Information processing system, display method, and service provision system

The information processing system addresses the challenge of displaying operable targets by using an authority information storage unit and authentication processing to ensure only permitted files and folders are displayed, simplifying user interactions with external service systems.

JP7793948B2Active Publication Date: 2026-01-06RICOH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021185744
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-15
Publication Date
2026-01-06
Estimated Expiration
2041-11-15

AI Technical Summary

Technical Problem

Conventional technologies fail to display operation targets that can be operated by an application among operation targets of an external service system, requiring dedicated implementation for each external service system, which is time-consuming.

Method used

An information processing system that includes an authority information storage unit, an authentication processing unit, and a screen generation unit to display operation objects that can be operated by an application, based on user access rights and permissions stored in the authority information storage unit.

Benefits of technology

Enables the display of operation targets that can be operated by an application, ensuring only permitted files and folders are shown, thereby simplifying user interactions with external service systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007793948000001
    Figure 0007793948000001
  • Figure 0007793948000002
    Figure 0007793948000002
  • Figure 0007793948000003
    Figure 0007793948000003
Patent Text Reader

Abstract

To provide an information processing system, a display method, and a service providing system that display, of operation objects in an external service system, an operation object that can be operated by an application.SOLUTION: An information processing system 10 is such that an application operates an operation object in an external service system 40, and the system has: an authority information storage unit 42 that stores authority information in which the authority set to the operation object and whether the operation can be performed are associated with each other; an authentication processing unit 19 that performs processing related to authentication of a user; an external service processing unit 14 that acquires, from the external service system, a list of operation objects to which the user has an access authority in response to a request from an apparatus 20 that is one of various electronic apparatuses used by the user; and a screen generation unit 12 that provides the apparatus with screen information for displaying the list of operation objects permitted to be operated in the authority information storage unit for the authority set to the acquired operation objects.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system, a display method, and a service providing system. [Background technology]

[0002] Services that provide applications that combine multiple functions (e.g., scanning, saving to a folder, sending by email, etc.) are known. The processing performed by such services is called a workflow. Some workflows use external service systems, such as printing files stored in an external service system such as a storage server using a device such as an image forming device, or sending files to a folder in an external service system.

[0003] A technology for managing the destinations of electronic data used in a workflow has been devised (see, for example, Patent Document 1). Patent Document 1 discloses a system that stores information regarding the availability of delivery to folders in order to check whether folders that have been registered in advance as destinations for scanned images are currently available for delivery. Summary of the Invention [Problem to be solved by the invention]

[0004] However, conventional technologies have a problem in that they do not display operation targets that can be operated by an application among operation targets of an external service system. Specifically, workflow applications that link with external service systems perform operations such as downloading and uploading files. Generally, external service systems set permissions required for operations on files and folders to restrict the operations that users can perform on those files and folders. If an information processing system simply provides files and folders from external service systems, users may select files and folders that cannot be operated by an application. Avoiding this requires dedicated implementation for each external service system, which is time-consuming.

[0005] In view of the above-mentioned problems, an object of the present invention is to provide an information processing system that displays operation objects that can be operated by an application, among operation objects that an external service system has. [Means for solving the problem]

[0006] In view of the above problems, the present invention is an information processing system in which an application operates an operation object held by an external service system, characterized by comprising: an authority information storage unit that stores authority information in which the authority set for the operation object is associated with whether or not the operation can be performed; an authentication processing unit that performs processing related to user authentication; an external service processing unit that, in response to a request from a device, obtains from the external service system a list of the operation objects to which the user has access rights; and a screen generation unit that provides the device with screen information that displays a list of the operation objects for which operation is permitted in the authority information storage unit, based on the authority set for the obtained operation object. [Effects of the Invention]

[0007] It is possible to provide an information processing system that displays operation targets that can be operated by an application, among operation targets possessed by an external service system. [Brief explanation of the drawings]

[0008] [Figure 1] FIG. 2 is a diagram illustrating the relationship between components and applications. [Figure 2] FIG. 2 is a diagram illustrating an outline of processing performed by the service providing system. [Figure 3] FIG. 1 illustrates a system configuration of an example of a service providing system. [Figure 4] FIG. 2 is a diagram illustrating an example of a hardware configuration of an information processing system and a terminal device. [Figure 5] FIG. 2 is a diagram illustrating a hardware configuration of an image forming apparatus, which is an example of a device. [Figure 6] FIG. 1 illustrates a functional configuration of an example of a service providing system. [Figure 7] FIG. 4 is a diagram illustrating an example of user information stored in a user information storage unit. [Figure 8] FIG. 10 is a diagram illustrating an example of authority information stored in an authority information storage unit. [Figure 9] FIG. 10 is a diagram showing an example of a name registration screen for registering the name of an authority. [Figure 10] FIG. 10 is a sequence diagram illustrating an example of a process in which the information processing system performs various operations on files / folders prepared in advance, and stores the operation results in association with the permissions. [Figure 11] FIG. 10 is a diagram showing an example of a list of files / folders and permissions set for the files / folders, which are acquired from an external service system. [Figure 12] FIG. 10 is a sequence diagram illustrating an example of a process for displaying only files / folders that can be operated by an application executed by a user, using pre-stored authority information. [Figure 13] FIG. 10 is a diagram illustrating an example of authority information acquired from an external service system. [Figure 14] FIG. 10 is a diagram illustrating an example of a determination result by an application executing unit. [Figure 15] FIG. 10 is a diagram showing an example of a file / folder display screen displayed by the device. [Figure 16] FIG. 10 is a sequence diagram illustrating an example of a process for updating authority information based on the execution result when a device executes an application. [Figure 17] FIG. 10 is a diagram illustrating a functional configuration of an example of a service providing system (embodiment 2). [Figure 18] FIG. 10 is a sequence diagram illustrating an example of a process in which the information processing system performs various operations on files / folders prepared in advance, and associates and saves the operation results with the authority (second embodiment). [Figure 19] FIG. 11 is a sequence diagram illustrating an example of a procedure in which an administrator updates authority information (third embodiment). [Figure 20] FIG. 11 is a diagram illustrating an example of a request body of authority information transmitted from a terminal device to an information processing system (third embodiment). [Figure 21] FIG. 11 is a diagram showing an example of an authority information setting screen displayed on the terminal device (third embodiment); [Figure 22] FIG. 11 is a sequence diagram illustrating an example of a process for updating authority information based on the execution result when a device executes an application (Fourth Embodiment). [Figure 23] FIG. 10 is a diagram illustrating a functional configuration of an example of a service providing system (embodiment 5). [Figure 24] FIG. 13 is a diagram illustrating an example of component information stored in a component information storage unit (Example 5). [Figure 25] FIG. 13 is a sequence diagram illustrating an example of a process for updating authority information based on the execution result when a device executes an application (Fifth Embodiment). [Figure 26] FIG. 10 is a diagram illustrating a functional configuration of an example of a service providing system (Example 6). [Figure 27] FIG. 13 is a diagram showing an example of an execution history stored in an execution history storage unit (Example 6). [Figure 28] FIG. 13 is a sequence diagram illustrating an example of a process for updating authority information based on the execution result when a device executes an application (sixth embodiment). DETAILED DESCRIPTION OF THE INVENTION

[0009] DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS An information processing system and a display method performed by the information processing system will be described below as an example of an embodiment of the present invention with reference to the accompanying drawings. [Example]

[0010] <Processing Overview> First, a further explanation of the workflow will be provided with reference to Figure 1. Figure 1 is a diagram illustrating the relationship between a component 201 and an application 202. In this embodiment, an application 202 is created by combining multiple components 201. A component 201 is a program part prepared for each function or processing unit. As shown in Figure 1(a), components 201 are provided that upload and download files to various external service systems, and that apply OCR, stamps, and PDF-related processing to files.

[0011] 1(b), one or more components 201 are arranged in the order of execution to create an application 202. A workflow is executed by executing the application 202.

[0012] FIG. 2 is a diagram for explaining an outline of the processing performed by the service providing system of this embodiment.

[0013] (1) The information processing system 10 performs various operations on files / folders that can be displayed using a pre-prepared administrator account. Permissions required for operations are set for files / folders. Operations are general processes that can be performed on files and folders, such as uploading, downloading, deleting, editing, and editing metadata.

[0014] (2) The information processing system 10 stores the authority required for a file or folder in association with the results of various operations that are actually performed.

[0015] (3) The user executes a desired application and inputs an operation to the device 20 requesting a list of files / folders that the user will operate with the application.

[0016] (4) The application requests a list of files / folders from the information processing system 10.

[0017] (5) The information processing system 10 obtains files / folders that the user can display (to which the user has access rights) from the external service system 40, and uses the saved operation results to send only files / folders that can be operated based on the permissions of the files / folders to the device 20. This allows the device 20 to display only files / folders that can be operated based on the permissions set for the files / folders when executing an application.

[0018] In this way, the information processing system 10 of this embodiment performs operations such as uploading and downloading to folders / files for which the administrator has various permissions and stores the operation results, so that permissions can be associated with whether or not an operation is permitted. Therefore, when a user runs an application, the information processing system 10 can provide the device 20 with only files / folders that the user can operate.

[0019] <Terminology> An application is a program that runs on a device or information processing device so that a user can receive a service. There are two types of applications: web apps that run in cooperation between a web browser and a server-side program, and native apps that run on an information processing device without requiring a server (although communication is permitted). In the case of web apps, the application may be a workflow app that executes a series of processes in order.

[0020] An application includes one or more processes. A process may be information processing that compiles a certain amount of functionality so that the application can output a desired result. In this embodiment, the information processing executed by a component or the component itself corresponds to a process.

[0021] File browsing is a file / folder operation method that displays a list of files or a folder structure on a display and accepts their selection.

[0022] The operation target is data that is held by an external service system and that is operated by an application. In this embodiment, this is explained using the terms file / folder.

[0023] Permissions are attributes of an operator that are required to perform operations on a file / folder. Permissions are set for files / folders. Files may also be called directories.

[0024] A file / folder to which a user has access rights is a file / folder that the logged-in user can view, edit, or delete. For example, it is a file / folder that the user owns and a shared file / folder that is shared within the tenant. In this embodiment, it is simply described as a "file / folder that the user can view."

[0025] <System configuration> The system configuration of the service providing system 100 according to this embodiment will be described with reference to Fig. 3. Fig. 3 is a diagram showing an example of the system configuration of the service providing system 100 according to this embodiment.

[0026] 3 includes an information processing system 10, a device 20, and a terminal device 30, which are communicatively connected via a wide area network N1 such as the Internet. The service providing system 100 communicates with an external service system 40, which is an external system.

[0027] The information processing system 10 is realized by one or more information processing devices, and provides various services via a network N1 that are realized by a series of processes in cooperation with an external service system 40, such as a cloud service. Specific examples of services provided by the information processing system 10 according to this embodiment will be described later. The information processing system 10 may be realized by cloud computing, or may be realized by a single information processing device. Cloud computing refers to a form in which resources on a network are used without regard to specific hardware resources. The information processing system 10 may exist on the Internet or on-premise. A series of processes is provided by a single application, and such a series of processes is also referred to as a "processing flow" or "workflow."

[0028] The devices 20 are various electronic devices used by users. The devices 20 are, for example, image forming devices such as MFPs (Multifunction Peripherals), PCs (Personal Computers), projectors, electronic whiteboards, video conference terminals, digital cameras, etc. The devices 20 are connected to the network N2. The users can use the devices 20 to utilize various services provided by the information processing system 10 or the external service system 40.

[0029] In the following description, when a plurality of devices 20 are to be distinguished from one another, they will be referred to using subscripts such as "device 201" and "device 202."

[0030] The terminal device 30 is, for example, a desktop PC, a notebook PC, a smartphone, a tablet terminal, or the like used by an administrator or a user. The terminal device 30 is connected to the network N2. The administrator or user can operate the terminal device 30 to use various services provided by the information processing system 10 or the external service system 40, and can also configure applications.

[0031] In the following description, when distinguishing between the multiple terminal devices 30, they will be referred to using subscripts such as "terminal device 301" and "terminal device 302."

[0032] The external service system 40 is one or more information processing devices that provide services by executing applications via the network N1. Data is saved or read by executing the applications. The "external" in the external service system 40 means that it is a system separate from the information processing system 10. In many cases, it is operated by a different company. For example, even for the same user, the external service system 40 and the information processing system 10 have different accounts.

[0033] Examples of the external service system 40 include various cloud services, ASPs (Application Service Providers), and the like, and may include various external services provided via a network. For example, a storage service is an example of a service. The external service system 40 may exist on the Internet or on-premise.

[0034] In the following description, when distinguishing between the multiple external service systems 40, they will be referred to as "external service system 401," "external service system 402," etc., as shown in the figure.

[0035] <Hardware configuration example> The hardware configuration of the information processing system 10 and the terminal device 30 according to this embodiment will be described with reference to FIG.

[0036] <<Information processing system and terminal device>> Fig. 4 is a diagram showing an example of the hardware configuration of the information processing system 10 and the terminal device 30 according to this embodiment. As shown in Fig. 4, the information processing system 10 and the terminal device 30 are constructed by a computer, and include a CPU 501, a ROM 502, a RAM 503, a HD (Hard Disk) 504, an HDD (Hard Disk Drive) controller 505, a display 506, an external device connection I / F (Interface) 508, a network I / F 509, a bus line 510, a keyboard 511, a pointing device 512, a DVD-RW (Digital Versatile Disk Rewritable) drive 514, and a media I / F 516.

[0037] Of these, the CPU 501 controls the overall operation of the information processing system 10 and the terminal device 30. The ROM 502 stores programs, such as an IPL, used to drive the CPU 501. The RAM 503 is used as a work area for the CPU 501. The HD 504 stores various data, such as programs. The HDD controller 505 controls the reading and writing of various data from and to the HD 504 under the control of the CPU 501. The display 506 displays various information, such as a cursor, menus, windows, characters, or images. The external device connection I / F 508 is an interface for connecting various external devices. In this case, external devices include, for example, USB (Universal Serial Bus) memories and printers. The network I / F 509 is an interface for data communication using the network N2. The bus line 510 is an address bus, a data bus, or the like, for electrically connecting the components, such as the CPU 501, shown in FIG. 4.

[0038] The keyboard 511 is a type of input means having multiple keys used to input characters, numbers, various instructions, etc. The pointing device 512 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The DVD-RW drive 514 controls reading and writing of various data from a DVD-RW 513, which is an example of a removable recording medium. The DVD-RW drive 514 is not limited to a DVD-RW, and may be a DVD-R or the like. The media I / F 516 controls reading and writing (storing) of data from a recording medium 515, such as a flash memory.

[0039] <<Equipment>> 5 is a hardware configuration diagram of an image forming apparatus, which is an example of device 20. As shown in FIG. 5, the image forming apparatus includes a controller 910, a short-range communication circuit 920, an engine control unit 930, an operation panel 940, and a network I / F 950.

[0040] Of these, the controller 910 has a CPU 901, which is the main part of the computer, a system memory (MEM-P) 902, a north bridge (NB) 903, a south bridge (SB) 904, an ASIC (Application Specific Integrated Circuit) 906, a local memory (MEM-C) 907, which is a storage unit, an HDD controller 908, and an HD 909, which is also a storage unit, and is configured such that the NB 903 and the ASIC 906 are connected by an AGP (Accelerated Graphics Port) bus 921.

[0041] Of these, the CPU 901 is a control unit that performs overall control of the image forming apparatus. The NB 903 is a bridge that connects the CPU 901 with the MEM-P 902, the SB 904, and the AGP bus 921, and includes a memory controller that controls reading and writing to the MEM-P 902, a PCI (Peripheral Component Interconnect) master, and an AGP target.

[0042] The MEM-P 902 comprises a ROM 902a, which is memory for storing programs and data that realize the functions of the controller 910, and a RAM 902b, which is used for expanding the programs and data and as a drawing memory during memory printing. The programs stored in the RAM 902b may be provided by being recorded in an installable or executable file format on a computer-readable recording medium such as a CD-ROM, CD-R, or DVD.

[0043] The SB 904 is a bridge for connecting the NB 903 with PCI devices and peripheral devices. The ASIC 906 is an integrated circuit (IC) for image processing applications that has hardware elements for image processing and serves as a bridge connecting the AGP bus 921, PCI bus 922, HDD controller 908, and MEM-C 907. The ASIC 906 includes a PCI target and AGP master, an arbiter (ARB) that forms the core of the ASIC 906, a memory controller that controls the MEM-C 907, multiple direct memory access controllers (DMACs) that perform image data rotation using hardware logic, and a PCI unit that transfers data between the scanner unit 931, printer unit 932, and facsimile unit via the PCI bus 922. The ASIC 906 may also have a universal serial bus (USB) interface or an Institute of Electrical and Electronics Engineers 1394 (IEEE 1394) interface.

[0044] The MEM-C907 is a local memory used as an image buffer for copying and a code buffer. The HD909 is a storage for storing image data, font data used during printing, and forms. The HD909 controls the reading and writing of data from and to the HD909 under the control of the CPU901. The AGP bus 921 is a bus interface for a graphics accelerator card proposed to speed up graphics processing, and direct high-throughput access to the MEM-P902 enables the graphics accelerator card to operate at high speed.

[0045] Further, the short-range communication circuit 920 is provided with a short-range communication circuit antenna 920a. The short-range communication circuit 920 is a communication circuit such as NFC or Bluetooth (registered trademark).

[0046] The engine control unit 930 further includes a scanner unit 931, a printer unit 932, and a facsimile unit 933. The operation panel 940 includes a panel display unit 940a, such as a touch panel, that displays current setting values ​​and selection screens and receives inputs from the operator, and hard keys 940b, such as a numeric keypad that receives setting values ​​for image formation conditions such as density settings and a start key that receives a copy start command. The controller 910 controls the entire image forming apparatus, and controls, for example, drawing, communication, and inputs from the operation panel 940. The scanner unit 931 or the printer unit 932 includes an image processing unit such as error diffusion and gamma conversion.

[0047] The image forming apparatus can be switched between the document box function, copy function, printer function, and facsimile function in sequence using the application switching key on the operation panel 940. When the document box function is selected, the image forming apparatus enters document box mode, when the copy function is selected, the image forming apparatus enters copy mode, when the printer function is selected, the image forming apparatus enters printer mode, and when the facsimile mode is selected, the image forming apparatus enters facsimile mode.

[0048] The network I / F 950 is an interface for performing data communication using the network N2. The short-range communication circuit 920 and the network I / F 950 are electrically connected to the ASIC 906 via a PCI bus 922.

[0049] <About the function> Next, the functional configuration of the service providing system 100 according to this embodiment will be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the functional configuration of the service providing system 100 according to this embodiment.

[0050] <<Equipment>> The device 20 has a second communication unit 21, a display control unit 22, an operation reception unit 23, an image data generation unit 24, a facsimile processing unit 25, and an email processing unit 26. Each of these functional units is a function or means realized by the CPU 901 executing instructions contained in one or more programs installed in the device 20. For example, the second communication unit 21, the display control unit 22, and the operation reception unit 23 are realized by a web browser, and the others are realized by individual applications (native apps).

[0051] The second communication unit 21 transmits and receives various types of information to and from the information processing system 10. In this embodiment, the second communication unit 21 receives screen information of various screens and the like from the information processing system 10, and transmits application execution requests and the like to the information processing system 10. The second communication unit 21 also receives a list of files / folders from the information processing system 10.

[0052] The display control unit 22 interprets screen information of various screens and displays it on the panel display unit 940a. The operation receiving unit 23 receives various operations by the user on the various screens displayed on the panel display unit 940a.

[0053] When the application selected by the operation receiving unit 23 is one that generates image data, the image data generating unit 24 generates image data by scanning an original document with the scanner unit 931. The facsimile processing unit 25 performs processing related to the reception and transmission of facsimiles by the facsimile unit 933, and when a facsimile is received, requests the information processing system 10 to execute a pre-associated application. The facsimile processing unit 25 may also request an application corresponding to the sender of the facsimile (fax number).

[0054] The email processing unit 26 performs processing related to sending and receiving emails, and when an email is received, requests the information processing system 10 to execute a pre-associated application. The email processing unit 26 may also request an application corresponding to the sender (email address) of the email.

[0055] <<Terminal Device>> The terminal device 30 has a first communication unit 31, a display control unit 32, and an operation reception unit 33. Each of these functional units is a function or means realized by the CPU 501 executing instructions contained in one or more programs installed in the terminal device 30. The programs may be a web browser or dedicated software.

[0056] The first communication unit 31 transmits and receives various information to and from the information processing system 10 or the external service system 40. In this embodiment, the first communication unit 31 requests the information processing system 10 to execute an authority pre-verification app that stores authority and whether or not an operation is possible. In addition, the first communication unit 31 registers the name of the authority in each external service system 40 in the information processing system 10.

[0057] The display control unit 32 interprets screen information of various screens and displays it on the display 506. The operation receiving unit 33 receives various operations on the various screens displayed on the display 506 by the application developer.

[0058] <<Information Processing System>> The information processing system 10 includes a third communication unit 11, a screen generation unit 12, an application execution unit 13, an external service processing unit 14, an authentication processing unit 19, a user information storage unit 41, and an authority information storage unit 42. Each of these functional units is a function or means realized by a CPU 501 shown in Fig. 4 executing instructions included in one or more programs installed in the information processing system 10. The user information storage unit 41 and the authority information storage unit 42 are constructed in the HD 504 shown in Fig. 4 or the like.

[0059] The third communication unit 11 transmits and receives various information between the terminal device 30 and the device 20. In this embodiment, when an application is executed, the third communication unit 11 transmits a list of applications to the device 20 or the terminal device 30 and receives a request to execute the application. In addition, the third communication unit 11 transmits to the device 20 a list of files / folders that the application can operate.

[0060] The screen generator 12 generates screen information to be displayed by the terminal device 30 when an application is created, and generates screen information for a screen to be displayed by the device 20 when the application is executed. The screen information is a program written in HTML, XML, a scripting language, CSS (Cascading Style Sheet), etc., with the structure of a web page being specified primarily by HTML, the behavior of the web page being defined by the scripting language, and the style of the web page being specified by CSS.

[0061] The application execution unit 13 manages the definition of an application that combines components, and executes the application by calling the components in the order of execution.

[0062] The external service processing unit 14 communicates with an API (Application Interface) of the external service system 40 and performs various operations on files / folders that the external service system 40 has.

[0063] The authentication processing unit 19 performs user authentication using user information. User authentication may not be performed by the information processing system 10, but may be performed by an external authentication device or by using a mechanism such as OAUTH.

[0064] 7 is an example of user information stored in the user information storage unit 41. The user information includes account information in the information processing system 10 and account information for each external service system 40, in association with each other. Therefore, when a login user who has logged in to the information processing system 10 is identified, the account information of this user in the external service system 40 is also identified.

[0065] The account information in the external service system 40 may be a user ID (user name) and password, or a token issued by the external service system 40. In the external service system 40, authorization information for a user is determined according to the user's account information (including the token). The authorization information determines which files / folders the user can display among the files / folders held by the external service system 40.

[0066] 8 shows the authority information stored in the authority information storage unit 42. The authority information registers whether various operations on files / folders can be performed in association with the authority set for the files / folders owned by the external service system 40.

[0067] The external service system ID is identification information of the external service system 40 .

[0068] Permissions are rights required for files / folders. Permissions include download, upload, admin, read, and write. The types of permissions available may vary depending on the external service system 40. On the other hand, there are permissions common to many external service systems 40, such as download and upload, but the names of the download and upload permissions often differ depending on the external service system 40. For this reason, the administrator registers the names of each permission in advance in the information processing system 10 for each external service system 40 (see FIG. 9).

[0069] Upload, download, delete, edit, and edit metadata are examples of operations performed on files / folders. True indicates permission, and False indicates restriction (prohibition).

[0070] <Registering the name of the authority in the external service system> Next, a method for registering the name of each authority for the external service system 40 will be described with reference to Fig. 9. Fig. 9(a) is a diagram illustrating a name registration screen 210 for registering the name of an authority. The name registration screen 210 is provided to the terminal device 30 from the information processing system 10. The administrator connects the terminal device 30 to the information processing system 10 and causes the name registration screen 210 to be displayed.

[0071] The name registration screen 210 has a list field 211 of external service systems 40 and a field 212 for the name of access authority. The administrator selects an external service system 40 in the list field 211 of external service systems 40. Then, the administrator inputs name registration information for registering the name of the authority in, for example, JSON format, into the field 212 for the name of access authority. In FIG. 9( a), "right" is the name of the authority. The administrator indicates that "right" represents the authority by associating it with a predetermined keyword, "#target." When the administrator presses the save button 213, the name of the authority in the external service system 40 is registered in the information processing system 10.

[0072] Note that the JSON format is just an example, and the name registration information may be in XML, or in CSV or a table in which "right" and "#target" are associated with each other.

[0073] 9(b) is also a diagram illustrating a name registration screen 220 for registering the name of an authority. The name registration screen 220 in FIG. 9(b) has a list field 221 of the external service system 40, an item list acquisition button 222, an item acquisition information display field 223, an import button 225, and an access authority name field 224. As shown in FIG. 7, the administrator has registered authentication information for the external service system 40 in the information processing system 10 in advance.

[0074] When the administrator presses the item list acquisition button 222, the information processing system 10 acquires a list of files / folders that the administrator can display and transmits it to the terminal device 30. The terminal device 30 displays the list of files / folders in an item acquisition information display field 223. The list of files / folders contains names representing permissions (here, "right"), so the administrator selects one. After the selection, when the administrator presses the import button 225, the terminal device 30 (or the information processing system 10 may convert it) generates name registration information in JSON format and displays it in the access permission name field 224. When the administrator presses the save button 226, the name of the permission in the external service system 40 is registered in the information processing system 10.

[0075] <Operation procedure> Next, the processing or operation performed by the information processing system 10 will be described with reference to FIGS.

[0076] <<Save permission information>> 10 is a sequence diagram showing a process in which the information processing system 10 performs various operations on files / folders prepared in advance, associates the operation results with the permissions, and saves them. For simplicity, the third communication unit 11 is omitted from the subsequent sequence diagrams including FIG. 10. The third communication unit 11 is used for communication with the terminal device 30 or the device 20.

[0077] 10 needs to be performed after preparatory work outside the system (creating a file / folder for an authority pre-verification application for which the administrator has set various authorities in the external service system 40), so the administrator may start the execution manually. However, as will be described in the second embodiment, the process may be automatically executed when the administrator registers the external service system 40 as a cooperation destination or as a periodic check.

[0078] S1: The administrator operates the terminal device 30 to connect to the information processing system 10, and performs an operation to request an administrator screen from the terminal device 30. The first communication unit 31 requests the information processing system 10 for the administrator screen.

[0079] S2: The third communication unit 11 of the information processing system 10 receives the request for the administrator screen, and if the administrator is not logged in, the screen generation unit 12 generates a login screen. The third communication unit 11 transmits screen information of the login screen to the terminal device 30.

[0080] S3: The first communication unit 31 of the terminal device 30 receives the screen information of the login screen, and the display control unit 32 displays the login screen. The administrator enters account information, so the first communication unit 31 specifies the account information and transmits a login request to the information processing system 10.

[0081] S4: The third communication unit 11 of the information processing system 10 receives the login request, and the authentication processing unit 19 performs authentication by referring to the user information. Here, it is assumed that the authentication is successful. The screen generation unit 12 generates a screen for the administrator. The third communication unit 11 transmits screen information of the screen for the administrator to the terminal device 30.

[0082] S5: The administrator specifies the external service system 40 on the administrator screen and inputs a command to start authority pre-verification. The operation reception unit 33 receives the operation, and the first communication unit 31 transmits a request for authority pre-verification to the information processing system 10.

[0083] S6: The third communication unit 11 of the information processing system 10 receives the request for authority pre-verification, and the screen generation unit 12 requests the application execution unit 13 to execute an application for authority pre-verification. The application for authority pre-verification is an application that creates the authority information of Fig. 8. The screen generation unit 12 specifies account information in the information processing system 10 and the external service system 40.

[0084] S7, S8: The application executing unit 13 first obtains, from the user information storage unit 41, the account information of the administrator in the external service system 40 that is associated with the account information in the information processing system 10.

[0085] S9, S10: Next, the application execution unit 13 is requested to execute the authority advance verification application, and therefore acquires a list of files / folders and the permissions set for the files / folders from the external service system 40. The files / folders and permissions for the authority advance verification application are registered in advance in the external service system 40. In other words, files / folders for creating permission information are prepared in advance.

[0086] Fig. 11 shows an example of a list of files / folders and the permissions set for the files / folders obtained from the external service system 40. Fig. 11 is in JSON format, and for each file / folder, file / folder names 231, 235, identification information 232, 236, file / folder distinctions 233, 237, and permissions 234, 238 are transmitted from the external service system 40. Note that the information in Fig. 11 transmitted from the external service system 40 is not limited to character strings, and may be numeric values ​​or symbols corresponding to the permissions.

[0087] S11, S12: Returning to FIG. 10, the explanation will be given. The application execution unit 13 performs all operations that an application can perform on files / folders acquired from the external service system 40. The application execution unit 13 performs, for example, all of uploading, downloading, deleting, editing, and metadata editing. All of these operations may be set in the permission advance verification application, or may be operations that can be performed by all components of the information processing system 10. For the sake of convenience of explanation, only uploading and downloading are shown in FIG. 10.

[0088] S13: If the operation is successful, the external service system 40 returns OK (operation successful) to the application execution unit 13.

[0089] S14, S15: The application execution unit 13 specifies the external service system ID, authority, type of operation, and operation result (permission), and writes the authority information into the authority information storage unit 42. Which information acquired from the external service system 40 is the authority is set for each external service system 40 as described above. For example, in the example of FIG. 9, "right" is the authority.

[0090] S16: If the operation fails, the external service system 40 returns NG (operation successful) to the external service processing unit 14. For example, in HTTP communication, 403 is notified. 403 indicates that although the resource exists, the accessing user does not have the authority to display the page (authorization error), so access has been denied.

[0091] S17, S18: The application executing unit 13 writes the authority information into the authority information storage unit 42 by specifying the external service system ID, authority, type of operation, and operation result (restriction).

[0092] S19: In the case of other errors, the authority cannot be verified, and therefore the application executing unit 13 does not store the authority information. With the above, the authority information as shown in FIG.

[0093] <<Displaying files / folders in external service systems>> Next, a method for displaying files / folders using permission information will be described with reference to Fig. 12. Fig. 12 is a sequence diagram showing a process for displaying only files / folders that can be operated by an application executed by a user, using permission information stored in advance.

[0094] S21: The user performs an operation to display an application screen on the device 20. The second communication unit 21 of the device 20 requests the application screen from the information processing system 10. The application screen is the main screen of an application that the user wants to execute.

[0095] S22: The third communication unit 11 of the information processing system 10 receives the request for the application screen, and if the user is not logged in, the screen generation unit 12 generates a login screen. The third communication unit 11 transmits screen information of the login screen to the device 20.

[0096] S23: The second communication unit 21 of the device 20 receives the screen information of the login screen, and the display control unit 22 displays the login screen. As the user enters account information, the second communication unit 21 designates the account information and transmits a login request to the information processing system 10.

[0097] S24: The third communication unit 11 of the information processing system 10 receives the login request, and the authentication processing unit 19 performs authentication by referring to the user information. Here, it is assumed that the authentication is successful. The screen generation unit 12 generates a home screen. The third communication unit 11 transmits screen information of the home screen to the terminal device 30. The home screen is a screen that displays a list of application icons and accepts execution of the application.

[0098] S25: The user selects an application from the home screen. The operation acceptance unit 23 accepts the operation, and the second communication unit 21 specifies the application ID and transmits a request to execute the application to the information processing system 10.

[0099] S26: The third communication unit 11 of the information processing system 10 receives the request to execute the application, and the screen generation unit 12 requests the application execution unit 13 to send an application screen by specifying the application ID.

[0100] S27: The application execution unit 13 returns to the screen generation unit 12 information (application name, menu, buttons, etc.) to be arranged on the application screen of the application specified by the application ID.

[0101] S28: The screen generation unit 12 generates an application screen, and the third communication unit 11 transmits screen information of the application screen to the device 20. The second communication unit 21 of the device 20 receives the screen information of the application screen, and the display control unit 22 displays the application screen.

[0102] S29: When an application executed by the user uses a file / folder (for example, an application that downloads and prints, an application that uploads a file, etc.), the user inputs an operation to display the file / folder into the device 20. The operation acceptance unit 23 accepts the operation, and the second communication unit 21 transmits a request to display the file / folder to the information processing system 10.

[0103] S30: The third communication unit 11 of the information processing system 10 receives the file / folder display request, and the screen generation unit 12 specifies the user's account information in the information processing system 10 and sends the file / folder display request to the application execution unit 13.

[0104] S31, S32: The application executing unit 13 first obtains, from the user information storage unit 41, the account information in the external service system 40 that is associated with the account information of the user in the information processing system 10.

[0105] S33, S34: Next, the application execution unit 13, via the external service processing unit 14, specifies account information in the external service system 40 and acquires a list of files / folders that the user can display.

[0106] S35, S36: Next, the application execution unit 13 acquires authority information of the external service system 40 with which the application cooperates from the authority information storage unit 42. FIG. 13 shows an example of authority information acquired from the external service system 40. In FIG. 13, as an example, (a) For the permission admin241, upload242 and download243 are True (allowed), (b) For the permission write244, upload245 and download246 are True (allowed), (c) For the permission read247, upload248 and download249 are False (restricted), It is as follows.

[0107] S37, S38: The application execution unit 13 determines whether or not the permissions for the files / folders that the user can display allow operations based on the permission information, and transmits only the files / folders for which operations are allowed to the screen generation unit 12. Note that this determination may be made on the device 20 side. For example, if the permissions for the files / folders that the user can display include admin, then (a) is True (allowed), and therefore the files / folders for which admin has permission are displayed on the device 20. For example, if the permissions for the files / folders that the user can display include write, then (b) is True (allowed), and therefore the files / folders for which write is allowed are displayed on the device 20. For example, if the permissions for the files / folders that the user can display include read, then (c) is False (restricted), and therefore the files / folders for which read is allowed are not displayed on the device 20.

[0108] In addition, when only some of the operations associated with the permissions in the permission information storage unit 42 are permitted, the application execution unit 13 determines that the operations are permitted and transmits only the file / folder to the screen generation unit 12. In this case, the types of permitted operations may also be transmitted to the device 20. The device 20 can notify the user of the permitted operations for each file / folder (this may be written in text on a button, or a pop-up may be displayed in response to pressing the button).

[0109] Furthermore, the application executing unit 13 may transmit only files / folders that the application is permitted to operate on to the screen generating unit 12. For example, when the operation that the application is to perform is uploading, the application executing unit 13 transmits to the screen generating unit 12 only files / folders that the application is permitted to operate on, based on the permissions of the files / folders that the user can display.

[0110] FIG. 14 shows the determination results made by the application executing unit 13. FIG. 14(a) shows the determination results in character string format, and FIG. 14(b) shows the determination results in list format. First, FIG. 14(a) will be described. The information in FIG. 14(a) is passed to the screen generating unit 12. Since folders with False (restricted) are not displayed, in FIG. 14(a) only files / folders with permissions of write 251 and admin 252 are passed to the screen generating unit 12.

[0111] Similarly, in FIG. 14(b), all the permissions 253 and 254 granted to each folder are described, and the included information is the same as in FIG. 14(a).

[0112] 12, the screen generation unit 12 generates a file / folder display screen including only files / folders that can be operated by the application, and transmits the generated screen to the device 20 via the third communication unit 11. The second communication unit 21 of the device 20 receives the screen information of the file / folder display screen, and the display control unit 22 displays the screen on the operation panel 940.

[0113] <File / folder display example> FIG. 15 shows a file / folder display screen 260 displayed by the device 20. Six folders 261a to 261f are displayed in FIG. 15. These six folders 261a to 261f are folders that can be operated by an application. When the user selects one of the folders 261a to 261f using the lower layer selection buttons 262a to 262f, the device 20 requests the files (or folders) in the folder from the information processing system 10. The information processing system 10 transmits only files that can be operated by an application to the device 20. Therefore, the device 20 can display only files that can be operated by an application.

[0114] <Updating permission information when an application is executed> Even if the permission information is created in advance by the permission advance verification application, there may be cases where not all permission files / folders present in the external service system 40 are prepared for the permission advance verification application, or where the permission specifications change on the external service system 40 side. Therefore, in this embodiment, the information processing system 10 updates the permission information according to the execution result of the application.

[0115] FIG. 16 is a sequence diagram showing a process for updating authority information based on the execution result when the device 20 executes an application.

[0116] S41: The user specifies a file / folder from the display screen on which the file / folder is displayed, and inputs a command to execute an application to the device 20. The operation acceptance unit 23 of the device 20 accepts the operation, and the second communication unit 21 specifies the file / folder ID and authority and sends an application execution request to the information processing system 10.

[0117] S42: The third communication unit 11 of the information processing system 10 receives the request to execute the application, and the screen generation unit 12 specifies the file / folder ID, permissions, and account information of the user in the information processing system 10, and sends the request to execute the application to the application execution unit 13.

[0118] S43, S44: The application executing unit 13 acquires, from the user information storage unit 41, the account information of the user in the external service system 40 that is associated with the account information of the user in the information processing system 10.

[0119] S45: The application execution unit 13 requests the external service system 40 to perform an operation related to the file / folder by specifying account information in the external service system 40. This operation is, for example, an operation selected by the user from among the operations available to the application, such as uploading or downloading a file.

[0120] S46 to S48: If the file / folder operation is successful, the external service system 40 returns OK (success). The information processing system 10 notifies the device 20 that the operation was successful.

[0121] S49, S50: Since the operation was successful, the application executing unit 13 updates the authority information stored in the authority information storage unit 42 by specifying the external service system ID, authority, operation, and operation result (permission).

[0122] Note that only when the permission for a file / folder is an unknown permission that is not included in the permission information, the application execution unit 13 may write the permission information to the permission information storage unit 42. A log of success / failure for a combination of a certain permission and operation may be accumulated, and the application execution unit 13 may update the permission information only for combinations that occur frequently. These will be described in Examples 4 and 6.

[0123] S51 to S53: If the external service processing unit 14 fails to operate on the file / folder, the external service system 40 returns NG (operation failed) to the external service processing unit 14. For example, in HTTP communication, 403 is notified. The information processing system 10 transmits to the device 20 that the operation has failed.

[0124] S54, S55: Since the operation has failed, the application executing unit 13 updates the authority information stored in the authority information storage unit 42 by specifying the external service system ID, authority, operation, and operation result (restriction).

[0125] S56 to S58: In the case of other failures, the information processing system 10 transmits to the device 20 a message indicating that the operation has failed.

[0126] In this way, this embodiment can also handle cases where there are files / folders with permissions that did not exist in the external service system 40 where pre-verification of permissions was performed, or cases where the specifications of permissions on the external service system 40 side have changed.

[0127] <Major Effects> According to this embodiment, an administrator's account is used to perform operations such as uploading and downloading to folders / files for which the administrator has various permissions, and the results of the operations are saved, so that permissions can be associated with whether or not an operation can be performed. When a user runs an application, the information processing system 10 can provide the device 20 with only files / folders that the user can operate. [Example]

[0128] In this embodiment, an information processing system 10 will be described in which the authority update determination unit 15 periodically performs the authority pre-verification, rather than the administrator manually performing the authority pre-verification.

[0129] In this embodiment, the hardware configuration diagrams of FIGS. 4 and 5 described in the above embodiment can be used.

[0130] <About the function> Fig. 17 is a diagram showing an example of the functional configuration of the service providing system 100 according to this embodiment. In the explanation of Fig. 17, components with the same reference numerals as in Fig. 6 perform similar functions, so in some cases only the main components of this embodiment will be mainly explained.

[0131] The information processing system 10 of this embodiment newly includes an authority update determination unit 15. The authority update determination unit 15 determines the timing for performing advance verification of authority and starts advance verification.

[0132] <Save permission information> FIG. 18 is a sequence diagram showing a process in which the information processing system 10 performs various operations on files / folders prepared in advance, and stores the operation results in association with the authorizations.

[0133] S61: The authority update determination unit 15 determines the timing for updating the authority, such as at midnight every day. The execution interval is set in the authority update determination unit 15.

[0134] S62, S63: The authority update determination unit 15 obtains a list of components that cooperate with the external service system 40 from the application execution unit 13. Component identification information is set in advance for the components that cooperate with the external service system 40. This may be performed for all components that the information processing system 10 has, not just the components that cooperate with the external service system 40. Each component is notified to the application execution unit, and all operations performed by each component are verified.

[0135] The following steps S64 to S77 are executed for each external service system 40.

[0136] S64: When the update timing arrives, the authority update determination unit 15 requests the application execution unit 13 to execute the authority advance verification application. The authority update determination unit 15 specifies the external service system 40.

[0137] S65, S66: The application executing unit 13 acquires, from the user information storage unit 41, the account information of the administrator in the external service system 40 that is associated with the account information of the administrator in the information processing system 10.

[0138] The subsequent processing in steps S67 to S77 may be the same as that in steps S9 to S19 in FIG.

[0139] <Major Effects> According to this embodiment, the authority update determination unit 15 can periodically perform pre-verification of the authority, and the administrator does not need to execute an application for pre-verification of the authority. Note that this embodiment can be executed in combination with the first embodiment. [Example]

[0140] In this embodiment, a method in which an administrator manually registers authority information will be described. Note that in this embodiment, the hardware configuration diagrams of Figures 4 and 5 and the functional block diagram of Figure 6 described in the above embodiment can be used.

[0141] 19 is a sequence diagram showing an example of a procedure for an administrator to update authority information. Note that the administrator has already logged in.

[0142] S401: The administrator operates the terminal device 30 to connect to the information processing system 10 and performs an operation to request an authority information setting screen from the terminal device 30. The screen generation unit 12 of the information processing system 10 acquires already set authority information from the authority information storage unit 42 and generates an authority information setting screen. If the authority information has not been registered, the screen generation unit 12 generates an authority information setting screen without any authority information.

[0143] S402: The first communication unit 31 of the terminal device 30 receives screen information of the authority information setting screen, and the display control unit 32 displays the authority information setting screen. An example of the authority information setting screen is shown in Fig. 21. The administrator inputs the authority information, which is accepted by the operation acceptance unit 33. The first communication unit 31 specifies the authority information and transmits an authority information update request to the information processing system 10.

[0144] S403: The third communication unit 11 of the information processing system 10 receives the authority information update request, and the screen generation unit 12 specifies the authority information and transmits the authority information update request to the application execution unit 13.

[0145] S404: The application executing unit 13 updates the authority information in the authority information storage unit .

[0146] Fig. 20 shows an example of a request body for authority information transmitted from the terminal device 30 to the information processing system 10. As shown in Fig. 20, the administrator writes the authority information in an editor provided by the information processing system 10, for example, in JSON format. The administrator may prepare a file such as that shown in Fig. 20 in advance and transmit this file from the terminal device 30 to the information processing system 10. As shown in Fig. 20, the authority information includes identification information 271 of the external service system 40 and permission 273, 275 for each operation for authorities 272, 274.

[0147] Fig. 21 shows an example of an authority information setting screen 280 displayed by the terminal device 30. Fig. 21 shows the authority information setting screen 280 prepared as a GUI (Graphical User Interface). The authority information setting screen 280 in Fig. 21 has an external service system selection field 281, an authority field 282, a possible operation field 283, an add button 284, an edit button 285, a delete button 286, and a save button 287.

[0148] The external service system selection field 281 is a field where the administrator selects the external service system 40 for which authority information is to be registered.

[0149] The authority column 282 and the possible operation column 283 display the authority information selected in the external service system selection column 281. The authority column 282 and the possible operation column 283 may be blank in the initial state.

[0150] The Add button 284 is a button that displays an input field for authority and available operations and receives input of authority and available operations from the administrator.

[0151] The edit button 285 is a button for accepting editing of the authority information selected by the administrator in the authority column 282 and the possible operations column 283 .

[0152] The delete button 286 is a button for accepting editing of the authority information selected by the administrator in the authority column 282 and the possible operations column 283 .

[0153] The save button 287 is a button for the device 20 to transmit the settings in FIG. 21 to the information processing system 10.

[0154] <Major Effects> In this embodiment, the administrator can manually register the authority information, so that when a specification change is notified in advance from the external service system 40, the authority information can be updated in accordance with the release of the external service system 40. This embodiment can be implemented in combination with the first and second embodiments. [Example]

[0155] In this embodiment, an information processing system 10 will be described that updates the authority information only when the authority information transmitted from the external service system 40 is unknown.

[0156] In this embodiment, the hardware configuration diagrams of FIGS. 4 and 5 and the functional block diagram shown in FIG. 6 described in the above embodiment can be used.

[0157] <Save permission information> 22 is a sequence diagram showing a process of updating authority information based on the execution result when an application is executed by the device 20. In the explanation of FIG. 22, the differences from FIG. 16 will be mainly explained.

[0158] In FIG. 22, steps S101 to S103 and S104 to S107 are added.

[0159] S101, S102: The application executing unit 13 specifies the external service system 40 and acquires the authority information currently registered in the authority information storage unit .

[0160] S103: The application executing unit 13 determines whether or not the authority of the file / folder is registered in the authority information storage unit 42 (whether or not it is unknown) based on the result of the operation executed on the file / folder in step S45.

[0161] S49, S50: Then, the application executing unit 13 updates the authority information only when the authority of the file / folder is not registered in the authority information storage unit 42. When the authority of the file / folder is registered in the authority information storage unit 42, the application executing unit 13 does not update the authority information.

[0162] The same applies if the request fails with error code 403.

[0163] S104, S105: The application executing unit 13 specifies the external service system 40 and acquires the authority information currently registered in the authority information storage unit .

[0164] S106: The application executing unit 13 determines whether or not the authority of the file / folder is registered in the authority information storage unit 42 (whether or not it is unknown) based on the result of the operation executed on the file / folder in step S45.

[0165] S54, S55: Then, the application executing unit 13 updates the authority information only when the authority of the file / folder is not registered in the authority information storage unit 42. When the authority of the file / folder is registered in the authority information storage unit 42, the application executing unit 13 does not update the authority information.

[0166] <Major Effects> According to this embodiment, the authority information is updated only when the authority information transmitted from the external service system 40 is unknown, so there is no need to perform a write process every time for a known authority. This embodiment can be implemented in place of embodiments 1 and 2, and in combination with embodiment 3. [Example]

[0167] In this embodiment, an information processing system 10 that updates the authority information only when there is a component that requires updating of the authority information will be described.

[0168] In this embodiment, the hardware configuration diagrams of FIGS. 4 and 5 described in the above embodiment can be used.

[0169] <About the function> Fig. 23 is a diagram showing an example of the functional configuration of the service providing system 100 according to this embodiment. In the explanation of Fig. 23, components with the same reference numerals as in Fig. 6 perform similar functions, so in some cases only the main components of this embodiment will be mainly explained.

[0170] The information processing system 10 of this embodiment newly includes a component information storage unit 43. FIG. 24 shows an example of component information stored in the component information storage unit 43. In the component information, an update setting (update or do not update) for permission information is registered in association with a component ID. Components are prepared in association with the external service system 40, but if the permissions of the external service system 40 have special specifications, or if learning from the execution results of end users would have a negative impact, the update setting for that component is registered as "do not set." This allows applications to display file / folder display screens using only the permission information manually registered by the administrator.

[0171] <Updating permission information when an application is executed> 25 is a sequence diagram showing a process of updating authority information based on the execution result when the device 20 executes an application. In the explanation of FIG. 25, the differences from FIG. 16 will be mainly explained.

[0172] In FIG. 25, steps S201 and S202 are added.

[0173] S201: The application executing unit 13 determines whether the components included in the application include a component for updating permission information. The application executing unit 13 determines whether the components include a component for updating permission information by referring to the component information shown in Fig. 24. Only when the application includes a component for updating permission information, the application executing unit 13 executes steps S49 and S50.

[0174] S202: The application execution unit 13 determines whether the components included in the application include a component that updates the authority information. Only if the application includes a component that updates the authority information, the application execution unit 13 executes steps S54 and S55.

[0175] <Major Effects> In this embodiment, when learning from the execution results of a user would have an adverse effect, for example, because the authority of the external service system 40 has special specifications, it is possible to store only the authority information manually registered by the administrator. Note that this embodiment can be implemented in place of embodiments 1 and 2 and in combination with embodiment 3. [Example]

[0176] In this embodiment, an information processing system 10 will be described that accumulates application execution results (external service system ID, authority, operation, operation result) as a log and updates authority information according to the analysis result of the execution result.

[0177] <About the function> Fig. 26 is a diagram showing an example of the functional configuration of the service providing system 100 according to this embodiment. In the explanation of Fig. 26, components with the same reference numerals as in Fig. 6 perform similar functions, so in some cases only the main components of this embodiment will be mainly explained.

[0178] The information processing system 10 of this embodiment newly includes a history determination unit 16 and an execution history storage unit 44. The history determination unit 16 determines whether or not to update the authority information based on the execution history of the application.

[0179] 27 is a diagram illustrating the execution history stored in the execution history storage unit 44. The execution history is information that associates authority, operation, and operation result when an application operates the external service system 40.

[0180] The job ID is identification information for the execution of an application that is assigned a number for each execution of a workflow. Instead of the job ID, the date and time or a sequential number may be used.

[0181] The external service system ID is identification information of the external service system 40 with which the application is linked.

[0182] · Permissions are the permissions that an application has.

[0183] The operation type is the content of the operation that the application performed on the file / folder.

[0184] The execution result indicates whether the operation on the file / folder by the application was successful (success) or failed (error). Note that this failure is preferably a 403 error, but may include other failures.

[0185] <Updating permission information when an application is executed> 28 is a sequence diagram showing a process of updating authority information based on the execution result when the device 20 executes an application. In the explanation of FIG. 28, the differences from FIG. 16 will be mainly explained.

[0186] First, steps S71 to S78 may be the same as steps S41 to S48 in FIG.

[0187] S79, S80: The application executing unit 13 writes the execution history of the application into the execution history storage unit 44, specifying the external service system ID, authority, operation, and operation result (permission).

[0188] S81 to S83: If the external service processing unit 14 fails to operate on the file / folder, the external service system 40 returns NG (operation failed). For example, in HTTP communication, 403 is notified. The information processing system 10 transmits to the device 20 that the operation has failed.

[0189] S84, S85: The application executing unit 13 writes the execution history of the application into the execution history storage unit 44, specifying the external service system ID, authority, operation, and operation result (restriction).

[0190] S86 to S88: In the case of other failures, the information processing system 10 transmits to the device 20 a message indicating that the operation has failed.

[0191] S89: The history determination unit 16 starts updating the authority information. The authority information is updated at a fixed time, such as at midnight every day. The administrator may also instruct the update.

[0192] S90, S91: The history determination unit 16 acquires the execution history from the execution history storage unit 44.

[0193] S92, S93: The history determining unit 16 acquires the authority information from the authority information storage unit .

[0194] S94: The application executing unit 13 determines whether or not the authority information needs to be updated. As an example of a method of determination, the history determining unit 16 acquires an execution history of the same combination of the external service system ID, authority, and operation from the execution history storage unit 44, and determines that the operation is permitted if, for example, the success rate of the execution results in the most recent XX times or the most recent XX days is equal to or greater than a threshold value.

[0195] S95: The history determination unit 16 notifies the application execution unit 13 of the determination result (update or not).

[0196] S96, S97: If an update is necessary, the application executing unit 13 updates the permission information by specifying the external service system ID, permission, operation, and operation content. If an update is not necessary, the application executing unit 13 does not update the permission information.

[0197] <Major Effects> According to this embodiment, the information processing system 10 can update the authority information with higher accuracy than updating the authority information in response to the success / failure of a single execution result. Note that this embodiment can be implemented in place of the first and second embodiments and in combination with the third embodiment.

[0198] <Other application examples> The best mode for carrying out the present invention has been described above using examples, but the present invention is not limited to these examples in any way, and various modifications and substitutions can be made within the scope that does not deviate from the gist of the present invention.

[0199] For example, the configuration example in Fig. 6 and the like is divided according to main functions to facilitate understanding of the processing by the terminal device 30, the device 20, and the information processing system 10. The method of dividing the processing units and the names thereof do not limit the present invention. The processing by the terminal device 30, the device 20, and the information processing system 10 can be divided into even more processing units depending on the processing content. Furthermore, the processing can be divided so that one processing unit includes even more processes.

[0200] Additionally, the devices described in the examples are merely illustrative of one of several computing environments for implementing the embodiments disclosed herein. In one embodiment, information processing system 10 includes multiple computing devices, such as a server cluster, configured to communicate with each other via any type of communication link, including a network, shared memory, etc., and to perform the processes disclosed herein.

[0201] Furthermore, the information processing system 10 can be configured to share the processing steps disclosed in this embodiment, such as those shown in FIG. 10, in various combinations. For example, a process executed by a specific unit can be executed by multiple information processing devices included in the information processing system 10. Furthermore, the information processing system 10 may be integrated into a single server device, or may be divided into multiple devices.

[0202] Each function of the above-described embodiments can be realized by one or more processing circuits. Here, the term "processing circuit" in this specification includes a processor programmed to perform each function by software, such as a processor implemented by an electronic circuit, as well as devices such as an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and conventional circuit modules designed to perform each of the above-described functions. [Explanation of symbols]

[0203] 10 Information Processing Systems 20 equipment 30 Terminal Equipment 40 External Service Systems 100 Service Delivery System [Prior art documents] [Patent documents]

[0204] [License 1] Patent No. 5050981

Claims

1. An information processing system in which an application operates an operation target of an external service system, an authority information storage unit that stores authority information in which the authority set for the operation object is associated with whether or not the operation is possible; an authentication processing unit that performs processing related to user authentication; an external service processing unit that acquires, in response to a request from the device, a list of the operation targets to which the user has access rights from the external service system; a screen generation unit that provides the device with screen information that displays a list of the operation targets that are permitted to be operated in the authority information storage unit in accordance with the acquired authority set for the operation target; An information processing system comprising:

2. The information processing system according to claim 1, further comprising an application execution unit that acquires a list of the operation targets from the external service system, performs each operation performed by the application on the operation targets, and registers the permission or non-permission of the operation in the permission information storage unit in association with the permission set for the operation target.

3. an authority update determination unit that starts a process of updating the authority information at a preset timing; The information processing system described in claim 2, characterized in that when the authority update determination unit determines that it is time to update the authority information, the application execution unit obtains a list of the operation targets from the external service system, performs each operation performed by the application on the operation targets, and registers the possibility of the operation in the authority information storage unit in association with the authority set for the operation target.

4. the external service processing unit performs an operation on the operation target in the external service system in response to an application execution request from a device; The information processing system according to claim 2 or 3, characterized in that the application execution unit registers in the authority information storage unit the operation performed by the application, the authority set for the operation target, and whether the operation is possible or not, in association with each other.

5. The information processing system according to claim 4, characterized in that the application execution unit registers the possibility of the operation in the authority information storage unit in association with the authority set for the operation target only when an unknown authority not stored in the authority information storage unit is set for the operation target on which the application performed the operation.

6. The application executes a plurality of components in sequence, a component information storage unit in which whether or not to update the authority information stored in the authority information storage unit is set in association with the component; If a component included in the application that performed the operation on the operation target is set to update authority information in the component information storage unit, 6. The information processing system according to claim 4, wherein the application execution unit registers whether or not the operation is permitted in association with an authority set for the operation target.

7. the application execution unit records the identification information of the external service system, the authority, the type of operation, and whether the operation is permitted or not in association with each other; The information processing system described in claim 4, characterized in that if the success rate of the operation is above a threshold, the operation's success rate is registered in the authority information storage unit in correspondence with the authority set for the operation target.

8. The screen generation unit generates, for each of the external service systems, a screen that accepts addition, editing, and deletion of the types of operations permitted for the authority; The information processing system according to any one of claims 2 to 7, characterized in that the information processing system receives from the terminal device that displays the screen generated by the screen generation unit the authority information accepted for the screen, and the application execution unit updates the authority information stored in the authority information storage unit.

9. A display method performed by an information processing system in which an application operates an operation target of an external service system, comprising: an authentication processing unit performing processing related to user authentication; an external service processing unit acquiring, in response to a request from a device, a list of the operation targets to which the user has access rights from the external service system; Based on an authority information storage unit that stores authority information in which the authority set for the operation object is associated with whether or not the operation is possible, a screen generation unit providing the device with screen information for displaying a list of the operation targets that are permitted to be operated in the authority information storage unit in accordance with the authority set for the acquired operation targets; A display method comprising:

10. A service providing system including a device that requests execution of an application, and an information processing system in which the application operates an operation target of an external service system, The information processing system includes: an authority information storage unit that stores authority information in which the authority set for the operation object is associated with whether or not the operation is possible; an authentication processing unit that performs processing related to user authentication; an external service processing unit that acquires, in response to a request from the device, a list of the operation targets to which the user has access rights from the external service system; a screen generation unit that provides the device with screen information that displays a list of the operation targets that are permitted to be operated in the authority information storage unit in accordance with the authority set for the acquired operation target, The device comprises: A service providing system, characterized in that a list of the operation targets for which operation is permitted in the authority information storage unit is displayed based on the screen information received from the information processing system.

Citation Information

Patent Citations

  • JP1975050981A

  • Image forming apparatus, access control program, and access control method

    JP2017045355A

  • Input / output device, program and information processing system

    JP2018107796A

  • Image forming device and web server providing workflow status of job, and method to provide workflow status of job in image forming device and web server

    US20080002220A1