Analytical device, analytical management system, and program

The analytical device and management system enforce confidentiality levels to secure sample handling and analysis, addressing unauthorized access issues in remote systems by restricting display and operation functions.

JP7806550B2Active Publication Date: 2026-01-27KK TOYOTA CHUO KENKYUSHO
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2022029670
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-02-28
Publication Date
2026-01-27
Estimated Expiration
2042-02-28

AI Technical Summary

Technical Problem

Existing remote analysis systems struggle to maintain the confidentiality of samples due to the potential for unauthorized access by on-site analysts with high authority, complicating efficient analysis support during abnormalities.

Method used

An analytical device and management system that sets and enforces confidentiality levels for samples and devices, restricting functions related to display and operation based on predefined thresholds to ensure secure handling and analysis.

Benefits of technology

Maintains sample confidentiality by restricting access and operations based on predefined security levels, ensuring secure handling and efficient analysis support even during abnormalities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007806550000001
    Figure 0007806550000001
  • Figure 0007806550000002
    Figure 0007806550000002
  • Figure 0007806550000003
    Figure 0007806550000003
Patent Text Reader

Abstract

To provide an analysis apparatus capable of preserving confidentiality of samples in analyzing the samples in accordance with a request for analysis from a remote place, an analysis management system, and a program.SOLUTION: An analysis apparatus includes: an acquisition unit which acquires a specific value of a first confidential level that represents confidentiality of a sample to be analyzed; a setting unit which sets, on the apparatus for analyzing the sample, a specific value of a second confidential level corresponding to the specific value of the first confidential level acquired by the acquisition unit, the second confidential level representing confidentiality of the apparatus; a functionality modification unit which modifies, when the specific value of the second confidential level set by the setting unit is equal to or higher than a threshold, functionality of the apparatus so as to restrict a part of the functionality related to display and operation; and an analysis processing unit which automatically analyzes the sample to be analyzed, under the functionality of the apparatus.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an analytical device, an analysis management system, and a program. [Background technology]

[0002] In business models where analysis is contracted via a network, access to the samples themselves and analytical information must be managed from the time of request until the receipt of the results, so that the client can request the analysis without worrying about information leaks. In particular, high confidentiality is required for analyses related to new products or product defects.

[0003] Patent Document 1 discloses a method for supporting the use of an analytical device by a customer in a communication system in which a server computer connected to an analytical device used at an analytical center that owns the analytical device, which is remotely operated based on an external operation signal to analyze samples and output analysis result data representing the analysis results, and a client computer used by a customer who wishes to analyze samples using the analytical device are communicatively connected to each other via a communication network, the method including a first step in which the server computer, in response to receiving the operation signal from the client computer, sends the operation signal to the analytical device, thereby operating the analytical device in accordance with the customer's wishes, and a second step in which the server computer, in response to receiving the analysis result data from the analytical device, sends the analysis result data to the client computer.

[0004] Patent Document 2 discloses an analysis system that includes one or more analysis devices that can be accessed by multiple users, and approval means that is connected to each of the analysis devices via a line and is capable of approving the results obtained by the analysis devices, and the results obtained by the analysis devices are approved by either the analysis devices or the approval means. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2002-181828 [Patent Document 2] Japanese Patent Application Laid-Open No. 2012-168050 Summary of the Invention [Problem to be solved by the invention]

[0006] However, since there are many on-site analysts at the analysis center where the analytical equipment is installed and any on-site analyst can operate the analytical equipment, it is difficult to ensure the confidentiality of samples with conventional remote analysis systems. On the other hand, it is desirable to proceed with analysis efficiently with the support of on-site analysts in the event of an abnormality.

[0007] For example, the technology described in Patent Document 1 is a technology for remotely sharing an analytical device, but Patent Document 1 does not mention a method for ensuring the confidentiality of samples.

[0008] Furthermore, the technology described in Patent Document 2 describes a method for managing access to equipment based on the authority of the analyst. With this management method, when an on-site analyst provides support in the event that automatic analysis cannot be continued, authentication is performed based on the on-site analyst's authority. Therefore, even if a sample requires high confidentiality, an on-site analyst with high authority can operate the equipment and obtain sample information, making it impossible to ensure the confidentiality of the sample.

[0009] An object of the present invention is to provide an analytical device, an analytical management system, and a program that can maintain the confidentiality of a sample when analyzing the sample in response to an analysis request from a remote location. [Means for solving the problem]

[0010] The analytical device of the present disclosure comprises an acquisition unit that acquires a specific value of a first confidentiality level that indicates the level of confidentiality of a sample to be analyzed; a setting unit that sets a specific value of a second confidentiality level that indicates the level of confidentiality of the device that analyzes the sample to be analyzed, the specific value of the second confidentiality level corresponding to the specific value of the first confidentiality level acquired by the acquisition unit; a function modification unit that modifies the functions of the device to restrict some functions related to display and operation if the specific value of the second confidentiality level set by the setting unit is equal to or greater than a threshold; and an analysis processing unit that performs automatic analysis of the sample to be analyzed under the functions of the device.

[0011] The analysis management system of the present disclosure includes a setting reception unit that receives the setting of the first confidentiality level value from a requester for a sample related to an analysis request, and a database that stores the set first confidentiality level value in association with identification information of the sample related to the analysis request, an analysis management device that manages the set first confidentiality level value, and an analysis device of the present disclosure, and an acquisition unit of the analysis device acquires a specific value of the first confidentiality level of the sample to be analyzed from the database of the analysis management device.

[0012] The program disclosed herein is a program for causing a computer to function as an acquisition unit that acquires a specific value of a first confidentiality level that indicates the level of confidentiality of a sample to be analyzed, a setting unit that sets a specific value of a second confidentiality level that indicates the level of confidentiality of the device that analyzes the sample to the computer, the specific value of the second confidentiality level corresponding to the specific value of the first confidentiality level acquired by the acquisition unit, and a function modification unit that modifies the functions of the device to restrict some functions related to display and operation if the specific value of the second confidentiality level set by the setting unit is equal to or greater than a threshold value. [Effects of the Invention]

[0013] According to the present invention, when a sample is analyzed in response to an analysis request from a client in a remote location, the confidentiality of the sample can be maintained. [Brief explanation of the drawings]

[0014] [Figure 1] 1 is a schematic diagram illustrating an example of the configuration of an analysis management system according to an embodiment of the present invention. [Figure 2] 1 is a block diagram showing an example of a hardware configuration of each unit of an analysis management system according to an embodiment of the present invention. [Figure 3] 10 is a diagram illustrating an example of a table of analysis request information stored in a DB. [Figure 4] FIG. 2 is a functional block diagram illustrating an example of a functional configuration of an analysis device according to an embodiment of the present invention. [Figure 5] 10 is a flowchart illustrating an example of an analysis procedure. [Figure 6] 10 is a flowchart showing an example of the flow of a "sample registration process." [Figure 7] 10 is a flowchart showing an example of the flow of an "analysis process." [Figure 8] 10 is a flowchart showing an example of the flow of a "process for changing the function of an analyzer." [Figure 9] 10 is a diagram showing an example of a table showing display contents of an analytical device and whether or not the display is possible depending on the device security level. [Figure 10] 10 is a diagram showing an example of a table showing operation items of an analytical device and whether the operation is possible depending on the device security level. [Figure 11] FIG. 2 is a schematic diagram illustrating an example of an operation screen of the analyzer. [Figure 12] FIG. 10 is a schematic diagram showing another example of the operation screen of the analyzer. [Figure 13] 10 is a flowchart showing an example of the flow of "post-analysis processing." [Figure 14] 10 is a flowchart illustrating an example of an abnormality handling procedure. DETAILED DESCRIPTION OF THE INVENTION

[0015] An embodiment of the present invention will now be described in detail with reference to the accompanying drawings.

[0016] <Analysis Management System> First, the overall configuration of the analysis management system will be described. The analysis management system of the present disclosure is a system that analyzes samples using an analysis device under the management of a server, which is an analysis management device, in response to an analysis request from a client located in a remote location.

[0017] FIG. 1 is a schematic diagram showing an example of the configuration of an analysis management system according to an embodiment of the present invention. 1, the analysis management system includes a server 10 that performs overall management of the entire system, an analytical device 20 that analyzes samples, a client terminal 40 used by a client R, an analyst terminal 50 used by a remote analyst RA, and a transport device 60 that transports a container V containing a sample. Note that the client R may also be the remote analyst RA.

[0018] The server 10 may be located in an analysis center or on a cloud. The analytical device 20 and the transport device 60 are located in the analysis center. The server 10, the analytical device 20, the client terminal 40, the analyst terminal 50, and the transport device 60 are each communicatively connected to one another via a wired or wireless network N such as a LAN (Local Area Network) or the Internet, and information exchange, instructions, inquiries, etc. required in the analysis management system are performed via the network N. For example, the transport device 60 transports samples under the control of the server 10 via the network N.

[0019] In this embodiment, a sample confidentiality level is set for each sample, indicating the level of confidentiality of the sample. The sample confidentiality level is expressed in multiple levels. In this embodiment, it is expressed as three values: low level, high level, and ultra-high level. The server 10 accepts the sample confidentiality level setting from the requester R, and stores and manages the analysis request information including the set sample confidentiality level in a database (hereinafter abbreviated as "DB") 18.

[0020] The analytical device 20 is shared by a remote analyst RA and an on-site analyst LA, and supports remote operation, remote observation, and automatic analysis by the remote analyst RA, as well as direct operation, direct observation, and manual analysis by the on-site analyst LA. Here, manual analysis refers to an analytical method in which analytical actions such as adjusting the parameters of the analytical device 20 are performed manually while viewing analytical data, and automatic analysis refers to an analytical technique in which these are automated.

[0021] The remote analyst RA remotely operates the transport device 60 via the server 10, grips the container V containing the sample with the sample gripper 67, and transports it to the analyzer 20. Then, the remote analyst RA remotely operates the sample loading / unloading unit 32 of the analyzer 20 to remove the sample from the container V and set the sample in the analyzer 20 to perform automatic analysis. The analyst terminal 50 of the remote analyst RA operably displays the operation screen of the analyzer 20, as well as various information such as images of the inside of the chamber, analysis conditions, and measurement results. The remote analyst RA may also perform analysis (i.e., manual analysis) himself / herself via the analyst terminal 50. Meanwhile, the on-site analyst LA performs sample loading / unloading and analysis via the operation input unit 26 and display unit 28 provided in the analyzer 20.

[0022] The server 10 assigns a responsible analyst to perform the analysis of a sample. The responsible analyst may be an on-site analyst LA or a remote analyst RA. In this embodiment, the server 10 assigns a remote analyst RA to a sample with a high confidentiality level, and assigns either an on-site analyst LA or a remote analyst RA to a sample with a low confidentiality level.

[0023] In this embodiment, an apparatus security level corresponding to the sample security level is also set for the analytical apparatus 20. The analytical apparatus 20 changes its functions, such as changing the information it displays and the operable contents, depending on the set apparatus security level. Specifically, when the sample security level is high, a high apparatus security level is set, and the functions of the analytical apparatus 20 are changed so as to restrict some of the functions related to display and operation.

[0024] For example, if the confidentiality level of the sample is high, in order to maintain the confidentiality of the sample, physical access (e.g., taking out, touching, or observing the sample) by anyone other than the analyst in charge (i.e., the on-site analyst LA) is prohibited, as well as informational access (e.g., unnecessary reading (information leakage) or writing (falsification) of sample information, reading or writing of information related to the analysis such as observation results and observation conditions, etc.).

[0025] The sample is sealed in a container V. In the case of a sample with a high level of confidentiality, the container V used for transportation may also be sealed so that it cannot be easily opened. The container V may be openable and closable by the sample attachment / detachment unit 32. The container V may also be lockable, in which case only an operator or device with a key can unlock the container V. The sample and container V are assigned identification information (hereinafter referred to as "ID"), allowing for individual identification. This information is managed by DB 18 as analysis request information, as will be described later.

[0026] (Hardware configuration) Here, the hardware configuration of each device will be described. 2 is a block diagram showing an example of the hardware configuration of each part of the analysis management system according to an embodiment of the present invention. As shown in FIG. 2, a server 10, an analysis device 20, a client terminal 40, and a transport device 60 are communicably connected via a network N.

[0027] -server- The server 10 is an information processing device such as a server computer, and includes a CPU (Central Processing Unit) 12, a memory 14, a storage unit 15, a communication unit 16, and various databases (hereinafter abbreviated as "DB") 18. The CPU 12, the memory 14, the storage unit 15, the communication unit 16, and the various DBs 18 are connected to each other via a bus 11 so as to be able to communicate with each other.

[0028] The CPU 12 is a central processing unit. The memory 14 is made up of RAM (Random Access Memory) and serves as a working area to temporarily store programs and data. The storage unit 15 is made up of ROM (Read Only Memory), HDD (Hard Disk Drive), SSD (Solid State Drive), etc., and stores various programs including the operating system and various data.

[0029] The CPU 12 reads out a program from the storage unit 15 and executes the program using the memory 14 as a work area. The CPU 12 also controls the above-mentioned components and performs various types of arithmetic processing in accordance with the program stored in the storage unit 15.

[0030] The communication unit 16 is an interface for communicating with other devices. The various DBs 18 are databases for managing analysis request information, and manage the analysis request information by dividing it into analysis request information before analysis and analysis request information after analysis (i.e., history information).

[0031] For example, as shown in FIG. 3, analysis request information can be managed in the form of a table 80. Each analysis request is assigned a request ID to identify the analysis request, and each sample is assigned a sample ID to identify the sample. Table 80 stores a container ID to identify the container, an analysis ID to identify the analysis, the requester, the analyst, the analysis date and time, and the sample confidentiality level, each associated with the request ID and the sample ID. Note that these management items are merely examples and are not limited to these. As will be described later, analysis results and restriction functions related to the display and operation of the analysis device 20 may also be stored as analysis request information.

[0032] -Analyzer- The analytical device 20 is an analytical device with an information processing function, and includes a CPU 22, a memory 24, a storage unit 25, an operation input unit 26, a display unit 28, a communication unit 30, a sample loading / unloading unit 32, and an analytical processing unit 34. The CPU 22, the memory 24, the storage unit 25, the operation input unit 26, the display unit 28, the communication unit 30, the sample loading / unloading unit 32, and the analytical processing unit 34 are all connected to each other via a bus 21 so as to be able to communicate with each other.

[0033] The CPU 22, memory 24, storage unit 25, and communication unit 30 are similar to the CPU 12, memory 14, storage unit 15, and communication unit 16 of the server 10. The CPU 22 controls the above-mentioned units and performs various arithmetic processing in accordance with a program stored in the storage unit 25.

[0034] The operation input unit 26 is a device for inputting various types of information, such as a keyboard or switches provided on an operation panel of the analyzer. The display unit 28 is a device for displaying various types of information, such as a display provided on an operation panel of the analyzer. Furthermore, the display unit 28 may also function as the operation input unit 26 by employing a touch panel display that accepts operation input from an operation screen.

[0035] The sample loading / unloading unit 32 is a device for loading / unloading samples into / from the analysis device 20. The sample loading / unloading unit 32 sets the sample in the analysis device 20 in a state ready for analysis, and after the analysis is completed, removes the sample from the analysis device 20 to make it ready for analysis. The analysis processing unit 34 is a device that performs the analysis operation of the set sample.

[0036] -Remote Terminal- The remote terminals provided are a client terminal 40 and an analyst terminal 50. Since both have the same configuration, the configuration of the client terminal 40 will be described here. Also, if the client R corresponds to the remote analyst RA, both are the same device.

[0037] The requester terminal 40 is an information processing device such as a personal computer, and includes a CPU 42, a memory 44, a storage unit 45, an operation input unit 46, a display unit 48, and a communication unit 49. The CPU 42, the memory 44, the storage unit 45, the operation input unit 46, the display unit 48, and the communication unit 49 are all connected to each other via a bus 41 so as to be able to communicate with each other.

[0038] The CPU 42, memory 44, storage unit 45, and communication unit 49 are similar to the CPU 12, memory 14, storage unit 15, and communication unit 16 of the server 10. The CPU 42 controls the above-mentioned units and performs various arithmetic processing.

[0039] The operation input unit 46 is a device for inputting various types of information, such as a keyboard, a mouse, etc. The display unit 48 is a device for outputting various types of information, such as a display, a printer, etc.

[0040] -Transportation equipment- The transport device 60 is a transport robot, and includes a CPU 62, a memory 64, a storage unit 65, a transport processing unit 66, a sample gripping unit 67, a camera 68, and a communication unit 69. The CPU 62, the memory 64, the storage unit 65, the transport processing unit 66, the sample gripping unit 67, the camera 68, and the communication unit 69 are all connected to each other via a bus 61 so as to be able to communicate with each other.

[0041] The CPU 62, memory 64, storage unit 65, and communication unit 69 are similar to the CPU 12, memory 14, storage unit 15, and communication unit 16 of the server 10. The CPU 62 controls the above-mentioned units in response to instructions from the server 10, and also performs various arithmetic processing.

[0042] The transport processing unit 66 is a device that performs processing to transport a container V containing a sample by autonomous driving. The sample gripping unit 67 is a device for gripping a sample to an analytical device. The camera 68 takes images of the surroundings of the transport device 60. The camera 68 may also function as a reader for reading a container ID attached to the container V.

[0043] The transport processing unit 66 recognizes the container V containing the sample based on the image obtained from the camera 68, and uses the sample gripping unit 67 to grasp the container V containing the sample and transport it to the analysis device 20. After the analysis is completed, the sample gripping unit 67 grasps the container V containing the sample and transports it to a predetermined position.

[0044] (Analyzer) Here, the functional configuration of the analysis device 20 will be described. Fig. 4 is a functional block diagram showing an example of the functional configuration of the analytical device 20 according to an embodiment of the present invention. As shown in Fig. 4, the analytical device 20 includes a sample security level acquisition unit 70 that acquires the security level of a sample (hereinafter referred to as the "sample security level") from the DB 18 of the server 10, an apparatus security level setting unit 72 that sets the security level of the analytical device 20 (hereinafter referred to as the "apparatus security level") in accordance with the sample security level of the sample to be analyzed, and a function modification unit 74 that modifies the functions of the analytical device 20 in accordance with the set apparatus security level. The CPU 22 of the analytical device 20 executes an "analysis processing" program, which will be described later, to realize the functional units of the sample security level acquisition unit 70, the apparatus security level setting unit 72, and the function modification unit 74.

[0045] <Analysis Procedure> Next, the analysis procedure will be explained, in which the remote analyst RA performs automatic analysis.

[0046] FIG. 5 is a flowchart showing an example of an analysis procedure. When an analysis request is received from the client terminal 40, the server 10 first issues a request ID and a sample ID to manage the request and the sample, and stores them in the DB 18 (ST1). As will be described later, the sample confidentiality level is also set here. When an analysis request is made, the analysis request is assigned to a responsible analyst. In this example, it is assumed that the sample confidentiality level is high and the analysis request is assigned to a remote analyst RA.

[0047] The remote analyst RA in charge of the analysis accesses the server 10 from the analyst terminal 50. When the server 10 is accessed from the analyst terminal 50 of the remote analyst RA, it issues an analysis ID and stores it in the DB 18 (ST2). The remote analyst RA in charge of the analysis accesses the analysis device 20 using the analysis ID, acquires the analysis environment data of the analysis device 20, and sends it to the server 10. The server 10 stores the analysis environment data of the analysis device 20 received from the analyst terminal 50 in the DB 18 (ST3).

[0048] The requester seals the sample to be analyzed in a container with a sample ID and a container ID attached, and sends it to the analysis center. When the sample arrives at the analysis center, for example, the transport device 60 reads the sample ID and container ID with a reader and transmits them to the server 10. In order to enable tracking of the container V containing the sample, the server 10 stores the time and location information when the sample ID and container ID were received from the transport device 60 in the DB 18 (ST4, ST5). The container V containing the sample is stored in a predetermined storage location until analysis.

[0049] When the analysis time arrives, the transport device 60 transports the sample to be analyzed to the analyzer 20 (ST6). The sample attachment / detachment unit 32 of the analyzer 20 opens the container V, removes the sample, and attaches the sample to the analyzer 20 in a state ready for analysis (ST7). The analyzer 20 starts the analysis, and the remote analyst RA observes the progress of the analysis (ST8). When the analysis is completed, the sample attachment / detachment unit 32 of the analyzer 20 removes the sample from the analyzer 20 (ST9). The transport device 60 then transports the removed sample to a predetermined location (ST10).

[0050] In this embodiment, the procedures from ST6 to ST10 are automatically performed by the analysis device 20. Of these procedures, the procedures from ST7 to ST10 will be described in detail below as "analysis processing" and "post-analysis processing."

[0051] <Program> Next, various programs executed by the server 10 and the analytical device 20 will be described. Here, the programs for executing the "sample registration process," "analysis process," and "post-analysis process" will be described. The "abnormality handling" procedure may also be executed by the CPU of the server 10 or the analytical device 20.

[0052] <Sample registration processing> 6 is a flowchart showing an example of the flow of the "sample registration process." The program for the "sample registration process" is executed by the CPU 12 of the server 10. For example, a requester uses a browser installed on the requester terminal 40 to access a website for an analysis service provided by the server 10, and presses a button on an initial screen (not shown) or the like to start an analysis request. This requests the server 10 to accept the analysis request, and the "sample registration process" begins.

[0053] First, in step S100, CPU 12 displays a registration acceptance screen on requester terminal 40. Subsequently, in step S102, CPU 12 accepts input of request information. The requester inputs requester information such as name, contact information (address to which analysis results should be sent), analysis information such as the type of analysis required and the scheduled date and time of analysis, and sample information such as the shape and weight of the sample as the request information.

[0054] Next, in step S104, the CPU 12 estimates the confidentiality level of the sample by referring to the requester's past request history stored in the DB 18. When the requester sets the confidentiality level of the sample themselves, they tend to select the same confidentiality level each time depending on their level of trust in the analytical service. For example, if the requester's past request history shows that "ultra-high level" is often selected, the confidentiality level of the sample is estimated to be "ultra-high level," and if the requester's past request history shows that "low level" is often selected, the confidentiality level of the sample is estimated to be "low level."

[0055] Next, in step S106, the CPU 12 displays a setting screen for setting the confidentiality level of the sample on the client terminal 40 and accepts the setting of the confidentiality level of the sample. The setting screen displays options (low level, high level, and ultra-high level) for selecting one of multiple values ​​of the confidentiality level of the sample. For example, the option representing the confidentiality level of the sample estimated in step S104 may be highlighted as a recommended confidentiality level. The client may select the recommended confidentiality level or another confidentiality level.

[0056] By presenting a recommended confidentiality level based on the request trends obtained from the requester's historical information, the requester can confirm whether the sample confidentiality level they select is the same as or different from the intended sample confidentiality level, and can set the sample confidentiality level correctly.

[0057] Next, in step S108, CPU 12 issues a request ID and a sample ID. Next, in step S110, CPU 12 associates the input request information (e.g., requester information, analysis information, sample information), sample ID, and set sample confidentiality level with the request ID as analysis request information and registers them in DB 18. Next, in step S112, CPU 12 displays a registration completion screen on requester terminal 40 and ends the routine.

[0058] <Analysis processing> FIG. 7 is a flowchart showing an example of the flow of the "analysis process." The "analysis processing" program is executed by the CPU 22 of the analysis device 20. At a predetermined time for a specific analysis request (for example, several minutes to several tens of minutes before the scheduled analysis date and time), the server 10 specifies the sample ID and container ID and instructs the transport device 60 to transport the sample to be analyzed (hereinafter referred to as the "target sample").

[0059] The transport device 60 identifies a container V containing a sample with a matching sample ID and container ID from a predetermined storage location, grasps it with the sample grasper 67, and transports it to the analysis device 20. The CPU 22 of the analysis device 20 starts the "analysis process" when it detects the arrival of the sample to be analyzed based on the sample ID and container ID.

[0060] First, in step S200, when the target sample arrives, the CPU 22 instructs the sample loading / unloading unit 32 to set the target sample. In response to the instruction, the sample loading / unloading unit 32 sets the target sample in a state where it can be analyzed. Next, in step S202, the CPU 22 obtains the confidentiality level of the target sample from the DB 18.

[0061] Next, in step S204, the CPU 22 executes "analyzer function change processing." Simply put, in the "analyzer function change processing," an apparatus security level is set according to the sample security level set by the requester, and the functions of the analyzer 20 are changed according to the set apparatus security level. For example, some display items are hidden, sample removal operations are prohibited, and operational inputs are prohibited.

[0062] Finally, in step S206, the CPU 22 instructs the analytical processing unit 34 to execute an analytical operation (e.g., various measurement processes), and ends the routine. If the sample security level and the device security level are high, the analytical operation is executed in a confidential mode. For example, due to a function change, some displays are erased from the display unit 28, and various operations via the operation input unit 26 are disabled, and the analytical operation is executed by the analytical processing unit 34.

[0063] (Analyzer function change processing) Here, the "analyzer function change process" will be described in detail with reference to FIG. First, in step S300, the CPU 22 sets the device security level based on the sample security level of the acquired target sample. For example, if the sample security level is expressed as a three-level value, low level, high level, and extra-high level, the device security level is also expressed as a three-level value, low level, high level, and extra-high level, according to the sample security level. Next, in step S302, the CPU 22 acquires a default function change according to the device security level.

[0064] Next, in step S304, the CPU 22 displays the default function changes to the remote analyst RA and accepts modifications. That is, the default function changes according to the equipment security level can be customized. In addition, customization of the default function changes may be suggested based on historical information involving the client R, the remote analyst RA, or the on-site analyst LA, or the default function changes may be customized automatically. Since it is expected that support from the on-site analyst will be received in the event of an abnormality, some functions can be left unchanged through customization.

[0065] Note that the modification of the default function may be accepted via the server 10, for example, at the time of sample registration.

[0066] Next, in step S306, the CPU 22 changes the functionality of the analyzer 20 to reflect the modifications to the default functionality changes, and then ends the routine.

[0067] The functional changes to the analytical device 20 can be broadly divided into those that restrict the information displayed on the display unit 28 of the analytical device 20, and those that restrict operations via the operation input unit 26 of the analytical device 20. These restrictions prohibit physical and informational access by anyone other than the remote analyst RA to samples with a high level of confidentiality, thereby maintaining the confidentiality of the samples.

[0068] Examples of functional changes that limit the information displayed include, for example, when the equipment confidentiality level is high, not displaying some or all of the items displayed on display unit 28 (e.g., the status of the analytical equipment, information about the sample, information related to the analysis, and analysis results) (e.g., filling them with black or gray, or applying a mosaic), or displaying other information (e.g., dummy video, dummy data, snow noise, etc.) on display unit 28. Displaying irrelevant information such as dummy video has the advantage of maintaining the confidentiality of the sample without the on-site analyst noticing.

[0069] Examples of functional changes that restrict operations include, when the device security level is high, prohibiting operations that change the state of the analytical device 20, prohibiting operations related to attaching and detaching samples, prohibiting operations related to observing samples, prohibiting operations related to the displayed content, turning off the power to the display device, closing the sample observation window, and blocking all operational input.

[0070] The higher the device security level, the less information is displayed and the fewer operable items are. For example, some or all of the function change items shown as examples may be set as "default function changes," and excluded items may be specified as appropriate through the customization described above. Note that changing the functions of the analytical device 20 does not involve rewriting the operation manual for the analytical device 20, so the procedures specified in the manual must be followed for operable items as well.

[0071] (Examples of function changes) An example of function changes according to the equipment security level will be explained using scanning electron microscope (SEM) analysis as an example. Figure 9 is a diagram showing an example of a table showing the display content of an analytical equipment and whether or not the display is possible according to the equipment security level. Equipment security levels are expressed in three levels: low level, high level, and ultra-high level. In the figure, low level is abbreviated as "low," high level as "high," and ultra-high level as "high+." For the operation screen of the analytical equipment, please refer to operation screen 82 shown in Figure 11 and operation screen 84 shown in Figure 12.

[0072] Examples of items showing the status of the analytical instrument include an indicator showing the operating status, an indicator showing the on / off status of the electron beam (see Figure 12), an indicator showing whether a sample is inside the analytical instrument, and numerical values ​​related to the operating status of the instrument (e.g., the degree of vacuum in each part, see Figure 11). In this example, only when the instrument security level is ultra-high is the display of numerical values ​​related to the operating status of the instrument related to the sample prohibited. These numerical values ​​are set depending on the sample and may reflect the characteristics of the sample, so it is preferable to hide them.

[0073] Examples of items representing information about a sample include a sample identifier and an image of the sample room (see Figure 11). In this example, when the equipment security level is high, only the display of the image of the sample room is prohibited, and when the equipment security level is ultra-high, the display of both the sample identifier and the image of the sample room is prohibited. Since the image of the sample room reveals the appearance of the sample, it is preferable to hide the image of the sample room. Furthermore, by hiding the sample identifier, the sample can be made anonymous.

[0074] Examples of items representing analysis-related information (i.e., analysis conditions, parameter groups set to obtain analysis results; see Figure 12) include sample-independent items such as stage position and sample-dependent items such as acceleration voltage. In this example, when the equipment security level is high, only the display of sample-dependent acceleration voltage is prohibited, and when the equipment security level is ultra-high, the display of both sample-dependent acceleration voltage and sample-independent stage position is prohibited. It is more preferable to hide sample-dependent information than sample-independent information.

[0075] Examples of items showing the analysis results include the progress of the analysis (for example, the number of images taken and the estimated time of completion) and measurement results (for example, SEM images (see Figure 12), energy dispersive X-ray spectroscopy (EDS) images, and other information obtained by the analysis). In this example, when the equipment security level is high, only the display of the measurement results is prohibited, and when the equipment security level is ultra-high, the display of both the measurement results and the progress of the analysis is prohibited. The analysis results of the sample are highly confidential information, and it is preferable that they not be displayed. It is not preferable to display the measurement results even when the equipment security level is low.

[0076] Figure 10 is a diagram showing an example of a table showing the operational items of an analytical device and whether or not the operations are possible depending on the device security level. The device security level is expressed in three levels: low level, high level, and ultra-high level.

[0077] Examples of operations that change the state of the analytical device 20 include changing the operating state, turning the electron beam on / off, and setting the degree of vacuum. Examples of operations related to attaching and detaching a sample include setting a sample and removing a sample. Examples of operations related to observing a sample include setting observation conditions (e.g., acceleration voltage, working distance) and moving the stage. Examples of operations related to the displayed content include changing the displayed items. In this example, all of these operations are prohibited when the device security level is high or ultra-high.

[0078] <Post-analysis processing> 13 is a flowchart showing an example of the flow of the "post-analysis processing." The CPU 22 of the analysis device 20 starts the "post-analysis processing" when the analysis operation by the analysis processing unit 34 is completed.

[0079] First, in step S220, the CPU 22 instructs the sample mounting / detaching unit 32 to remove the target sample. The sample mounting / detaching unit 32 removes the target sample and makes it unavailable for analysis. If the sample needs to be returned, the sample mounting / detaching unit 32 may re-seal the sample in the container V.

[0080] Next, in step S222, CPU 22 cancels the setting of the device security level. By canceling the setting of the device security level, analytical device 20 is initialized and the changed functions are restored. Finally, in step S224, CPU 22 transmits the analysis results to client terminal 40, analyst terminal 50, or server 10, and ends the routine.

[0081] When the analysis results are sent to the server 10, the server 10 stores the analysis results in the DB 18 and reports the analysis results to the client R. When the analysis results are sent to the analyst terminal 50, the remote analyst RA reports the analysis results to the client R.

[0082] The extracted sample is stored in a container V and transported by the transport device 60. In this case, when the analysis device 20 notifies the server 10 of the completion of the analysis, the server 10 specifies the sample ID and container ID and instructs the transport device 60 to transport the target sample. The analysis device 20 authenticates the transport device 60 using the sample ID and container ID and permits the transport of the target sample. The transport device 60 grips the target sample with the sample gripper 67 and transports it to a predetermined location.

[0083] <Abnormality Treatment> If an abnormality occurs during automated sample analysis and the analysis cannot continue, assistance from an on-site analyst is required to ensure the efficiency of the automated analysis. Here, cases where the automated analysis cannot continue include cases where the results obtained by the analytical instrument are undesirable or where some kind of action is required to address an abnormality detected by the instrument. For example, in the case of SEM analysis, this would include cases where an unclear image is obtained due to inappropriate observation conditions or where electron beam parameters exceed acceptable thresholds.

[0084] If the sample has a low confidentiality level, the on-site analyst can handle the sample. If the sample has a high confidentiality level, the equipment confidentiality level is temporarily lowered below the sample confidentiality level to allow the on-site analyst to work. Whether to lower the equipment confidentiality level and to what level the equipment confidentiality level should be lowered may be determined by the client or a remote analyst, or may be determined automatically by the server 10 or the analytical device 20, taking into account the nature of the abnormality, the confidentiality of the sample, efficiency, etc.

[0085] The procedure for dealing with abnormalities is briefly described below. FIG. 14 is a flowchart showing an example of an abnormality handling procedure. 14, when an abnormality is detected (step S400), it is determined whether the sample security level is low or not (step S402). If the sample security level is low, the process proceeds to step S412. If the sample security level is high or ultra-high, the remote analyst RA is notified of the abnormality (step S404).

[0086] Next, it is determined whether or not the on-site analyst LA can take action (step S406). If it is difficult for the on-site analyst LA to take action, the remote analyst RA, who is the analyst in charge, will take action remotely to take care of the abnormality (step S408). Once the action is complete, the remote analyst RA will notify the user that the action has been taken (step S410), and the automatic analysis will resume (step S422).

[0087] On the other hand, if the on-site analyst LA can take action, the above-mentioned equipment security level is reset to low (step S418). If the sample security level is determined to be low in step S402 or if the equipment security level is reset to low in step S418, the on-site analyst LA is then requested to take action to deal with the abnormality (step S412), and the on-site analyst LA takes action to deal with the abnormality (step S414).

[0088] When the abnormality handling is completed, the on-site analyst LA notifies the user of the completion of the abnormality handling (step S416). After the abnormality handling is completed, the equipment security level is reset again to the high level or ultra-high level (step S420), and the automatic analysis is resumed (step S422).

[0089] The above-described abnormality handling procedure may be executed by the CPU of the server 10 or the analytical device 20. In this case, the decision as to whether or not the on-site analyst LA can handle the abnormality, i.e., the decision as to whether or not to lower the device confidentiality level, may be made by the client or the remote analyst, or may be made automatically by the server 10 or the analytical device 20.

[0090] For example, when the sample confidentiality level is high or ultra-high, the server 10 or analytical device 20 estimates the trustworthiness of the on-site analyst from the history information, and if the trustworthiness of the on-site analyst is higher than a predetermined threshold, the device confidentiality level is lowered to a low level, but if the trustworthiness of the on-site analyst is equal to or lower than the threshold, maintaining the confidentiality of the sample is prioritized and the device confidentiality level is maintained at a high or ultra-high level. For example, if the on-site analyst is an affiliate of a competitor, the trustworthiness of the on-site analyst is low and the device confidentiality level is maintained at a high or ultra-high level.

[0091] As described above, in this embodiment, a confidentiality level is set for each sample, and if the sample confidentiality level is high, physical and informational access to the analyzer 20 is restricted during sample analysis, thereby maintaining the confidentiality of the sample. For example, even an on-site analyst LA with high authority is restricted from operating the analyzer 20 and accessing sample information. On the other hand, since only "some" functions related to display and operation are restricted while the remaining functions are maintained, the operating status of the analyzer 20 can be grasped from the outside.

[0092] Furthermore, in this embodiment, a recommended confidentiality level for the sample is proposed based on historical information, so that when selecting the sample confidentiality level, the requester can confirm whether it is the same as or different from the intended sample confidentiality level, and can set the sample confidentiality level correctly.

[0093] Furthermore, in this embodiment, default function changes are prepared in advance according to the device security level, but the default function changes can be customized, so that the functions to be restricted can be set flexibly.

[0094] Furthermore, in this embodiment, if an abnormality occurs during automatic analysis, the security level of the equipment is lowered so that assistance can be received from an on-site analyst, thereby improving the efficiency of automatic analysis compared to when the involvement of an on-site analyst is completely eliminated. In other words, both analytical efficiency and confidentiality can be achieved.

[0095] <Modification> It goes without saying that the configurations of the analysis device, analysis management system, and program described in the above embodiments are merely examples, and may be modified within the scope of the present invention.

[0096] For example, in the above embodiment, when the sample security level is expressed in three stages, namely, low level, high level, and extra-high level, the device security level is also expressed in three stages, namely, low level, high level, and extra-high level, according to the sample security level, but this correspondence is merely an example. The device security level may be determined from the sample security level based on the predetermined correspondence between each sample security level and each device security level.

[0097] Furthermore, the number of security levels is merely an example, and the equipment security level may be divided into two levels: low and high. In this case, the correspondence between the three levels of specimen security levels and the two levels of equipment security levels is determined in advance.

[0098] In the above embodiment, the "analysis process" and "post-analysis process" are performed on the analysis device 20 side, but the analysis device 20 may perform only the analysis operation, and the "analysis process" and "post-analysis process" may be performed on the server 10 side. In this case, the analysis device 20 changes its functions in accordance with instructions from the server 10. [Explanation of symbols]

[0099] 10 Servers 18 DB 20 Analyzer 26 Operation input section 28 Display section 32 Sample attachment / detachment section 34 Analysis processing section 40 Client terminal 50 Analyst terminal 60 Conveyor 70 Sample Confidentiality Level Acquisition Department 72 Equipment security level setting section 74 Functional change section 80 tables 82 Operation screen 84 Operation screen LA Field Analyst N Network R Client RA Remote Analyst

Claims

1. an acquisition unit that acquires a specific value of a first confidentiality level that indicates the confidentiality level of the sample to be analyzed; a setting unit that sets a second security level representing the level of security of the device for analyzing the sample to a specific value of the second security level corresponding to the specific value of the first security level acquired by the acquisition unit, the setting unit determining the specific value of the second security level corresponding to the specific value of the first security level acquired by the acquisition unit based on a predetermined correspondence relationship between a plurality of values ​​of the first security level and a plurality of values ​​of the second security level; a function modification unit that modifies functions of the device itself so as to restrict some functions related to display and operation when the specific value of the second confidentiality level set by the setting unit is equal to or greater than a threshold value; an analysis processing unit that performs analysis of the analysis target sample under the function of its own device; An analytical device comprising:

2. The analysis device according to claim 1 , wherein the function modification unit performs at least one of a function modification to hide part of the information displayed on the display unit and a function modification to prohibit part of the operation via the operation input unit.

3. The analytical device of claim 2, wherein the functional change to hide part of the information displayed on the display unit is to not display part or all of the display items including the status of the device itself, information about the sample to be analyzed, information related to the analysis, and analysis results.

4. The analytical device of claim 2, wherein the functional change to hide part of the information displayed on the display unit is to display part or all of information unrelated to the sample to be analyzed, including dummy images, dummy data, and snow noise.

5. The analytical device according to any one of claims 2 to 4, wherein the functional change that prohibits some of the operations via the operation input unit is one or more selected from the group consisting of prohibiting operations that change the state of the device itself, prohibiting operations related to the attachment and detachment of the sample to be analyzed, prohibiting operations related to the observation of the sample to be analyzed, prohibiting operations related to the displayed content, turning off the power to the display unit, closing the sample observation window, and blocking all operation input.

6. The analysis device according to claim 1 , wherein the function restricted by the function changing unit is a function that is predetermined for the value of the second security level.

7. The analytical device of claim 6 , wherein the predetermined functions are customizable.

8. 8. The analysis device according to claim 1, wherein the setting unit changes the specific value of the second confidentiality level to a lower value and resets the changed value if an abnormality occurs in the device during automatic analysis.

9. an analysis management device that includes a setting reception unit that receives a setting of the value of the first security level from a requester for a sample related to an analysis request, and a database that stores the set value of the first security level in association with identification information of the sample related to the analysis request, and that manages the set value of the first security level; An analysis device according to any one of claims 1 to 8; Equipped with the acquisition unit of the analysis device acquires the specific value of the first confidentiality level of the analysis target sample from the database of the analysis management device; Analysis management system.

10. The database of the analysis management device stores historical information about analysis requests, the analysis management device further includes an estimation unit that estimates the value of the first confidentiality level of the sample based on a request tendency obtained from the history information of the requester, the setting reception unit displays a plurality of values ​​of the first confidentiality level as options, and when receiving a setting of the value of the first confidentiality level from the client, highlights the value of the first confidentiality level estimated by the estimation unit. The analysis management system according to claim 9 .

11. Computer, an acquisition unit that acquires a specific value of a first confidentiality level that indicates the level of confidentiality of the sample to be analyzed; a setting unit that sets a second security level representing a level of security of the device for analyzing the sample to a specific value of the second security level corresponding to the specific value of the first security level acquired by the acquisition unit, the setting unit determining the specific value of the second security level corresponding to the specific value of the first security level acquired by the acquisition unit based on a predetermined correspondence relationship between a plurality of values ​​of the first security level and a plurality of values ​​of the second security level; a function modification unit that modifies functions of the device itself so as to restrict some functions related to display and operation when the specific value of the second confidentiality level set by the setting unit is equal to or greater than a threshold; A program to function as a

Citation Information

Patent Citations

  • Analyzer usage support method, storage medium, analyzer usage support system, and analyzer usage support server computer

    JP2002181828A

  • Accuracy management method and its system

    JP2004004105A

  • Processing apparatus

    JP2005196508A

  • Information processor

    JP2006350494A

  • Autoanalyzer and genetic information management method therefor

    JP2008046095A