At least one information processing apparatus, information processing system, and role setting method
14 claims: 3 independent, 11 dependent
- 11つ以上のアプリを含むアプリパッケージの利用権限を割り当て可能なロールの設定を前記アプリパッケージに対して受け付けるパッケージ管理部と、前記アプリのユーザに割り当てられているロール及び前記アプリパッケージに設定されたロールに応じて、ユーザによる前記アプリパッケージの利用を許可又は制限するユーザ管理部と、を有し、 前記ユーザ管理部は、前記ユーザに割り当てられているロールと、前記アプリパッケージに設定されたロールとに基づいて、前記ユーザに前記利用権限を割り当て可能な前記アプリパッケージのリストが含まれる画面を提供 することを特徴とする1つ以上の情報処理装置。
- 2前記1つ以上の情報処理装置は、前記アプリパッケージと前記アプリパッケージを用いたサービスの提供を受けるテナントとの対応を受け付けることを特徴とする請求項1に記載の1つ以上の情報処理装置。
- 3前記ロールは、前記テナントを管理する役割のテナント管理者、又は、一般ユーザであることを特徴とする請求項2に記載の1つ以上の情報処理装置。
- 4前記アプリパッケージに前記ロールを設定する権限を有する者を認証する認証部を有し、前記認証部は前記テナント管理者、又は、前記一般ユーザには前記アプリパッケージへの前記ロールの設定を許可しないことを特徴とする請求項3に記載の1つ以上の情報処理装置。
- 5前記ユーザ管理部は、ユーザ情報の登録時に受け付けた前記ロールと同じロールが設定されている前記アプリパッケージの利用権限を前記ユーザ情報に設定することを特徴とする請求項1~4のいずれか1項に記載の1つ以上の情報処理装置。
- 6前記ユーザ管理部は、ユーザ情報に登録されている前記ロールと同じロールが設定されている前記アプリパッケージのリストがユーザごとに対応付けられた画面を提供し、前記画面において前記ユーザ情報への前記アプリパッケージの登録を受け付けることを特徴とする請求項1~5のいずれか1項に記載の1つ以上の情報処理装置。
- 7端末装置と1つ以上の情報処理装置とがネットワークを介して通信する情報処理システムであって、前記端末装置は、1つ以上のアプリを含むアプリパッケージのパッケージ新規作成画面において前記アプリパッケージを利用できるロールの設定を受け付ける操作受付部と、前記操作受付部が受け付けた前記ロールを前記1つ以上の情報処理装置に送信する通信部と、を有し、前記1つ以上の情報処理装置は、前記端末装置から送信された前記ロールを、前記アプリパッケージの利用権限を前記アプリパッケージに対して割り当て可能なロールとして設定するパッケージ管理部と、前記アプリのユーザに割り当てられているロール及び前記アプリパッケージに設定されたロールに応じて、ユーザによる前記アプリパッケージの利用を許可又は制限するユーザ管理部と、を有し、 前記ユーザ管理部は、前記ユーザに割り当てられているロールと、前記アプリパッケージに設定されたロールとに基づいて、前記ユーザに前記利用権限を割り当て可能な前記アプリパッケージのリストが含まれる画面を提供 することを特徴とする情報処理システム。
- 8前記ユーザ管理部は、ユーザ情報の登録時に、ユーザ情報に登録されている前記ロールと同じロールが設定されている前記アプリパッケージのリストが含まれるパッケージ一覧画面の画面情報を前記端末装置に提供し、前記端末装置は前記パッケージ一覧画面を表示し、前記パッケージ一覧画面で表示された選択を受け付けた前記アプリパッケージの前記ユーザ情報への登録を要求することを特徴とする請求項7に記載の情報処理システム。
- 9前記ユーザ管理部は、ユーザ情報の登録後、ユーザ情報に登録されている前記ロールと同じロールが設定されている前記アプリパッケージのリストがユーザごとに対応付けられた利用権限管理画面の画面情報を前記端末装置に提供し、前記端末装置は前記利用権限管理画面を表示し、ユーザごとに受け付けた利用権限を割り当てる前記アプリパッケージの前記ユーザ情報への登録を前記1つ以上の情報処理装置に要求することを特徴とする請求項7に記載の情報処理システム。
- 10前記1つ以上の情報処理装置は、前記アプリパッケージによるサービスの提供を受けるテナントのテナント一覧画面とアプリパッケージの一覧画面の画面情報を前記端末装置に提供し、前記端末装置は前記テナント一覧画面を表示し、前記テナント一覧画面で前記テナントの選択を受け付け、前記アプリパッケージの一覧画面を表示し、前記アプリパッケージの一覧画面で前記アプリパッケージの選択を受け付け、選択を受け付けた前記アプリパッケージに前記テナントへ対応付けることを前記1つ以上の情報処理装置に要求することを特徴とする請求項7~9のいずれか1項に記載の情報処理システム。
- 11前記アプリパッケージの一覧画面は、前記テナントに対応付けられていない未導入パッケージ一覧画面であり、前記端末装置は前記テナントに対応付けられていない前記未導入パッケージ一覧画面から前記アプリパッケージの選択を受け付けることを特徴とする請求項10に記載の情報処理システム。
- 12前記1つ以上の情報処理装置は、前記テナントに対応付けられている前記アプリパッケージを含むテナント情報画面の画面情報を前記端末装置に提供し、前記端末装置は前記テナント情報画面を表示し、前記アプリパッケージの選択を受け付け、前記1つ以上の情報処理装置は、前記アプリパッケージの一覧画面で選択を受け付けた前記アプリパッケージが有するアプリ一覧画面の画面情報を前記端末装置に提供し、前記端末装置は前記アプリ一覧画面を表示し、前記アプリパッケージに含まれる前記アプリの編集を受け付けることを特徴とする請求項10又は11に記載の情報処理システム。
- 13前記アプリパッケージに含まれるアプリ毎に、アプリを利用可能なロールの設定を、前記端末装置を介して受け付け、少なくとも1つのアプリの利用可能なロールの設定を受け付けた際に、前記アプリを含んでいるアプリパッケージにロールがすでに設定されていた場合は、前記アプリパッケージのロールを解除するか否かの選択を受け付け、前記アプリパッケージのロールを解除した場合は、継続して、アプリを利用可能なロールの設定を受け付けるが、前記アプリパッケージのロールを解除しなかった場合は、アプリを利用可能なロールの設定を受け付けないことを特徴とする請求項12に記載の情報処理システム。
- 14パッケージ管理部が、1つ以上のアプリを含むアプリパッケージの利用権限を割り当て可能なロールの設定を受け付けるステップと、ユーザ管理部が、前記アプリのユーザに割り当てられているロール及び前記アプリパッケージに設定されたロールに応じて、ユーザによる前記アプリパッケージの利用を許可又は制限するステップと、 前記ユーザ管理部が、前記ユーザに割り当てられているロールと、前記アプリパッケージに設定されたロールとに基づいて、前記ユーザに前記利用権限を割り当て可能な前記アプリパッケージのリストが含まれる画面を提供するステップと、 を有することを特徴とするロール設定方法。
Independent claims14
230 paragraphs, as filed
The present invention relates to one or more information processing devices, an information processing system, and a role setting method.
There are known one or more information processing devices that provide software and the like to users via a network. By preparing a certain environment, such as a terminal device such as a PC (personal computer) or electronic device, and a web browser that runs on the terminal device, a user can use services provided by a web application or the like provided by the information processing device from the terminal device.
In some cases, a company or the like contracts as an organization for a service provided by one or more such information processing devices, and members of the organization use the service as users. In addition, organizations that contract for a service are managed in units called tenants. In order for a user (an employee of a company, etc.) to use the service, the user must be registered with the tenant, and for example, an administrator may register the user with the tenant. In addition, a technology for registering an electronic device with a tenant is known (for example, see Patent Document 1). Patent Document 1 discloses a registration method in which a device requests client registration to an access management server based on first authentication information held by a linked application.
<p>However, the conventional technology had a problem in that it was not possible to set roles for an app package. An app package is one or more apps sold as a set by a service provider to a tenant. Since the service provider and the user side could not set roles for an app package, for example, there were cases where the use authority of an app package was assigned to a user whom the administrator did not want to use.</p><p>In view of the above-mentioned problems, an object of the present invention is to provide one or more information processing devices capable of setting a role for an application package.</p>
<p>In view of the above problems, the present invention provides a method for controlling a user of an application package including one or more applications, the method comprising: receiving a role setting for the application package that can be assigned a usage authority of the application package; and a user management unit that permits or restricts a user from using the application package according to a role assigned to the user of the application and a role set in the application package,<u style="Single">The user management unit provides a screen including a list of the application packages for which the usage authority can be assigned to the user based on a role assigned to the user and a role set in the application package.</u>The present invention provides one or more information processing devices.</p>
<p>The present invention can provide one or more information processing devices capable of setting a role for an application package.</p>
<figref num="1">1 is a diagram for explaining an outline of setting a role for an application package and assigning the application package to a user. FIG.</figref><figref num="2">FIG. 1 is a configuration diagram of an example of an information processing system.</figref><figref num="3">FIG. 2 is a diagram illustrating a hardware configuration of an example of a computer.</figref><figref num="4">FIG. 2 is a diagram illustrating a hardware configuration of an example of an image forming apparatus.</figref><figref num="5">FIG. 2 is an example of a functional block diagram illustrating functions of a first terminal device, a second terminal device, a third terminal device, an electronic device, and one or more information processing devices, divided into blocks. </figref><figref num="6">FIG. 1 is an example of a sequence diagram showing a procedure for a product designer to create an app package.</figref><figref num="7">13 is an example of a sequence diagram illustrating a procedure in which a product designer associates an application package with a tenant. </figref><figref num="8">FIG. 13 illustrates an example of a new package creation screen.</figref><figref num="9">FIG. 13 illustrates an example of a new package creation screen.</figref><figref num="10">13 is a diagram showing an example of an application list screen. </figref><figref num="11">FIG. 13 illustrates an example of a tenant list screen.</figref><figref num="12">FIG. 13 illustrates an example of a tenant information screen.</figref><figref num="13">FIG. 13 is a diagram illustrating an example of a list screen of unintroduced packages.</figref><figref num="14">11 is an example of a sequence diagram illustrating a process and operation in which a tenant administrator registers a user in a tenant.</figref><figref num="15">FIG. 13 is a diagram showing an example of a user information registration screen.</figref><figref num="16">FIG. 13 is a diagram showing an example of an available package list screen.</figref><figref num="17">FIG. 13 is a diagram showing an example of a user registration email sending screen.</figref><figref num="18">11 is an example of a sequence diagram illustrating a process and an operation at the time of a user's login.</figref><figref num="19">FIG. 13 illustrates an example of a login screen.</figref><figref num="20">13 is an example of a home screen displayed on a first terminal device after a tenant administrator logs in. </figref><figref num="21">FIG. 13 is a diagram showing an example of a home screen displayed on a second terminal device to which a general user has logged in;</figref><figref num="22">11 is an example of a sequence diagram illustrating a process in which a tenant administrator assigns an application package to a registered user.</figref><figref num="23">FIG. 13 is a diagram illustrating an example of an application package usage authority management screen.</figref><figref num="24">FIG. 13 is an example of a sequence diagram showing a procedure in which a product designer adds an app to an app package.</figref><figref num="25">FIG. 13 is a diagram illustrating an example of an application list screen.</figref><figref num="26">FIG. 11 illustrates an example of an application selection screen.</figref>
An information processing system and a role setting method performed by the information processing system will be described below as an example of an embodiment of the present invention.
<Outline of Operation> First, an outline of the operation performed by the information processing system 1 will be described with reference to Fig. 1. Fig. 1 is a diagram for explaining an outline of setting a role to an application package and assigning the application package to a user. First, in the information processing system 1, the usage authority of an application and an application package is determined by a role. In this embodiment, there are the following roles.
Tenant administrator C: A person who manages the use of services by users and tenant administrators in the customer environment within the scope of the contract between the company and the service provider. This is mainly a person in charge on the tenant side. For example, they register general users to the tenant, manage the account status of general users, and register services that can be used by general users.
- General user: A user who can use the service if usage rights are assigned.
In addition, in this embodiment, there is also a role called product designer P, but this is distinguished from a role. Product designer P is a person who creates application packages. He is mainly a person in charge on the service provider side. In this embodiment, roles are registered in application packages. In addition to these, roles may also include a usage authority manager who manages usage authority for each application user, and a contract manager who manages contracts for application packages. These multiple roles can be set in the service provider environment and usage restrictions in the customer environment, as described below.
(1) In a service provider environment, a product designer P sets, for an application package, a role (general user or tenant administrator C) that can use this application package. One or more information processing devices 50 have a package management unit 53 that manages the application package, and the role of the application package is set in the package management unit 53.
(2) On the other hand, in the customer environment, the tenant administrator C can register users belonging to the tenant, and a role (general user, tenant administrator C, etc.) is set for each user in the user management unit 55 of one or more information processing devices 50.
(3) When the tenant administrator C assigns an app package to each user, the one or more information processing devices 50 obtain the user's role from the user management unit 55 and extract app packages in which the same role as the user's role is set from the package management unit 53. The one or more information processing devices 50 provide the tenant administrator C with only app packages that match the user's role, so the tenant administrator C can assign usage authority of the app package only to users who have the role set in the app package. Therefore, it is possible to permit or restrict users from using the app package.
In this manner, the information processing system 1 of this embodiment allows the product designer P to set a role for an application package, and can prevent the usage authority of the application package from being assigned to a user that the tenant administrator C does not want to use the application package.
<Terminology> A tenant is a customer that shares the same software with multiple customers, i.e., information that indicates a company or other group of customers. Each user in the tenant can use the application package contracted with the tenant, and the tenant administrator of the tenant can grant users permission to use multiple software instances (application packages and each application within them) that exist in the system.
An application (hereinafter, simply referred to as an app) is a program executed by a terminal device and an information processing device in order for a user to receive a service. A program executed cooperatively by a terminal device and an information processing device is also called a web app. An app may be, for example, a workflow app that executes a series of processes in sequence. An app can be built by combining components by a tenant administrator C or the like. For example, by combining a document reading component and a cloud transmission component, an app can be built that uploads a document read by an electronic device to cloud storage and stores it.
An app package is one or more apps sold as a set. A set may contain only one app, but it is a set of apps that are commonly used in business or related and sold together for user convenience.
It is a role within a tenant. Roles are granted rights according to the role. For example, the tenant administrator decides on a role by considering the user's job type, job title, and how the app will be used. Not only when the user's role and the app package's role match, but also when the user's role has greater rights than the app package's role, it is possible to assign the user permission to use the app package.
<System Configuration Example> Fig. 2 is a configuration diagram of an example of an information processing system 1 according to this embodiment. In the information processing system 1 in Fig. 2, a customer environment 8 and a service provider environment 7 are connected to one or more information processing devices 50 via a network N1 such as the Internet. The network N1 also includes telephone lines such as a mobile phone network.
A customer is a customer of a service provided by one or more information processing devices 50, and includes organizations such as a company, an organization, an educational institution, an administrative agency, or a department. A person who has some employment relationship with these customers is called a user. In the customer environment 8, one or more electronic devices 10, a first terminal device 20, a second terminal device 30, and a firewall 16 are connected via a network N2 such as a LAN. In addition, the one or more information processing devices 50 have one or more information processing devices connected to the network N1. A service provider is a business that provides a service to a customer. In the service provider environment 7, a third terminal device 40 exists.
The electronic device 10 is, for example, an image forming device 10a, but the image forming device 10a also includes a laser printer, a multifunction device (multifunction printer), an MFP (Multi-function Peripheral/Product/Printer), etc. Another example of the electronic device 10 is an electronic whiteboard 10b. In addition, the electronic device 10 may be, for example, a PJ (Projector), an output device such as digital signage, a HUD (Head Up Display) device, industrial machinery, an imaging device, a sound collection device, a medical device, a network home appliance, an automobile (Connected Car), a notebook PC, a mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, a desktop PC, etc.
The electronic device 10 of this embodiment serves as a terminal through which a user registered in one or more information processing devices 50 uses a service. The user logs into one or more information processing devices 50 from the electronic device 10, selects an application (application software) that the user has permission to use, and receives a service provided by one or more information processing devices 50. In this manner, a service is provided on an application-by-application basis.
The first terminal device 20 is an information processing device such as a smartphone, mobile phone, tablet PC, desktop PC, or notebook PC used by the tenant administrator C. The first terminal device 20 is equipped with a program having a screen display function such as a web browser. This program is not limited to a web browser as long as it has a function of displaying screen information received from the information processing device as a screen. It may also be a program dedicated to one or more information processing devices 50.
The second terminal device 30 is an information processing device used by a user, such as a smartphone, a mobile phone, a tablet PC, a desktop PC, or a notebook PC. The second terminal device 30 is equipped with a program having a screen display function, such as a web browser. This program is not limited to a web browser as long as it has a function of displaying screen information received from the information processing device as a screen. One or more programs dedicated to the information processing device 50 may also be used.
The third terminal device 40 is an information processing device such as a smartphone, mobile phone, tablet PC, desktop PC, or notebook PC used by the product designer P. The third terminal device 40 is equipped with a program having a screen display function such as a web browser. This program is not limited to a web browser as long as it has a function of displaying screen information received from the information processing device as a screen. One or more programs dedicated to the information processing device 50 may also be used.
The firewall 16 is a device for preventing intrusion into the customer environment 8 from the outside, and all communications from the customer environment 8 are monitored by the firewall 16. However, this does not apply to the case where the first terminal device 20, the second terminal device 30, or the third terminal device 40 communicates with one or more information processing devices 50 via telephone lines such as a mobile phone network.
The one or more information processing devices 50 provide various services to the electronic device 10, the second terminal device 30, etc. The services vary depending on the type of electronic device 10. In the case of the image forming device 10a, there are services such as a service for uploading and saving a scanned document to a cloud storage, and a service for downloading and printing image data from a cloud storage, but are not limited to these. In the case of the electronic whiteboard 10b, there are services such as a service for creating minutes by performing real-time voice recognition, and a service for converting handwritten data into text. In the case of the second terminal device 30, there are services such as a real-time translation service for web pages.
Tenants and users are associated with each other in one or more information processing devices 50. The services (applications) that can be used are determined according to the user's role, and the user uses the applications that he or she can use from the electronic device 10 or the second terminal device 30. In addition, there is the following relationship between the tenants, the tenant administrator C, and the users.
- One customer -> one tenant (tenant administrator C and users belong to one tenant) - One customer -> multiple tenants (tenant administrator C does not necessarily belong to a tenant, but manages each tenant and the users who belong to it. Users belong to one or more tenants) In either case, a user registered in one or more information processing devices 50 belongs to a tenant, so once a user is identified after registration, the tenant to which the user belongs is also identified. In the case of one customer -> one tenant, the tenant is automatically determined when the tenant administrator C logs in to the tenant (there is no need to specify the tenant). In the case of one customer -> multiple tenants, it is recommended that the tenant administrator C specify the tenant when logging in (or have a different account for each tenant).
The one or more information processing devices 50 create screen information of a Web page to be displayed on the first terminal device 20, the second terminal device 30, the third terminal device 40, or the electronic device 10, and transmit it to these devices. For example, a new package creation screen, a user information registration screen, a package allocation screen, a login screen, and the like, which will be described later, are displayed.
Screen information is created using HTML, XML, CSS (Cascade Style Sheet), JavaScript (registered trademark), and the like. Web pages may be provided by Web applications. A Web application is software or a mechanism executed on a Web browser that operates through cooperation between a program written in a programming language (e.g. JavaScript (registered trademark)) that runs on a Web browser and a program on the Web server side. Web pages can be dynamically changed by Web applications.
The one or more information processing devices 50 may be compatible with cloud computing. Cloud computing refers to a usage form in which resources on a network are used without being aware of specific hardware resources. One or more information processing devices 50 compatible with cloud computing may be called a cloud system. The cloud system may be located on the Internet or on-premise.
2 is an example, and one or more server devices (such as a proxy server or a gateway server) may be interposed between the customer environment and the information processing device. The first terminal device 20 and the second terminal device 30 may be located outside the customer environment, for example, connected to the network N1. The third terminal device 40 may be located outside the service provider environment, for example, connected to the network N1.
The one or more information processing devices 50 may be realized by one information processing device 49, or may be distributed and realized by multiple information processing devices 49. For example, there may be an information processing device 49 that provides each service, one information processing device 49 may provide multiple services, or multiple information processing devices 49 may provide one service.
In addition, in the information processing system 1 in Fig. 2, the information processing device is connected to a network N1 such as the Internet outside the customer environment. In other words, the information processing system 1 in Fig. 2 is an example in which one or more information processing devices 50 are provided in a cloud environment. However, one or more information processing devices 50 may be provided inside the customer environment (on-premise environment).
<Hardware Configuration Example> <Computer> The first terminal device 20, the second terminal device 30, the third terminal device 40, or one or more information processing devices 50 in Fig. 2 are realized by a computer having a hardware configuration shown in Fig. 3, for example. Fig. 3 is a hardware configuration diagram of an example of a computer. The computer 500 in Fig. 3 is constructed by a computer, and as shown in Fig. 3, includes a CPU 501, a ROM 502, a RAM 503, a HD 504, a HDD controller 505 (Hard Disk Drive), a display 506, an external device connection I/F 508 (Interface), a network I/F 509, a bus line 510, a keyboard 511, a pointing device 512, a DVD-RW drive 514 (Digital Versatile Disk Rewritable), and a media I/F 516.
Among these, the CPU 501 controls the operation of the entire computer. The ROM 502 stores programs such as IPL used to drive the CPU 501. The RAM 503 is used as a work area for the CPU 501. The HD 504 stores various data such as programs. The HDD controller 505 controls reading or writing of various data from the HD 504 under the control of the CPU 501. The display 506 displays various information such as a cursor, a menu, a window, a character, or an image. The external device connection I/F 508 is an interface for connecting various external devices. In this case, the external device is, for example, a USB (Universal Serial Bus) memory or a printer. The network I/F 509 is an interface for data communication using the communication network 100. The bus line 510 is an address bus, a data bus, or the like for electrically connecting each component such as the CPU 501 shown in FIG. 3.
Moreover, the keyboard 511 is a type of input means having a plurality of keys for inputting characters, numbers, various instructions, etc. The pointing device 512 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The DVD-RW drive 514 controls reading and writing of various data from a DVD-RW 513 as an example of a removable recording medium. Note that this is not limited to DVD-RW, and may be DVD-R, etc. The media I/F 516 controls reading and writing (storing) of data from a recording medium 515 such as a flash memory.
<<Image forming apparatus>> Fig. 4 is a hardware configuration diagram of an example of the image forming apparatus 10a. As shown in Fig. 4, the image forming apparatus 10a includes a controller 910, a short-range communication circuit 920, an engine control unit 930, an operation panel 940, and a network I/F 950.
Of these, the controller 910 has a CPU 901 which is the main part of the computer, a system memory 902 (MEM-P), a north bridge 903 (NB), a south bridge 904 (SB), an ASIC 906 (Application Specific Integrated Circuit), a local memory 907 (MEM-C) which is a storage unit, an HDD controller 908, and an HD 909 which is also a storage unit, and is configured such that the NB 903 and the ASIC 906 are connected by an AGP bus 921 (Accelerated Graphics Port).
Among these, the CPU 901 is a control unit that performs overall control of the image forming apparatus 10a. The NB 903 is a bridge for connecting the CPU 901 with the MEM-P 902, the SB 904, and the AGP bus 921, and includes a memory controller that controls reading and writing to the MEM-P 902, a PCI (Peripheral Component Interconnect) master, and an AGP target.
The MEM-P 902 is composed of a ROM 902a which is a memory for storing programs and data for implementing the various functions of the controller 910, and a RAM 902b which is used for developing the programs and data, and as a drawing memory during memory printing, etc. The programs stored in the RAM 902b may be provided by being recorded in a computer-readable recording medium such as a CD-ROM, CD-R, or DVD in the form of an installable or executable file.
The SB904 is a bridge for connecting the NB903 with PCI devices and peripheral devices. The ASIC906 is an IC (Integrated Circuit) for image processing purposes that has hardware elements for image processing, and plays the role of a bridge connecting the AGP bus 921, the PCI bus 922, the HDD controller 908, and the MEM-C907. The ASIC906 is made up of a PCI target and an AGP master, an arbiter (ARB) that is the core of the ASIC906, a memory controller that controls the MEM-C907, a plurality of DMACs (Direct Memory Access Controllers) that rotate image data using hardware logic, and a PCI unit that transfers data between the scanner unit 931 and the printer unit 932 via the PCI bus 922. The ASIC906 also has a USB (Universal Serial Bus) interface and an IEEE1394 (Institute of Electrical and Electronics Engineers 1394) interface may be connected.
The MEM-C907 is a local memory used as an image buffer for copying and a code buffer. The HD909 is a storage for storing image data, font data used during printing, and forms. The HD909 controls the reading and writing of data from and to the HD909 under the control of the CPU901. The AGP bus 921 is a bus interface for a graphics accelerator card proposed to speed up graphic processing, and by directly accessing the MEM-P902 at high throughput, the graphics accelerator card can be made faster.
Further, the short-range communication circuit 920 includes a short-range communication circuit antenna 920a. The short-range communication circuit 920 is a communication circuit such as NFC or Bluetooth (registered trademark).
Further, the engine control unit 930 is composed of a scanner unit 931 and a printer unit 932. The operation panel 940 includes a panel display unit 940a such as a touch panel that displays current setting values and a selection screen, etc., and receives input from an operator, and hard keys 940b including a numeric keypad that receives setting values for image formation conditions such as density setting conditions, and a start key that receives a copy start instruction. The controller 910 controls the entire image forming apparatus 10a, and controls, for example, drawing, communication, and input from the operation panel 940. The scanner unit 931 or the printer unit 932 includes an image processing unit such as error diffusion and gamma conversion.
The image forming apparatus 10a can sequentially switch among the document box function, copy function, printer function, and facsimile function by using an application switching key on the operation panel 940. When the document box function is selected, the document box mode is selected, when the copy function is selected, the copy mode is selected, when the printer function is selected, the printer mode is selected, and when the facsimile mode is selected, the facsimile mode is selected.
The network I/F 950 is an interface for performing data communication using the communication network 100. The short-range communication circuit 920 and the network I/F 950 are electrically connected to the ASIC 906 via a PCI bus 922.
<Functions> The functions of each device in the information processing system 1 according to this embodiment are realized, for example, by the processing blocks shown in Fig. 5. Fig. 5 is an example of a functional block diagram in which the functions of the first terminal device 20, the second terminal device 30, the third terminal device 40, the electronic device 10, and one or more information processing devices 50 are divided into blocks and explained.
<<First Terminal Device>> The first terminal device 20 has a first communication unit 22, a display control unit 23, and an operation receiving unit 24. The first terminal device 20 executes a program (e.g., a Web browser 21) to realize functional blocks as shown in FIG.
The first communication unit 22 communicates with one or more information processing devices 50 to receive screen information for displaying a user information registration screen or the like on the first terminal device 20. The first communication unit 22 also transmits information input by the tenant administrator C on the user information registration screen or the like to one or more information processing devices 50.
The display control unit 23 analyzes screen information received from one or more information processing devices 50, and displays, for example, a user information registration screen on the display 506. The operation receiving unit 24 receives operations by the tenant administrator C on the first terminal device 20 (for example, input to the user information registration screen or package allocation screen).
<<Second Terminal Device>> The second terminal device 30 has a second communication unit 32, a display control unit 33, and an operation receiving unit 34. The second terminal device 30 executes a program (e.g., a Web browser 31) to realize the functional blocks shown in FIG.
The second communication unit 32 communicates with one or more information processing devices 50 to receive screen information for displaying a login screen, a home screen, or the like on the second terminal device 30. In addition, the second communication unit 32 transmits information input by the user to the login screen or the home screen to one or more information processing devices 50.
The display control unit 33 analyzes screen information received from one or more information processing devices 50, and displays, for example, a login screen or a home screen on the display 506. The operation accepting unit 34 accepts operations on the second terminal device 30 by the user.
<<Third Terminal Device>> The third terminal device 40 has a third communication unit 42, a display control unit 43, and an operation receiving unit 44. The third terminal device 40 executes a program (e.g., a Web browser 31) to realize the functional blocks shown in FIG.
The third communication unit 42 communicates with one or more information processing devices 50 to receive screen information for displaying a new package creation screen or the like on the third terminal device 40. Also, the third communication unit 42 transmits information input by the product designer P on the new package creation screen to the one or more information processing devices 50.
The display control unit 43 analyzes screen information received from one or more information processing devices 50, and displays, for example, a new package creation screen on the display 506. The operation receiving unit 34 receives operations from the product designer P on the third terminal device 40.
<<Electronic Device>> The electronic device 10 has a fourth communication unit 12, a display control unit 13, and an operation reception unit 14. The electronic device 10 executes a program (for example, a Web browser 11) to realize functional blocks as shown in FIG.
The fourth communication unit 12 communicates with one or more information processing devices 50 to receive screen information for displaying a standby screen, a launcher screen, a login screen, an application screen, etc. on the electronic device 10. The fourth communication unit 12 also transmits information input by the user to the standby screen, the launcher screen, the login screen, and the application screen to one or more information processing devices 50.
The display control unit 13 analyzes screen information received from one or more information processing devices 50, and displays, for example, a standby screen, a launcher screen, a login screen, and an application screen on the operation panel 940. The operation accepting unit 14 accepts user operations on the electronic device 10 (for example, starting up a launcher, inputting authentication information, selecting an application, an operation on an application, etc.).
<<One or More Information Processing Devices>> The one or more information processing devices 50 have a fifth communication unit 52, a package management unit 53, an authentication unit 54, a user management unit 55, an application management unit 56, and a tenant management unit 57. These functions of the one or more information processing devices 50 are functions or means realized by the CPU 501 of the computer 500 shown in FIG. 3 executing a program loaded from the HD 504 to the RAM 503.
The fifth communication unit 52 transmits and receives various information to and from the first terminal device 20, the second terminal device 30, the third terminal device 40, and the electronic device 10. For example, it transmits screen information of a user information registration screen and a package allocation screen to the first terminal device 20, transmits screen information of a login screen and a home screen to the second terminal device 30, transmits screen information of a new package creation screen and the like to the third terminal device 40, and transmits screen information of a standby screen, a launcher screen, a login screen, and an application screen to the electronic device 10. It also receives information input on these screens.
The package management unit 53 manages application package information stored in a package information storage unit 591 described later. For example, the package management unit 53 registers application package information transmitted from the third terminal device 40, and acquires application package information from the package information storage unit 591.
The authentication unit 54 authenticates the product designer P, the tenant administrator C, and the user, and determines whether the authentication is successful or unsuccessful. Authentication refers to judging whether the person requesting authentication is a legitimate authority. In the case of this embodiment, it refers to whether the person has the authority to use one or more information processing devices 50, and further, it is possible to judge whether the product designer P, the user, or the tenant administrator C is authorized to log in to one or more information processing devices 50. Login refers to an authentication action to access system resources using account information registered in advance when using various services on a computer or the Internet. The account information is a user ID and password, an IC card number, or biometric authentication information, etc.
The user management unit 55 manages user information, and performs operations such as registering the user information in a user information storage unit 592 (described later) and acquiring (reading) the user information from the user information storage unit 592.
The application management unit 56 manages each application, manages default settings of the application for each user, and reflects the default settings in the application.
The tenant management unit 57 manages tenant information related to tenants, and stores and retrieves the tenant information in the tenant information storage unit 594 .
Furthermore, the one or more information processing devices 50 have a storage unit 59 realized by the HD 504, the RAM 503, etc. shown in Fig. 3. The storage unit 59 has a package information storage unit 591, a user information storage unit 592, an application information storage unit 593, and a tenant information storage unit 594. The package information storage unit 591 will be described with reference to Table 1.
<tables><img file="JP7605264B2_D0001.tif" /></tables> Table 1 illustrates the application package information stored in the package information storage unit 591. The application package information is associated with a tenant ID, and includes items such as a package name, a description, a device type, available roles, and an application list.
A tenant ID is identification information for identifying a tenant. ID is an abbreviation of Identification and means identifier or identification information. An ID is a name, code, character string, number, or a combination of one or more of these that is used to uniquely distinguish a specific object from multiple objects. The same applies to IDs other than tenant IDs.
Package name: This is the name of the package created by product designer P. It is good if it has an identifying function.
Description: A description of the package created by product designer P. Product designer P can set any information.
Device Type: The type of electronic device that can be used with the application package licensed to the electronic device (e.g., electronic whiteboard, image forming device).
Available roles: These are the roles available on the tenant when the app package created by product designer P is introduced. These are the roles of users who have the authority to use this app package. For example, this is set to tenant administrator C or a general user.
App list...Identification information (app ID) of the apps included in the app package.
<tables><img file="JP7605264B2_D0002.tif" /></tables> Table 2 shows a schematic diagram of user information stored in the user information storage unit 592. User information is associated with a tenant ID. That is, there is as much user information as there are users belonging to a tenant. Note that the users in the user information storage unit 592 include the tenant administrator C. The tenant administrator C registers the user information by connecting to one or more information processing devices 50.
The user information includes each item such as a tenant ID, a user ID, a password, a gender, a first name, an email address, a display language (locale), an account status, a role, and an initial setting of application usage permissions.
Tenant ID: Identification information of the tenant to which the user belongs.
User ID...User identification information.
Password...Confidential information that proves the user's identity.
Last name...The user's last name.
First name...The user's name.
Email address: The user's email address.
Display language (locale)...The language of the characters displayed on the screen used by the user.
Account status: An account is a right for a user to log in to one or more information processing devices 50. There are at least three account states: "valid, invalid, or account locked." When user information is provisionally registered, the account is invalid, and when the user information is fully registered, the account is valid. Even after the account is valid, the tenant administrator C can set the account to invalid. An account is locked when the user enters the wrong password several times while the account is valid. An account is locked differently from an invalid account in that the account reverts to valid after a certain period of time has passed, or in that the account remains counted as a user belonging to the tenant.
Role: the authority of the user. For example, there is "tenant administrator C or general user." In this embodiment, the tenant administrator and general users are called users.
· Initial settings of app usage authority... A list of app packages available to this user. It has a list of app packages for which usage authority is assigned to the user.
The tenant ID, account status, role, and "initial settings for app usage permissions" that are not blank in Table 2 are automatically determined. The user ID, password, last name, first name, email address, and display language (locale) that are blank in Table 2 are set by tenant administrator C.
<tables><img file="JP7605264B2_D0003.tif" /></tables> Table 3 shows a schematic diagram of the application information stored in the application information storage unit 593. The application information has items of application ID and role in association with the tenant ID. The application information is registered by the product designer P according to the service contract status. The application information may be registered automatically according to the service contract. Each application may or may not belong to an application package.
Tenant ID: Identification information of the tenant in which the app was sold.
App ID...Identification information for the app.
Role: The authority to use the app. For example, "tenant administrator C or general user." Either role in the app package can take priority.
<tables><img file="JP7605264B2_D0004.tif" /></tables> Table 4 illustrates the tenant information stored in the tenant information storage unit 594. The tenant information has items of tenant name and registration date in association with the tenant ID.
Tenant ID: Tenant identification information.
- Tenant name: The name of the tenant, such as the company name or department name.
- Registration date: The date the tenant was registered.
It should be noted that Tables 1 to 4 are shown merely for the purpose of explaining this embodiment, and non-main information is omitted.
<Application Package Creation Process and Operation> FIG. 6 is an example of a sequence diagram showing the procedure by which a product designer P creates an application package.
S1: First, the product designer P operates the third terminal device 40 to perform a login operation to one or more information processing devices 50 (enter authentication information).
S2: The operation acceptance unit 44 of the third terminal device 40 accepts an operation, and the third communication unit 42 transmits an authentication request to one or more information processing devices 50.
S3: The fifth communication unit 52 of the one or more information processing devices 50 receives the authentication request, and the authentication unit 54 authenticates the product designer P based on the authentication information. Here, it is assumed that the authentication is successful.
Only product designer P is permitted to create an app package or set a role; tenant administrators or general users cannot set a role for an app package. In other words, if the authentication unit authenticates that the user is a tenant administrator or a general user, it does not allow the user to set a role for an app package. This type of processing can be achieved by restricting the display of the new package creation screen described below only when product designer P logs in.
S4: The product designer P inputs an operation to open a new package creation screen into the third terminal device 40. The product designer may set the role to which the usage authority may be assigned for each application included in the application package. In that case, the role for the application package on the new package creation screen (the role that is set collectively for all applications included in the package) is selected as "Do not set."
S5: The operation acceptance unit 44 of the third terminal device 40 accepts the operation, and the third communication unit 42 requests one or more information processing devices 50 to transmit a new package creation screen.
S6: The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the new package creation screen, and the package management unit 53 generates screen information for the new package creation screen. The screen information for the new package creation screen is transmitted to the third terminal device 40, and the display control unit 43 of the third terminal device 40 displays the new package creation screen. An example of the new package creation screen is shown in FIG.
S7: Product designer P inputs app package information, including roles to which usage rights may be assigned, into the new package creation screen.
S8: Product designer P inputs the command to create a new app package (create the package).
S9: The operation acceptance unit 44 of the third terminal device 40 accepts the input, and the third communication unit 42 requests the one or more information processing devices 50 to provide the input application package information.
S10: The fifth communication unit 52 of the one or more information processing devices 50 receives the application package information, and the package management unit 53 causes the package information storage unit 591 to store the application package information.
S11: Next, the product designer P inputs an operation to display a list of applications into the third terminal device 40 in order to register the application in the application package.
S12: The operation acceptance unit 44 of the third terminal device 40 accepts an input, and the third communication unit 42 sends an application list request to one or more information processing devices 50.
S13: The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the application list, and the application management unit 56 generates screen information of the application list by referring to the application information storage unit 593. The list of applications that the product designer P can include in the application package is predetermined based on the service content of the client. The screen information of the application list is transmitted to the third terminal device 40, and the display control unit 43 of the third terminal device 40 displays the application list screen. An example of the application list screen is shown in FIG. 10.
S14: The product designer P selects an app from the app list screen. When setting a role for each app, the product designer P may set a role for each app each time an app is selected. At that time, if a role has already been set for the app package (as a whole), the product designer P changes (cancels) the role for the app package to none. The operation acceptance unit 44 of the third terminal device 40 accepts the cancellation. Alternatively, the execution of the change (cancellation) may be accepted via a change confirmation screen. If the operation acceptance unit 44 accepts the cancellation of the role for the app package, it continues to accept the setting of a role that can use the app, but if the role for the app package is not cancelled, the operation acceptance unit 44 does not accept the setting of a role that can use the app.
S15: The operation acceptance unit 44 of the third terminal device 40 accepts the selection of the application, and the third communication unit 42 requests one or more information processing devices 50 for identification information of the application.
S16: The fifth communication unit 52 of the one or more information processing devices 50 receives the identification information of the application, and registers the application in the application package created by the package management unit 53.
S17: Product designer P inputs to the application list screen that the application package creation is complete. For example, the product designer P presses the Finish button displayed in the message notifying the completion of application registration, or presses the Creation Complete button prepared on the application list screen.
S18: The operation reception unit 44 of the third terminal device 40 receives the creation completion, and the third communication unit 42 requests the one or more information processing devices 50 to complete the package creation.
S19: The fifth communication unit 52 of the one or more information processing devices 50 receives the creation completion notification, and stores the application package created by the package management unit 53.
The above process creates an app package. At this point, the app package has been created, but it is not associated with a tenant. Next, product designer P associates the app package with a tenant.
FIG. 7 is an example of a sequence diagram showing a procedure in which a product designer P associates an application package with a tenant.
S21 to S23: Login can be performed in the same manner as steps S1 to S3 in Fig. 6. If the product designer P continues to operate as in Fig. 6, he or she does not need to log in.
S24: Next, the product designer P inputs an operation to the third terminal device 40 to display a tenant list screen.
S25: The operation reception unit 44 of the third terminal device 40 receives the input, and the third communication unit 42 requests a tenant information list from one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the tenant information list, and the tenant management unit 57 generates screen information of the tenant list by referring to the tenant information storage unit 594. The tenant list is a list of tenants to which the product designer P can assign an application package. For example, it may be a tenant (e.g., a customer list) that has contracted for a service. The screen information of the tenant list is transmitted to the third terminal device 40, and the display control unit of the third terminal device 40 displays the tenant list screen. An example of the tenant list screen is shown in FIG. 11.
S26: Next, the product designer P selects a tenant to which the application package is to be assigned on the tenant list screen.
S27: The operation acceptance unit 44 of the third terminal device 40 accepts the selection, and the third communication unit 42 transmits the identification information of the tenant to one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the identification information of the tenant, and the tenant management unit 57 generates screen information of the tenant information associated with the identification information of the tenant by referring to the tenant information storage unit 594. The screen information of the tenant information is transmitted to the third terminal device 40, and the display control unit 43 of the third terminal device 40 displays the tenant information screen. An example of the tenant information screen is shown in FIG. 12.
S28: Next, the product designer P inputs an operation to add an app package to the tenant.
S29: The operation acceptance unit 44 of the third terminal device 40 accepts the operation, and the third communication unit 42 requests the one or more information processing devices 50 for identification information of the tenant.
S30: The fifth communication unit 52 of one or more information processing devices 50 receives the identification information of the tenant, and the package management unit 53 registers the tenant ID in association with the application package in the package information storage unit 591.
This creates package information with a role set for the app package.
<Screen Examples When Creating an Application Package> Screen examples when creating an application package will be described with reference to Fig. 8 to Fig. 13. Fig. 8 and Fig. 9 are an example of a new package creation screen 200. The new package creation screen 200 is a screen on which a product designer P creates an application package.
Package name field 201: A field in which the name of the application package is input.
Service type column 202: Identification information of the application package.
Description field 203: A description of the application package.
License control field 204: Whether or not the device type item of the package information is enabled is set here. Fig. 9 shows the new package creation screen 200 when the license control field 204 is set to "enabled".
Device control field 205: displayed when the license control field is set to "enabled." This field corresponds to the device type item of the application package information, and is used to set the type of electronic device in the case of an application package licensed to an electronic device.
Publication range column 206: The range to which the application package is published.
Available roles column 207: These are the roles of users for whom the tenant administrator C can set usage authority for this application package.
10 is an example of the application list screen 210. The application information screen has a similar configuration.
Application name field 211: A field in which the name of the application to be searched for is input.
Status column 212: This column specifies the status of the application to be searched for (whether the application is at capacity and unavailable, etc.).
App List 213: A field that displays a list of apps that match the search. Before the search, nothing may be displayed, or all may be displayed. The app name, description, app type, status, and creation date are displayed.
11 is an example of the tenant list screen 220. The tenant list screen 220 is a screen for selecting a specific tenant (a tenant to which an application package is to be assigned) from a customer list (tenant list).
Customer name field 221: A field in which the tenant name of the tenant to be searched is input.
Tenant ID field 222: A field in which the tenant ID of the tenant to be searched is input.
Registration date field 223: A field in which the registration date of the tenant to be searched for is input.
Status column 224: A column in which the status of the tenant to be searched for (in service, before service has started, etc.) is specified.
Tenant List 225: A field that displays a list of tenants that match the search. Before the search, nothing may be displayed, or all may be displayed. The tenant list displays the customer name, tenant ID, status, and registration date.
When a product designer P selects a tenant name on the tenant list screen 220 in Fig. 11, a tenant information screen 230 in Fig. 12 is displayed. Fig. 12 is a diagram showing an example of the tenant information screen 230. The tenant information screen 230 is a screen for adding an application package to a specific tenant. The tenant information screen displays a list 231 of application packages that have been introduced to this tenant. This list 231 is displayed based on the application packages associated with the tenant ID in the package information storage unit 591.
The tenant information screen 230 has an Add button 232, and when the product designer P presses the Add button 232, an unintroduced package list screen 240 in Fig. 13 is displayed. Fig. 13 shows an example of the unintroduced package list screen 240. The unintroduced package list screen 240 is a screen that displays application packages that are not associated with the tenant selected in Fig. 11.
Package name field 241: A field in which the name of the application package to be searched for is input.
Package List 242: A field that displays a list of application packages that match the search. Before the search, nothing may be displayed, or all may be displayed.
Add button 243: A button for associating the application package selected by the radio button 244 at the top of the package list with the tenant.
In this manner, the application package selected in FIG. 13 is associated with the tenant selected in FIG.
<User Registration Process and Operation> Next, the process and operation of the tenant administrator C registering a user in a tenant will be described with reference to Fig. 14. Fig. 14 is an example of a sequence diagram illustrating the process and operation of the tenant administrator C registering a user in a tenant.
S41 to S43: The login operation may be the same as steps S1 to S3 in FIG.
S44: The tenant administrator C inputs an operation to open a user information registration screen into the first terminal device 20.
S45: The operation reception unit 24 of the first terminal device 20 receives the operation, and the first communication unit 22 requests a user information registration screen from one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the user information registration screen, and the user management unit 55 generates screen information for the user information registration screen. The screen information for the user information registration screen is transmitted to the first terminal device 20, and the display control unit 23 of the first terminal device 20 displays the user information registration screen. An example of the user information registration screen is shown in FIG. 15.
S46: The tenant administrator C inputs user information including the role into the user information registration screen. The operation reception unit 24 of the first terminal device 20 receives the input.
S47: Tenant administrator C performs an operation to display a list of application packages available to this user.
S48: The operation reception unit 24 of the first terminal device 20 receives the input, and the first communication unit 22 requests a list of available application packages together with the user's role from one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the list of available application packages, and the package management unit 53 searches the package information storage unit 591 by the user's role. The package management unit 53 generates screen information of a list screen of application packages that matches the search. The screen information of the list screen of available application packages is transmitted to the first terminal device 20, and the display control unit 23 of the first terminal device 20 displays the list screen of available application packages. An example of the list screen of application packages is shown in FIG. 16.
S49: The tenant administrator C assigns an application package to the user on the screen listing available application packages. In other words, the tenant administrator C accepts the selection of an application package. This allows the user to be permitted or restricted from using the application package.
S50: The operation acceptance unit 24 of the first terminal device 20 accepts an input, and the first communication unit 22 requests one or more information processing devices 50 to register user information including identification information of the selected application package.
S51: The fifth communication unit 52 of one or more information processing devices 50 receives a request to register user information, and the user management unit 55 registers the user information in the user information storage unit 592. That is, the user management unit 55 accepts the association between an application package and a tenant that receives a service using the application package.
This allows the tenant administrator C to use the roles set in the app package to assign usage permissions for the app package only to users that he or she wants to use.
<Examples of Screens for Registering User Information> Examples of screens for registering user information will be described with reference to Fig. 15 to Fig. 17. Fig. 15 is an example of a user information registration screen 250. The user information registration screen 250 is a screen on which the tenant administrator C registers user information.
User ID column 251: A column in which the user ID is input.
Email address field 252: A field in which the user's email address is entered.
Last name field 253: A field in which the user's last name is entered.
First name field 254: A field in which the user's first name is entered.
E-mail reply language 255: This is a field in which the language used when one or more information processing devices 50 reply to an e-mail is set.
Role column 256: This is a column in which the role of the tenant administrator C or a general user is set.
Function account link setting field 257: This is a field where an electronic device is selected when linking user information with an account of the electronic device.
Application use authority initial setting field 258: A field for selecting an application package by pressing a Select Application button 259. Pressing the Select Application button 259 transitions to a usable package list screen 260 in FIG.
16 is an example of the usable package list screen 260. The usable package list screen 260 displays a list of application packages usable by the role of the user to be registered. In the usable package list screen 260, application names 261 and number of uses 262 are associated with each other. This application name 261 is the name of an application package that can be used by the user's role. Furthermore, the number of uses 262 is the current number of allocations (numerator) relative to the upper limit of the number that can be allocated (denominator) determined by the contract. Tenant administrator C checks a check box 263 to select an application package to which usage rights are to be assigned.
If the current allocation number (numerator) has reached the upper limit of the allocable number (denominator), check box 263 is not displayed, the application name and usage number are displayed in half brightness, and tenant administrator C cannot select it.
In addition, if roles are set for each app included in an app package and available user roles are set for one or more of the individual apps, the apps are displayed as available as an app package, and it may be possible to assign usage permissions on an app-by-app basis on the details screen after selecting the package.
Fig. 17 is a diagram showing an example of a user registration email sending screen 270. When the tenant administrator C registers an application package for a user, the user registration email sending screen 270 as shown in Fig. 17 is displayed. The user registration email sending screen 270 displays a message 271 saying "The user registration email has been sent. The application will become available when the user completes the login information registration according to the email." The user receives the email and accesses the URL described in the email to register authentication information and other information among the user information.
<Processing and Operation When a User Logs In> Next, the processing and operation when a user logs in will be described with reference to Fig. 18. Fig. 18 is an example of a sequence diagram that explains the processing and operation when a user logs in. This user may be either a general user or a tenant administrator C.
S61: The user U operates the second terminal device 30 to communicate with one or more information processing devices 50 and display a login screen.
S62: The user U inputs authentication information, for example, a tenant ID, a user ID and password, or an email address and password.
S63: The operation acceptance unit 34 of the second terminal device 30 accepts the input, and the second communication unit 32 requests the one or more information processing devices 50 for authentication information.
S64: The fifth communication unit 52 of the one or more information processing devices 50 receives the authentication information, and the authentication unit 54 transmits to the user management unit 55 the tenant ID and the user ID.
S65: The user management unit 55 sends the user information associated with the tenant ID and the user ID to the authentication unit .
S66: The authentication unit 54 determines whether the tenant ID, user ID, and password entered by the user are the same as those registered in the user information storage unit 592.
S67: If the authentication is successful, the authentication unit 54 transmits a notification of the authentication success to the second terminal device 30.
When the authentication is successful, one or more information processing devices 50 transmit screen information of a home screen corresponding to the user to the second terminal device 30, so that the user of the second terminal device 30 can select an application from only the applications for which the user has usage authority. In other words, the second terminal device 30 displays only the applications included in the application package set in the initial setting item of the application usage authority of the user information.
<Login screen, etc.> Fig. 19 shows an example of a login screen. Fig. 19 is an example of a login screen 300 displayed by the second terminal device 30. The login screen 300 has a tenant ID field 304, a user ID field 301, a password field 302, and a login button 303. The user inputs a tenant ID in the tenant ID field, a user ID in the user ID field 301, and his/her password in the password field 302. These are examples of authentication information. When the user presses the login button 303, a login request is transmitted to one or more information processing devices 50. The user can also log in using an email address and a password.
FIG. 20 is an example of a home screen 310 displayed by the first terminal device 20 when the tenant administrator C logs in. When authentication is successful in response to a login request, the first terminal device 20 displays the home screen 310. The home screen 310 displays a list 311 of applications for which the tenant administrator C has usage authority in the user information. The same applies to a general user. The home screen 310 also has a setting button 312, and when the tenant administrator C presses the setting button 312, buttons for user management 313, application usage authority management (user) 314, application usage authority management (device) 315, and tenant information 316 are displayed. The user management 313 is a button for displaying a user management screen for the tenant administrator C to manage users. The application usage authority management (user) 314 is a button for displaying a screen for managing which user can use which application. The application usage authority management (device) 315 is a button for displaying a screen for managing which electronic device 10 can use the application. The tenant information 316 is a button for displaying a screen for displaying the tenant contract details and the like.
Fig. 21 is a diagram showing an example of a home screen 460 displayed by a second terminal device 30 logged in by a general user. Although it has a similar configuration to the home screen 310 for the tenant administrator C in Fig. 20, the setting button 312 is not displayed. This is because there is little need for the user to perform settings for the tenant administrator C. However, the setting button 312 may be displayed on the home screen 460 for the user. On the home screen 460, it is possible to set up apps for which the logged-in user has been given usage authority. Depending on the app, it may be possible to execute processing (such as image formation) using the electronic device 10 from the home screen.
<Assignment of application package after user registration> In FIG. 14, an application package is assigned to the user when the user information is registered, but it is also possible for the tenant administrator C to assign an application package to a user who has already been registered.
FIG. 22 is an example of a sequence diagram showing a process in which the tenant administrator C assigns an application package to a registered user.
S71 to S73: The login operation may be the same as steps S1 to S3 in FIG.
S74: The tenant administrator C inputs an operation to open an application package usage authority management screen into the first terminal device 20.
S75: The operation reception unit 24 of the first terminal device 20 receives the operation, and the first communication unit 22 requests the one or more information processing devices 50 for an application package usage authority management screen. The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the application package usage authority management screen, and the user management unit 55 generates screen information of the application package usage authority management screen. A tenant is specified by the login of the tenant administrator C, and the number of application packages assigned to users having the same tenant ID is tallied for each application package. It is assumed that the upper limit of the number of app packages that can be assigned is determined. In addition, the application packages for which the user is granted usage authority are read for each user from the initial settings of the application usage authority of the user information. The screen information of the application package usage authority management screen is transmitted to the first terminal device 20, and the display control unit 23 of the first terminal device 20 displays the application package usage authority management screen. An example of the application package usage authority management screen is shown in FIG. 23.
S76: The tenant administrator C assigns the user the right to use the application package. The operation reception unit 24 of the first terminal device 20 receives an input.
S77: The first communication unit 22 of the first terminal apparatus 20 transmits, to one or more information processing apparatuses 50, the identification information of the user associated with the tenant administrator C and the identification information of the assigned application package.
S78: The user management unit associates the identification information of the application package with the user information specified by the user identification information, and registers the associated information (initial setting item of application usage authority).
<<Application Package Usage Authority Management Screen>> FIG. 23 shows an example of an application package usage authority management screen 360. The application package usage authority management screen 360 is a screen on which the tenant administrator C assigns usage authority of an application package to each user. The application package usage authority management screen 360 displays usage authority 362 of each application package in association with a user ID 361. Each user can use an application with a check mark 364 in the usage authority 362. The usage authority status 363 of each application sets the maximum number of licenses (denominator) for each application, and also makes it possible to know the number of licenses (numerator) currently assigned. The usage authority 362 reflects the "initial setting of application usage authority" in the user information of each user. The tenant administrator C can edit which users are to be granted usage authority (permitted) or revoked (restricted) for each application package on the application package usage authority management screen 360.
A minus mark 365 indicates that the tenant administrator C cannot assign (prohibit) usage rights in the correspondence between the user and the app package. Some user roles cannot use the app package, and a minus mark 365 is displayed for these users. For example, when the available roles item in the app package information in Table 1 is "administrator," a minus mark 365 is displayed in correspondence with a general user on the app package usage authority management screen 360. In contrast, users who are left blank on the app package usage authority management screen 360 are users who have not been granted usage rights.
<Adding apps to an app package> Product designer P can also register or delete apps from an app package that has already been created.
FIG. 24 is an example of a sequence diagram showing a procedure in which a product designer P adds an application to an application package.
S81 to S83: The login operation may be the same as steps S1 to S3 in FIG.
S84: The product designer P inputs an operation to open a package list screen into the third terminal device 40.
S85: The operation reception unit 44 of the third terminal device 40 receives the operation, and the third communication unit 42 requests a package list screen from one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the package list screen, and the package management unit 53 generates screen information for the package list screen. The package management unit 53 acquires application package information stored in the package information storage unit 591 and generates the screen information for the package list screen. A tenant may be specified. The screen information for the package list screen is transmitted to the third terminal device 40, and the display control unit 43 of the third terminal device 40 displays the package list screen. This package list screen may be the same as that shown in FIG. 12, for example.
S86: Product designer P selects a package to add the app to.
S87: The operation acceptance unit 44 of the third terminal device 40 accepts the selection, and the third communication unit 42 designates identification information of a package and requests a list of applications included in this package from one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the application list request, and the package management unit 53 generates screen information of an application list screen included in the designated package. The package management unit 53 acquires applications included in this application package from the application package stored in the package information storage unit 591, and generates screen information of the application list screen. The screen information of the application list screen is transmitted to the third terminal device 40, and the display control unit 43 of the third terminal device 40 displays the application list screen. An example of the application list screen is shown in FIG. 25 .
S88: Product designer P presses the add app button 375 (FIG. 25).
S89: The operation reception unit 44 of the third terminal device 40 receives the operation, and the third communication unit 42 specifies a tenant ID and requests an application selection screen from one or more information processing devices 50. The fifth communication unit 52 of the one or more information processing devices 50 receives the request for the application selection screen, and the application management unit 56 generates screen information for the application selection screen. The application management unit 56 identifies the application package or application for which the customer has made a contract based on the tenant ID, and generates screen information for the application selection screen. The screen information for the application selection screen is transmitted to the third terminal device 40, and the display control unit 43 of the third terminal device 40 displays the application selection screen. An example of the application selection screen is shown in FIG. 26.
S90: Product designer P selects an application on the application selection screen.
S91: The operation acceptance unit 44 of the third terminal device 40 accepts an operation, and the third communication unit 42 requests one or more information processing devices 50 for application identification information.
S92: The fifth communication unit 52 of the one or more information processing devices 50 receives the identification information of the application, and the package management unit 53 registers the application in a package.
In this way, you can register an app to a package that has already been created.
<<Application List Screen, Application Selection Screen>> FIG. 25 is a diagram showing an example of an application list screen 370. The application list screen 370 is a screen where a product designer P edits applications included in an application package. The application list screen 370 has an application list 371, a details button 372, an edit button 373, a delete button 374, and an add application button 375. The details button 372 is a button for displaying the processing content of this application, the edit button 373 is a button for editing a combination of components to change the workflow, and the delete button 374 is a button for deleting an application from an application package. The add application button 375 is a button for adding an application to the application package. When the add application button 375 is pressed, an application selection screen 380 in FIG. 26 is displayed. FIG. 26 shows an example of the application selection screen 380. The application selection screen 380 may be the same as that in FIG. 10.
<Summary> As described above, the information processing system of this embodiment allows the product designer P to set roles for application packages, and prevents the tenant administrator C from assigning usage rights to application packages to users that the tenant administrator C does not want to use the application packages.
<Other Application Examples> Although the best mode for carrying out the present invention has been described above using examples, the present invention is not limited to these examples in any way, and various modifications and substitutions can be made without departing from the spirit and scope of the present invention.
For example, in this embodiment, each terminal device uses a general-purpose web browser, but a dedicated application may be used for the information processing system.
In addition, the configuration example of Fig. 5 and the like is divided according to main functions in order to facilitate understanding of the processing by the first terminal device 20, the second terminal device 30, the third terminal device 40, the electronic device 10, and one or more information processing devices 50. The present invention is not limited by the manner of division or names of the processing units. The processing by the first terminal device 20, the second terminal device 30, the third terminal device 40, the electronic device 10, and one or more information processing devices 50 can be further divided into more processing units according to the processing contents. Also, it is possible to divide one processing unit so that it includes more processes.
Additionally, the devices described in the examples are merely one of a number of computing environments for implementing the embodiments disclosed herein. In one embodiment, the one or more information processing devices 50 include a number of computing devices, such as a server cluster. The computing devices are configured to communicate with each other via any type of communication link, including a network, shared memory, and the like, and perform the processes disclosed herein.
Furthermore, one or more information processing devices 50 can be configured to share the disclosed processing steps, such as those shown in Figures 6, 7, 14, 18, 22, and 24, in various combinations. For example, a process executed by a given unit can be executed by multiple information processing devices included in one or more information processing devices 50. Furthermore, one or more information processing devices 50 may be integrated into one server device, or may be divided into multiple devices.
Each function of the above-described embodiments can be realized by one or more processing circuits. Here, the term "processing circuit" in this specification includes a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, and a device such as an ASIC (Application Specific Integrated Circuit), a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), or a conventional circuit module designed to execute each function described above.
1 Information Processing System
10 Electronics
20 First terminal device
30 Second terminal device
40 Third terminal device
50 One or more information processing devices
<p><patcit num="1"><text>JP 2017-120502 A</text></patcit></p>
30 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2012256248A | Cites | Japan |
| JP7347133B2 | Cites | Japan |
| JP2003202930A | Cites | Japan |
7 members in 3 offices
Priority claims1
| Document | Office | Kind | Date |
|---|---|---|---|
| 2019201773 | Japan | A |
Members7
| Document | Office | Kind | |
|---|---|---|---|
| US2021136074A1 | United States of America | A1 | |
| EP3819796A1 | European Patent Office (EPO) | A1 | |
| JP2021076986A | Japan | A | |
| US11595394B2 | United States of America | B2 | |
| JP7347133B2 | Japan | B2 | |
| JP2023166529A | Japan | A | |
| JP7605264B2This record | Japan | B2 |
8 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 7605264
- Application
- 144940
Titles2
- Japanese
- 1つ以上の情報処理装置、情報処理システム、ロール設定方法
- English
- One or more information processing devices, information processing system, and role setting method
Classification
- CPC, 10
- G06F21/105
- H04L63/101
- G06F21/604
- G06F21/45
- H04L63/102
- H04L63/104
- G06F21/6218
- H04L63/083
- H04L67/125
- G06F21/1015
- IPC, 2
- G06F21 10
- G06F21 62
