DATA MANAGEMENT DEVICE, DATA PROVIDING SYSTEM, DATA MANAGEMENT METHOD AND PROGRAM
Patent Information
- Application Number
- JP2024520638
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-11-30
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2043-11-30
AI Technical Summary
The burden of preparatory work for controlling access to data generated in facilities becomes complex due to the involvement of multiple groups with different roles, such as facility managers, system integrators, and maintenance companies, when using Role-Based Access Control (RBAC) systems, especially in industrial settings like factories.
A data management device that receives device information from facilities, manages data related to this information, and provides data management via a network, using a data model that combines roles assigned to groups and defines data attributes, with a management system that stores access permissions and allows registration of additional groups, applying a common data model for multiple groups to simplify access control.
This approach reduces the workload for preparing access control by allowing a common data model to be applied across different groups, simplifying the determination of access rights and reducing the need for redundant model creation and coordination between groups.
Smart Images

Figure 00000017_0000 
Figure 00000017_0001 
Figure 00000018_0000
Abstract
Description
[Technical field]
[0001] The present disclosure relates to a data management device, a data providing system, a data management method, and a program. [Background technology]
[0002] RBAC (Role Based Access Control) is known, which controls user access to data in a system by assigning roles to users of the system and giving them access rights associated with the roles. When the number of managed objects such as roles handled in RBAC increases, the processing load increases and the responsiveness to access to data decreases. Therefore, a technology for reducing the processing load of RBAC has been proposed (for example, see Patent Document 1).
[0003] Patent Document 1 describes a device that determines access authority based on user list information in access control using extended roles. This device can reduce the processing load required to determine access authority when access to content that is restricted is attempted. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] JP 2010-117885 A Summary of the Invention [Problem to be solved by the invention]
[0005] In RBAC, roles are usually assigned to users who belong to groups such as organizations, companies, or groups. The types of data that can be accessed are then determined for each role. Such an RBAC method is also used in the technology of Patent Document 1.
[0006] When data generated in a facility such as a factory or facility is to be processed by RBAC, the administrator of the facility corresponds to the above-mentioned group. However, data generated in the facility may be used by users belonging to groups other than the administrator of the facility, such as a group that produces (including sells) the equipment installed in the facility, a group that uses the equipment, or a system integrator and maintenance company. Furthermore, each group is not limited to being confined to the same company. The task of determining the type of accessible data for each role to be assigned to users belonging to such various groups may be very cumbersome for the worker. Therefore, there is room to reduce the burden of preparation work for controlling access to data generated in the facility.
[0007] The present disclosure has been made in light of the above-mentioned circumstances, and aims to reduce the burden of preparatory work for controlling access to data generated in a facility. [Means for solving the problem]
[0008] In order to achieve the above-mentioned object, the data management device disclosed herein is a data management device that receives device information from a device installed in a facility, manages data related to the device information, and provides the data to objects via a network, and is equipped with a management means that stores and manages a table indicating, for a combination of a role assigned to each of a plurality of objects belonging to a group and an attribute of data defined by a predetermined data model corresponding to a group, whether or not an object to which the role is assigned is permitted to access data having the attribute, an access control means that controls access from the object to the data based on the table corresponding to the group to which the object belongs, and a reception means that accepts registration of a second group different from the first group by an object belonging to the first group, and the management means applies the data model corresponding to the first group as a data model for constructing a table corresponding to the second group. Effect of the Invention
[0009] According to the present disclosure, it is possible to reduce the burden of preparation work for controlling access to data generated in a facility. [Brief description of the drawings]
[0010] [Figure 1] FIG. 1 shows a configuration of a data providing system according to a first embodiment. [Diagram 2] FIG. 1 is a diagram showing a hardware configuration of a data management device according to a first embodiment. [Diagram 3] FIG. 1 is a diagram showing a functional configuration of a data management device according to a first embodiment; [Figure 4] FIG. 1 shows how two groups according to the first embodiment are managed as a set. [Diagram 5] FIG. 1 is a diagram showing an example of a data model according to the first embodiment; [Figure 6] FIG. 1 is a diagram for explaining access control according to the first embodiment. [Figure 7] FIG. 1 is a diagram for explaining designation of a secret device according to the first embodiment; [Figure 8] FIG. 1 is a first diagram showing an example of specifying whether or not data is to be disclosed for each device according to the first embodiment; [Figure 9] FIG. 2 is a second diagram showing an example of specifying whether or not data is to be disclosed for each device according to the first embodiment; [Figure 10] Flowchart showing data management processing according to the first embodiment [Figure 11] FIG. 11 is a diagram for explaining designation of data to be kept secret according to the second embodiment; [Figure 12] FIG. 11 is a diagram showing access controlled data according to a modified example. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0011] Hereinafter, a data providing system according to an embodiment of the present disclosure will be described in detail with reference to the drawings.
[0012] Embodiment 1 As shown in FIG. 1, a data providing system 1000 according to this embodiment is a system in which data relating to information transmitted from a facility 20, such as a factory or a plant, is managed in a data management device 10 and provided to an object 40 via a network NW. The data providing system 1000 performs access control as a cloud service. Specifically, the data providing system 1000 provides data to users having a predetermined access authority, and restricts the provision of data to users not having the access authority. A user is a target to which data is provided by the data providing system 1000, and hereinafter, a user is referred to as an object 40. Note that an object is not limited to a user.
[0013] The data providing system 1000 includes a device 21 and a gateway device 22 installed in a facility 20, a data management device 10 that performs access control, and a terminal 30 that is used by an object 40 that is a user.
[0014] The device 21 may be a control device such as a PLC (Programmable Logic Controller), a controlled device such as a sensor, an actuator, a robot, or a machine tool, a UI (User Interface) device for an operator to set control contents, or other FA devices constituting an FA system. The device 21 may be a transmitting device that transmits information.
[0015] The information transmitted by the device 21 indicates, for example, a sensing result, an operating state of the device 21, the occurrence of an abnormality, or an execution result of a predetermined program. The operating state of the device 21 may be, for example, a current value, a voltage value, a speed, an acceleration, an angular velocity, or an angular acceleration measured in the device 21, or may correspond to data stored in the memory of the device 21. The transmission of information by the device 21 may be performed periodically at a predetermined cycle, may be repeated aperiodically, or may be performed in response to the establishment of a predetermined trigger condition. In addition, the transmission of information by the device 21 may be performed spontaneously from the device 21, may be performed in response to an operation by an operator on the device 21, or may be performed in response to a request from the data management device 10.
[0016] 1 illustrates, as examples of information transmitted from the device 21, operation status data 51 indicating the operation status of the device 21 and alarm data 52 indicating the occurrence of an abnormality in the device 21. Note that, although one device 21 is representatively illustrated in FIG 1, a plurality of devices 21 may be installed in the facility 20. The information transmitted by the device 21 corresponds to an example of device information transmitted from a device installed in the facility.
[0017] The gateway device 22 relays the transmission of information between the device 21 and the data management device 10 outside the facility 20. The gateway device 22 provides an API (Application Protocol Interface) function for uploading information from the device 21 to the data management device 10. FIG. 1 illustrates that the gateway device 22 has the functions of an operating status API 221 for uploading operating status data 51 and an alarm API 222 for uploading alarm data 52.
[0018] The data management device 10 is a server device on a network such as the Internet. The data management device 10 receives and manages information uploaded via a gateway device 22. In the data management device 10, the information transmitted from the device 21 is standardized by a data model called model g, and becomes a data group including operating status data 51 and alarm data 52. As shown in the data model DB 101 in Fig. 1, model g is a data model corresponding to group G, and defines data attributes including operating status and alarm. Here, group G is a group to which a plurality of objects 40 to which data related to the information transmitted from the device 21 is provided belong. Note that the API function of the gateway device 22 is implemented in the gateway device 22 after being predetermined as corresponding to model g.
[0019] 1, in order to facilitate understanding of the explanation, it is shown that the information transmitted from the device 21 is provided to the object 40 as is through access control. However, this is not limited to this, and data resulting from processing the information transmitted from the device 21 by the gateway device 22 or the data management device 10 may be the target of access by the object 40. For example, data indicating the result of performing statistical processing on the information repeatedly transmitted from the device 21 may be provided to the object 40.
[0020] Data managed by the data management device 10 is appropriately provided to objects 40 belonging to group G under access control based on an access control table 102. This access control table 102 is a two-dimensional table in which a list of attributes of data defined by model g corresponds to the vertical axis, and a list of roles assigned to each object 40 of group G corresponds to the horizontal axis, and indicates whether or not access to data having the attribute from an object 40 assigned the role is permitted for each combination of attribute and role. For example, in the access control table 102 in FIG. 1, a check mark indicates that an object 40 assigned with "role A" is permitted to access data having an attribute of "alarm". In addition, "NO" indicates that access to data having an attribute of "operation status" by an object 40 assigned with "role B" is restricted.
[0021] As described above, the list of data attributes constituting the access control table 102 is predefined in correspondence with the group G. For example, if there is a desire in the group G to access the operating status data 51 and the alarm data 52, the operating status data 51 and the alarm data 52 transmitted from the device 21 are added to the list. Here, if it is desired that the access to the operating status data 51 and the access to the alarm data 52 are based on different access rights, the attribute of the data corresponding to the operating status data 51 and the attribute of the data corresponding to the alarm data 52 become different list elements. On the other hand, if there is no need to distinguish the operating status data 51 and the alarm data 52, the attribute of the data including both the operating status data 51 and the alarm data 52 can become one list element. In this way, the list of data attributes corresponds to the way data is handled in the group. Therefore, when controlling access by the objects 40 belonging to different groups, the list of data attributes constituting the access control table 102 can become different in correspondence with the groups.
[0022] Therefore, the data model DB 101 manages data models that define the attributes of data in association with groups.
[0023] 1 shows one device 21, and typically, an organization, company, or group that maintains the device 21 after it is in operation corresponds to group G. When the data management device 10 collects information from multiple devices 21 maintained by different groups, access by objects 40 belonging to each group is controlled based on a data model corresponding to each group.
[0024] The data management device 10 controls access to data via the network NW based on the access control table 102 to which the object 40 that has made the access belongs. For example, in the example of FIG. 1, if role A is assigned to an object 40 that belongs to group G, the data management device 10 permits the object 40 to access alarm data 52 and provides the alarm data 52 to the object 40. Also, if role B is assigned to an object 40 that belongs to group G, the data management device 10 restricts the object 40 from accessing operating status data 51 and does not provide the operating status data 51 to the object 40. Note that providing data to an object 40 means transmitting data to a terminal 30 used by the object 40.
[0025] The terminal 30 is a UI device for a user as an object 40 to refer to data, and is, for example, an industrial personal computer (PC), a tablet terminal, or a smartphone. The terminal 30 may display a dashboard on a web browser, and display data provided from the data management device 10 in a card model type UI on the dashboard. In the example of FIG. 1, the terminal 30 and the object 40 are located outside the facility 20, but the terminal 30 and the object 40 may be located inside the facility 20.
[0026] Next, the data management device 10 that executes the access control will be described in more detail. The data management device 10 is composed of hardware elements for functioning as a computer that receives device information, manages data related to the device information, and provides the data to objects via a network. In detail, as shown in Fig. 2, the data management device 10 has a processor 61, a main memory unit 62, an auxiliary memory unit 63, an input unit 64, an output unit 65, and a communication unit 66. The main memory unit 62, the auxiliary memory unit 63, the input unit 64, the output unit 65, and the communication unit 66 are all connected to the processor 61 via an internal bus 67.
[0027] The processor 61 includes a CPU (Central Processing Unit) as a processing circuit. The processor 61 executes a program P1 stored in the auxiliary storage unit 63 to realize various functions and execute the processes described below.
[0028] The main memory unit 62 includes a RAM (Random Access Memory). The program P1 is loaded into the main memory unit 62 from the auxiliary memory unit 63. The main memory unit 62 is used as a working area for the processor 61.
[0029] The auxiliary storage unit 63 includes a non-volatile memory such as an EEPROM (Electrically Erasable Programmable Read-Only Memory) and an HDD (Hard Disk Drive). In addition to the program P1, the auxiliary storage unit 63 stores various data used in the processing of the processor 61. The auxiliary storage unit 63 supplies the processor 61 with data used by the processor 61 in accordance with an instruction from the processor 61. The auxiliary storage unit 63 also stores data supplied from the processor 61.
[0030] The input unit 64 includes input devices such as a hardware switch, an input key, a keyboard, and a pointing device. The input unit 64 acquires information input by a user of the data management device 10, and notifies the processor 61 of the acquired information.
[0031] The output unit 65 includes output devices such as a light emitting diode (LED), a liquid crystal display (LCD), and a speaker. The output unit 65 presents various information to the user in accordance with instructions from the processor 61.
[0032] The communication unit 66 includes a communication interface circuit for communicating with an external device. The communication unit 66 receives a signal from the outside and outputs data indicated by the signal to the processor 61. The communication unit 66 also transmits a signal indicating the data output from the processor 61 to the external device. Although one communication unit 66 is representatively shown in FIG. 2, the data management device 10 may have multiple communication units 66. For example, a communication unit 66 for communicating with the gateway device 22 of the facility 20 and a communication unit 66 for communicating with the terminal 30 via the network NW may be provided separately.
[0033] The above-mentioned hardware configurations work together to allow the data management device 10 to perform various functions. In detail, as shown in Fig. 3, the data management device 10 has, as its functions, a storage unit 110 for storing received information, an access control unit 120 for executing access control for the information stored in the storage unit 110, a management unit 100 for managing a table for executing the access control, a first communication unit 130 for communicating with the facility 20, a Web server unit 140 for providing data to the object 40, and a second communication unit 150 for communicating with the object 40 via the network NW. The first communication unit 130 and the second communication unit 150 are each realized by a communication unit 66.
[0034] The management unit 100 is mainly realized by the processor 61. The management unit 100 has an access control table 102 that specifies the details of access control, and a data model DB 101 that associates a data model for configuring the access control table 102 with a group. However, in the access control table 102 shown in FIG. 3, common data attributes are used for two groups, a maintenance group and a use group. Here, the maintenance group is a group that is responsible for the maintenance work of maintaining the device 21 that configures the FA system of the facility 20, and the maintenance object 41 is an object 40 that corresponds to a worker belonging to the maintenance group. In addition, the use group is a group that is responsible for the work of operating the FA system using the device 21, and the use object 42 is an object 40 that corresponds to a worker belonging to the use group. Hereinafter, the maintenance object 41 and the use object 42 may be collectively referred to as the object 40. The FA system is a system constructed using the device 21 in a facility, and is, for example, a production system that processes a large number of workpieces by controlling a large number of devices 21 to produce products.
[0035] As described above, the contents of the access control by the object 40 correspond to the group to which the object 40 belongs, typically to the maintenance group that maintains the device 21. However, it may be desirable for the data generated in the FA system to be used by a plurality of groups, such as the operator of the FA system including the device 21, the manufacturer of the device 21, the set manufacturer of the device group including the device 21, and the system integrator that delivers software to the FA system, in addition to the maintenance company of the device 21. For example, when an abnormality occurs in the device 21 during operation of the FA system, there may be a case where the user group, which is the operator of the FA system, requests the maintenance group to repair or replace the device 21. In such a case, if the objects 40 of both the maintenance group and the user group can refer to the data of the device 21, it is expected that the malfunction will be quickly eliminated. Note that, although an example in which the maintenance group is solely responsible for the maintenance work has been described, the present invention is not limited to this, and the user group may make a maintenance plan and perform maintenance work including repair and replacement.
[0036] Since the tasks handled by the groups are different, different roles are assigned to the objects 40 belonging to each group. However, if a different data model for configuring the access control table 102 is to be determined for each group, the determination process may become complicated. Therefore, if a common data model is used for these groups, the data model determination process can be consolidated into one process, reducing the workload.
[0037] In detail, the management unit 100 applies the model g1 corresponding to the maintenance group as a data model for configuring a table corresponding to the usage group. That is, the management unit 100 adopts the model g1 corresponding to the maintenance group as a data model for the usage group in the data model DB 101. The data model for configuring the access control table of the maintenance group and the data model for configuring the access control table of the usage group are associated as the same data model, and this correspondence is maintained.
[0038] Furthermore, when managing a plurality of groups including a maintenance group and a usage group, the management unit 100 manages the maintenance group and the usage group as one set, as shown in Fig. 4. In detail, the management unit 100 manages information indicating combinations in which the maintenance group and the usage group are associated with each other, and the data model of the access control table is made common for the combinations indicated by the information.
[0039] An example of a model g1 corresponding to a maintenance group is shown in Fig. 5. As shown in Fig. 5, the data model hierarchically defines data attributes and is described in, for example, XML (Extensible Markup Language) format. The model g1 has three categories: business data related to the business of the maintenance group, event data related to events that have occurred in the device 21, and file data representing files provided by the device 21. The event data and file data are collected from the device 21 via the event APIs and file APIs of the gateway device 22, respectively.
[0040] The business data includes data on customer information management for managing customers of the maintenance contractor, which is the maintenance group, maintenance user management for managing the maintenance objects 41, user management for managing the use objects 42, and other items. The event data includes data on operation status, alarms, and other items. The file data includes five levels of confidential information, from confidentiality level 1 information to confidentiality level 5 information, and information exclusive to the maintenance group.
[0041] With the three categories of business data, event data, and file data defined, templates for the event API and file API are provided to the maintenance group by the data management device 10 or by a provider of cloud services by the data management device 10. Then, the maintenance object 41, which is the administrator of the maintenance group, creates details of each item belonging to the three categories and APIs corresponding to each item.
[0042] Note that the API and the items in the data model do not have to correspond one-to-one. For example, as illustrated in the file data of Fig. 5, the file data uploaded via the standard time series file API and the general device file API may be classified into six types of file data according to the ID included in the data.
[0043] Moreover, the business data is stored in advance in the data management device 10 by the maintenance object 41 without being collected from the facility 20 .
[0044] Furthermore, the roles of the maintenance group and the use group may be determined by the maintenance object 41. When the maintenance group is the manufacturer of the device 21, flexible access control based on the roles becomes possible for the event data and files that the manufacturer independently causes the device 21 to transmit.
[0045] The management unit 100 corresponds to an example of a management means that stores and manages a table indicating, for a combination of a role assigned to each of a plurality of objects belonging to a group and an attribute of data defined by a predetermined data model corresponding to the group, whether an object to which the role is assigned is permitted to access data having the attribute.
[0046] Returning to Fig. 3, the storage unit 110 is mainly realized by at least one of the main storage unit 62 and the auxiliary storage unit 63. Information transmitted from the device 21 is stored in the storage unit 110 as data to be accessed by the object 40. However, the data transmitted from the device 21 is not directly accessed by the object 40, and the object 40 indirectly accesses the data because access to the data is permitted for the role assigned to the object 40 in the access control table 102. That is, as shown in Fig. 3, an access control unit 120 is interposed between the storage unit 110 and the object 40.
[0047] The access control unit 120 is mainly realized by the processor 61. The access control unit 120 controls access by the maintenance object 41 and the usage object 42 via the Web server unit 140 and the second communication unit 150. The access control by the access control unit 120 is based on the access control table 102 and the assignment of roles to each object 40.
[0048] Fig. 6 illustrates information that specifies the contents of access control by the access control unit 120. In detail, the upper side of Fig. 6 illustrates an access control table 102 configured using the data model of Fig. 5, and the lower side illustrates role data 104 indicating roles assigned to the maintenance object 41 and the usage object 42, respectively.
[0049] In FIG. 6, the role data 104 is information in a table format in which the vertical axis corresponds to a list of objects and the horizontal axis corresponds to a list of roles identical to those in the access control table 102, and a black circle is added to a combination of an object and a role if the object has the role. For example, the role data 104 shows that the role "SYSTEM_ADMIN" of the maintenance group is assigned to the "object 41a" which is a maintenance object. Therefore, the "object 41a" can access the "confidential level 1 information" which is checked in the access control table 102 for the combination with the "SYSTEM_ADMIN". It can also be seen that the roles "XXX" and "YYY" of the usage group are assigned to the "object 42b" which is a use object. However, since neither the "XXX" nor the "YYY" is checked in the access control table 102 for the combination with the "confidential level 1 information", the "object 42b" cannot access the "confidential level 1 information". The access control unit 120 corresponds to an example of an access control means that controls access from an object to data on the basis of a table corresponding to the group to which the object belongs.
[0050] Returning to FIG. 3, the Web server unit 140 is mainly realized by the processor 61. The Web server unit 140 provides a management screen to be displayed for the maintenance object 41 and the use object 42 via the second communication unit. In this management screen, the designation of a use group by the maintenance object 41 is accepted. In detail, the Web server unit 140 accepts the registration of a use group as a target for which the maintenance service of the device 21 is to be provided by the maintenance object 41. By designating a use group by the maintenance object 41 in this way, as shown in FIG. 3, a data model corresponding to the maintenance group is applied as constituting an access control table of the use group. In addition, the Web server unit 140 accepts the registration of business data including the manual and consumable information of the device 21 from the maintenance object 41. The Web server unit 140 corresponds to an example of a receiving means for accepting the registration of a use group by an object belonging to the maintenance group.
[0051] Furthermore, the Web server unit 140 accepts, from the usage object 42, a designation of a secret device that transmits information that should be kept secret among the multiple devices 21 used in the usage group. Data relating to the information transmitted from the secret device is kept secret from groups other than the usage group, and access to the data from the maintenance object 41 is restricted. This access restriction is executed by the access control unit 120, separately and independently of the access control by the access control table 102.
[0052] Fig. 7 shows an example in which the use object 42 specifies a secret device. In the example of Fig. 7, the fact that the device E1 of the devices E1 and E2, which are the devices 21, is specified as a secret device is shown as "NG" in the setting data 105. For this reason, for example, the object 41a of the maintenance group is stipulated in the access control table 102 to have the authority to access data indicating the operating status of the device 21, but cannot access data indicating the operating status of the device E1.
[0053] The access control table 102 that specifies the contents of access control is set by the maintenance group as described above, but there are cases where the user group wishes to keep information about some of the devices 21 they are using secret from the outside. In this case, the Web server unit 140 accepts the designation of a secret device from the use object 42, and the access control unit 120 restricts access from objects belonging to groups other than the user group to data related to the information transmitted from the secret device. A data masking function that enables the user group to designate whether to disclose or not disclose data is provided to the user group by the data management device 10.
[0054] Instead of designating a secret device as shown in Fig. 7, the Web server unit 140 may receive, from the use object 42, designation of whether or not to disclose data to those outside the use group for each combination of the device 21 and the attribute defined by the data model, as shown in Fig. 8. In the example of Fig. 8, the setting data 105a indicates that the alarm data of "device E1" is not to be disclosed to those outside the use group. For this reason, for example, the object 41a of the maintenance group is defined in the access control table 102 as having the authority to access the alarm data of the device 21, but cannot access the alarm data of the device E1. In addition, in the setting data 105a of Fig. 8, items for which the object 42 of the use group cannot set the disclosure status are hatched.
[0055] Also, the setting data 105 shown in Fig. 7 and the setting data 105a shown in Fig. 8 may be used in combination. For example, as shown in Fig. 9, for a device 21 that is not designated as a secret device, whether or not to disclose data may be designated for each attribute of data.
[0056] Returning to FIG. 3, the second communication unit 150 corresponds to a communication interface with a Web application used by the terminal 30 and an external system via the network NW, and provides an API to an external device.
[0057] Next, a data management process executed by the data management device 10 having the above-mentioned functions will be described with reference to Fig. 10. The data management process shown in Fig. 10 starts when the data management device 10 is powered on.
[0058] In the data management process, the Web server unit 140 receives settings of the maintenance object 41, role, and data model of the maintenance group from the maintenance object 41, which is the administrator of the maintenance group (step S1). Then, the management unit 100 generates an access control table 102 of the maintenance group based on the information received in step S1 (step S2). The contents of the access control table, that is, whether or not access is permitted for each combination of each role and each attribute of data, may be set by the maintenance object 41 in step S1, or a predetermined initial value may be applied.
[0059] Next, the Web server unit 140 accepts the registration of the usage group by the maintenance object 41, and accepts settings related to the usage objects 42 and roles of this usage group (step S3). As a result, information related to the usage group in the role data 104 shown in FIG. 6, for example, is set.
[0060] Next, the management unit 100 applies the data model of the maintenance group as a data model constituting the access control table 102 of the usage group to generate the access control table 102 (step S4). The contents of this table, i.e., whether or not access is permitted for a combination of each role and each attribute of data, may be set by the maintenance object 41 in step S3, may be set by the usage object 42 when generating the table, or a predetermined initial value may be applied. The management unit 100 corresponds to an example of a management means that generates an access control table indicating whether or not an object to which a role is assigned is permitted to access data having the attribute for a combination of a role assigned to each of a plurality of objects belonging to the usage group and an attribute of data defined by a data model for constituting the access control table corresponding to the maintenance group.
[0061] Next, the Web server unit 140 receives a setting as to whether or not to disclose data to other groups from the use object 42 (step S5). Specifically, the Web server unit 140 receives the contents of the setting data 105 in FIG. 7, the setting data 105a in FIG. 8, or the setting data 105b in FIG.
[0062] Then, the access control unit 120 controls access from the maintenance object 41 or the use object 42 in accordance with the access control table 102 for each group generated in steps S2 and S4, and the settings for disclosure by the use group accepted in step S5 (step S6).
[0063] Next, the management unit 100 determines whether the data model corresponding to the maintenance group has been changed by the maintenance group (step S7). The change in the data model is, for example, an increase or decrease in any of the items of the business data, event data, and file data shown in FIG.
[0064] If it is determined that the data model has not been changed (step S7; No), the data management device 10 repeats the processing from step S6 onwards. On the other hand, if it is determined that the data model has been changed (step S7; Yes), the management unit 100 applies the data model of the maintenance group as the data model constituting the access control table 102 of the use group, and updates the access control tables 102 of both the maintenance group and the use group (step S8). When the data model for constituting the access control table corresponding to the maintenance group is changed by an object belonging to the maintenance group, the management unit 100 corresponds to an example of a management means that updates the table by applying the changed data model to the access control table corresponding to the use group. Thereafter, the processing from step S6 onwards is repeated.
[0065] As described above, the Web server unit 140 accepts the registration of a usage group by the maintenance object 41, and the management unit 100 applies the data model corresponding to the maintenance group as a data model for constructing the access control table 102 corresponding to the usage group. This makes the data model common to the maintenance group and the usage group, and eliminates the need to create the data model again after the usage group is registered. This reduces the burden of preparation work for controlling access to data that occurs in the facility.
[0066] In detail, the management unit 100 manages the maintenance group and the usage group as one set, and generates the access control table 102 for each group using a data model common to the groups constituting this set. This eliminates the need to create a data model when generating the access control table 102 corresponding to the usage group, reducing the workload.
[0067] Furthermore, when the data model is changed, the management unit 100 applies the change to the access control table 102 corresponding to the usage group, and updates the access control table 102. This eliminates the need to redesign the data model of the usage group when the data model of the maintenance group is changed, thereby reducing the workload.
[0068] The data management device 10 also provides a data masking function that is set by the use group. In detail, the Web server unit 140 accepts the designation of a secret device that transmits information that should be kept secret from the use object 42, and the access control unit 120 restricts access from objects that belong to groups other than the use group to data related to the information transmitted from the secret device. This allows the maintenance group to define the data model while the use group can designate the secret device.
[0069] With regard to data on the device 21, both the maintenance group, which is the manufacturer of the device 21, and the user group, which actually uses the device 21, request that the data be handled freely, and coordination between the two groups may be necessary. However, such coordination takes time and does not necessarily lead to a reasonable conclusion. Here, in normal maintenance work, the maintenance group often places importance on the type of data handled by multiple devices 21, without distinguishing between individual devices 21. On the other hand, although the user group may wish to keep information about some of the devices 21 among the multiple devices 21 arranged in the facility 20 confidential, they tend to place less importance on the type of data than the maintenance group.
[0070] In response to these requests from both groups, the data management device 10 according to the present embodiment adopts the data model determined by the maintenance group in the access control tables of both the maintenance group and the user group, and restricts access to data according to the settings of data disclosure for each device by the user group. This provides a framework that meets the requests of both groups to some extent, and can eliminate the need for coordination between the two groups or contribute to shortening the time required for coordination.
[0071] As shown in Fig. 8, if the use object 42 determines whether or not to disclose a combination of the device 21 and the attribute of the data, the needs of the use group can be met in more detail than the designation of a secret device as shown in Fig. 7. In the example of Fig. 8, the Web server unit 140 corresponds to an example of a receiving means that receives from the use object a setting as to whether or not access by an object other than the use object is permitted to data related to information transmitted from the device and having the attribute, for a combination of each device and the attribute of data related to information transmitted from the device. Also, the access control unit 120 corresponds to an example of an access control means that controls access by an object other than the use object in accordance with the setting received by the receiving means.
[0072] Furthermore, according to the data management device 10, attributes such as confidentiality and origin are assigned to data generated in the facility 20, and access can be controlled indirectly and securely within the scope of the role of each object 40 by defining the relationship between the attribute and the role. This access control is performed at the base level closest to the management unit 100, so that access control can be implemented in a unified manner regardless of the means of utilizing data such as a web screen, email, or API. Even in a system configuration in which multiple systems operate in cooperation with each other, as seen in recent years, data obtained by the data management system 1000 can be safely provided to surrounding external systems by controlling data access at the base level.
[0073] Embodiment 2 Next, the second embodiment will be described, focusing on the differences from the first embodiment. Note that the same or equivalent configurations as the first embodiment will be denoted by the same reference numerals. In the first embodiment, an example was described in which the use group specifies data to be kept secret by focusing on individual devices 21. However, there may be cases in which the use group specifies data to be kept secret by focusing on differences. Below, an example will be described in which the use group specifies data to be kept secret based on the time and area associated with the data, and the contents of the data.
[0074] As shown in FIG. 11, the Web server unit 140 of this embodiment sets data that is to be kept confidential from anyone other than the user group, and provides examples of such data, including data with a timestamp within a specified confidential period, data associated with a specified region, and data containing specified confidential information.
[0075] The data stored in the storage unit 110 may be associated with a time stamp indicating a time. This time may be the time when the information is transmitted from the device 21, the time when the data is stored in the storage unit 110, or other time. The use object 42 specifies the data to be kept secret among the data stored in the storage unit 110 by a time. In detail, the Web server unit 140 accepts the specification of a confidential period during which the data should be kept secret, and the access control unit 120 restricts the disclosure of the data with the time stamp within the specified confidential period to a group other than the use group. The management unit 100 corresponds to an example of a management means that associates data with a time and manages the data. The Web server unit 140 corresponds to an example of a reception means that accepts the specification of a confidential period including a time associated with the data to be kept secret from the use object. The access control unit 120 corresponds to an example of an access control means that restricts access from objects other than the use object to the data associated with a time within the confidential period.
[0076] In addition, the data stored in the storage unit 110 may be associated with a region. The region may be a region where the facility 20 is located, a manufacturing region of the device 21, a region where the headquarters of the maintenance group or the user group is located, or other regions. The region may be a country or a region similar to a country, a region divided by latitude and longitude, a region corresponding to a continent, or other regions. The use object 42 designates data to be kept secret among the data stored in the storage unit 110 by a region. In detail, the Web server unit 140 accepts the designation of a secret region where data should be kept secret, and the access control unit 120 restricts the disclosure of data associated with the designated secret region to a group other than the user group. The management unit 100 corresponds to an example of a management means for managing data by associating a region with the data. The Web server unit 140 corresponds to an example of a reception means for accepting, from the use object, the designation of a secret region that is a region associated with data to be kept secret. The access control unit 120 corresponds to an example of an access control means for restricting access to data associated with the secret region from objects other than the use object.
[0077] In addition, the data that the use object 42 wants to keep secret may include secret information for distinguishing it from other data. Here, the target to be kept secret may be the data or the secret information. For example, the secret information may be an identifier or a flag indicating the data to be kept secret. The use object 42 specifies the data to be kept secret among the data stored in the storage unit 110 by the secret information. In detail, the Web server unit 140 accepts the designation of the secret information, and the access control unit 120 restricts the disclosure of the data including the designated secret information to a group other than the use group. The Web server unit 140 corresponds to an example of a receiving means that accepts the designation of the secret information included in the data to be kept secret from the use object. The access control unit 120 corresponds to an example of an access control means that restricts the access from objects other than the use object to the data including the secret information.
[0078] As described above, if a user group can specify data that should be kept secret by focusing on time, region, and secret information, the detailed needs of the user group can be met.
[0079] In addition, the designation of data to be kept secret for each device 21 in embodiment 1 and the designation of data to be kept secret by time, area, and secret information in this embodiment may be combined in any manner, or only one of them may be adopted.
[0080] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments.
[0081] For example, although an example in which the object 40 corresponds to a user has been described, the present invention is not limited to this. The target of data provision by the data provision system 1000 may be a device to which a role is assigned, or an external system such as a customer management system or a parts management system.
[0082] In addition, when the maintenance object 41 registers a usage group, a table range that can be created by the usage object 42 in the access control table of the usage group is set, and within that range, each of the objects 40 in the two groups managed as a set may determine the contents within that table range.
[0083] Although an example has been described in which the maintenance object 41 mainly performs the work related to the access control of the usage group, if the maintenance group and the usage group are managed as a set by registering the usage group by the maintenance object 41, the usage object 42 may perform the work related to the access control. For example, the usage object 42 may edit a data model corresponding to the maintenance group, and the edited content may be reflected in the access control table 102 of the usage group. Furthermore, the authority to perform such editing may be granted to the role of the usage object 42 in the access control table 102.
[0084] Also, an example in which the maintenance group specifies the data model and designates the use group has been described, but this is not limiting. The maintenance group and the use group may be interchanged, or at least one of the maintenance group and the use group may be changed to another group. The maintenance group according to the above embodiment corresponds to an example of a first group, and the use group corresponds to an example of a second group different from the first group.
[0085] When the maintenance group and the use group are interchanged, the data model corresponding to the use group is applied when generating the access control table 102 corresponding to the maintenance group, so there is no need to create a data model for the maintenance group, reducing the workload. Also, when the data model of the use group is changed, there is no need to redesign the data model for the maintenance group, reducing the workload.
[0086] Furthermore, when the device 21 has the above-mentioned API function, the data providing system 1000 may be configured without the gateway device 22.
[0087] Furthermore, the roles are not limited to the above examples, and may be defined hierarchically.
[0088] Also, although an example has been described in which the data management device 10 receives the designation of data to be kept secret from the usage object 42, the usage object 42 may set a parameter designating data to be kept secret in the device 21, and the data management device 10 may receive the parameter from the device 21. When this parameter is received, the first communication unit 130 corresponds to an example of a receiving means for receiving the designation of data to be kept secret.
[0089] Although an example has been described in which data related to information transmitted from the device 21 and the business data shown in Fig. 5 are subject to access control, other data may be subject to access control. Fig. 12 shows that the access control unit 120 controls access to the access-controlled data in the storage unit 110 based on the access control table 102 and the using group side setting data 105d. The using group side setting data 105d is information specifying data that should be kept secret by the using group, and corresponds to the setting data 105 in Fig. 7 and the setting data 105c in Fig. 11, for example. Fig. 12 shows device data 111 based on information transmitted from the device 21, a data model DB 101, and role data 104 as the access-controlled data. That is, the data model and role data 104 may be subject to access control.
[0090] Furthermore, although the management unit 100 and the storage unit 110 have been described as separate components, the management unit 100 may include the storage unit 110, or the management unit 100 and the storage unit 110 may be configured as an integrated unit.
[0091] Also, an example has been described in which data transmitted from device 21 is provided directly to object 40. In this example, device 21 is the data source in data providing system 1000. However, the present invention is not limited to this example, and device 21 may obtain data from another device that does not have a function of communicating with gateway device 22 and transmit the data to gateway device 22.
[0092] The functions of the data management device 10 according to the above-described embodiment can be realized by dedicated hardware or by a general computer system.
[0093] For example, the program P1 can be stored and distributed on a computer-readable recording medium such as a flexible disk, a CD-ROM (Compact Disk Read-Only Memory), a DVD (Digital Versatile Disk), or an MO (Magneto-Optical disk), and the program P1 can be installed on a computer to configure an apparatus that executes the above-mentioned processing.
[0094] Also, the program P1 may be stored in a disk device of a server device on a communication network such as the Internet, and may be downloaded to a computer, for example, by being superimposed on a carrier wave.
[0095] The above-mentioned processing can also be achieved by starting and executing the program P1 while transferring it via a network such as the Internet.
[0096] Furthermore, the above-mentioned processing can also be achieved by executing all or part of the program P1 on a server device, and executing the program P1 while the computer transmits and receives information related to the processing via a communications network.
[0097] In addition, when the above-mentioned functions are shared and realized by the OS (Operating System) or by the OS working together with an application, only the parts other than the OS may be stored on a medium and distributed, or may be downloaded to a computer.
[0098] Furthermore, the means for realizing the functions of the data management device 10 is not limited to software, and some or all of the functions may be realized by dedicated hardware or circuits.
[0099] Various embodiments and modifications of the present disclosure are possible without departing from the broad spirit and scope of the present disclosure. The above-described embodiments are for explaining the present disclosure and do not limit the scope of the present disclosure. In other words, the scope of the present disclosure is indicated by the claims, not the embodiments. Various modifications made within the scope of the claims and within the scope of the disclosure equivalent thereto are considered to be within the scope of the present disclosure. [Industrial Applicability]
[0100] The present disclosure is suitable for controlling access via a network to data generated in a facility. [Explanation of symbols]
[0101] 10 data management device, 20 facility, 21 device, 22 gateway device, 30 terminal, 40 object, 41 maintenance object, 42 usage object, 51 operation status data, 52 alarm data, 61 processor, 62 main memory unit, 63 auxiliary memory unit, 64 input unit, 65 output unit, 66 communication unit, 67 internal bus, 100 management unit, 101 data model DB, 102 access control table, 104 role data, 105, 105a, 105b, 105c setting data, 105d usage group side setting data, 110 memory unit, 111 device data, 120 access control unit, 130 first communication unit, 140 Web server unit, 150 second communication unit, 221 operation status API, 222 alarm API, 1000 data providing system, NW network, P1 program.
Claims
1. A data management device that receives device information from devices installed in a facility, manages data related to the device information, and provides the data to objects via a network, a management means for storing and managing a table indicating whether or not the object to which the role is assigned is permitted to access the data having the attribute, for a combination of a role assigned to each of the plurality of objects belonging to one group and an attribute of the data defined by a data model predetermined for the one group; and an access control means for controlling access from the object to the data based on the table corresponding to the group to which the object belongs; a receiving means for receiving registration of a second group different from the first group by the object belonging to the first group; Equipped with the management means applies the data model corresponding to the first group as the data model for configuring the table corresponding to the second group. Data management device.
2. the management means manages the first group and the second group as one set. The data management device according to claim 1 .
3. the accepting unit accepts registration of the second group as a target for providing maintenance service for the device by the object belonging to the first group; The data management device according to claim 1 .
4. the management means generates the table indicating whether or not the object to which the role is assigned is permitted to access the data having the attribute for a combination of the role assigned to each of the plurality of objects belonging to the second group and the attribute of the data defined by the data model for configuring the table corresponding to the first group; The data management device according to claim 1 .
5. when the data model for configuring the table corresponding to the first group is changed by the object belonging to the first group, the management means updates the table by applying the changed data model to the table corresponding to the second group. The data management device according to claim 1 .
6. a data management device that receives the device information from a plurality of the devices installed in the facility, the receiving means receives, from the object belonging to the second group or from the secret device itself, a designation of a secret device that transmits the device information that should be kept secret, among the plurality of devices; the access control means restricts access to the data relating to the device information transmitted from the secret device from the objects other than the objects belonging to the second group. The data management device according to claim 1 .
7. a data management device that receives the device information from a plurality of the devices installed in the facility, the receiving means receives, for each of the devices and the attribute of the data related to the device information transmitted from the device, a setting as to whether or not the data related to the device information transmitted from the device and having the attribute is permitted to be accessed by the objects other than the object belonging to the second group, from the device or from the object belonging to the second group; the access control means controls access by the objects other than the objects belonging to the second group in accordance with the setting accepted by the acceptance means. The data management device according to claim 1 .
8. The management means manages the data by associating it with a time, the receiving means receives, from the object belonging to the second group or from the device, a designation of a confidentiality period including a time associated with the data to be kept confidential; the access control means restricts access to the data associated with a time within the confidentiality period from the objects other than the objects belonging to the second group. The data management device according to claim 1 .
9. the management means manages the data by associating it with a region; the receiving means receives, from the object belonging to the second group or from the device, a designation of a secret area that is an area associated with the data that should be kept secret; the access control means restricts access to the data associated with the secret area from the objects other than the objects belonging to the second group. The data management device according to claim 1 .
10. the receiving means receives, from the object belonging to the second group or from the device, designation of secret information included in the data that should be kept secret; the access control means restricts access to the data including the confidential information from the objects other than the objects belonging to the second group. The data management device according to claim 1 .
11. Equipment installed in the facility; a data management device according to claim 1 , which receives device information from the device and manages data relating to the device information; a terminal that receives the data from the data management device via a network; A data provision system including:
12. 1. A data management method executed by a data management device that receives device information from devices installed in a facility, manages data related to the device information, and provides the data to an object via a network, comprising: a management means for storing and managing a table indicating whether or not the object to which the role is assigned is permitted to access the data having the attribute, for a combination of a role assigned to each of the plurality of objects belonging to one group and an attribute of the data defined by a data model predetermined for the one group; an access control means for controlling access from the object to the data based on the table corresponding to the group to which the object belongs; a receiving means for receiving registration of a second group different from the first group by the object belonging to the first group; the management means applies the data model corresponding to the first group as the data model for configuring the table corresponding to the second group. A data management method including:
13. a data management device that receives device information from devices installed in the facility, manages data related to the device information, and provides the data to objects via a network; a management means for storing and managing a table indicating whether or not the object to which the role is assigned is permitted to access the data having the attribute, for a combination of a role assigned to each of the plurality of objects belonging to one group and an attribute of the data defined by a data model predetermined for the one group; access control means for controlling access from the object to the data based on the table corresponding to the group to which the object belongs; a receiving means for receiving registration of a second group different from the first group by the object belonging to the first group; It functions as the management means applies the data model corresponding to the first group as the data model for configuring the table corresponding to the second group. program.