Data management device, data sharing system and method, and data management program

The data management device addresses the increased workload on data owners by allowing users to input sharing information and approve data access, reducing the owner's burden and enhancing data sharing efficiency.

JP7802887B2Active Publication Date: 2026-01-20NTT DOCOMO BUSINESS INC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024174633
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-10-03
Publication Date
2026-01-20
Estimated Expiration
2041-09-16

AI Technical Summary

Technical Problem

Existing data sharing systems impose a greater workload on data owners, reducing their motivation to share data, especially when multiple users request data sharing, and this burden increases with the amount of data owned.

Method used

A data management device that allows users to input sharing information, with the data owner's approval, using a dedicated storage area isolated from the second user, enabling data sharing with reduced workload on the owner by storing shared data as copies, symbolic links, or processed data.

Benefits of technology

This approach reduces the workload on data owners by requiring data users to input sharing information while allowing data owners to approve, facilitating efficient data sharing among multiple users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007802887000001
    Figure 0007802887000001
  • Figure 0007802887000002
    Figure 0007802887000002
  • Figure 0007802887000003
    Figure 0007802887000003
Patent Text Reader

Abstract

To share data between users with less workload on a data owner.SOLUTION: A data management device causes at least part of information related to data to be shared from a second user terminal operated by a second user who utilizes data to be input, causes a first user terminal operated by a first user who is a data owner to view the information related to the data to be shared after input by the second user terminal, and permits the second user terminal to access the data to be shared in response to approval from the first user terminal.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a data management device, a data sharing system and method, and a data management program. [Background technology]

[0002] Several devices have been proposed for sharing data among multiple users.

[0003] For example, Patent Document 1 discloses a device that stores the same user data in multiple user terminals, and when the user data is updated in the user terminal of a certain user (updator), the user data is also updated in the user terminals of other users.

[0004] Furthermore, Patent Document 2 discloses a technology that stores a symbolic link to user data stored in one user's user area in another user's user area, thereby virtually storing the user data in the other user's user area and enabling viewing and editing operations similar to those when actual data is stored. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-168630 [Patent Document 2] Japanese Patent Application Publication No. 2019-200643 Summary of the Invention [Problem to be solved by the invention]

[0006] When sharing data, a user who owns the data (hereinafter referred to as the data owner) and a user who uses the data (hereinafter referred to as the data user) must first obtain a sharing agreement via telephone, email, or other means. Once the sharing agreement is obtained, the data owner can share data only after specifying, in a data management device that manages data sharing, which data to share with whom. Therefore, the workload on the data owner is greater than that of the data users. When multiple data users request data sharing, the workload on each individual data user remains the same, while the workload on the data owner increases. Furthermore, the greater the amount of data owned by the data owner, the greater the workload on the data owner. This increased workload reduces the motivation of the data owner and hinders the expansion of data sharing.

[0007] The present invention has been made in light of the above circumstances, and its object is to enable data to be shared among users with less work burden on the data owner. [Means for solving the problem]

[0008] In order to solve the above problems, one aspect of a data management device according to the present invention is a data management device that manages data sharing between a first user who is the owner of the data and a second user who uses the data, and includes a communication interface that communicates with a first user terminal operated by the first user and a second user terminal operated by the second user, and a control unit that controls the data management device. The control unit causes the second user terminal to input at least a portion of information related to the data to be shared, causes the first user terminal to view the information related to the data to be shared after input by the second user terminal, and permits the second user terminal to access the shared data in response to approval from the first user terminal. The data is stored in a dedicated storage area that is isolated from the second user and accessible only to the first user. The shared data includes at least one of a copy of the data, a symbolic link to the data, data extracted from a portion of the data, and processed data in which at least a portion of the data has been processed.

[0009] One aspect of the data sharing system according to the present invention includes a storage unit having a dedicated storage area and a shared area, and one aspect of the data management device according to the present invention.

[0010] One aspect of the data sharing method of the present invention is a data sharing method for sharing data between a first user who is the owner of the data and a second user who uses the data, comprising the steps of: a computer having the second user terminal input at least a portion of information regarding the data to be shared; a computer having the first user terminal operated by the first user view the information regarding the data to be shared after input by the second user terminal; and a computer having the second user terminal permitted to access the shared data in response to approval from the first user terminal. The data is stored in a dedicated storage area that is isolated from the second user and accessible only to the first user. The shared data includes at least one of a copy of the data, a symbolic link to the data, data extracted from a portion of the data, and processed data in which at least a portion of the data has been processed.

[0011] One aspect of a data management program according to the present invention is a program that causes a computer to execute processing by each processing unit included in one aspect of a data management device according to the present invention. [Effects of the Invention]

[0012] According to each aspect of the present invention, the data user is required to input the information necessary for data sharing, and the data owner only needs to approve the input, thereby making it possible to share data between users with less work burden on the data owner. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a diagram showing an example of the overall configuration of a data sharing system according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a block diagram showing an example of the hardware configuration of the data management device according to the first embodiment of the present invention. [Figure 3] FIG. 3 is a block diagram showing an example of the software configuration of the data management device according to the first embodiment. [Figure 4]FIG. 4 is a diagram showing an example of the content of a workflow management table created by the data management device according to the first embodiment. [Figure 5] FIG. 5 is a flowchart showing an example of the overall processing procedure of the shared area management processing by the data management device according to the first embodiment. [Figure 6] FIG. 6 is a flowchart showing an example of the processing procedure of the shared area creation processing out of the overall processing procedure shown in FIG. [Figure 7] FIG. 7 is a flowchart showing an example of the processing procedure of the shared area access processing out of the overall processing procedure shown in FIG. [Figure 8] FIG. 8 is a flowchart illustrating an example of the processing procedure of the shared area deletion processing from the overall processing procedure shown in FIG. [Figure 9] FIG. 9 is a block diagram showing an example of the software configuration of a data management device according to the second embodiment of the present invention. [Figure 10] FIG. 10 is a flowchart illustrating an example of the overall processing procedure of the shared area management processing by the data management device according to the second embodiment. [Figure 11] FIG. 11 is a flowchart showing an example of the procedure of the abnormality detection process among the overall procedure shown in FIG. [Figure 12] FIG. 12 is a flowchart showing an example of the processing procedure for creating an abnormality handling shared area from the overall processing procedure shown in FIG. [Figure 13] FIG. 13 is a flowchart showing a part of an example of the processing procedure of the shared area deletion processing among the overall processing procedures shown in FIG. DETAILED DESCRIPTION OF THE INVENTION

[0014] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0015] [First embodiment] (Configuration example) (1) System 1 is a diagram showing the overall configuration of a data sharing system 1 according to a first embodiment of the present invention. The data sharing system 1 provides data sharing among a plurality of users.

[0016] The data sharing system 1 includes, for example, user A terminals 10A1 and 10A2, user B terminal 10B, user C terminal 10C, ..., cloud storage 20, and a data management device 30 according to the first embodiment of the present invention. Note that, when there is no need to distinguish between the user A terminals 10A1 and 10A2, user B terminal 10B, user C terminal 10C, ..., they will hereinafter be simply referred to as user terminals 10. The user terminals 10, cloud storage 20, and data management device 30 are connected via a network NW.

[0017] Users A, B, C, ... are, for example, in different companies, and each user terminal 10 is a PC located in a different company. In Fig. 1, two user terminals 10 are shown in the company of user A, and one user terminal 10 is shown in each of the companies of users B, C, ..., but each company may have any number of user terminals 10.

[0018] The data sharing system 1 may also be configured as a system within a single company. In this case, each user terminal 10 may be located in a branch office within the single company, or in a different department within the single company.

[0019] The data sharing system 1 includes dedicated storage areas for each user, isolated from other user terminals 10. Specifically, the data sharing system 1 includes a user A dedicated storage area 11A dedicated to user A terminals 10A1 and 10A2, a user B dedicated storage area 11B dedicated to user B terminal 10B, a user C dedicated storage area 11C dedicated to user C terminal 10C, and so on, each storing at least one data file. These dedicated storage areas for each user terminal 10 may be provided in cloud storage or in an in-house server corresponding to the user terminal 10. In the example of FIG. 1 , the user A dedicated storage area 11A, the user C dedicated storage area 11C, and so on are provided in an individual area 41 of cloud storage 40, and the user B dedicated storage area 11B is provided in an individual area 12 of a user B server (not shown). The individual areas 12 and 41 are dedicated storage areas for each user, connected to a network NW and isolated from other user terminals 10. The individual area 12 is also connected to user B terminal 10B via an in-house LAN or the like. In the following, when there is no need to distinguish between the user A dedicated storage area 11A, the user B dedicated storage area 11B, the user C dedicated storage area 11C, . . . , they will simply be referred to as the user dedicated storage area 11.

[0020] The cloud storage 20 is a first storage device including a shared area 21. The shared area 21 is a storage area for storing shared data shared among multiple user terminals 10. For example, the shared area 21 includes a user A+B shared storage area 2111 shared by user A terminals 10A1 and 10A2 with user B terminal 10B, a user A+C shared storage area 2112 shared by user A terminals 10A1 and 10A2 with user C terminal 10C, and so on. Note that when there is no need to distinguish between the user A+B shared storage area 2111, the user A+C shared storage area 2112, and so on, they will hereinafter be referred to simply as user shared storage areas 211. The user shared storage area 211 is an area that can be accessed only by specific users who are the target of sharing. For example, a user A+B shared storage area can be accessed by user A terminals 10A1 and 10A2 and user B terminal 10B, but cannot be accessed by user C terminal 10C, and even its existence is kept secret from user terminals 10 of users other than user A and user B. These user shared storage areas 211 are created for each piece of shared data. Therefore, for example, the area shared by user A terminals 10A1 and 10A2 and user B terminal 10B may include a second user A+B shared storage area (not shown) in addition to user A+B shared storage area 2111.

[0021] Here, private area 41 is configured in cloud storage 40, which is a second storage device that is physically different from cloud storage 20, which is a first storage device that includes shared area 21. However, private area 41 may be configured in cloud storage 20 that configures shared area 21 by logically separating it. Similarly, private area 12 may be configured in private area 41 of cloud storage 40, or may be configured in cloud storage 20 by logically separating it.

[0022] The data management device 30 launches a workflow for data sharing agreement in response to a workflow creation request from any of the user terminals 10 that are data user terminals. The data management device 30 then circulates the workflow between the user terminal 10 of the data user and the user terminal 10 that is the data owner terminal, thereby obtaining an agreement on data sharing. Once an agreement on data sharing has been obtained, the data management device 30 creates a shared storage area in the shared area 21 of the cloud storage 20 that is shared by the user terminal 10 that is the data owner terminal and another user terminal 10 that is the data user terminal.

[0023] For example, assume that user A stores three data files 111, A1, A2, and A3, in the user A-dedicated storage area 11A, and user B learns of the existence of the A1 data file 111 directly or indirectly from user A. When user B wants to use the A1 data file 111, user B transmits a workflow creation request from his / her user B terminal 10B to the data management device 30. In response to the workflow creation request from user B terminal 10B, the data management device 30 launches a workflow and prompts user B terminal 10B to input usage conditions. The usage conditions include, for example, the data to be shared (A1 data file 111), the owner of the data (user A), and, in some cases, the usage period (number of days and / or number of accesses) and usage fee. The data management device 30 then sends the workflow containing the usage conditions to the user terminal of the user registered as the approver of the A1 data file 111, for example, user A terminal 10A1, to obtain approval. If approval is obtained, it is assumed that an agreement on data sharing has been obtained, and the data management device 30 creates a user A+B shared storage area 2111 shared by user A and user B in the shared area 21 of cloud storage 20 based on the workflow.

[0024] Furthermore, the data management device 30 stores the data to be shared, for example, the A1 data file 111, based on the workflow in a shared storage area created in the shared area 21 of the cloud storage 20, for example, the user A+B shared storage area 2111. Furthermore, the data management device 30 stores a workflow management table 212 describing workflow management information in the created shared storage area, for example, the user A+B shared storage area 2111. Furthermore, if the user terminal 10, who is the data user, performs a viewing or editing operation on the shared data, the data management device 30 adds the operation history to this workflow management table 212.

[0025] (2) Data management device 30 2 and 3 are block diagrams showing an example of the hardware configuration and software configuration of the data management device 30, respectively.

[0026] The data management device 30 includes a control unit 31 having a hardware processor such as a central processing unit (CPU), and this control unit 31 is connected via a bus 35 to a storage unit having a program storage unit 32 and a data storage unit 33, and a communication interface (hereinafter abbreviated as communication I / F) 34.

[0027] Under the control of the control unit 31, the communication I / F 34 transmits various types of data between the user terminal 10, the cloud storage 20, and the individual areas 12 and 41 using a communication protocol defined by the network NW.

[0028] The program storage unit 32 is configured by combining, for example, a nonvolatile memory such as a hard disk drive (HDD) or a solid state drive (SSD) as a storage medium that can be written to and read from at any time, and a nonvolatile memory such as a read only memory (ROM). The program storage unit 32 stores middleware such as an operating system (OS) as well as programs required to execute various control processes according to the first embodiment of the present invention.

[0029] The data storage unit 33 is, for example, a combination of a nonvolatile memory such as an HDD or SSD, which can be written to and read from as needed, and a volatile memory such as a RAM (Random Access Memory), as a storage medium. The data storage unit 33 includes a setting information storage unit 331, an area information storage unit 332, and a temporary storage unit 333, which are storage units required to implement the first embodiment of the present invention.

[0030] The setting information storage unit 331 is used to store user setting information for each registered user who uses the data management device 30 and data setting information for each piece of data stored in the individual areas 12 and 41.

[0031] The user setting information includes at least a user ID and the user's contact information. The user ID is identification information for uniquely identifying a registered user. Here, a registered user is, for example, a contracted user who pays a specified usage fee to use the data sharing system 1 including the data management device 30, and can be the user of the user terminal 10. The user ID is a number, a human-recognizable character string, or a combination of a character string and a number assigned by the data management device 30 during user registration. The user ID may be a name arbitrarily designated by the user that is unique to other registered users. The contact information may be, for example, an email address. The user setting information may also include authentication information such as a password for authentication. The user setting information may also include payment information such as a payment account or card number for usage fees, personal information such as company name, affiliation, address, name, and telephone number.

[0032] The data setting information includes at least a data ID and an approver who approves sharing. The data ID is identification information for uniquely identifying data. The data ID may be the file name of the data file, a number, a human-recognizable character string, or a combination of a character string and a number assigned by the data management device 30 when storing the data file in the individual area 12, 41. The approver is the user ID of the registered user who approves, and there may be multiple approvers. For example, if sharing the A1 data file 111 with another user requires approval from the registered user of the user A terminal 10A1 as well as from the registered user of the user A terminal 10A2 who is the superior of the registered user, the user IDs of both the user A terminal 10A1 and the user A terminal 10A2 are stored as approvers. Note that in a system where the approver is limited to one person, contact information may be stored for each data ID instead of the approver. The data setting information may also include the data type (e.g., log data or document data), date information (e.g., creation date or registration date), owner information (the same or different from the approver), and so on.

[0033] The area information storage unit 332 is used to store area information regarding each of the user-dedicated memory areas 11 of each user terminal 10 created in the individual areas 12, 41, and area information regarding each of the user shared memory areas 211 between multiple user terminals 10 created in the shared area 21 of the cloud storage 20.

[0034] The area information regarding the user-dedicated storage area 11 includes at least the dedicated area location and the owner. The dedicated area location is address information that identifies the storage location of the user-dedicated storage area 11 for accessing the user-dedicated storage area 11 via the network NW. This may include the IP address of the cloud storage 40 or the user B server (not shown), the physical / logical location of a drive letter or folder name of an HDD or SSD, etc. The owner is identification information that identifies the user of the user-dedicated storage area 11, and may be a user ID.

[0035] The area information regarding the user shared storage area 211 includes at least the shared storage location and workflow ID. In FIG. 3 and the figures described below, workflow is abbreviated as WF. The shared storage location is address information that identifies the storage location of the user shared storage area 211 in question, for accessing the user shared storage area 211 via the network NW. This may include the IP address of the cloud storage 20, the physical / logical location such as the drive letter of an HDD or SSD, or the folder name. The workflow ID is identification information that identifies the workflow for the sharing agreement. This may be a uniquely assigned number, a human-recognizable character string, or a combination of a character string and a number.

[0036] The temporary storage unit 333 is used to temporarily store various data and information that the control unit 31 generates during processing.

[0037] The control unit 31 includes, as processing functions according to the first embodiment of the present invention, a setting information acquisition processing unit 311, a workflow management processing unit 312, an area management processing unit 313, and a data writing processing unit 314. These processing units 311 to 314 are all realized by causing a hardware processor of the control unit 31 to execute a program stored in the program storage unit 32, for example.

[0038] The setting information acquisition processing unit 311 performs processing to receive, via the communication I / F 34, setting instructions for user setting information or data setting information sent from each user terminal 10 and transmitted over the network NW. The setting information acquisition processing unit 311 further performs processing to store, in the setting information storage unit 331, the user or data setting information included in the received setting instructions.

[0039] The workflow management processing unit 312 performs processing to receive, via the communication I / F 34, workflow creation requests sent from the user terminal 10 of a user who will become a data user and transmitted over the network NW. In response to receiving the workflow creation request, the workflow management processing unit 312 further performs processing to create a workflow for sharing agreement, store it in the temporary storage unit 333, and circulate the workflow between the data user and the data owner to obtain the sharing agreement. Specifically, the workflow management processing unit 312 transmits workflow screen information for displaying the workflow on a web browser screen of the requesting user terminal 10 via the communication I / F 34 and the network NW to the requesting user terminal 10. Furthermore, upon receiving information such as the data desired to be shared and the data owner entered on the workflow web browser screen of the user terminal 10, the workflow management processing unit 312 stores the received information in the temporary storage unit 333 as the description content of the workflow. Furthermore, the workflow management processing unit 312 transmits workflow screen information for displaying the workflow containing this information on a web browser screen of the user terminal 10 of the data owner via the network NW using the communication I / F 34. Then, the workflow management processing unit 312 performs processing for accepting an approval operation on the web browser screen of the workflow in the user terminal 10.

[0040] When an agreement on sharing is obtained in the workflow, the area management processing unit 313 performs processing to send an instruction to create the user shared storage area 211 to the cloud storage 20 via the network NW using the communication I / F 34, based on the description of the workflow stored in the temporary storage unit 333. As a result, the user shared storage area 211 among the multiple user terminals 10 is created in the shared area 21 of the cloud storage 20. The area management processing unit 313 also performs processing to store area information related to the created user shared storage area 211 in the area information storage unit 332.

[0041] The data writing processing unit 314 reads the data file 111 of the data to be shared from the user-dedicated storage area 11 of the data owner via the network NW using the communication I / F 34 based on the workflow description stored in the temporary storage unit 333, and stores the data in the temporary storage unit 333. The data writing processing unit 314 further performs a process of identifying the corresponding user shared storage area 211 created in the cloud storage 20 based on the area information about the user shared storage area 211 stored in the area information storage unit 332. The data writing processing unit 314 then writes the data file 111 stored in the temporary storage unit 333 to the user shared storage area 211 via the network NW using the communication I / F 34. The data writing processing unit 314 also performs a process of writing the content of the workflow description stored in the temporary storage unit 333 as a workflow management table 212 to the user shared storage area 211 via the network NW using the communication I / F 34.

[0042] (3) Workflow Management Table 212 4 is a diagram showing an example of the contents of the workflow management table 212 created by the data management device 30 and stored in the user shared storage area 211. The workflow management table 212 includes information such as a workflow ID, a sharing source ID, a sharing destination ID, a data ID, a sharing deadline, and a history.

[0043] Here, the workflow ID is identification information that identifies the workflow management table 212, and corresponds to the workflow ID in the area information stored in the area information storage unit 332. The supplier ID is identification information that indicates the data owner, and the sharer ID is identification information that indicates the data user, and each corresponds to the user ID in the user setting information stored in the setting information storage unit 331. Furthermore, the data ID is identification information that identifies the data file 111, which is shared data stored in the user shared storage area 211, and corresponds to the data ID in the data setting information stored in the setting information storage unit 331.

[0044] The sharing period is information indicating the time limit for which data sharing is permitted, and can be set as the number of accesses and / or the number of days from the start of sharing. This sharing period can be set when the data user inputs the desired period when obtaining a sharing agreement and the data owner approves it. The sharing period may also be set to a predetermined value, independent of input by the data user. The sharing period may also be stored by converting the number of days into actual days.

[0045] The history is a history of work performed by the workflow. Every time a data user accesses the data file 111, which is shared data, from the user terminal 10 to perform viewing, editing, or other work, the workflow management processing unit 312 performs processing to add the history to this workflow management table 212 via the communication I / F 34 over the network NW.

[0046] The area management processing unit 313 reads the workflow management table 212 via the network NW using the communication I / F 34 based on the area information stored in the area information storage unit 332, and performs processing based on the sharing deadline. This processing includes, for example, a process of deleting the corresponding user shared storage area 211 after the sharing deadline has elapsed by sending a deletion instruction for the user shared storage area 211 to the cloud storage 20 via the network NW using the communication I / F 34. If the sharing deadline is specified by the number of times, the area management processing unit 313 can determine whether the sharing deadline has elapsed by comparing the number of histories since the start of sharing in the history with the specified number of times. If the sharing deadline is specified by the number of days, the area management processing unit 313 can determine whether the sharing deadline has elapsed by comparing the number of days since the start of sharing in the history with the specified number of days. If the sharing deadline is specified by both the number of times and the number of days, the area management processing unit 313 determines that the sharing deadline has elapsed if one of the sharing deadlines has elapsed.

[0047] (Example of operation) Next, the operation of the data sharing system 1 configured as above will be described.

[0048] The operations of user registration from each user terminal 10, authentication operations when using the data sharing system 1, and file operations such as saving and reading data files in the corresponding user-dedicated memory area 11 are well known, so a description thereof will be omitted. Below, the processing operations of the data management device 30 related to the sharing of shared data among multiple user terminals 10 will be described using the flowcharts shown in Figures 5 to 8.

[0049] First, a description will be given of the overall processing procedure of the data management device 30. Fig. 5 is a flowchart showing an example of the overall processing procedure of the shared area management process by the data management device 30.

[0050] In step S31, the control unit 31 of the data management device 30, under the control of the setting information acquisition processing unit 311, determines whether a setting instruction for data setting information transmitted from one of the user terminals 10 and transmitted over the network NW has been received via the communication I / F 34. The user, who is the data owner, authenticates through the user terminal 10, selects "Set data setting information" on a menu screen after authentication, and can enter the data setting information on the setting screen that appears. Although not specifically illustrated, the control unit 31 may have a web server function that provides the authentication screen, menu screen, and setting screen to the user terminal 10 as web browser screens. Then, in response to a predetermined transmission operation on the setting screen of the web browser, the user terminal 10 transmits a setting instruction for the data setting information. If it is determined that a setting instruction for the data setting information has been received, the control unit 31 determines YES in step S31 and proceeds to the processing operation of step S32. If it is determined that a setting instruction for the data setting information has not been received, the control unit 31 determines NO in step S31 and proceeds to the processing operation of step S33.

[0051] In step S32, the control unit 31, under the control of the setting information acquisition processing unit 311, registers a data ID and an approver based on the setting instruction of the received data setting information. That is, based on the designation in the setting instruction of the data file 111 to be set and the user ID of the user who will be the approver, the control unit 31 stores the corresponding data ID and approver in the setting information storage unit 331. Thereafter, the control unit 31 proceeds to the processing operation of step S33.

[0052] In step S33, the control unit 31, under the control of the workflow management processing unit 312, determines whether a workflow creation request sent from any of the user terminals 10 and transmitted over the network NW has been received via the communication I / F 34. Note that a user who wishes to use data performs authentication on the user terminal 10, and this workflow creation request is sent from the user terminal 10, for example, by performing a predetermined sharing request operation on a menu screen after authentication. If it is determined that a workflow creation request has been received, the control unit 31 determines YES in step S33 and proceeds to the processing operation of step S34. On the other hand, if it is determined that a workflow creation request has not been received, the control unit 31 determines NO in step S33 and proceeds to the processing operation of step S35.

[0053] In step S34, the control unit 31 executes a shared area creation process under the control of the workflow management processing unit 312, area management processing unit 313, and data writing processing unit 314. This shared area creation process is a processing operation that starts a workflow, obtains a sharing agreement between the data owner and the data user, creates a user shared storage area 211, and stores the shared data, and the details of this process will be described later. Thereafter, the control unit 31 proceeds to the processing operation of step S35.

[0054] In step S35, the control unit 31, under the control of the workflow management processing unit 312, determines whether a shared area access request sent from the user terminal 10 of the data user and transmitted over the network NW has been received via the communication I / F 34. The user who is the data user authenticates themselves using the user terminal 10, and then, for example, performs a predetermined shared area access operation on a menu screen after authentication, which causes the shared area access request to be sent from the user terminal 10. If it is determined that a shared area access request has been received, the control unit 31 determines YES in step S35 and proceeds to the processing operation of step S36. If it is determined that a shared area access request has not been received, the control unit 31 determines NO in step S35 and proceeds to the processing operation of step S37.

[0055] In step S36, the control unit 31 executes shared area access processing under the control of the workflow management processing unit 312 and the data writing processing unit 314. This shared area access processing is a processing operation that allows the data user's user terminal 10 to view and edit the shared data stored in the user shared storage area 211, and adds the work history to the workflow management table 212. Details of this shared area access processing operation will be described later. Thereafter, the control unit 31 proceeds to the processing operation of step S37.

[0056] In step S37, the control unit 31 executes a shared area deletion process under the control of the workflow management processing unit 312, the area management processing unit 313, and the data writing processing unit 314. This shared area deletion process is a processing operation for deleting the user shared storage area 211 if any of the shared data stored in each user shared storage area 211 has passed its sharing time limit. Details of this shared area deletion process will be described later. Thereafter, the control unit 31 proceeds to the processing operation of step S31.

[0057] (1) Shared area creation process FIG. 6 is a flowchart showing an example of the processing procedure of the shared area creation processing in step S34 executed by the control unit 31 of the data management device 30.

[0058] Under the control of the workflow management processing unit 312, the control unit 31 first launches a workflow in step S3401, that is, creates a workflow management table and workflow screen information. The workflow management table contains a workflow ID and a sharee ID. The workflow ID is automatically generated by the control unit 31. The sharee ID is the user ID of the authenticated registered user who operated the user terminal 10 that sent the workflow creation request, and can be obtained from the setting information storage unit 331. The created workflow management table and workflow screen information are stored in the temporary storage unit 333.

[0059] Next, in step S3402, the control unit 31, under the control of the workflow management processing unit 312, transmits the workflow screen information to the user terminal 10 via the communication I / F 34 through the network NW.

[0060] Then, in step S3403, under the control of the workflow management processing unit 312, the control unit 31 acquires, via the communication I / F 34, input information that has been entered on the web browser screen of the workflow on the user terminal 10 and that is transmitted from the user terminal 10 via the network NW. The acquired input information is stored in the temporary storage unit 333. The input information is, for example, information about the data to be shared, such as the data desired to be shared and the data owner. The input information may also be a sharing request made by a predetermined sharing request operation after input has been completed.

[0061] In step S3404, the control unit 31, under the control of the workflow management processing unit 312, determines whether the input information is a sharing request. If it is determined that the input information is not a sharing request, the control unit 31 determines NO in step S3404 and proceeds to the processing operation of step S3405. On the other hand, if it is determined that the input information is a sharing request, the control unit 31 determines YES in step S3404 and proceeds to the processing operation of step S3406.

[0062] In step S3405, under the control of the workflow management processing unit 312, the control unit 31 updates the workflow management table and workflow screen information stored in the temporary storage unit 333 based on the input information stored in the temporary storage unit 333. For example, if the input information is information identifying a user who owns data to be shared, the control unit 31 updates the sharing source ID in the workflow management table to the user ID of the identified user. Also, for example, if the input information is information identifying data to be shared, the control unit 31 updates the data ID in the workflow management table to the data ID of the identified data. Also, for example, if the input information is information identifying a period during which sharing is desired, the control unit 31 updates the sharing deadline in the workflow management table to the identified period. Thereafter, the control unit 31 proceeds to the processing operation of step S3402, where the updated workflow screen information is transmitted to the corresponding user terminal 10 via the communication I / F 34 over the network NW.

[0063] Furthermore, in step S3406, under the control of the workflow management processing unit 312, the control unit 31 sends an approval request via the communication I / F 34 and the network NW to the approver who approves the sharing agreement for the data indicated by the data ID in the workflow management table stored in the temporary storage unit 333. That is, the control unit 31 obtains the user ID of the user stored as the approver of the corresponding data ID from the setting information storage unit 331, and further obtains the contact information for that user ID from the setting information storage unit 331 and sends the approval request to the contact information. The approval request may include a workflow ID for identifying the workflow. The approval request may also include an IP address that is link information to workflow screen information for the workflow indicated by the workflow ID.

[0064] Then, in step S3407, under the control of the workflow management processing unit 312, the control unit 31 updates the workflow management table stored in the temporary storage unit 333. Here, the control unit 31 adds the history of the sharing request to the workflow management table.

[0065] Thereafter, under the control of the workflow management processing unit 312, the control unit 31 waits in step S3408 for reception of a workflow screen request corresponding to the approval request from the user terminal 10 via the communication I / F 34 via the network NW. For example, the user terminal 10 of the user who is the approver and who has received the approval request including the workflow ID can accept input of the workflow ID on the approver screen displayed in response to selecting an approver operation on the menu screen after user authentication, and transmit a workflow screen request including the input workflow ID. The control unit 31 determines whether or not a workflow screen request has been received. If it determines that the workflow screen request has not been received, the control unit 31 determines NO in step S3408 and repeats the processing operation of step S3408. If it determines that a workflow screen request has been received, the control unit 31 determines YES in step S3408 and proceeds to the processing operation of step S3409.

[0066] If the approval request includes link information to workflow screen information, the user terminal 10 of the user who received the approval request will transmit a workflow screen request for workflow screen information of the workflow ID indicated by the link information in response to a selection operation of the link information. In this case, since the user has not yet been authenticated, the control unit 31 transmits screen information for user authentication to the user terminal 10 and executes a predetermined authentication process. If the user is authenticated, the control unit 31 determines YES in step S3408 and proceeds to the processing operation of step S3409.

[0067] In step S3409, the control unit 31, under the control of the workflow management processing unit 312, transmits the workflow screen information to the user terminal 10 via the communication I / F 34 through the network NW.

[0068] Then, in step S3410, the control unit 31, under the control of the workflow management processing unit 312, acquires, via the communication I / F 34, input information that has been entered on the web browser screen of the workflow at the user terminal 10 and that is transmitted from the user terminal 10 via the network NW. The acquired input information is stored in the temporary storage unit 333. The input information is either to approve sharing or to disapprove sharing.

[0069] In step S3411, the control unit 31, under the control of the workflow management processing unit 312, determines whether the input information indicates approval of sharing. If it is determined that the input information indicates disapproval, the control unit 31 determines NO in step S3411 and proceeds to the processing operation of step S3419. On the other hand, if it is determined that the input information indicates approval of sharing, the control unit 31 determines YES in step S3411 and proceeds to the processing operation of step S3412.

[0070] Then, in step S3412, the control unit 31, under the control of the workflow management processing unit 312, updates the workflow management table stored in the temporary storage unit 333. Here, the control unit 31 adds approval of the sharing request to the workflow management table.

[0071] Thereafter, in step S3413, the control unit 31, under the control of the workflow management processing unit 312, determines whether approval for data sharing has been obtained from all approvers set for the data ID. If it is determined that approval has not been obtained from all approvers, the control unit 31 determines NO in step S3413 and proceeds to the processing operation of step S3406 above, where it sends approval requests to approvers who have not yet obtained approval. If it is determined that approval has been obtained from all approvers, the control unit 31 determines YES in step S3413 and proceeds to the processing operation of step S3414.

[0072] In step S3414, under the control of the area management processing unit 313, the control unit 31 creates a user shared storage area 211, which is a storage area shared between the share source user terminal 10 and the share destination user terminal 10, in the shared area 21 of the cloud storage 20, and also stores area information about the user shared storage area 211 in the area information storage unit 332. The control unit 31 can create the user shared storage area 211 by sending an instruction to create the user shared storage area 211 to the cloud storage 20 via the communication I / F 34 over the network NW, based on the workflow management table stored in the temporary storage unit 333. Thereafter, the control unit 31 proceeds to the processing operation of step S3415.

[0073] In step S3415, under the control of the data writing processing unit 314, the control unit 31 reads the data file 111 to be shared data from the user dedicated storage area 11, which is the sharing source, via the communication I / F 34 over the network NW, and saves it in the user shared storage area 211, which is the sharing destination. That is, the control unit 31 first reads the data file 111 to be shared data from the corresponding user dedicated storage area 11 over the network NW via the communication I / F 34 based on the workflow management table stored in the temporary storage unit 333, and stores it in the temporary storage unit 333. Then, the control unit 31 identifies the user shared storage area 211 to be the save destination based on the area information stored in the area information storage unit 332, and writes the data file 111 stored in the temporary storage unit 333 to the corresponding user shared storage area 211 over the network NW via the communication I / F 34.

[0074] Thereafter, in step S3416, the control unit 31, under the control of the workflow management processing unit 312, sends a sharing permission notification via the network NW using the communication I / F 34 to the data user identified by the sharer ID in the workflow management table stored in the temporary storage unit 333. That is, the control unit 31 obtains the contact information for the user ID corresponding to the sharer ID from the setting information storage unit 331, and sends the sharing permission notification to the contact information. The sharing permission notification includes the workflow ID for accessing the data file 111, which is the shared data stored in the user shared storage area 211, from the web browser screen of the workflow.

[0075] Then, in step S3417, the control unit 31, under the control of the workflow management processing unit 312 and the data writing processing unit 314, updates the workflow management table stored in the temporary storage unit 333, and saves the updated workflow management table as the workflow management table 212 in the corresponding user shared storage area 211 via the network NW via the communication I / F 34. Note that the update of the workflow management table here adds a history of when sharing started.

[0076] Thereafter, in step S3418, control unit 31, under the control of data write processing unit 314, deletes the temporarily stored information stored in temporary storage unit 333 in each processing operation in the shared area creation processing of step S34. Then, control unit 31 ends the processing operation of this shared area creation processing, and proceeds to the processing operation of step S35.

[0077] In step S3419, which is the processing operation when it is determined in step S3411 that there is unauthorized input information, the control unit 31, under the control of the workflow management processing unit 312, sends a sharing denial notice via the communication I / F 34 and the network NW to the data user identified by the share destination ID in the workflow management table stored in the temporary storage unit 333. Note that it is preferable to configure the workflow screen so that input information on the reason for denial can also be acquired from the user terminal 10, so that the reason for denial can also be sent when this sharing denial notice is sent. Thereafter, the control unit 31 proceeds to the processing operation of step S3418.

[0078] (2) Shared area access processing FIG. 7 is a flowchart showing an example of the processing procedure of the shared area access processing in step S36 executed by the control unit 31 of the data management device 30.

[0079] In step S3601, under the control of the workflow management processing unit 312, the control unit 31 reads the workflow management table 212 from the corresponding user shared storage area 211 via the network NW using the communication I / F 34 based on the shared storage area access request from the user terminal 10 of the data user, and stores the table in the temporary storage unit 333. The control unit 31 can confirm the user shared storage area 211 from which to read the workflow management table 212 based on the workflow ID included in the shared storage area access request, by the shared storage area position stored in the area information storage unit 332 in association with the workflow ID.

[0080] In step S3602, the control unit 31, under the control of the workflow management processing unit 312, creates a workflow screen for operating shared data based on the contents of the workflow management table stored in the temporary storage unit 333.

[0081] Next, in step S3603, the control unit 31, under the control of the workflow management processing unit 312, transmits the workflow screen information to the user terminal 10 of the data user who made the request via the communication I / F 34 over the network NW.

[0082] Then, in step S3604, under the control of the workflow management processing unit 312, the control unit 31 acquires, via the communication I / F 34, input information that has been entered on the web browser screen of the workflow on the user terminal 10 and that is transmitted from the user terminal 10 via the network NW. The acquired input information is stored in the temporary storage unit 333. The input information includes, for example, instructions to refer to the data file 111 that is shared data, update the data file 111, delete the data file 111, end access, etc. Furthermore, although not specifically shown in FIG. 7, the input information may also include other operational instructions for the shared data, such as renaming the data file 111.

[0083] In step S3605, the control unit 31 determines whether the input information indicates the end under the control of the workflow management processing unit 312. If it is determined that the input information indicates the end, the control unit 31 determines NO in step S3605 and proceeds to the processing operation of step S3615. If it is determined that the input information does not indicate the end, the control unit 31 determines YES in step S3605 and proceeds to the processing operation of step S3606.

[0084] In step S3606, the control unit 31 determines whether the input information was a reference under the control of the workflow management processing unit 312. If it is determined that the input information was not a reference, the control unit 31 determines NO in step S3606 and proceeds to the processing operation of step S3611. If it is determined that the input information was a reference, the control unit 31 determines YES in step S3606 and proceeds to the processing operation of step S3607.

[0085] In step S3607, under the control of the data writing processing unit 314, the control unit 31 reads the data file 111, which is shared data, from the user shared storage area 211 via the network NW using the communication I / F 34 based on the contents of the workflow management table stored in the temporary storage unit 333, and stores the data file 111 in the temporary storage unit 333. The control unit 31 can obtain the shared area location in the user shared storage area 211 from which the data file 111 is to be read, from the area information storage unit 332, based on the workflow ID listed in the workflow management table.

[0086] In step S3608, under the control of the data writing processing unit 314, the control unit 31 saves the data file 111, which is the shared data stored in the temporary storage unit 333, in the user-dedicated storage area 11 of the data user via the network NW using the communication I / F 34. The control unit 31 can acquire the location of each user's user-dedicated storage area 11 from the area information storage unit 332, based on the user ID indicated by the sharer ID written in the workflow management table stored in the temporary storage unit 333.

[0087] Thereafter, in step S3609, the control unit 31, under the control of the workflow management processing unit 312, updates the workflow management table stored in the temporary storage unit 333. For example, a history of share destination references is added.

[0088] Then, in step S3610, the control unit 31, under the control of the workflow management processing unit 312, updates the workflow screen based on the workflow management table stored in the temporary storage unit 333. Thereafter, the control unit 31 proceeds to the processing operation of step S3603, and transmits the updated workflow screen information to the user terminal 10 of the data user via the network NW using the communication I / F 34.

[0089] Furthermore, in step S3611, the control unit 31 determines whether the input information is a data update under the control of the workflow management processing unit 312. If it is determined that the input information is not a data update, the control unit 31 determines NO in step S3611 and proceeds to the processing operation of step S3614. If it is determined that the input information is a data update, the control unit 31 determines YES in step S3611 and proceeds to the processing operation of step S3612.

[0090] In step S3612, under the control of the workflow management processing unit 312, the control unit 31 acquires update data from the data user's user terminal 10 via the network NW using the communication I / F 34, and stores the data in the temporary storage unit 333. For example, the data user's user terminal 10 is configured to allow update data to be set on the workflow web browser screen prior to issuing a data update instruction. The control unit 31 acquires this set update data.

[0091] Then, in step S3613, under the control of the data write processing unit 314, the control unit 31 updates the data file 111 stored in the user shared storage area 211 with the update data stored in the temporary storage unit 333. That is, the control unit 31 overwrites and saves the update data as the data file 111 in the corresponding user shared storage area 211 via the network NW using the communication I / F 34. The control unit 31 can obtain the shared area location in the user shared storage area 211 where the shared data is to be updated from the area information storage unit 332, based on the workflow ID listed in the workflow management table stored in the temporary storage unit 333. Thereafter, the control unit 31 proceeds to the processing operation of step S3609 above, and updates the workflow management table stored in the temporary storage unit 333. For example, the control unit 31 adds a history of editing at the shared destination.

[0092] Furthermore, in step S3614, the control unit 31 determines that the input information is an instruction to delete shared data, and deletes the data file 111, which is the shared data, from the user shared storage area 211 via the network NW using the communication I / F 34 under the control of the data write processing unit 314. The control unit 31 can acquire the shared area location in the user shared storage area 211 from which the shared data is to be deleted from the area information storage unit 332, based on the workflow ID listed in the workflow management table stored in the temporary storage unit 333. Thereafter, the control unit 31 proceeds to the processing operation of step S3609 above, and updates the workflow management table stored in the temporary storage unit 333. For example, a history of shared destination deletion may be added.

[0093] Furthermore, in step S3615, under the control of the workflow management processing unit 312 and the data writing processing unit 314, the control unit 31 saves the workflow management table stored in the temporary storage unit 333 as the workflow management table 212 in the corresponding user shared storage area 211 via the network NW using the communication I / F 34. The control unit 31 can acquire the shared area location in the user shared storage area 211 as the save destination from the area information storage unit 332, based on the workflow ID written in the workflow management table stored in the temporary storage unit 333.

[0094] Thereafter, in step S3616, the control unit 31, under the control of the data write processing unit 314, deletes the temporarily stored information stored in the temporary storage unit 333 in each processing operation in the shared area access processing of this step S36. Then, the control unit 31 ends the processing operation of this shared area access processing, and proceeds to the processing operation of the above step S37.

[0095] (3) Shared area deletion process FIG. 8 is a flowchart showing an example of the processing procedure of the shared area deletion processing in step S37 executed by the control unit 31 of the data management device 30.

[0096] First, in step S3701, the control unit 31 selects one user shared storage area 211 as a processing target under the control of the workflow management processing unit 312 and the area management processing unit 313. For example, the control unit 31 selects one piece of area information from the area information related to the multiple user shared storage areas 211 stored in the area information storage unit 332, thereby selecting this user shared storage area 211 as a processing target.

[0097] Next, in step S3702, under the control of the workflow management processing unit 312, the control unit 31 reads the workflow management table 212 from the selected user shared storage area 211 via the network NW using the communication I / F 34, and stores it in the temporary storage unit 333. The control unit 31 can confirm the shared area location of the relevant user shared storage area 211 from the area information related to the user shared storage area 211.

[0098] Then, in step S3703, the control unit 31, under the control of the workflow management processing unit 312, determines whether the sharing deadline has expired based on the sharing deadline recorded in the workflow management table stored in the temporary storage unit 333. If it is determined that the sharing deadline has expired, the control unit 31 determines YES in step S3703 and proceeds to the processing operation of step S3706. On the other hand, if it is determined that the sharing deadline has not expired, the control unit 31 determines NO in step S3703 and proceeds to the processing operation of step S3704.

[0099] In step S3704, under the control of the area management processing unit 313, the control unit 31 deletes the temporarily stored information stored in the temporary storage unit 333 in each processing operation in the shared area deletion processing in step S37.

[0100] Thereafter, in step S3705, the control unit 31, under the control of the workflow management processing unit 312, determines whether or not the selection of all user shared storage areas 211 as processing targets has been completed. If it is determined that the selection of all user shared storage areas 211 has been completed, the control unit 31 determines YES in step S3705, terminates the processing operation of this shared storage area deletion process, and proceeds to the processing operation of step S31. On the other hand, if it is determined that the selection of all user shared storage areas 211 has not yet been completed, the control unit 31 determines NO in step S3705, proceeds to the processing operation of step S3701, and selects the next user shared storage area 211 to be processed.

[0101] Furthermore, in step S3706, the control unit 31, under the control of the workflow management processing unit 312, saves the workflow management table stored in the temporary storage unit 333 in the user dedicated storage area 11 of the user who is the data owner. The control unit 31 searches the area information storage unit 332 for the owner's user ID corresponding to the sharing source ID written in the workflow management table, and can acquire the dedicated area location associated with that owner as the dedicated area location in the user dedicated storage area 11 where the data is to be saved.

[0102] Furthermore, in step S3707, the control unit 31, under the control of the workflow management processing unit 312, determines whether updated data exists in the corresponding user shared storage area 211. For example, whether updated data exists can be determined based on whether shared destination editing is listed as history in the workflow management table stored in the temporary storage unit 333. If it is determined that updated data does not exist, the control unit 31 determines NO in step S3707 and proceeds to the processing operation of step S3710. On the other hand, if it is determined that updated data exists, the control unit 31 determines YES in step S3707 and proceeds to the processing operation of step S3708.

[0103] In step S3708, under the control of the data writing processing unit 314, the control unit 31 reads the updated data from the user shared memory area 211 confirmed in step S3702 above via the network NW using the communication I / F 34, and stores it in the temporary memory unit 333.

[0104] In step S3709, under the control of the data writing processing unit 314, the control unit 31 saves the updated data stored in the temporary storage unit 333 via the communication I / F 34 over the network NW in the user dedicated storage area 11 of the user who is the data owner confirmed in step S3706 above. At this time, the file name may be renamed by adding a character string indicating that it is updated data, so as not to overwrite data already stored in the user dedicated storage area 11.

[0105] In step S3710, under the control of the area management processing unit 313, the control unit 31 deletes the selected user shared storage area 211 via the network NW using the communication I / F .

[0106] Furthermore, in step S3711, the control unit 31, under the control of the area management processing unit 313, deletes the area information relating to the deleted user shared storage area 211 from the area information storage unit 332.

[0107] Then, in step S3712, the control unit 31, under the control of the workflow management processing unit 312, reports, for example by email, to the user who is the data owner of the shared data and the user who is the data user, that the user shared storage area 211 has been deleted. The control unit 31 can obtain the contact information for that user ID from the setting information storage unit 331 using the sharing source ID and sharing destination ID listed in the workflow management table stored in the temporary storage unit 333. Note that if the shared data has been updated and the updated data has been saved in the user-only storage area 11 of the data owner user in step S3709, the control unit 31 also reports this to the data owner user. Thereafter, the control unit 31 proceeds to the processing operation of step S3704.

[0108] (Actions and Effects) As described above, the data management device 30 according to the first embodiment of the present invention is a data management device that manages data sharing between a data owner who is a first user and a data user who is a second user, and includes a communication I / F 34 that communicates with the user terminal 10 that is a first user terminal operated by the data owner and the user terminal 10 that is a second user terminal operated by the data user, and a control unit 31 that controls the data management device 30. The control unit 31 also includes a workflow management processing unit 312 that creates a workflow for inputting information about the data to be shared from the data user's user terminal 10, causes the data user's user terminal 10 to input at least part of the information about the data using the workflow, and causes the data owner's user terminal 10 to view the workflow after input by the data user's user terminal 10. The workflow management processing unit 312 further permits the data user's user terminal 10, upon approval from the data owner's user terminal 10, to access a copy of the data stored in the user shared storage area 211 accessible only to the data owner and the data user, which is isolated from the data user and accessible only to the data owner. Therefore, the data user is required to input the information necessary for sharing the data, and the data owner only needs to perform the approval operation, so that data can be shared among users with less work burden on the data owner.

[0109] Furthermore, in the data management device 30 according to the first embodiment, the workflow management processing unit 312 creates a workflow in response to a workflow creation request, which is a sharing request from the user terminal 10 of the data user, and causes the user terminal 10 of the data user to input at least part of the information relating to the data by the workflow. Then, the area management processing unit 313 of the data management device 30 creates a user shared storage area 211 in response to approval from the user terminal 10 of the data owner, and the data writing processing unit 314 of the data management device 30 stores a copy of the data stored in the user dedicated storage area 11 in the user shared storage area 211. Therefore, upon receiving a sharing request from a data user, the data management device 30 creates a workflow, and upon receiving approval from the data owner, stores the data in the user shared storage area 211, so that the data owner only needs to perform the approval operation to automatically start sharing the data.

[0110] The information about the data to be shared includes at least a data ID that identifies the data, a sharing source ID that identifies the data owner, a sharing destination ID that identifies the data user, and a sharing deadline for the data. The workflow management processing unit 312 of the data management device 30 stores a workflow management table 212 that describes information about the data input by the workflow in the user shared memory area 211, and the area management processing unit 313 deletes the user shared memory area 211 that stores data whose sharing deadline has passed, based on the sharing deadline described in the workflow management table 212. Therefore, the period for sharing data in the user shared storage area 211 can be managed based on the sharing deadline recorded in the workflow management table 212 .

[0111] Furthermore, in the data management device 30 according to the first embodiment, the workflow management processing unit 312 adds the access history to the workflow management table 212 each time a copy of data in the user shared memory area 211 is accessed from the data user's user terminal 10, and when the area management processing unit 313 deletes the user shared memory area 211, it saves the workflow management table 212 in the user-only memory area 11 of the data owner where the data is stored. Therefore, the data owner can check the usage history of the shared data by the data user even after the sharing is terminated.

[0112] [Second embodiment] Next, a data management device 30 according to a second embodiment of the present invention will be described. In the first embodiment, a workflow is created in response to a data user's request for sharing. In contrast, in the second embodiment, the data management device 30 automatically creates a workflow when an abnormality is detected based on the data stored in the user-dedicated storage area 11.

[0113] Here, only the configuration, operation, and effects that differ from those of the first embodiment will be described, and descriptions of the similar parts will be omitted.

[0114] (Configuration example) FIG. 9 is a block diagram showing an example of the software configuration of a data management device 30 according to the second embodiment of the present invention.

[0115] In this embodiment, the control unit 31 of the data management device 30 includes an anomaly detection processor 315 in addition to the configuration of the first embodiment. The anomaly detection processor 315 monitors daily updated data, such as machine operation log data, stored in each user-dedicated storage area 11, and performs processing to detect anomalies, such as failures, in the data source machine from the data content. While the anomaly detection method is not particularly limited here, anomalies can be detected, for example, by pattern matching with pre-registered anomaly patterns or by discrepancies with daily data learned by AI. While all data stored in the user-dedicated storage area 11 may be monitored, it is preferable to determine the data to be monitored in advance from the user terminal 10 of the data owner, since it is pointless to monitor unnecessary data for anomaly detection.

[0116] Furthermore, in this embodiment, the setting information storage unit 331 of the data storage unit 33 further includes a maintainer in the data setting information for each piece of data stored in the individual areas 12 and 41. The maintainer is the user ID of a registered user registered as the manufacturer of the device that generated the data or the maintenance contact. Furthermore, if the abnormality detection processing unit 315 detects an abnormality, such as a failure, in the machine that generated the data based on the monitored data, it performs processing to report the abnormality detection to the data owner and maintainer of the data. The data owner can be identified by the approver in the data setting information stored in the setting information storage unit 331.

[0117] Furthermore, in this embodiment, when the abnormality detection processing unit 315 detects an abnormality such as a breakdown in the data source machine based on the monitored data, the workflow management processing unit 312 performs processing to launch a workflow for agreeing to share the data.

[0118] (Example of operation) FIG. 10 is a flowchart showing an example of the overall processing procedure of the shared area management processing by the data management device 30 according to the second embodiment.

[0119] In this embodiment, if it is determined in step S35 that a shared area access request has not been received and the determination is NO, the control unit 31 proceeds to the processing operation of step S38. After executing the shared area access process in step S36, the control unit 31 proceeds to the processing operation of step S38.

[0120] In step S38, the control unit 31 executes an abnormality detection process under the control of the workflow management processing unit 312, area management processing unit 313, data writing processing unit 314, and abnormality detection processing unit 315. This abnormality detection process is a processing operation that detects an abnormality using data to be monitored for an abnormality stored in each user-dedicated memory area 11, and if an abnormality is detected, launches a workflow, creates a user shared memory area 211, and sends an abnormality detection report notifying the data owner and maintainer of the abnormality. Details of this abnormality detection process will be described later. Thereafter, the control unit 31 proceeds to the processing operation of step S39. Note that the abnormality detection report to the maintainer may include a workflow ID that identifies the workflow.

[0121] In step S39, the control unit 31, under the control of the workflow management processing unit 312, determines whether or not a workflow screen request including a workflow ID has been received from the user terminal 10 of the maintainer via the network NW through the communication I / F 34. If it is determined that a workflow screen request from the maintainer has not been received, the control unit 31 determines NO in step S39 and proceeds to the processing operation of step S31 above. If it is determined that a workflow screen request from the maintainer has been received, the control unit 31 determines YES in step S39 and proceeds to the processing operation of step S3A.

[0122] The anomaly detection report sent by the anomaly detection process in step S38 above is delivered to both the data owner of the data that caused the anomaly detection and the maintainer set for that data. The data owner and maintainer who receive this anomaly detection report can communicate with each other via communication tools such as telephone or email. Depending on the nature of the anomaly, the maintainer may need to analyze the data. In such a case, the maintainer's user terminal 10 sends a workflow screen request to the data management device 30, requesting that the data be shared. For example, the maintainer's user terminal 10 receives the anomaly detection report including the workflow ID, and by entering this workflow ID in the sharing request operation on the menu screen after user authentication, the maintainer's user terminal 10 sends a workflow screen request including the workflow ID instead of a workflow creation request.

[0123] In step S3A, the control unit 31 executes anomaly response shared area creation processing under the control of the workflow management processing unit 312 and the data writing processing unit 314. This anomaly response shared area creation processing is a processing operation for obtaining a sharing agreement with the data owner and saving the data in the user shared storage area 211. Details of this anomaly response shared area creation processing will be described later. Thereafter, the control unit 31 proceeds to the processing operation of step S31.

[0124] (1) Abnormality detection processing FIG. 11 is a flowchart showing an example of the procedure of the abnormality detection process in step S38 executed by the control unit 31 of the data management device 30.

[0125] First, in step S3801, the control unit 31 selects one user dedicated memory area 11 as a processing target under the control of the abnormality detection processing unit 315. For example, the control unit 31 selects one piece of area information from the area information related to the multiple user dedicated memory areas 11 stored in the area information storage unit 332, thereby selecting this user dedicated memory area 11 as the processing target.

[0126] Next, in step S3802, under the control of the abnormality detection processing unit 315, the control unit 31 reads one piece of monitoring target data, which is dedicated data, from the selected user dedicated memory area 11 via the network NW using the communication I / F 34, and stores the data in the temporary memory unit 333. The control unit 31 can confirm the dedicated area location of the corresponding user dedicated memory area 11 from the area information related to the user dedicated memory area 11.

[0127] Then, in step S3803, under the control of the abnormality detection processing unit 315, the control unit 31 determines whether or not an abnormality, such as a breakdown, has occurred in the machine that generated the monitoring target data, based on the monitoring target data stored in the temporary storage unit 333. If it is determined that an abnormality has occurred, the control unit 31 determines YES in step S3803 and proceeds to the processing operation of step S3806. On the other hand, if it is determined that no abnormality has occurred, the control unit 31 determines NO in step S3803 and proceeds to the processing operation of step S3804.

[0128] In step S3804, under the control of the abnormality detection processing unit 315, the control unit 31 deletes the temporarily stored information stored in the temporary storage unit 333 in each processing operation in the abnormality detection processing in step S38.

[0129] Thereafter, in step S3805, the control unit 31, under the control of the anomaly detection processing unit 315, determines whether the anomaly detection processing operation has been completed for all monitoring target data stored in the selected user-dedicated memory area 11. If it is determined that the processing operation for all monitoring target data has been completed, the control unit 31 determines YES in step S3805 and proceeds to the processing operation of step S3811. On the other hand, if it is determined that the processing operation for all monitoring target data has not yet been completed, the control unit 31 determines NO in step S3805 and proceeds to the processing operation of step S3802, where the next monitoring target data is read.

[0130] Furthermore, in step S3806, the control unit 31 launches a workflow under the control of the workflow management processing unit 312, i.e., creates a workflow management table. The workflow management table contains a workflow ID, a sharing source ID, a sharing destination ID, a data ID, and a sharing deadline. Here, the workflow ID is automatically generated by the control unit 31. Furthermore, the data ID is the data ID of the data to be monitored, and the control unit 31 can obtain the approver and maintainer as the sharing source ID and sharing destination ID from the setting information storage unit 331 using this data ID. The control unit 31 automatically generates the sharing deadline as a certain number of days assumed to be the consultation period between the data owner and the maintainer. The created workflow management table is stored in the temporary storage unit 333.

[0131] In step S3807, under the control of the area management processing unit 313, the control unit 31 creates a user shared storage area 211, which is a storage area shared between the user terminal 10 of the data owner and the user terminal 10 of the maintainer, in the shared area 21 of the cloud storage 20, and also stores area information about the user shared storage area 211 in the area information storage unit 332. The control unit 31 can create the user shared storage area 211 by sending an instruction to create the user shared storage area 211 to the cloud storage 20 via the communication I / F 34 over the network NW based on the workflow management table stored in the temporary storage unit 333. Thereafter, the control unit 31 proceeds to the processing operation of step S3808.

[0132] In step S3808, under the control of the data writing processing unit 314, the control unit 31 saves the workflow management table stored in the temporary storage unit 333 as the workflow management table 212 in the corresponding user shared storage area 211 via the network NW via the communication I / F 34.

[0133] Furthermore, in step S3809, under the control of the data writing processing unit 314, the control unit 31 saves the monitored data stored in the temporary memory unit 333 as shared data in the corresponding user shared memory area 211 via the network NW using the communication I / F 34.

[0134] Then, in step S3810, the control unit 31, under the control of the abnormality detection processing unit 315, sends an abnormality detection report, for example by email, to the approver who is the owner of the monitored data and the maintenance person who maintains the machine that is the source of the monitored data, notifying them of the detection of an abnormality. The abnormality detection report to the maintenance person may include a workflow ID that identifies the workflow management table 212. Thereafter, the control unit 31 proceeds to the processing operation of step S3804 above.

[0135] Furthermore, in step S3811, the control unit 31, under the control of the abnormality detection processing unit 315, determines whether or not the selection of all user-dedicated storage areas 11 as processing targets has been completed. If it is determined that the selection of all user-dedicated storage areas 11 has been completed, the control unit 31 determines YES in step S3811, terminates the processing operation of this abnormality detection processing, and proceeds to the processing operation of step S39. If it is determined that the selection of all user-dedicated storage areas 11 has not yet been completed, the control unit 31 determines NO in step S3811, proceeds to the processing operation of step S3801, and selects the next user-dedicated storage area 11 to be processed.

[0136] In the processing operation of this anomaly detection process, a user shared storage area 211 is created and the shared data and workflow management table 212 are stored there, but this is not reported to either the data owner or the maintainer. Therefore, the data owner and the maintainer cannot access the user shared storage area 211. Here, the monitored data for which an anomaly has been detected is simply saved in the user shared storage area 211.

[0137] (2) Creation of a shared area for handling abnormalities FIG. 12 is a flowchart showing an example of the processing procedure of the anomaly handling shared area creation processing in step S3A executed by the control unit 31 of the data management device 30.

[0138] Under the control of the workflow management processing unit 312, the control unit 31 first reads the workflow management table 212 from the user shared storage area 211 and creates a workflow screen in step S3A01. That is, based on a workflow screen request from the user terminal 10 of the maintainer, the control unit 31 reads the workflow management table 212 from the corresponding user shared storage area 211 via the network NW using the communication I / F 34 and stores it in the temporary storage unit 333. Based on the workflow ID included in the workflow screen request, the control unit 31 can confirm the user shared storage area 211 from which the workflow management table 212 is to be read by the shared storage location stored in the area information storage unit 332 in association with the workflow ID.

[0139] Next, in step S3A02, the control unit 31 transmits the workflow screen information to the user terminal 10 via the communication I / F 34 through the network NW under the control of the workflow management processing unit 312, similar to step S3402.

[0140] Then, in step S3A03, similarly to step S3403, the control unit 31, under the control of the workflow management processing unit 312, acquires input information transmitted from the user terminal 10 via the network NW, via the communication I / F 34. The acquired input information is stored in the temporary storage unit 333. In this case, the data to be shared, the data owner, etc. are already included in the workflow screen information transmitted to the user terminal 10. Therefore, the input information is either information related to setting a sharing period or a sharing request.

[0141] In step S3A04, the control unit 31, under the control of the workflow management processing unit 312, determines whether or not the input information is a sharing request, similarly to step S3404.

[0142] If it is determined that the input information is not a sharing request, the control unit 31, in step S3A05, under the control of the workflow management processing unit 312, updates the workflow management table and workflow screen information stored in the temporary storage unit 333 based on the input information stored in the temporary storage unit 333, as in step S3405 above.

[0143] Furthermore, if it is determined in step S3A04 that the input information is a sharing request, the control unit 31 executes processing operations in steps S3A06 to S3A13 to obtain approval for data sharing from all approvers under the control of the workflow management processing unit 312, similar to steps S3406 to S3413.

[0144] Then, when approval for data sharing is obtained from all approvers, in step S3A14, similar to step S3416 above, the control unit 31, under the control of the workflow management processing unit 312, sends a sharing permission notification to the maintainer, who is the data user, via the network NW using the communication I / F 34. Because the user shared storage area has already been created and the shared data has already been stored therein, there is no need for processing operations such as those in steps S3414 and S3415 above.

[0145] Then, in step S3A15, similar to step S3417, the control unit 31 updates the workflow management table stored in the temporary storage unit 333 under the control of the workflow management processing unit 312 and the data writing processing unit 314, and saves the updated workflow management table as the workflow management table 212 in the corresponding user shared storage area 211 via the network NW via the communication I / F 34. Note that the update to the workflow management table here adds a history of sharing requests, approvals, and sharing starts, and also changes the sharing deadline to one specified by the maintainer.

[0146] Thereafter, in step S3A16, the control unit 31, under the control of the data write processing unit 314, deletes the temporarily stored information stored in the temporary storage unit 333 in each processing operation in the abnormality response shared area creation processing of step S3A. Then, the control unit 31 ends the processing operation of this abnormality response shared area creation processing, and proceeds to the processing operation of step S31.

[0147] Furthermore, in step S3A17, which is a processing operation when it is determined in step S3A11 that there is unauthorized input information, the control unit 31, similar to step S3419, transmits a sharing denial notification to the data user via the network NW by the communication I / F 34 under the control of the workflow management processing unit 312. Thereafter, the control unit 31 proceeds to the processing operation of step S3A17.

[0148] (3) Shared area deletion process 13 is a flowchart showing a portion of an example of the processing procedure for the shared area deletion processing in step S37 executed by the control unit 31 of the data management device 30. In this embodiment, to deal with a case where a workflow screen request is not made by the maintenance person in response to the abnormality detection report, a portion of the processing procedure for the shared area deletion processing is changed from that in the first embodiment. This changed portion will be described below.

[0149] If it is determined in step S3703 that the sharing time limit has expired, the control unit 31 determines YES in step S3703, and in this embodiment, the process proceeds to the processing operation of step S3721.

[0150] In step S3703, the control unit 31, under the control of the workflow management processing unit 312, determines whether a history is recorded in the workflow management table stored in the temporary storage unit 333. If the workflow management table 212 stored in the user shared storage area 211 created in the abnormality detection processing operation in step S38 above has been stored but no workflow screen request has been made by the maintenance person, no history is recorded. Therefore, by determining whether or not this history exists, it is possible to determine whether the workflow was actually shared. If it is determined that a history is recorded, the control unit 31 determines YES in step S3721 and proceeds to the processing operation of step S3706 above. On the other hand, if it is determined that a history is not recorded, the control unit 31 determines NO in step S3721 and proceeds to the processing operation of step S3722.

[0151] In step S3722, under the control of the area management processing unit 313, the control unit 31 deletes the selected user shared storage area 211 via the network NW through the communication I / F .

[0152] Furthermore, in step S3723, under the control of the area management processing unit 313, the control unit 31 deletes the area information related to the deleted user shared storage area 211 from the area information storage unit 332. Thereafter, the control unit 31 proceeds to the processing operation of step S3704.

[0153] (Actions and Effects) As described above, the data user in the second embodiment of the present invention is a maintenance person who maintains the machine from which the data stored in the user-dedicated memory area 11 originates, and the data management device 30 in the second embodiment comprises an abnormality detection processing unit 315 that monitors the data stored in the user-dedicated memory area 11, detects the occurrence of an abnormality in the machine from which the data originates based on the monitored data, and reports the detection of the abnormality to the user terminals 10 of the data owner and the data user, respectively; an area management processing unit 313 that creates a user shared memory area 211 in response to the detection of the abnormality; and a data writing processing unit 314 that stores a copy of the data stored in the user-dedicated memory area 11 in the user shared memory area 211. Then, in response to detecting the occurrence of an abnormality, the workflow management processing unit 312 creates a workflow into which information regarding the data to be shared is input, causes the data user's user terminal 10 to update and input at least part of the information regarding the data using the workflow, allows the data owner's user terminal 10 to view the workflow after the update and input by the data user's user terminal 10, and, in response to approval from the data owner's user terminal 10, permits the data user's user terminal 10 to access a copy of the data stored in the user shared memory area 211. Therefore, the data management device 30 creates a workflow upon detecting an abnormality based on the monitored data, and after receiving approval from the data owner for the workflow modified by the data user who is the maintainer, it creates the user shared storage area 211 and stores the data therein.Therefore, the data owner only needs to perform the approval operation, and data sharing will begin automatically.

[0154] [Other embodiments] In the first and second embodiments, all user data is stored in the user shared storage area 211, but it is also possible to create a new data file that is different from the original data by extracting at least a portion of the data from the data file 111 or by processing the actual data into an anonymized and abstracted (generalized) format to create processed data, and store this as shared data.

[0155] In addition, in the first and second embodiments, the user data in the user-dedicated memory area 11 is copied to the user shared memory area 211, but as in non-patent document 2, the user data may be stored virtually in the user shared memory area 211 by storing a symbolic link to the user data.

[0156] Furthermore, in the first and second embodiments, the user terminal 10 of the data user accesses the shared data stored in the user shared storage area 211 via the data management device 30, but this may be done without going through the data management device 30. In that case, however, the data sharing system 1 must additionally have a function to detect that the user terminal 10 of the data user has accessed the user shared storage area 211 and notify the data management device 30, or a function to update the history of the workflow management table 212 in response to access from the user terminal 10.

[0157] Furthermore, in the first and second embodiments, a user shared storage area 211 is created for each shared data item, but multiple shared data items may be stored in one user shared storage area 211. In this case, deletion of the user shared storage area 211 itself is put on hold until all the shared data in the user shared storage area 211 is deleted. In this case, the workflow management tables 212 for each shared data item may be merged.

[0158] 5 to 8 and 10 to 13 are merely examples, and the order of the processing steps is not limited to these. For example, the order of steps S3406 and S3407 in Fig. 6 may be reversed. The order of each processing step may be changed or may be performed in parallel, as long as there is no discrepancy with the preceding or following processing step.

[0159] Although the embodiments of the present invention have been described in detail above, the above description is merely an example of the present invention in every respect. It goes without saying that various improvements and modifications can be made without departing from the scope of the present invention. In other words, when implementing the present invention, specific configurations according to the embodiments may be appropriately adopted.

[0160] In short, this invention is not limited to the above-described embodiments, and the components can be modified and embodied in practice without departing from the spirit of the invention. Furthermore, various inventions can be formed by appropriately combining multiple components disclosed in the above-described embodiments. For example, some components may be omitted from all the components shown in each embodiment. Furthermore, components from different embodiments may be appropriately combined. [Explanation of symbols]

[0161] 1. Data sharing system 10...User terminal 10A1, 10A2...User A terminal 10B...User B terminal 10C...User C terminal 11...User-dedicated storage area 11A... User A dedicated storage area 11B: User B dedicated storage area 11C: User C dedicated storage area 12,41…Individual area 20,40…Cloud storage 21…Shared area 30...Data management device 31...Control unit 32...Program memory section 33...Data storage unit 34...Communication interface (communication I / F) 35...Bus 41…Individual area 111...Data file 211…User shared storage area 2111…User A+B shared storage area 2112…User A+C shared storage area 212...Workflow management table 311...setting information acquisition processing unit 312...Workflow management processing unit 313...Area management processing unit 314...Data writing processing unit 315...Abnormality detection processing unit 331...setting information storage unit 332…Area information storage unit 333…Temporary storage unit NW...Network

Claims

1. A data management device that manages data sharing between a first user who is an owner of data and a second user who uses the data, comprising: a communication interface for communicating with a first user terminal operated by the first user and a second user terminal operated by the second user; a control unit that controls the data management device; Equipped with The control unit having the second user terminal input at least a portion of information related to the data to be shared; allowing the first user terminal to view information regarding the data to be shared after input by the second user terminal; granting the second user terminal access to the shared data in response to authorization from the first user terminal; the data is stored in a dedicated storage area isolated from the second user and accessible only by the first user; A data management device, wherein the shared data includes at least one of a copy of the data, a symbolic link to the data, data obtained by extracting a portion of the data, and processed data obtained by processing at least a portion of the data.

2. The control unit creating a workflow for inputting information about the data to be shared from the second user terminal in response to a sharing request from the second user terminal; having the second user terminal input at least a portion of information regarding the data to be shared through the workflow; a workflow management processing unit that allows the first user terminal to view the workflow after input by the second user terminal; an area management processing unit that creates a shared storage area in response to approval from the first user terminal; The data management device according to claim 1 , further comprising: a data writing processor that stores the shared data in the shared storage area.

3. the second user is a maintenance person who maintains a machine that is a source of the data stored in the dedicated storage area, The data management device an abnormality detection processing unit that monitors the data stored in the dedicated storage area, detects an abnormality in the source machine of the data based on the monitored data, and reports the detection of the abnormality to the first and second user terminals; the area management processing unit creates the shared storage area in response to the detection of the occurrence of the abnormality, The workflow management processing unit creating the workflow into which information regarding the data to be shared is input in response to the detection of the occurrence of the abnormality; updating and inputting at least a part of information related to the data to be shared from the second user terminal through the workflow; causing the first user terminal to view the workflow after the update input by the second user terminal; The data management device according to claim 2 , wherein the second user terminal is permitted to access the shared data in response to approval from the first user terminal.

4. the information about the data to be shared includes at least a data ID that identifies the data to be shared, a sharing source ID that identifies the first user, a sharing destination ID that identifies the second user, and a sharing expiration date of the data to be shared; the workflow management processing unit stores in the shared storage area a workflow management table that describes information about the data input through the workflow; The data management device according to claim 2 or 3, wherein the area management processing unit deletes the shared memory area storing the shared data whose sharing deadline has passed, based on the sharing deadline described in the workflow management table.

5. the workflow management processing unit adds an access history to the workflow management table every time the second user terminal accesses the shared data; 5. The data management device according to claim 4, wherein, when deleting the shared storage area, the area management processing unit saves the workflow management table in the dedicated storage area of ​​the first user in which the data is stored.

6. a storage unit including the dedicated storage area and the shared storage area; A data management device according to any one of claims 3 to 5; A data sharing system comprising:

7. 7. The data sharing system of claim 6, wherein the storage unit includes a first storage device having the dedicated storage area, and a second storage device physically different from the first storage device in which the shared storage area is created.

8. A data sharing method for sharing data between a first user who is an owner of the data and a second user who uses the data, comprising: The computer a step of inputting at least a part of information regarding the data to be shared from a second user terminal operated by the second user; a step of displaying the information on the data to be shared after input by the second user terminal on a first user terminal operated by the first user; granting the second user terminal access to the shared data in response to authorization from the first user terminal; Equipped with the data is stored in a dedicated storage area isolated from the second user and accessible only by the first user; A data sharing method, wherein the shared data includes at least one of a copy of the data, a symbolic link to the data, data obtained by extracting a portion of the data, and processed data obtained by processing at least a portion of the data.

9. A data management program that causes a computer to execute processing by each processing unit included in the data management device according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Personnel search system, server and method, program, and recording medium

    JP2005208945A

  • Browsing-approval file system for confidential document

    JP2009032212A

  • Data management device, data management method, and program

    JP2012168630A

  • Information processing device and information processing program

    JP2019079224A

  • File sharing device

    JP2019200643A