Data management device, data provision system, data management method, and program

The data management device addresses the challenge of managing access rights across multiple user groups in RBAC systems by using a common data model to streamline access control, thereby reducing processing loads and improving responsiveness.

WO2025115182A1PCT designated stage expired Publication Date: 2025-06-05MITSUBISHI ELECTRIC CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2023/042929
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

In Role-Based Access Control (RBAC) systems, managing access rights for users across various groups, such as facility administrators, device manufacturers, users, and system integrators, becomes cumbersome as the number of management targets increases, leading to a high processing load and decreased responsiveness.

Method used

A data management device that receives device information from facilities, manages related data, and provides access control based on a table indicating permitted access for combinations of roles and data attributes, allowing for efficient access control across multiple groups by applying a common data model.

Benefits of technology

This solution reduces the burden of preparatory work for controlling access to data generated in facilities by simplifying the management of access rights across diverse user groups, thereby improving responsiveness and reducing processing loads.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2023042929_05062025_PF_FP_ABST
    Figure JP2023042929_05062025_PF_FP_ABST
Patent Text Reader

Abstract

A data management device (10) comprises: a management unit (100) that stores and manages an access control table (102) that indicates whether or not access is permitted for a combination of a role assigned to each of a plurality of objects (41) belonging to a group and an attribute of data defined by a predetermined data model corresponding to the group; an access control unit (120) that controls access from the object (41) to the data on the basis of the access control table (102) corresponding to the group to which the object (41) belongs; and a Web server unit 140 that receives registration of a usage group by a maintenance object (41) belonging to a maintenance group. The management unit (100) applies a data model corresponding to the maintenance group as a data model for configuring the access control table (102) corresponding to the usage group.
Need to check novelty before this filing date? Find Prior Art

Description

Data management device, data providing system, data management method and program

[0001] The present disclosure relates to a data management device, a data providing system, a data management method, and a program.

[0002] Role-based access control (RBAC) is known, which controls user access to data within a system by assigning roles to users of the system and granting them access rights associated with the roles. When the number of managed objects, such as roles handled by RBAC, increases, the processing load increases and responsiveness to data access decreases. Therefore, a technology for reducing the processing load of RBAC has been proposed (see, for example, Patent Document 1).

[0003] Patent Literature 1 describes a device that determines access rights based on user list information in access control using extended roles. This device can reduce the processing load required to determine access rights when access to access-restricted content occurs.

[0004] JP 2010-117885 A

[0005] In RBAC, roles are typically assigned to users who belong to a group such as an organization, company, or group. The types of data that can be accessed are then determined for each role. This RBAC method is also used in the technology of Patent Document 1.

[0006] When RBAC is used to process data generated at a facility, such as a factory or facility, the facility administrator corresponds to the above-mentioned group. However, data generated at the facility may also be used by users belonging to groups other than the facility administrator, such as the group that produces (including sells) the equipment installed at the facility, the group that uses the equipment, or system integrators and maintenance companies. Furthermore, individual groups are not necessarily confined to the same company. The task of determining the types of data accessible to each role to be assigned to users belonging to such various groups can be extremely cumbersome for workers. Therefore, there is room for reducing the burden of preparation work required to control access to data generated at the facility.

[0007] The present disclosure has been made in light of the above-mentioned circumstances, and aims to reduce the burden of preparation work for controlling access to data generated in a facility.

[0008] In order to achieve the above-mentioned object, the data management device disclosed herein is a data management device that receives device information from devices installed in a facility, manages data related to the device information, and provides the data to objects via a network, and is equipped with: a management means that stores and manages a table that indicates, for a combination of a role assigned to each of a plurality of objects belonging to a group and a data attribute defined by a predetermined data model corresponding to a group, whether an object to which the role is assigned is permitted to access data having the attribute; an access control means that controls access from an object to the data based on the table corresponding to the group to which the object belongs; and a reception means that accepts registration of a second group different from the first group by an object belonging to the first group, and the management means applies the data model corresponding to the first group as a data model for constructing a table corresponding to the second group.

[0009] According to the present disclosure, it is possible to reduce the burden of preparation work for controlling access to data generated in a facility.

[0010] FIG. 1 shows the configuration of a data providing system according to the first embodiment. FIG. 2 shows the hardware configuration of a data management device according to the first embodiment. FIG. 3 shows the functional configuration of a data management device according to the first embodiment. FIG. 4 shows that two groups according to the first embodiment are managed as a set. FIG. 5 shows an example of a data model according to the first embodiment. FIG. 6 shows an example of specifying whether or not data is to be disclosed for each device according to the first embodiment. FIG. 7 shows an example of specifying whether or not data is to be disclosed for each device according to the first embodiment.

[0011] Hereinafter, a data providing system according to an embodiment of the present disclosure will be described in detail with reference to the drawings.

[0012] Embodiment 1 As shown in FIG. 1 , a data providing system 1000 according to this embodiment is a system in which data relating to information transmitted from a facility 20, such as a factory or a plant, is managed in a data management device 10 and provided to an object 40 via a network NW. The data providing system 1000 implements access control as a cloud service. Specifically, the data providing system 1000 provides data to users who have predetermined access rights and restricts the provision of data to users who do not have the access rights. A user is a target to which data is provided by the data providing system 1000, and hereinafter, a user will be referred to as an object 40. Note that an object is not limited to a user.

[0013] The data providing system 1000 includes a device 21 and a gateway device 22 installed in a facility 20, a data management device 10 that controls access, and a terminal 30 that is used by an object 40 that is a user.

[0014] The device 21 may be a control device such as a PLC (Programmable Logic Controller), a controlled device such as a sensor, actuator, robot, or machine tool, a UI (User Interface) device for an operator to set control contents, or another FA device constituting an FA system. The device 21 may be a transmitting device that transmits information.

[0015] The information transmitted by the device 21 may indicate, for example, sensing results, the operating status of the device 21, the occurrence of an abnormality, or the execution result of a predetermined program. The operating status of the device 21 may be, for example, a current value, a voltage value, a speed, an acceleration, an angular velocity, or an angular acceleration measured by the device 21, or may correspond to data stored in the memory of the device 21. The transmission of information by the device 21 may be performed periodically at a predetermined cycle, may be repeated aperiodically, or may be performed in response to the establishment of a predetermined trigger condition. Furthermore, the transmission of information by the device 21 may be performed autonomously by the device 21, may be performed in response to an operation by an operator on the device 21, or may be performed in response to a request from the data management device 10.

[0016] 1 illustrates, as examples of information transmitted from the device 21, operation status data 51 indicating the operation status of the device 21 and alarm data 52 indicating the occurrence of an abnormality in the device 21. Note that, although one device 21 is shown as a representative in FIG. 1, multiple devices 21 may be installed in the facility 20. The information transmitted by the device 21 corresponds to an example of device information transmitted from a device installed in the facility.

[0017] The gateway device 22 relays the transmission of information between the device 21 and the data management device 10 outside the facility 20. The gateway device 22 provides an API (Application Protocol Interface) function for uploading information from the device 21 to the data management device 10. FIG. 1 illustrates that the gateway device 22 has the functions of an operating status API 221 for uploading operating status data 51 and an alarm API 222 for uploading alarm data 52.

[0018] The data management device 10 is a server device on a network, such as the Internet. The data management device 10 receives and manages information uploaded via a gateway device 22. In the data management device 10, information transmitted from a device 21 is standardized by a data model called model g, resulting in a data group including operational status data 51 and alarm data 52. As shown in the data model DB 101 in FIG. 1 , model g is a data model corresponding to group G, and defines data attributes including operational status and alarms. Here, group G is a group to which multiple objects 40 belong, to which data related to the information transmitted from the device 21 is provided. The API function of the gateway device 22 is predefined as corresponding to model g and then implemented in the gateway device 22.

[0019] 1, for ease of understanding, the example shows that the information transmitted from the device 21 is provided to the object 40 as is via access control. However, this is not limited to this, and data resulting from processing the information transmitted from the device 21 by the gateway device 22 or the data management device 10 may be the target of access by the object 40. For example, data indicating the results of statistical processing performed on the information repeatedly transmitted from the device 21 may be provided to the object 40.

[0020] Data managed by the data management device 10 is provided appropriately to objects 40 belonging to group G under access control based on an access control table 102. This access control table 102 is a two-dimensional table in which a list of data attributes defined by model g corresponds to the vertical axis and a list of roles assigned to each object 40 in group G corresponds to the horizontal axis, and indicates, for each combination of attribute and role, whether or not an object 40 assigned that role is permitted to access data having the attribute. For example, in the access control table 102 in FIG. 1 , a check mark indicates that an object 40 assigned "role A" is permitted to access data having an "alarm" attribute. Also, "NO" indicates that an object 40 assigned "role B" is restricted from accessing data having an "operating status" attribute.

[0021] As described above, the list of data attributes constituting the access control table 102 is predetermined for each group G. For example, if there is a request in group G to access the operating status data 51 and the alarm data 52, the operating status data 51 and the alarm data 52 transmitted from the device 21 are added to the list. Here, if it is desired that access to the operating status data 51 and access to the alarm data 52 be based on different access permissions, the data attributes corresponding to the operating status data 51 and the data attributes corresponding to the alarm data 52 are each configured as different list elements. On the other hand, if there is no need to distinguish between the operating status data 51 and the alarm data 52, the data attributes including both the operating status data 51 and the alarm data 52 can be configured as a single list element. In this way, the list of data attributes corresponds to how data is handled in the group. Therefore, when controlling access by objects 40 belonging to different groups, the list of data attributes constituting the access control table 102 can differ depending on the group.

[0022] Therefore, the data model DB 101 manages data models that define the attributes of data in association with groups.

[0023] 1 shows one device 21, and typically, an organization, company, or group that maintains the device 21 after it is operational corresponds to group G. When the data management device 10 collects information from multiple devices 21 maintained by different groups, access by objects 40 belonging to each group is controlled based on the data model corresponding to each group.

[0024] The data management device 10 controls access to data via the network NW based on the access control table 102 to which the accessed object 40 belongs. For example, in the example of FIG. 1 , if role A is assigned to an object 40 belonging to group G, the data management device 10 permits the object 40 to access alarm data 52 and provides the alarm data 52 to the object 40. Furthermore, if role B is assigned to an object 40 belonging to group G, the data management device 10 restricts the object 40 from accessing operating status data 51 and does not provide the operating status data 51 to the object 40. Note that providing data to an object 40 means transmitting the data to the terminal 30 used by the object 40.

[0025] The terminal 30 is a UI device that allows a user as an object 40 to refer to data, and is, for example, an industrial personal computer (PC), a tablet terminal, or a smartphone. The terminal 30 may display a dashboard on a web browser, and display data provided from the data management device 10 on the dashboard using a card model UI. In the example of FIG. 1 , the terminal 30 and the object 40 are located outside the facility 20, but the terminal 30 and the object 40 may also be located inside the facility 20.

[0026] Next, the data management device 10 that executes access control will be described in more detail. The data management device 10 is configured with hardware elements that function as a computer that receives device information, manages data related to the device information, and provides the data to objects via a network. In detail, as shown in Figure 2, the data management device 10 has a processor 61, a main memory unit 62, an auxiliary memory unit 63, an input unit 64, an output unit 65, and a communication unit 66. The main memory unit 62, the auxiliary memory unit 63, the input unit 64, the output unit 65, and the communication unit 66 are all connected to the processor 61 via an internal bus 67.

[0027] The processor 61 includes a CPU (Central Processing Unit) as a processing circuit. The processor 61 executes a program P1 stored in the auxiliary storage unit 63 to realize various functions and execute the processes described below.

[0028] The main memory 62 includes a RAM (Random Access Memory). The program P1 is loaded into the main memory 62 from the auxiliary memory 63. The main memory 62 is used as a working area for the processor 61.

[0029] The auxiliary storage unit 63 includes a non-volatile memory such as an EEPROM (Electrically Erasable Programmable Read-Only Memory) and an HDD (Hard Disk Drive). In addition to the program P1, the auxiliary storage unit 63 stores various data used in the processing of the processor 61. The auxiliary storage unit 63 supplies the processor 61 with data used by the processor 61 in accordance with instructions from the processor 61. The auxiliary storage unit 63 also stores data supplied from the processor 61.

[0030] The input unit 64 includes input devices such as a hardware switch, an input key, a keyboard, and a pointing device. The input unit 64 acquires information input by a user of the data management device 10 and notifies the processor 61 of the acquired information.

[0031] The output unit 65 includes output devices such as a light emitting diode (LED), a liquid crystal display (LCD), and a speaker, and presents various information to the user in accordance with instructions from the processor 61.

[0032] The communication unit 66 includes a communication interface circuit for communicating with an external device. The communication unit 66 receives a signal from the outside and outputs data indicated by this signal to the processor 61. The communication unit 66 also transmits a signal indicating the data output from the processor 61 to the external device. Note that while one communication unit 66 is representatively shown in FIG. 2 , the data management device 10 may have multiple communication units 66. For example, a communication unit 66 for communicating with the gateway device 22 of the facility 20 and a communication unit 66 for communicating with the terminal 30 via the network NW may be provided separately.

[0033] The above-described hardware configurations work together to enable the data management device 10 to perform various functions. In detail, as shown in Fig. 3, the data management device 10 has, as its functions, a memory unit 110 that stores received information, an access control unit 120 that executes access control for the information stored in the memory unit 110, a management unit 100 that manages tables for executing access control, a first communication unit 130 that communicates with the facility 20, a Web server unit 140 that provides data to the object 40, and a second communication unit 150 that communicates with the object 40 via the network NW. The first communication unit 130 and the second communication unit 150 are each realized by a communication unit 66.

[0034] The management unit 100 is mainly realized by the processor 61. The management unit 100 has an access control table 102 that defines details of access control, and a data model DB 101 that associates data models for configuring the access control table 102 with groups. In the access control table 102 shown in FIG. 3 , common data attributes are used for two groups, a maintenance group and a user group. Here, the maintenance group is a group responsible for the maintenance work of maintaining the devices 21 that configure the FA system of the facility 20, and the maintenance object 41 is an object 40 corresponding to a worker belonging to the maintenance group. The user group is a group responsible for the work of operating the FA system using the devices 21, and the user object 42 is an object 40 corresponding to a worker belonging to the user group. Hereinafter, the maintenance object 41 and the user object 42 may be collectively referred to as the object 40. The FA system is a system constructed using devices 21 in a facility, such as a production system that controls a large number of devices 21 to process a large number of workpieces to produce products.

[0035] As described above, the access control content by the object 40 corresponds to the group to which the object 40 belongs, typically the maintenance group that maintains the device 21. However, it may be desirable for data generated in an FA system to be used by multiple groups, not just the maintenance company of the device 21, such as the operator of the FA system including the device 21, the manufacturer of the device 21, the manufacturer of a set of devices including the device 21, and a system integrator that delivers software to the FA system. For example, if an abnormality occurs in the device 21 during operation of the FA system, the user group, which is the operator of the FA system, may request the maintenance group to repair or replace the device 21. In such a case, if the data of the device 21 can be accessed by the objects 40 of both the maintenance group and the user group, the malfunction can be expected to be resolved quickly. Note that, although an example in which the maintenance group is solely responsible for maintenance work has been described, this is not limited to this. The user group may also make its own maintenance plan and perform maintenance work, including repair and replacement.

[0036] Since the tasks performed by the multiple groups are different, different roles are assigned to the objects 40 belonging to each group. However, if different data models for configuring the access control table 102 are to be determined for each group, the determination process can become complicated. Therefore, if a common data model is used for these groups, the process of determining the data model can be consolidated into one process, reducing the workload.

[0037] Specifically, the management unit 100 applies the model g1 corresponding to the maintenance group as a data model for constructing a table corresponding to the usage group. That is, the management unit 100 adopts the model g1 corresponding to the maintenance group in the data model DB 101 as the data model corresponding to the usage group. The data model for constructing the access control table for the maintenance group and the data model for constructing the access control table for the usage group are associated as identical data models, and this association is maintained.

[0038] Furthermore, when managing multiple groups including a maintenance group and a usage group, the management unit 100 manages the maintenance group and the usage group as a set, as shown in Fig. 4. In detail, the management unit 100 manages information indicating combinations in which the maintenance group and the usage group are associated with each other, and the data model of the access control table is made common for the combinations indicated by the information.

[0039] 5 shows an example of a model g1 corresponding to a maintenance group. As shown in FIG. 5, the data model hierarchically defines data attributes and is written in, for example, XML (Extensible Markup Language) format. The model g1 has three categories: business data related to the business of the maintenance group, event data related to events that occur in the device 21, and file data representing files provided by the device 21. The event data and file data are collected from the device 21 via the event APIs and file APIs of the gateway device 22, respectively.

[0040] The business data includes data on customer information management for managing customers of the maintenance contractor, which is the maintenance group, maintenance user management for managing the maintenance objects 41, user management for managing the use objects 42, and other items. The event data includes data on operation status, alarms, and other items. The file data includes five levels of confidential information, from confidentiality level 1 information to confidentiality level 5 information, and information exclusive to the maintenance group.

[0041] With the three categories of business data, event data, and file data defined, templates for the event API and file API are provided to the maintenance group by the data management device 10 or by the provider of the cloud service provided by the data management device 10. Then, the maintenance object 41, which is the administrator of the maintenance group, creates details of each item belonging to the three categories and APIs corresponding to each item.

[0042] Note that there does not have to be a one-to-one correspondence between the API and the items in the data model. For example, as illustrated in the file data of Fig. 5, file data uploaded via the standard time series file API and the general device file API may be classified into six types of file data according to the ID included in the data.

[0043] Furthermore, the business data is stored in advance in the data management device 10 by the maintenance object 41 without being collected from the facility 20 .

[0044] Furthermore, roles for the maintenance group and the use group may be defined by the maintenance object 41. If the maintenance group is the manufacturer of the device 21, flexible role-based access control becomes possible for event data and files that the manufacturer independently causes to be transmitted to the device 21.

[0045] The management unit 100 corresponds to an example of a management means that stores and manages a table indicating whether or not an object assigned a role is permitted to access data having a combination of a role assigned to each of multiple objects belonging to a group and a data attribute defined by a predetermined data model corresponding to the group.

[0046] Returning to Fig. 3, the storage unit 110 is mainly realized by at least one of the main storage unit 62 and the auxiliary storage unit 63. Information transmitted from the device 21 is stored in the storage unit 110 as data to be accessed by the object 40. However, the data transmitted from the device 21 is not directly accessed by the object 40; the object 40 indirectly accesses the data because the role assigned to the object 40 is permitted to access the data in the access control table 102. In other words, as shown in Fig. 3, an access control unit 120 is interposed between the storage unit 110 and the object 40.

[0047] The access control unit 120 is mainly realized by the processor 61. The access control unit 120 controls access by the maintenance object 41 and the usage object 42 via the web server unit 140 and the second communication unit 150. The access control by the access control unit 120 is based on the access control table 102 and the assignment of roles to each object 40.

[0048] Fig. 6 illustrates information that defines the details of access control by the access control unit 120. In detail, the upper side of Fig. 6 illustrates an access control table 102 configured using the data model of Fig. 5, and the lower side illustrates role data 104 that indicates roles assigned to the maintenance object 41 and the usage object 42, respectively.

[0049] 6, the role data 104 is table-format information in which the vertical axis corresponds to a list of objects and the horizontal axis corresponds to a list of roles identical to those in the access control table 102. For example, the role data 104 indicates that a maintenance object "object 41a" is assigned the role "SYSTEM_ADMIN" of the maintenance group. Therefore, "object 41a" can access "Level 1 information," for which a check mark is placed in the combination with "SYSTEM_ADMIN" in the access control table 102. Furthermore, it can be seen that a use object "object 42b" is assigned the roles "XXX" and "YYY" of the use group. However, because neither "XXX" nor "YYY" is placed in the combination with "Level 1 information" in the access control table 102, "object 42b" cannot access "Level 1 information." The access control unit 120 corresponds to an example of an access control unit that controls access from an object to data based on a table corresponding to the group to which the object belongs.

[0050] Returning to FIG. 3 , the Web server unit 140 is primarily realized by the processor 61. The Web server unit 140 provides a management screen, which is displayed for the maintenance object 41 and the usage object 42, via the second communication unit. This management screen accepts the designation of a usage group by the maintenance object 41. Specifically, the Web server unit 140 accepts the registration of a usage group as a target for providing maintenance services for the device 21 by the maintenance object 41. By designating a usage group by the maintenance object 41 in this manner, as shown in FIG. 3 , a data model corresponding to the maintenance group is applied to constitute the access control table for the usage group. In addition, the Web server unit 140 accepts registration of business data, including the manual for the device 21 and information on consumables, from the maintenance object 41. The Web server unit 140 corresponds to an example of a receiving means for accepting registration of a usage group by an object belonging to the maintenance group.

[0051] The Web server unit 140 also receives from the use object 42 the designation of a secret device that transmits information that should be kept secret, among the multiple devices 21 used in the use group. Data relating to the information transmitted from the secret device is kept secret from groups other than the use group, and access to the data from the maintenance object 41 is restricted. This access restriction is executed by the access control unit 120, separately and independently from the access control by the access control table 102.

[0052] 7 shows an example in which the use object 42 specifies a secret device. In the example of FIG. 7, the fact that device E1 of devices E1 and E2, which are devices 21, is designated as a secret device is indicated as "NG" in the setting data 105. For this reason, for example, although the access control table 102 specifies that object 41a of the maintenance group has the authority to access data indicating the operating status of device 21, it cannot access data indicating the operating status of device E1.

[0053] As described above, the access control table 102, which defines the details of access control, is set by the maintenance group. However, there are cases where the user group wants to keep information about some of the devices 21 they use secret from the outside. Therefore, the Web server unit 140 accepts the designation of a secret device from the use object 42, and the access control unit 120 restricts access from objects belonging to groups other than the use group to data related to the information transmitted from the secret device. A data masking function that enables the user group to designate whether to disclose or not disclose data is provided to the user group by the data management device 10.

[0054] Instead of specifying a secret device as shown in Fig. 7, the Web server unit 140 may receive from the use object 42 a specification of whether or not to disclose data to parties other than the use group for each combination of the device 21 and the attributes defined by the data model, as shown in Fig. 8. In the example of Fig. 8, the non-disclosure of alarm data for "device E1" to parties other than the use group is indicated as "NG" in the setting data 105a. For this reason, for example, the object 41a of the maintenance group is specified in the access control table 102 as having the authority to access the alarm data of the device 21, but cannot access the alarm data of the device E1. Also, in the setting data 105a of Fig. 8, items for which the object 42 of the use group cannot set whether or not to disclose data are hatched.

[0055] 7 and the setting data 105a shown in Fig. 8 may be used together. For example, as shown in Fig. 9, for a device 21 that is not designated as a secret device, whether or not to disclose data may be designated for each attribute of the data.

[0056] Returning to FIG. 3, the second communication unit 150 corresponds to a communication interface with a web application used by the terminal 30 and an external system via the network NW, and provides an API to an external device.

[0057] Next, the data management process executed by the data management device 10 having the above-described functions will be described with reference to Fig. 10. The data management process shown in Fig. 10 starts when the data management device 10 is powered on.

[0058] In the data management process, the Web server unit 140 receives settings for the maintenance object 41, roles, and data models of the maintenance group from the maintenance object 41, who is the administrator of the maintenance group (step S1). Then, the management unit 100 generates an access control table 102 for the maintenance group based on the information received in step S1 (step S2). The contents of the access control table, i.e., whether or not access is permitted for each combination of each role and each attribute of data, may be set by the maintenance object 41 in step S1, or a predetermined initial value may be applied.

[0059] Next, the Web server unit 140 accepts the registration of the usage group by the maintenance object 41 and accepts settings related to the usage objects 42 and roles of this usage group (step S3). As a result, information related to the usage group is set in the role data 104 shown in FIG. 6, for example.

[0060] Next, the management unit 100 generates the access control table 102 by applying the data model of the maintenance group as the data model constituting the access control table 102 of the usage group (step S4). The contents of this table, i.e., whether or not access is permitted for each combination of each role and each attribute of data, may be set by the maintenance object 41 in step S3, may be set by the usage object 42 when generating the table, or a predetermined initial value may be applied. The management unit 100 corresponds to an example of a management means that generates an access control table that indicates, for a combination of a role assigned to each of multiple objects belonging to the usage group and a data attribute defined by the data model for constituting the access control table corresponding to the maintenance group, whether or not an object assigned the role is permitted to access data having the attribute.

[0061] Next, the Web server unit 140 receives a setting as to whether or not to disclose data to other groups from the use object 42 (step S5). Specifically, the Web server unit 140 receives the contents of the setting data 105 in Fig. 7, the setting data 105a in Fig. 8, or the setting data 105b in Fig. 9.

[0062] Then, the access control unit 120 controls access from the maintenance object 41 or the use object 42 in accordance with the access control table 102 for each group generated in steps S2 and S4, and the disclosure settings by the use group accepted in step S5 (step S6).

[0063] Next, the management unit 100 determines whether the maintenance group has changed the data model corresponding to the maintenance group (step S7). The change in the data model is, for example, an increase or decrease in any of the items of business data, event data, and file data shown in FIG.

[0064] If it is determined that the data model has not been changed (step S7; No), the data management device 10 repeats the processing from step S6 onwards. On the other hand, if it is determined that the data model has been changed (step S7; Yes), the management unit 100 applies the data model of the maintenance group as the data model constituting the access control table 102 of the use group, and updates the access control tables 102 of both the maintenance group and the use group (step S8). When the data model constituting the access control table corresponding to the maintenance group is changed by an object belonging to the maintenance group, the management unit 100 corresponds to an example of a management means that updates the table by applying the changed data model to the access control table corresponding to the use group. Then, the processing from step S6 onwards is repeated.

[0065] As described above, the Web server unit 140 accepts the registration of a usage group by the maintenance object 41, and the management unit 100 applies the data model corresponding to the maintenance group as the data model for constructing the access control table 102 corresponding to the usage group. This makes the data model common to the maintenance group and the usage group, eliminating the need to recreate the data model after registering the usage group. This reduces the burden of preparation work required to control access to data that occurs in the facility.

[0066] In detail, the management unit 100 manages the maintenance group and the usage group as one set, and generates the access control table 102 for each group using a data model common to the groups that make up this set. This eliminates the need to create a data model when generating the access control table 102 corresponding to the usage group, thereby reducing the workload.

[0067] Furthermore, when the data model is changed, the management unit 100 applies the change to the access control table 102 corresponding to the usage group, and updates the access control table 102. This eliminates the need to redesign the data model of the usage group when the data model of the maintenance group is changed, thereby reducing the workload.

[0068] The data management device 10 also provides a data masking function that is set by the user group. Specifically, the Web server unit 140 accepts, from the user object 42, the designation of a secret device that transmits information that should be kept secret, and the access control unit 120 restricts access from objects belonging to groups other than the user group to data related to the information transmitted from the secret device. This allows the maintenance group to define the data model while the user group can designate the secret device.

[0069] With regard to data related to the device 21, both the maintenance group, which is the manufacturer of the device 21, and the user group, which actually uses the device 21, may wish to handle the data freely, and coordination between the two groups may be necessary. However, such coordination takes time and does not necessarily lead to a reasonable conclusion. Here, in normal maintenance work, the maintenance group often places emphasis on the type of data handled by multiple devices 21, without distinguishing between individual devices 21. On the other hand, the user group may wish to keep information about some of the devices 21 installed in the facility 20 confidential, but tends to place less emphasis on the type of data than the maintenance group.

[0070] In response to these requests from both groups, the data management device 10 according to this embodiment adopts the data model determined by the maintenance group in the access control tables of both the maintenance group and the user group, and restricts access to data according to the data disclosure settings for each device set by the user group. This provides a framework that satisfies the requests of both groups to some extent, eliminating the need for coordination between the two groups or contributing to reducing the time required for coordination.

[0071] As shown in Figure 8, if the use object 42 determines whether or not to disclose a combination of device 21 and data attribute, the needs of the use group can be met in more detail than by specifying a secret device as shown in Figure 7. In the example of Figure 8, the Web server unit 140 corresponds to an example of a receiving means that receives from the use object a setting regarding whether or not access by objects other than the use object is permitted to data related to information transmitted from the device and having the attribute, for each combination of device and data attribute related to information transmitted from the device. Furthermore, the access control unit 120 corresponds to an example of an access control means that controls access by objects other than the use object in accordance with the setting received by the receiving means.

[0072] Furthermore, the data management device 10 assigns attributes such as confidentiality and origin to data generated in the facility 20, and by defining the relationship between the attributes and roles, secure access control can be indirectly performed within the scope of the role of each object 40. This access control is performed at the base level closest to the management unit 100, allowing for unified access control regardless of the means of utilizing data, such as web screens, email, or APIs. Even in recent system configurations in which multiple systems operate in conjunction with each other, controlling data access at the base level allows data obtained by the data management system 1000 to be safely provided to surrounding external systems.

[0073] Second Embodiment Next, a second embodiment will be described, focusing on the differences from the first embodiment described above. Note that the same or equivalent components as those in the first embodiment will be designated by the same reference numerals. In the first embodiment described above, an example was described in which a user group specifies data to be kept secret by focusing on individual devices 21. However, there may be cases in which a user group specifies data to be kept secret by focusing on differences. Below, an example will be described in which a user group specifies data to be kept secret based on the time and region associated with the data, and the content of the data.

[0074] As shown in FIG. 11, the Web server unit 140 according to this embodiment sets data that is not to be disclosed to anyone other than the user group, and examples of such data include data with a timestamp within a specified confidential period, data associated with a specified region, and data containing specified confidential information.

[0075] A timestamp indicating a time may be associated with data stored in the storage unit 110. This time may be the time when information is transmitted from the device 21, the time when the data is stored in the storage unit 110, or some other time. The usage object 42 specifies data stored in the storage unit 110 that should be kept secret by time. Specifically, the Web server unit 140 accepts a designation of a confidentiality period during which the data should be kept secret, and the access control unit 120 restricts disclosure of data with a timestamp within the designated confidentiality period to anyone other than the user group. The management unit 100 corresponds to an example of a management means that associates a time with data and manages it. The Web server unit 140 corresponds to an example of a receiving means that accepts, from the usage object, a designation of a confidentiality period including a time associated with data that should be kept confidential. The access control unit 120 corresponds to an example of an access control means that restricts access from objects other than the usage object to data associated with a time within the confidentiality period.

[0076] The data stored in the memory unit 110 may be associated with a region. This region may be the region where the facility 20 is located, the manufacturing region of the device 21, the region where the headquarters of a maintenance group or a user group is located, or another region. The region may also be a country or a region similar to a country, a region divided by latitude and longitude, a region corresponding to a continent, or another region. The usage object 42 specifies, by region, data to be kept secret among the data stored in the memory unit 110. In detail, the web server unit 140 accepts the designation of a secret region where data should be kept secret, and the access control unit 120 restricts disclosure of data associated with the designated secret region to parties other than the user group. The management unit 100 corresponds to an example of a management means for associating data with a region and managing it. The web server unit 140 corresponds to an example of a receiving means for accepting, from the usage object, the designation of a secret region, which is a region associated with data to be kept secret. The access control unit 120 corresponds to an example of an access control means that restricts access to data associated with the secret area from objects other than the use object.

[0077] Furthermore, data that the use object 42 desires to keep secret may include secret information for distinguishing it from other data. Here, the object to be kept secret may be the data itself or the secret information. For example, the secret information may be an identifier or a flag indicating the data to be kept secret. The use object 42 designates data stored in the storage unit 110 that it desires to keep secret using the secret information. Specifically, the web server unit 140 accepts the designation of the secret information, and the access control unit 120 restricts disclosure of data containing the designated secret information to parties other than the use group. The web server unit 140 corresponds to an example of a receiving means that accepts, from the use object, the designation of the secret information included in the data to be kept secret. The access control unit 120 corresponds to an example of an access control means that restricts access to data containing secret information from objects other than the use object.

[0078] As described above, if a user group can specify data that should be kept secret by focusing on time, region, and confidential information, the detailed needs of the user group can be met.

[0079] In addition, the designation of data to be kept secret for each device 21 in embodiment 1 and the designation of data to be kept secret using time, region, and secret information in this embodiment may be combined in any manner, or only one of them may be adopted.

[0080] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the above-described embodiments.

[0081] For example, although an example in which the object 40 corresponds to a user has been described, the present invention is not limited to this. The data providing system 1000 may provide data to a device to which a role is assigned, or to an external system such as a customer management system or a parts management system.

[0082] Furthermore, when the maintenance object 41 registers a usage group, it may set a table range that can be created by the usage object 42 in the access control table of the usage group, and within that range, each of the objects 40 in the two groups managed as a set may determine the contents within that table range.

[0083] Although an example has been described in which the maintenance object 41 mainly performs work related to access control for the usage group, if the maintenance object 41 registers the usage group and the maintenance group and the usage group are managed as a set, the usage object 42 may perform work related to access control. For example, the usage object 42 may edit a data model corresponding to the maintenance group, and the edited content may be reflected in the access control table 102 for the usage group. Furthermore, the authority to perform such editing may be granted to the role of the usage object 42 in the access control table 102.

[0084] Although the example in which the maintenance group defines the data model and specifies the usage group has been described, this is not limiting. The maintenance group and the usage group may be interchanged, or at least one of the maintenance group and the usage group may be changed to another group. The maintenance group in the above embodiment corresponds to an example of a first group, and the usage group corresponds to an example of a second group different from the first group.

[0085] When the maintenance group and the use group are interchanged, the data model corresponding to the use group is applied when generating the access control table 102 corresponding to the maintenance group, eliminating the need to create a data model for the maintenance group and reducing the workload. Also, when the data model of the use group is changed, eliminating the need to redesign the data model for the maintenance group and reducing the workload.

[0086] Furthermore, if the device 21 has the above-mentioned API function, the data providing system 1000 may be configured without the gateway device 22 .

[0087] Furthermore, the roles are not limited to the above examples, and may be defined hierarchically.

[0088] Although the example in which the data management device 10 receives the designation of data to be kept secret from the usage object 42 has been described, the usage object 42 may set a parameter designating the data to be kept secret in the device 21, and the data management device 10 may receive the parameter from the device 21. When this parameter is received, the first communication unit 130 corresponds to an example of a receiving means for receiving the designation of data to be kept secret.

[0089] Although the example in which data related to information transmitted from the device 21 and the business data shown in FIG. 5 are subject to access control has been described, other data may also be subject to access control. FIG. 12 shows that the access control unit 120 controls access to the access-controlled data in the storage unit 110 based on the access control table 102 and the user group setting data 105d. The user group setting data 105d is information specifying data that should be kept secret by the user group, and corresponds to, for example, the setting data 105 in FIG. 7 and the setting data 105c in FIG. 11. FIG. 12 also shows, as access-controlled data, device data 111 based on information transmitted from the device 21, the data model DB 101, and role data 104. In other words, the data model and role data 104 may be subject to access control.

[0090] Furthermore, although the management unit 100 and the memory unit 110 have been described as separate components, the management unit 100 may include the memory unit 110, or the management unit 100 and the memory unit 110 may be configured as an integrated unit.

[0091] Also, an example has been described in which data transmitted from device 21 is provided as is to object 40. In this example, device 21 is the source of data in data providing system 1000. However, the present invention is not limited to this example, and device 21 may obtain data from another device that does not have the function of communicating with gateway device 22 and transmit the data to gateway device 22.

[0092] The functions of the data management device 10 according to the above-described embodiment can be realized by dedicated hardware or by a general computer system.

[0093] For example, by storing and distributing program P1 on a computer-readable recording medium such as a flexible disk, a CD-ROM (Compact Disk Read-Only Memory), a DVD (Digital Versatile Disk), or an MO (Magneto-Optical disk), and installing program P1 on a computer, a device that executes the above-mentioned processing can be configured.

[0094] Furthermore, the program P1 may be stored in a disk device of a server device on a communication network such as the Internet, and may be downloaded to a computer by superimposing it on a carrier wave, for example.

[0095] The above process can also be achieved by starting and executing the program P1 while transferring it via a network such as the Internet.

[0096] Furthermore, the above-described processing can also be achieved by executing all or part of program P1 on a server device, and executing program P1 while the computer sends and receives information about the processing via a communications network.

[0097] In addition, when the above-mentioned functions are realized by an operating system (OS) or by the OS working together with an application, only the parts other than the OS may be stored on a medium and distributed, or may be downloaded to a computer.

[0098] Furthermore, the means for realizing the functions of the data management device 10 is not limited to software, and some or all of the functions may be realized by dedicated hardware or circuits.

[0099] The present disclosure allows various embodiments and modifications without departing from the broad spirit and scope of the present disclosure. Furthermore, the above-described embodiments are intended to explain the present disclosure and do not limit the scope of the present disclosure. In other words, the scope of the present disclosure is defined by the claims, not the embodiments. Various modifications made within the scope of the claims and the meaning of equivalent disclosures are considered to be within the scope of the present disclosure.

[0100] The present disclosure is suitable for controlling access via a network to data generated in a facility.

[0101] 10 Data management device, 20 Facility, 21 Device, 22 Gateway device, 30 Terminal, 40 Object, 41 Maintenance object, 42 Usage object, 51 Operation status data, 52 Alarm data, 61 Processor, 62 Main memory unit, 63 Auxiliary memory unit, 64 Input unit, 65 Output unit, 66 Communication unit, 67 Internal bus, 100 Management unit, 101 Data model DB, 102 Access control table, 104 Role data, 105, 105a, 105b, 105c Setting data, 105d Usage group side setting data, 110 Memory unit, 111 Device data, 120 Access control unit, 130 First communication unit, 140 Web server unit, 150 Second communication unit, 221 Operation status API, 222 Alarm API, 1000 Data providing system, NW Network, P1 Program.

Claims

1. A data management device that receives device information from a device installed in a facility, manages data related to the device information, and provides the data to an object via a network, the data management device comprising: management means for storing and managing a table indicating whether access by the object to which the role is assigned to the data having the attribute is permitted for a combination of a role assigned to each of a plurality of the objects belonging to one group and an attribute of the data defined by a data model predetermined corresponding to the one group; access control means for controlling access from the object to the data based on the table corresponding to the group to which the object belongs; reception means for receiving registration of a second group different from the first group by the object belonging to the first group; wherein the management means applies the data model corresponding to the first group as the data model for constructing the table corresponding to the second group.

2. The data management device according to claim 1, wherein the management means manages the first group and the second group as one set.

3. The data management device according to claim 1 or 2, wherein the reception means receives registration of the second group as a target for providing a maintenance service of the device by the object belonging to the first group.

4. The data management device according to any one of claims 1 to 3, wherein the management means generates the table indicating whether access by the object to which the role is assigned to the data having the attribute is permitted for a combination of a role assigned to each of a plurality of the objects belonging to the second group and the attribute of the data defined by the data model for constructing the table corresponding to the first group.

5. The data management apparatus according to any one of claims 1 to 4, wherein when the data model for constructing the table corresponding to the first group is changed by the object belonging to the first group, the management means updates the table by applying the changed data model to the table corresponding to the second group.

6. A data management apparatus that receives the device information from a plurality of the devices installed in the facility, wherein the reception means receives a designation of a secret device that transmits the device information to be kept secret from among the plurality of devices from an object belonging to the second group or from the secret device itself, and the access control means restricts access to the data regarding the device information transmitted from the secret device from an object other than the object belonging to the second group. The data management apparatus according to any one of claims 1 to 5.

7. A data management apparatus that receives the device information from a plurality of the devices installed in the facility, wherein the reception means receives, from an object belonging to the second group or from the device, a setting as to whether access by an object other than the object belonging to the second group to the data regarding the device information transmitted from the device, which has the attribute, is permitted for each combination of the device and the attribute of the data regarding the device information transmitted from the device, and the access control means controls access by an object other than the object belonging to the second group according to the setting received by the reception means. The data management apparatus according to any one of claims 1 to 5.

8. The data management apparatus according to any one of claims 1 to 7, wherein the management means manages the data in association with a time, the reception means receives a designation of a secret period including a time associated with the data to be kept secret from an object belonging to the second group or from the device, and the access control means restricts access to the data associated with a time within the secret period from an object other than the object belonging to the second group.

9. The management means manages the data by associating a region therewith, the reception means receives a designation of a secret region, which is a region associated with the data to be kept secret, from the object belonging to the second group or from the apparatus, and the access control means restricts access to the data associated with the secret region from an object other than the object belonging to the second group. The data management apparatus according to any one of claims 1 to 8.

10. The reception means receives a designation of secret information included in the data to be kept secret from the object belonging to the second group or from the apparatus, and the access control means restricts access to the data including the secret information from an object other than the object belonging to the second group. The data management apparatus according to any one of claims 1 to 9.

11. A data providing system including: an apparatus installed in a facility; the data management apparatus according to any one of claims 1 to 10, which receives apparatus information from the apparatus and manages data regarding the apparatus information; and a terminal that receives the provision of the data via a network from the data management apparatus.

12. A data management method executed by a data management device that receives device information from a device installed in a facility, manages data related to the device information, and provides the data to an object via a network, the method comprising: a management unit storing and managing a table indicating whether access by an object to which a role is assigned to data having the attribute is permitted or not, for a combination of a role assigned to each of a plurality of the objects belonging to one group and an attribute of the data defined by a data model defined in advance corresponding to the one group; an access control unit controlling access to the data from the object based on the table corresponding to the group to which the object belongs; a reception unit receiving registration of a second group different from the first group by an object belonging to the first group; and the management unit applying the data model corresponding to the first group as the data model for constructing the table corresponding to the second group.

13. A program that causes a data management device that receives device information from a device installed in a facility, manages data related to the device information, and provides the data to an object via a network to function as: a management unit storing and managing a table indicating whether access by an object to which a role is assigned to data having the attribute is permitted or not, for a combination of a role assigned to each of a plurality of the objects belonging to one group and an attribute of the data defined by a data model defined in advance corresponding to the one group; an access control unit controlling access to the data from the object based on the table corresponding to the group to which the object belongs; a reception unit receiving registration of a second group different from the first group by an object belonging to the first group; and the management unit applying the data model corresponding to the first group as the data model for constructing the table corresponding to the second group.

Citation Information

Patent Citations

  • Management device, management system, management method, and program

    WO2020166026A1