Information processing device, information processing method, and program
The information processing device allows duplicate email addresses to be used for login by storing multiple user information with different passwords and enabling tenant selection, addressing the challenge of assigning the same person to multiple tenants.
Patent Information
- Application Number
- JP2021148864
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-13
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2041-09-13
AI Technical Summary
Conventional systems face difficulties in allowing the same person to be assigned to multiple tenants when using email addresses as login usernames, as they do not permit duplicate email addresses, making it challenging to register multiple user information with overlapping email addresses.
An information processing device and method that allows for the storage of multiple user information items with different passwords associated with the same email address, enabling selection of the appropriate user information for login based on email address and password matching, and providing an entry selection screen for users to choose the correct tenant and user ID.
Enables the use of duplicate email addresses for login, allowing the same person to be assigned to multiple tenants by selecting the correct user information through matching email and password, and providing options for tenant selection.
Smart Images

Figure 0007793912000001 
Figure 0007793912000002 
Figure 0007793912000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, an information processing method, and a program. [Background technology]
[0002] Conventionally, there are systems that allow a user's email address to be used as a username for logging in. For example, Patent Document 1 discloses a configuration that determines whether a contact email address can uniquely identify a user, with the aim of enabling the user to log in using the email address, and allows the user to log in using the email address if the user can be uniquely identified.
[0003] On the other hand, there is a system in which user information is registered for each combination of a user name and the tenant (a subscriber of a service such as a department) to which the user belongs. Summary of the Invention [Problem to be solved by the invention]
[0004] In systems where identification information such as email addresses can be used as login usernames, duplicate email addresses are not permitted because each email address is unique for each user.
[0005] On the other hand, when user information is differentiated for each combination of username and tenant, there are cases where it is desired to assign the same person to multiple tenants. In such a case, if an email address is used as the username, conventional technology makes it difficult to register multiple user information with overlapping email addresses, making it difficult to assign the same person to multiple tenants.
[0006] The present invention has been made in view of the above points, and has as its object to allow overlapping of identification information used for login. [Means for solving the problem]
[0007] In order to solve the above problem, the information processing device is configured to email address and a storage unit for storing user information including a password, email address a storage unit that stores a plurality of user information items each having a different password and overlapping with another user; email address and a password, the storage unit stores the password included in the login request. email address Matches email address and a selection unit that, when a plurality of pieces of user information are acquired by the search unit, selects one piece of user information from the plurality of pieces of user information as user information relating to a user to be permitted to log in. [Effects of the Invention]
[0008] Duplicate identification information used for login may be permitted. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 illustrates an example of a system configuration according to a first embodiment. [Figure 2] 1 is a diagram illustrating an example of a hardware configuration of an information processing device 10 according to a first embodiment. [Figure 3] 1 is a diagram illustrating an example of a functional configuration of an information processing device 10 according to a first embodiment. [Figure 4] FIG. 2 is a diagram illustrating an example of a processing procedure executed by the information processing device 10 in the first embodiment. [Figure 5] FIG. 10 is a diagram illustrating an example of a login screen. [Figure 6] FIG. 2 is a diagram illustrating an example of the configuration of a user information storage unit 121. [Figure 7] FIG. 10 is a diagram showing a display example of an entry selection screen in the first embodiment. [Figure 8] FIG. 10 is a diagram illustrating an example of a functional configuration of an information processing device 10 according to a second embodiment. [Figure 9]FIG. 2 is a diagram illustrating an example of the configuration of a password policy storage unit 122. [Figure 10] FIG. 11 is a diagram showing a display example of an entry selection screen in the second embodiment. [Figure 11] FIG. 13 is a diagram showing a display example of an entry selection screen in the third embodiment. [Figure 12] FIG. 13 is a diagram illustrating an example of a processing procedure executed by the information processing device 10 in the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIG. 1 is a diagram showing an example of a system configuration in a first embodiment. In FIG. 1, an information processing device 10 is connected to user terminals 20a, 20b, and 20c (hereinafter, when there is no need to distinguish between them, they will simply be referred to as "user terminals 20") via a network such as the Internet. Each user terminal 20 is used by a user belonging to one of the tenants (in FIG. 1, tenant A, tenant B, tenant C, or the like). A tenant is a person who has entered into a service contract for a service provided by the information processing device 10, and is, for example, a group of multiple people such as a corporation, an individual, or a public organization.
[0011] The information processing device 10 is, for example, one or more computers that provide services (hereinafter simply referred to as "services") that can be used via a network, such as cloud services.
[0012] The user terminal 20 is a terminal used by a user of the service, such as a PC (Personal Computer), a tablet terminal, or a smartphone. In order to use the service, the user needs to log in to the information processing device 10.
[0013] In FIG. 1, which tenant each user who uses each user terminal 20 belongs to is indicated by a dashed frame indicating the tenant and an inclusion relationship between the user terminal 20 and the user terminal 20. That is, it is indicated that the user of user terminal 20a belongs to tenants X, Y, and Z. It is indicated that the user of user terminal 20b belongs to tenants X and Y. It is indicated that the user of user terminal 20c belongs to tenant Z. In this way, in this embodiment, a certain user can belong to multiple tenants (a certain user can be assigned multiple tenants). As examples of cases in which one user belongs to multiple tenants, cases (1) to (3) are shown below.
[0014] (1) A user who belongs to a branch (office) or department-level tenant (e.g., Tenant X or Y) needs to also belong to a company-wide tenant (e.g., Tenant Z).
[0015] (2) A user who belongs to a company tenant (e.g., tenant Y or Z) wants to use the information processing device 10 privately (e.g., tenant X). Conversely, a user who uses the information processing device 10 privately (e.g., tenant X) also wants to use the information processing device 10 at work (e.g., tenant Y or Z).
[0016] (3) A user who belongs to a tenant at the head office (for example, Tenant Z) is transferred to another company and needs to also belong to the tenant at the company where he or she is transferred (for example, Tenant X).
[0017] The relationship between the user terminal 20 and the user does not have to be one-to-one. That is, the user terminal 20 may be shared by multiple users.
[0018] 2 is a diagram showing an example of the hardware configuration of the information processing device 10 according to the first embodiment. The information processing device 10 in FIG. 2 includes a drive device 100, an auxiliary storage device 102, a memory device 103, a CPU 104, and an interface device 105, which are all interconnected via a bus B.
[0019] A program for realizing processing in the information processing device 10 is provided by a recording medium 101 such as a CD-ROM. When the recording medium 101 storing the program is set in the drive device 100, the program is installed from the recording medium 101 to the auxiliary storage device 102 via the drive device 100. However, the program does not necessarily have to be installed from the recording medium 101, but may be downloaded from another computer via a network. The auxiliary storage device 102 stores the installed program as well as necessary files, data, etc.
[0020] When an instruction to start a program is received, the memory device 103 reads the program from the auxiliary storage device 102 and stores it. The CPU 104 executes functions related to the information processing device 10 in accordance with the program stored in the memory device 103. The interface device 105 is used as an interface for connecting to a network.
[0021] Fig. 3 is a diagram showing an example of the functional configuration of the information processing device 10 in the first embodiment. In Fig. 3, the information processing device 10 has a login request receiving unit 11, a login candidate searching unit 12, and a login target selecting unit 13. Each of these units is realized by a process executed by the CPU 104 of one or more programs installed in the information processing device 10. The information processing device 10 also uses a user information storage unit 121. The user information storage unit 121 can be realized using, for example, the auxiliary storage device 102, or a storage device connectable to the information processing device 10 via a network.
[0022] The login request receiving unit 11 receives a login request sent from the user terminal 20. The login request includes the user's email address and password. Here, the email address is an example of identification information used for login. However, the identification information used for login is not limited to the email address, and may be any information that can identify the user, such as a name, telephone number, or ID.
[0023] The login candidate search unit 12 searches for a candidate entry that is permitted to log in based on the login request from among the entries (user information) stored in the user information storage unit 121.
[0024] The login target selection unit 13 selects one entry related to a user who is permitted to log in from the entries searched for by the login candidate search unit 12.
[0025] The following describes the processing procedure executed by the information processing device 10. Fig. 4 is a diagram for explaining an example of the processing procedure executed by the information processing device 10 in the first embodiment.
[0026] When a user logs in to the information processing device 10, the user terminal 20 displays, in response to the user's operation, a login screen such as that shown in Fig. 5. When the user inputs an email address and a password into the login screen, the user terminal 20 transmits a login request including the email address and the password to the information processing device 10.
[0027] In step S101, the login request receiving unit 11 receives the login request. Subsequently, the login candidate searching unit 12 searches the user information storage unit 121 for candidates (hereinafter referred to as "candidate entries") for entries that are permitted to log in based on the login request, among the entries (user information) stored in the user information storage unit 121 (S102).
[0028] Fig. 6 is a diagram illustrating an example of the configuration of the user information storage unit 121. As illustrated in Fig. 6, the user information storage unit 121 stores entries including an email address, a password, a creation date and time, a login date and time, etc. for each pair of a tenant ID and a user ID.
[0029] The tenant ID is identification information of the tenant to which the user belongs. The user ID is identification information used by the information processing device 10 to identify each user. Note that the user ID may be unique across all tenants or may be unique within a tenant. The email address is an email address used as identification information of the user when logging in. The password is a character string used to verify the legitimacy of the user when logging in. The creation date and time is the date and time when the entry is stored in the user information storage unit 121. In other words, the creation date and time is the date and time when the email address, password, etc. are stored in the user information storage unit 121. The login date and time is the date and time when the user last logged in.
[0030] There is a one-to-one correspondence between email addresses and users. In other words, in the user information storage unit 121, entries with a common email address correspond to the same user but belong to different tenants.
[0031] For example, Figure 6 shows four entries with the email address "yamada@abc.com." These are entries for one user who has yamada@abc.com as their email address. In this way, in this embodiment, duplicate email addresses are allowed between entries.
[0032] In addition, duplicate passwords are permitted between entries with the same email address. For example, in the example of Figure 6, among the entries with the email address "yamada@abc.com", the password is the same "AAAAAA1234" between two entries with tenant IDs "11111111" and "222222222".
[0033] In the first embodiment, entries whose email address and password stored in the user information storage unit 121 match the email address and password included in the login request are searched for as candidate entries.
[0034] If there is no candidate entry (No in S103), the login candidate search unit 12 transmits a response indicating that the login has failed to the user terminal 20 (S104). In this case, upon receiving the response, the user terminal 20 redisplays the login screen (FIG. 5).
[0035] If there is one or more candidate entries (Yes in S103), the login candidate search unit 12 acquires a list of each candidate entry (hereinafter referred to as a "candidate entry list") from the user information storage unit 121 (S105).
[0036] Next, the login target selection unit 13 determines whether the candidate entry list includes a plurality of candidate entries (S106). If the candidate entry list includes one candidate entry (No in S106), the login target selection unit 13 selects the candidate entry as the entry related to the login user (S107). The login target selection unit 13 updates the login date and time of the entry related to the login user to the current date and time in the user information storage unit 121 (FIG. 6).
[0037] On the other hand, if there are multiple candidate entries included in the candidate entry list (Yes in S106), the login target selection unit 13 generates information (screen data of an entry selection screen) including pairs of tenant IDs and user IDs of each of the multiple candidate entries as options, and transmits the screen data to the user terminal 20 that has transmitted the login request (S108). The user terminal 20 displays the entry selection screen based on the screen data.
[0038] Fig. 7 is a diagram showing a display example of an entry selection screen in the first embodiment. As shown in Fig. 7, the entry selection screen 510 includes a tenant ID, a user ID, and a selection button 511 for each candidate entry. Fig. 7 shows a display example of the entry selection screen 510 when the email address included in the login request is "yamada@abc.com" and the password is "AAAAAA1234". Therefore, in the user information storage unit 121 (Fig. 6), the tenant IDs and user IDs of the two candidate entries corresponding to the email address and password are made available as options.
[0039] When a user selects a selection button 511 corresponding to a desired tenant ID and user ID (for example, the tenant ID and user ID that the user wants to log in to this time) from the list of tenant IDs and user IDs displayed on the entry selection screen 510, the user terminal 20 sends the selection result including the tenant ID and user ID to the login target selection unit 13.
[0040] In step S109, the login target selection unit 13 receives the selection result. Subsequently, the login target selection unit 13 selects a candidate entry related to the tenant ID and user ID included in the selection result as an entry related to the login user (S110). The login target selection unit 13 updates the login date and time of the entry related to the login user to the current date and time in the user information storage unit 121 (FIG. 6).
[0041] As described above, according to the first embodiment, it is possible to allow the same identification information to be used for login between different tenants.
[0042] Next, a second embodiment will be described. In the second embodiment, differences from the first embodiment will be described. Therefore, unless otherwise specified, the second embodiment may be the same as the first embodiment.
[0043] Fig. 8 is a diagram showing an example of the functional configuration of the information processing device 10 according to the second embodiment. In Fig. 8, the same components as those in Fig. 2 are denoted by the same reference numerals, and their description will be omitted.
[0044] 8, in the second embodiment, the information processing device 10 further uses a password policy storage unit 122. The password policy storage unit 122 can be realized using, for example, the auxiliary storage device 102 or a storage device connectable to the information processing device 10 via a network.
[0045] The password policy storage unit 122 stores, for each tenant, the password policy defined for that tenant. A password policy is information that indicates constraints on the configuration of a password. More specifically, a password policy is information that indicates conditions regarding the number of characters that can be used in a password, the combination of characters, and so on.
[0046] FIG. 9 is a diagram illustrating an example of the configuration of the password policy storage unit 122. As illustrated in FIG. 9, the password policy storage unit 122 stores, in association with a tenant ID, a password policy defined for a tenant associated with the tenant ID. FIG. 9 illustrates an example in which the password length, whether numbers are required, and whether symbols are required are components of a password policy. The password length is a provision regarding the number of characters in a password. Whether numbers are required is whether one or more numbers are required to be included in the password. Whether symbols are required is whether one or more symbols are required to be included in the password. Note that the password policy illustrated in FIG. 9 is merely an example. A password policy configured with other components may also be used.
[0047] In the second embodiment, the basic processing procedure executed by the information processing device 10 is the same as the processing procedure shown in Fig. 4. However, in the second embodiment, the definition of the candidate entry searched for in step S102 in Fig. 4 is different from that in the first embodiment. Specifically, in step S102, the login candidate search unit 12 searches, as a candidate entry, for an entry whose email address stored in the user information storage unit 121 corresponds to the email address included in the login request and whose password policy of the tenant related to the entry matches the password included in the login request.
[0048] In this case, in step S108, the login target selection unit 13 generates screen data for an entry selection screen 510 as shown in FIG. 10. FIG. 10 is a display example of the entry selection screen 510 when the email address included in the login request is "yamada@abc.com" and the password is "AAAAAA1234." There are four entries including the email address in the user information storage unit 121 (FIG. 6). Of the password policies of the tenants (FIG. 9) associated with the tenant IDs of these four entries, the password policy that conforms to "AAAAAA1234" (satisfied by "AAAAAA1234") is the password policy of the tenant associated with the tenant IDs "11111111," "22222222," or "333333333." Therefore, the three entries associated with any of these three tenants correspond to candidate entries. Therefore, the entry selection screen 510 in FIG. 10 includes the tenant ID, user ID, etc. of the candidate entry.
[0049] As described above, according to the second embodiment, it is possible to obtain the same effects as in the first embodiment. Furthermore, not only entries that include a password that exactly matches the input password, but also entries whose password policy conforms to the input password can be set as candidate entries. Therefore, for example, by setting a password for one tenant, it is possible to log in to any of multiple tenants within the range of tenants corresponding to the password policy that conforms to the input password.
[0050] Next, a third embodiment will be described. In the third embodiment, differences from the first embodiment will be described. Therefore, points that are not particularly mentioned may be the same as those in the first embodiment.
[0051] In the third embodiment, the definition of the candidate entry searched for in step S102 of Fig. 4 is different from that in the first embodiment. Specifically, in step S102, the login candidate search unit 12 searches for an entry whose email address stored in the user information storage unit 121 matches the email address included in the login request as a candidate entry. That is, among the entries registered in the user information storage unit 121, if the entry has an email address that matches the login request, it is searched for as a candidate entry even if the password is different from the password in the login request.
[0052] In this case, in step S108, the login target selection unit 13 transmits screen data of an entry selection screen 510 as shown in Fig. 11 to the user terminal 20. Fig. 11 is a display example of the entry selection screen 510 when the email address included in the login request is "yamada@abc.com". Therefore, in the user information storage unit 121 (Fig. 6), the tenant IDs and user IDs of the four candidate entries corresponding to the email address are set as options.
[0053] As described above, according to the third embodiment, it is possible to obtain the same effect as in the first embodiment. Furthermore, if the password matches the password set in any of the entries registered for different tenants and having the same identification information (email address), it is possible to log in as any user of the entries.
[0054] Next, a fourth embodiment will be described. In the fourth embodiment, differences from the first to third embodiments will be described. Therefore, unless otherwise specifically mentioned, the fourth embodiment may be the same as any of the first to third embodiments.
[0055] Fig. 12 is a diagram for explaining an example of a processing procedure executed by information processing device 10 in the fourth embodiment. In the fourth embodiment, information processing device 10 executes the processing procedure in Fig. 12 instead of the processing procedure in Fig. 4. In Fig. 12, the same steps as those in Fig. 4 are assigned the same step numbers, and their explanations will be omitted.
[0056] 12, steps S108 to S110 in Fig. 4 are replaced with step S111. In step S111, the login target selection unit 13 selects the candidate entry with the highest priority among multiple candidate entries as the entry related to the login user. The login target selection unit 13 updates the login date and time of the entry related to the login user to the current date and time in the user information storage unit 121 (Fig. 6).
[0057] Here, the priority of each candidate entry may be determined based on the order in which each candidate entry is stored (registered) in the user information storage unit 121. For example, the earlier (earlier) the creation date and time, the higher the priority. In this case, the login target selection unit 13 selects the candidate entry with the earliest creation date and time among the multiple candidate entries. Alternatively, the later (later) the creation date and time, the higher the priority. In this case, the login target selection unit 13 selects the candidate entry with the latest creation date and time among the multiple candidate entries.
[0058] Alternatively, the later the login date and time, the higher the priority. In this case, the login target selection unit 13 selects the candidate entry with the latest login date and time (the last selected candidate entry) from among the multiple candidate entries.
[0059] As described above, according to the fourth embodiment, it is possible to obtain the same effects as those of the first to third embodiments.
[0060] Furthermore, if the priority of entries with earlier creation dates and times is given higher, for example, even if entries with duplicate identification information (email addresses) are unintentionally created for multiple tenants, the user can still log in as a user of the tenant they previously used.
[0061] Furthermore, if the priority of an entry with a later creation date and time is increased, for example, it may be possible to quickly log in using a newly created entry.
[0062] Furthermore, if the priority of an entry with a later login date and time is increased, for example, it is possible to facilitate login using the entry that the user uses most frequently.
[0063] The information processing device 10 or the user terminal 20 is not limited to a general-purpose computer such as a PC, as long as it is a device equipped with a communication function. The information processing device 10 may be, for example, an image forming device, a PJ (Projector), an IWB (Interactive White Board: a white board with an electronic blackboard function that allows mutual communication), an output device such as digital signage, a HUD (Head Up Display) device, industrial machinery, an imaging device, a sound collection device, medical equipment, a network home appliance, a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game console, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, a desktop PC, or the like.
[0064] The functions of the above-described embodiments can be realized by one or more processing circuits. Here, the term "processing circuit" in this specification includes a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, as well as devices such as an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and conventional circuit modules designed to execute each of the above-described functions.
[0065] In this embodiment, the login candidate search unit 12 is an example of a search unit, and the login target selection unit 13 is an example of a selection unit.
[0066] Although the embodiments of the present invention have been described in detail above, the present invention is not limited to such specific embodiments, and various modifications and variations are possible within the scope of the gist of the present invention as set forth in the claims. [Explanation of symbols]
[0067] 10. Information processing equipment 11 Login request receiver 12 Login candidate search section 13 Login target selection section 20 User terminal 100 Drive device 101 Recording media 102 Auxiliary storage device 103 Memory Device 104 CPU 105 Interface Device 121 User information storage unit 122 Password Policy Storage B Bus [Prior art documents] [Patent documents]
[0068] [License 1] Patent No. 6476760
Claims
1. a storage unit that stores user information including an email address and a password used by each user to log in, the storage unit storing multiple pieces of user information with overlapping email addresses and different passwords; a search unit that, in response to a login request including an email address and a password, retrieves user information including an email address that matches the email address included in the login request from the storage unit; a selection unit that, when a plurality of pieces of user information are acquired by the search unit, selects one piece of user information from the plurality of pieces of user information as user information related to a user who is permitted to log in; An information processing device comprising:
2. the selection unit transmits information having the plurality of pieces of user information as options to a terminal that has transmitted the login request, and selects the user information selected from the plurality of pieces of user information at the terminal as user information related to the user who is permitted to log in.
2. The information processing apparatus according to claim 1, wherein:
3. the selection unit selects one piece of user information from the plurality of pieces of user information based on the order in which the email addresses and passwords are stored in the storage unit.
2. The information processing apparatus according to claim 1, wherein:
4. the selection unit selects the last selected user information from the plurality of pieces of user information.
2. The information processing apparatus according to claim 1, wherein:
5. the search unit retrieves, from the storage unit, user information including an email address and a password that match the email address and password included in the login request; 4. The information processing apparatus according to claim 1, wherein the information processing apparatus is a computer.
6. the search unit acquires user information of a user corresponding to an email address included in the login request, the user information having a password policy for the user that matches the password included in the login request; 4. The information processing apparatus according to claim 1, wherein the information processing apparatus is a computer.
7. A storage unit that stores user information including identification information and passwords used by each user to log in, the storage unit storing multiple pieces of user information in which the identification information overlaps and the passwords are different; a search unit that, in response to a login request including identification information and a password, retrieves user information including identification information that matches the identification information included in the login request from the storage unit; a selection unit that, when a plurality of pieces of user information are acquired by the search unit, selects one piece of user information from the plurality of pieces of user information as user information related to a user who is permitted to log in; and the search unit retrieves the user information from the storage unit if the user information includes identification information that matches the identification information included in the login request, even if the user information includes a password that is different from the password included in the login request.
1. An information processing device comprising:
8. A storage unit that stores user information including an email address and a password used by each user to log in in response to a login request including an email address and a password, wherein the storage unit stores multiple pieces of user information with overlapping email addresses and different passwords, and a search procedure that retrieves user information including an email address that matches the email address included in the login request from the storage unit that stores multiple user information with overlapping email addresses and different passwords; a selection step of selecting, when a plurality of pieces of user information are acquired by the search step, any one piece of user information from the plurality of pieces of user information as user information relating to a user who is permitted to log in; An information processing method characterized by being executed by a computer.
9. A storage unit that stores user information including an email address and a password used by each user to log in in response to a login request including an email address and a password, wherein the storage unit stores multiple pieces of user information with overlapping email addresses and different passwords, and a search procedure that retrieves user information including an email address that matches the email address included in the login request from the storage unit that stores multiple user information with overlapping email addresses and different passwords; a selection step of selecting, when a plurality of pieces of user information are acquired by the search step, any one piece of user information from the plurality of pieces of user information as user information relating to a user who is permitted to log in; A program characterized by causing a computer to execute the above.
Citation Information
Patent Citations
Manufacture of semiconductor device
JP1989076760A
Peripheral equipment device, its control method, and program for making computer execute processing at the peripheral equipment device
JP2007094541A
Image forming apparatus, and computer program
JP2011004087A
Information processing unit, system, and information providing method
JP2014089678A
Connection destination solution system and method
JP2015109015A