Account management system and method of managing accounts
The account management system addresses the challenge of securely notifying parents of account information in school settings by associating student and parent accounts with temporary passwords and automatic password changes, ensuring secure distribution without collecting personal information.
Patent Information
- Application Number
- JP2021143107
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-02
- Publication Date
- 2025-08-13
- Estimated Expiration
- 2041-09-02
AI Technical Summary
Existing account management systems in school settings face challenges in securely notifying parents of account information without collecting personal information, such as email addresses, due to the risk of information leakage and difficulty in data collection.
An account management system that associates first user accounts (students) with second user accounts (parents) without requiring personal information, using temporary passwords and automatic password change mechanisms to securely distribute account information.
Enables secure notification of account information to parents without collecting their personal details, enhancing security and reducing the risk of information leakage.
Smart Images

Figure 0007722067000001 
Figure 0007722067000002 
Figure 0007722067000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to account management systems, and more particularly to notification processing for a second account associated with a first account. [Background technology]
[0002] In a school-provided system, one method of notifying parents of students of account information is for the school or local government to assign fixed account information (ID (Identifier) and password) to each parent and hand over a piece of paper or other document containing the account information to the student while at school. In this case, parents receive the account information through the student. Another possible method is for the school or local government to collect email addresses and other information from parents in advance and notify the collected email addresses of information for creating an account (for example, a URL: Uniform Resource Locator).
[0003] It is difficult for schools or local governments to collect personal information from parents, so the former method is often used. In this case, there is a risk of information leakage, such as students losing the paper containing account information. Therefore, there is a need for a method to safely notify parents of account information without collecting personal information from parents, or a method to safely create parent accounts.
[0004] Regarding account notification or creation, for example, Japanese Patent Application Laid-Open Publication No. 2010-55196 (Patent Document 1) discloses an information processing system and method for completing an online application for adding a family card more quickly and easily. The information processing system and method are as follows: "When an information processing system that transmits and receives data between a first user device and a second user device receives a request for adding a family card from a primary member, it generates a first dedicated URL. When the primary member sets a temporary password via the first dedicated URL on the first user device, the information processing system generates a second dedicated URL. The primary member's family member accesses the information processing system via the second dedicated URL on the second user device, is authenticated with the temporary password, and then submits the necessary information. The temporary password is transmitted between the primary member and the family member via either a wired or wireless medium" (see [Abstract]). [Prior art documents] [Patent documents]
[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-55196 Summary of the Invention [Problem to be solved by the invention]
[0006] According to the technology disclosed in Patent Document 1, it is necessary to obtain the address of the primary member's family, such as an email address, in order to send the second dedicated URL to the primary member's family. In a school system or the like, it is difficult to collect personal information, such as an email address, of a second user (family member or guardian, etc.) related to a first user (student, etc.) as described above. Therefore, there is a need for a technology that can notify a second user related to a first user of account information without collecting the second user's personal information.
[0007] The present disclosure has been made in consideration of the above-described background, and an object of one aspect is to provide a technology for notifying a second user related to a first user of account information without collecting personal information of the second user. [Means for solving the problem]
[0008] According to one embodiment, an account management system is provided. The account management system includes a storage unit that stores multiple accounts, a related information acquisition unit that searches the storage unit for related information for each of the multiple accounts, and a display unit that displays a user screen. The related information acquisition unit searches for a second account associated with a first account among the multiple accounts. The display unit displays login information for the second account on the user screen for the first account.
[0009] In one aspect, the account management system further includes an account registration unit for registering an account, the account registration unit performing a registration process for a first account and generating a second account associated with the first account, the second account including an identifier of the first account.
[0010] In one aspect, the login information for the second account includes a temporary password, and the display unit displays information prompting the user to change the temporary password.
[0011] In one aspect, the account management system further includes a determination unit for determining whether or not to display the temporary password on the user screen of the first account based on password change information included in the second account.
[0012] In one aspect, the account management system further includes an operation accepting unit that accepts a user operation, The operation accepting unit accepts an operation to change the temporary password and changes the password change information to a status where the password has been changed.
[0013] In one aspect, the determination unit determines not to display the temporary password on the user screen of the first account based on the password change information indicating that the password has been changed.
[0014] In one aspect, the operation accepting unit changes the password change information to a status before the password was changed based on the acceptance of a password reset operation for the second account. The determination unit determines to display the temporary password on the user screen for the first account based on the password change information being the status before the password was changed.
[0015] According to another embodiment, a method of account management is provided, the method including retrieving from a storage device a second account associated with a first account of a plurality of accounts, and displaying login information for the second account on a user screen of the first account.
[0016] In one aspect, the method further includes performing a registration process for the first account and generating a second account associated with the first account, the second account including an identifier of the first account.
[0017] In one aspect, the login information for the second account includes a temporary password. The method further includes displaying information on a user screen prompting the user to change the temporary password.
[0018] In one aspect, the method further includes determining whether to display the temporary password on a user screen of the first account based on password change information included in the second account.
[0019] In one aspect, the method further includes the steps of accepting an operation to change the temporary password and changing the password change information to a status where the password has been changed.
[0020] In one aspect, the method further includes determining not to display the temporary password on a user screen of the first account based on the password change information being in a password changed status.
[0021] In one aspect, the method further includes a step of changing the password change information to a status before the password change based on receiving a password reset operation for the second account, and a step of determining to display a temporary password on a user screen for the first account based on the password change information being the status before the password change. [Effects of the Invention]
[0022] According to one embodiment, a second user related to a first user may be notified of account information without collecting personal information about the second user.
[0023] The above and other objects, features, aspects and advantages of the present disclosure will become apparent from the following detailed description of the disclosure taken in conjunction with the accompanying drawings. [Brief explanation of the drawings]
[0024] [Figure 1] FIG. 1 illustrates an example application of an account management system 100 according to an embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of a functional configuration of an account management system 100. [Figure 3] FIG. 2 is a diagram showing an example of data contained in each of a first account and a second account. [Figure 4] 1 is a diagram illustrating an example of the configuration of an information processing device 400 used as hardware for an account management system 100. FIG. [Figure 5] FIG. 5 is a diagram showing an example of a first screen 500 displayed on the display of the terminal 110. [Figure 6]It is a diagram showing an example of a second screen 600 displayed on the display of the terminal 110. [Figure 7] It is a diagram showing an example of a third screen 700 displayed on the display of the terminal 110. [Figure 8] It is a first example of a flowchart regarding the display of the user screen of the first user (user 120: student). [Figure 9] It is an example of a flowchart regarding the display of the user screen of the second user (user 130: guardian). [Figure 10] It is an example of a flowchart regarding the automatic update of the password of the second user (user 130: guardian). [Figure 11] It is a second example of a flowchart regarding the display of the user screen of the first user (user 120: student). [Figure 12] It is an example of a flowchart regarding the password reset process of the second user (user 130: guardian).
Embodiments for Carrying Out the Invention
[0025] Hereinafter, embodiments of the technical idea according to the present disclosure will be described while referring to the drawings. In the following description, the same parts are denoted by the same reference numerals. Their names and functions are also the same. Therefore, detailed descriptions thereof will not be repeated.
[0026] <A. Application Example> FIG. 1 is a diagram showing an application example of an account management system 100 according to the present embodiment. Referring to FIG. 1, the general operation of the account management system 100 according to the present embodiment will be described. The account management system 100 manages account information such as a web application (notification service to students and guardians, etc.) operated by a school, for example. In addition, the account management system 100 has a function of securely distributing account information to each of the students and guardians of the school.
[0027] In this disclosure, the account information of school students and their parents will be described as an example, but application examples of the account management system 100 are not limited to this. In one aspect, the account management system 100 may manage account information of public service members and their spouses. In another aspect, the account management system 100 may manage account information of company employees and their families. In yet another aspect, the account management system 100 may manage account information of any other first users and second users.
[0028] The network environment 10 according to this embodiment includes an account management system 100 and a terminal 110. Hereinafter, when referring to individual terminals 110, they will be referred to as terminals 110A, 110B, 110C, 110D, etc. When referring to these collectively or to any terminal, they will be referred to as terminal 110. The same applies to users 120 and 130.
[0029] The account management system 100 stores a first account and a second account in association with each other, and securely notifies each of the first user (e.g., a student) and the second user (e.g., a parent) of the account information. In one aspect, the account management system 100 may be implemented as one or more servers, or may be provided as a cloud service. In another aspect, the account management system 100 may be located within a facility (e.g., a school) where first users (e.g., students) gather, or may be located outside the facility.
[0030] Terminal 110 communicates with account management system 100 via a network and can use various functions of account management system 100. A user can use the browser function of terminal 110 or an application installed on terminal 110 to perform operations such as user registration with account management system 100, password changes, and viewing user screens provided by account management system 100. In some aspects, terminal 110 may be a personal computer, smartphone, tablet, or any other information processing terminal.
[0031] Next, a description will be given of the basic operation of the account management system 100. In the following description, as an example, an account is notified to a first user (student: user 120) and a second user (guardian: user 130). In this case, the operator (school) of the account management system 100 does not need to collect personal information (such as an email address) of the second user (guardian).
[0032] In a first step, the account management system 100 registers a first account (an account for a user 120). For example, at a school, each first user (a user 120: a student) creates an account in the account management system 100 via a terminal 110D on campus. In one aspect, each first user (a user 120: a student) may create an account by operating an account registration screen. In another aspect, each first user (a user 120: a student) may log in to the account management system 100 using a fixed ID and password prepared in advance and change the initial password. In another aspect, the terminal 110D may be a personal terminal of each user 120. For example, the school notifies each first user (a user 120: a student) of a QR (Quick Response) code (registered trademark) or a link from the school's homepage. In this case, each first user (user 120: student) can open the user registration page of the account management system 100 by reading the QR code on their own terminal or by opening the link.
[0033] In a second step, the account management system 100 automatically generates a second account (user 130's account) associated with the first account (user 120's account). The account management system 100 sets a temporary password for the second account (user 130's account). For example, based on the registration of user 120A's account (first account), the account management system 100 generates an account (second account) for user 130A, who is the guardian of user 120A, associated with the account of user 120A. Similarly, based on the registration of user 120B's account (first account), the account management system 100 generates an account (second account) for user 130B, who is the guardian of user 120B, associated with the account of user 120B. Based on the registration of the account (first account) of the user 120C, the account management system 100 generates an account (second account) of the user 130C, who is the guardian of the user 120C, in association with the account of the user 120C.
[0034] When creating a second account, the account management system 100 does not require personal information of the second user (user 130). The second account only needs to include the second account ID, related information to the first account, and a temporary password. For example, the account (second account) of user 130A does not require any personal information such as the name or contact information of user 130A. The account of user 130A only needs to include the account ID of user 130A (second account ID), the account ID of user 120A (first account ID), and a temporary password. Similarly, the account of user 130B only needs to include the account ID of user 130B (second account ID), the account ID of user 120B (first account ID), and a temporary password. The account of user 130C may include the ID of the account of user 130C (second account ID), the ID of the account of user 120C (first account ID), and a temporary password.
[0035] In the third step, the account management system 100 accepts the change of the password of the second account (the account of user 130). More specifically, each user 120 (student) goes home and logs in to their user screen on their home terminal 110. On the user screen of each first user (user 120: student), login information (URL of the login page, user ID, temporary password, QR code for opening the URL of the login page, etc.) for the user screen of each second user (user 130: guardian) is displayed. Each second user (user 130: guardian) can use the login information displayed on the user screen of each user 120 (student) to open their own user screen and change the password. By doing so, the operator of the account management system 100 (school) can notify each second user (user 130: guardian) of the user account without collecting the personal information of each second user (user 130: guardian), just by having each first user (user 120: student) create an account within the school. Also, the method of notifying the account by the account management system 100 does not require distributing paper with account information to each first user (user 120: student), and the security is improved compared to the conventional method.
[0036] <B. Example of the Configuration of the Account Management System> Next, referring to FIGS. 2 to 4, an example of the functional configuration, hardware configuration of the account management system 100, and the information included in the accounts managed by the account management system 100 will be described.
[0037] FIG. 2 is a diagram illustrating an example of the functional configuration of the account management system 100. Each function of the account management system 100 will be described with reference to FIG. 2. In one aspect, at least a portion of the functions illustrated in FIG. 2 may be implemented as software. In this case, at least a portion of the functions illustrated in FIG. 2 may be implemented by hardware illustrated in FIG. 4 working together to execute a program. In another aspect, at least a portion of the functions illustrated in FIG. 2 may be implemented by an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a general-purpose processor, a module including multiple components, a printed circuit board (PCB), or the like. In another aspect, the account management system 100 may further include any configuration other than the configuration illustrated in FIG. 2.
[0038] The account management system 100 includes, as functional components, an account registration unit 210, an account DB (Database) 220, a related information acquisition unit 230, a determination unit 240, a display unit 250, and an operation reception unit 260.
[0039] The account registration unit 210 accepts account registration processing via a user registration page or the like provided by the account management system 100. For example, the account management system 100 may accept user registration processing by each user 120 (student) via terminal 110D. In one aspect, the account registration unit 210 may accept user registration processing by each user 120 (student) via a browser function of terminal 110D. In another aspect, the account registration unit 210 may accept user registration processing by each user 120 (student) via an application installed on terminal 110D.
[0040] Furthermore, when each user 120 (student) is registered, the account registration unit 210 automatically generates an account for each user 130 (guardian) associated with the account of the user 120 (student). That is, the account registration unit 210 automatically generates a second account (user 130: guardian account) associated with the first account (user 120: student account).
[0041] The second account (user 130: parent account) does not need to include personal information such as the name, phone number, email address, etc. of each user 130 (parent). The second account (user 130: parent account) only needs to include at least the ID of the second account (user 130: parent account), the ID of the first account (user 120: student account), and a temporary password.
[0042] The account registration unit 210 stores the first account (user 120: student account) and the second account (user 130: parent account) in the account DB 220.
[0043] The account DB 220 stores accounts registered in the account management system 100. More specifically, the account registration unit 210 stores a first account (user 120: student account) and a second account (user 130: parent account) in association with each other. In one aspect, the account DB 220 may be implemented using a relational database. In another aspect, the account DB 220 may be implemented using any other format, such as CSV (Comma Separated Value) or JSON (JavaScript Object Notation).
[0044] The related information acquisition unit 230 searches the account DB 220 for a second account (user 130: parent's account) associated with a first account (user 120: student's account). For example, when the user 120 (student) logs in to a user screen, the related information acquisition unit 230 searches for a second account associated with the first account. Information about the searched second account may be displayed on the user screen of the first user.
[0045] The determination unit 240 determines whether or not to display all or part of the information of the second user account (user ID, temporary password, URL of a login page to the user screen, etc.) on the user screen of the first user.
[0046] As an example, the determination unit 240 may determine that if the user 130 (guardian) has not changed the temporary password for the second account, the information of the second account is to be displayed on the user screen of the first user.
[0047] As another example, if user 130 has already changed the temporary password for the second account, determination unit 240 may determine not to display information about the second account on the user screen of the first user. By not displaying information about the second account on the user screen of the first user more than necessary, determination unit 240 may prevent a third party from peeking at the information about the second account displayed on the display. In one aspect, determination unit 240 may determine whether to display only the temporary password.
[0048] As another example, if the password for the second account is reset because user 130A has forgotten the password, for example, the determination unit 240 may determine to display information about the second account on the user screen of the first user. In this case, the information about the second account may include the user ID, the newly issued temporary password, the URL of the login page for the user screen, etc.
[0049] Furthermore, as another example, if user 130 has not changed the temporary password for the second account, determination unit 240 may periodically change the temporary password for the second account. By doing so, determination unit 240 may prevent the same temporary password from being displayed on the user screen of the first user for a long period of time, thereby suppressing unauthorized logins by third parties. In one aspect, determination unit 240 may update the temporary password for the second account at any interval, such as every few days or hours. In another aspect, determination unit 240 may update the temporary password for the second account every time the user screen of the first user is displayed.
[0050] The determination unit 240 can determine whether the user 130 has changed the temporary password based on the password change information 313 (see FIG. 3) included in the second account stored in the account DB 220. The password change information 313 can express the status of whether the password has been changed in any format, such as binary, numeric, text, or Boolean.
[0051] Display unit 250 delivers to terminal 110 a screen or content within the screen to be displayed on the display of terminal 110. In one aspect, when terminal 110 displays a screen using a browser function, display unit 250 delivers to terminal 110 a HyperText Markup Language (HTML) file, other related files (Javascript, images, Cascading Style Sheets (CSS) files, etc.), account information, etc. In another aspect, when terminal 110 displays a screen using an installed application, display unit 250 delivers account information, etc. to terminal 110. Display unit 250 changes the display of the user screen of the first user (user 120: student) based on the determination of determination unit 240. Changing the display of the user screen may include changing the display of information for the second account, changing the displayed temporary password, etc.
[0052] The operation accepting unit 260 accepts operation inputs from the users 120 and 130 via the terminal 110. As one example, the operation accepting unit 260 may accept an operation input for registering a first account from each user 120 (student) via a terminal 110D installed in the facility (school) (or via any terminal 110). As another example, the operation accepting unit 260 may accept a login operation for a first account or a second account via any terminal 110. As yet another example, the operation accepting unit 260 may accept a password change input via any terminal 110. As yet another example, the operation accepting unit 260 may accept a password reset input via any terminal 110 or a specific terminal 110. The operation accepting unit 260 may update the first account or the second account stored in the account DB 220 based on the accepted operation input.
[0053] 3 is a diagram showing an example of data included in each of a first account and a second account. With reference to FIG. 3, the data that each of the first account and the second account may include and how the two accounts are associated will be described.
[0054] As an example, the first account 300 includes a first user ID 301, a name 302, a gender 303, an affiliation 304, and a password 305. The first user ID 301 uniquely identifies the first account 300. The first user ID 301 can be expressed in any format, such as a numeric value, an alphanumeric value, binary data, or a hash key. The name 302 is the name of the first user (user 120: student). The gender 303 is the gender of the first user (user 120: student). The affiliation 304 is the affiliation (grade, class, etc.) of the first user (user 120: student). The password 305 is the password for the first account 300.
[0055] 3 is merely an example, and the data included in first account 300 is not limited to this. In some aspects, first account 300 may not include any items other than first user ID 301, or may include any other items not shown in FIG.
[0056] In one aspect, based on the operation receiving unit 260 receiving a user registration input operation (for example, based on each user 120 (student) performing a user registration operation input via a user registration screen displayed on the display of the terminal 110D), the account registration unit 210 generates a first account 300.
[0057] In another aspect, when operation receiving unit 260 receives an input operation for a list of users 120 (any list such as a CSV file), account registration unit 210 may automatically generate first accounts 300 for each user 120 included in the list. In this case, a temporary password is set for each first account 300.
[0058] As an example, the second account 310 includes a second user ID 311, a first user ID 312, password change information 313, and a password 314. The second user ID 311 uniquely identifies the second account 310. The second user ID 311 can be expressed in any format, such as numeric values, alphanumeric characters, binary data, or a hash key.
[0059] The first user ID 312 indicates a relationship with the first account 300. For example, when the first account 300 and the second account 310 are represented as a relational database, the first user ID 312 is used as a foreign key. In this case, the related information acquisition unit 230 can search for the second account 310 associated with the first account 300 by linking the first user ID 301 (primary key) included in the first account 300 with the first user ID 312 (foreign key) included in the second account 310.
[0060] Password change information 313 may express the status of whether the password has been changed in any format, such as binary, numeric, text, or Boolean. Password change information 313 is used by determination unit 240 to determine whether to display some or all of the information of the second account on the user screen of the first user (user 120: student) and to determine whether to periodically change the temporary password. Furthermore, password change information 313 may be updated by operation reception unit 260 based on the operation reception unit 260 receiving an operation input, such as a password change, from the user. In one aspect, if password 314 has not been changed for a long period of time, determination unit 240 may change password change information 313 to a status indicating the password before the change.
[0061] The password 314 is the password for the second account 310. In the initial state, the password 314 is a temporary password.
[0062] The second account 310 is automatically generated by the account registration unit 210 in association with the first account 300. The second account 310 is required to include at least a second user ID 311, a first user ID 312, password change information 313, and a password 314, and does not require personal information of the second user (user 130: parent). In some cases, if it is not necessary to determine whether or not to display information about the second account 310 on the user screen of the first user (user 120: student) based on whether or not the temporary password has been changed, the second account 310 does not need to include the password change information 313.
[0063] In one aspect, the first account 300 may include the second user ID (e.g., as a foreign key) instead of the second account 310 including the first user ID 312. In other aspects, the account DB 220 may store the association information of the first account and the second account in any other format.
[0064] Fig. 4 is a diagram illustrating an example of the configuration of an information processing device 400 used as hardware of the account management system 100. In one aspect, the information processing device 400 may implement each of the functions illustrated in Fig. 2 by executing a program on the hardware illustrated in Fig. 4.
[0065] In another aspect, the account management system 100 may be realized by a cluster or cloud system configured by multiple information processing devices 400. Note that the information processing devices 400 may not have some of the components shown in FIG. 4, as necessary. For example, when multiple information processing devices 400 are used as part of a server or cloud system, some of the information processing devices 400 may not have the input interface 5, the output interface 6, etc.
[0066] In another aspect, information processing device 400 may be a personal computer, a smartphone, a tablet, or the like, and may also be used as terminal 110.
[0067] The information processing device 400 includes a CPU (Central Processing Unit) 1, a primary storage device 2, a secondary storage device 3, an external device interface 4, an input interface 5, an output interface 6, and a communication interface .
[0068] The CPU 1 can execute programs for implementing various functions of the information processing device 400. The CPU 1 is configured, for example, by at least one integrated circuit. The integrated circuit may be configured, for example, by at least one CPU, at least one FPGA, or a combination thereof.
[0069] The primary storage device 2 stores programs executed by the CPU 1 and data referenced by the CPU 1. In one aspect, the primary storage device 2 may be realized by a dynamic random access memory (DRAM) or a static random access memory (SRAM), etc.
[0070] The secondary storage device 3 is a non-volatile memory and may store programs executed by the CPU 1 and data referenced by the CPU 1. In this case, the CPU 1 executes programs read from the secondary storage device 3 to the primary storage device 2 and references data read from the secondary storage device 3 to the primary storage device 2. In one aspect, the secondary storage device 3 may be realized by an HDD (Hard Disk Drive), an SSD (Solid State Drive), an EPROM (Erasable Programmable Read Only Memory), an EEPROM (Electrically Erasable Programmable Read Only Memory), a flash memory, or the like.
[0071] The external device interface 4 can be connected to any external device such as a printer, a scanner, and an external HDD. In a certain aspect, the external device interface 4 may be realized by a USB (Universal Serial Bus) terminal or the like.
[0072] The input interface 5 can be connected to any input device such as a keyboard, a mouse, a touch pad, or a game pad. In a certain aspect, the input interface 5 may be realized by a USB terminal, a PS / 2 terminal, a Bluetooth (registered trademark) module, or the like.
[0073] The output interface 6 can be connected to any output device such as a cathode ray tube display, a liquid crystal display, or an organic EL (Electro-Luminescence) display. In a certain aspect, the output interface 6 may be realized by a USB terminal, a D-sub terminal, a DVI (Digital Visual Interface) terminal, an HDMI (registered trademark) (High-Definition Multimedia Interface) terminal, or the like.
[0074] The communication interface 7 is connected to a wired or wireless network device. In a certain aspect, the communication interface 7 may be realized by a wired LAN (Local Area Network) port, a Wi-Fi (registered trademark) (Wireless Fidelity) module, or the like. In other aspects, the communication interface 7 may transmit and receive data using communication protocols such as TCP / IP (Transmission Control Protocol / Internet Protocol) and UDP (User Datagram Protocol).
[0075] <C. Display example of screen> Next, examples of screen displays provided by the account management system 100 will be described with reference to Figures 5 to 7. Each screen shown in Figures 5 to 7 is displayed on the display of the terminal 110.
[0076] In one aspect, each of the screens shown in Figures 5 to 7 may be expressed using HTML, Javascript, CSS, or the like. In this case, terminal 110 may use a browser function to display each of the screens shown in Figures 5 to 7 on a display. In another aspect, each of the screens shown in Figures 5 to 7 may be displayed on a display by an application installed on terminal 110.
[0077] Fig. 5 is a diagram showing an example of a first screen 500 displayed on the display of terminal 110. A first configuration of the screen displayed on the display of terminal 110 will be described with reference to Fig. 5.
[0078] The first screen 500 is the user screen of the first user (user 120: student) when the second user (user 130: parent) has not changed the temporary password. In reality, the first screen 500 is a part of the user screen of the first user (user 120: student). The user screen of the first user (user 120: student) may include other content such as messages sent by the school to the first user (user 120: student).
[0079] First screen 500 may include URL link 501, second user ID 502, password 503, and QR code 504 as information for second user (user 130: guardian) to move to his / her own user screen and change the temporary password. In one aspect, first screen 500 may further include information prompting the user to change the temporary password.
[0080] URL link 501 is a link to the user screen of the second user (user 130: guardian). In one aspect, first screen 500 may include, instead of URL link 501, a button or the like that transitions to the user screen of the second user (user 130: guardian) when clicked or touched.
[0081] The second user ID 502 is the ID of the second user (user 130: guardian). The second user ID 502, together with the password 503, is used when logging in to the user screen of the second user (user 130: guardian).
[0082] The password 503 is the password of the second user (user 130: guardian), and is a temporary password generated by the account management system 100. The second user (user 130: guardian) can log in to his / her own user screen and change the temporary password.
[0083] The QR code 504 includes information for transitioning to a user screen of the second user (user 130: guardian). The second user (user 130: guardian) can display the user screen on the terminal 110 by capturing an image of the QR code 504 with the camera of the terminal 110, such as a smartphone.
[0084] As described above, the second user (user 130: parent) can view the user screen of the first user (user 120: student) and log in to their own user screen and change their password without disclosing personal information to the school.
[0085] Fig. 6 is a diagram showing an example of a second screen 600 displayed on the display of terminal 110. A second configuration of the screen displayed on the display of terminal 110 will be described with reference to Fig. 6.
[0086] The second screen 600 is a user screen of the second user (user 130: parent). In reality, the second screen 600 is a part of the user screen of the second user (user 130: parent). The user screen of the second user (user 130: parent) may include other content such as a message sent by the school to the second user (user 130: parent).
[0087] The second screen 600 may include information for the second user (user 130: guardian) to change the temporary password, such as a message 601 prompting the user to change the password, an input field 602 for the new password, an input field 603 for confirming the new password, and a set button (or OK button, etc.) 604.
[0088] The message 601 prompting the user to change their password may include a request to change their temporary password and the types of characters that can be used in the password. The new password input field 602 is a text box or the like for entering a new password. The new password confirmation input field 603 is a text box or the like for entering the new password again to confirm it. The set button 604 is a button for confirming the change to the new password.
[0089] Based on the second user (user 130: guardian) changing the password via the second screen 600, the operation receiving unit 260 changes the password change information 313 of the second account 310 to a status indicating that the password has been changed from before the password change.
[0090] In one aspect, the user screen of the second user (user 130: guardian) may display the items shown in FIG. 6 until the temporary password is changed. In another aspect, the user screen of the second user (user 130: guardian) may periodically display the items shown in FIG. 6 (such as when a deadline for recommending password updating arrives). In another aspect, the user screen of the second user (user 130: guardian) may display the items shown in FIG. 6 when the password is reset.
[0091] Fig. 7 is a diagram showing an example of a third screen 700 displayed on the display of terminal 110. The third configuration of the screen displayed on the display of terminal 110 will be described with reference to Fig. 7.
[0092] The third screen 700 is a user screen of the first user (user 120: student) after the second user (user 130: parent) has changed the temporary password. Note that, in reality, the third screen 700 is a part of the user screen of the first user (user 120: student).
[0093] Unlike the first screen 500, the third screen 700 does not display the password 503, but instead displays a message 703 informing the user that the password has been changed. The account management system 100 may remove the display of the password from the user screen of the first user (user 120: student) based on the second user (user 130: parent) changing the temporary password. This allows the account management system 100 to prevent the password from being leaked to a third party. In some cases, when the second user (user 130: parent) changes the temporary password, the user screen of the first user (user 120: student) may not only display the password 503, but may also not display all or some of the items shown in FIG. 5.
[0094] <D.フローチャート> Next, the internal processing procedure of the account management system 100 will be described with reference to Figures 8 to 12. In one aspect, the CPU 1 may load a program for performing the processing shown in Figures 8 to 12 from the secondary storage device 3 into the primary storage device 2 and execute the program. In this way, the functional configurations shown in Figure 2 may cooperate to perform the processing shown in Figures 8 to 12. In another aspect, some or all of the processing may be realized as a combination of circuit elements configured to perform the processing.
[0095] FIG. 8 is a first example of a flowchart relating to the display of a user screen of a first user (user 120: student).
[0096] In step S810, the determination unit 240 determines whether or not there is an account of a second user (user 130: parent) associated with the account of the first user (user 120: student), based on the fact that the operation reception unit 260 has received a display operation of a user screen or a login operation of the first user (user 120: student). As an example, the determination unit 240 may search for the account of the second user (user 130: parent) by referring to the account DB 220 and linking the first user ID 301 included in the first account 300 with the first user ID 312 included in the second account 310.
[0097] If the determination unit 240 determines that an account of a second user (user 130: parent) associated with the account of the first user (user 120: student) exists (YES in step S810), the determination unit 240 transfers control to step S820. Otherwise, the determination unit 240 transfers control to step S830.
[0098] In step S820, the determination unit 240 determines to display information about the second account (each item included in the first screen 500) on the user screen of the first user (user 120: student).
[0099] In step S830, the determination unit 240 determines not to display information about the second account (each item included in the first screen 500) on the user screen of the first user (user 120: student).
[0100] Based on the determination result of the determination unit 240, the display unit 250 changes the content of the user screen of the first user (user 120: student) to be distributed to the terminal 110.
[0101] FIG. 9 is an example of a flowchart relating to the display of the user screen of the second user (user 130: guardian).
[0102] In step S910, the operation accepting unit 260 executes the login process based on the login request (including the user ID and password) from the second user. Even if the login process is successful, the operation accepting unit 260 does not deliver the user screen (the screen after login) to the terminal 110 at this point, or does not cause the user screen to be displayed.
[0103] In step S920, the determination unit 240 determines whether the password change information 313 included in the second account 310 is, for example, 0 (determines whether the password change information 313 indicates the state before the password change).
[0104] If the determination unit 240 determines that the password change information 313 included in the second account 310 is 0 (YES in step S920), the control proceeds to step S930. Otherwise (NO in step S920), the determination unit 240 ends the process. In this case, the display unit 250 delivers to the terminal 110 a user screen that does not include the items of the second screen 600.
[0105] In step S930, display unit 250 displays a password change screen (second screen 600) on the display of terminal 110 of the second user (user 130: guardian).
[0106] In step S940, the operation accepting unit 260 accepts an operation input for changing the password.
[0107] In step S950, operation acceptance section 260 updates the password. More specifically, operation acceptance section 260 changes password 314 included in second account 310 to the accepted password.
[0108] In step S960, operation receiving unit 260 changes password change information 313 included in second account 310 to, for example, 1 (changes password change information 313 to a status indicating that the password has been changed).
[0109] FIG. 10 is an example of a flowchart for automatically updating the password of the second user (user 130: parent).
[0110] In step S1010, the determination unit 240 determines whether the password change information 313 included in the second account 310 is, for example, 0 (determines whether the password change information 313 indicates the state before the password change).
[0111] If determination unit 240 determines that password change information 313 included in second account 310 is 0 (YES in step S1010), it transfers control to step S1020. Otherwise (NO in step S1010), determination unit 240 ends the process.
[0112] In step S1020, the determination unit 240 determines whether the second account 310 meets a password change condition. The password change condition may include, for example, a state in which the second user (user 130: guardian) has not changed the temporary password, a state in which the password has not been changed for a predetermined period, a state in which the password has been reset, etc.
[0113] If determination unit 240 determines that second account 310 meets the password change condition (YES in step S1020), it transfers control to step S1030. Otherwise (NO in step S1020), determination unit 240 ends the process.
[0114] In step S1030, the determination unit 240 changes the password 314 of the second account 310.
[0115] 11 is a second example of a flowchart related to the display of the user screen of the first user (user 120: student). The account management system 100 switches whether or not to display the password of the second user on the user screen of the first user (user 120: student) based on the value of the password change information 313. In one aspect, the account management system 100 may execute the processing shown in FIG. 11 as a subroutine of steps S820 and S830.
[0116] In step S1110, the judgment unit 240 determines whether the password change information 313 of the account of the second user (user 130: parent) associated with the account of the first user (user 120: student) is, for example, 0 (determines whether the password change information 313 indicates the state before the password was changed).
[0117] If the determination unit 240 determines that the password change information 313 for the account of the second user (user 130: parent) associated with the account of the first user (user 120: student) is 0 (YES in step S1110), the determination unit 240 transfers control to step S1120. Otherwise, the determination unit 240 transfers control to step S1130.
[0118] In step S1120, the determination unit 240 determines to display the password of the second account (password 503 included in the first screen 500) on the user screen of the first user (user 120: student).
[0119] In step S1130, the determination unit 240 determines not to display the password of the second account (password 503 included in the first screen 500) on the user screen of the first user (user 120: student).
[0120] Based on the determination result of the determination unit 240, the display unit 250 changes the content of the user screen of the first user (user 120: student) to be distributed to the terminal 110.
[0121] FIG. 12 is an example of a flowchart relating to a password reset process for a second user (user 130: guardian).
[0122] In step S1210, the operation accepting unit 260 determines whether the password of the second user has been reset. More specifically, the operation accepting unit 260 may accept a request to reset the password of the second user from a user screen or an administrator page. In some aspects, the determination unit 240, instead of the operation accepting unit 260, may receive a notification from the operation accepting unit 260 (notification that a password reset request has been received) and determine whether the password of the second user has been reset.
[0123] If operation receiving unit 260 determines that the password of the second user has been reset (YES in step S1210), it transfers control to step S1220. Otherwise (NO in step S1210), operation receiving unit 260 ends the process.
[0124] In step S1220, the operation accepting unit 260 changes the password change information 313 included in the second account 310 from 1 to 0 (changing the status from indicating that the password has been changed to a status indicating the password before the change). In some cases, the determination unit 240, instead of the operation accepting unit 260, may change the password change information 313 included in the second account 310 from 1 to 0 (changing the status from indicating that the password has been changed to a status indicating the password before the change) upon receiving a notification from the operation accepting unit 260 (notification that a password reset request has been acquired). The determination unit 240 may decide, based on the fact that the password has been reset, to display the reset password (new temporary password) of the second user (user 130: parent) on the user page of the first user (user 120: student).
[0125] As described above, the account management system 100 according to the present embodiment can notify a first user (user 120: student) and a second user (user 130: parent) of an account. In this case, the account management system 100 can notify the second user (user 130: parent) of the account via the user screen of the first user (user 120: student) without collecting personal information of the second user (user 130: parent).
[0126] Furthermore, the account management system 100 automatically creates an account for a second user (user 130: parent) in association with the account of a first user (user 120: student). This eliminates the need for the second user (user 130: parent) to register an account, and the second user only needs to change the password.
[0127] The embodiments disclosed herein should be considered to be illustrative in all respects and not restrictive. The scope of the present disclosure is defined by the claims, not by the above description, and is intended to include all modifications within the meaning and scope equivalent to the claims. Furthermore, the disclosures described in the embodiments and each modification are intended to be implemented, as far as possible, either alone or in combination. [Explanation of symbols]
[0128] 1 CPU, 2 primary storage device, 3 secondary storage device, 4 external device interface, 5 input interface, 6 output interface, 7 communication interface, 10 network environment, 100 account management system, 110, D terminal, 120, 130 user, 210 account registration unit, 220 account DB, 230 related information acquisition unit, 240 judgment unit, 250 display unit, 260 operation reception unit, 300 first account, 301, 312 first user ID, 302 name, 303 gender, 304 affiliation, 305, 314, 503 password, 310 second account, 311, 502 second user ID, 313 password change information, 400 information processing device, 500 first screen, 501 link, 504 QR code, 600 second screen, 601, 703 message, 602 input field, 603 Confirmation input field, 604 Settings button, 700 Third screen.
Claims
1. a storage unit for storing a plurality of accounts; a related information acquisition unit for searching related information for each of the plurality of accounts from the storage unit; a display unit for displaying a user screen; an account registration unit for registering the account, The account registration unit performing a registration process for a first account for use by a first user; generating a second account associated with the first account, the second account including a temporary password, for use by a second user who is a guardian of the first user; An account management system in which the display unit displays login information including the temporary password of the second account identified by the related information acquisition unit and information prompting the user to change the temporary password on the user screen of the first account.
2. The account management system according to claim 1 , further comprising a determination unit for determining whether or not to display the temporary password on the user screen of the first account based on password change information included in the second account.
3. further comprising an operation receiving unit that receives user operations, The operation reception unit Accept the operation to change the temporary password, The account management system according to claim 2 , wherein the password change information is changed to a status where the password has been changed.
4. The account management system according to claim 3 , wherein the determination unit determines not to display the temporary password on the user screen of the first account based on the password change information indicating a status where the password has been changed.
5. the operation accepting unit changes the password change information to a status before the password was changed based on acceptance of a password reset operation for the second account; The account management system according to claim 4 , wherein the determination unit determines to display the temporary password on the user screen of the first account based on the password change information being a status before the password was changed.
6. 1. A method of account management, comprising: performing a registration process for a first account for use by a first user; generating a second account associated with the first account, the second account including a temporary password, for use by a second user who is a guardian of the first user; and displaying, on a user screen of the first account, login information including the temporary password for the second account associated with the first account and information prompting the user to change the temporary password.
7. The method of claim 6 , further comprising the step of determining whether to display the temporary password on the user screen of the first account based on password change information included in the second account.
8. accepting an operation to change the temporary password; 8. The method of claim 7, further comprising: changing the password change information to a password changed status.
9. The method of claim 8 , further comprising determining not to display the temporary password on the user screen of the first account based on the password change information indicating a password changed status.
10. changing the password change information to a status before the password was changed based on the reception of a password reset operation for the second account; The method of claim 9 , further comprising: determining to display the temporary password on the user screen of the first account based on the password change information being a status before the password was changed.
Citation Information
Patent Citations
Auction method, auction system and recording medium in which auction program is recorded
JP2001125993A
Information processing system and information processing method
JP2010055196A
Information processing device, audio-video transmission / reception system, and program
JP2017117494A
IoT device
JP2021047505A
Information processor and program
JP2021051552A