Information processing device and program

The information processing device automates access right settings for files in multi-user messaging services by associating files with user roles and deadlines, reducing user effort and ensuring efficient access control.

JP7749982B2Active Publication Date: 2025-10-07FUJIFILM BUSINESS INNOVATION CORP
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
JP2021137355
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-08-25
Publication Date
2025-10-07
Estimated Expiration
2041-08-25

AI Technical Summary

Technical Problem

Setting access rights for files in a multi-user messaging service requires significant user effort, especially when files are sent to a group, as users need to manually set permissions for each recipient.

Method used

An information processing device that automatically sets access rights to files based on the roles assigned to users, using a processor to associate files with user roles and deadlines, and granting access rights accordingly.

Benefits of technology

Reduces the user's effort in setting access rights by automating the process, allowing for efficient and timely access control based on user roles and deadlines.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007749982000001
    Figure 0007749982000001
  • Figure 0007749982000002
    Figure 0007749982000002
  • Figure 0007749982000003
    Figure 0007749982000003
Patent Text Reader

Abstract

To reduce the time and effort of a user regarding the setting of access rights, as compared with the case where when a file is transmitted to a service that exchanges messages between a plurality of users, the users individually set an access right to the file.SOLUTION: A processor provides users with a service for exchanging messages between a plurality of users to whom roles in specific activity are assigned, in which service when a first user transmits, to a second user, a first message with which a file is associated, an access right according to the role of the second user is set to the file.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing device and a program. [Background technology]

[0002] A service that allows a plurality of users to exchange messages, such as a group chat, is provided to users, and files may be sent to the service.

[0003] Patent Document 1 describes a system that determines whether or not to allow access to an image file based on the access authority given to the user type that has made the access request to the image file.

[0004] Patent Document 2 describes a device that controls access authority to each application according to role information of an operator.

[0005] Patent Document 3 describes a system that controls access to data in accordance with the role and attributes of the user and changes in the state of the data. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2002-140685 [Patent Document 2] Japanese Patent Application Laid-Open No. 2006-202009 [Patent Document 3] Japanese Patent Application Laid-Open No. 2013-114598 Summary of the Invention [Problem to be solved by the invention]

[0007] When a file is sent to a service that allows multiple users to exchange messages, it is possible to set access rights for the file to prevent the file from being disclosed to users who do not need to see the file. For example, a user could manually set the range of users who are permitted to access the file for each file. However, this requires a lot of effort on the part of the user.

[0008] The object of the present invention is to reduce the user's effort in setting access rights when a file is sent to a service that allows multiple users to exchange messages, compared to when the user sets access rights to the file individually. [Means for solving the problem]

[0009] The invention according to claim 1 has a processor, and the processor provides a service for users to exchange messages among a plurality of users assigned roles in a specific activity, and when a first user sends a first message to a second user in the service, the first message is associated with a file, and the processor sets access rights to the file according to the role of the second user. death , If the first message includes information about a deadline, an access right according to the deadline is set for the file. It is an information processing device.

[0010] The invention of claim 2 is the information processing device described in claim 1, characterized in that the processor further grants access rights to the file to a user assigned the same role as the role of the second user.

[0012] Claim 3 The invention according to claim 1 further comprises: when an operation on the file according to the role of the second user is completed, the processor cancels the access right granted to the role of the second user. or Claim 2 The information processing device is described in

[0013] Claim4 The invention according to any one of claims 1 to 5 is characterized in that the processor further grants access rights to the file to a third user who has a role corresponding to a task subsequent to a task corresponding to a role of the first user in the activity. 3 1 is an information processing device according to any one of the preceding claims.

[0014] Claim 5 The invention according to any one of claims 1 to 5 is characterized in that the processor further sets an access right to the file according to a keyword included in the first message. 4 1 is an information processing device according to any one of claims 1 to 8.

[0015] Claim 6 The invention relates to a computer that provides users with a service for exchanging messages among a plurality of users to which roles are assigned in a specific activity, and when a first user sends a first message to a second user in the service, the computer sets access rights to the file according to the role of the second user. death , If the first message includes information about a deadline, an access right according to the deadline is set for the file. This is a program to make it work like this. [Effects of the Invention]

[0016] Claims 1 and 2, 6 According to the present invention, when a file is sent to a service that allows multiple users to exchange messages, the effort required of the user to set access rights to the file is reduced compared to when the user sets access rights to the file individually.

[0017] Furthermore Therefore, even if the user does not set an access right according to the time limit to the file, the access right according to the time limit can be set to the file.

[0018] Claim 3 According to the invention, it is possible to prevent a user who has completed the work corresponding to his / her role from accessing a file.

[0019] Claim 4 According to the invention, access rights can be set to files according to the workflow.

[0020] Claim 5 According to the invention, access rights can be set to a file by sending a message. [Brief explanation of the drawings]

[0021] [Figure 1] FIG. 1 is a block diagram showing a configuration of an information processing system. [Figure 2] FIG. 2 is a block diagram showing the hardware configuration of a collaboration server. [Figure 3] FIG. 2 is a block diagram showing the hardware configuration of the terminal device. [Figure 4] FIG. 1 is a diagram illustrating roles. [Figure 5] FIG. 10 is a diagram illustrating file access rights. [Figure 6] FIG. [Figure 7] FIG. 10 is a diagram showing a message screen. [Figure 8] FIG. 10 is a diagram showing a message screen. [Figure 9] FIG. 10 is a diagram showing a message screen. [Figure 10] FIG. 10 is a diagram showing a message screen. DETAILED DESCRIPTION OF THE INVENTION

[0022] An information processing system according to an embodiment will be described with reference to Fig. 1. Fig. 1 shows an example of the configuration of an information processing system according to an embodiment.

[0023] As an example, the information processing system according to the embodiment includes a link server 14, K (K is an integer greater than or equal to 1) file management servers, L (L is an integer greater than or equal to 1) messaging servers, and M (M is an integer greater than or equal to 1) terminal devices.

[0024] 1, the information processing system according to the embodiment includes file management servers 10A, 10B,...,10K, messaging servers 12A, 12B,...,12L, and terminal devices 16A, 16B,...,16M. These are merely examples, and one or more file management servers, one or more messaging servers, and one or more terminal devices are included in the information processing system according to the embodiment.

[0025] Hereinafter, when there is no need to distinguish between the file management servers 10A, 10B, ..., 10K, they will be referred to as "file management servers 10." When there is no need to distinguish between the messaging servers 12A, 12B, ..., 12L, they will be referred to as "messaging servers 12." When there is no need to distinguish between the terminal devices 16A, 16B, ..., 16M, they will be referred to as "terminal devices 16."

[0026] The file management server 10, messaging server 12, link server 14, and terminal device 16 have the function of communicating with other devices. This communication may be wired communication using a cable, or may be wireless communication. Wireless communication may be, for example, short-range wireless communication or Wi-Fi (registered trademark). Short-range wireless communication may be, for example, Bluetooth (registered trademark) or RFID (Radio Frequency Identifier). Each device may communicate with other devices via a communication path N such as a LAN (Local Area Network) or the Internet.

[0027] The file management server 10 provides a service for managing files (hereinafter referred to as a "file management service"). For example, as the file management service, the file management server 10 provides one or more repositories, which are areas where files are stored. A repository is an example of a storage area, and is realized by, for example, a memory.

[0028] An access right (hereinafter referred to as a "first access right") that is the authority to access and use a repository is given to the user in advance. The user uses the terminal device 16 to access the repository to which the user has the first access right, and stores files in the repository or retrieves files from the repository.

[0029] For example, user account information (hereinafter referred to as "first account information") for logging in to the file management server 10 is defined for each user and registered in the file management server 10. The first account information is, for example, a user ID, a password, or the user's biometric information. When logging in to the file management server 10, the user uses the terminal device 16 to send their own first account information to the file management server 10 and request login to the file management server 10. The file management server 10 authenticates the user who requested login by comparing the first account information sent from the user's terminal device 16 with first account information pre-registered in the file management server 10. If the first account information sent from the user's terminal device 16 is registered in the file management server 10, the file management server 10 permits the user to log in to the file management server 10. A user who is permitted to log in is permitted to log in to the file management server 10 and use a repository to which the user has a first access right. If the first account information transmitted from the user's terminal device 16 is not registered in the file management server 10, the file management server 10 does not permit the user to log in to the file management server 10. In this case, the user is not permitted to log in to the file management server 10 and use the repository. As a separate control, the file management server 10 may permit the user to create a new repository to which the user has access rights, even if the file management server 10 does not permit the user to log in to the file management server 10. Furthermore, the file management server 10 may permit the user to use or create a repository regardless of whether the user is logged in.

[0030] The process of authenticating a user may be performed by a device (for example, an authentication server) other than the file management server 10. In this case, the file management server 10 receives the result of the authentication process by the authentication server, and, depending on the result, permits or does not permit the user to log in to the file management server 10.

[0031] The file management server 10 may provide file management services to users who do not log in to the file management server 10 using the first account information (for example, guest users).

[0032] First account information is defined for each file management server 10 or for each file management service and registered in each file management server 10. The first account information registered in each file management server 10 may be the same information or different information. For example, the first account information for logging in to file management server 10A and the first account information for logging in to file management server 10B may be the same information or different information. The same applies to first account information registered in other file management servers 10. Note that the same first account information may be shared among multiple file management servers 10 to authenticate users.

[0033] A first access right may be set for each individual repository, or multiple repositories may be collectively managed and a first access right may be set for each of the multiple repositories. A first access right for one repository may be set for one piece of first account information, or a first access right for multiple repositories may be set for one piece of first account information. Furthermore, multiple different first account information may be grouped together, and a first access right for one or multiple repositories may be set for the multiple different first account information (i.e., the single group). The first access right may be set or changed when the first account information is registered in the file management server 10, or may be set or changed after the first account information is registered in the file management server 10. Note that a repository without a first access right may be created, and all users may be permitted to access the repository. All users include users who are logged in to the file management server 10 and users who are not logged in to the file management server 10 (e.g., guest users).

[0034] A user may use a terminal device 16 to log in to the file management server 10 without going through the linking server 14 and use the file management service, or may use the file management service via the linking server 14 as described below.

[0035] The concept of a file includes image data, video data, graphic data, audio data such as music data and voice data, document data such as text data, programs, and a combination of at least two of these. The file format is not particularly limited, and files managed by the file management server 10 may have any format. Of course, the format of files managed by the file management server 10 may be limited, and only files having a specific format may be managed by the file management server 10.

[0036] For example, the file management server 10 is operated by a file management service provider. That is, the file management service provider provides the file management service by operating the file management server 10. Multiple different file management servers 10 may be operated by the same provider. For example, each file management server 10 may provide a different file management service, and multiple different file management services may be provided by the same provider. Of course, each file management server 10 may be operated by a different provider, and each file management service may be provided by a different provider.

[0037] The messaging server 12 provides a service (hereinafter referred to as a "messaging service") for exchanging at least messages among multiple users. A message includes characters, symbols or codes other than characters, images, videos, figures, sounds, or at least two of these. For example, the messaging service is a service for sending and receiving emails, a social networking service (SNS), groupware, voice calls such as telephones, a service for providing online conferences (for example, services using voice, images, videos, etc.), or a service for providing online games. An online conference is sometimes called a web conference, a remote conference, a video conference, etc.

[0038] An access right (hereinafter referred to as "second access right") that is the authority to use a messaging service is given to the user in advance. The user uses the terminal device 16 to participate in the messaging service to which the user has the second access right, and exchanges messages with other users who use the messaging service. For example, when the user sends a message to the messaging service using the terminal device 16, the message is sent to other users who use the messaging service. The sent message is, for example, displayed on the display of the terminal device 16 or output as sound from a speaker.

[0039] For example, user account information (hereinafter referred to as "second account information") for logging in to the messaging server 12 is determined for each user and registered in the messaging server 12. The second account information is, for example, a user ID, a password, or the user's biometric information. When logging in to the messaging server 12, the user uses the terminal device 16 to send their second account information to the messaging server 12 and request logging in to the messaging server 12. The messaging server 12 authenticates the user who requested logging in by comparing the account information sent from the user's terminal device 16 with account information pre-registered in the messaging server 12. If the second account information sent from the user's terminal device 16 is registered in the messaging server 12, the messaging server 12 permits the user to log in to the messaging server 12. A user who is permitted to log in is permitted to log in to the messaging server 12 and send, receive, and view messages. If the second account information sent from the user's terminal device 16 is not registered in the messaging server 12, the messaging server 12 does not permit the user to log in to the messaging server 12. In this case, the user is not permitted to log in to the messaging server 12 and exchange messages.

[0040] The process of authenticating a user may be performed by a device (e.g., an authentication server) other than the messaging server 12. In this case, the messaging server 12 receives the result of the authentication process by the authentication server and, depending on the result, allows or does not allow the user to log in to the messaging server 12.

[0041] The messaging server 12 may provide a messaging service to users who do not log in to the file management server 10 using the second account information (for example, guest users).

[0042] Second account information is defined for each messaging server 12 or for each messaging service and registered in each messaging server 12. The second account information registered in each messaging server 12 may be the same information or different information. For example, the second account information for logging in to messaging server 12A and the second account information for logging in to messaging server 12B may be the same information or different information. The same applies to second account information registered in other messaging servers 12. Note that the same second account information may be shared among multiple messaging servers 12 to authenticate users. Note that the same information as the first account information may be used as the second account information.

[0043] For example, a group made up of multiple users (e.g., a group on an SNS (e.g., group chat), a mailing list (ML), groupware, etc.), a thread on an electronic bulletin board, a topic, or a collection of messages on a particular topic, etc., are defined as channels of a messaging service. A user joins one or more channels and exchanges messages with other users who join the same channel. For example, in a messaging service, a channel is created by a user, an administrator, etc., and one or more users are permitted to join the channel and exchange messages.

[0044] The second access right may be set for each individual channel, or multiple channels may be collectively managed and the second access right may be set for each of the multiple channels. The second access right for one channel may be set for one piece of second account information, or the second access right for multiple channels may be set for one piece of second account information. Furthermore, multiple different pieces of second account information may be grouped together, and the second access right for one or multiple channels may be set for the multiple different pieces of second account information (i.e., the single group). The second access right may be set or changed when the second account information is registered in the messaging server 12, or may be set or changed after the second account information is registered in the messaging server 12.

[0045] The user may use the messaging service by logging in to the messaging server 12 using the terminal device 16 without going through the link server 14, or may use the messaging service via the link server 14 as described below.

[0046] For example, the messaging server 12 is operated by a messaging service provider. That is, the messaging service provider provides a messaging service by operating the messaging server 12. Multiple different messaging servers 12 may be operated by the same provider. For example, each messaging server 12 may provide a different messaging service, and multiple different messaging services may be provided by the same provider. Of course, each messaging server 12 may be operated by a different provider, and each messaging service may be provided by a different provider.

[0047] The linking server 14 links one or more services included in one or more file management services and one or more messaging services to each activity set by a user for a specific purpose, and provides the linked file management service and messaging service. The linking server 14 may link one or more file management services to an activity, may link one or more messaging services to an activity, or may link one or more file management services to one or more messaging services.

[0048] For example, multiple users participate in an activity to achieve a specific goal. Hereinafter, users participating in an activity will be referred to as "participants." There are various types of activities, such as work activities, physical activities such as sports, and hobby activities. An example of a work activity is a work project or task in which multiple participants (e.g., employees, contractors, workers, etc.) perform tasks, operations, or actions. There are various types of specific goals, such as work goals (e.g., project or task goals), physical activities, and hobby goals.

[0049] A user who sets up an activity may be a participant of the activity or an administrator, and the administrator may also participate in the activity.

[0050] For example, user account information for logging in to link server 14 (hereinafter referred to as "third account information") is defined for each user and registered in link server 14. The third account information is, for example, a user ID, a password, or the user's biometric information. When logging in to link server 14, the user uses terminal device 16 to transmit their own third account information to link server 14 and requests logging in to link server 14. Link server 14 authenticates the user who requested logging in by comparing the third account information transmitted from the user's terminal device 16 with third account information pre-registered in link server 14. If the third account information transmitted from the user's terminal device 16 is registered in link server 14, link server 14 permits the user to log in to link server 14. If the account information transmitted from the user's terminal device 16 is not registered in link server 14, link server 14 does not permit the user to log in to link server 14.

[0051] The process of authenticating a user may be performed by a device (for example, an authentication server) other than linked server 14. In this case, linked server 14 receives the result of the authentication process by the authentication server, and, depending on the result, permits or does not permit the user to log in to linked server 14.

[0052] Account information common to the file management server 10, the messaging server 12, and the linking server 14 may be used, and one piece of account information may be used to permit login to each of the file management server 10, the messaging server 12, and the linking server 14. Common account information may be used by at least two of the file management server 10, the messaging server 12, and the linking server 14.

[0053] The file management server 10, the messaging server 12, and the linking server 14 may be configured as a single server. The file management server 10 and the messaging server 12 may link the file management service and the messaging service without going through the linking server 14.

[0054] The linking server 14 does not have to be used. In this case, the file management server 10 or the messaging server 12 provides both the file management service and the messaging service. For example, the file management server 10 or the messaging server 12 may provide a messaging service having a file management function (i.e., a function to provide a file management service), or a file management service having a messaging function (i.e., a function to provide a messaging service).

[0055] When a messaging service with a file management function or a file management service with a messaging function is provided by either the file management server 10 or the messaging server 12, the other server and the linking server 14 do not need to be included in the information processing system.

[0056] Below, we will explain an example in which a file management service and a messaging service are linked and provided to a user by the linking server 14, but a messaging service with a file management function, or a file management service with a messaging function may also be provided to a user.

[0057] The terminal device 16 is, for example, a personal computer (hereinafter referred to as a "PC"), a tablet PC, a smartphone, or a mobile phone.

[0058] The hardware configuration of link server 14 will be described below with reference to Fig. 2. Fig. 2 shows an example of the hardware configuration of link server 14.

[0059] The link server 14 includes, for example, a communication device 18, a UI 20, a memory 22, and a processor 24.

[0060] The communication device 18 is a communication interface having a communication chip, a communication circuit, etc., and has a function of transmitting information to other devices and a function of receiving information from other devices. The communication device 18 may have a wireless communication function or a wired communication function. The communication device 18 may communicate with other devices by using, for example, short-range wireless communication, or may communicate with other devices via a communication path N.

[0061] The UI 20 is a user interface and includes at least one of a display and an operation device. The display is a liquid crystal display, an EL display, or the like. The operation device is a keyboard, a mouse, input keys, an operation panel, or the like. The UI 20 may be a UI such as a touch panel that combines a display and an operation device. The UI 20 may also include a microphone and a speaker.

[0062] The memory 22 is a device that configures one or more storage areas for storing data. The memory 22 is, for example, a hard disk drive (HDD), a solid state drive (SSD), various types of memory (e.g., RAM, DRAM, ROM, etc.), other storage devices (e.g., optical disks, etc.), or a combination thereof. One or more memories 22 are included in the linking server 14.

[0063] The processor 24 is configured to control the operation of each unit of the link server 14. The processor 24 may include a memory.

[0064] The processor 24 associates multiple participants in each activity set by the user for each specific purpose. The processor 24 associates and manages each activity with each participant in the activity. For example, the processor 24 associates, for each activity, activity identification information (e.g., the name or ID of the activity) for identifying the activity with account information (e.g., third account information) of each participant in the activity, and stores activity management information including this information in the memory 22 to manage the activity and the participants. The processor 24 may further link the activity identification information with first account information and second account information of each participant. Furthermore, account information common to the file management server 10, the messaging server 12, and the linking server 14 may be associated with the activity identification information.

[0065] Participants in an activity are assigned roles to be played by the participants in that activity. For each participant in the activity, processor 24 associates activity identification information for identifying the activity, account information (e.g., third account information) of the participant in that activity, and role identification information (e.g., role name, ID, etc.) for identifying the role of the participant, and stores role management information including this information in memory 22, thereby managing the roles of each participant in each activity. Roles are assigned to participants, for example, by an activity manager or the like. For example, roles are assigned to participants in advance, and role information of each participant is stored in memory 22 in advance.

[0066] An activity may also include multiple phases. A phase is a task to be performed in an activity and corresponds to a role of a participant. For each activity, processor 24 associates activity identification information for identifying the activity with phase identification information (e.g., a phase name or ID) for identifying each phase included in the activity, stores this information in memory 22 as phase management information, and manages the phases of each activity. For example, when an activity includes multiple phases whose execution order is predetermined, and the activity is performed, each phase is executed by the participants in that order.

[0067] Activity management information, role management information, and phase management information may be integrated and stored in memory 22 as a single piece of management information (e.g., integrated management information) to manage activities, participants, participant roles, and phases.

[0068] Processor 24 also associates each activity with one or more services, including one or more file management services and one or more messaging services.

[0069] For example, the processor 24 links a repository of a file management service to which at least one participant has a first access right to an activity. The processor 24 manages each activity by linking it with one or more repositories of the file management service linked to the activity. For example, the processor 24 links, for each activity, activity identification information for identifying the activity with an address (e.g., a URL) for accessing each repository linked to the activity, and stores and manages this information in the memory 22.

[0070] Furthermore, the processor 24 associates a messaging service to which at least one participant has a second access right with the activity. For example, the processor 24 associates a channel to which at least one participant has a second access right with the activity. The processor 24 associates, for each activity, an activity with a channel of the messaging service associated with the activity and manages the activity. For example, the processor 24 associates, for each activity, activity identification information for identifying the activity with an address (e.g., a URL) for accessing the channel of the messaging service associated with the activity, and stores and manages this information in the memory 22.

[0071] In this manner, processor 24 provides file management and messaging services to participants in a particular activity in association with that activity.

[0072] The processor 24 also controls the setting of access rights to files. Hereinafter, the access rights set to a file will be referred to as "file access rights."

[0073] For example, in a messaging service, when a first participant sends a first message to a second participant with an associated file, the processor 24 sets file access rights to the file according to the role of the second participant. Note that the first participant corresponds to an example of a first user, and the second participant corresponds to an example of a second user.

[0074] Setting the file access rights according to the role to the file means, for example, associating the file with role identification information for identifying the role of the second participant who is the destination of the first message.

[0075] When a participant requests access to a file using his / her own terminal device 16, if role identification information for identifying the role of the participant is associated with the file, the participant is permitted to access the file. If role identification information for identifying the role of the participant is not associated with the file, the participant is not permitted to access the file. The determination of whether to permit access to the file may be made by the processor 32 of the terminal device 16 used by the participant or by the processor 24 of the linking server 14. Note that a file sent to a messaging service is stored in the file management server 10 that provides the messaging service. The file may be stored in the linking server 14 or in the terminal device 16 used by the destination participant.

[0076] A file with file access rights set according to a role is permitted to be accessed by a participant to whom that role is assigned. In other words, a participant to whom a certain role is assigned is permitted to access a file with file access rights set according to that role. A participant who is permitted to access a file is permitted to open the file and view its contents, copy or move the file, download the file, etc.

[0077] The processor 24 may set file access rights to the file for other participants who have the same role as the second participant. For example, the processor 24 sets file access rights to the file for other participants who participate in the same activity as the second participant and have the same role as the second participant.

[0078] The processor 24 may set file access rights corresponding to keywords included in the first message to a file associated with the first message. For example, the processor 24 analyzes the first message by applying language processing such as morphological analysis to character strings included in the first message, extracts keywords included in the first message, and sets file access rights corresponding to the extracted keywords to the file.

[0079] The hardware configuration of the terminal device 16 will be described below with reference to Fig. 3. Fig. 3 shows an example of the hardware configuration of the terminal device 16.

[0080] The terminal device 16 includes, for example, a communication device 26 , a UI 28 , a memory 30 , and a processor 32 .

[0081] The communication device 26 is a communication interface having a communication chip, a communication circuit, etc., and has a function of transmitting information to other devices and a function of receiving information transmitted from other devices. The communication device 26 may have a wireless communication function or a wired communication function. The communication device 26 may communicate with other devices by using, for example, short-range wireless communication, or may communicate with other devices via a communication path N.

[0082] The UI 28 is a user interface and includes at least one of a display and an operation device. The display is a liquid crystal display, an EL display, or the like. The operation device is a keyboard, a mouse, input keys, an operation panel, or the like. The UI 28 may be a UI such as a touch panel that combines a display and an operation device. The UI 28 may also include a microphone and a speaker.

[0083] The memory 30 is a device that configures one or more storage areas for storing data. The memory 30 is, for example, a hard disk drive (HDD), a solid state drive (SSD), various types of memory (e.g., RAM, DRAM, ROM, etc.), other storage devices (e.g., optical disks, etc.), or a combination thereof. One or more memories 30 are included in the terminal device 16.

[0084] The processor 32 is configured to control the operation of each part of the terminal device 16. The processor 32 may include a memory.

[0085] The following describes the embodiments in detail with specific examples. As an example, the following describes the embodiments assuming a scenario in which a work project is launched as an activity and the project is carried out. For example, a manager who manages the project and participants who join the project and perform tasks and operations are involved in the project. The manager may also join the project as a participant. The manager and participants use their own terminal devices 16 to use the file management service provided by the file management server 10 and the messaging service provided by the messaging server 12. The manager and participants also use their own terminal devices 16 to use services (e.g., file management services and messaging services) linked to the activity by the linking server 14.

[0086] The roles of participants will be described with reference to Figure 4. Figure 4 shows an example of a role. Roles may include, for example, sales, requirements analysis / requirements definition, system design, detailed design, implementation, testing, and project management. One or more of these roles are assigned to each participant in the project. Information indicating the role of each participant is included in the integrated management information described above, and the role of each participant is managed. Note that the same role may be assigned to multiple participants.

[0087] The file access rights set for a file will be described with reference to Figure 5. Figure 5 shows an example of file access rights set for a file. File access rights are set for each role. A file to which file access rights for a certain role are set is a file that participants assigned to that role are permitted to access. As file access rights, for example, file access rights for sales, file access rights for requirements definition, file access rights for detailed design, file access rights for implementation, file access rights for testing, and file access rights for project management are defined.

[0088] Files with file access rights set for sales are files that participants assigned the role of "Sales" are permitted to access. Files with file access rights set for requirements analysis / requirements definition are files that participants assigned the role of "requirements analysis / requirements definition" are permitted to access. The same applies to other file access rights.

[0089] Referring to Figure 6, the phases included in a project, which is an example of an activity, will be described. Figure 6 shows an example of phases included in Project α. Project α includes the following phases: "1. Sales," "2. Requirements Analysis / Requirements Definition," "3. System Design," "4. Detailed Design," "5. Implementation," and "6. Testing." In Project α, these phases are scheduled to be executed in the order of the numbers shown in Figure 6. That is, each phase (i.e., each task) is scheduled to be executed in the order of "Sales," "Requirements Analysis / Requirements Definition," "System Design," "Detailed Design," "Implementation," and "Testing." A phase is an operation to be performed by a participant assigned a role corresponding to that phase. For example, the "Sales" phase is an operation to be performed by a participant assigned the role "Sales." The "Requirements Analysis / Requirements Definition" phase is an operation to be performed by a participant assigned the role "Requirements Analysis / Requirements Definition." The same applies to other phases.

[0090] An example of rules for setting file access rights to a file will be described below.

[0091] As an example, assume that a participant who has created a file uses his / her terminal device 16 to post the file to a message service associated with project α in which the participant is participating. Posting a file means sending the file to the message service, either associated with a message or not. Participants are permitted to access the file posted to the message service according to the file access rights set for the file.

[0092] (Rule 1) In setting access rights in accordance with Rule 1, the processor 24 sets, to the file, file access rights for roles corresponding to phases later than the phase corresponding to the role of the participant who posted the file. For example, if a participant assigned the role "Sales" posts a file, the processor 24 sets, to the file, file access rights for roles corresponding to phases later than the phase "Role". As a result, participants assigned roles corresponding to phases later than the phase "Role" are permitted to access the file for which the file access rights are set. For example, file access rights for roles corresponding to the phases "Requirements Analysis / Requirements Definition", "System Design", "Detailed Design", "Implementation", and "Test" are set to the file, and participants assigned each of the roles are permitted to access the file.

[0093] (Rule 2) In setting access rights according to rule 2, processor 24 sets file access rights to a file according to keywords included in the first message associated with the file. Examples of keywords include the name of a role, the name of a phase, the name of a file type, the name of a file, and comments about work performed on the file.

[0094] For example, the processor 24 extracts the character string "phase name" included in the first message as a keyword, and sets file access rights for the role corresponding to the phase having the "phase name" to the file associated with the first message. To give a specific example, if the keyword included in the first message associated with a file is the character string "system design," the processor 24 sets file access rights for the role "system design" to the file. This allows participants assigned the role "system design" to access the file.

[0095] The processor 24 may also set a file access right corresponding to the file type name or file name for the file. For example, roles and phases corresponding to the file type name or file name are determined in advance, and the processor 24 sets a file access right for the role and phase corresponding to the posted file type name or file name for the file in accordance with the determination.

[0096] The processor 24 may also extract a character string "comment regarding work performed on the file" included in the first message as a keyword and set file access rights related to the "comment" to the file. The comment may be, for example, "created," "completed," or "stored" for the file. For example, if the first message includes a character string indicating "completion of a phase," the processor 24 extracts the character string as a keyword and analyzes the character string to recognize that the phase has been completed. In this case, the processor 24 sets file access rights for the role corresponding to the phase next to the current phase to the file. To give a specific example, if a character string such as "system design completed" is extracted from the first message, the processor 24 sets file access rights for the role "detailed design" corresponding to the phase "detailed design" next to the phase "system design" to the file. As a result, participants assigned the role "detailed design" are permitted to access the file.

[0097] (Rule 3) In setting access rights in accordance with Rule 3, when a first participant sends a first message associated with a file to a second participant in a messaging service corresponding to project α in which the first and second participants are participating, processor 24 sets file access rights to the file according to the role of the second participant.

[0098] For example, if the role of the second participant is the role "system design," the processor 24 sets the file access rights for the role "system design" to the file, thereby allowing the second participant to access the file.

[0099] Furthermore, even if another participant is participating in project α in which the first and second participants are participating, a file sent to the second participant in the messaging service corresponding to project α will be sent only to the second participant, not to the other participant. If the other participant is included in the recipients of the file, the file will also be sent to the other participant.

[0100] (Rule 4) If the role to be granted file access rights to the posted file is not identified based on messages exchanged on the messaging service corresponding to project α, the processor 24 may grant file access rights to all participants participating in project α, may grant file access rights only to the participant who posted the file, or may grant file access rights to the role of the participant who posted the file. In other words, the processor 24 may set file access rights for all roles in project α, may set file access rights for the file that are accessible only to the participant who posted the file, or may set file access rights for the role of the participant who posted the file.

[0101] The above-mentioned rules 1 to 4 are examples of rules for setting access rights, and access rights may be set to files according to other rules.

[0102] The processing according to the embodiment will be described in detail below with a specific example. As an example, assume that project α is being carried out as an example of an activity, and participants A, B, C, D, E, F, and G are participating in project α.

[0103] Participant A is assigned the role of "sales," participant B is assigned the role of "requirements analysis / requirements definition," participant C is assigned the role of "system design," participant D is assigned the role of "detailed design," participant E is assigned the role of "implementation," participant F is assigned the role of "test," and participant G is assigned "project management." Information about these is, for example, registered in advance in the integrated management information described above.

[0104] For example, each participant uses their own terminal device 16 to send their own account information (e.g., third account information) to the link server 14, requesting login to the link server 14 and access to project α. A participant who is successfully authenticated is permitted to log in to the link server 14 and is permitted to access the file management service and messaging service associated with project α. A participant who is successfully authenticated is permitted to, for example, access a repository provided by the file management service associated with project α and to exchange information with other participants using the messaging service associated with project α. Note that each participant may access the link server 14 using their own terminal device 16 and use the file management service and messaging service associated with project α without logging in to the link server 14 or being authenticated.

[0105] For example, the processor 24 of the link server 14 displays a screen for using a messaging service associated with project α on the display of the terminal device 16 used by the participants of project α. Note that a file management service may also be used via this screen. Hereinafter, the screen for using the messaging service will be referred to as a "message screen." Messages sent by each participant to the messaging service are displayed on the message screen.

[0106] For example, a group chat may be formed with multiple participants, and messages may be exchanged between the multiple participants in the group chat on a message screen. Also, multiple threads (e.g., multiple channels for exchanging messages about a specific topic) may be formed for project α, and messages may be exchanged in each thread. Each thread may involve all participants in project α, or only some of the participants. The same or different multiple participants may participate in each thread.

[0107] An example of a message screen is shown in Fig. 7. A message screen 34D shown in Fig. 7 is a message screen displayed on the display of participant D's terminal device 16D.

[0108] The processor 24 displays messages sent to a messaging service associated with project α (more specifically, channels linked to project α) on the message screen 34D. For example, each message is displayed according to a timeline notation. That is, each message is displayed in order according to the date and time when the message was sent to the channel. For example, each message is displayed in order from top to bottom on the message screen 34D according to the date and time when the message was sent to the channel. Note that information for identifying the participant who sent the message (for example, a name, nickname, ID, or an image such as an icon) may be associated with the message and displayed on the message screen 34D. For example, the information is displayed near the message.

[0109] Messages that cannot be displayed on the message screen 34D can be displayed within the message screen 34D by moving the message screen 34D up or down (for example, by scrolling the message screen 34D up or down).

[0110] Additionally, if a file associated with a message has been sent to a messaging service, an image (eg, an icon) representing the file is displayed on message screen 34D.

[0111] When a participant other than participant D accesses project α, a message screen similar to message screen 34D is also displayed on the display of the terminal device 16 of the other participant.

[0112] In the example shown in Figure 7, messages 36, 40, 42, and 44 are displayed on message screen 34D. Messages 36 and 44 are messages sent by participant D to a message service associated with project α. Messages 40 and 42 are messages sent by participant C to a message service associated with project α. Message 36 has file 38 attached. In other words, message 36, to which file 38 is associated, was sent by participant C to a messaging service.

[0113] An input field 46 is also displayed on the message screen 34D. The input field 46 is a field for sending a message to the messaging service. When a message is entered in the input field 46 and an instruction to send is given (for example, when a send button displayed on the message screen 34D is pressed), the processor 24 displays the entered message on the message screen 34D as a message from participant D. The processor 24 also sends the entered message to other participants who are accessing the messaging service associated with project α.

[0114] Messages sent to the messaging service associated with project α may be viewable by all participants in project α, i.e., messages sent to the messaging service associated with project α may be displayed on message screens displayed on the displays of the terminal devices 16 of all participants.

[0115] As another example, in a messaging service associated with project α, a message sent to a specific participant may be viewable only by the participant who sent the message and the specific participant. In other words, the message may be displayed only on a message screen displayed on the display of the terminal device 16 of the participant who sent the message and the specific participant. For example, when a participant specifies a destination for a message and sends it, the message is sent to the participant specified as the destination, and the message is displayed only on a message screen displayed on the display of the terminal device 16 of the participant who sent the message and the destination participant.

[0116] 7, messages 36 and 44 are messages sent from participant D to participant C, and messages 40 and 42 are messages sent from participant C to participant D. Therefore, messages 36, 40, 42, and 44 are displayed only on the message screens displayed on the displays of the terminal devices 16 of participants C and D, respectively, and are not displayed on the message screens displayed on the displays of the terminal devices 16 of other participants such as participant A.

[0117] When the destination of the message 36 is specified as participant C, the processor 24 displays information for identifying participant C (e.g., name, account information, etc.) near the message 36, as indicated by the reference symbol 36a. For example, a list of participants participating in project α is displayed on the message screen 34D, and participant D may specify the destination participant (e.g., participant C) from the list, or participant D may directly input information for identifying the destination participant.

[0118] Although not shown in FIG. 7, information for identifying the intended participants is also displayed near each of the messages 40, 42, and 44.

[0119] Even if a participant to whom a message is addressed is specified, information for identifying the participant to whom the message is addressed (for example, the character string indicated by the reference symbol 36a) does not necessarily have to be associated with the message and displayed on the message screen.

[0120] Note that the message may be sent to each participant as an individual message, rather than being sent to project α. For example, message 36 associated with file 38 may be sent from participant D to participant C, rather than being sent to project α.

[0121] In the example shown in FIG. 7, the message 36 associated with the file 38 corresponds to an example of the first message.

[0122] For example, the processor 24 sets file access rights to the file 38 according to the role "detailed design" assigned to the participant D who posted the message 36 (i.e., the participant D who sent the message 36 to the messaging service associated with the project α). That is, the processor 24 associates role identification information for identifying the role "detailed design" with the file 38. This allows participants who are assigned the role "detailed design" to access the file 38. For example, the participant D is allowed to access the file 38.

[0123] Additionally, participants who are assigned the same role as participant D who posted message 36 are granted file access rights to file 38. In other words, participants other than participant D who are assigned the role of "detailed design" are permitted to access file 38.

[0124] The processor 24 may analyze a character string included in the message 36 with which the file 38 is associated, and set file access rights to the file 38 according to the analysis results. For example, the processor 24 extracts a character string indicating a role, a character string indicating a phase, or a character string indicating an operation from the message 36, and sets file access rights corresponding to the extracted character string to the file 38. The message 36 includes a character string "detailed design," which is a character string indicating a role or a phase. In this case, the processor 24 associates role identification information for identifying the role "detailed design" with the file 38, and thereby sets file access rights for the role "detailed design" to the file 38.

[0125] The processor 24 may set file access rights to the file 38 according to the role "system design" of the participant C, who is the destination of the message 36. That is, the processor 24 associates role identification information for identifying the role "system design" with the file 38. This allows participants assigned the role "system design" to access the file 38. For example, the participant C is allowed to access the file 38.

[0126] Furthermore, file access rights to the file 38 are granted to participants who are assigned the same role as participant C, who is the destination of the message 36. In other words, even if a participant is other than participant C, if the participant is assigned the role of "system design," the participant is permitted to access the file 38.

[0127] If the first message includes information about a deadline, the processor 24 may set a file access right according to the deadline to the file associated with the first message. The file access right according to the deadline is a file access right for which a deadline is set. For example, a file for which a file access right according to the deadline is set is a file for which access is permitted until the deadline arrives or passes.

[0128] For example, if the message 36 to which the file 38 is associated contains information about a deadline, the processor 24 sets file access rights for the file 38 according to the deadline.

[0129] To give a specific example, if message 36 is a message indicating that participant D has requested participant C to review file 38, and message 36 includes a character string related to a deadline, such as "by October 5th," processor 24 sets file access rights for file 38 according to the deadline. For example, processor 24 associates information indicating the deadline with file 38. In this case, access to file 38 is permitted until October 5th arrives or passes. For example, role identification information for identifying the role "system design" and information indicating the deadline are associated with file 38. Participants assigned the role "system design" are permitted to access file 38 until the deadline arrives or passes.

[0130] When the work on the file corresponding to the role of the second participant is completed, processor 24 may cancel the file access rights granted to the role of the second participant. Canceling the file access rights to the file involves deleting the role identification information associated with the file, or, without deleting the role identification information associated with the file, associating information with the file indicating that participants assigned the role indicated by the role identification information are not permitted to access the file. When the file access rights granted to a role are cancelled, participants assigned the role are not permitted to access the file for which the cancelled file access rights are set.

[0131] For example, the processor 24 analyzes a character string included in a message posted by participant C, who is the second participant to whom the message 36 associated with the file 38 is addressed, and determines whether the work corresponding to the role of participant C has been completed. In the example shown in FIG. 7, the message 42 posted by participant C contains the character strings "review" and "complete." In this case, the processor 24 extracts these character strings from the message 42, recognizes that the review by participant C has been completed, and revokes the file access rights granted to participant C's role "system design" from the file 38. As a result, a participant (e.g., participant C) assigned the role "system design" is not permitted to access the file 38.

[0132] The processor 24 may grant file access rights to a file to a third participant who is assigned a role corresponding to a phase (e.g., a task) next to the phase (e.g., a task) corresponding to the role of the first participant in the activity. For example, the processor 24 refers to the integrated management information described above to identify the order of each phase included in the activity, and grants file access rights to a file to a third participant who is assigned a role corresponding to the next phase. In this case, the processor 24 associates role identification information for identifying the role corresponding to the next phase with the file, thereby allowing the participant who is assigned the role to access the file.

[0133] 7, the role of "detailed design" is assigned to participant D, who is the first participant. In this case, processor 24 associates, with file 38, role identification information for identifying the role "implementation" corresponding to the phase "implementation" that follows the phase "detailed design" corresponding to the role "detailed design." This allows participants assigned the role "implementation" to access file 38.

[0134] When the task corresponding to the role of participant C, who is the second participant, is completed, the processor 24 may grant file access rights to the file 38 to a participant assigned a role corresponding to the phase next to the phase corresponding to the role of participant C. Explaining this process in detail, the processor 24 analyzes a string included in a message (e.g., messages 40 and 42) posted by participant C, who is the destination participant of the message 36 to which the file 38 is associated, and determines whether the task corresponding to the role of participant C has been completed. If the task has been completed, the processor 24 grants file access rights to the file to a participant assigned a role corresponding to the phase next to the phase corresponding to the role of participant C. That is, the processor 24 associates role identification information for identifying the role corresponding to the next phase with the file 38.

[0135] To give a specific example, message 42 posted by participant C, who is the destination participant of message 36 with which file 38 is associated, contains the character strings "review" and "complete." In this case, processor 24 determines that the work corresponding to the role assigned to participant C has been completed, and associates with file 38 role identification information for identifying role "detailed design" corresponding to the phase "detailed design" that follows the phase "system design" corresponding to participant C's role "system design."

[0136] When the work corresponding to the role of participant C, the second participant, is completed, processor 24 may grant file access rights to file 38 to a participant who is assigned a role corresponding to the phase next to the phase corresponding to the role of participant D, the first participant.

[0137] In the example shown in FIG. 7, when the work corresponding to the role "system design" of participant C, who is the second participant to whom message 36, which is associated with file 38, is addressed, is completed, processor 24 grants file access rights to file 38 to participants who are assigned the role "implementation" corresponding to the phase "implementation" that follows the phase "detailed design" corresponding to the role "detailed design" of participant D, who is the first participant who posted message 36. In other words, processor 24 associates role identification information for identifying the role "implementation" corresponding to the next phase "implementation" with file 38. As a result, participants who are assigned the role "implementation" are permitted to access file 38.

[0138] The example of file access right settings described with reference to FIG. 7 is one example. For example, file access rights for the file 38 are granted to the role "detailed design" of participant D, who posted the message 36 associated with the file 38, and the role "system design" of participant C, who is the recipient of the message 36. Furthermore, when the work corresponding to the role "system design" of participant C, who is the recipient of the message 36, is completed, file access rights for the file 38 are granted to the role "implementation," which corresponds to the phase "implementation" that follows the phase "detailed design" corresponding to the role "detailed design" of participant D, who posted the message 36. As a result, participants assigned the role "detailed design," participants assigned the role "system design," and participants assigned the role "implementation" are permitted to access the file 38. Furthermore, participants assigned roles for which file access rights have been revoked are not permitted to access the file 38.

[0139] FIG. 8 shows messages exchanged between participant D and participant F. FIG. 8 shows a message screen 34D displayed on the display of participant D's terminal device 16D. Messages 48, 50, 52, 54, and 58 are displayed on message screen 34D. Messages 50 and 54 are messages sent by participant D to participant F. Messages 48, 52, and 58 are messages sent by participant F to participant D. A screen similar to message screen 34D is also displayed on the display of participant F's terminal device 16F, and messages 48, 50, 52, 54, and 58 are displayed on this screen. In addition, message 54 is associated with file 56, which indicates a link (e.g., an address such as a URL) to file 38. By accessing this link, file 38 can be accessed.

[0140] 7, messages are exchanged between participant C and participant D, and as a result, file access rights for file 38 are granted to the roles "detailed design," "system design," and "implementation." For example, participant D, who posted message 36 associated with file 38, exchanges messages with participant C (see FIG. 7), and then exchanges messages with participant F (see FIG. 8).

[0141] The processor 24 sets file access rights for the file 38 posted by the participant D for the role "test" of the participant F, who is the destination participant of the message posted by the participant D. In other words, the processor 24 associates role identification information for identifying the role "test" with the file 38. As a result, the participant to whom the role "test" is assigned is permitted to access the file 38.

[0142] Another message exchange is shown in Figure 9. Figure 9 shows a message screen 34E. The message screen 34E is a screen displayed on the display of the terminal device 16E of participant E. On the message screen 34E, messages 60, 62, 64, and 66 are exchanged between participant E and other participants. A file 68 is attached to the message 60 posted by participant E.

[0143] For example, the processor 24 analyzes a character string included in the message 60 to which the file 68 is associated, and sets file access rights for the file 68 according to the analysis result. The message 60 includes the character string "implementation." In this case, the processor 24 associates role identification information for identifying the role "implementation" with the file 68, thereby setting file access rights for the file 68 for the role "implementation." As a result, participants to whom the role "implementation" is assigned are permitted to access the file 68.

[0144] Message 60 also includes the character string "implemented" along with the character string "completed." In this case, processor 24 recognizes that the work corresponding to role "implemented" has been completed, and may set file access rights for role "implemented" by associating role identification information for identifying role "implemented" with file 68.

[0145] Processor 24 may set file access rights for file 68 to the role "implement" of participant E, who posted message 60 with which file 68 is associated.

[0146] Another message exchange is shown in Figure 10. Figure 10 shows a message screen 34F. The message screen 34F is a screen displayed on the display of the terminal device 16F of participant F. On the message screen 34F, messages 70, 72, 74, and 76 are exchanged between participant F and other participants. A file 78 is attached to the message 70 posted by participant F.

[0147] For example, the processor 24 analyzes a character string included in a message 70 to which a file 78 is associated, and sets file access rights to the file 78 according to the analysis result. The message 70 includes the character string "test." In this case, the processor 24 associates role identification information for identifying the role "test" with the file 78, thereby setting file access rights to the file 78 for the role "test." As a result, participants assigned the role "test" are permitted to access the file 78.

[0148] Additionally, message 70 includes the string "create" along with the string "test." In this case, processor 24 may recognize that work corresponding to role "test" has been completed and may set file access rights for role "test" by associating role identification information for identifying role "test" with file 78.

[0149] Processor 24 may set file access rights for file 78 to the role "test" of participant F, who posted message 70 with which file 78 is associated.

[0150] Another application example of the embodiment will be described below. The embodiment may be applied to an activity in which work flows in one direction. For example, the embodiment is applied to an activity including multiple tasks that are to be performed in a predetermined order, and authority for each task is granted to a worker involved in each task.

[0151] For example, the embodiments are applied to activities (e.g., medical procedures, diagnoses, etc.) that include multiple tasks performed in a medical setting. Specifically, the embodiments may be applied to medical procedures and diagnoses that include imaging using a CT device, an MRI device, etc. In such situations, tasks such as scanning by a radiologist or other imager, image generation, image quality confirmation, and loading of diagnostic information onto the image, and display and printing of the image by a doctor, nurse, etc. are performed in this order. In this case, because the doctor's authority is greater than the other authorities, the doctor is granted authority for all tasks, and workers other than the doctor are granted authority according to the role of the worker.

[0152] As another example, the embodiment may be applied to publishing or advertising work. For example, tasks such as creating a manuscript, submitting the manuscript, typesetting, proofreading, color proofing, and printing are performed in this order. Each worker is granted authority according to the role and order of the worker involved in each task.

[0153] The functions of each of the above-described file management server 10, messaging server 12, link server 14, and terminal device 16 are realized, for example, by a combination of hardware and software. For example, the processor of each device reads and executes a program stored in the memory of each device, thereby realizing the function of each device. The program is stored in the memory via a recording medium such as a CD or DVD, or via a communication path such as a network.

[0154] In the above embodiments, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.). Furthermore, the operations of the processor in the above embodiments may not only be performed by a single processor, but may also be performed by multiple processors located in physically separate locations working together. Furthermore, the order of the operations of the processor is not limited to the order described in the above embodiments, and may be changed as appropriate. [Explanation of symbols]

[0155] 10A,10B,···,10K file management servers, 12A,12B,···,12L messaging servers, 14 collaboration servers, 16A,16B,···,16M terminal devices, 24 processors.

Claims

1. a processor; The processor: providing users with a service for exchanging messages among multiple users who are assigned roles in a specific activity; When a first user sends a first message to a second user in the service, the first message has a file associated therewith. The second user's access rights are set to the file according to the role of the second user; If the first message includes information about a deadline, an access right according to the deadline is set for the file. Information processing device.

2. The processor further comprises: granting access rights to the file to a user assigned a role that is the same as the role of the second user; 2. The information processing apparatus according to claim 1, wherein:

3. The processor further comprises: When the work on the file according to the role of the second user is completed, the access right granted to the role of the second user is cancelled.

3. The information processing device according to claim 1 or 2.

4. The processor further comprises: granting access rights to the file to a third user who has a role corresponding to a task subsequent to a task corresponding to a role of the first user in the activity; 4. The information processing device according to claim 1, wherein the information processing device is a computer.

5. The processor further comprises: setting an access right to the file according to a keyword included in the first message; 5. The information processing device according to claim 1, wherein the information processing device is a computer.

6. The computer providing users with a service for exchanging messages among multiple users who are assigned roles in a specific activity; When a first user sends a first message to a second user in the service, the first message has a file associated therewith. The second user's access rights are set to the file according to the role of the second user; If the first message includes information about a deadline, an access right according to the deadline is set for the file. A program to make it work like this.

Citation Information

Patent Citations

  • Method and device for changing dynamic access right

    JP1995287688A

  • Image management system and its method

    JP2002140685A

  • Medical equipment and access control program

    JP2006202009A

  • File access control method, file access control system, and delivery file generation program

    JP2008282164A

  • Mailing list device, mail distribution method, and program

    JP2013105193A