Access control system

The authorization management system simplifies access control by separating user assignment and authorization information, reducing errors and enhancing security in pharmaceutical manufacturing facilities with multiple production lines.

JP7836929B1Active Publication Date: 2026-03-27CKD CORP
View PDF 7 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Manufacturing facilities with multiple production lines face complex access control due to numerous access control IDs, leading to cumbersome management and increased error risk, especially in pharmaceutical manufacturing where user assignments frequently change, affecting productivity and security.

Method used

An authorization management system that separates user assignment information from authorization information, allowing different users to change these independently, with permission determination mechanisms to ensure only authorized personnel can modify specific types of information, and includes device matching and notification features to prevent incorrect operations.

Benefits of technology

This system simplifies access control management, reduces errors, enhances security, and maintains efficient operations by ensuring only authorized personnel can make changes, thereby improving productivity in pharmaceutical manufacturing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007836929000001_ABST
    Figure 0007836929000001_ABST
Patent Text Reader

Abstract

This provides an access control system that can prevent the complexity of access control information from increasing. [Solution] The authorization management system 1 includes an account information storage unit 10a that stores authentication information and authorization information for each user, an assignment information storage unit 10d that stores information regarding the assignment of users to production lines and equipment, separate from the authentication information and authorization information, an account information change permission determination unit 11j that permits or denies changes to the information stored in the account information storage unit 10a based on the authorization information stored in the account information storage unit 10a, and an authorization determination unit 202j that permits or denies changes to the information stored in the assignment information storage unit 10d based on the authorization information stored in the account information storage unit 10a. The account information change permission determination unit 11j and the authorization determination unit 202j are set so that the authorization information that will be permitted to be changed is different.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authority management system for managing authority information related to information changes and device operations.

Background Art

[0002] Conventionally, in order to improve security and prevent information setting errors, operations of devices provided in manufacturing facilities and changes to information stored in various storage means are configured to be executable within the scope of authorities set for each user. And, in order to adopt such a configuration, it is necessary to appropriately manage information indicating the authorities of users (authority information).

[0003] As an authority management system for managing authority information, when a user ID is sent from a device to a server via communication means, an operation authority ID assigned to the user is sent from the server to the device, and the device can be operated (driven) within the scope of the authority corresponding to this operation authority ID (see, for example, Patent Document 1). In this authority management system, as the operation authority ID, a combination of information for specifying a device (device ID) and information indicating the authority of a user (authority ID) is used. By using such an operation authority ID, it is said that even if authorities are diversely differentiated for each device, it is possible to assign diversely differentiated authorities according to the device.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] However, factories involved in the manufacture and packaging of pharmaceuticals often have multiple production lines, each with one or more devices. Applying the aforementioned access control system to such factories could result in a very large number of access control IDs. For example, if there are 10 production lines, each consisting of 5 devices, and there are 4 types of access control for each device, there would be 200 (= 5 × 10 × 4) types of access control IDs. Consequently, the access control information would become complex, and its management and configuration could become cumbersome.

[0006] Furthermore, the users assigned to production lines and equipment are not necessarily the same from day to day; they may change daily. However, when using an operation authority ID that combines the equipment ID and authority ID as described above, when attempting to assign a user to a particular production line or piece of equipment, the equipment ID changes depending on the production line or equipment being assigned. Consequently, the operation authority ID to be granted to the user must also be changed in accordance with this change in equipment ID. Such changes lead to extremely cumbersome work and increase the likelihood of errors.

[0007] Furthermore, when attempting to change the operation authority ID according to the assigned production line, if the user responsible for operating the equipment (e.g., the operator) changes the equipment ID included in the operation authority ID, flexible and efficient operation can be achieved. However, in this case, there is a risk of accidentally changing the user's authority information (authority ID) included in the operation authority ID. On the other hand, in order to prevent such unnecessary changes to information and ensure security, it is conceivable to allow only users with system management privileges (e.g., system administrators) to change the operation ID included in the operation authority ID. However, in this case, flexible and efficient operation may not be possible, and productivity may decrease.

[0008] Furthermore, factories involved in the manufacturing and packaging of pharmaceuticals, in particular, need to be especially careful to avoid errors or unnecessary changes to the information mentioned above.

[0009] The present invention has been made in view of the above circumstances, and its purpose is to provide an access control system that can more reliably prevent the complexity of access control information, and furthermore, can ensure security and agile and efficient operation while improving work efficiency and suppressing the occurrence of errors when assigning users to production lines and equipment. [Means for solving the problem]

[0010] Below, we will describe, in separate sections, each means suitable for achieving the above objectives. Furthermore, we will add notes on the effects and benefits specific to each means as needed.

[0011] Means 1. An authorization management system applicable to a manufacturing facility that manufactures and / or packages pharmaceuticals, comprising multiple production lines, each having one or more devices, An account information storage means that stores predetermined authentication information and predetermined authorization information for each user, In addition to the authentication information and the authorization information, the assignment information storage means stores information regarding the assignment of users to the production line and the equipment, Information modification means capable of modifying information stored in at least one of the account information storage means and the assignment information storage means, including operating means for operating the device provided in the device, Authentication processing means that determines whether the user is legitimate based on the authentication information input by the user to the information modification means and the authentication information stored in the account information storage means, If the authentication processing means determines that the user is legitimate, the system includes an information modification permission determination means that, based on the user's authority information stored in the account information storage means, permits or denies modifying the information stored in the account information storage means or the assignment information storage means via the information modification means within the scope of the authority corresponding to the authority information, The means for determining whether the information can be changed is: An account information modification permission determination means that determines whether to permit or deny changes to the information stored in the account information storage means based on the authority information stored in the account information storage means, The system includes an assignment information modification permission determination means that determines whether to permit or deny changes to the information stored in the assignment information storage means based on the authority information stored in the account information storage means, An authorization management system characterized in that the account information change permission determination means and the assignment information change permission determination means are set so that the authorization information that will be permitted to be changed is different.

[0012] Please note that "changing information" includes registering, adding, modifying, and deleting information.

[0013] According to the above-described method 1, information regarding the assignment of users to production lines and equipment is stored separately from the authorization information. Therefore, it is possible to more reliably prevent the complexity of authorization information and to make the management and setting of authorization information easier.

[0014] Furthermore, when assigning users to production lines or equipment, there is no need to change the authorization information; it is sufficient to change only the assignment-related information stored in the assignment information storage means, thereby improving work efficiency and reducing the occurrence of errors.

[0015] Furthermore, according to the above means 1, there is an account information change permission determination means that permits or denies changes to the information (authority information and authentication information) stored in the account information storage means, and an assignment information change permission determination means that permits or denies changes to the information (information regarding the assignment of users to production lines and equipment) stored in the assignment information storage means. These means are configured such that the authorization information that will be permitted to be changed is different for each. Therefore, only users with authority to make system changes (e.g., system administrators) can change the authorization information, while only those responsible for operating the equipment (e.g., drivers) can change the assignment information. This makes it possible to achieve both security and flexible and efficient operation.

[0016] Means 2. The assignment information storage means is Information regarding the production line to which the user is assigned, Information regarding the equipment assigned to the user, which is independent of the aforementioned production line, The authorization management system according to means 1, characterized by storing them separately.

[0017] According to method 2 described above, even if a user is responsible for multiple production lines, that user will always be assigned the same equipment. Therefore, it is possible to more reliably prevent a user from being assigned to equipment they should not be responsible for, and from performing operations or tasks related to equipment they are not supposed to be responsible for. This allows for more proper manufacturing and packaging of medicines.

[0018] Means 3. When the authentication processing means determines that the user is legitimate based on the authentication information input by the user to the operating means, the operating means determines whether the corresponding device and the device to which the user is assigned based on the assignment information stored in the assignment information storage means match, When it is determined by the device matching determination means that they match, login permission means for permitting the user to log in to the operation means, When it is determined by the device matching determination means that they do not match, notification means for notifying the user that the operation means for which information has been input by the user does not match the device corresponding thereto and the device to which the user is assigned, which is stored in the allocation information storage means, and a permission management system according to means 1, characterized in that it comprises:

[0019] Note that by being "permitted to log in", the operation of the device by the operation means becomes possible within the authority of the user.

[0020] According to the above means 3, when the device corresponding to the operation means into which the user has input the authentication information (the device that the user is trying to operate) does not match the device to which the user is assigned, the notification means notifies the user that they do not match. Therefore, it is possible to more surely make the user aware that they are trying to operate the wrong device. As a result, it is possible to more surely prevent operations and work related to a device that should not be originally in charge from being carried out, and thus the production and packaging of drugs can be carried out more appropriately.

[0021] Means 4. The notification means is configured to be able to notify the user of information indicating the correct production line and the device to which the user is assigned, which is stored in the allocation information storage means, when it is determined by the device matching determination means that they do not match, and a permission management system according to means 3, characterized in that it comprises:

[0022] According to the above means 4, when the user is trying to operate the wrong device, it is possible to notify the user of the correct production line and device that should be originally in charge. Therefore, the production and packaging of drugs can be carried out more appropriately.

[0023] Means 5. The authorization management system according to Means 3, characterized in that, when the device matching determination means determines that there is no matching, the notification means is configured to notify the user of information that allows the user to identify the device to which the operating means, which has been input by the user, corresponds, and the production line including the device.

[0024] According to the above-described means 5, when a user is about to operate the wrong device, the user is notified of information that allows them to identify the device and the production line containing that device. Therefore, based on this information, the user can determine their location. This allows them to move to the production line or device they are originally responsible for earlier, thereby further increasing productivity.

[0025] Means 6. Necessary qualification storage means for storing information regarding qualifications necessary for assignment to the production line and information regarding qualifications necessary for assignment to the equipment, A user credentials storage means that stores information about the credentials a user possesses, Changes to the aforementioned information for The authorization management system according to means 1, further comprising: an assignment eligibility determination means that determines whether a user can be assigned to the production line or the device based on the information stored in the required qualifications storage means and the user qualifications storage means when changing the information stored in the assignment information storage means via means.

[0026] According to the above means 6, the assignment eligibility determination means makes it possible to assign only users with the necessary qualifications to specific production lines or equipment. Therefore, it is possible to more reliably prevent users without the necessary qualifications from operating the equipment, and to manufacture and package medicines more appropriately.

[0027] Means 7. The device is equipped with a cumulative duty time storage means for storing the cumulative duty time of the user, The allocation feasibility determination means changes the information forThe authorization management system according to means 6, characterized in that when changing the information stored in the assignment information storage means via means, it determines whether or not a user can be assigned to the device based on the information stored in the cumulative assignment time storage means.

[0028] According to the above means 7, the assignment feasibility determination means makes it possible, for example, to assign only users with sufficient experience to the production line individually, or to assign only users with sufficient experience to specific equipment. This further enhances the appropriateness of drug manufacturing and packaging.

[0029] Means 8. The system includes a validity period storage means that stores information regarding the validity period for each user of the qualifications necessary for assigning a user to the production line or the equipment, The allocation feasibility determination means changes the information for The authorization management system according to means 6, characterized in that when changing the information stored in the assignment information storage means via means, it determines whether or not a user can be assigned to the production line or the device based on the information stored in the validity period storage means.

[0030] According to the above method 8, only users whose qualifications have not expired can be assigned to production lines and equipment. Therefore, the appropriateness of the manufacturing and packaging of pharmaceuticals can be further enhanced.

[0031] Furthermore, the technical aspects related to each of the above means may be combined as appropriate. For example, at least one of the technical aspects related to means 3 to 8 may be combined with the technical aspects related to means 2. [Brief explanation of the drawing]

[0032] [Figure 1] This is a block diagram showing the general configuration of the access control system and manufacturing equipment. [Figure 2] This is a diagram showing the general configuration of PTP devices, etc. [Figure 3]This is a block diagram showing the functional configuration of a touch panel. [Figure 4] A branch of the functional configuration for servers, etc. [Figure 5] This is a table diagram showing an example of information such as user IDs stored in the account information storage unit. [Figure 6] This is a table diagram showing an example of information such as permission categories stored in the account information storage unit. [Figure 7] This is a table diagram showing an example of line configuration information stored in the line configuration information storage unit. [Figure 8] This is a table diagram showing an example of line attribute information stored in the line configuration information storage unit. [Figure 9] This is a table diagram showing an example of information related to the qualifications required for production line personnel, which is stored in the required qualifications memory unit. [Figure 10] This is a table diagram showing an example of information related to the qualifications required to operate the device, which is stored in the required qualifications memory unit. [Figure 11] This is a table diagram showing an example of information such as the user's qualifications stored in the user qualifications and validity period memory unit. [Figure 12] This is a table diagram showing an example of information related to the validity period of user credentials stored in the user credentials and validity period memory unit. [Figure 13] This is a table diagram showing an example of information related to the cumulative operating time of an operator for a device, which is stored in the cumulative operating time memory unit. [Figure 14] This is a table diagram showing an example of information related to the cumulative time spent by an operator assisting with the device, which is stored in the cumulative time storage unit. [Figure 15] This is a table diagram showing an example of information related to the assignment of drivers and other personnel to production lines, which is stored in the assignment information storage unit. [Figure 16] This is a table diagram showing an example of information related to the assignment of operators, etc., to a device, which is stored in the assignment information storage unit. [Figure 17] This is a table diagram illustrating an example of the relationship between permission categories and the devices used. [Figure 18] This flowchart shows the login process flow on PC11. [Figure 19] This figure shows an example of information regarding driver assignments, etc., displayed by the assignment viewing unit. [Figure 20] This is a flowchart showing the login process flow on PC12. [Figure 21] This is a flowchart showing the login process flow on PC13. [Figure 22] This flowchart shows the login process flow on PC14. [Figure 23] This is a flowchart showing the login process on a touch panel. [Figure 24] This figure shows an example of the information displayed when the device is not compatible. [Figure 25] In another embodiment, this is a flowchart showing the login process on a shared PC. [Figure 26] In another embodiment, this block diagram shows a schematic configuration of an access control system having an administrative server. [Figure 27] A table diagram illustrating an example of authority categories in another embodiment. [Figure 28] In another embodiment, this block diagram shows a schematic configuration of an access control system having separate networks for administrative systems and manufacturing equipment systems. [Figure 29] This block diagram shows a schematic configuration of an access control system in another embodiment, where the account information storage unit is located outside the directory service area. [Modes for carrying out the invention]

[0033] An embodiment will be described below with reference to the drawings. As shown in Figure 1, the authorization management system 1 is applied to a manufacturing facility 100 that manufactures and packages pharmaceuticals, and is for managing authorization information related to the operation and information changes of the manufacturing facility 100. Before describing the authorization management system 1, the manufacturing facility 100 will be described first.

[0034] The manufacturing facility 100 includes production line L1, which is set to line No. "1", and similarly, production lines L2, L3, L4, L5, L6, L7, L8, L9, and L10, which are set to line No. "2" through "10", respectively. In other words, the manufacturing facility 100 has multiple (10 in this embodiment) production lines L1 through L10. The line No. functions as information for identifying production lines L1 through L10.

[0035] Each production line L1 to L10 has multiple pieces of equipment for manufacturing PTP sheets as "medicine" and for packaging said PTP sheets. A PTP sheet comprises a container film having a pocket portion in which the contents (e.g., tablets or capsules) are contained, and a cover film attached to the container film so as to close the opening of the pocket portion.

[0036] In this embodiment, each production line L1 to L10 has all or some of the following "devices": a PTP machine 101, a stacking machine 102, a banding machine 103, a pillow machine 104, and a boxing machine 105. The PTP machine 101 manufactures PTP sheets, the stacking machine 102 stacks the manufactured PTP sheets in predetermined numbers, the banding machine 103 bundles the stacked PTP sheets with predetermined bands, and the pillow machine 104 performs pillow packaging to bag the PTP sheets. The boxing machine 105 boxes the PTP sheets. In each production line L1 to L10, the line configuration (i.e., the equipment that makes up the production line) is appropriately set according to the final product to be obtained. For example, production line L6, which ultimately produces products that do not require bundling or bagging of PTP sheets, is equipped with a PTP machine 101, a stacking machine 102, and a boxing machine 105, but does not have a banding machine 103 or a pillow machine 104.

[0037] Furthermore, as shown in Figure 2, the PTP machine 101, stacking machine 102, banding machine 103, pillow machine 104, and boxing machine 105 are each equipped with a control device 201 and a touch panel 202. In Figure 2, production line L1 is shown as a representative of the multiple production lines L1 to L10, but the PTP machines 101 and other components that make up the other production lines L2 to L10 are also each equipped with a control device 201 and a touch panel 202.

[0038] The control device 201 stores various setting information (production speed for each product type, heater temperature, pressure for molding and sealing, inspection conditions, etc.) and operating programs, and controls the operation of the device (PTP machine 101, etc.) based on this setting information and operating programs. Changes to the settings in the control device 201 (e.g., setting information) are made by changing the settings using the setting change unit 202xc (described later), and then the setting change is approved by the setting change approval unit 14u (see Figure 4) (described later). Changes include registration, addition, modification, and deletion (the same applies hereinafter).

[0039] The touch panel 202 is equipped with various processing functions and functions for displaying and inputting information, and is used for operating the corresponding device (such as the PTP machine 101), changing the settings mentioned above, and confirming various information. In this embodiment, the touch panel 202 corresponds to the "operating means" and the "information changing means". The touch panel 202 functions as a component of the authorization management system 1. The touch panel 202 will be described in detail later.

[0040] Next, the access control system 1 will be described. As shown in Figure 4, the access control system 1 includes a server 10, a number of PCs (four in this embodiment) 11, PC12, PC13, and PC14, and a number of touch panels 202 (only one touch panel 202 is shown in Figure 4).

[0041] Server 10 is connected to PCs 11-14 and touch panel 202, and performs tasks such as sending and receiving various information between them and managing stored information. Server 10 is composed of a computer that includes a CPU (Central Processing Unit) for executing predetermined calculations, ROM (Read Only Memory) for storing various programs and fixed value data, and storage media for storing various information (for example, HDD (Hard Disk Drive) or SSD (Solid State Drive)).

[0042] Server 10 is equipped with a storage area composed of the aforementioned storage medium, which includes an account information storage unit 10a, a line configuration information storage unit 10b, a driver / assistant driver information storage unit 10c, an assignment information storage unit 10d, and an audit trail storage unit 10e. In particular, the account information storage unit 10a is located in the directory service area of ​​the storage area, and the information stored in the account information storage unit 10a is centrally managed using a directory service. In this embodiment, the account information storage unit 10a corresponds to the "account information storage means," and the assignment information storage unit 10d corresponds to the "assignment information storage means."

[0043] The account information storage unit 10a stores predetermined "authentication information" and predetermined "authority information" for each user as a user account (see Figure 5). In this embodiment, the account information storage unit 10a stores the user ID and password as "authentication information" and the authority category as "authority information" in association. The account information storage unit 10a also stores the authority category and authority in association (see Figure 6). This manages the authority for each user. Note that the authority in Figure 6 is just an example, and the type of authority may be changed as appropriate. For example, an authority related to device maintenance may be provided.

[0044] In this embodiment, there are a total of seven authority categories: "0: Manufacturer / Distributor," "1: System Administrator," "2: Maintenance Personnel," "3: Quality Manager," "4: Production Supervisor," "5: Driver," and "6: Driver Assistant." Within each authority category, permissions are further subdivided and set. For example, the authority category "1: System Administrator" has permissions such as viewing audit trails and changing user accounts. Also, for example, the authority category "5: Driver" has permissions such as changing and viewing user assignments to production lines L1 to L10 and equipment (such as the PTP machine 101), changing and viewing various information related to drivers and driver assistants (hereinafter sometimes referred to as "drivers, etc."), and operating equipment (such as the PTP machine 101).

[0045] The line configuration information storage unit 10b stores information regarding the constituent devices of production lines L1 to L10 (see Figure 7) and the attributes of production lines L1 to L10 (see Figure 8). The attributes of production lines L1 to L10 refer to matters that differ from general production lines in terms of the tablets and capsules they handle. In this embodiment, for example, production line L1 has the attribute of "hazardous chemicals" and manufactures PTP sheets using tablets that require careful handling. Also, for example, production line L4 has the attribute of "total tablet management" and requires appropriate management regarding the location of all tablets. The types of attributes can be changed as appropriate, and for example, attributes corresponding to production lines that handle orally disintegrating tablets that require consideration in terms of tablet powder, or attributes corresponding to production lines that handle capsules that do not require consideration in terms of tablet powder, may be provided.

[0046] Furthermore, the line configuration information storage unit 10b is equipped with a required qualification storage unit 10b1. In this embodiment, the required qualification storage unit 10b1 corresponds to the "required qualification storage means". The required qualification storage unit 10b1 stores information (see Figures 9 and 10) regarding the qualifications required for assignment to production lines L1 to L10 and each piece of equipment (such as the PTP machine 101). For example, the required qualification storage unit 10b1 stores that assignment to each production line L1 to L10 requires the qualification of having received safety training 1, and that assignment to production line L1, which has the attribute of "hazardous chemicals," requires the qualification of having received training 7 to properly handle hazardous chemicals. The required qualification storage unit 10b1 also stores, for example, that assignment to the PTP machine 101 requires the qualification of having received training 2 to properly operate the PTP machine 101. In this embodiment, in order to facilitate the modification and management of information, the required qualification storage unit 10b1 stores separately information regarding the qualifications required for assignment to production lines L1 to L10 and information regarding the qualifications required for assignment to each device (such as the PTP machine 101).

[0047] The driver / assistant driver information storage unit 10c stores information about the driver and assistant driver who are primarily responsible for operating the equipment (such as the PTP machine 101). Unlike the assistant driver, the driver has authority over changes to assignments to production lines L1 to L10 and equipment, as well as changes to equipment settings. The driver / assistant driver information storage unit 10c includes a user qualification / validity period storage unit 10c1 and a cumulative duty time storage unit 10c2. In this embodiment, the user qualification / validity period storage unit 10c1 corresponds to the "user qualification storage means" and the "validity period storage means," and the cumulative duty time storage unit 10c2 corresponds to the "cumulative duty time storage means."

[0048] The user qualification / validity period storage unit 10c1 stores information regarding qualifications acquired by the user (educational training 1-8 received by the user) and the date on which those qualifications were acquired (see Figure 11), as well as information regarding the validity period of each qualification (see Figure 12). Therefore, it can be said that the user qualification / validity period storage unit 10c1 stores information regarding the qualifications held by the user (educational training 1-8 received by the user) and information regarding the validity period of these qualifications for each user. The server 10 may also have a function to automatically delete information regarding qualifications whose validity period has expired based on its own clock function.

[0049] The cumulative duty time storage unit 10c2 stores the cumulative duty time of users (especially the driver and driver assistant) for the device (such as the PTP machine 101) (see Figures 13 and 14). In this embodiment, the cumulative duty time serves as a criterion for determining whether the driver or driver assistant can independently manage the device. Of course, the cumulative duty time may be used as a criterion for other purposes. For example, the cumulative duty time may be used as a criterion for determining whether a particular device can be managed.

[0050] The assignment information storage unit 10d stores information regarding the assignment of users (especially drivers and assistant drivers) to production lines L1 to L10 and equipment (such as the PTP machine 101) (see Figures 15 and 16). The assignment information storage unit 10d stores assignment information separately from the user ID and password (i.e., "authentication information") and authority category (i.e., "authorization information") stored in the account information storage unit 10a. In addition, the assignment information storage unit 10d stores separately information regarding the production lines L1 to L10 to which the user is assigned (see Figure 15) and information regarding equipment (such as the PTP machine 101) to which the user is assigned, which is independent of the production lines L1 to L10 (determined independently of the production lines L1 to L10).

[0051] The audit trail storage unit 10e stores information such as the operation details on PCs 11-14 and the touch panel 202, and setting changes on the control device 201, along with information to identify the user who performed the operation (user ID in this embodiment), as an audit trail. In this embodiment, when an operation is performed on PCs 11-14 or the touch panel 202, information such as the operation details and user ID is automatically sent from PCs 11-14 or the device (PTP machine 101, etc.) to the server 10, and this sent information is automatically stored in the audit trail storage unit 10e.

[0052] PCs 11-14 are used for modifying and viewing information stored on server 10. PCs 11-14 are composed of computers having a CPU, ROM, RAM, storage media, etc. In addition, PCs 11-14 are equipped with input means for inputting various types of information (e.g., keyboards) and display means for displaying various types of information (e.g., liquid crystal displays). In this embodiment, PCs 11-14 each correspond to "information modification means".

[0053] PC11 is a terminal that can be used by multiple users, specifically the system administrator (see Figure 17). PC11 includes an audit trail viewing unit 11f, an audit trail registration unit 11g, an authentication processing unit 11h, and an account information change permission determination unit 11j. In this embodiment, the authentication processing unit 11h corresponds to the "authentication processing means," and the account information change permission determination unit 11j corresponds to the "account information change permission determination means." Various functions such as the audit trail viewing unit 11f are realized by the CPU operating according to various programs.

[0054] The audit trail viewing unit 11f displays the audit trail stored in the audit trail storage unit 10e of the server 10 using the display means of the PC 11. However, the functions related to viewing and modifying information by each functional unit of the PC 11 are only available if login to the PC 11 is permitted.

[0055] The audit trail registration unit 11g sends information regarding logins and logouts to PC 11, and operations performed using PC 11 (for example, operations to change information stored in account information storage unit 10a), to the server 10 as an audit trail.

[0056] The authentication processing unit 11h works in cooperation with the account information change permission determination unit 11j to handle the login process on the PC 11 (see Figure 18). The authentication processing unit 11h determines whether the user is legitimate based on the user ID and password entered by the user into the PC 11 and the user ID and password stored in the account information storage unit 10a.

[0057] More specifically, when the user inputs a user ID and password from the user (step S11), the authentication processing unit 11h sends the user ID, etc. to the server 10 and requests the server 10 to perform a determination process to determine whether the input user ID, etc. matches the user ID, etc. stored in the account information storage unit 10a, and to return the determination result. If the authentication processing unit 11h receives a reply indicating that the user ID, etc. matches, the authentication processing unit 11h determines that the user is legitimate (step S12; Yes). On the other hand, if the authentication processing unit 11h receives a reply indicating that the user ID, etc. does not match, the authentication processing unit 11h determines that the user is not legitimate (step S12; No).

[0058] Furthermore, if it is determined that the user is not legitimate, a message to that effect may be displayed. In addition, instead of requiring the input of a user ID and password, the system may read "identification information" stored on the ID card using a designated ID card information reader. Moreover, biometric information (such as iris scans or fingerprints) may be used instead of an ID and password.

[0059] The account information change permission determination unit 11j is a functional unit that, when the authentication processing unit 11h determines that the user is legitimate, permits or denies changes to the information stored in the account information storage unit 10a via the PC 11, based on the user's authority category stored in the account information storage unit 10a.

[0060] More specifically, the account information modification permission determination unit 11j sends the user ID of the user determined to be legitimate to the server 10 and requests the server 10 to reply with the permission category associated with that user ID. If the replied permission category is "1: System Administrator" (Step S13; Yes), the account information modification permission determination unit 11j permits login as a system administrator (Step S14). This permits changes to the information stored in the account information storage unit 10a via the PC 11 (for example, the permission category associated with the user ID). In addition, once login to the PC 11 is permitted, a menu screen for the system administrator is displayed on the display means of the PC 11 (Step S15). By using this menu screen, various operations can be performed on the PC 11 within the system administrator's privileges (for example, viewing audit trails or changing information stored in the account information storage unit 10a).

[0061] On the other hand, the account information change permission determination unit 11j denies login to PC 11 if the returned permission category is not "1: System Administrator" (Step S13; No). Therefore, changes to the information stored in the account information storage unit 10a via PC 11 are not permitted. Furthermore, the account information change permission determination unit 11j displays on the PC 11's display means that the permission category associated with the entered user ID and the permission category corresponding to PC 11 do not match (Step S16).

[0062] PC12 is a terminal that can be used by multiple users, specifically the production manager (see Figure 17). PC12 is equipped with an audit trail viewing unit 12f, an audit trail registration unit 12g, an assignment viewing unit 12k, a driver information viewing unit 12m, an assignment approval unit 12n, a driver information approval unit 12p, an authentication processing unit 12h, and an authorization determination unit 12j. The audit trail viewing unit 12f and the audit trail registration unit 12g function similarly to the audit trail viewing unit 11f and the audit trail registration unit 11g in PC11.

[0063] The assignment viewing unit 12k displays information regarding the assignment of users (especially drivers and assistant drivers) to production lines L1 to L10 and equipment (such as the PTP machine 101) stored in the assignment information storage unit 10d of the server 10, using the display means of the PC 12 (see Figure 19). However, the functions related to viewing, modifying, and approving information by each functional unit of the PC 12 are only available when login to the PC 12 is permitted. For example, the audit trail mentioned above and the information regarding drivers, etc., described below, can only be viewed when login to the PC 12 is permitted.

[0064] The driver information viewing unit 12m displays information about the driver and driver assistant stored in the driver / driver assistant information storage unit 10c of the server 10 using the display means of the PC 12.

[0065] The assignment approval unit 12n is a functional unit that approves changes when the assignment change unit 202xc of the touch panel 202 (described later) attempts to change the information regarding the user's assignment to production lines L1 to L10 and equipment, which is stored in the assignment information storage unit 10d of the server 10. In this embodiment, when the user's assignment is changed (provisionally changed) by the assignment change unit 202xc (described later), information regarding the new assignment is sent to the server 10, and this information is sent from the server 10 to the PC 12. The assignment approval unit 12n then displays the information regarding the new assignment and a request for approval of the assignment change on the display means of the PC 12. When information indicating approval of the assignment change is input to the PC 12 via the input means, the assignment approval unit 12n approves the assignment change, and the approval information is input to the server 10. As a result, the assignment change is reflected in the assignment information storage unit 10d of the server 10.

[0066] The Driver Information Approval Unit 12p is a functional unit that approves changes to information about drivers and driver assistants stored in the Driver / Driver Assistant Information Storage Unit 10c of the Server 10 when the Driver Information Change Unit 202xe, described later, of the Touch Panel 202 attempts to change that information. In this embodiment, when the Driver Information Change Unit 202xe, described later, changes (provisional changes) to information about drivers (for example, the qualifications held by the user), the new information about drivers is sent to the Server 10, and this information is sent from the Server 10 to the PC 12. The Driver Information Approval Unit 12p then displays the new information about drivers and a request for approval of the information change on the display means of the PC 12. When information approving the information change is entered into the PC 12 via the input means, the Driver Information Approval Unit 12p approves the information change, and the approval information is entered into the Server 10. As a result, the information change is reflected in the Driver / Driver Assistant Information Storage Unit 10c of the Server 10.

[0067] The authentication processing unit 12h works in cooperation with the authorization determination unit 12j to handle the login process on PC 12 (see Figure 20). Specifically, when the user enters the user ID and password (step S21), the authentication processing unit 12h performs the same processing as the authentication processing unit 11h on PC 11, and if it receives a reply from the server 10 indicating that the user ID etc. matches, it determines that the user is legitimate (step S22; Yes). On the other hand, if the authentication processing unit 12h receives a reply from the server 10 indicating that the user ID etc. does not match, it determines that the user is not legitimate (step S22; No).

[0068] The authorization determination unit 12j is a functional unit that, when the authentication processing unit 12h determines that the user is legitimate, allows or denies logging in to the PC 12 based on the user's authorization category stored in the account information storage unit 10a.

[0069] More specifically, the authorization determination unit 12j sends the user ID of the user determined to be legitimate to the server 10 and requests the server 10 to reply with the authorization category associated with that user ID. If the replied authorization category is "4: Production Manager" (step S23; Yes), the authorization determination unit 12j grants permission for PC 12 to log in as the production manager (step S24). Once login is permitted, a menu screen for the production manager is displayed on the display means of PC 12 (step S25). Using this menu screen, various operations can be performed on PC 12 within the authority of the production manager (for example, viewing audit trails or approving assignment changes).

[0070] On the other hand, if the authorization determination unit 12j finds that the returned authorization category is not "4: Production Manager" (Step S23; No), it denies login to PC12. Then, the authorization determination unit 12j displays on the PC12's display means that the authorization category associated with the entered user ID does not match the authorization category that PC12 corresponds to (Step S26).

[0071] PC13 is a terminal that can only be used by maintenance personnel among multiple users (see Figure 17). PC13 is equipped with an audit trail viewing unit 13f, an audit trail registration unit 13g, a line configuration information viewing unit 13q, a line configuration information modification unit 13r, an authentication processing unit 13h, and an authorization determination unit 13j. The audit trail viewing unit 13f and the audit trail registration unit 13g function similarly to the audit trail viewing unit 11f and the audit trail registration unit 11g in PC11.

[0072] The line configuration information viewing unit 13q displays information about the components of production lines L1 to L10 and the attributes of production lines L1 to L10, which are stored in the line configuration information storage unit 10b of the server 10, on the display means of the PC 13. However, each function of viewing and modifying information by each functional unit of the PC 13 is only available if login to the PC 13 is permitted. For example, viewing the line configuration information mentioned above and modifying the components described below are only available if login to the PC 13 is permitted.

[0073] The line configuration information modification unit 13r is a functional unit for modifying the information stored in the line configuration information storage unit 10b of the server 10. For example, if the configuration equipment is changed in any of the production lines L1 to L10, the line configuration information modification unit 13r modifies the information stored in the line configuration information storage unit 10b to reflect that change.

[0074] The authentication processing unit 13h works in cooperation with the authorization determination unit 13j to handle the login process on PC 13 (see Figure 21). Specifically, when the user ID and password are entered by the user (step S31), the authentication processing unit 13h performs the same processing as the authentication processing unit 11h on PC 11, and if the server 10 replies that the user ID etc. matches, it determines that the user is legitimate (step S32; Yes). On the other hand, if the server 10 replies that the user ID etc. does not match, the authentication processing unit 13h determines that the user is not legitimate (step S32; No).

[0075] The authorization determination unit 13j is a functional unit that, when the authentication processing unit 13h determines that the user is legitimate, allows or denies login to PC 13 based on the user's authorization category stored in the account information storage unit 10a. That is, the authorization determination unit 13j performs the same processing as the authorization determination unit 12j of PC 12, and if the authorization category returned from the server 10 is "2: Maintenancer" (Step S33; Yes), it allows login to PC 13 as a maintenanceer (Step S34). Once login is permitted, a maintenanceer menu screen is displayed on the display means of PC 13 (Step S35). Using this menu screen, various operations can be performed on PC 13 within the scope of the maintenanceer's authorization (for example, viewing audit trails or changing the configuration of production line L1 to L10).

[0076] On the other hand, if the authorization determination unit 13j finds that the returned authorization category is not "2: Maintainer" (step S33; No), it denies login to PC13. Then, the authorization determination unit 13j displays on the display means of PC13 that there is a mismatch between the authorization category associated with the entered user ID and the authorization category that PC13 corresponds to (step S36).

[0077] PC14 is a terminal that can be used by multiple users, specifically the quality administrator (see Figure 17). PC14 is equipped with an audit trail viewing unit 14f, an audit trail registration unit 14g, an audit trail verification unit 14s, a settings viewing unit 14t, a settings change approval unit 14u, an authentication processing unit 14h, and an authorization determination unit 14j. The audit trail viewing unit 14f and the audit trail registration unit 14g function similarly to the audit trail viewing unit 11f and the audit trail registration unit 11g in PC11.

[0078] The audit trail verification unit 14s is a functional unit that records to the audit trail storage unit 10e of the server 10 that it has confirmed that the stored audit trail is correct. However, each function of the PC 14 related to the verification, viewing, and approval of information is only available if login to the PC 14 is permitted. For example, the verification of the audit trail mentioned above and the approval of setting changes described later are only available if login to the PC 14 is permitted.

[0079] The settings viewing unit 14t displays the settings information (such as production speed for each product type) stored in the control device 201 of the device (such as the PTP machine 101) on the display means of the PC 14.

[0080] The setting change approval unit 14u is a functional unit that approves setting changes when the setting change unit 202xb of the touch panel 202 (described later) attempts to change the settings of a device (such as the PTP machine 101). In this embodiment, when the setting change unit 202xb (described later) changes the settings of the device (temporarily changes them), the new settings are sent to the PC 14 via the server 10. The setting change approval unit 14u then displays the new settings and a request for approval of the setting change on the display means of the PC 14. When information indicating approval of the setting change is input to the PC 14 via the input means, the setting change approval unit 14u approves the setting change, and the approval information is input to the device (such as the PTP machine 101) that is subject to the setting change. As a result, the setting change is reflected in the device.

[0081] The authentication processing unit 14h works in cooperation with the authorization determination unit 14j to handle the login process on PC 14 (see Figure 22). Specifically, when the user ID and password are entered by the user (step S41), the authentication processing unit 14h performs the same processing as the authentication processing unit 11h on PC 11, and if the server 10 replies that the user ID etc. matches, it determines that the user is legitimate (step S42; Yes). On the other hand, if the server 10 replies that the user ID etc. does not match, the authentication processing unit 14h determines that the user is not legitimate (step S42; No).

[0082] The authorization determination unit 14j is a functional unit that, when the authentication processing unit 14h determines that the user is legitimate, allows or denies login to PC 14 based on the user's authorization category stored in the account information storage unit 10a. That is, the authorization determination unit 14j performs the same processing as the authorization determination unit 12j of PC 12, and if the authorization category returned from the server 10 is "3: Quality Administrator" (Step S43; Yes), it allows login to PC 14 as a quality administrator (Step S44). Once login is permitted, a menu screen for quality administrators is displayed on the display means of PC 14 (Step S45). By using this menu screen, various operations can be performed on PC 14 within the scope of the quality administrator's authority (for example, viewing audit trails and configuration information, approving configuration changes, etc.).

[0083] On the other hand, if the authorization determination unit 14j finds that the returned authorization category is not "3: Quality Administrator" (Step S43; No), it denies login to PC14. Then, the authorization determination unit 14j displays on the PC14's display means that the authorization category associated with the entered user ID does not match the authorization category that PC14 corresponds to (Step S46).

[0084] Next, the touch panel 202 will be described. The touch panel 202 is used for changing and viewing information stored in the server 10 and devices (such as the PTP machine 101), and for operating the devices. The touch panel 202 comprises a control unit having a CPU, ROM, RAM, and storage medium, and a panel unit for inputting information to the control unit and displaying information stored in the control unit.

[0085] The touch panel 202 is a terminal that can only be used by those who are authorized to operate the device (such as the PTP machine 101) among multiple users (manufacturers / distributors, maintenance personnel, production managers, drivers, and driver assistants) (see Figure 17). As shown in Figure 3, the touch panel 202 includes an audit trail registration unit 202g, an assignment viewing unit 202k, a driver information viewing unit 202m, a line configuration information viewing unit 202q, a setting viewing unit 202t, an operation unit 202xa, a setting change unit 202xb, an assignment change unit 202xc, an assignment eligibility determination unit 202xd, a driver information change unit 202xe, an authentication processing unit 202h, an authority determination unit 202j, a device matching determination unit 202xf, a login permission unit 202xg, and a notification unit 202xh. In this embodiment, the assignment eligibility determination unit 202xd corresponds to the "assignment eligibility determination means," similarly, the authentication processing unit 202h corresponds to the "authentication processing means," the authorization determination unit 202j corresponds to the "assignment information change eligibility determination means," the device matching determination unit 202xf corresponds to the "device matching determination means," the login permission unit 202xg corresponds to the "login permission means," and the notification unit 202xh corresponds to the "notification means."

[0086] The audit trail registration unit 202g functions similarly to the audit trail registration unit 11g in PC11. The assignment viewing unit 202k and the driver information viewing unit 202m function similarly to the assignment viewing unit 12k and the driver information viewing unit 12m in PC12. The line configuration information viewing unit 202q functions similarly to the line configuration information viewing unit 13q in PC13. The setting viewing unit 202t functions similarly to the setting viewing unit 14t in PC14.

[0087] The operation unit 202xa is a functional unit for operating devices (such as the PTP machine 101) that correspond to the touch panel 202. However, the devices can only be operated using the touch panel 202 that corresponds to those devices.

[0088] The setting change unit 202xb is a functional unit for changing the setting information stored in the device's control unit 201. However, changes to the setting information in the device can only be made using the touch panel 202 corresponding to that device. For example, changes to the setting information in PTP machine 101 can only be made using the touch panel 202 corresponding to that PTP machine 101, and cannot be made using the touch panel 202 corresponding to other PTP machines 101 or integrator 102. When the setting information of the control unit 201 is changed by the setting change unit 202xb, the new setting is sent to the PC 14 via the server 10. Then, as described above, the setting change is only reflected in the device after approval by the setting change approval unit 14u.

[0089] The assignment change unit 202xc is a functional unit for changing the user's assignment information for production lines L1 to L10 and equipment, which is stored in the assignment information storage unit 10d of the server 10. When the assignment information is changed by the assignment change unit 202xc, the new assignment information is sent to the PC 12 via the server 10. Then, as described above, the assignment change is reflected in the assignment information storage unit 10d only after approval by the assignment approval unit 12n. However, the transmission of new assignment information from the touch panel 202 to the PC 12 can only be performed if the assignment feasibility determination unit 202xd determines that the user can be assigned.

[0090] When changing the assignment information stored in the assignment information storage unit 10d via the touch panel 202, the assignment eligibility determination unit 202xd determines whether a user can be assigned to production lines L1 to L10 or equipment based on the information stored in the required qualification storage unit 10b1, the user qualification / validity period storage unit 10c1, and the cumulative assignment time storage unit 10c2. When the assignment change unit 202xc determines new assignment information, the assignment eligibility determination unit 202xd determines that the user can be assigned if the newly determined assignment information is deemed appropriate based on the information stored in the required qualification storage unit 10b1, the user qualification / validity period storage unit 10c1, and the cumulative assignment time storage unit 10c2.

[0091] For example, when assigning a driver with user ID: E001, who has received training 1 and 2 and whose qualifications have not expired, to the PTP machine 101 in new assignment information, the new assignment information is considered appropriate, and therefore, the user assignment is determined to be possible. Once it is determined that the assignment is possible, the new assignment information can be sent to the PC 12.

[0092] On the other hand, if the new assignment information assigns a driver assistant with user ID: F010 who has not received training 4 to the band machine 103, the new assignment information is deemed inappropriate, and the user assignment is determined to be impossible. Similarly, if the new assignment information assigns a driver whose qualification for training 1 has expired to the PTP machine 101, the new assignment information is deemed inappropriate, and the user assignment is determined to be impossible. Furthermore, if the new assignment information assigns a driver with user ID: E010, who has a relatively short cumulative assignment time for the PTP machine 101, to the PTP machine 101 alone, the new assignment information is deemed inappropriate, and the user assignment is determined to be impossible. The reason for the assignment being impossible may be displayed on the touch panel 202.

[0093] The driver information modification unit 202xe is a functional unit for modifying information about drivers and driver assistants stored in the driver / driver assistant information storage unit 10c of the server 10. When the driver information modification unit 202xe modifies the information about drivers, the new information is sent to the PC 12 via the server 10. Then, as described above, the driver information modification unit 12p approves the modification, and only after approval is performed is the change in driver information reflected in the driver / driver assistant information storage unit 10c.

[0094] The authentication processing unit 202h works in cooperation with the authorization determination unit 202j, the device matching determination unit 202xf, and the login permission unit 202xg to handle the login process on the touch panel 202 (see Figure 23). Specifically, when the user inputs a user ID and password from the user (step S41), the authentication processing unit 202h performs the same processing as the authentication processing unit 11h on the PC 11, and if the server 10 replies that the user ID etc. matches, it determines that the user is legitimate (step S52; Yes). On the other hand, if the server 10 replies that the user ID etc. does not match, the authentication processing unit 202h determines that the user is not legitimate (step S52; No).

[0095] The authorization determination unit 202j is a functional unit that, when the authentication processing unit 202h determines that the user is legitimate, allows or denies login to the touch panel 202 based on the user's authorization category stored in the account information storage unit 10a. Specifically, the authorization determination unit 202j checks the user's authorization category stored in the account information storage unit 10a (step S53), and if the authorization category returned from the server 10 is "2: Maintenancer", it allows login to the touch panel 202 as a maintenanceer (step S54). Once login is permitted, a menu screen for maintenanceers is displayed on the touch panel 202 (step S55). This allows various operations on the touch panel 202 within the scope of the maintenanceer's authorization.

[0096] Furthermore, if the authorization determination unit 202j determines that the authorization category returned from the server 10 is "4: Production Manager," it grants permission to log in to the touch panel 202 as the production manager (step S56). Once login is permitted, the menu screen for the production manager is displayed on the touch panel 202 (step S57). This allows the production manager to perform various operations on the touch panel 202 within the scope of their authorization.

[0097] Furthermore, if the authorization determination unit 202j receives an authorization category from the server 10 that is "0: Manufacturer / Seller", it grants permission to log in to the touch panel 202 as a manufacturer / seller (step S58). Once login is permitted, a menu screen for manufacturers / sellers is displayed on the touch panel 202 (step S57). This allows various operations to be performed on the touch panel 202 within the scope of manufacturer / seller authorization.

[0098] Furthermore, if the authorization determination unit 202j receives a response authorization category of "5: Driver", it permits the modification of the assignment information stored in the assignment information storage unit 10d within the scope of the driver's authorization using the touch panel 202. On the other hand, if the authorization determination unit 202j receives a response authorization category other than "5: Driver", it does not permit the modification of the assignment information stored in the assignment information storage unit 10d. Therefore, the authorization determination unit 202j has the function of permitting or denying modification of the information stored in the assignment information storage unit 10d based on the authorization category stored in the account information storage unit 10a. However, in this embodiment, even if the authorization determination unit 202j permits modification of the information in the assignment information storage unit 10d, the information cannot be modified unless the device matching determination unit 202xf determines that the device is a match.

[0099] Furthermore, in this embodiment, if the account information change permission determination unit 11j and the permission determination unit 202j determine that the user is legitimate, an information change permission determination unit 213j (see Figure 4) is configured to allow or deny changes to the information stored in the account information storage unit 10a or the assignment information storage unit 10d via the PC 11 or touch panel 202, based on the user's permission category stored in the account information storage unit 10a, within the scope of the permission corresponding to the permission category. In this embodiment, the information change permission determination unit 213j corresponds to the "information change permission determination means". As described above, the permission category for which the account information change permission determination unit 11j will allow changes to the information stored in the account information storage unit 10a is "1: System Administrator", while the permission determination unit 202j will allow changes to the information stored in the assignment information storage unit 10d is "5: Driver". Therefore, the account information change permission determination unit 11j and the permission determination unit 202j are configured so that the permission categories for which information changes will be permitted are different.

[0100] On the other hand, if the authorization determination unit 202j finds that the returned authorization category is not one of "0: Manufacturer / Seller", "2: Maintainer", "4: Production Manager", "5: Driver", or "6: Driver Assistant" (Step S53; No), it denies permission to log in to the touch panel 202. Then, the authorization determination unit 202j displays on the touch panel 202 that there is a mismatch between the authorization category associated with the entered user ID and the authorization category that the touch panel 202 corresponds to (Step S60).

[0101] The device matching determination unit 202xf is a functional unit that, when the authorization determination unit 202j determines that the user is "5: Driver" or "6: Driver Assistant", determines whether the device (such as the PTP machine 101) corresponding to the touch panel 202 into which the user entered their user ID matches the device to which the user is assigned based on the assignment information stored in the assignment information storage unit 10d. That is, the device matching determination unit 202xf checks the device to which the user who entered their user ID is assigned based on the assignment information stored in the assignment information storage unit 10d, and determines whether that device matches the device corresponding to the touch panel 202 into which the user entered their user ID (step S61). For example, if a driver with user ID: E003 enters their user ID into the touch panel 202 of the PTP machine 101 on production line L1, the device matching determination unit 202xf determines that the device matches because the device to which the driver is assigned matches the device corresponding to the touch panel 202 into which the user entered their user ID.

[0102] The login permission unit 202xg allows the user to log in to the touch panel 202 if the device matching determination unit 202xf determines that a match exists. In this embodiment, if the user is the driver (step S62; Yes), the login permission unit 202xg allows login as the driver (step S63) and displays a menu screen for the driver on the touch panel 202 (step S64). This enables various operations on the touch panel 202 within the driver's authority. Also, if the user is a driver assistant (step S62; No), the login permission unit 202xg allows login as a driver assistant (step S65) and displays a menu screen for the driver assistant on the touch panel 202 (step S66). This enables various operations on the touch panel 202 within the driver assistant's authority.

[0103] If the device matching determination unit 202xf determines that there is no match, the notification unit 202xh notifies the user that the device corresponding to the touch panel 202 to which the user has entered information does not match the device to which the user has been assigned, as stored in the assignment information storage unit 10d. In this embodiment, the notification unit 202xh displays information (see Figure 24) regarding the assignment of users (especially drivers and assistant drivers) to production lines L1 to L10 and devices (such as the PTP machine 101) stored in the assignment information storage unit 10d of the server 10 on the touch panel 202, and notifies the user that there is no match by indicating "Not in charge" in the alarm column of this information (step S67).

[0104] Furthermore, if the device matching determination unit 202xf determines that there is no match, the notification unit 202xh notifies the user of information stored in the assignment information storage unit 10d that indicates the correct production lines L1 to L10 and devices to which the user is assigned. For example, if an assistant operator with user ID: F003, who should be in charge of production line L3, mistakenly attempts to log in to the touch panel 202 on the band machine 103 of production line L2, the notification unit 202xh will highlight on the touch panel 202 that the assistant operator with user ID: F003 is assigned to each device on production line L3 (for example, by changing the color of F003 or displaying F003 with a thick line; see Figure 24). In this way, the assistant operator is notified of the correct production line L3 and devices to which the assistant operator is assigned.

[0105] Furthermore, if the device matching determination unit 202xf determines that there is no match, the notification unit 202xh notifies the user of information that allows them to identify the device corresponding to the touch panel 202 to which the user has entered information, and the production lines L1 to L10 that include that device. In other words, the notification unit 202xh notifies the user of information about their current location. For example, if an assistant driver with user ID: F003, who should be in charge of production line L3, attempts to log in to the touch panel 202 on the band machine 103 of production line L2, the notification unit 202xh will highlight the production line L2 and band machine 103 corresponding to this touch panel 202 (for example, by changing the color of the column corresponding to production line L2 and band machine 103, or by adding a diagonal line. See Figure 24). As a result, the assistant driver is notified of the production line L2 and band machine 103 that they are mistakenly trying to take charge of, and as a result, the assistant driver can determine their current location.

[0106] As detailed above, according to this embodiment, in addition to the permission categories, the server 10 stores information regarding user assignments to production lines L1 to L10 and equipment. Therefore, it is possible to more reliably prevent the complexity of permission categories and to make the management and setting of permission categories easier.

[0107] Furthermore, when assigning users to production lines L1 to L10 or to equipment, there is no need to change the authorization category; it is sufficient to change only the assignment-related information stored in the assignment information storage unit 10d, thereby improving work efficiency and reducing the occurrence of errors.

[0108] Furthermore, the account information change permission determination unit 11j and the permission determination unit 202j are configured so that the permission categories for which information changes are permitted are different. In this embodiment, only system administrators with the authority to make system changes can change permission categories, etc., while only the operator responsible for operating the device can change the information related to assignments. This makes it possible to achieve both security and flexible and efficient operation.

[0109] In addition, the assignment information storage unit 10d stores separately information regarding the production lines L1 to L10 to which the user is assigned, and information regarding equipment assigned to the user that is independent of the production lines L1 to L10. Therefore, even if a user is in charge of multiple production lines L1 to L10, the same equipment will always be assigned to that user. This makes it possible to more reliably prevent a user from being assigned to equipment to which they should not be, and from performing operations or tasks related to equipment that they should not be in charge of. As a result, the manufacturing and packaging of PTP sheets can be carried out more appropriately.

[0110] Furthermore, if the device corresponding to the touch panel 202 into which the user has entered their user ID (the device the user is trying to operate) does not match the device to which the user is assigned, the notification unit 202xh will notify the user of the mismatch. This makes it possible to more reliably make the user aware that they are trying to operate the wrong device. This makes it even more reliable to prevent users from operating or working on devices they are not supposed to be responsible for, and consequently, to manufacture and package PTP sheets more appropriately.

[0111] In addition, the notification unit 202xh can notify the user of the correct production lines L1 to L10 and equipment they should be responsible for when they are attempting to operate the wrong equipment. Therefore, the manufacturing and packaging of PTP sheets can be carried out more appropriately.

[0112] In addition, when a user is attempting to operate the wrong device, the notification unit 202xh notifies the user of information that allows them to identify the device and the production line L1 to L10 that includes it. Based on this information, the user can determine their location. This allows them to move to the production line or device they are originally responsible for earlier, further increasing productivity.

[0113] Furthermore, the assignment eligibility determination unit 202xd makes it possible to assign only users with the necessary qualifications to specific production lines L1 to L10 or equipment. Therefore, it is possible to more reliably prevent users without the necessary qualifications from operating the equipment, and to manufacture and package PTP sheets more appropriately.

[0114] Furthermore, the assignment eligibility determination unit 202xd allows only users with sufficient experience to be assigned to production lines L1 to L10 independently. This further enhances the suitability of the manufacturing and packaging of PTP sheets.

[0115] In addition, the assignment eligibility determination unit 202xd ensures that only users whose qualifications have not expired are assigned to production lines L1 to L10 and equipment. Therefore, the suitability of the manufacturing and packaging of PTP sheets can be further enhanced.

[0116] Furthermore, the embodiment is not limited to the description above, and may be implemented as follows, for example. Of course, other applications and modifications not exemplified below are also possible.

[0117] (a) In the above embodiment, a PC 12 for the production manager, a PC 13 for the maintenance worker, and a PC 14 for the quality manager are provided, but one PC may be configured to be shared by the production manager, maintenance worker, and quality manager. In this case, during the login process (see Figure 25), when the user enters a user ID and password (step S71) and the user is determined to be legitimate (step S72; Yes), the user's authority category stored in the account information storage unit 10a is checked (step S73), and based on the authority category, login may be permitted as either a maintenance worker, production manager, or quality manager. That is, if the user's authority category is "2: Maintenance worker", login to the PC as a maintenance worker may be permitted (step S74), and the maintenance worker's menu screen may be displayed on the PC (step S75). Also, if the user's authority category is "4: Production manager", login to the PC as a production manager may be permitted (step S76), and the production manager's menu screen may be displayed on the PC (step S77). Furthermore, if the user's permission category is "3: Quality Administrator," permission may be granted to log in to the PC as a quality administrator (step S78), and a menu screen for quality administrators may be displayed on the PC (step S79).

[0118] Furthermore, if the user's permission category is anything other than "2: Maintenance", "3: Quality Manager", and "4: Production Manager", the PC's display mechanism may indicate that the permission category associated with the entered user ID does not match the permission category the PC corresponds to (step S80).

[0119] (b) As shown in Figure 26, an account information storage unit 10a may be provided in the directory service area of ​​the storage area of ​​the office server 10Y used by employees performing administrative tasks such as general affairs, and the information stored in the account information storage unit 10a may be managed by the office server 10Y. In this case, new authority categories for employees performing administrative tasks (for example, "7: Office Manager", "8: Office Worker", "9: Office Assistant", etc.) may be created (see Figure 27), and the PC 15 for the office manager, the PC 16 for the office worker, and the PC 17 for the office assistant may be configured to be available within the authority corresponding to the authority category. In this case, a line configuration information storage unit 10b, etc. may be provided in a manufacturing equipment server 10Z separate from the office server 10Y.

[0120] (c) As shown in Figure 28, the network may be divided into an office system and a manufacturing equipment system, and PCs 12, 13, 14 and the touch panel 202 may obtain user IDs, permission categories, assignment information, etc., stored in the account information storage unit 10a of the office system server 10Y via the manufacturing equipment server 10Z.

[0121] (d) As shown in Figure 29, the account information storage unit 10a may be configured not to be located in the directory service area of ​​the server 10's storage area. In other words, the information stored in the account information storage unit 10a may be managed without using the directory service.

[0122] (e) In the above embodiment, the login process on PCs 11-14 and touch panel 202 is performed on PCs 11-14 and touch panel 202, but the login process may be performed on server 10.

[0123] (f) In the above embodiment, the information stored in the account information storage unit 10a can only be changed on PC 11, but it may be possible to change the information using other PCs 12, 13, 14 or the touch panel 202 by logging in as a system administrator.

[0124] Furthermore, in the above embodiment, the information stored in the assignment information storage unit 10d can only be changed via the touch panel 202, but it may also be possible to change this information using PCs 11-14 by logging in as a driver.

[0125] (g) In the above embodiment, the manufacturing equipment 100 performs both the manufacturing and packaging of PTP sheets, but it may also perform only one of the two: the manufacturing or packaging of PTP sheets.

[0126] (h) In the above embodiment, each production line L1 to L10 has multiple devices, but it may also have only one device. For example, production line L1 may be equipped only with a PTP machine 101.

[0127] (i) In the above embodiment, a PTP sheet is given as the medicine, but the medicine is not limited to a PTP sheet. The medicine includes, for example, tablets, capsules, powders, granules, oral liquids, ointments, and containers containing these.

[0128] (j) In the above embodiment, the PTP machine 101 corresponds to the "device," but the various devices that make up the PTP machine 101 (for example, devices for forming pockets, devices for filling tablets into pockets, devices for attaching cover films to container films, devices for inspecting tablets and sheet portions, etc.) may each correspond to the "device." In this case, a touch panel 202 may be provided for each device. [Explanation of Symbols]

[0129] 1...Authority management system, 10a...Account information storage unit (account information storage means), 10b1...Required qualification storage unit (required qualification storage means), 10c1...User qualification / validity period storage unit (user qualification storage means, validity period storage means), 10c2...Cumulative assignment time storage unit (cumulative assignment time storage means), 10d...Assignment information storage unit (assignment information storage means), 11,12,13,14...PC (information modification means), 11h,202h...Authentication processing unit (authentication processing means), 11j...Account information modification feasibility determination unit (account information modification feasibility determination means), 10 0...Manufacturing equipment, 101...PTP machine (device), 102...Stacking machine (device), 103...Banding machine (device), 104...Pillow machine (device), 105...Boxing machine (device), 202...Touch panel (means for changing information, means for operation), 202j...Authority determination unit (means for determining whether assignment information can be changed), 202xd...Assignment feasibility determination unit (means for determining whether assignment can be changed), 202xf...Device matching determination unit (means for determining whether device matching), 202xg...Login permission unit (means for determining whether login permission is granted), 202xh...Notification unit (means for notification), 213j...Information change feasibility determination unit (means for determining whether information can be changed).

Claims

1. An authorization management system applicable to a manufacturing facility that manufactures and / or packages pharmaceuticals, comprising multiple production lines, each having one or more devices, An account information storage means that stores predetermined authentication information and predetermined authorization information for each user, In addition to the authentication information and the authorization information, the assignment information storage means stores information regarding the assignment of users to the production line and the equipment, Information modification means capable of modifying information stored in at least one of the account information storage means and the assignment information storage means, including operating means for operating the device provided in the device, Authentication processing means that determines whether the user is legitimate based on the authentication information input by the user to the information modification means and the authentication information stored in the account information storage means, If the authentication processing means determines that the user is legitimate, the system includes an information modification permission determination means that, based on the user's authority information stored in the account information storage means, permits or denies modifying the information stored in the account information storage means or the assignment information storage means via the information modification means within the scope of the authority corresponding to the authority information, The means for determining whether the information can be changed is: An account information modification permission determination means that determines whether to permit or deny changes to the information stored in the account information storage means based on the authority information stored in the account information storage means, The system includes an assignment information modification permission determination means that determines whether to permit or deny changes to the information stored in the assignment information storage means based on the authority information stored in the account information storage means, An authorization management system characterized in that the account information change permission determination means and the assignment information change permission determination means are set so that the authorization information that will be permitted to be changed is different.

2. The aforementioned allocation information storage means is Information regarding the production line to which the user is assigned, Information regarding the equipment assigned to the user, which is independent of the aforementioned production line, The authorization management system according to claim 1, characterized in that it stores the data separately.

3. When the authentication processing means determines that the user is legitimate based on the authentication information input by the user to the operating means, the operating means determines whether the corresponding device and the device to which the user is assigned based on the assignment information stored in the assignment information storage means match, If the device matching determination means determines that a match has been found, the login permission means allows the user to log in to the operation means, The authorization management system according to claim 1, further comprising a notification means for notifying the user that, when the device matching determination means determines that there is no match, the device to which the user is assigned, as stored in the assignment information storage means, does not match the device to which the user is assigned.

4. The authorization management system according to claim 3, characterized in that the notification means is configured to notify the user of information stored in the assignment information storage means indicating the correct production line and equipment to which the user has been assigned when the device matching determination means determines that the devices do not match.

5. The authorization management system according to claim 3, characterized in that the notification means is configured to notify the user of information that allows the user to identify the device and the production line including the operating means to which the user has input information, when the device matching determination means determines that the device does not match.

6. A necessary qualification storage means for storing information regarding the qualifications required for assignment to the production line and information regarding the qualifications required for assignment to the device, A user credentials storage means that stores information about the credentials a user possesses, The authorization management system according to claim 1, further comprising: an assignment eligibility determination means that determines whether a user can be assigned to the production line or the device based on the information stored in the required qualifications storage means and the user qualifications storage means when changing the information stored in the assignment information storage means via the information modification means.

7. The device is equipped with a cumulative duty time storage means for storing the cumulative duty time of the user for the device, The authorization management system according to claim 6, characterized in that the assignment eligibility determination means determines whether a user can be assigned to the device based on the information stored in the cumulative assignment time storage means when changing the information stored in the assignment information storage means via the information modification means.

8. The system includes a validity period storage means for storing information regarding the validity period for each user of the qualifications necessary for assigning a user to the production line or the equipment, The authorization management system according to claim 6, characterized in that the allocation eligibility determination means determines whether a user can be assigned to the production line or the device based on the information stored in the validity period storage means when changing the information stored in the allocation information storage means via the information changing means.

Citation Information

Patent Citations

  • Power management assistance device, program, and power management assistance method

    CN118401951A

  • Biometric authentication system and biometric authentication method

    JP2019200633A

  • RFID reader writer device

    JP2020160990A

  • Management system, information processing device, method, and program

    JP2025042352A

  • Management device and article management system

    US20220221840A1