Management device, electronic commerce system, management method, and management program
The management device and system address user authority expiration issues by issuing timely warnings and managing user access, ensuring smooth operation and compliance with expiration dates in electronic commerce systems.
Patent Information
- Application Number
- JP2022090277
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-06-02
- Publication Date
- 2025-10-02
- Estimated Expiration
- 2042-06-02
AI Technical Summary
Electronic commerce systems face issues with users continuing to use the system after expiration dates or using it despite losing legitimate authority, leading to operational inconveniences.
A management device and system that includes a communication control unit and notification control unit to manage user authority expiration dates by issuing warnings and allowing for warning invalidation, ensuring smooth operation based on user expiration dates.
Ensures the electronic commerce system operates appropriately by managing user authority expiration dates, preventing unauthorized use and maintaining system integrity.
Smart Images

Figure 0007748335000001 
Figure 0007748335000002 
Figure 0007748335000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a management device, an electronic commerce system, a management method, and a management program. [Background technology]
[0002] Nowadays, a Web EDI (Electronic Data Interchange) system is known in which an electronic commerce system is built on a server device on the Web (World Wide Web), and each trading partner conducts electronic commerce by sending and receiving data via a web browser on a terminal device.
[0003] As background technology relating to such a WebEDI system, Patent Document 1 (Japanese Patent Laid-Open Publication No. 2003-091658) discloses an electronic commerce system aimed at efficiently realizing transactions between buyers and sellers.
[0004] This electronic commerce system allows one trading entity to establish a trading venue as the owner, and allows multiple trading entities to participate in the trading venue in accordance with the owner's requests. In this trading venue, the establishment of a group for trading specific products or a group consisting of specific trading entities is accepted, and an environment is created in which transactions in line with the established group objectives are conducted only among members of the group.
[0005] This allows trading entities to freely establish markets such as sales markets, purchase markets, trading company markets, and general markets as they wish, and also allows them to flexibly set up groups for specific products. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2003-091658 Summary of the Invention [Problem to be solved by the invention]
[0007] Here, users of electronic commerce systems are often given an expiration date indicating their authority to use the system. If the electronic commerce system is not operated appropriately based on this expiration date, for example, a user who needs to continue using the electronic commerce system may be unable to use the system after the expiration date. Furthermore, a user who loses legitimate authority to use the electronic commerce system due to a transfer or retirement may be able to continue using the system even after the expiration date. Such inconveniences hinder the smooth and sound operation of the electronic commerce system.
[0008] The present invention has been made in consideration of the above-mentioned problems, and aims to provide a management device, an electronic commerce system, a management method, and a management program that enable the electronic commerce system to be operated appropriately based on the expiration date assigned to each user. [Means for solving the problem]
[0009] In order to solve the above-mentioned problems and achieve the object, a management device according to the present invention includes a communication control unit that controls a communication unit so as to mediate the transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network, and a notification control unit that issues a warning indicating that the legitimate user authority will expire from a date a predetermined number of days before the date on which the legitimate user authority will expire, based on expiration date information indicating the expiration date of the user authority to officially use electronic commerce, which is included in the user information stored in the storage unit. The notification control unit controls the display of a warning indicating that the expiration date will come, and a warning invalidation selection object for specifying whether or not the warning will be unnecessary in the future, on the display unit.
[0010] In addition, in order to solve the above-mentioned problems and achieve the object, the electronic commerce system of the present invention comprises a first communication device having a first memory unit and communicating with terminal devices of each trading partner conducting electronic commerce via a network, and communicating with terminal devices of users of an operating company that operates the electronic commerce system via the network; a second communication device having a second memory unit and communicating with terminal devices of users of the operating company via the network; and a linkage device that synchronizes the data stored in the first memory unit and the data stored in the second memory unit at a predetermined timing, wherein the first communication device has a communication control unit that controls the communication unit to mediate the transmission and reception of various data between the terminal devices of each trading partner conducting electronic commerce via the network, and a notification control unit that notifies a warning indicating that the legitimate user authority will expire a predetermined number of days before the date on which the legitimate user authority will expire, based on expiration date information indicating the expiration date of the user authority to officially use electronic commerce contained in the user information stored in the memory unit.
[0011] In order to solve the above-mentioned problems and achieve the object, the management method according to the present invention includes a communication control step in which a communication control unit controls a communication unit so as to mediate transmission and reception of various data between terminal devices of each trading partner performing electronic commerce via a network, and a notification control step in which the communication control unit issues a warning indicating that the legitimate user authority will expire from a date a predetermined number of days before the date on which the legitimate user authority will expire, based on expiration date information indicating the expiration date of the user authority to legitimately use electronic commerce, which is included in the user information stored in the storage unit. The notification control step controls the display of a warning indicating that the expiration date will come, and the display of a warning invalidation selection object for specifying whether or not the warning will be unnecessary in the future, on the display unit.
[0012] In order to solve the above-mentioned problems and achieve the object, a management program according to the present invention includes a computer, which includes a communication control unit that controls a communication unit so as to mediate transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network, and a notification control unit that issues a warning indicating that the legitimate user authority will expire from a date a predetermined number of days before the date on which the legitimate user authority will expire, based on expiration date information indicating the expiration date of the user authority to officially use electronic commerce, which is included in the user information stored in the storage unit. The notification control unit controls the display of a warning indicating that the expiration date will come, and a warning invalidation selection object for specifying whether or not the warning will be unnecessary in the future, on the display unit. [Effects of the Invention]
[0013] The present invention allows the electronic commerce system to be operated appropriately based on the expiration date assigned to each user, thereby ensuring smooth and sound operation of the electronic commerce system. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 1 is a system configuration diagram of an electronic commerce system (EDI system) in which a management device according to an embodiment mediates electronic commerce. [Figure 2] FIG. 2 is a system configuration diagram of an operating company equipped with a management device. [Figure 3] FIG. 3 is a block diagram illustrating a hardware configuration of a management apparatus according to an embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of the WebEDI customer classification master. [Figure 5] FIG. 5 is a diagram illustrating an example of the WebEDI supplier master data. [Figure 6] FIG. 6 is a diagram illustrating an example of the WebEDI user group master. [Figure 7] FIG. 7 is a diagram illustrating an example of the WebEDI user master. [Figure 8] FIG. 8 is a diagram for explaining a screen displayed to each manager or person in charge of a user group. [Figure 9]FIG. 9 is a diagram showing an example of the supplier master maintenance screen. [Figure 10] FIG. 10 is a diagram showing an example of the operating company user master maintenance screen. [Figure 11] FIG. 11 is a diagram showing an example of the operating company supplier user master maintenance screen. [Figure 12] Figure 12 shows an example of a supplier user master maintenance screen for business partners that is displayed when launched by a customer manager user, and an example of a supplier user master maintenance screen for business partners that is displayed when launched by a supplier manager user. [Figure 13] FIG. 13 is a flowchart showing the flow of the registration operation when the operating company administrator newly registers an operating company user. [Figure 14] FIG. 14 shows an example of a login screen and data referenced in the WebEDI user master. [Figure 15] FIG. 15 shows data referenced in the WebEDI user group master, an example of an operating company user master maintenance screen, and a record to be added and registered in the WebEDI user master. [Figure 16] FIG. 16 is a flowchart showing the flow of the registration operation when the operating company administrator newly registers a supplier person in charge user. [Figure 17] FIG. 17 shows an example of selection and input on the operating company supplier user master maintenance screen when a new user is registered. [Figure 18] FIG. 18 is a diagram showing data referenced in the WebEDI business partner master, data referenced in the WebEDI user master, and records added to and registered in the WebEDI user master. [Figure 19] FIG. 19 is a flowchart showing the flow of the registration operation when a client manager newly registers a user of his or her own company. [Figure 20] FIG. 20 shows an example of a login screen and data referenced in the WebEDI user master. [Figure 21]FIG. 21 is a diagram showing an example of data referenced in the WebEDI supplier master, data referenced in the WebEDI user group master, and a supplier user master maintenance screen for suppliers. [Figure 22] FIG. 22 is a diagram showing data referenced in the WebEDI supplier master and data referenced in the WebEDI user master. [Figure 23] Figure 23 shows an example of an error message displayed on the business partner user master maintenance screen for the operating company or the business partner user master maintenance screen when an attempt is made to register a user who exceeds the maximum number of users that can be registered, and a figure showing the record that is added to the WebEDI user master. [Figure 24] FIG. 24 is a flowchart showing the flow of a bulk invalidation operation in which the operating company administrator invalidates the transaction status for a business partner, thereby invalidating the authority of all users of that business partner to use the EDI system. [Figure 25] Figure 25 shows a diagram showing a trading partner whose transaction status has been invalidated by the operating company administrator, and the user ID expiration date of each user of the trading partner whose transaction has been invalidated, updated to expired. [Figure 26] Figure 26 is a flowchart showing the flow of operations that, when an administrator of the operating company logs in to the management device, detects a user of the operating company or a business partner whose validity is about to expire and sends a warning notification to the administrator of the operating company. [Figure 27] FIG. 27 is a diagram showing an example of the login screen. [Figure 28] FIG. 28 is a diagram showing an example of a menu screen displaying a predetermined warning message (a message urging a user whose validity period is about to expire to check). [Figure 29] FIG. 29 is a diagram showing an example of a list screen of user information of each user such as a business partner. [Figure 30] FIG. 30 is a diagram showing an example of the user master detail screen. [Figure 31] FIG. 31 is a diagram for explaining the operation of registering an extension of the expiration date. [Figure 32] FIG. 32 shows an example of an error message that is displayed when a validity period exceeding the set upper limit is specified. [Figure 33] FIG. 33 is a diagram for explaining how to disable the expiration date warning. [Figure 34] FIG. 34 is a flowchart showing the flow of the operation for issuing a warning indicating the presence of a user whose expiration date has passed. [Figure 35] FIG. 35 is a diagram showing an example of the menu screen. [Figure 36] FIG. 36 is a diagram showing an example of the list screen. [Figure 37] FIG. 37 is a diagram showing an example of a user master detail screen for a user whose validity period has expired. [Figure 38] FIG. 38 is a diagram for explaining the registration of an extension of the validity period for a user whose validity period has expired. [Figure 39] FIG. 39 is a diagram for explaining how to disable a warning about the expiration date to a user whose expiration date has expired. [Figure 40] FIG. 40 is a schematic diagram showing the warning form of warning pattern 1. [Figure 41] FIG. 41 is a schematic diagram showing the warning form of warning pattern 2. [Figure 42] FIG. 42 is a schematic diagram showing the warning form of warning pattern 3. [Figure 43] FIG. 43 is a schematic diagram showing the warning form of warning pattern 4. [Figure 44] FIG. 44 is a flowchart showing the flow of the warning operation of warning pattern 0. [Figure 45] FIG. 45 is a flowchart showing the flow of the warning operation of warning pattern 1. [Figure 46] FIG. 46 is a diagram showing an example of the WebEDI user group master. [Figure 47] FIG. 47 is a diagram showing an example of the WebEDI user master. [Figure 48]FIG. 48 is a flowchart showing the flow of the warning operation for warning pattern 3 and warning pattern 4. [Figure 49] FIG. 49 is a diagram showing an example of the WebEDI customer classification master. [Figure 50] FIG. 50 is a flowchart showing the flow of the warning operation for warning pattern 2 and warning pattern 4. DETAILED DESCRIPTION OF THE INVENTION
[0015] Hereinafter, embodiments to which the present invention is applied will be described. Note that these embodiments are merely examples of the present invention, and the present invention is not limited to these embodiments.
[0016] [System Configuration] FIG. 1 is a diagram showing the system configuration of an electronic commerce system (EDI system, EDI: Electronic Data Interchange) in which a management device 1 according to an embodiment mediates and manages electronic commerce. As shown in FIG. 1, the EDI system is configured to include a management system of an operating company including the management device 1 according to an embodiment, a customer terminal device 100 of a customer who conducts commerce, and a supplier terminal device 200 of a supplier. As illustrated in FIG. 1, the management system of the operating company mediates, using the management device 1 according to an embodiment, inventory confirmation and order input from the customer terminal device 100, and ordering and order acceptance from the supplier terminal device 200. Note that customers and suppliers are examples of trading partners.
[0017] (Operating company system configuration) Fig. 2 is a configuration diagram of the management system of the operating company. As shown in Fig. 2, the management system of the operating company includes a front environment (an example of a first communication device) configured by the management device 1 of the embodiment, a backyard environment (an example of a second communication device) configured by a terminal device 80 for management of the operating company, and a linking tool 90 which is a terminal device that links the front environment and the backyard environment.
[0018] The front environment is connected to the terminal devices of users of the operating company as well as the terminal devices of users of customers and suppliers via a wide area network such as the Internet 8. This front environment is an environment that users of business partners (customers and suppliers) and users of the operating company can log in to and use.
[0019] The front environment is made public on the Internet and can be accessed and used by users of the operating company and users who have business relationships with the operating company. Specifically, the storage unit 2 of the management device 1 of the embodiment included in the operating company's front environment stores user information on users of the operating company, users of recipients (customers) of goods or services, etc., and users of suppliers (suppliers) of goods or services, etc. The storage unit 2 also temporarily stores business data resulting from commercial transactions between customers and suppliers. Users of the operating company and users who have business relationships with the operating company can access the management device 1 and use the user data (examples of user information such as names and email addresses) in the storage unit 2 and the temporarily stored business data (= commercial transaction data).
[0020] If the number of business partners is small, the front environment can be made public by restricting the connection sources. This allows the front environment to be made public with higher security.
[0021] The backyard environment is an environment in which connections to external companies such as business partners are not permitted, and is configured with terminal devices 80 that can only be logged in and used by authorized users of the operating company. For this reason, it is preferable that the terminal devices 80 in this backyard environment be connected to the terminal devices of authorized users of the operating company via a network 9 such as a private network that is not connected to a wide area network such as the Internet, or a dedicated line.
[0022] Authorized users of the operating company can access a memory unit (commercial transaction data management database) 82 in which business data (commercial transaction data) for data management is stored via a communication interface unit 81 of a terminal device 80 in this backyard environment.
[0023] The collaboration tool 90 periodically or irregularly accesses the storage unit 2 in the front environment and the storage unit 82 in the backyard environment, and synchronizes the business data for temporary storage stored in the storage unit 2 in the front environment with the business data for data management stored in the storage unit 82 in the backyard environment. In other words, the collaboration tool 90 periodically or irregularly collaborates the business data for temporary storage in the storage unit 2 and the business data for data management in the storage unit 82 so that they are the same data.
[0024] By separating the front and back-end environments in this way, even if one of the environments goes down, business can continue in the other environment. Furthermore, each environment can be constructed with specifications according to the expected number of users of each environment, such as by constructing the front-end environment with high-spec terminal devices since it will be used by a large number of people, and by constructing the back-end environment with low-spec terminal devices since it only needs to be accessible by a limited number of users. This allows resources to be optimized.
[0025] Furthermore, for example, since personal information of users of each business partner is registered in the memory unit 2 (database) of the front environment, the data can be operated in accordance with the nature of the data stored in the database of each environment (memory unit 2 or memory unit 82), such as by applying special encryption processing before registration.
[0026] Furthermore, by permitting only specific communications (the above-mentioned data synchronization) using the collaboration tool 90, an infrastructure boundary can be established between the front environment and the backyard environment, separating them and enhancing security.
[0027] (Hardware configuration of management device) Next, Fig. 3 shows the hardware configuration of the management device 1 of the operating company. As described above, this management device 1 is connected to the customer terminal device 100 and the supplier terminal device 200 via a wide area network such as the Internet 8. Such management device 1 includes a storage unit 2, a control unit 3, and a communication interface unit 4. The communication interface unit 4 is connected to the customer terminal device 100 and the supplier terminal device 200 via the network 8. The communication interface unit 4 is also connected to a terminal device 80 in a backyard environment via the network 8 and a collaboration tool 90.
[0028] The storage unit 2 may be, for example, a read-only memory (ROM), a random access memory (RAM), a hard disk drive (HDD), or a solid state drive (SSD). The storage unit 2 stores a WebEDI customer classification master 11, a WebEDI customer master 12, a WebEDI user group master 13, and a WebEDI user master 14. The storage unit 2 also stores the above-mentioned user data and business data for temporary storage (transaction data) in addition to a management program for managing transactions.
[0029] Fig. 4 is a diagram showing an example of the WebEDI customer classification master 11. As shown in Fig. 4, the WebEDI customer classification master 11 stores "customer" and "supplier" as customer classifications.
[0030] Figure 5 is a diagram showing an example of the WebEDI customer master data 12. As shown in Figure 5, the WebEDI customer master data 12 stores, for each customer classification and customer company, the upper limit of the number of users that can be registered, and status information indicating whether the customer company can use the EDI system. In the example of Figure 5, for customer company A, the upper limit of the number of users that can be registered is "3," and the status information indicating whether the EDI system can be used is set to "enabled."
[0031] 5 shows an example in which the supplier company X has a maximum number of users that can be registered of "8 people" and the status information indicating whether or not the company can use the EDI system is set to "invalid." As will be described later, the management device 1 of the embodiment updates the user ID expiration date of each user of the company whose status information is set to "invalid" to the expiration date. As a result, by setting the status information for the company to "invalid," it is possible to collectively restrict the use of the EDI system by all users of that company.
[0032] 6 is a diagram showing an example of the WebEDI user group master 13. The master stores business partner classifications, user groups, operating company management availability information, and business partner management availability information.
[0033] Of these, the user groups indicate each user in charge of the business (jobs) of the operating company, clients, and suppliers. That is, the user group of "operating company administrator" indicates a group made up of each user who performs management tasks at the operating company. Also, the user group of "client representative" indicates a group made up of each user who is in charge at a client.
[0034] The user group "Supplier Estimator" indicates a group made up of users who are in charge of quotation work at the supplier. The user group "Supplier Worker" indicates a group made up of users who are in charge of actual work at the supplier.
[0035] The operating company management permission information is information that indicates the user groups for which the operating company is allowed to manage user registration. In the example of Fig. 6, the operating company is allowed to manage user registration (user registration authority) for all user groups, including the operating company itself, its customers, and its suppliers.
[0036] Furthermore, in the management device 1 of the embodiment, the authority to register users can be delegated (set) to desired user groups of customers and suppliers. Information indicating whether or not the authority to register users has been delegated is the business partner management availability information. The example in FIG. 6 shows an example in which the operating company delegates (sets) the authority to register users to the user groups of "customer manager" and "customer representative" of the customer via the management device 1. In other words, the user with the registration authority in this case is the customer manager, and this indicates that user registration is possible only for the user groups of "customer manager" and "customer representative."
[0037] The example in Figure 6 shows that the operating company has delegated (set) the authority to register users for the supplier's "Supplier Worker" user group to the supplier's supplier manager. In other words, the user with registration authority in this case is the supplier manager, and this supplier manager can only register users for the "Supplier Worker" user group.
[0038] In this example, the explanation will be given assuming that the authority to register users is set for each user group of business partners, but the authority to register users may be set for each business partner.
[0039] Fig. 7 is a diagram showing an example of the WebEDI user master 14 in which the above-mentioned user data is registered. As shown in Fig. 7, the WebEDI user master 14 stores the user identification information (user ID), user name, and user ID expiration date of each user belonging to the user group of the operating company and each business partner. The user ID expiration date is information indicating the date on which the EDI system can be used.
[0040] The example in Figure 7 shows that the user ID expiration dates for the user "Operating Company Administrator UK1" with the user ID "UK01" and the user "Operating Company Administrator UK2" with the user ID "UK02" who belong to the user group of "Operating Company Administrator" of the operating company are both "March 31, 2030." The example in Figure 7 also shows that the user ID expiration dates for the user "Company A Person AT1" with the user ID "AT01" and the user "Company A Person AT3" with the user ID "AT03" who belong to the user group of "Customer Representative" of Company A are both "March 31, 2030," but the user ID expiration date for the user "Company A Person AT2" with the user ID "AT02" expires on "January 1, 2010."
[0041] Similarly, the example in Figure 7 shows that the user ID expiration dates for the users "Company X Administrator XK1" and "Company X Estimator XMT1" of Company X are both set to expire on March 1, 2022.
[0042] Next, Fig. 8 is a diagram showing a list of various screens provided by the management device 1 to users of the user group of the operating company and each business partner. As shown in Fig. 8, a "Business Partner Master Maintenance Screen," a "Business Partner User Master Maintenance Screen," and a "Business Partner User Master Maintenance Screen for Operating Company" are provided by the management device 1 to each user of the user group of the "Operating Company Administrator." In addition, an "Operating Company Business Screen" is provided by the management device 1 to each user of the user group of the "Operating Company Personnel."
[0043] Furthermore, the management device 1 provides a "Customer User Master Maintenance Screen for Customers" to users in the "Customer Manager" user group, and a "Customer Business Screen" to users in the "Customer Person in Charge" user group.
[0044] Furthermore, the management device 1 provides a "Supplier User Master Maintenance Screen for Suppliers" to users in the user group of "Supplier Manager", a "Supplier Quotation Work Screen" to users in the user group of "Supplier Actual Worker", and a "Supplier Actual Work Screen" to users in the user group of "Supplier Manager".
[0045] More specifically, Figure 9 shows an example of the "Customer Master Maintenance Screen" provided to each user in the "Operating Company Administrator" user group. The "Customer Master Maintenance Screen" shown in Figure 9 is a screen for registering suppliers who use the EDI system. The operating company uses this "Customer Master Maintenance Screen" to register supplier classifications, supplier names, maximum number of users, and statuses.
[0046] As the business partner classification, "Supplier" or "Customer" is selected and registered. As the business partner name, for example, a business partner name such as "Company X" is registered. As the user limit, the upper limit of the number of users who are allowed to use the EDI system is registered. As the status, status information indicating whether or not the EDI system is allowed to be used (enabled or disabled) is registered. In the example of Figure 9, the status information for Company X is set to "disabled," and Company X is therefore not allowed to use the EDI system.
[0047] Fig. 10 is a diagram showing an example of the "operating company user master maintenance screen" provided to each user in the user group of the "operating company administrator." As shown in Fig. 10, the "operating company user master maintenance screen" is a screen on which "operating company users" are classified into user groups and user information is registered. Users on the operating company side register their user group (operating company administrator or operating company staff), user ID, user name, initial password, and user ID expiration date via this "operating company user master maintenance screen."
[0048] FIG. 11 is a diagram showing an example of the "Operating Company Business Partner User Master Maintenance Screen" provided to each user in the "Operating Company Administrator" user group. As shown in FIG. 11, the "Operating Company Business Partner User Master Maintenance Screen" is a screen on which "business partner users on the operating company side" are classified into user groups and user information is registered. The operating company user registers business partner classification, business partner name, user group, user ID, user name, initial password, and user ID expiration date via this "Operating Company Business Partner User Master Maintenance Screen." For business partner classification, supplier or customer is selected. For business partner name, a business partner name such as "Company X" or "Company Y" is selected. For user group, the above-mentioned user groups such as "Supplier Person" or "Customer Manager" are selected.
[0049] Figure 12 shows an example of the "Customer User Master Maintenance Screen for Suppliers" provided to each user in the user group of the "Customer Manager" or "Supplier Manager." Of these, Figure 12(a) is an example of the "Customer User Master Maintenance Screen for Suppliers" provided to the "Customer Manager," and Figure 12(b) is an example of the "Customer User Master Maintenance Screen for Suppliers" provided to the "Supplier Manager."
[0050] As shown in Figure 12(a), the "Customer Administrator" selects the user group to which the company's users will belong via the "Customer User Master Maintenance Screen for Customers," and registers the user ID, user name, initial password, and user ID expiration date.
[0051] Similarly, the "Supplier Manager" selects the user group to which his company's users will belong via the "Supplier User Master Maintenance Screen for Suppliers" as shown in Figure 12(b), and registers the user ID, user name, initial password, and user ID expiration date. Note that in the example of Figure 12(b), the user group selected is "Supplier Workers."
[0052] (Functional configuration of management device) Next, the control unit 3 of the management device 1 shown in Figure 3 executes the management program stored in the memory unit 2, thereby functioning as a communication control unit 21, a user management authority setting unit 22, a data generation unit 23, a discrimination unit 24, a memory control unit 25, a display screen generation unit 26, a status setting unit 27, and a notification control unit 28.
[0053] The communication control unit 21 controls the communication interface unit 4, which is an example of a communication unit, to mediate the transmission and reception of various commercial transaction data between the terminal devices 100, 200 of each trading partner conducting electronic commerce via the network 8. The user management authority setting unit 22 sets user management authority for the trading partner to register or edit specified user information including expiration date information indicating the expiration date of legitimate user authority. "Editing" is a concept that includes actions such as changing and deleting data content, such as correcting and deleting user information.
[0054] When a request for new user registration or editing (including deletion) is made via the business partner's terminal device 100, 200, the display screen generation unit 26 generates a user registration screen (business partner user master maintenance screen for business partners shown in Figures 12(a) and 12(b)) for new user registration, etc., which is sent via the communication interface unit 4 to the business partner's terminal device that requested the new user registration, etc.
[0055] The determination unit 24 determines whether the business partner that has requested new user registration, etc. is a business partner for which user management authority has been set. When the determination unit 24 gives a determination result indicating that the business partner that has requested new user registration, etc. is a business partner for which user management authority has been set, the storage control unit 25 stores the user information, including the user ID expiration date information of the user who has been newly registered, in the WebEDI user master 14 of the storage unit 2, which stores user information, including expiration date information (user ID expiration date information) for each user, set for each business partner.
[0056] The user management authority setting unit 22 sets user management authority for each user group made up of managers or personnel of each business partner. The user management authority setting unit 22 also sets an upper limit on the number of users that can be registered for each business partner.
[0057] The status setting unit 27 also sets a status indicating whether a transaction with each business partner is valid or invalid. The storage control unit 25 adds status information indicating the status set by the status setting unit 27 for each business partner together with the user information and user ID expiration date information of the user of each business partner, and stores the added information in the WebEDI business partner master 12 in the storage unit 2.
[0058] Furthermore, when the status setting unit 27 sets the status of "invalid" for a supplier, the storage control unit 25 updates the status information of the supplier whose transaction has been invalidated, stored in the WebEDI supplier master 12, to status information of "invalid." At the same time, the storage control unit 25 updates the user ID expiration date information of the user of the supplier whose transaction has been invalidated, stored in the WebEDI user master 14, to the expiration date.
[0059] The data generating unit 23 generates user data including the user group, user ID, initial password, user ID expiration date, etc., input via the various screens described with reference to FIGS.
[0060] The notification control unit 28 issues a warning indicating that the authorized user authority will expire a predetermined number of days before the expiration date of the authorized user authority, based on expiration date information (user ID expiration date information) indicating the expiration date of the user authority to officially use electronic commerce included in the user data stored in the storage unit 2. The "predetermined number of days before" is preset, for example, 30 days before the expiration date.
[0061] The "warning notification" may be a warning message displayed on the display unit, or an audio output such as an electronic sound or voice message indicating that the expiration date is approaching. The "warning notification" may also be an electronic message such as an email or short message containing a statement indicating that the expiration date is approaching.
[0062] In the following, we will explain that a "warning notification" indicating the expiration of a user's authorization to use e-commerce legitimately is a warning message indicating that there is a user whose authorization is about to expire, or a warning message indicating that there is a user whose authorization has already expired.
[0063] In addition to the warning message indicating the expiration date, the notification control unit 28 also displays a warning invalidation selection object (an area in FIG. 30 where the text "Invalidate warning" and a checkbox are displayed) for specifying whether or not to make this warning message unnecessary in the future. At this time, the notification control unit 28 displays the warning invalidation selection object from a date a predetermined number of days before the expiration date of the regular user authority, such as 30 days. Furthermore, when an extension of the expiration date of the user who is the target of a warning is registered, the notification control unit 28 hides the warning invalidation selection object for a predetermined period, such as until the warning period of the next year.
[0064] In addition, when the invalidation of a warning is specified via the warning invalidation selection object, the memory control unit 25 updates the warning information, which is stored in the memory unit 2 and is included in the user information of the user who is the target of the warning, and indicates whether or not a warning will be issued, to "invalid," which indicates that a warning will not be issued in the future.
[0065] Furthermore, when registering an extension of the expiration date of a user who is the target of a warning, if an expiration date exceeding a predetermined upper limit, such as "365 days," is entered, the notification control unit 28 will issue a predetermined error notification (display an error message) such as "The user ID expiration date has exceeded the set upper limit." The predetermined error notification may be an electronic sound or a voice message, as described above.
[0066] Furthermore, the notification control unit 28 issues a warning to the effect that there is a user whose expiration date has expired without an extension registration, and displays the above-mentioned warning invalidation selection object. When an extension registration of the expiration date of the user who is the target of the warning is performed, the notification control unit 28 hides the warning invalidation selection object. When invalidation of the warning is specified via the warning invalidation selection object without an extension registration of the expiration date, the storage control unit 25 updates the warning information, which indicates whether or not to issue a warning and is included in the user information of the user who is the target of the warning and is stored in the storage unit 2, to "invalid," which indicates that a warning will not be issued in the future.
[0067] Furthermore, the notification control unit 28 notifies the user of the following as a warning: (Warning pattern 0) Notification to users whose regular user privileges are about to expire, (Warning pattern 1) Notification to the administrator of a user whose regular user privileges are about to expire. (Warning pattern 2) If the user whose regular user permissions are about to expire is a business partner user, a notification will be sent to the business partner's administrator. (Warning pattern 3) If the user whose regular user authority is about to expire is a business partner user, a notification will be sent to the operating company administrator of the operating company that manages all business partners. (Warning pattern 4) If the user whose regular user authority is about to expire is a user of a business partner, notification will be sent to the business partner's administrator and the operating company administrator of the operating company that manages all business partners. One or more of these warning patterns are set in advance, and the notification control unit 28 issues a warning of the set warning pattern based on this setting information.
[0068] Furthermore, if the expiration date setting information, which is included in the user information of the operating company administrator of the operating company that manages all business partners and indicates whether or not an expiration date must be set for the authorized user authority, indicates that no expiration date is set, the notification control unit 28 suppresses the warning. Setting this expiration date setting information (expiration date required flag) to "FALSE" enables a setting that allows user registration without setting an expiration date. Furthermore, since it is generally assumed that business partner management and user management tasks are performed indefinitely for operating companies, it is possible to select an operation in which the expiration date setting information (expiration date required flag) is set to OFF. If no expiration date is set, the expiration date in the WebEDI user master 14 becomes "NULL" (see Figure 47).
[0069] The user information stored in the storage unit 2 includes the expiration date information indicating the expiration date of the legitimate user authority, as well as warning date information indicating the warning period during which the warning is issued, which is set uniquely for the entire e-commerce system, or set for a predetermined group, or set for each user. The storage control unit 25 stores the expiration date information indicating the specified expiration date and the warning date information indicating the specified warning period in the user information of the target user in the storage unit 2.
[0070] (Operating company registers new users) Next, the operation of registering a new user for the operating company in the management device 1 of such an operating company will be explained using the flowchart of FIG. 13. Note that the following explanation will be given taking "registration" of a new user as an example, but the same operation will be performed when "editing" such as correcting or deleting user information. Therefore, please refer to the explanation below for the operation when editing such as correcting or deleting user information. Each process in the flowchart of FIG. 13 is executed by the control unit 3 of the management device 1 based on the management program stored in the memory unit 2. That is, a user who wishes to register a new user for the operating company makes a login request to the management device 1 via the administrator terminal device. This starts the flowchart of FIG. 13, and the processing is executed in order from step S1.
[0071] In step S1, the display screen generation unit 26 of the management device 1 generates a login screen exemplified in FIG. 14(a). The communication control unit 21 transmits this login screen to the administrator terminal device of the user of the operating company who has made the login request. The user of the operating company who has made the login request inputs a user ID and password into the login screen displayed on the display screen of the administrator terminal device. The input user ID and password are transmitted to the management device 1.
[0072] The determination unit 24 of the management device 1 refers to the user ID expiration date in the WebEDI user master 14 shown in Fig. 14(b) based on the user ID entered via the login screen (step S2). The determination unit 24 then determines whether the entered user ID has expired by determining whether today's date is past the date set as the user ID expiration date (step S3). If the determination unit 24 determines that the entered user ID has expired (step S3: Yes), the user does not have the authority to register, and the processing of the flowchart in Fig. 13 ends.
[0073] On the other hand, if it is determined that the entered user ID is within the expiration date (step S3: No), the discrimination unit 24 determines whether there is a request to launch the operating company user master maintenance screen (step S4). If a request to launch the operating company user master maintenance screen is detected (step S4: Yes), the discrimination unit 24 determines in step S5 based on the user ID by referring to the WebEDI user master 14 shown in Figure 14(c) whether the user is a user of the user group of the "operating company administrator" who has the authority to register a new user. If the user is not a user of the user group of the "operating company administrator" (step S5: No), the user does not have the authority to register a user, and the processing of the flowchart in Figure 13 ends.
[0074] If the user is in the user group of the "operating company administrator" (step S5: Yes), the process proceeds to step S6. In step S6, the determination unit 24 refers to the WebEDI user group master 13 as shown in Fig. 15(a) to identify a user group whose customer classification has not been set and which can be managed by the operating company.
[0075] In other words, a user group for which a customer classification has not been set is not a user group for either a customer or a supplier, but a user group for the operating company. For this reason, the discrimination unit 24 detects user groups of the operating company for which a customer classification has not been set. Then, by referring to the operating company management availability information in the WebEDI user group master 13, the discrimination unit 24 identifies user groups for which user registration is possible (user groups for which user management within the operating company is possible) among the user groups of the operating company for which a customer classification has not been set. The example in Figure 15(a) is an example in which new user registration is permitted for the user groups of "operating company administrator" and "operating company staff."
[0076] Next, in step S7, the display screen generation unit 26 generates an operating company user master maintenance screen exemplified in FIG. 15(b), and the communication control unit 21 transmits this operating company user master maintenance screen to the manager terminal device.
[0077] The user of the administrator terminal device selects either the "operating company administrator" or the "operating company staff" user group, which is a user group for which user registration is permitted, based on the operating company user master maintenance screen shown in Fig. 15(b). The user of the administrator terminal device also performs a registration operation by entering the user ID, user name, initial password, and user ID expiration date of the user to be newly registered on the operating company user master maintenance screen shown in Fig. 15(b).
[0078] As a result, the information on the user group, user ID, user name, initial password, and user ID expiration date entered via the operating company user master maintenance screen is sent from the administrator terminal device to the management device 1, and a registration request is made. When this registration request is received by the management device 1, the data generation unit 23 of the management device 1 determines that a registration operation has been performed (step S8: Yes), and generates detailed data (records) for the WebEDI user master 14, including the user group, user ID, user name, initial password, and user ID expiration date received from the administrator terminal device.
[0079] In step S9, the storage control unit 25 adds and stores the detailed data (records) generated by the data generation unit 23 in the WebEDI user master 14 as shown in Fig. 15(c). As a result, for example, a user with a user ID of "UT99" and a user name of "Operating Company Personnel UT99" is newly registered in the user group of "Operating Company Personnel" of the operating company, with the user ID expiration date set to "December 31, 2030."
[0080] (Registration of a new supplier user by a user of the operating company) Next, the operation of registering a new supplier user by a user of the operating company in the management device 1 of such an operating company will be described with reference to the flowchart of Fig. 16. Each process in the flowchart of Fig. 16 is executed by the control unit 3 of the management device 1 based on the management program stored in the memory unit 2.
[0081] That is, a user of the operating company who registers a new supplier user makes a login request to the management device 1 via the administrator terminal device. This starts the flowchart in Fig. 16, but the operations of steps S1 to S3 up to the point where it is determined whether the user expiration date has expired based on the user ID entered on the login screen are the same as the operations of steps S1 to S3 in the flowchart in Fig. 13. Therefore, for a detailed explanation of the operations of steps S1 to S3, please refer to the explanation of the operations of steps S1 to S3 in the flowchart in Fig. 13.
[0082] Next, if it is determined in step S3 that the user ID has not expired (step S3: No), the process proceeds to step S11 in the flowchart of Fig. 16. In step S11, the determination unit 24 determines whether or not there is a request from a user of the operating company to launch the operating company's business partner user master maintenance screen, as exemplified in Fig. 17(a).
[0083] When a request to launch the operating company customer user master maintenance screen is detected (step S11: Yes), the discrimination unit 24 refers to the WebEDI user master 14 based on the user ID in step S5, and determines whether the user is a user in the user group of the "operating company administrator" who has the authority to register new users. If the user is not a user in the user group of the "operating company administrator" (step S5: No), the user does not have the authority to register a user, and the processing of the flowchart in Figure 16 ends.
[0084] If the user is a user of the user group of the "operating company administrator" (step S5: Yes), the process proceeds to step S12. In step S12, the display screen generation unit 26 generates the operating company business partner user master maintenance screen exemplified in Fig. 17(a), and the communication control unit 21 transmits this operating company business partner user master maintenance screen to the administrator terminal device.
[0085] As shown in Figure 17(b), the user of the administrator terminal device selects a business partner classification such as "Supplier" based on the business partner user master maintenance screen for the operating company. Furthermore, as shown in Figure 17(c), the user of the administrator terminal device inputs a business partner name such as "Company Y" based on the business partner user master maintenance screen for the operating company. Furthermore, as shown in Figure 17(d), the user of the administrator terminal device inputs a user group, user ID, user name, initial password, and user ID expiration date based on the business partner user master maintenance screen for the operating company, and performs a registration operation.
[0086] As a result, the information entered via the operating company's supplier user master maintenance screen, including supplier classification, supplier, user group, user ID, user name, initial password, and user ID expiration date, is sent from the administrator terminal device to the management device 1, and a registration request is made. When this registration request is received by the management device 1, the determination unit 24 of the management device 1 determines that a registration operation has been performed (step S13: Yes). Then, in step S14, the determination unit 24 references the WebEDI supplier master 12 shown in FIG. 18(a) and detects the upper limit of the number of users for the entered supplier. In the example of FIG. 18(a), the upper limit of the number of users is set to "10 people."
[0087] The discrimination unit 24 also detects the current number of valid users of the business partner currently attempting to register a new user by referring to the WebEDI user master 14 shown in Figure 18(b). The example in Figure 18(b) shows that the business partner currently attempting to register a new user is Company Y, and that Company Y currently has three valid users.
[0088] In this example, the upper limit for the number of users at Company Y is "10," and the current number of valid users is "3." Therefore, even if a new user is registered, the upper limit for the number of users at Company Y will not be exceeded. Therefore, the determination unit 24 determines that the upper limit for the number of users will not be exceeded (step S14: No). As a result, the data generation unit 23 generates detailed data (records) for the WebEDI user master 14, including the customer classification, customer, user group, user ID, user name, initial password, and user ID expiration date received from the administrator terminal device.
[0089] As will be described later, if registering a new user would exceed the upper limit of the number of users set for the business partner (step S14: Yes), the display screen generation unit 26 generates an operating company business partner user master maintenance screen displaying an error message such as "Users cannot be added beyond the upper limit of users," as shown in FIG. 23(a). The communication control unit 21 then transmits the operating company business partner user master maintenance screen displaying this error message to the operator terminal device. This allows the user of the operator terminal device to recognize that no more new users can be registered, and they will delete unnecessary users or increase the upper limit of the number of users.
[0090] Next, in step S9, the storage control unit 25 adds and stores the detailed data (records) generated by the data generation unit 23 in the WebEDI user master 14 as shown in Fig. 18(c). As a result, for example, a user with a user ID of "YJT99" and a user name of "Y Company Actual Worker YJT99" is newly registered in the user group of "Supplier Actual Worker" of Y Company, with the user ID expiration date set to "December 31, 2030."
[0091] (Customer registration of new users) Next, the operation of the management device 1 when a supplier company, which is an example of a business partner, registers a new user for its company will be described using the flowchart in Fig. 19. Each process in the flowchart in Fig. 19 is executed by the control unit 3 of the management device 1 based on the management program stored in the storage unit 2. That is, a user of the supplier company registering a new user makes a login request to the management device 1 via the supplier terminal device 200. This starts the flowchart in Fig. 19, and the processes are executed in order from step S21.
[0092] In step S21, the display screen generation unit 26 of the management device 1 generates a login screen as shown in FIG. 20(a). The communication control unit 21 transmits this login screen to the supplier terminal device 200 of the user of the supplier company who made the login request. The user of the supplier company who made the login request inputs a user ID and password into the login screen displayed on the display screen of the supplier terminal device 200. The input user ID and password are transmitted to the management device 1.
[0093] The determination unit 24 of the management device 1 refers to the user ID expiration date in the WebEDI user master 14 shown in Fig. 20(b) based on the user ID entered via the login screen (step S22). The determination unit 24 then determines whether the user ID of the entered supplier company user has expired by determining whether today's date is past the date set as the user ID expiration date (step S23). If the determination unit 24 determines that the entered user ID has expired (step S23: Yes), the user of the supplier company does not have the authority to register as a user, and the processing of the flowchart in Fig. 19 ends immediately.
[0094] On the other hand, if it is determined that the entered user ID is within the expiration date (step S23: No), the discrimination unit 24 determines whether or not there is a request to launch the supplier user master maintenance screen for the supplier (step S24). If a request to launch the supplier user master maintenance screen for the supplier is detected (step S24: Yes), the discrimination unit 24 determines in step S25 based on the user ID by referring to the WebEDI user master 14 shown in FIG. 20(c) whether the user of the supplier company is a user of the "supplier manager" user group, which has the authority to register new users. If the user is not a user of the "supplier manager" user group (step S25: No), the user of the supplier company does not have the authority to register a user, and the processing of the flowchart in FIG. 19 ends.
[0095] If the user is in the "Supplier Manager" user group (Step S25: Yes), the process proceeds to Step S26. In Step S26, the discrimination unit 24 references the WebEDI customer master 12 shown in FIG. 21(a) and confirms that the status information for the supplier, Company Y, is "valid." The discrimination unit 24 also references the WebEDI user group master 13 shown in FIG. 21(b) to identify a user group whose customer classification is the same as that of the logged-in user, "Supplier," and who can manage the customer. In the example of FIG. 21(b), the discrimination unit 24 identifies the user group of "Supplier Worker" as a user group for which user registration is permitted.
[0096] Next, in step S27, the display screen generation unit 26 generates a supplier user master maintenance screen for the supplier, as illustrated in Figure 21 (c), and the communication control unit 21 transmits this supplier user master maintenance screen for the supplier to the supplier terminal device 200.
[0097] The supplier manager of the supplier terminal device 200 selects the user group of "supplier actual worker" who is permitted to register users based on the supplier user master maintenance screen for suppliers shown in Fig. 21(c). The supplier manager of the supplier terminal device 200 also performs the registration operation by entering the user ID, user name, initial password, and user ID expiration date of the user to be newly registered on the supplier user master maintenance screen for suppliers shown in Fig. 21(c).
[0098] As a result, the information on the user group, user ID, user name, initial password, and user ID expiration date entered via the supplier user master maintenance screen for the supplier is sent from the supplier terminal device 200 to the management device 1, and a registration request is made. When this registration request is received by the management device 1, the determination unit 24 of the management device 1 determines that a registration operation has been performed (step S28: Yes), and the process proceeds to step S29.
[0099] In step S29, the discrimination unit 24 refers to the WebEDI master 12 shown in Fig. 22(a) and detects the "user limit" of the company currently being registered as a user. In this example, the discrimination unit 24 detects that the user limit for Company Y, a supplier being registered as a new user, is "10 people," as shown in Fig. 22(a).
[0100] Furthermore, the discrimination unit 24 refers to the WebEDI user master shown in Fig. 22(b) and detects the current number of valid users for the supplier who is the target of new user registration. In the example of Fig. 22(b), the discrimination unit 24 detects that the current number of valid users for Company Y, the supplier who is the target of new user registration, is "3".
[0101] In step S29, the determination unit 24 determines whether the number of valid users will exceed the user upper limit if a new user is registered. If the new user registration would cause the number of valid users to exceed the user upper limit (step S29: Yes), the number of registered users will exceed the specified number. Therefore, the display screen generation unit 26 generates a supplier user master maintenance screen for the supplier, displaying an error message such as "Users cannot be added beyond the user upper limit," as shown in FIG. 23(a). The display screen generation unit 26 then transmits the screen to the supplier terminal device 200, terminating the processing of the flowchart in FIG. 19. In this case, the supplier representative in the supplier terminal device 200 recognizes that no more new users can be registered and requests the operating company to delete unnecessary users or to increase the user upper limit. Upon receiving such a request, the operating company increases the user upper limit in the WebEDI master 12. This allows the supplier representative to register new users.
[0102] On the other hand, if the number of valid users does not exceed the user upper limit (step S29: No), the data generation unit 23 of the management device 1 generates detail data (record) of the WebEDI user master 14 including the user group, user ID, user name, initial password, and user ID expiration date received from the supplier terminal device 200.
[0103] In step S30, the storage control unit 25 adds and stores the detailed data (records) generated by the data generation unit 23 in the WebEDI user master 14 as shown in Fig. 23(b). As a result, for example, a user with a user ID of "YJT99" and a user name of "Company Y actual worker YJT99" is newly registered in the user group of "Supplier actual worker" of Company Y, which is a supplier, with the user ID expiration date set to "December 31, 2030."
[0104] (Invalid behavior of business partner) Next, the operation of the operating company administrator changing the status of a business partner to "invalid" to collectively disable all users of that business partner will be described using the flowchart in Fig. 24. Each process in the flowchart in Fig. 24 is executed by the control unit 3 of the management device 1 based on the management program stored in the memory unit 2.
[0105] That is, a user who wants to change the status of a business partner to "invalid" makes a login request to the management device 1 via the administrator terminal device. This starts the flowchart in Fig. 24, but the operations of steps S1 to S3 up to the point where it is determined whether the user expiration date has expired based on the user ID entered on the login screen are the same as the operations of steps S1 to S3 in the flowchart in Fig. 13. Therefore, for a detailed explanation of the operations of steps S1 to S3, please refer to the explanation of the operations of steps S1 to S3 in the flowchart in Fig. 13.
[0106] Next, when it is determined that the user ID expiration date is within the expiration date (step S3: Yes), the process proceeds to step S11, where display screen generation unit 26 determines whether or not there is a request from the administrator terminal device to launch the supplier master maintenance screen shown in Fig. 9. Then, when a request to launch the supplier master maintenance screen is made from the administrator terminal device (step S11: Yes), determination unit 24 determines in step S5, based on the user ID at the time of the login request, whether the user currently requesting the launch of the supplier master maintenance screen is a user in the user group of the "operating company administrator."
[0107] If the user currently requesting the launch of the customer master maintenance screen is not a user in the "operating company administrator" user group (step S5: No), the user does not have the authority to change the customer status to "invalid," and the processing of the flowchart in Figure 24 ends.
[0108] On the other hand, if the user currently requesting the launch of the customer master maintenance screen is a user of the "operating company administrator" user group (step S5: Yes), the display screen generation unit 26 generates the customer master maintenance screen illustrated in FIG. 9, and the communication control unit 21 transmits this customer master maintenance screen to the administrator terminal device (step S12).
[0109] The "operating company administrator" user specifies a supplier classification, supplier name, and user limit based on the supplier master maintenance screen illustrated in FIG. 9, and sets the status to "invalid." In step S41 of the flowchart in FIG. 24, status setting unit 27 determines whether or not such an invalid operation has been performed. If status setting unit 27 detects an invalid operation (step S41: Yes), in step S42 it generates status information that sets the status of the supplier specified on the supplier master maintenance screen to "invalid" (= sets the supplier status to "invalid").
[0110] When the status information of "invalid" is generated, the storage control unit 25 updates the status information of, for example, Company X, which was a supplier, to "invalid" as shown in Figure 25(a). This restricts Company X's use of the EDI system.
[0111] At the same time, in step S43, the status setting unit 27 generates a user ID expiration date with the expiration date as the user ID expiration date for all users belonging to all user groups of the business partner X company whose status information has been set to "invalid." The storage control unit 25 inputs the generated user ID expiration date with the expiration date as the user ID expiration date for all users of all user groups of X company, as shown in FIG. 25(b).
[0112] This allows the user ID expiration dates of all users in all user groups of Company X whose status has been set to "invalid" to be updated to expired all at once, thereby restricting their use of the EDI system. Even if the operating company invalidates transactions with a trading partner, if each user belonging to the trading partner is not invalidated, users who should not be able to use the EDI system may continue to be able to use it, which is an inconvenience. However, the management device 1 of the embodiment prevents such inconvenience and restricts the use of the EDI system by each user of the trading partner who has been set to "invalid."
[0113] (Problems caused by user ID expiration being overlooked) If the user information of a user who has been transferred or retired is still stored in the storage unit 2 in a valid state, there is a concern that the user who has been transferred or retired may log in to the EDI system using a user account that remains valid and perform fraudulent acts such as illegally obtaining data, which is not desirable from a security standpoint.
[0114] In particular, when the level of user management operations at the business partner to which user management authority is entrusted is low, as described above, such security problems become more pronounced. For this reason, the management device 1 of the embodiment manages the period during which each user has legitimate user authority based on the user ID expiration date information included in the user information of each user, and issues an expiration warning a predetermined number of days before the date on which the legitimate user authority expires. The administrator registers an expiration date extension for users who will continue to be able to use the EDI system.
[0115] This allows users who have registered an extension of the expiration date to continue using the EDI system, while users who have not registered an extension of the expiration date can be disabled from using the EDI system after the expiration date. This helps maintain the security of the EDI system and eliminates the need for cumbersome tasks such as periodically inspecting users registered in the EDI system to determine whether they are using the system legitimately.
[0116] (Action to warn the operating company administrator about users of the operating company or business partners whose expiration dates are about to expire) A specific example will be described below. The flowchart in Fig. 26 is a flow chart showing the flow of operations for detecting a user of the operating company or a business partner whose validity period is about to expire and sending a warning to the administrator of the operating company when the administrator of the operating company logs in to the management device 1. The control unit 3 of the management device 1 operates based on the management program stored in the memory unit 2, thereby executing the processing of the flowchart in Fig. 26.
[0117] That is, when an administrator of the operating company makes a login request via the administrator terminal device, the display screen generation unit 26 of the management device 1 generates a login screen as shown in FIG. 27, and the communication control unit 21 transmits it to the administrator terminal device. The administrator of the operating company inputs a user ID and password into the login screen displayed on the administrator terminal device and transmits it to the management device 1. As a result, the control unit 3 of the management device 1 performs user authentication processing based on the input user ID and password. If this user authentication processing authenticates that the user making the login request is a legitimate user (in this example, the administrator of the operating company), the flowchart of FIG. 26 starts.
[0118] In step S51, the notification control unit 28 detects the user ID expiration dates of all users of the operating company and business partners stored in the WebEDI user master 14 shown in FIG. 7. Then, in step S52, the notification control unit 28 determines whether there are any users whose expiration dates are approaching (whether there are any users who fall within the expiration warning period). The warning period is set, for example, from 30 days before the expiration date to the expiration date. Therefore, the notification control unit 28 determines whether there are any users whose user ID expiration dates fall within the warning period. If there are no users whose user ID expiration dates fall within the warning period, the processing of the flowchart in FIG. 26 ends.
[0119] If there is a user whose user ID expiration date falls within the warning period, the notification control unit 28 generates a menu screen displaying a predetermined warning message (a message urging the user whose expiration date is about to expire) via the display screen generation unit 26 in step S53, as shown in FIG. 28, and transmits the generated menu screen to the administrator terminal device via the communication control unit 21. As an example, the menu screen shown in FIG. 28 includes selection items such as order entry, order inquiry, and user maintenance. In step S53, a warning message such as "Among the users belonging to Company A, there is one user whose expiration date is approaching. Please check the user master maintenance menu" is displayed on this menu screen.
[0120] When checking users whose expiration dates are approaching, the administrator of the operating company selects the user master maintenance selection item on the menu screen shown in Fig. 28. As a result, selection data indicating that the user master maintenance selection item on the menu screen has been selected is transmitted from the administrator terminal device to the management device 1. The notification control unit 28 of the management device 1 monitors whether or not this selection data exists, thereby determining whether or not the user master maintenance selection item has been selected (step S54). If the user master maintenance selection item has not been selected (step S54: No), the process of the flowchart in Fig. 26 ends.
[0121] If the user master maintenance selection item is selected (step S54: Yes), the notification control unit 28 displays a list of all users of the operating company and all users of each business partner on the administrator terminal device, and displays the details (records) of users whose expiration dates are about to expire in a predetermined display format indicating that the expiration dates are about to expire, and also displays them with a predetermined icon (step S55).
[0122] In this example, the notification control unit 28 displays the list, but more precisely, the notification control unit 28 generates a list screen via the display screen generation unit 26 and transmits this list screen to the administrator terminal device via the communication control unit 21, thereby displaying the list screen on the administrator terminal device. Hereinafter, such detailed explanation will be omitted, but the statement "the notification control unit 28 displays a screen" should be understood to include the screen generation operation in the display screen generation unit 26 and the transmission operation by the communication control unit 21.
[0123] Fig. 29 is an example of a list displaying all users of XXX Corporation. The notification control unit 28 may display a list of all users of the operating company and each business partner, or, as shown in Fig. 29, it is also possible to specify a business partner company and display only the users of the business partner. As shown in Fig. 29, the list screen displays each user's "status," "user group," "business partner," user ID, user name, "warning status," and "user ID expiration date (expiration date)."
[0124] On this list screen, the notification control unit 28 determines and displays the "status" based on the expiration date of each user, and if today's date is equal to or less than the expiration date, it displays "valid," and if today's date is greater than the expiration date, it displays "expired." Also, "warning" is information indicating whether issuing an expiration warning is "enabled" or "disabled." In the example of FIG. 29, all users are set to "enabled," which indicates that expiration warnings will be issued.
[0125] 29, the expiration date for a user with user ID "X004" and user name "Person in Charge R" is "March 31, 2022." If the date on which this list screen was displayed (= the date on which the administrator of the operating company logged in) was "March 1, 2022" and the warning period described above was set to "30 days," the warning period for this user "Person in Charge R" would include the date on which the administrator of the operating company logged in.
[0126] For this reason, as shown in FIG. 29, the notification control unit 28 displays the expiration date display field or text for the user "person in charge R" in a different display format from the expiration date display fields for other users, for example, by displaying it in red or yellow. Furthermore, the notification control unit 28 displays a predetermined icon indicating that the expiration date is approaching in the expiration date display field for the user "person in charge R." The example in FIG. 29 is an example in which an icon with an "!" inside a triangle mark is displayed. The administrator of the operating company recognizes users whose expiration date display field has an icon displayed in this manner as users whose expiration date is approaching.
[0127] In this example, the display field for the expiration date of a user whose expiration date is approaching is displayed in a different format from the others and a specified icon is attached to issue a warning, but the warning may also be issued by displaying a specified message, or by an electronic sound or voice message.
[0128] Next, the administrator of the operating company issues a display instruction operation for the user master detail screen in order to extend the expiration date of the user for whom such a warning has been issued or to invalidate the warning. As an example, in the case of the management device 1, the desired user can be specified and the user master detail screen can be displayed by double-clicking the details (record) of the desired user among the users on the list screen shown in FIG. 29 . In this case, the administrator of the operating company double-clicks the details (record) of the user for whom the warning has been issued. In step S56 of the flowchart in FIG. 26 , the notification control unit 28 determines whether or not such a display instruction operation for the user master detail screen has been issued. Then, upon detecting the display instruction operation for the user master detail screen (step S56: Yes), the notification control unit 28 generates a user master detail screen via the display screen generation unit 26 and transmits it to the administrator terminal device of the operating company via the communication control unit 21. As a result, the user master detail screen illustrated in FIG. 30 is displayed on the administrator terminal device (step S57).
[0129] The user master details screen displays the user group name, user ID, user name, and user ID expiration date (expiration date) as shown in Fig. 30. In this example, since the user master details screen is for a user whose expiration date is approaching, the expiration date display field is displayed in red or yellow text, for example, as described above, and a specified icon is added.
[0130] The notification control unit 28 also controls the display of a warning disable selection object for specifying whether or not to disable a warning, i.e., whether or not the warning will be unnecessary in the future, on the user master detail screen via the display screen generation unit 26. As an example, the warning disable selection object displays the words "Disable warning" and a check box.
[0131] Next, when setting an extension of the expiration date based on such a user master detail screen, the administrator of the operating company inputs the extended expiration date, for example, "March 31, 2023," into the expiration date display field as shown in FIG. 31(a). In step S58 of the flowchart in FIG. 26, the notification control unit 28 determines whether or not such an extension of the expiration date has been set. If an extension of the expiration date is detected (step S58: Yes), the process proceeds to step S59.
[0132] If it were possible to register a long-term expiration date, such as a date 100 years in the future, it would make security management of the EDI system difficult. For this reason, in the management device 1 of the embodiment, an upper limit value (maximum expiration date) for the expiration date that can be entered, such as "365 days," is predetermined. In step S59, the notification control unit 28 determines whether the entered expiration date is a date after "today's date + maximum user validity period." In other words, in step S59, the notification control unit 28 determines whether the entered expiration date exceeds the maximum expiration date.
[0133] If the entered expiration date exceeds the maximum expiration date (step S59: Yes), in step S63, the notification control unit 28 displays an error message such as "The user ID expiration date has exceeded the set upper limit (maximum user ID expiration date: 365 days)," as illustrated in FIG. 32.
[0134] On the other hand, if the input expiration date is within the maximum expiration date (step S59: No), in step S60, the notification control unit 28 updates and displays the details (record) of the user whose expiration date has been extended on the list screen (see FIG. 29) based on the input expiration date, as shown in FIG. 31(b). In this example, the expiration date of the user with user ID "X004" and user name "Person in Charge R" is updated to "March 31, 2023" and displayed. Furthermore, when the expiration date is extended in this manner, the storage control unit 28 updates and stores the user ID expiration date in the WebEDI user master 14 to the extended date, "March 31, 2023," as shown in FIG. 31(c).
[0135] Furthermore, if the entered expiration date is outside the warning period (step S59: No), the notification control unit 28 hides the text "Disable warning" and the warning disable selection object, which is a check box, as shown in Fig. 31(a). This prevents the user from accidentally checking the check box of the warning disable selection object while the warning disable selection object continues to be displayed even after the expiration date extension is registered, which can result in the user not being warned about the expiration date thereafter.
[0136] On the other hand, if the administrator of the operating company looks at the list screen shown in Fig. 29 and determines that the user who is being warned that the expiration date is approaching is a user who can be allowed to expire as is, he or she performs an input operation to check the check box of the warning invalidation selection object without inputting an extension of the expiration date, as shown in Fig. 33(a). When the input operation to check the check box of this warning invalidation selection object is performed, the process proceeds to step S62 via step S58 and step S61.
[0137] In step S62, the notification control unit 28 updates the "Warning" input field of the details (record) of the user who has checked the checkbox of the warning invalidation selection object on the list screen (see FIG. 29) from "Valid" to "Invalid" and displays it, as shown in the example of FIG. 33(b). This allows the administrator of the operating company to recognize through the list screen that the expired warning for the user who has checked the checkbox of the warning invalidation selection object will be invalid thereafter.
[0138] Additionally, the WebEDI user master 14 stores a warning disable flag along with the user ID expiration date, etc. This warning disable flag is information that indicates whether to disable the expiration warning (=do not issue a warning=TRUE) or whether to not disable the expiration warning (=issue a warning=FALSE). The default setting for this warning disable flag is "FALSE," which means that the expiration warning is not disabled and is issued.
[0139] Therefore, when an input operation to check the checkbox of the warning invalidation selection object is performed, the storage control unit 23 updates the warning invalidation flag for that user from "FALSE" to "TRUE" as shown in Fig. 33(c) in step S62, and stores this in the WebEDI user master 14. As a result, from this point on, warnings of the approaching expiration date will not be issued to this user, and the authority to use the EDI system will expire on the preset expiration date.
[0140] (Action to warn the operating company administrator about users whose validity has expired at the operating company or business partner) The above example was an example of issuing a warning to users whose licenses are about to expire, but the following example is an example of issuing a warning to indicate the existence of users whose licenses have actually expired as the expiration date passes. The flowchart in Figure 34 shows the flow of such operations. The control unit 3 of the management device 1 operates based on the management program stored in the memory unit 2, thereby executing the processing of the flowchart in Figure 34.
[0141] In the flowchart of Figure 34, when an administrator of the operating company makes a login request via the administrator terminal device, user authentication processing is performed based on the user ID and password entered via the login screen illustrated in Figure 27 as described above, and processing proceeds to step S71.
[0142] In step S71, the notification control unit 28 detects the expiration dates of the user IDs of all users of the operating company and trading companies stored in the WebEDI user master 14 shown in Fig. 7. Then, in step S72, the notification control unit 28 compares the login date with the expiration date of the user ID of each user to determine whether or not there are any users whose expiration dates have expired. If there are no users whose expiration dates have expired (step S72: No), the processing of the flowchart in Fig. 34 ends.
[0143] If there is a user whose expiration date has expired (step S72: Yes), in step S73, the notification control unit 28 displays a menu screen on the administrator terminal device showing a predetermined warning message (a message prompting the user to check for expired users) as shown in Fig. 35. Fig. 35 is an example in which a warning message saying "Among the users belonging to Company C, one user has expired. Please check the user master maintenance menu" is displayed on the menu screen.
[0144] When the administrator of the operating company checks for users whose expiration dates have expired, the administrator selects the user master maintenance option on the menu screen shown in Fig. 35. As a result, in step S74, the notification control unit 28 of the management device 1 monitors whether or not the user master maintenance option has been selected. If the user master maintenance option has not been selected (step S74: No), the processing of the flowchart in Fig. 34 ends.
[0145] If the user master maintenance selection item is selected (step S74: Yes), the notification control unit 28 displays a list of all users of the operating company and all users of each business partner on the administrator terminal device, and displays the details (records) of expired users in a predetermined display format indicating that they have expired, and also displays them with a predetermined icon (step S75).
[0146] Fig. 36 is an example of a list displaying all users of XXX Corporation. The notification control unit 28 may display a list of all users of the operating company and each business partner, or as shown in Fig. 36, it is also possible to specify a business partner company and display only the users of the business partner. As shown in Fig. 36, the list screen displays each user's "status," "user group," "business partner," "user ID," "user name," "warning status," and "user ID expiration date (expiration date)."
[0147] On this list screen, the notification control unit 28 determines and displays the "status" based on the expiration date of each user, and if today's date is equal to or less than the expiration date, it displays "valid," and if today's date is greater than the expiration date, it displays "expired." Also, "warning" is information indicating whether issuing an expiration warning is "enabled" or "disabled." In the example of FIG. 36, all users are displayed as "enabled," indicating that they are subject to expiration warnings.
[0148] Also, in Figure 36, the user with user ID "X003" and user name "Person in Charge Q" is about to expire, so a warning is displayed using the display format and icon described above to indicate that the expiration date is about to expire.
[0149] Also, if the login date is "April 1, 2022," the expiration date for the user with user ID "X004" and username "Person in Charge R" is "March 31, 2022," and therefore the expiration date has expired. Therefore, the notification control unit 28 displays "Expired" as the "Status" because today's date is greater than the expiration date.
[0150] Furthermore, as shown in FIG. 36, the notification control unit 28 displays the display field or text of the expiration date of the user "Person in Charge R" in a display format using a color that is different from the display fields of the expiration dates of other users, such as red or yellow, and that is different from the color used in the warning to the user whose expiration date is about to expire. Furthermore, the notification control unit 28 displays an icon in the display field of the expiration date of the user "Person in Charge R" indicating that the expiration date has expired, and that is different from the icon used in the warning to the user whose expiration date is about to expire. The example in FIG. 36 is an example in which the expiration date is displayed with an icon marked with an X. The administrator of the operating company recognizes a user whose expiration date display field has an icon in this display format as a user whose expiration date has expired.
[0151] In this example, the above-mentioned display format and icon are used to warn of the presence of a user whose expiration date has expired, but the warning may also be given by displaying a message, or by using an electronic sound or voice message.
[0152] Next, the administrator of the operating company issues a display instruction to the user master detail screen in order to extend the expiration date of the user for whom such a warning has been issued or to invalidate the warning. As described above, in the case of the management device 1, the desired user is designated and the user master detail screen is displayed by double-clicking the details (record) of the desired user among the users on the list screen shown in FIG. 36. In this case, the administrator of the operating company double-clicks the details (record) of the user "Person in Charge R" whose expiration date has expired. In step S76 of the flowchart in FIG. 34, the notification control unit 28 determines whether or not such a display instruction to the user master detail screen has been issued. Then, when the display instruction to the user master detail screen is detected (step S76: Yes), the notification control unit 28 displays the user master detail screen illustrated in FIG. 37 on the administrator terminal device (step S77).
[0153] The user master details screen displays the user group name, user ID, user name, and user ID expiration date (expiration date) as shown in Figure 37. In this example, since this is the user master details screen for an expired user, the expiration date display field displays the expired date in characters in a display format indicating expiration, with a specified icon such as "x" added.
[0154] The notification control unit 28 also controls the display of a warning disable selection object for specifying whether or not such expired warnings will be unnecessary in the future on the user master detail screen via the display screen generation unit 26. As an example, the warning disable selection object displays the words "Disable warning" and a check box.
[0155] Next, when setting an extension of the expiration date based on such a user master detail screen, the administrator of the operating company inputs the extended expiration date, for example, "March 31, 2023," into the expiration date display field as shown in Fig. 38(a). In step S78 of the flowchart in Fig. 34, the notification control unit 28 determines whether or not such an extension of the expiration date has been set. If an extension of the expiration date is detected (step S78: Yes), the process proceeds to step S79.
[0156] In step S79, as explained in step S59 above, the notification control unit 28 determines whether the input expiration date is set to exceed the maximum expiration date. If the input expiration date exceeds the maximum expiration date (step S79: Yes), the notification control unit 28 displays an error message in step S83, such as "The user ID expiration date has exceeded the upper limit set (maximum number of days for user ID expiration date: 365 days)," as shown in FIG.
[0157] On the other hand, if the entered expiration date is within the maximum expiration date (step S79: No), in step S80, the notification control unit 28 updates and displays the details (record) of the user whose expiration date has been extended on the list screen (see FIG. 36) based on the entered expiration date, as shown in FIG. 38(b). The example in FIG. 38(b) is an example in which the expiration date of a user with a user ID of "X004" and a user name of "Person in Charge R" is updated to "March 31, 2023" and displayed. In addition, the notification control unit 28 updates the "status" of the user "Person in Charge R" from "Expired" to "Valid" and displays it on the list screen. When the expiration date is extended in this way, the storage control unit 28 updates and stores the user ID expiration date in the WebEDI user master 14 to the extended date, "March 31, 2023," as shown in FIG. 38(c).
[0158] Furthermore, if the entered expiration date is outside the warning period (step S79: No), the notification control unit 28 hides the text "Disable warning" and the warning disable selection object, which is a check box, as shown in Fig. 38(a). This prevents the user from accidentally checking the check box of the warning disable selection object while the warning disable selection object continues to be displayed even after the expiration date extension is registered, which can result in the user not being warned about the expiration date thereafter.
[0159] On the other hand, if the administrator of the operating company looks at the list screen shown in Fig. 36 and determines that the user who is being warned about the expiration date is a user who can be allowed to let the expiration date expire as is, he or she performs an input operation to check the check box of the warning invalidation selection object without inputting an extension of the expiration date, as shown in Fig. 39(a). When the input operation to check the check box of this warning invalidation selection object is performed, the process proceeds to step S82 via step S78 and step S81.
[0160] In step S82, the notification control unit 28 updates the "Warning" input field of the details (record) of the user who has checked the checkbox of the warning invalidation selection object on the list screen (see FIG. 36) from "Valid" to "Invalid" and displays it, as shown in the example of FIG. 39(b). This allows the administrator of the operating company to recognize through the list screen that the expired warning for the user who has checked the checkbox of the warning invalidation selection object will be invalid thereafter.
[0161] Furthermore, when an input operation to check the checkbox of the warning invalidation selection object is performed, the storage control unit 23 updates the warning invalidation flag for that user from "FALSE" to "TRUE (no warning)" as shown in Fig. 33(c) in step S82, and stores this in the WebEDI user master 14. As a result, from this point on, warnings of expiration will not be issued to this user, and the authority to use the EDI system will expire on the preset expiration date.
[0162] (Warning pattern type) Next, in a normal system, it is preferable to manage users according to the same policy for all users. However, in an EDI system, since the presence or absence of entrustment of user management authority and the business relationship differ for each trading partner, it is preferable to manage users according to different policies for each trading partner. This is a major difference between a normal system and an EDI system. For this reason, the management device 1 of the embodiment is capable of selecting and setting warning pattern 0 to warning pattern 4, which will be described below, for each operating company or trading partner. This allows a warning notifier (=user to notify a warning) to be set for each operating company or trading partner, and makes it possible to issue warnings to users whose expiration dates are about to expire or whose expiration dates have expired.
[0163] Warning pattern information indicating the set warning pattern is stored in the storage unit 2. The notification control unit 28 issues the above-mentioned warning at a predetermined timing using the warning pattern indicated by the warning pattern information stored in the storage unit 2.
[0164] (Warning pattern 0) First, "warning pattern 0" is a warning pattern that warns a logged-in user when the expiration date of the log-in user is approaching. When this warning pattern 0 is set, when a user whose expiration date is about to expire logs in, the notification control unit 28 warns the user that the expiration date is about to expire, for example, "The user's expiration date is about to expire. Please contact the administrator. Expiration date: {year / month / day}."
[0165] When warning pattern 0 is set, the notification control unit 28 issues a warning to all users, regardless of whether they are an administrator or a person in charge. Also, when warning pattern 0 is set, a user whose account has expired cannot log in, so the notification control unit 28 does not issue the above-mentioned warning.
[0166] (Warning pattern 1) Next, "Warning Pattern 1" is a warning pattern that warns the administrator of the operating company when there is a warning target among the users of the operating company, as shown in Fig. 40. In this case, the notification control unit 28 also targets the administrator himself as a warning target. In other words, when warning pattern 1 is set, the notification control unit 28 warns the administrator and all users of the operating company that the expiration date is approaching or has expired.
[0167] (Warning pattern 2) Next, "Warning Pattern 2", as shown in FIG. 41, is a warning pattern in which a warning is issued to the manager of a business partner, for example, if there is a person to be warned among the manager and person in charge of the business partner, such as a customer. In this warning pattern 2, the notification control unit 28 also targets the manager himself as a warning target. FIG. 41 shows an example in which there are two people to be warned within customer company A. In this case, the notification control unit 28 notifies the terminal device of the manager of company A with a warning message, for example, "Among the users belonging to company A, there are two users whose expiration date is approaching. Please check the user master maintenance."
[0168] 41 shows an example in which there are three people who need to be warned within a client company, Company B. In this case, the notification control unit 28 notifies the terminal device of the administrator of Company B of a warning message such as, for example, "Among the users belonging to Company B, there are three users whose expiration dates are approaching. Please check the user master maintenance." (Warning pattern 3) Next, "Warning Pattern 3," as shown in FIG. 42, is a warning pattern in which, for example, the operating company manages all personnel in charge of business partners such as suppliers, and if there is a person who is a warning target among the personnel of the business partners, a warning is issued to the administrator of the operating company. FIG. 42 shows an example in which there are three people who are a warning target within supplier company C. In this case, the notification control unit 28 notifies the administrator terminal device of the operating company with a warning message, for example, "Among the users belonging to company C, there are three users whose expiration date is approaching. Please check the user master maintenance."
[0169] (Warning pattern 4) Next, "Warning Pattern 4" is a warning pattern in which, as shown in FIG. 43, if there are warning recipients among the administrators and personnel of a company that is the destination, a warning is issued to both the administrator of the destination and the administrator of the operating company. FIG. 43 shows an example in which there are three warning recipients within company C that is the destination. In this case, the notification control unit 28 notifies the administrator terminal device of the administrator of the operating company and the administrator of company C of a warning message that reads, for example, "Among the users belonging to company C, there are three users whose expiration date is approaching. Please check the user master maintenance."
[0170] (Warning pattern 0 warning behavior) Next, the warning operation for each warning pattern will be described. First, Fig. 44 is a flowchart showing the flow of the warning operation for warning pattern 0, which warns a logged-in user when the expiration date of the logged-in user is approaching. The control unit 3 of the management device 1 controls the execution of the warning operation of the flowchart in Fig. 44 based on the management program stored in the memory unit 2. That is, the flowchart in Fig. 44 starts when the control unit 3 recognizes that "warning pattern 0" is set in the warning pattern information stored in the memory unit 2, and processing is executed from step S91.
[0171] In step S91, the notification control unit 28 refers to the WebEDI user master 14 shown in Fig. 47 based on the user ID entered on the login screen shown in Fig. 27 at the time of login, and detects the expiration date and warning invalidation flag attached to that user. Also, in step S92, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 based on the user ID, and detects the warning period set for the user group to which the logged-in user belongs.
[0172] In step S93, the notification control unit 28 determines whether the following conditions are met.
[0173] Condition = "Disable warnings FLG" = "FALSE" and "Expiration Date" ≠ "NULL" and "Expiration date" ≤ "Today's date" + "Warning period set for the user group to which the user belongs"
[0174] If this condition is met, the notification control unit 28 notifies the logged-in user in step S94 of a warning indicating that the expiration date is approaching (=notification of warning pattern 0).
[0175] (Warning pattern 1 warning action) Next, Fig. 45 is a flowchart showing the flow of the warning operation of warning pattern 1, which warns the administrator of the operating company when there is a warning target among the operating company users. The control unit 3 of the management device 1 controls the execution of the warning operation of the flowchart in Fig. 45 based on the management program stored in the memory unit 2. That is, the flowchart in Fig. 45 starts when the control unit 3 recognizes that "warning pattern 1" is set in the warning pattern information stored in the memory unit 2, and processing is executed from step S101.
[0176] In step S101, the notification control unit 28 refers to the WebEDI user master 14 shown in Fig. 47 based on the user ID entered on the login screen shown in Fig. 27 at the time of login, and acquires the details (records) of that user. In addition, in step S102, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 based on the user ID, and acquires the details (records) of each user in the user group to which the logged-in user belongs.
[0177] In step S103, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 and determines whether the affiliated user warning target flag set for the user group to which the logged-in user belongs is "FALSE." If the affiliated user warning target flag is "FALSE" (step S103: Yes), this means that the user group to which the logged-in user belongs is not subject to a warning, and the processing of the flowchart in Fig. 45 is terminated.
[0178] On the other hand, if the affiliated user warning target flag is "TRUE" (step S103: No), it means that the user group to which the logged-in user belongs is the target of a warning. Therefore, in step S104, the notification control unit 28 refers to the WebEDI user master 14 shown in Fig. 47 based on the user ID of the logged-in user, and determines whether the logged-in user is a manager or a person in charge of the user group of the operating company manager of the operating management company.
[0179] To explain the operation of step S104 in more detail, first, the notification control unit 28 references the WebEDI user master 14 and acquires the user group to which the logged-in user belongs. Next, the notification control unit 28 references the WebEDI user group master 13 based on the acquired user group and acquires the operating company group flag. If this acquired operating company group flag is "TRUE", the notification control unit 28 determines that the logged-in user is an administrator of the operating company (step S104: Yes). Note that if the logged-in user is not an administrator of the operating company (step S104: No), the user is not a user to be notified of a warning in this warning pattern 1, and the processing of the flowchart in FIG. 45 is terminated.
[0180] On the other hand, if the logged-in user is an administrator of the operating company (step S104: Yes), in step S105, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 and acquires details of the user group whose operating company group flag is "TRUE". In addition, in step S106, the notification control unit 28 refers to the WebEDI user master 14 shown in Fig. 47 and acquires details of the user group whose operating company group flag is "TRUE".
[0181] Then, in step S107, the notification control unit 28 determines whether or not all users of the operating company satisfy the following conditions.
[0182] Condition = "Disable warnings FLG" = "FALSE" and "Expiration Date" ≠ "NULL" and "Expiration date" ≤ "Today's date" + "Warning period set for the user group to which the user belongs"
[0183] A user who satisfies this condition is a user whose validity period is about to expire, so in step S108, the notification control unit 28 notifies the administrator of the operating company of the above-mentioned warning (=notification of warning pattern 1).
[0184] (Warning behavior for warning pattern 3 and warning pattern 4) Next, Figure 48 is a flowchart showing the flow of warning operations for warning pattern 3, in which a warning is sent to the administrator of the operating company when a person in charge of a business partner is the person to be warned, and warning pattern 4, in which a warning is sent to both the administrator of the operating company and the administrator of the business partner (or XX customer) when a person in charge of a business partner (or XX customer) is the person to be warned.
[0185] The control unit 3 of the management device 1 controls the execution of the warning operation of the flowchart of Fig. 48 based on the management program stored in the memory unit 2. That is, the flowchart of Fig. 48 starts when the control unit 3 recognizes that "warning pattern 3" or "warning pattern 4" is set in the warning pattern information stored in the memory unit 2, and processing is executed from step S101.
[0186] In step S101, similarly to the above, the notification control unit 28 refers to the WebEDI user master 14 illustrated in Fig. 47 based on the user ID entered on the login screen illustrated in Fig. 27 at the time of login, and acquires the details (records) of that user. In addition, in step S102, the notification control unit 28 refers to the WebEDI user group master 13 illustrated in Fig. 46 based on the user ID, and acquires the details (records) of each user in the user group to which the logged-in user belongs.
[0187] In step S103, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 and determines whether the affiliated user warning target flag set for the user group to which the logged-in user belongs is "FALSE". If the affiliated user warning target flag is "FALSE" (step S103: Yes), this means that the user group to which the logged-in user belongs is not subject to a warning, and the processing of the flowchart in Fig. 48 is terminated. By processing this step S103, it is possible to limit the users to whom a warning is notified to only the administrator, excluding the person in charge.
[0188] On the other hand, if the affiliated user warning target flag is "TRUE" (step S103: No), it means that the user group to which the logged-in user belongs is the target of a warning. Therefore, in step S111, the notification control unit 28 refers to the WebEDI user master 14 shown in Fig. 47 based on the user ID of the logged-in user, and determines whether the logged-in user is a manager or a person in charge of the user group of the operating company manager of the operating management company.
[0189] To explain the operation of step S111 in more detail, first, the notification control unit 28 references the WebEDI user master 14 and acquires the user group to which the logged-in user belongs. Next, the notification control unit 28 references the WebEDI user group master 13 based on the acquired user group and acquires the operating company group flag. If the acquired operating company group flag is "TRUE", the notification control unit 28 determines that the logged-in user is an administrator of the operating company (step S111: Yes). Note that if the logged-in user is not an administrator of the operating company (step S111: No), the processing of the flowchart in FIG. 45 ends immediately.
[0190] On the other hand, if the logged-in user is the administrator of the operating company (step S111: Yes), in step S112, the notification control unit 28 refers to the WebEDI customer classification master 11 shown in Fig. 49 and acquires details of the customer classification for which the operating company notification flag, indicating that a warning should be sent to the administrator of the operating company, is "TRUE (notify the administrator of the operating company)." In addition, in step S113, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 and acquires details of the user group of customers for which a warning should be sent to the operating company.
[0191] Next, in step S114, the notification control unit 28 determines whether or not all users of the business partner satisfy the following conditions.
[0192] Condition = "Disable warnings FLG" = "FALSE" and "Expiration Date" ≠ "NULL" and "Expiration date" ≤ "Today's date" + "Warning period set for the user group to which the user belongs"
[0193] A user who satisfies this condition is a user whose validity period is about to expire, so in step S115, the notification control unit 28 notifies the administrator of the operating company of the above-mentioned warning (=notification of warning pattern 3 or warning pattern 4).
[0194] (Warning behavior for warning pattern 2 and warning pattern 4) Next, Figure 50 is a flowchart showing the flow of warning operations for warning pattern 2, in which a warning is sent to the business partner's administrator when the business partner's person in charge is the person to be warned, and warning pattern 4, in which a warning is sent to both the operating company's administrator and the business partner's (or XX's) administrator when the business partner's (or XX's) person in charge is the person to be warned.
[0195] The control unit 3 of the management device 1 controls the execution of the warning operation of the flowchart of Fig. 50 based on the management program stored in the memory unit 2. That is, the flowchart of Fig. 50 starts when the control unit 3 recognizes the setting of "warning pattern 2" or "warning pattern 4" in the warning pattern information stored in the memory unit 2, and processing is executed from step S101.
[0196] In step S101, similarly to the above, the notification control unit 28 refers to the WebEDI user master 14 illustrated in Fig. 47 based on the user ID entered on the login screen illustrated in Fig. 27 at the time of login, and acquires the details (records) of that user. In addition, in step S102, the notification control unit 28 refers to the WebEDI user group master 13 illustrated in Fig. 46 based on the user ID, and acquires the details (records) of each user in the user group to which the logged-in user belongs.
[0197] In step S103, the notification control unit 28 refers to the WebEDI user group master 13 shown in Fig. 46 and determines whether the affiliated user warning target flag set for the user group to which the logged-in user belongs is "FALSE". If the affiliated user warning target flag is "FALSE" (step S103: Yes), this means that the user group to which the logged-in user belongs is not subject to a warning, and the processing of the flowchart in Fig. 50 is terminated. By processing this step S103, it is possible to limit the users to whom a warning is notified to only the administrator, excluding the person in charge.
[0198] On the other hand, if the affiliated user warning target flag is "TRUE" (step S103: No), it means that the user group to which the logged-in user belongs is the target of a warning. Therefore, in step S120, the notification control unit 28 refers to the WebEDI user master 14 shown in Fig. 47 based on the user ID of the logged-in user, and determines whether the logged-in user is an administrator of the customer's user group.
[0199] To explain the operation of step S120 in more detail, first, the notification control unit 28 references the WebEDI user master 14 and acquires the user group to which the logged-in user belongs. Next, the notification control unit 28 references the WebEDI user group master 13 based on the acquired user group and acquires the operating company group flag. If the acquired operating company group flag is "FALSE", the notification control unit 28 determines that the logged-in user is the administrator of the client's user group (step S120: Yes). Note that if the logged-in user is not the administrator of the client's user group (step S120: No), the processing of the flowchart in FIG. 50 ends immediately.
[0200] On the other hand, if the logged-in user is the administrator of the business partner (step S120: Yes), in step S121, the notification control unit 28 refers to the WebEDI user master 14 shown in Figure 47 and obtains the details of the user of the same business partner as the logged-in user.
[0201] Next, in step S122, the notification control unit 28 determines whether or not all users of the business partner satisfy the following conditions.
[0202] Condition = "Disable warnings FLG" = "FALSE" and "Expiration Date" ≠ "NULL" and "Expiration date" ≤ "Today's date" + "Warning period set for the user group to which the user belongs"
[0203] A user who satisfies this condition is a user whose validity period is about to expire, so in step S123, the notification control unit 28 notifies the administrator of the business partner of the above-mentioned warning (=notification of warning pattern 2 or warning pattern 4).
[0204] (Effects of the embodiment) The operating company that provides the EDI system via the management device 1 must manage the users belonging to the trading partners as well as the trading partners, which results in very high management costs for the operating company. Furthermore, when a trading partner wants to add, modify, or delete a user, the operating company must request this, which creates problems with the accuracy and real-time nature of user settings.
[0205] Furthermore, even if the operating company invalidates the status of a business partner, if each user belonging to that business partner is not invalidated, users who should not be able to use the EDI system will continue to be able to use it.Furthermore, if a setting error by the operating company occurs and a user is registered in association with a business partner different from the one that should have been registered, this user will be able to view business partner information of business partners to which they do not belong, which will be an inconvenience.
[0206] Here, since it is difficult for a single operating company to manage the system, the company considers delegating user management authority to each of its business partners. However, if user management authority is unconditionally delegated to a business partner, the delegated business partner will have no restrictions on user management authority, which can lead to the inconvenience of being able to manage users of other business partners as well. Furthermore, since the delegated business partner can register an unlimited number of users, over time the system will end up with many users who are not currently employed, which can lead to the inconvenience of increasing security risks. For this reason, it is necessary to delegate user management authority to business partners in a limited manner.
[0207] For this reason, the management device 1 of the embodiment assigns user management authority to business partners to register or edit user information including expiration date information indicating the expiration date of legitimate user authority. This allows user management authority to be delegated to each business partner, reducing the management costs of the e-commerce system managed by the operating company of the management device 1. Furthermore, since user management authority can be delegated to trusted business partners, management costs can be safely distributed. Furthermore, business partners who have been delegated user management authority can manage users themselves, allowing for accurate and real-time user management.
[0208] Furthermore, user management authority can be set for each manager or person in charge of a desired user group at each business partner. This allows user management authority to be entrusted to the manager or person in charge of the desired user group, enabling detailed distribution of management costs and further improving security.
[0209] In addition, the upper limit on the number of new users that can be registered can be set for each business partner. This prevents the inconvenience of, for example, a business partner registering an unlimited number of users, which could result in many inactive users being registered over the years and increase security risks.
[0210] Furthermore, the authority to use the EDI system is managed by assigning a status indicating whether it is "enabled" or "disabled" for each trading partner. When a trading partner's status is set to "disabled," the expiration date of the user ID of each user belonging to that trading partner is updated to "expired," and the authority to use the EDI system is disabled. In this way, by setting the trading partner's status to "disabled," the authority to use the EDI system for each user belonging to that trading partner can be disabled all at once, further reducing management costs. It also reduces security risks even if the operating company makes a user management error.
[0211] Furthermore, when registering user information, the management device 1 of the embodiment registers the user ID with an expiration date. Then, when each user logs into the system, a warning is sent to the user whose expiration date is approaching, the administrator of the operating company, or the administrator of the business partner to which the user belongs, urging them to review the user expiration date. The administrator then registers an extension of the expiration date for users who are to be allowed to continue using the EDI system, and does not register an extension of the expiration date for users who are not to be allowed to use the EDI system.
[0212] This makes it possible to disable the use of the EDI system for users who have not registered an extension of the validity period, from the expiration date onwards, thereby maintaining the security of the EDI system and eliminating the need for the cumbersome task of periodically inspecting users registered in the EDI system to determine whether they are using the system legitimately.
[0213] Therefore, even if the level of user management operations at the business partner to whom user management authority has been entrusted is low, the security of the EDI system can be maintained.
[0214] 33(a), if an expiration date extension registration is not performed, it is possible to specify that expiration date warnings will not be sent to the user in the future using the warning invalidation selection object. This makes it possible to suppress expiration date warnings in the future, preventing the inconvenience of continued warnings for users who do not register an expiration date extension.
[0215] [Contribution to the United Nations-led Sustainable Development Goals (SDGs)] This embodiment can contribute to improving business efficiency and promoting appropriate management decisions by companies, thereby contributing to the achievement of Goals 8 and 9 of the SDGs.
[0216] Furthermore, this embodiment can contribute to reducing waste and promoting paperless and electronic systems, thereby contributing to the achievement of SDGs Goals 12, 13, and 15.
[0217] Furthermore, this embodiment can contribute to strengthening control and governance, which can contribute to Goal 16 of the SDGs.
[0218] [Other embodiments] The present invention may be implemented in various different embodiments other than those described above within the scope of the technical concept set forth in the claims.
[0219] For example, among the processes described in the embodiments, all or part of the processes described as being performed automatically can be performed manually, or all or part of the processes described as being performed manually can be performed automatically using known methods.
[0220] Furthermore, the processing procedures, control procedures, specific names, information including parameters such as registered data and search conditions for each process, screen examples, and database configurations shown in this specification and drawings can be changed as desired unless otherwise specified.
[0221] Furthermore, with regard to the management device 1, the components shown in the figure are conceptual functional components, and do not necessarily have to be physically configured as shown in the figure.
[0222] For example, all or any part of the processing functions of the management device 1, particularly the processing functions performed by the control unit 3, may be implemented by a CPU (Central Processing Unit) and a program interpreted and executed by the CPU, or may be implemented as hardware using wired logic. The program is recorded on a non-transitory computer-readable recording medium containing programmed instructions for causing the information processing device to execute the processes described in each embodiment, and is mechanically read by the management device 1 as needed. That is, a storage unit such as a ROM or HDD stores a computer program for working with the OS to issue instructions to the CPU and perform various processes. The computer program is executed by being loaded into RAM, and works with the CPU to constitute the control unit 3 or 43.
[0223] In addition, the management program of this management device 1 may be stored in another server device connected to the management device 1 via any network, and all or part of it may be downloaded as needed.
[0224] Furthermore, the management program for executing the processes described in each embodiment may be stored in a non-transitory computer-readable recording medium, or may be configured as a program product. Here, the term "recording medium" includes any "portable physical medium" such as a memory card, a Universal Serial Bus (USB) memory, a Secure Digital (SD) card, a flexible disk, a magneto-optical disk, a ROM, an Erasable Programmable Read Only Memory (EPROM), an Electrically Erasable and Programmable Read Only Memory (EEPROM (registered trademark)), a Compact Disk Read Only Memory (CD-ROM), a Magneto-Optical Disk (MO), a Digital Versatile Disk (DVD), and a Blu-ray (registered trademark) disc.
[0225] Furthermore, a "program" is a data processing method written in any language or description method, and does not matter whether it is in the form of source code or binary code. Note that a "program" is not necessarily limited to a single structure, but also includes a structure that is distributed as multiple modules or libraries, or a structure that achieves its function by cooperating with a separate program, such as an OS. Note that well-known structures and procedures can be used for the specific structure and reading procedure for reading a recording medium in the management device 1 shown in the embodiment, as well as the installation procedure after reading.
[0226] The memory unit 2 is a storage means such as a memory device such as RAM or ROM, a fixed disk device such as a hard disk, a flexible disk, or an optical disk, and stores various programs, tables, databases, and web page files used for various processes and providing websites.
[0227] The management device 1 may be configured as an information processing device such as a known personal computer or workstation, or may be configured as an information processing device connected to any peripheral device. The information processing device may be realized by installing software (including programs, data, etc.) that realizes the processing described in this embodiment.
[0228] Furthermore, the specific form of distribution and integration of the devices is not limited to that shown in the drawings, and all or part of them can be configured by functionally or physically distributing and integrating them in any unit according to various additions or functional additions. In other words, the above-described embodiments can be implemented in any combination, or embodiments can be implemented selectively. [Industrial Applicability]
[0229] The present invention can be applied to any type of business in which commercial transactions are conducted via a network. [Explanation of symbols]
[0230] 1. Management device of the operating company 2 Storage section 3. Control Unit 4. Communication interface section 5 Input / output interface section 6 Input Devices 7 Output Devices 8 Network 9 Network 11 WebEDI Customer Classification Master 12 WebEDI Customer Master 13 WebEDI User Group Master 14 WebEDI User Master 21 Communication control unit 22 User Management Authority Settings 23 Data Generation Unit 24 Discrimination part 25 Memory control unit 26 Display screen generation section 27 Status setting section 28 Notification control section 80 Terminal devices that make up the backyard environment of the operating company 81 Communication interface section 82 Business data storage unit for data management 90 Collaboration tool that connects the operating company's front and back environments 100 Customer terminal 200 Supplier's terminal equipment
Claims
1. a communication control unit that controls a communication unit so as to mediate the transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network; a notification control unit that issues a warning indicating that the authorized user authority will expire, starting from a date a predetermined number of days before the expiration date of the authorized user authority, based on expiration date information indicating the expiration date of the user authority to officially use the electronic commerce, which is included in the user information stored in the storage unit; the notification control unit controls the display of the warning indicating that the expiration date will come, and the display of a warning invalidation selection object for specifying whether or not the warning will be unnecessary in the future, on a display unit; A management device comprising:
2. the notification control unit displays the warning invalidation selection object from a date a predetermined number of days before the date on which the valid user authority expires; The management device according to claim 1 .
3. the notification control unit hides the warning invalidation selection object for a predetermined period when an extension of the expiration date of the user who is the target of the warning is registered; 3. The management device according to claim 2, wherein:
4. a storage control unit that stores or updates the user information in the storage unit, when the invalidation of the warning is designated via the warning invalidation selection object, the storage control unit updates warning information, which is included in the user information of the user who is the target of the warning and is stored in the storage unit, and indicates whether or not the warning will be issued, to "invalid" which indicates that a warning will not be issued in the future; 4. The management device according to claim 3, wherein:
5. the notification control unit issues a predetermined error notification when an expiration date exceeding a predetermined upper limit is entered during the extension registration of the expiration date of the user who is the target of the warning; 5. The management device according to claim 4, wherein:
6. the notification control unit issues a warning to the effect that there is a user whose expiration date has expired without the extension registration being performed, and displays the warning invalidation selection object, and when an extension registration of the expiration date of the user who is the target of the warning is performed, hides the warning invalidation selection object; when invalidation of the warning is specified via the warning invalidation selection object without registration of an extension of the expiration date, the storage control unit updates warning information, which is included in the user information of the user who is the target of the warning and is stored in the storage unit, and indicates whether or not the warning will be issued, to "invalid," which indicates that a warning will not be issued in the future; The management device according to claim 5 .
7. The notification control unit notifies the warning by: Notifying users whose legitimate user privileges are about to expire; Notifying administrators of users whose legitimate user privileges are about to expire; If the user whose regular user authority is about to expire is a user of a business partner, notify the administrator of said business partner; If a user whose regular user authority is about to expire is a user of a business partner, notification will be sent to the operating company administrator of the operating company that manages all business partners. If the user whose regular user authority is about to expire is a user of a business partner, notify the administrator of the business partner and the operating company administrator of the operating company that manages all business partners; To give one or more notifications of the following: The management device according to claim 1 .
8. A communication control unit that controls a communication unit so as to mediate the transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network; a notification control unit that issues a warning indicating that the authorized user authority will expire, starting from a date a predetermined number of days before the expiration date of the authorized user authority, based on expiration date information indicating the expiration date of the user authority to officially use the electronic commerce, which is included in the user information stored in the storage unit; and a setting unit that sets expiration date setting information, which is information included in the user information of an operating company administrator of an operating company that manages all business partners, and indicates whether or not it is necessary to set an expiration date for a legitimate user authority; A management device having the following.
9. A communication control unit that controls a communication unit so as to mediate the transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network; a notification control unit that issues a warning indicating that the authorized user authority will expire, starting from a date a predetermined number of days before the expiration date of the authorized user authority, based on expiration date information indicating the expiration date of the user authority to officially use the electronic commerce, which is included in the user information stored in the storage unit; and The user information stored in the storage unit includes the expiration date information indicating the expiration date of a valid user's authority, as well as warning date information indicating a warning date during which the warning is issued, the warning date being set uniquely for the entire electronic commerce system, or set for a predetermined group, or set for each user; a storage control unit that stores or updates the user information in the storage unit, the storage control unit stores the expiration date information indicating the specified expiration date and the warning period information indicating the specified warning period in the user information of the target user, the expiration date information indicating the specified expiration date and the warning period information being included in the user information of the target user, in the storage unit; A management device comprising:
10. a first communication device including a first storage unit, for communicating with a terminal device of each trading partner that conducts electronic commerce via a network, and for communicating with a terminal device of a user of an operating company that operates the electronic commerce system via the network; a second communication device including a second storage unit and configured to communicate with the terminal device of the user of the operating company via the network; a linking device that synchronizes the data stored in the first storage unit and the data stored in the second storage unit at a predetermined timing, the first communication device, a communication control unit that controls a communication unit so as to mediate the transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network; a notification control unit that issues a warning indicating that the authorized user authority will expire, starting from a date a predetermined number of days before the expiration date of the authorized user authority, based on expiration date information indicating the expiration date of the user authority to officially use the electronic commerce, which is included in the user information stored in the storage unit; An electronic commerce system comprising:
11. a communication control step in which the communication control unit controls the communication unit so as to mediate transmission and reception of various data between terminal devices of each trading partner that is conducting electronic commerce via the network; a notification control step of notifying the user of a warning indicating that the authorized user authority will expire, from a date a predetermined number of days before the expiration date of the authorized user authority, based on expiration date information indicating the expiration date of the user authority to officially use the electronic commerce, which is included in the user information stored in the storage unit; the notification control step includes controlling the display of the warning indicating that the expiration date will come, and the display of a warning invalidation selection object for specifying whether or not the warning will be unnecessary in the future, on a display unit; A management method characterized by:
12. Computer, a communication control unit that controls a communication unit so as to mediate the transmission and reception of various data between terminal devices of each trading partner that conducts electronic commerce via a network; functioning as a notification control unit that issues a warning indicating that the legitimate user authority will expire, from a date a predetermined number of days before the date on which the legitimate user authority will expire, based on expiration date information indicating the expiration date of the user authority to legitimately use the electronic commerce, which is included in the user information stored in the storage unit; the notification control unit controls the display of the warning indicating that the expiration date will come, and the display of a warning invalidation selection object for specifying whether or not the warning will be unnecessary in the future, on a display unit; A management program featuring:
Citation Information
Patent Citations
Guarantee insurance processing system, and method and device for guarantee processing of electronic transaction
JP2002207949A
Electronic commerce system, method, and program for realizing management function about transaction on computer
JP2003091658A
Device and method for managing contents usage rights
JP2003157335A
Mediating method of inter-enterprise transaction information in electronic commerce market, server and terminal used for this method
JP2003203163A
Network-compatible peripheral equipment, program and recording medium
JP2006171914A