpose attribute names of the security upper-level document (step S3).

[0043] Then, the specifying unit 15d specifies the operation procedure corresponding to the selected unique attribute name in the operation procedure correspondence table 14b among the presented unique attribute names. Further, the display unit 15e displays the specified operation procedure on the output unit 12 or the like (step S4). Thereby, a series of creation support processes is completed.

[0044] [Effect] As described above, in the creation support apparatus 10 of the present embodiment, the storage unit 14 stores an attribute name correspondence table 14a that associates the general-purpose attribute names of the information terminal with the unique attribute names, and an operation procedure correspondence table 14b that associates the unique attribute names with the operation procedures regarding the attribute values of the unique attribute names. Further, the extraction unit 15b extracts the unique attribute names corresponding to the general-purpose attribute names of the document described using the general-purpose attribute names of the information terminal in the attribute name correspondence table 14a. The presentation unit 15c presents the extracted unique attribute names corresponding to the general-purpose attribute names in accordance with the presentation of the document. Further, the specifying unit 15d specifies the operation procedure corresponding to the selected unique attribute name in the operation procedure correspondence table 14b among the presented unique attribute names.

[0045] Specifically, the operation procedure correspondence table 14b stores, as the operation procedure, information indicating the transition order of the operation screens. Further, the operation procedure of the operation procedure correspondence table 14b includes at least either a reference procedure or a setting procedure of the attribute value of the unique attribute name.

[0046] This enables the manual creator to easily check, from the security high-level document, the operation procedures regarding the attribute values of the attribute names specific to the information processing terminal. For example, from the security policy document, it becomes possible to easily check the transition order of the operation screens for "method for checking the version of Windows 10" and "method for checking the version of IE11". Thus, according to the creation support device 10, it becomes possible to easily create a manual for the operation procedures of referring to or setting security-related items according to individual information terminal products from the generally written security high-level document.

[0047] Further, the display unit 15e displays the specified operation procedure. This enables the manual creator to easily create a manual by using the displayed operation procedure.

[0048] [Program] It is also possible to create a program that describes the processing executed by the creation support device 10 according to the above embodiment in a computer-executable language. As one embodiment, the creation support device 10 can be implemented by installing a creation support program that executes the above creation support processing as package software or online software on a desired computer. For example, by causing the information processing device to execute the above creation support program, the information processing device can be made to function as the creation support device 10. The information processing device mentioned here includes desktop or notebook personal computers. In addition, the information processing device also includes mobile communication terminals such as smartphones, mobile phones, and PHS (Personal Handyphone System), and further includes slate terminals such as PDAs (Personal Digital Assistants) within its scope. Also, the functions of the creation support device 10 may be implemented on a cloud server.

[0049] FIG. 9 is a diagram showing an example of a computer that executes a creation support program. The computer 1000 includes, for example, a memory 1010, a CPU 1020, a hard disk drive interface 1030, a disk drive interface 1040, a serial port interface 1050, a video adapter 1060, and a network interface 1070. These components are connected by a bus 1080.

[0050] The memory 1010 includes a ROM (Read Only Memory) 1011 and a RAM 1012. The ROM 1011 stores, for example, a boot program such as a BIOS (Basic Input Output System). The hard disk drive interface 1030 is connected to a hard disk drive 1031. The disk drive interface 1040 is connected to a disk drive 1041. A removable storage medium such as a magnetic disk or an optical disk is inserted into the disk drive 1041. For example, a mouse 1051 and a keyboard 1052 are connected to the serial port interface 1050. For example, a display 1061 is connected to the video adapter 1060.

[0051] Here, the hard disk drive 1031 stores, for example, an OS 1091, an application program 1092, a program module 1093, and program data 1094. Each piece of information described in the above embodiment is stored, for example, in the hard disk drive 1031 or the memory 1010.

[0052] Also, the creation support program is stored in the hard disk drive 1031 as a program module 1093 in which, for example, instructions to be executed by the computer 1000 are described. Specifically, a program module 1093 in which each process executed by the creation support device 10 described in the above embodiment is described is stored in the hard disk drive 1031.

[0053] In addition, data used for information processing by the creation support program is stored, for example, as program data 1094 in the hard disk drive 1031. Then, the CPU 1020 reads out the program module 1093 and the program data 1094 stored in the hard disk drive 1031 into the RAM 1012 as necessary, and executes each of the above-described procedures.

[0054] Note that the program module 1093 and the program data 1094 related to the creation support program are not limited to being stored in the hard disk drive 1031, and may be stored, for example, in a removable storage medium and read by the CPU 1020 via the disk drive 1041 or the like. Alternatively, the program module 1093 and the program data 1094 related to the creation support program may be stored in another computer connected via a network such as a LAN or a WAN (Wide Area Network), and read by the CPU 1020 via the network interface 1070.

[0055] As described above, the embodiments to which the invention made by the present inventor is applied have been described. However, the present invention is not limited by the description and the drawings that form a part of the disclosure of the present invention according to the present embodiment. That is, all other embodiments, examples, operation techniques, etc. made by those skilled in the art based on the present embodiment are included in the scope of the present invention.

Description of Reference Numerals

[0056] 10 Creation support device 11 Input unit 12 Output unit 13 Communication control unit 14 Storage unit 14a Attribute name correspondence table 14b Operation procedure correspondence table 15 Control unit 15a Acquisition unit 15b Extraction unit 15c Presentation unit 15d Identification unit 15e Display unit

Claims

1. A storage unit that stores an attribute name correspondence table associating a general-purpose attribute name of an information terminal with a unique attribute name, and an operation procedure correspondence table associating the unique attribute name with an operation procedure regarding an attribute value of the unique attribute name; An extraction unit that extracts, in the attribute name correspondence table, the unique attribute name corresponding to the general-purpose attribute name of a document described using the general-purpose attribute name of the information terminal; A presentation unit that presents the extracted unique attribute name corresponding to the general-purpose attribute name in accordance with the presentation of the document; A specifying unit that specifies, among the presented unique attribute names, the operation procedure corresponding to the selected unique attribute name in the operation procedure correspondence table; A creation support device, characterized by comprising the above.

2. The operation procedure correspondence table stores, as the operation procedure, information indicating the transition order of an operation screen. The creation support device according to Claim 1, characterized by this.

3. The operation procedure of the operation procedure correspondence table includes at least one of a reference procedure or a setting procedure for the attribute value. The creation support device according to Claim 1, characterized by this.

4. The creation support device according to Claim 1, further comprising a display unit that displays the specified operation procedure.

5. A creation support method executed by a creation support device, wherein the creation support device has a storage unit that stores an attribute name correspondence table associating a general-purpose attribute name of an information terminal with a unique attribute name, and an operation procedure correspondence table associating the unique attribute name with an operation procedure regarding an attribute value of the unique attribute name, an extraction step of extracting, in the attribute name correspondence table, the unique attribute name corresponding to the general-purpose attribute name of a document described using the general-purpose attribute name of the information terminal; a presentation step of presenting the extracted unique attribute name corresponding to the general-purpose attribute name in accordance with the presentation of the document; a specifying step of specifying, among the presented unique attribute names, the operation procedure corresponding to the selected unique attribute name in the operation procedure correspondence table; A creation support method, characterized by including the above.

6. Referring to a storage unit that stores an attribute name correspondence table associating a general-purpose attribute name of an information terminal with a unique attribute name, and an operation procedure correspondence table associating the unique attribute name with an operation procedure regarding an attribute value of the unique attribute name, An extraction step of extracting the specific attribute name corresponding to the general attribute name of a document described using the general attribute name of an information terminal in the attribute name correspondence table; A presentation step of presenting the extracted specific attribute name corresponding to the general attribute name in accordance with the presentation of the document; A specifying step of specifying the operation procedure corresponding to the selected specific attribute name in the operation procedure correspondence table among the presented specific attribute names; A creation support program for causing a computer to execute the above.

Citation Information

Patent Citations

  • Word processor

    JP1993061857A

  • Method for dynamically creating moving image on the basis of structured document, and electronic device, electronic system, and electronic device program therefor

    JP2015141664A

  • Operation manual creation support device and operation manual creation support method

    JP2020201654A