Data access controller
Abstract
[Task] A data access control device and a data access control method for efficiently executing control for access requests to a database are provided.
Solution.The hierarchical structure data menu to be displayed to the user who requests access to the database is set according to the user ID unique to the user. Based on the user identifier included in the access request, the user master table is searched, the menu identifier set corresponding to the user identifier is extracted, and the data file having the same menu identifier is selected from the menu master table to create a hierarchical structure data menu. Is generated, and this is output to the terminal device as a display menu.

Term
Term ended
Projected expiry passed 23 April 2019, 7.4 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
7 claims: 3 independent, 4 dependent
- 1【特許請求の範囲】 【請求項1】階層構造を構成する複数のデータファイルを格納したデータベース手段と、前記データベース手段内のデータファイルに対するアクセスを行なう1以上の端末装置と、前記端末装置から前記データファイルに対するアクセス要求に関する制御を実行するアクセス制御手段とを有するデータアクセス制御装置において、 前記アクセス制御手段は、前記端末装置からのアクセス要求中に含まれるユーザ識別情報に基づいて、前記データベースに格納された前記複数のデータファイルの少なくとも一部のデータファイルのファイル識別子によって構成される階層構造データメニューを表示メニューとしてアクセス要求を行なった端末装置に出力する構成を有することを特徴とするデータアクセス制御装置。
- 2【請求項2】前記データアクセス制御装置は、 ユーザ毎のユーザ情報を格納したユーザマスタテーブルと、 前記データベースに格納された複数のデータファイル各々のデータファイルに対応するデータファイル固有情報を格納したメニューマスタテーブルとを有し、 前記ユーザマスタテーブルには、ユーザ固有のユーザ識別子と、前記複数のデータファイルの少なくとも一部のデータファイルのファイル識別子によって構成される階層構造データメニューを一義的に決めるメニュー識別子とが設定され、 前記メニューマスタテーブルには、前記データファイルの各々に対応して前記メニュー識別子が対応付けられて設定された構成を有し、 前記アクセス制御手段は、 前記端末装置からのアクセス要求中に含まれるユーザ識別子に基づいて、前記ユーザマスタテーブルから対応するユーザ識別子を抽出するとともに、抽出されたユーザ識別子に対応して設定されたメニュー識別子を識別し、該識別されたメニュー識別子に対応するメニュー識別子を有するデータファイルを前記メニューマスタテーブルから選択して前記階層構造データメニューを表示メニューとしてアクセス要求を行なった端末装置に出力する構成を有することを特徴とする請求項1に記載のデータアクセス制御装置。
- 3【請求項3】前記ユーザマスタテーブルは、ユーザ毎のデータファイルに対する処理権限設定フィールドを有し、 前記メニューマスタテーブルは、前記データファイルの各々に対応して設定された起動権限設定フィールドを有し、 前記アクセス制御手段は、前記ユーザマスタテーブルの処理権限設定フィールドの設定値、および前記メニューマスタテーブルの起動権限設定フィールドの設定値に基づいて、データファイルの起動を制御する構成を有することを特徴とする請求項2記載のデータアクセス制御装置。
- 4【請求項4】前記データアクセス制御装置は複数の入力端末をネットワークによって接続した会計処理システムを構成するものであり、 前記データベースは会計処理に関する複数の会計データファイルを格納したデータベースであり、 前記メニューマスタテーブルは前記複数の会計データファイルの各々について固有情報を格納したテーブルであることを特徴とする請求項2または3に記載のデータアクセス制御装置。
- 5【請求項5】前記データアクセス制御装置は、 ユーザ毎のユーザ情報を格納したユーザマスタテーブルと、 前記データベースに格納された複数のデータファイルのデータファイル識別子によって構成される複数の階層構造データメニューを格納した階層構造データメニューテーブルとを有し、 前記ユーザマスタテーブルには、ユーザ固有のユーザ識別子と、前記複数のデータファイルの少なくとも一部のデータファイルのファイル識別子によって構成される階層構造データメニューを一義的に決めるメニュー識別子とが設定され、 前記階層構造データメニューテーブルには、前記メニュー識別子が対応付けられた階層構造データメニューが登録された構成を有し、 前記アクセス制御手段は、 前記端末装置からのアクセス要求中に含まれるユーザ識別子に基づいて、前記ユーザマスタテーブルから対応するユーザ識別子を抽出するとともに、抽出されたユーザ識別子に対応して設定されたメニュー識別子を識別し、該識別されたメニュー識別子に対応するメニュー識別子を有する階層構造データメニューを前記階層構造データメニューテーブルから選択して表示メニューとしてアクセス要求を行なった端末装置に出力する構成を有することを特徴とする請求項1に記載のデータアクセス制御装置。
- 6【請求項6】データベース中に格納された階層構造を構成する複数のデータファイルに対する端末装置からのアクセス要求をアクセス制御手段によって制御するデータアクセス制御方法において、 前記アクセス制御手段は、 前記端末装置からのアクセス要求中に含まれるユーザ識別情報を判別し、 前記判別されたユーザ識別情報に基づいて前記データベースに格納された前記複数のデータファイルの少なくとも一部のデータファイルのファイル識別子によって構成される階層構造データメニューを表示メニューとして前記端末装置に出力することを特徴とするデータアクセス制御方法。
- 7【請求項7】前記データアクセス制御方法において、前記アクセス制御手段は、 前記端末装置からのアクセス要求中に含まれるユーザ識別子に基づいて、ユーザマスタテーブルから対応するユーザ識別子を抽出し、 前記抽出されたユーザ識別子に対応して前記ユーザマスタテーブルに設定されたメニュー識別子を識別し、 前記識別されたメニュー識別子に対応するメニュー識別子を有するデータファイルをメニューマスタテーブルから選択し、 前記選択されたデータファイルによって構成される階層構造データメニューを表示メニューとして前記端末装置に出力することを特徴とする請求項6に記載のデータアクセス制御方法。
Independent claims7
159 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a data access control device and a data access control method. More specifically, in a configuration in which a database has multiple data files and multiple users access the data files in the database, the access rights of individual users are controlled to clarify the scope of access rights for each user. In addition to showing, the present invention relates to a data access control device and a data access control method capable of more reliably protecting confidential information.
【0002】
[Conventional technology]
In general, a data processing system that handles various types of data is configured to restrict user access to data stored in a database for reasons such as security, writing, and modification of specific data. In the field of accounting, many accounting systems using computers have been developed, and various accounting processes are executed programmatically based on various accounting data input via the user interface, and the input data or processing data. Is stored in a database, and a system that automates the generation and output of various accounting documents such as slips, invoices, and financial statements is used.
【0003】
For example, a network-type accounting system that connects a company's head office, branch offices, etc. via a network and connects a large number of user terminals so that data can be input and output at each connected terminal is rapidly becoming widespread. Multiple users input accounting data from each user terminal, accumulate the input data in the database, execute accounting processing of the accumulated data by a predetermined processing program, and various types such as profit and loss statement, balance trial calculation table, cash flow chart, etc. Create accounting data for.
【0004】
In such a network-type accounting processing system, various users access a database and execute various processing such as input processing of accounting data such as transfer slips, deposit slips, and withdrawal slips, or inquiry processing such as balance inquiry. To do. The input data is subjected to journal processing and the like in accordance with predetermined accounting rules, and various form data such as a journal diary, a general ledger, a trial balance, and an income statement are generated. For example, payment processing by sales, withdrawal processing by spending expenses, transfer processing by salary payment, etc. that occur daily in various departments are sequentially input from the user terminal of each department connected to the network, and the data processing means The processing of these input data is executed according to a preset program to generate various book table data. Furthermore, it performs closing processing and settlement processing of accounting processing for each predetermined accounting period such as monthly or yearly, and outputs various forms, summary tables, etc.
【0005】
These accounting data are stored in the database, but if all networked users are allowed to access, write, correct, etc. all the data files in the database, the data protection will be incomplete. Furthermore, accounting processing data often includes data that should be kept confidential to general users, such as information specific to the head office or branch office of a company, or management data of the accounting department, and general users to these confidential data. It is necessary to have a configuration that prohibits or restricts access to.
【0006】
[Problems to be Solved by the Invention]
In a conventional data processing system, as a configuration for protecting specific data, writing, restricting changes, etc., that is, restricting access, for example, a user ID or user password, which is a user identifier, is recognized and these IDs or passwords are recognized. Create a table that corresponds to each data file of multiple data files stored in the database, and allow or prohibit access to the data file requested by the user by referring to this table. Was generally adopted.
【0007】
However, in the above configuration, when a user tries to access one file, a file designation signal specifying one data file is transmitted, and this file designation signal is received by, for example, a database management server. The process of searching the table that associates the user ID with the specified file, allowing access if the table has a correspondence between the user ID and the specified file, and denying access if there is no correspondence, and sending an access approval / disapproval answer to the user terminal. Is required for each specified file.
【0008】
When the user makes continuous file requests, it is necessary to repeatedly specify a new file and obtain an access approval / disapproval answer from the database management server. In this way, when a user accesses a database that is composed of multiple files and has access restrictions in succession, signals are frequently transmitted and received for access approval / disapproval between the user and the database. As a result, the processing becomes complicated and the processing time is delayed.
【0009】
The data access control device and the data access control method of the present invention solve the above-mentioned problems, and can determine the accessible range of each user in response to a user's access request to a database storing a plurality of data files. It can be presented to users in a batch, allowing individual users to list their own assessable data files, and omitting the process of permitting and disallowing access between users and database servers. The purpose.
【0010】
Further, the data access control device and the data access control method of the present invention present a hierarchical data file structure to the user in response to an access request from the user to a database storing a plurality of data files in the database. The purpose is to easily understand the data file structure and achieve easy file usage even for users who do not have knowledge about the data file structure of.
【0011】
Further, the data access control device and the data access control method of the present invention have a configuration in which a confidential data file does not show not only the file name but also the existence itself in the database to a user who does not have the access right. By doing so, the purpose is to strengthen the protection of confidentiality.
【0012】
[Means for solving problems]
In order to achieve the above object, the data access control device of the present invention includes a database means for storing a plurality of data files constituting a hierarchical structure, one or more terminal devices for accessing the data files in the database means, and the like. In a data access control device having an access control means for executing control regarding an access request to a data file from the terminal device, the access control means stores in a database based on the user identification information included in the access request from the terminal device. At least hierarchical data menu constituted by the file identifier of a part of the data files of the plurality of data files that are characterized by having a configuration to be output to the terminal apparatus of performing an access request as a display menu chromatography.
【0013】
Further, the data access control device of the present invention has a user master table that stores user information for each user and a menu master table that stores data file-specific information corresponding to each data file of a plurality of data files stored in the database. The user master table has a user identifier unique to the user and a menu identifier that uniquely determines a hierarchical structure data menu composed of file identifiers of at least a part of data files of a plurality of data files. The menu master table is set and has a configuration in which menu identifiers are associated with each of the data files, and the access control means is set to the user identifier included in the access request from the terminal device. Based on this, the corresponding user identifier is extracted from the user master table, the menu identifier set corresponding to the extracted user identifier is identified, and the data file having the menu identifier corresponding to the identified menu identifier is generated. It is characterized in that it has a configuration in which a hierarchical structure data menu is selected from a menu master table and output as a display menu to a terminal device that has made an access request.
【0014】
Further, in the data access control device of the present invention, the user master table has a processing authority setting field for the data file for each user, and the menu master table has a start authority setting field corresponding to each of the data files. The access control means is characterized by having a configuration for controlling the activation of a data file based on the setting value of the processing authority setting field of the user master table and the setting value of the activation authority setting field of the menu master table.
【0015】
Further, the data access control device of the present invention constitutes an accounting processing system in which a plurality of input terminals are connected by a network, a plurality of accounting data files related to accounting processing are stored in a database, and a menu master table contains a plurality of accounting data. The feature is that it is a table that stores unique information for each of the files.
【0016】
Further, in the data access control device of the present invention, the data access control device has a plurality of hierarchical structures composed of a user master table storing user information for each user and data file identifiers of a plurality of data files stored in the database. It has a hierarchical data menu table that stores data menus, and the user master table has a hierarchical data menu composed of a user-specific user identifier and a file identifier of at least a part of data files of a plurality of data files. A menu identifier that uniquely determines the data is set, and the hierarchical structure data menu table has a configuration in which a hierarchical structure data menu associated with the menu identifier is registered, and the access control means is accessed from the terminal device. Based on the user identifier included in the request, the corresponding user identifier is extracted from the user master table, the menu identifier set corresponding to the extracted user identifier is identified, and the identified menu identifier is supported. It is characterized in that it has a configuration in which a hierarchical structure data menu having a menu identifier to be used is selected from the hierarchical structure data menu table and output as a display menu to a terminal device that has made an access request.
【0017】
Further, the data access control method of the present invention is a data access control method in which an access request from a terminal device for a plurality of data files constituting a hierarchical structure stored in a database is controlled by the access control means. , The user identification information included in the access request from the terminal device is determined, and it is composed of the file identifiers of at least a part of the data files of the plurality of data files stored in the database based on the determined user identification information. The feature is that the hierarchical structure data menu is output to the terminal device as a display menu.
【0018】
Further, in the data access control method of the present invention, the access control means extracts the corresponding user identifier from the user master table based on the user identifier included in the access request from the terminal device, and uses the extracted user identifier as the extracted user identifier. The menu identifier set in the user master table is identified correspondingly, the data file having the menu identifier corresponding to the identified menu identifier is selected from the menu master table, and the hierarchical structure data composed of the selected data files. The feature is that the menu is output to the terminal device as a display menu.
【0019】
BEST MODE FOR CARRYING OUT THE INVENTION
FIG. 1 shows a system configuration block diagram of the data access control device of the present invention. A plurality of user terminals 11, 12, and 13 are connected to the access management server 30 via the network 20, and the access management server 30 is an information file database 50 containing data having a plurality of data files as components, and individual users. Each of the user master database 51 that stores the information and the menu master database 52 that stores the menu information related to the unique information corresponding to each data file of the plurality of data files included in the information file database 50 and the hierarchical structure information of the data files. It has an accessible configuration.
【0020】
FIG. 2 shows an example of a system configuration in which the data access control device and the data access control method of the present invention are applied as an accounting system. The example shown in FIG. 2 is a network-type accounting system in which the input / output devices 101, 102, 103, the application server 104, and the database server 105 are connected via the network 106.
【0021】
The data access control device and the data access control method of the present invention are applicable not only to accounting systems but also to various database systems. Basically, it is applicable as long as it has a database configuration that can be accessed by multiple users connected by the network shown in Fig. 1, and various data access such as document management database and personnel information management database. It can be applied in the control device. Hereinafter, an example applied to the network-type accounting system shown in FIG. 2 will be described as a specific example of the data access control device and the data access control method of the present invention.
【0022】
The user terminals 11, 12, and 13 in FIG. 1 correspond to the input / output devices 101, 102, 103 in FIG. 2, and the access management server in FIG. 1 is the server 1051 in the database server 105 in FIG. 2 or the server 1041 in the application server 104. , 1042, and the information file database 50, user master database 51, and menu master database 52 in FIG. 1 correspond to the database 1052 in FIG.
【0023】
Hereinafter, the details of the data access control device and the data access control method of the present invention will be described by taking the network-type accounting system shown in FIG. 2 as an example. The input / output devices 101, 102, 103 are user terminal devices that use the accounting processing system, and the user inputs predetermined accounting data. For example, input accounting data generated at a business establishment, department, individual, etc. where each input / output device is arranged, such as input of a deposit slip related to sales and input of a withdrawal slip due to transportation expenses. Each of the input / output devices 101, 102, and 103 is a device assigned to a predetermined unit such as each business establishment unit, each department unit, or a user unit, and the accounting processing data generated in each assigned range is generated. Entered. The input / output devices 101, 102, 103 are described on behalf of the input / output device 103, but have a GUI function, and can output various data input screens and data display screens on the display as described later, and are displayed. You can enter accounting data on the screen.
【0024】
These input / output devices 101, 102, 103 are connected to the application server 104 and the database server 105 via the network 106.
【0025】
The application server 104 has servers 1041 and 1042 configured by, for example, a PC server as hardware, and executes various accounting processes according to the application programs in the servers 1041 and 1042. The database server 105 has a server 1051 and a database 1052. The server 1051 is composed of, for example, a UNIX machine or a PC server. The database 1052 stores the data input by the input / output devices 101, 102, 103, and the data processed by the application server 104 and the database server 105. The database 1052 further stores a user master table that stores user information and a menu master table that stores file information, which will be described in detail later.
【0026】
The application server 104 and the database server 105 execute various accounting processes such as input data processing, that is, journalizing processing of each input data, recording in each accounting book, and posting processing in the general ledger. The application server 104 mainly executes the processing according to each application program, and the database server 105 mainly executes the batch processing of the processing data by the application server 104, for example, the batch processing of the data on a daily basis.
【0027】
In order for the users of the input / output devices 101, 102, 103 to access the data files stored in the database 1052, the user ID and password unique to the user are entered in the input / output devices that execute the access. The login screen is shown in Fig. 3. As shown in FIG. 3, the user inputs the user ID and the setting password given to each user in advance on the screen.
【0028】
These entered user IDs and passwords are transferred over the network 106 to a server that performs access control. In Figure 2, server 1051 is assumed to be the server that performs access control. The server 1051 receives the user ID and input password from the user over the network.
【0029】
The server 1051 that receives the user ID and the input password from the user executes the determination of the user based on the user master table shown in FIG. 4 stored in the database 1052. As shown in FIG. 4, the user master table is a table that defines identification information, access authority, etc. of individual users. Company code, user ID, use start, end date, user name, user password, etc. are set as input information for each user. Based on these table information, matching with the user input ID and password is executed.
【0030】
Furthermore, in the user master table shown in Fig. 4, in items 8 to 11 such as "8. Temporary tightening period input possible classification" and "9. Input system authority classification", input, inquiry, and registration for the period or data file , A field for determining whether or not to modify is provided, and a predetermined value is input for each user. Further, item 12 is provided with a field indicating a menu ID. This menu ID is an ID indicating a hierarchical data menu of a plurality of data files that can be accessed by individual users, and will be described in detail later.
【0031】
Figure 5 shows an example of the data generated according to the user master table. As shown in FIG. 5, the data of each item in the user master table is set for each user, and is stored in the database 1052 in the network accounting processing system of FIG. In the system configuration example of FIG. 1, the user master table storing user data is stored in the user master database 51.
【0032】
In the example of the network-type accounting system shown in FIG. 2, the database 1052 further holds a menu master table. Figure 6 shows the data contents of the menu master table. The menu master table is a table that defines the unique information of each data file of a plurality of data files held in the database. In the example of the accounting processing system shown in FIG. 2, a plurality of accounting data held in the database 1052. It is organized as a table that defines the unique information corresponding to each accounting data file in the file.
【0033】
FIG. 6 is a diagram for explaining the data contents of the menu master table, and FIG. 7 is a diagram showing an example of sample data of the menu master table. FIG. 8 is a diagram showing an example of displaying a hierarchical data structure of a plurality of data files stored in the database 1052, that is, a hierarchically structured data structure stored in the database 1052.
【0034】
As can be seen from FIG. 6, the menu master table is set with individual data file specific information of a plurality of data files stored in the database 1052. For example, unique information corresponding to each data file such as a company code, a menu ID, and a menu item is set as an input item. The fields (items) shown in FIG. 6 indicate typical fields, and various fields other than the fields shown in FIG. 6 are set in the actual table.
【0035】
The menu master table of FIG. 6 will be described with reference to FIGS. 7 and 8 with actual examples. As shown in Fig. 8, the multiple data files stored in the database 1052 are hierarchically structured. FIG. 8 is a hierarchical structure data menu in which the name of the data file stored in the database 1052 is used as the data file identifier and the data file structure in the database 1052 is expressed in a hierarchical structure. In FIG. 8, for example, there are five data files under the file "general account": the files "balance inquiry", "organization input", "consumption tax", "others", and "source input". In addition, there are three files under the file "Balance Inquiry": the files "Account Ledger Inquiry", "Holding Ledger Inquiry", and "Journal Inquiry".
【0036】
Each item of the menu master table is set for each of these individual data files. Figure 7 shows an example of sample data for the menu master table. Similar to FIG. 6, the items shown in FIG. 7 show typical items, and various items other than the items shown in FIG. 7 are set in the actual table.
【0037】
As can be understood from FIG. 7, for example, in the data file whose menu display name is "Balance Inquiry", the menu ID is "ACM0000", the menu item is "1100", the parent item is "1000", and the menu division is "". 1 "is set. Furthermore, "ACM0000" is set as the menu ID, "1101" is set as the menu item, "1100" is set as the parent item, and "2" is set as the menu category in "Balance ledger inquiry" which is a lower file of "Balance inquiry". .. Note that the sample data example in FIG. 7 is simply described, and not all of the items shown in FIG. 6 are described.
【0038】
In FIGS. 6 and 7, the menu item ID is an identifier unique to each data file, and is an identifier uniquely assigned to each of all the data files forming the hierarchical structure of the hierarchical structure data menu shown in FIG. is there. The "parent item ID" indicates the "menu item ID" of the data file that is higher in the hierarchical structure shown in FIG. For example, the upper file of the file "Balance Ledger Inquiry" is "Balance Inquiry", and the "Menu Item ID" of "Balance Inquiry" is "1100", so the "Parent Item ID" of the file "Balance Ledger Inquiry" is "Parent Item ID". 1100 ". The "menu division" is used as an identifier that distinguishes between a data file in which a program should be started and a submenu in which a unique program does not need to be started, as described in FIG.
【0039】
The "menu ID" will be described. The menu ID is, for example, an identifier indicating the hierarchical structure data menu structure shown in FIG. In Fig. 8, "Plenary rights menu" is written at the top. This indicates that all accessible data in the database is shown as a hierarchical structure. The identifier of the hierarchical structure data structure corresponding to this plenipotentiary menu is, for example, menu ID: ACM0000.
【0040】
FIG. 9 shows a hierarchical structure data menu having a structure different from that of the hierarchical structure data menu shown in FIG. For example, the source input file, which is a subordinate file of the file general account shown in FIG. 8, is not shown in FIG. For example, the identifier of the hierarchical structure data menu structure shown in FIG. 9 is menu ID: ACM0001.
【0041】
Further, FIG. 10 shows a hierarchical structure data menu structure having a structure different from the hierarchical structure shown in FIGS. 8 and 9. For example, each file of "organization input", "consumption tax", "others", and "source input", which are subordinate files of the file "general account" shown in FIG. 8, is not shown in FIG. The identifier of the hierarchical data menu structure shown in FIG. 10 is defined as menu ID: ACM0002. FIG. 11 is similar to the hierarchical data menu structure shown in FIG. 10, and is shown by expanding the file Employee Management.
【0042】
Returning to FIG. 7, the correspondence with FIGS. 8 to 10 will be described. In FIG. 7, "ACM0000", "ACM0001", or "ACM0002" is set in the item "Menu ID" column. These indicate which menu ID is specified for each data file to be displayed as a hierarchical structure as shown in FIGS. 8 to 10.
【0043】
As shown in FIGS. 4 and 5, the item menu ID is set for each user. That is, the menu ID is uniquely determined based on the user ID of each user. For example, in the sample example shown in Fig. 5, Mr. Sato with the user ID "ABCAB" has ACM0000 set as the menu ID, and is composed of a data file with the menu ID "ACM0000" set in the menu master sample shown in Fig. 7. The hierarchical data menu is displayed. This is the plenipotentiary menu shown in FIG.
【0044】
Mr. Sato of the user ID "ABCAB" uses any of the input / output devices 101 to 103 shown in Fig. 2 to enter the user ID and user password and send them to the database server 1051 so that the database server 1051 becomes a user. The ID and the user password are identified, the user is confirmed using the user master table described in FIGS. 4 and 5, and the menu ID set in the user master table is determined.
【0045】
Further, the database server 1051 extracts a data file having the same menu ID as the discriminated menu ID from the menu master table described in FIGS. 6 and 7 based on the discriminated menu ID, and the extracted data file is used, for example, in the figure. Generate the hierarchical structure data menu shown in 8 ~ 10. These hierarchical data menus are generated based on the menu display name, parent item data, etc. set in the menu master table.
【0046】
For example, the hierarchical data menu shown in FIGS. 8 to 10 shows the data file name of each data file, the icon of each data file, the connection indicating the upper and lower file relations, and the existence of the lower file in the file. It is composed of + "symbols and symbols such as"-"indicating that there are no subordinate files in the file, but the information for generating these hierarchical structure data menus is basically obtained from the menu master table.
【0047】
In the above example, the database server 1051 selects a data file from the menu master table based on the menu ID and generates a hierarchical structure data menu based on the selected data file. However, a plurality of menu IDs are used in advance. A plurality of hierarchical structure data menus corresponding to the above may be registered in an independent hierarchical structure data menu table. With such a configuration, based on the menu ID sent from the user and identified by the user master table, the hierarchical data menu corresponding to the identification menu ID is immediately selected from the hierarchical data menu table of the user. It can be displayed on the input / output device. Therefore, it is possible to omit the step of searching the menu master table and generating the hierarchical structure data menu based on the search result.
【0048】
When the user receives, for example, the hierarchical structure data menu display shown in FIG. 8 in the input / output devices 101 to 103, the user determines the file to be opened from the displayed hierarchical structure data menu based on the hierarchical structure data menu shown in FIG. The file can be opened by specifying the pointing device of, for example, by clicking the mouse. Note that writing, deleting, etc. of data in each file is further set by input authority, inquiry authority, etc. as shown in FIGS. 4 and 5, and processing is controlled according to the set data.
【0049】
Returning to FIGS. 4 to 6, various authority control configurations such as input authority will be described. Fields 8 to 11 of the user master table in FIG. 4 are fields for setting various privileges corresponding to individual users. For example, "9. Input authority classification" is configured to set whether to input in company-wide units, accounting units, and department units, as described in the details column, and "10. Inquiry authority classification". "Is configured to set whether or not to make inquiries on a company-wide basis, accounting unit, or departmental basis.
【0050】
Field 7 "Startup permission check classification" of the menu master table in Fig. 6 is a field in which the start conditions of each data file are set corresponding to the various permissions set in fields 8 to 11 of the user master table in Fig. 4 above. is there. The details are as described in the "Details" column of FIG. 6. For example, if "N" is set in the field 7 of the menu master table of FIG. 6, the field "9: NKENKNBN" of the user master table is set. If ": Input system authority classification" is blank, this data file will not be started.
【0051】
For example, "9: NKEKNBN: Input system authority classification" is set in the menu master table corresponding to each of all the data files displayed in the hierarchical structure data menu shown in Fig. 8, and corresponds to each user. It is configured to allow input restrictions such as registration, modification, and deletion, and inquiry restrictions.
【0052】
For example, Mr. Suzuki of the user ID "KLMKN" shown in FIG. 5 has "ACM0001" set as the menu ID, and is composed of a data file in which the menu ID "ACM0001" is set in the menu master sample of FIG. The hierarchical data menu is displayed. This is menu 001 shown in FIG.
【0053】
Mr. Tanaka of the user ID "PQRFD" shown in FIG. 5 has "ACM0002" set as the menu ID, and is composed of data files in which "ACM0002" is set as the menu ID in the menu master sample of FIG. The structure data menu is displayed. This is menu 002 shown in FIG.
【0054】
When opening the required files from each displayed hierarchical structure data menu and executing data inquiry, data entry, data registration, etc., input each file set in the user master table and menu master table as described above. Whether or not processing is possible is determined based on various permissions such as permissions, and the user can perform processing within the permitted permissions.
【0055】
As described above, since the data access control device of the present invention is associated with the menu ID in which the hierarchical structure data menu to be displayed corresponding to each user is set, the user identification based on the user ID or the like is executed once. Then, all the files that the user can access can be displayed on the terminal used by the user as a hierarchically structured data menu, and the access permission processing for each data file can be performed as in the conventional database system. There is no need to execute it, complicated processing is alleviated, and processing time can be shortened. The user can also list the data structures available to the user, which helps the user understand the database structure and facilitates the use of data files. Further, for a confidential data file, not only the file name but also the existence itself in the database is not shown to the user who does not have the access right, so that the protection of confidentiality can be strengthened.
【0056】
12 and 13 show a setting screen for setting individual user information in the user master table in the data access control device of the present invention. FIG. 12 shows a basic information input screen for each user, and FIG. 13 shows a security information input screen.
【0057】
On the setting screen shown in FIG. 12, the company name, user ID, start and end date of use, user name, and department to which the user belongs are registered as basic user information. Regarding the password, each user executes communication with the database management server at an appropriate timing, inputs the password together with the user ID, and the password is registered and changed.
【0058】
On the security information input screen of FIG. 13, a menu ID that determines the hierarchical structure of accessible data files is set, and data entry, inquiry, and other privileges for accessible files are set. The data set in FIGS. 12 and 13 are registered in the user master table described in FIGS. 4 and 5.
【0059】
In the system configuration example of the data access control device shown in FIG. 1, the user information set in FIGS. 12 and 13 is registered in the user master database 51. When the access management server 30 receives the user ID and password set from the user terminals 11 to 13 via the network 20, the data in which the corresponding user ID is registered is extracted from the user master database 51 and the corresponding menu ID is extracted. , The menu master table is searched from the menu master database 52 based on the extracted menu ID, the data file having the corresponding menu ID is extracted, the hierarchical structure data menu is generated, and the data file is sent to the user terminal in which the access request is made.
【0060】
The present invention has been described in detail with reference to the specific examples. However, it is self-evident that a person skilled in the art can modify or substitute the embodiment without departing from the gist of the present invention. That is, the present invention has been disclosed in the form of an example, and should not be construed in a limited manner. In order to judge the gist of the present invention, the column of claims described at the beginning should be taken into consideration.
【0061】
[Effect of the invention]
As described above, according to the data access control device and the data access control method of the present invention, the hierarchical structure data menu to be displayed for each user is set according to the user ID unique to the user. Therefore, by identifying the user ID, it is possible to present the entire accessible data range to the user as a hierarchical structure data menu, which eliminates the need for access approval / disapproval processing for each file and shortens the processing time.
【0062】
Further, according to the data access control device and the data access control method of the present invention, the data files that can be used by the user can be listed as a hierarchical structure at the start of access, which helps the user to understand the database configuration and uses the data files. Simplification is achieved. Further, for a confidential data file, not only the file name but also the existence itself in the database is not shown to the user who does not have the access right, so that the protection of confidentiality can be strengthened.
[Simple explanation of drawings]
[Figure 1]
It is a figure which shows the system configuration example of the data access control apparatus which concerns on this invention.
[Figure 2]
It is a figure which shows the structure which applied the data access control device which concerns on this invention as a network type accounting processing system.
[Fig. 3]
It is a figure which shows the example of the login screen in the input terminal of the network type accounting processing system of FIG.
[Fig. 4]
It is a figure explaining the table structure of the user master table in the accounting processing system which concerns on this invention.
[Fig. 5]
It is a figure which shows the data sample of the user master table in the accounting processing system which concerns on this invention.
[Fig. 6]
It is a figure explaining the table structure of the menu master table in the accounting processing system which concerns on this invention.
[Fig. 7]
It is a figure which shows the data sample of the menu master table in the accounting processing system which concerns on this invention.
[Fig. 8]
It is a figure which shows the display example (the 1) of the hierarchical structure data menu of the accounting processing system which concerns on this invention.
[Fig. 9]
It is a figure which shows the display example (the 2) of the hierarchical structure data menu of the accounting processing system which concerns on this invention.
[Fig. 10]
It is a figure which shows the display example (the 3) of the hierarchical structure data menu of the accounting processing system which concerns on this invention.
[Fig. 11]
It is a figure which shows the display example (the 4) of the hierarchical structure data menu of the accounting processing system which concerns on this invention.
[Fig. 12]
It is a figure (the 1) which shows the data setting screen of the user master table in the accounting processing system which concerns on this invention.
[Fig. 13]
It is a figure (the 2) which shows the data setting screen of the user master table in the accounting processing system which concerns on this invention.
[Explanation of symbols]
11,12,13 User terminal 20 networks 30 Access management server 50 Information file database 51 User master database 52 Menu master database 101,102,103 I / O device 104 application server 105 database server 106 network 1041,1042 server 1051 server 1052 database
14 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN116662623A | Cited by | China | Search report |
| JP2019061619A | Cited by | Japan | Search report |
| JP2015049742A | Cited by | Japan | Search report |
| US11169756B2 | Cited by | United States of America | Applicant |
| JP2016076134A | Cited by | Japan | Search report |
| US11204729B2 | Cited by | United States of America | Applicant |
| US10984019B2 | Cited by | United States of America | Applicant |
| JP2016076134A | Cited by | Japan | Search report |
| JP2016076134A | Cited by | Japan | Search report |
| JPWO2004017240A1 | Cited by | Japan | Search report |
| JP2011170661A | Cited by | Japan | Examiner |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 11631699 | Japan | A | |
| JP19990116316 | – | – | – |
9 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of registration of transferJAPANESE INTERMEDIATE CODE: R350R350 | R350 | |
| Written request for registration of change of domicileJAPANESE INTERMEDIATE CODE: R313531S531 | S531 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 |
Numbers
- Publication
- 2000-305834
- Publication, DOCDB
- 2000305834
- Publication, EPODOC
- JP2000305834
- Application
- 11116316
- Application, DOCDB
- 11631699
- Application, EPODOC
- JP19990116316
Titles2
- Japanese
- データアクセス制御装置
- English
- [Title of Invention] Data Access Control Device
Classification
- IPC, 4
- G06F12 00
- G06Q10 00
- G06Q10 06
- G06Q50 00