Function execution apparatus, computer program for function execution apparatus, and method executed by function execution apparatus

The FIDO authentication method with key pairs in function-performing devices allows secure function execution with or without user ID input, addressing the need for efficient and secure authentication in function-performing devices.

JP2026006149APending Publication Date: 2026-01-16BROTHER KOGYO KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024104935
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-28
Publication Date
2026-01-16

AI Technical Summary

Technical Problem

Existing authentication systems for function-performing devices lack a secure and efficient method to perform specific functions without requiring input of account information, especially in scenarios where biometric authentication is successful.

Method used

A function-performing device employs a FIDO authentication method using a pair of keys, enabling secure execution of functions based on biometric authentication, allowing both user ID input and user ID-free execution by utilizing private and public keys for signature verification.

Benefits of technology

The solution ensures secure and efficient execution of functions by validating user identity through biometric authentication, either with or without input of account information, enhancing user convenience and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026006149000001_ABST
    Figure 2026006149000001_ABST
Patent Text Reader

Abstract

To provide a new technique for making a function execution device execute a specific function according to a predetermined authentication system using a pair of keys.SOLUTION: In a case of accepting an input of the specific account information, send a first authentication request to the server and receive first verification information from the server; In a case where the authentication of the target user is successful and the first verification information is received from the server, the function execution apparatus acquires the first signature information, transmits the first signature information to the server, and receives the first function execution instruction from the server. The function execution apparatus transmits a second authentication request including predetermined information to the server without receiving an input of the account information, and receives second verification information from the server. In a case where the authentication of the target user is successful and the second verification information is received from the server, the function execution apparatus acquires the second signature information, transmits the second signature information to the server, and receives the second function execution instruction from the server.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This specification discloses a technique for causing a function-performing device to perform a specific function. [Background technology]

[0002] Patent Document 1 discloses a system including an image processing device, an external authenticator, and a service providing system. When the image processing device accepts an operation to use a printing service, it transmits a service provision request to the service providing system, receives biometric authentication including an Assertion Challenge from the service providing system, and transmits an assertion creation request including the Assertion Challenge to the external authenticator. If the biometric authentication is successful, the external authenticator encrypts the Assertion Challenge using a private key to generate signature data. The external authenticator then transmits assertion information including the signature data to the image processing device, and the image processing device transmits an assertion verification request including the assertion information to the service providing system. The service providing system uses a public key to decrypt the signature data included in the assertion information, and if the decrypted value matches the Assertion Challenge, determines that user authentication is successful and transmits a signal to the image processing device to provide the printing service. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2019-86937 Summary of the Invention [Problem to be solved by the invention]

[0004] This specification provides a novel technique for allowing a function-performing device to perform a specific function according to a predetermined authentication scheme that utilizes a pair of keys. [Means for solving the problem]

[0005] The function-performing device disclosed herein operates according to a predetermined authentication scheme that utilizes a pair of keys. the function executing device includes a function executing engine for executing a specific function; a first authentication request sending unit that sends a first authentication request including specific account information to a server when input of the specific account information is accepted; a first verification information receiving unit that receives first verification information from the server in response to the first authentication request being sent to the server; a first signature information acquiring unit that acquires first signature information generated by encrypting the first verification information using a first private key in the first memory when authentication of the target user using biometric authentication information in a first memory is successful and the first verification information is received from the server; a first signature information sending unit that transmits the first signature information to the server, wherein the server decrypts the first signature information using a first public key stored in the server in association with the specific account information; a first receiving unit that receives a first function execution instruction from the server when the server successfully decrypts the first signature information; a first engine control unit that causes the function executing engine to execute the specific function when a first function execution instruction is received; a second authentication request sending unit that sends a second authentication request including predetermined information to the server without receiving input of account information; a second verification information receiving unit that receives second verification information from the server in response to the second authentication request being sent to the server; a second signature information acquisition unit that acquires second signature information generated by encrypting the second verification information using a second private key in the first memory when authentication of the target user using the biometric authentication information in the first memory is successful and the second verification information is received from the server; a second signature information sending unit that sends the second signature information to the server, wherein the server decrypts the second signature information using a second public key stored in the server in association with the predetermined information; and a second receiving unit that receives a second function execution instruction from the server when the server successfully decrypts the second signature information.and a second engine control unit that causes the function execution engine to execute the specific function when the second function execution instruction is received from the server.

[0006] According to the above configuration, the function executing device accepts input of specific account information, transmits a first authentication request to the server, and executes the specific function if authentication of the target user using the biometric authentication information in the first memory is successful and the server successfully decrypts the first signature information. Furthermore, the function executing device transmits a second authentication request to the server, and executes the specific function without accepting input of account information if authentication of the target user using the biometric authentication information in the first memory is successful and the server successfully decrypts the second signature information. Therefore, the function executing device can execute the specific function both when accepting input of account information and when not accepting input of account information.

[0007] A computer program for the function-performing device, a computer-readable recording medium storing the computer program, and a method executed by the function-performing device are also novel and useful. Also novel and useful are a communication system including the function-performing device and a server. [Brief explanation of the drawings]

[0008] [Figure 1] 1 shows the configuration of a communication system. [Figure 2] An example of each table is shown below. [Figure 3] FIG. 10 is a sequence diagram of a first registration process. [Figure 4] This is a continuation of the sequence diagram of FIG. [Figure 5] This is a continuation of the sequence diagram of FIG. [Figure 6] FIG. 10 is a sequence diagram of a first printing process. [Figure 7] This is a continuation of the sequence diagram of FIG. [Figure 8] FIG. 10 is a sequence diagram of a second registration process. [Figure 9] This is a sequence diagram continuing from FIG. 8. [Figure 10] FIG. 10 is a sequence diagram of a second printing process. [Figure 11] FIG. 10 is a sequence diagram of a first printing process according to a second embodiment. [Figure 12] FIG. 10 is a sequence diagram of a second printing process according to the second embodiment. [Figure 13] FIG. 11 is a sequence diagram of a first printing process according to a third embodiment. [Figure 14] FIG. 11 is a sequence diagram of a second printing process according to the third embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0009] (First Example) (Configuration of communication system 2; Figure 1) 1, the communication system 2 includes a printer 10, an authentication device 50, a PC 100, and a server 200. The printer 10, the PC 100, and the server 200 are connected to the Internet 6. The printer 10, the PC 100, and the server 200 can communicate with each other via the Internet 6.

[0010] (Printer 10 configuration) The printer 10 is a peripheral device (e.g., a peripheral device of the PC 100) that can execute a printing function. The printer 10 can operate according to the FIDO (short for Fast Identity Online) authentication method, which uses a pair of keys. The FIDO authentication method is an authentication method that uses a pair of keys, i.e., a private key and a public key. The FIDO authentication method is also an authentication method that performs user authentication using biometric authentication (e.g., fingerprint authentication, voiceprint authentication, or facial authentication) instead of password-based authentication. Hereinafter, authentication according to the FIDO authentication method will be referred to as "FIDO authentication."

[0011] The printer 10 includes an operation unit 12, a display unit 14, a print engine 16, a USB interface 18, a communication interface 20, and a control unit 30. Hereinafter, the interface will be referred to as "I / F."

[0012] The operation unit 12 is a user interface that allows the user to input various information to the printer 10. The operation unit 12 includes, for example, a touch panel for displaying software keys (operation area), hardware keys, or both. The hardware keys include, for example, buttons or switches. The display unit 14 is a display or panel for displaying various information and various screens described below. The display is, for example, a liquid crystal display or an organic EL display. The panel may or may not be a touch panel. The panel is, for example, a liquid crystal panel or an organic EL panel.

[0013] The print engine 16 is an electrophotographic, inkjet, or thermal print engine. An inkjet print engine has a print head that ejects ink droplets. An electrophotographic print engine has a photosensitive member and an exposure device that emits light to expose the photosensitive member. A thermal print engine has a print head that generates heat using a heater.

[0014] The USB I / F 18 is an I / F to which a USB connector is connected. The communication I / F 20 is an I / F for executing communication with other devices. The communication I / F 20 is connected to the Internet 6. The communication I / F 20 may be a wired I / F or a wireless I / F.

[0015] The control unit 30 includes a CPU 32 and a memory 34. The memory 34 includes a main storage device and an auxiliary storage device. As an example, the main storage device includes a RAM and a cache memory. As an example, the auxiliary storage device may be a ROM, a flash memory, a solid state drive (SSD), a hard disk drive (HDD), or a combination thereof. A program 40 is stored in the auxiliary storage device of the memory 34. The CPU 32 performs various processes in accordance with the program loaded from the auxiliary storage device to the main storage device.

[0016] (Configuration of Authenticator 50) The authenticator 50 is operable in accordance with the FIDO authentication method. The authenticator 50 operates as a so-called authenticator in the FIDO authentication method. The authenticator 50 has a serial number "SN1." The serial number is an identification number assigned when the authenticator is manufactured. The authenticator 50 includes a USB cable (not shown) with a USB connector, and a memory 60. The memory 60 includes a main storage device and an auxiliary storage device. The auxiliary storage device of the memory 60 stores fingerprint information 62 and an RPID "URL1." The fingerprint information 62 is information related to the fingerprint of the user who uses the PC 100. Hereinafter, the user who uses the PC 100 may be referred to as the "target user." The RPID is information that identifies the service that performs authentication. As an example, the RPID indicates the URL of the server 200.

[0017] (PC100 configuration) The PC 100 is a PC such as a desktop PC, a notebook PC, a tablet PC, etc. The PC 100 includes an operation unit 112, a display unit 114, a USB I / F 118, a communication I / F 120, and a control unit .

[0018] The operation unit 112 is a user interface that allows a user to input various information to the PC 100. The operation unit 112 includes, for example, a touch panel for displaying software keys (operation area), hardware keys, or both. The hardware keys include, for example, buttons or switches. The display unit 114 is a display or panel for displaying various information and various screens described below. The display is, for example, a liquid crystal display or an organic EL display. The panel may or may not be a touch panel. The panel is, for example, a liquid crystal panel or an organic EL panel. The USB I / F 118 is an I / F to which a USB connector is connected. The communication I / F 120 is an I / F for executing communication with other devices. The communication I / F 120 is connected to the Internet 6.

[0019] The control unit 130 includes a CPU 132 and a memory 134. The memory 134 includes a main storage device and an auxiliary storage device. An Operating System (OS) program 140 is stored in the auxiliary storage device of the memory 134. The OS program 140 controls the basic operations of the PC 100. The CPU 132 performs various processes in accordance with programs loaded from the auxiliary storage device to the main storage device.

[0020] (Configuration of Server 200) The server 200 is a server installed on the Internet 6, and is provided by, for example, the vendor of the printer 10. In a modified example, the server 200 may be installed on the Internet 6 by a business operator other than the vendor. In another modified example, the vendor may not prepare the hardware for the server 200 on its own, but may use an environment provided by an external cloud computing service. In this case, the vendor may prepare a program (i.e., software) for the server 200 and implement the program in the above-described environment to realize the server 200. The server 200 is operable according to the FIDO authentication method. The server 200 operates as a so-called authentication server in the FIDO authentication method.

[0021] The server 200 operates as a server that provides an intermediation service related to the printer 10. The intermediation service is a service for operating the printer 10 via the server 200. In the intermediation service, the server 200 uses XMPP (short for eXtensible Messaging and Presence Protocol) to send instructions to the printer 10 based on information received from the user's PC. An XMPP connection is a so-called always-on connection. By using an XMPP connection, the server 200 can send a signal to the printer 10 across the firewall of the LAN to which the printer 10 belongs, even if it does not receive a request from the printer 10. Note that the mechanism for sending a request from the server 200 to the printer 10 may be other than an XMPP connection. For example, an HTTPS (short for Hypertext Transfer Protocol Secure) connection may be established between the printer 10 and the server 200.

[0022] The server 200 includes a communication I / F 220 and a control unit 230. The communication I / F 220 is an I / F for communicating with other devices. The communication I / F 220 is connected to the Internet 6. The control unit 230 includes a CPU 232 and a memory 234. The memory 234 includes a main storage device and an auxiliary storage device. The auxiliary storage device of the memory 234 stores a program 240 and a management table 242. The CPU 232 performs various processes in accordance with the program loaded from the auxiliary storage device to the main storage device.

[0023] (Configuration of management table 242; Figure 2) The contents of the management table 242 in the server 200 will be described with reference to FIG.

[0024] The management table 242 is a table for managing information related to FIDO authentication. The management table 242 stores an RPID, a public key, a user ID, a serial number, and a job ID in association with each other. The public key is registered when a registration process is executed to register a pair of keys used for FIDO authentication. The job ID is information that identifies a print job and is generated when an upload request including a print file is received from a PC.

[0025] (First registration process; Figures 3 to 5) 3 to 5, a first registration process for registering information related to FIDO authentication in each device will be described. The first registration process includes a process for registering a print job in the server 200. In the first registration process, a target user logs in to the server 200 using the user ID "Tanaka" and the password "PW1." In the initial state of FIG. 3, the combination of the user ID "Tanaka" and the password "PW1" is stored in the memory 234 of the server 200. The management table 242 is empty. In the following, the processes executed by the CPU of each device will be described as the subject of the process, rather than the CPU. Note that in the following, communication between each device is performed via a communication I / F. Therefore, in the following, when describing processes related to communication via a communication I / F, the expression "via a communication I / F" will be omitted. In addition, communication between the printer 10 and the authenticator 50 is performed via the USB I / F 18 of the printer 10. Therefore, in the following description, when describing processing related to communication via the USB I / F, the phrase "via the USB I / F 18" will be omitted.

[0026] At T10, the target user performs a login operation on PC 100 to log in to server 200. As a result, PC 100 transmits a login screen data request to 200 at T12, receives login screen data from server 200 at T14, and displays a login screen represented by the login screen data on display unit 114 at T16. At T18, the user inputs the user ID "Tanaka" and password "PW1" into PC 100, i.e., the login screen displayed on display unit 114. As a result, PC 100 transmits a login request including the user ID "Tanaka" and password "PW1" to server 200 at T20.

[0027] When the server 200 receives a login request from the PC 100 at T20, it determines at T22 that password authentication has been successful because the combination of the user ID "Tanaka" and the password "PW1" in the login request is stored in the memory 234, and sends home screen data to the PC 100 at T24.

[0028] When the PC 100 receives the home screen data from the server 200 in T24, the PC 100 displays the home screen represented by the home screen data on the display unit 114 in T26.

[0029] At T30, the target user connects the USB connector of the authenticator 50 to the USB I / F 118 of the PC 100. As a result, the PC 100 determines that the authenticator 50 is connected to the PC 100. At T31, the PC 100 acquires the serial number "SN1" from the authenticator 50. At T32, the target user executes a first device registration operation on the PC 100 to register information about FIDO authentication in each device. As a result, at T40, the PC 100 transmits an authentication request including the user ID "Tanaka" and the RPID "URL1" to the server 200.

[0030] When the server 200 receives an authentication request from the PC 100 at T40, it generates a one-time pass OP1 at T42 and stores the one-time pass OP1 in the memory 234. At T44, the server 200 transmits an authentication instruction including the RPID "URL1" and the one-time pass OP1 to the PC 100. The authentication instruction is a signal for instructing the execution of biometric authentication.

[0031] When the PC 100 receives an authentication instruction from the server 200 in T44, in T46, it displays a fingerprint authentication screen on the display unit 114. A message requesting execution of fingerprint authentication using the authentication device 50 is displayed on the fingerprint authentication screen.

[0032] At T50, the target user performs a fingerprint authentication operation on the authentication device 50. The authentication device 50 determines that the fingerprint authentication has been successful because the fingerprint information acquired by the fingerprint authentication operation matches the fingerprint information 62 in the memory 60, and at T52 transmits fingerprint authentication success information indicating that the fingerprint authentication has been successful to the PC 100.

[0033] When the PC 100 receives fingerprint authentication success information from the authentication device 50 at T52, it transmits a key generation request to the authentication device 50 at T60 in Fig. 4. The key generation request is a signal requesting the generation of a pair of keys to be used in FIDO authentication.

[0034] When the authenticator 50 receives a key generation request from the PC 100 at T60, it generates a private key PRK1 and a public key PUK1 at T62, and stores the private key PRK1 in the memory 60 at T64. At T66, the authenticator 50 transmits an authentication response including the public key PUK1 and the serial number "SN1" to the PC 100.

[0035] When the PC 100 receives the authentication response from the authenticator 50 in T66, it transmits the authentication response including the public key PUK1, the serial number "SN1" and the one-time pass OP1 to the server 200 in T68.

[0036] In T68, when the server 200 receives the authentication response from the PC 100, it determines that the one-time pass OP1 in the authentication response matches the one-time pass OP1 in the memory 234, and identifies the public key PUK1 in the authentication response. In T70, the server 200 associates the RPID "URL1", the public key PUK1, and the user ID "Tanaka" of the currently logged-in user, and stores them in the management table 242. In T72, the server 200 transmits first registration completion screen data to the PC 100.

[0037] When PC 100 receives first registration completion screen data from server 200 in T72, PC 100 displays a first registration completion screen represented by the first registration completion screen data on display unit 114 in T74. The first registration completion screen includes a message indicating that registration of information related to FIDO authentication has been completed. The first registration completion screen also includes a message indicating that the information has been registered in association with the user ID.

[0038] At T80, the target user performs a print data registration operation on PC 100 to register print data in server 200. As a result, at T90, PC 100 sends an authentication request including the user ID "Tanaka" and the RPID "URL1" to server 200. T92 and T94 are similar to T42 and T44 in FIG. 3, respectively, except that one-time pass OP2 is used. T96, T100, and T102 are similar to T46, T50, and T52, respectively.

[0039] When the PC 100 receives fingerprint authentication success information from the authentication device 50 in T102, it sends a signature information generation request including the one-time pass OP2 to the authentication device 50 in T104. The signature information generation request is a signal requesting the generation of signature information.

[0040] When the authenticator 50 receives the signature information generation request from the PC 100 in T104, it identifies the private key PRK1 in the memory 60. In T106, the authenticator 50 generates signature information SI1 by encrypting the received one-time pass OP2 using the identified private key PRK1, and in T108, it transmits the generated signature information SI1 to the PC 100.

[0041] When PC 100 receives signature information SI1 from authentication device 50 in T108, it transmits an authentication response including user ID "Tanaka" and signature information SI1 to server 200 in T110 of FIG.

[0042] In T110, upon receiving the authentication response from the PC 100, the server 200 identifies the public key PUK1 associated with the user ID "Tanaka" and stored in the management table 242. The server 200 decrypts the signature information SI1 in the authentication response using the identified public key PUK1. Because the private key PRK1 and the public key PUK1 form a key pair, the one-time pass OP2 is obtained by decrypting the signature information SI1 using the public key PUK1. The server 200 determines that the acquired one-time pass OP2 matches the one-time pass OP2 stored in the memory 234 (see T92 in FIG. 4), and determines in T120 that the FIDO authentication has been successful. In this case, the server 200 transitions from the logged-out state to the logged-in state. By transitioning the server 200 to the logged-in state, the target user can upload a print file to the server 200. In T122, the server 200 transmits an authentication success notification to the PC 100 indicating that the FIDO authentication has been successful.

[0043] When the PC 100 receives a successful authentication notification from the server 200 in T122, it displays an authentication success screen on the display unit 114 in T124. This allows the target user to know that the FIDO authentication has been successful. In T130, the target user performs an upload operation on the PC 100 to upload a print file (more specifically, print data) to the server 200. In the upload operation, the target user selects the print file to be sent. As a result, the PC 100 transmits an upload request including the print file selected by the target user to the server 200 in T132.

[0044] When the server 200 receives an upload request from the PC 100 in T132, in T134 the server 200 generates a job ID "job1" and converts the print file in the request to generate print data PD1 representing a print image in a data format that can be interpreted by the printer 10. In T136, the server 200 associates the generated job ID "job1" with the received user ID "Tanaka" and stores it in the management table 242. The server 200 stores the print data PD1 in memory 234 in association with the job ID "job1". In T138, the server 200 sends an upload completion notification to the PC 100 indicating that the upload of the print file has been completed.

[0045] When the PC 100 receives an upload completion notification from the server 200 in T138, it displays an upload completion screen on the display unit 114 in T140. This allows the target user to know that the upload of the print file has been completed. Although not shown in the figure, the PC 100 transmits a logout request to the server 200. This causes the server 200 to transition from a logged-in state to a logged-out state. In this way, the user logs in to the server 200, and in response to successful FIDO authentication, the print file is uploaded to the server 200.

[0046] (First printing process: Figures 6 and 7) 6 and 7, a first print process in which print data is downloaded from server 200 in response to successful FIDO authentication will be described. The initial state of the first print process is the state after the first registration process in FIGS. 3 to 5. That is, private key PRK1 is stored in memory 60 of authentication device 50. In addition, RPID "URL1", public key PUK1, user ID "Tanaka", and job ID "job1" are associated and stored in management table 242 of server 200.

[0047] In T210, the target user connects the USB connector of the authenticator 50 to the USB I / F 18 of the printer 10. As a result, the printer 10 determines that the authenticator 50 is connected to the printer 10. In T211, the printer 10 acquires the serial number "SN1" from the authenticator 50. In T212, the printer 10 displays the selection screen SC10 on the display unit 14. The selection screen SC10 is a screen for selecting whether or not to display the user ID input screen SC12 on the printer 10. In other words, the selection screen SC10 is a screen for allowing the user to select whether or not to use a user ID. In T214, the target user operates the YES button on the selection screen SC10 on the printer 10. As a result, the printer 10 displays the user ID input screen SC12 on the display unit 14 in T216. The user ID input screen SC12 is a screen for entering a user ID. In T218, the target user inputs the user ID "Tanaka" and presses the OK button on the printer 10. As a result, in T220, the printer 10 sends an authentication request including the user ID "Tanaka" and the RPID "URL1" to the server 200. T222 and T224 are similar to T42 and T44 in FIG. 3, respectively, except that one-time pass OP3 is used and the communication target is the printer 10. Note that if the authentication request received from the printer 10 includes a user ID or serial number that is not stored in the management table 242, the server 200 sends an error response to the printer 10. T226, T230, and T232 are similar to T46, T50, and T52, respectively, except that the communication target is the printer 10.

[0048] At T234 in Figure 7, the authenticator 50 receives a signature information generation request including the one-time pass OP3 from the printer 10, and at T236, generates signature information SI2 by encrypting the received one-time pass OP3 using the private key PRK1 in the memory 234, and at T238, transmits the generated signature information SI2 to the printer 10.

[0049] When the printer 10 receives the signature information SI2 from the authentication device 50 in T238, it transmits an authentication response including the user ID "Tanaka" and the signature information SI2 to the server 200 in T240.

[0050] When the server 200 receives the authentication response from the printer 10 in T240, it identifies the public key PUK1 stored in the management table 242 in association with the user ID "Tanaka." The server 200 obtains a one-time pass OP3 by decrypting the signature information SI2 in the authentication response using the identified public key PUK1. The server 200 determines that the obtained one-time pass OP3 matches the one-time pass OP3 stored in the memory 234 (see T222 in FIG. 6), and determines that the FIDO authentication has been successful in T250. As a result, the server 200 transitions from the logged-out state to the logged-in state. In this case, the server 200 identifies the job ID "job1" stored in the management table 242 in association with the user ID "Tanaka," and transmits an authentication success notification including the identified job ID "job1" to the printer 10 in T252.

[0051] When the printer 10 receives a notification of successful authentication from the server 200 in T252, it displays a job selection screen including the received job ID "job1" on the display unit 14 and stores the received job ID "job1" in the memory 34 in T254. The job selection screen is a screen for allowing the target user to select the job ID of the job to be printed. The target user selects the job ID "job1" on the job selection screen in T260. As a result, the printer 10 transmits a print data request including the selected job ID "job1" to the server 200 in T262.

[0052] When the server 200 receives a print data request from the printer 10 at T262, it identifies the print data PD1 stored in the memory 234 in association with the job ID "job1" in the request, and at T264 sends a print instruction including the identified print data PD1 to the printer 10.

[0053] When the printer 10 receives a print instruction from the server 200 in T264, it associates the print data PD1 in the print instruction with the job ID "job1" and stores it in the memory 234 in T266, and executes printing using the print data PD1. In T268, the printer 10 sends a print completion notification including the job ID "job1" to the server 200, and in T270, it deletes the job ID "job1" and the print data PD1 from the memory 234.

[0054] When the server 200 receives a print completion notification from the printer 10 in T268, it deletes the job ID "job1" from the management table 242 and deletes the print data PD1 from the memory 234 in T272. Although not shown, when the target user removes the authentication device 50 from the printer 10, the printer 10 sends a logout request to the server 200. Then, when the server 200 receives the logout request from the printer 10, it transitions from the logged-in state to the logged-out state. In this way, printing is executed in response to the user ID "Tanaka" being input by the target user.

[0055] (Second registration process; Figure 8, Figure 9) A second registration process for registering information related to FIDO authentication in each device will be described with reference to Figures 8 and 9. In the second registration process, the target user does not perform an operation to log in to the server 200 using the user ID "Tanaka" and password "PW1". The initial state of the second registration process is the same as the initial state of the first registration process in Figures 3 to 5.

[0056] T310 and T311 are the same as T30 and T31 in Fig. 3, respectively. At T312, the target user performs a second device registration operation on the PC 100 to register information about FIDO authentication in each device. At T320, the PC 100 sends an authentication request including the serial number "SN1" and the RPID "URL1" to the server 200. T322 to T332 are the same as T42 to T52 in Fig. 3, except that the one-time pass OP4 is used.

[0057] When the authenticator 50 receives a key generation request from the PC 100 at T340, it generates a private key PRK2 and a public key PUK2 at T342, and stores the private key PRK2 in the memory 60 at T344. At T346, the authenticator 50 transmits a first authentication response including the public key PUK2 and the serial number "SN1" to the PC 100.

[0058] When the PC 100 receives the authentication response from the authenticator 50 at T346, it transmits the authentication response including the public key PUK2, the serial number "SN1" and the one-time pass OP4 to the server 200 at T348.

[0059] When the server 200 receives the authentication response from the PC 100 in T348, it determines that the one-time pass OP4 in the second authentication response matches the one-time pass OP4 in the memory 234, and also determines that the target user is not currently logged in to the server 200. In this case, in T350, the server 200 associates the RPID "URL1", the public key PUK2, and the serial number "SN1" and stores them in the management table 242. In T352, the server 200 transmits second registration completion screen data to the PC 100.

[0060] When the PC 100 receives the second registration completion screen data from the server 200 at T352, at T354, the PC 100 displays a second registration completion screen represented by the second registration completion screen data on the display unit 114. The second registration completion screen includes a message indicating that registration of information related to FIDO authentication has been completed. The second registration screen also includes information indicating that the user ID is not associated with the information.

[0061] T360 to T384 in FIG. 9 are the same as T80 to T104 in FIG. 4, except that one-time path OP5 is used.

[0062] When the authenticator 50 receives a signature information generation request from the PC 100 at T384, it generates signature information SI3 at T386 by encrypting the received one-time pass OP5 using the private key PRK2 in the memory 60, and sends the generated signature information SI3 to the PC 100 at T388.

[0063] When PC 100 receives signature information SI3 from authenticator 50 in T388, it transmits an authentication response including serial number "SN1" and signature information SI3 to server 200 in T390.

[0064] When the server 200 receives the authentication response from the PC 100 in T390, the server 200 identifies the public key PUK2 stored in the management table 242 in association with the serial number "SN1." The server 200 uses the identified public key PUK2 to decrypt the signature information SI3 in the authentication response and acquire the one-time pass OP5. The server 200 determines that the acquired one-time pass OP5 matches the one-time pass OP5 stored in the memory 234 (see T372), and determines in T400 that the FIDO authentication has been successful. In this case, the server 200 transitions from the logout state to the login state. T402, T404, T410, and T412 are the same as T122, 124, 130, and T132 in FIG. 5, respectively.

[0065] When the server 200 receives an upload request from the PC 100 in T412, the server 200 generates a job ID "job2" and generates print data PD2 in T414. In T416, the server 200 associates the generated job ID "job2" with the received serial number "SN1" and stores them in the management table 242. The server 200 stores the print data PD2 in memory 234 in association with the job ID "job2." T418 and T420 are the same as T138 and T140 in FIG. 5, respectively. In this way, the print file is uploaded to the server 200 in response to successful FIDO authentication, even if the target user does not log in to the server 200.

[0066] (Second printing process; Figure 10) Referring to Figure 10, a second print process in which print data is downloaded from the server 200 in response to successful FIDO authentication will be described. The initial state of the second print process is the state after the second registration process in Figures 8 and 9. That is, the private key PRK2 is stored in the memory 60 of the authenticator 50. In addition, the RPID "URL1", the public key PUK2, the serial number "SN1", and the job ID "job2" are associated and stored in the management table 242 of the server 200.

[0067] T510 to T512 are the same as T210 to T212 in FIG. 6. In this process, the target user performs an operation on the NO button on the selection screen SC10 of the printer 10 at T514. As a result, the printer 10 transmits an authentication request including the serial number "SN1" and the RPID "URL1" to the server 200 at T520 without displaying the user ID input screen SC12. T522 and T524 are the same as T322 and T324 in FIG. 8, respectively, except that the one-time pass OP6 is used and the communication target is the printer 10. T526, T530, and T532 are the same as T326, T330, and T332, respectively.

[0068] At T534, the authenticator 50 receives a signature information generation request including the one-time pass OP6 from the printer 10, and at T536, generates signature information SI4 by encrypting the received one-time pass OP6 using the private key PRK2 in the memory 234, and at T538, transmits the generated signature information SI4 to the printer 10.

[0069] When the printer 10 receives the signature information SI4 from the authenticator 50 in T538, it transmits an authentication response including the serial number "SN1" and the signature information SI4 to the server 200 in T540.

[0070] When the server 200 receives the authentication response from the printer 10 in T540, it identifies the public key PUK2 stored in the management table 242 in association with the serial number "SN1." The server 200 obtains a one-time pass OP6 by decrypting the signature information SI4 in the authentication response using the identified public key PUK2. The server 200 determines that the obtained one-time pass OP6 matches the one-time pass OP6 stored in the memory 234 (see T522), and determines in T550 that the FIDO authentication has been successful. As a result, the server 200 transitions from the logged-out state to the logged-in state. In this case, the server 200 identifies the job ID "job2" stored in the management table 242 in association with the serial number "SN1," and in T552 sends an authentication success notification including the identified job ID "job2" to the printer 10.

[0071] When the printer 10 receives a notification of successful authentication from the server 200 in T552, it displays a job selection screen including the received job ID "job2" on the display unit 14 in T554, and stores the received job ID "job2" in the memory 34. The target user selects the job ID "job2" in the job selection screen in T560. Thereafter, processing similar to T262 to T270 in FIG. 7 is executed between the printer 10 and the server 200. Note that in this processing, the job ID "job2" and print data PD2 are used.

[0072] At T572, the server 200 deletes the RPID "URL1", the public key PUK2, the serial number "SN1", and the job ID "job2" from the management table 242, and also deletes the print data PD2 from the memory 234. At T574, the server 200 sends a deletion request to the printer 10 requesting deletion of the private key.

[0073] When the printer 10 receives the deletion request from the server 200 in T574, it transmits the deletion request to the authenticator 50 in T576.

[0074] When the authenticator 50 receives the deletion request from the printer 10 in T576, it deletes the private key PRK2 from the memory 60 in T578. In this way, printing is performed without the target user having to enter a user ID.

[0075] As described above, if the decryption of the signature information SI4 is successful, the server 200 erases the serial number "SN1" and the public key PUK2 stored in the server 200 (T572 in FIG. 10). This configuration allows the authenticator 50 to be shared. On the other hand, as shown in FIG. 7, even if the decryption of the signature information SI2 is successful, the server 200 does not erase the user ID "Tanaka" and the public key PUK1 stored in the server 200 (T572 in FIG. 10). This configuration eliminates the need for the target user to perform an operation to register information related to FIDO authentication again when uploading a new print file to the server 200. This improves user convenience.

[0076] (Effects of this embodiment) 6 and 7, the printer 10 accepts input of the user ID "Tanaka" (T218 in FIG. 6), sends an authentication request including the user ID "Tanaka" to the server 200 (T220), and if authentication of the target user using the fingerprint information 62 in the memory 60 of the authentication device 50 is successful (T230 in FIG. 6) and the server 200 is successful in decrypting the signature information SI2 (T250 in FIG. 7), the printer 10 executes the print function (T266). Also, as shown in FIG. 10, the printer 10 sends an authentication request including the serial number "SN1" to the server 200 (T520 in FIG. 10), and if authentication of the target user using the fingerprint information 62 is successful (T530) and the server 200 is successful in decrypting the signature information SI4 (T550), the printer 10 executes the print function without accepting input of the user ID. Therefore, the printer 10 can execute the print function when it accepts input of a user ID and when it does not accept input of a user ID.

[0077] By using a user ID, the security level can be improved compared to a configuration that does not use a user ID. Also, by not using a user ID, there is no need to enter a user ID, which improves user convenience. With the above configuration, it is possible to appropriately select whether to use a method with a high security level or a method with high user convenience.

[0078] Furthermore, when the authenticator 50 is attached to the printer 10, the printer 10 displays a selection screen SC10 on the display unit 14. With this configuration, the target user can select whether or not to use the user ID, thereby improving user convenience.

[0079] (Correspondence) The FIDO authentication method is an example of a "predetermined authentication method." The printer 10 is an example of a "function executing device." The printing function is an example of a "specific function." The print engine 16 is an example of a "function executing engine." The user ID "Tanaka" is an example of "specific account information." The authentication request of T220 in FIG. 6 is an example of a "first authentication request." The one-time pass OP3 of T224 in FIG. 6 is an example of "first verification information." The memory 60 of the authenticator 50 is an example of a "first memory." The fingerprint information 62 is an example of "biometric authentication information." The private key PRK1 is an example of a "first private key." The signature information SI2 of T238 in FIG. 7 is an example of "first signature information." The public key PUK1 is an example of a "first public key." The print instruction of T264 in FIG. 7 is an example of a "first function execution instruction." The user ID is an example of "account information." The serial number "SN1" is an example of "predetermined information." The authentication request of T520 in FIG. 10 is an example of a "second authentication request." The one-time pass OP6 of T524 in FIG. 10 is an example of "second verification information." The private key PRK2 is an example of a "second private key." The signature information SI4 of T538 in FIG. 10 is an example of "second signature information." The public key PUK2 is an example of a "second public key." The print instruction of T264 in FIG. 7 cited in FIG. 10 is an example of a "second function execution instruction." T210 in FIG. 7 and T510 in FIG. 10 are examples of a "predetermined operation." The USB I / F 18 of the printer 10 is an example of an "interface." The serial number "SN1" is an example of "device identification information."

[0080] T220 in FIG. 6 is an example of a process executed by the "first authentication request transmitting unit." T224 in FIG. 6 is an example of a process executed by the "first verification information receiving unit." T238 in FIG. 7 is an example of a process executed by the "first signature information obtaining unit." T240 in FIG. 7 is an example of a process executed by the "first signature information transmitting unit." T264 in FIG. 7 is an example of a process executed by the "first receiving unit." T266 in FIG. 7 is an example of a process executed by the "first engine control unit." T520 in FIG. 10 is an example of a process executed by the "second authentication request transmitting unit." T524 in FIG. 10 is an example of a process executed by the "second verification information receiving unit." T538 in FIG. 10 is an example of a process executed by the "second signature information obtaining unit." T540 in FIG. 10 is an example of a process executed by the "second signature information transmitting unit." T264 in Fig. 7, which is cited in Fig. 10, is an example of processing executed by a "second receiving unit." T266 in Fig. 7, which is cited in Fig. 10, is an example of processing executed by a "second engine control unit."

[0081] (Second Example) A second embodiment will be described with reference to Figures 11 and 12. In the second embodiment, the processes executed by the printer 10 in the first print process and the second print process differ from the processes executed in the first embodiment.

[0082] (First printing process; Figure 11) The first printing process will be described with reference to Fig. 11. The initial state of the first printing process is similar to the initial state of the first printing process in Figs.

[0083] T610 and T611 are the same as T210 and T211 in Fig. 6. In this embodiment, the printer 10 transmits an authentication request including the serial number "SN1" and the RPID "URL1" to the server 200 in T612 without displaying the selection screen SC10 and the user ID input screen SC12.

[0084] When the server 200 receives the authentication request from the printer 10 in T612, it identifies the serial number "SN1" in the authentication request and determines that the serial number "SN1" is not stored in the management table 242. In this case, the server 200 sends an error response to the printer 10 in T614.

[0085] When the printer 10 receives an error response from the server 200 in T614, in T620 the printer 10 displays the selection screen SC10 on the display unit 14. T622, T624, T626, and T630 are respectively similar to T214, T216, T218, and T220 in Fig. 6. Thereafter, processing similar to T222 to T232 in Fig. 6 and T234 to T272 in Fig. 7 is executed between the printer 10 and the server 200.

[0086] (Second printing process; Figure 12) The second printing process will be described with reference to Fig. 12. The initial state of the second printing process is similar to the initial state of the second printing process in Fig. 10.

[0087] T710, T711, and T720 are the same as T510, T511, and T520 in FIG. 10, respectively.

[0088] When the server 200 receives the authentication request from the printer 10 in T720, it identifies the serial number "SN1" in the authentication request and determines that the serial number "SN1" is stored in the management table 242. In this case, the server 200 generates a one-time pass OP6 in T722, stores the one-time pass OP6 in the memory 234, and sends an authentication instruction including the RPID "URL1" and the one-time pass OP6 to the PC 100 in T724.

[0089] Thereafter, the same processes as those in T526 to T578 in FIG. 10 are executed between the printer 10 and the server 200.

[0090] According to the above configuration, the target user does not need to perform operations on the selection screen etc. in the second print process, thereby improving user convenience.

[0091] (Correspondence) The authentication request of T630 in Fig. 11 is an example of a "first authentication request." The authentication request of T720 in Fig. 12 is an example of a "second authentication request." T610 in Fig. 11 and T710 in Fig. 12 are examples of a "predetermined operation."

[0092] T630 in FIG. 11 is an example of processing performed by the "first authentication request transmitting unit." T224 in FIG. 6, which is cited in FIG. 11, is an example of processing performed by the "first verification information receiving unit." T238 in FIG. 7, which is cited in FIG. 11, is an example of processing performed by the "first signature information obtaining unit." T240 in FIG. 7, which is cited in FIG. 11, is an example of processing performed by the "first signature information transmitting unit." T264 in FIG. 7, which is cited in FIG. 11, is an example of processing performed by the "first receiving unit." T266 in FIG. 7, which is cited in FIG. 11, is an example of processing performed by the "first engine control unit." T720 in FIG. 12 is an example of processing performed by the "second authentication request transmitting unit." T724 in FIG. 12 is an example of processing performed by the "second verification information receiving unit." T538 in FIG. 10, which is cited in FIG. 12, is an example of processing performed by the "second signature information obtaining unit." T540 in Fig. 10, which is cited in Fig. 12, is an example of processing executed by a "second signature information transmitting unit." T564 in Fig. 10, which is cited in Fig. 12, is an example of processing executed by a "second receiving unit." T566 in Fig. 10, which is cited in Fig. 12, is an example of processing executed by a "second engine control unit."

[0093] (Third Example) A third embodiment will be described with reference to FIGS. 13 and 14. In the third embodiment, the processing executed by the printer 10 in the first and second printing processes differs from the processing executed in the first and second embodiments. Also, as shown in FIG. 1, setting information 42 is stored in the memory 34 of the printer 10 of this embodiment. The setting information 42 is information for specifying whether or not to use a user ID. Specifically, the setting information 42 is information for setting whether or not to display the selection screen SC10 and the user ID input screen SC12 on the display unit 14 of the printer 10 when an authentication device is attached to the printer 10. The setting information 42 indicates either "ON," which indicates that the use of a user ID is specified, or "OFF," which indicates that the use of a user ID is specified. The setting information 42 is set by an administrator of the printer 10.

[0094] (First printing process; Figure 13) The first printing process will be described with reference to Fig. 13. The initial state of the first printing process is the same as the initial state of the first printing process in Fig. 6 and Fig. 7, except that the setting information 42 is "ON".

[0095] T810 and T811 are the same as T210 and T211 in Fig. 6, respectively. At T812, the printer 10 determines that the setting information 42 in the memory 34 is "ON," and at T820, displays the selection screen SC10 on the display unit 14. T822, T824, T826, and T830 are the same as T214, T216, T218, and T220 in Fig. 6, respectively. Thereafter, processing similar to T222 to T232 in Fig. 6 and T234 to T272 in Fig. 7 is executed between the printer 10 and the server 200.

[0096] (Second printing process; Figure 14) The second printing process will be described with reference to Fig. 14. The initial state of the second printing process is the same as the initial state of the second printing process in Fig. 10, except that the setting information 42 is "OFF".

[0097] T910 and T911 are the same as T510 and T511 in Fig. 10, respectively. In T912, the printer 10 determines that the setting information 42 in the memory 34 is "OFF," and, without displaying the selection screen SC10, in T920 transmits an authentication request including the serial number "SN1" and the RPID "URL1" to the server 200. T922 and T924 are the same as T522 and T524 in Fig. 10, respectively. Thereafter, processing similar to T526 to T578 in Fig. 10 is executed between the printer 10 and the server 200.

[0098] According to the above configuration, the administrator of the printer 10 can set the setting information 42 to appropriately determine whether or not a user ID should be used.

[0099] (Correspondence) The authentication request T830 in FIG. 13 is an example of a "first authentication request." The authentication request T920 in FIG. 14 is an example of a "second authentication request." "ON" in the setting information 42 is an example of a "first value." "OFF" in the setting information 42 is an example of a "second value." The memory 34 of the printer 10 is an example of a "second memory."

[0100] T830 in FIG. 13 is an example of a process executed by the "first authentication request transmitting unit." T224 in FIG. 6, which is cited in FIG. 13, is an example of a process executed by the "first verification information receiving unit." T238 in FIG. 7, which is cited in FIG. 13, is an example of a process executed by the "first signature information obtaining unit." T240 in FIG. 7, which is cited in FIG. 13, is an example of a process executed by the "first signature information transmitting unit." T264 in FIG. 7, which is cited in FIG. 13, is an example of a process executed by the "first receiving unit." T266 in FIG. 7, which is cited in FIG. 13, is an example of a process executed by the "first engine control unit." T920 in FIG. 14 is an example of a process executed by the "second authentication request transmitting unit." T924 in FIG. 14 is an example of a process executed by the "second verification information receiving unit." T538 in FIG. 10, which is cited in FIG. 14, is an example of a process executed by the "second signature information obtaining unit." T540 in Fig. 10, which is cited in Fig. 14, is an example of processing executed by a "second signature information transmitting unit." T564 in Fig. 10, which is cited in Fig. 14, is an example of processing executed by a "second receiving unit." T566 in Fig. 10, which is cited in Fig. 14, is an example of processing executed by a "second engine control unit."

[0101] Although specific examples of the present invention have been described above in detail, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and variations of the specific examples exemplified above. Modifications of the above-mentioned embodiments are listed below.

[0102] (First Variation) The "function performing device" is not limited to a printer, but may be a scanner, MFP, etc. When a scanner is a "function performing device," a scan function is an example of a "specific function," and a scan engine is an example of a "function performing engine." When an MFP is an example of a "function performing device," a print function, a scan function, or a fax function is an example of a "specific function," and a print engine, a scan engine, or a fax engine is an example of a "function performing engine."

[0103] (Second Modification) The "account information" is not limited to a user ID, but may be a combination of a user ID and a password, or the like.

[0104] (Third Modification) The "biometric authentication information" is not limited to fingerprint authentication information, but may be voiceprint authentication information, face authentication information, or the like.

[0105] (Fourth Modification) The printer 10 may be provided with a reception unit that receives fingerprint authentication operations. In this modification, fingerprint information 62 may be stored in the memory 34 of the printer 10. In this modification, the memory 34 is an example of a "first memory." In another modification, a terminal device such as a smartphone may receive fingerprint authentication operations instead of the authentication device 50. In this case, the printer 10 may be provided with an NFC I / F. In this modification, the printer 10 communicates fingerprint authentication success information and the like with the terminal device via the NFC I / F. In this modification, the memory of the terminal device is an example of a "first memory."

[0106] (Fifth Modification) The "predetermined information" is not limited to a serial number, and may be a predetermined character string, information, etc. A Resident Key may be an example of the "predetermined information." In this modification, the "acquisition unit" may be omitted.

[0107] (Sixth Modification) The "device identification information" is not limited to a serial number, but may be a MAC address, a device name, or the like.

[0108] (Seventh Modification) T572 in FIG. 10 can be omitted.

[0109] (Eighth Modification) The server 200 may delete the RPID “URL1”, the public key PUK1, the user ID “Tanaka”, and the job ID “job1” from the management table 242, and may also delete the print data PD2 from the memory 234 at T272 in FIG.

[0110] (Ninth Modification) In each of the above embodiments, the processes of FIGS. 3 to 14 are realized by software (for example, programs 40, 140, 240), but at least one of these processes may be realized by hardware such as a logic circuit.

[0111] Furthermore, the technical elements described in this specification or drawings exhibit technical utility either alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Furthermore, the technologies illustrated in this specification or drawings simultaneously achieve multiple objectives, and achieving one of those objectives is itself technically useful.

[0112] In the scope of the claims at the time of filing, even if each claim depends on only some of the claims, it is not limited to the fact that each claim can depend on only those some of the claims. To the extent that there is no technical contradiction, each claim can also depend on other claims that were not dependent at the time of filing. In other words, the technology of each claim can be combined in various ways as follows: (Item 1) A function performing device that operates according to a predetermined authentication method using a pair of keys, a function execution engine for executing a specific function; a first authentication request sending unit that sends a first authentication request including the specific account information to a server when the input of the specific account information is accepted; a first verification information receiving unit that receives first verification information from the server in response to the first authentication request being transmitted to the server; a first signature information acquisition unit that acquires first signature information generated by encrypting the first verification information using a first private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the first verification information is received from the server; and a first signature information transmission unit that transmits the first signature information to the server, the server decrypting the first signature information using a first public key that is associated with the specific account information and stored in the server; a first receiving unit that receives a first function execution instruction from the server when the first signature information is successfully decrypted by the server; a first engine control unit that causes the function execution engine to execute the specific function when the first function execution instruction is received from the server; a second authentication request sending unit that sends a second authentication request including predetermined information to the server without accepting input of account information; a second verification information receiving unit that receives second verification information from the server in response to the second authentication request being transmitted to the server; a second signature information acquisition unit that acquires second signature information generated by encrypting the second verification information using a second private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the second verification information is received from the server; and a second signature information transmission unit that transmits the second signature information to the server, wherein the server decrypts the second signature information using a second public key that is associated with the predetermined information and stored in the server; a second receiving unit that receives a second function execution instruction from the server when the second signature information is successfully decrypted by the server; a second engine control unit that causes the function execution engine to execute the specific function when the second function execution instruction is received from the server; A function performing device comprising: (Item 2) The function performing device further comprises: A display unit; a first display control unit that, when a predetermined operation is accepted, causes the display unit to display a selection screen for selecting whether or not to use account information; the first authentication request transmission unit transmits the first authentication request to the server when use of account information is selected on the selection screen and input of the specific account information is accepted; Item 1. The function executing device according to item 1, wherein the second authentication request sending unit sends the second authentication request to the server without accepting input of account information when not using account information is selected on the selection screen. (Item 3) the second authentication request transmission unit, when a predetermined operation is accepted, transmits the second authentication request to the server without accepting input of account information; The function performing device further comprises: an error response receiving unit that receives an error response from the server in response to the second authentication request being sent to the server; 3. The function executing device according to claim 1, wherein the first authentication request sending unit sends the first authentication request to the server when the error response is received from the server and the input of the specific account information is accepted. (Item 4) The function performing device further comprises: a second memory for storing a setting value indicating either a first value indicating that use of account information is designated or a second value indicating that no use of account information is designated; the first authentication request transmission unit transmits the first authentication request to the server when the setting value in the second memory indicates the first value and the input of the specific account information is accepted; 4. The function executing device according to any one of items 1 to 3, wherein the second authentication request sending unit sends the second authentication request to the server without accepting input of account information when the setting value in the second memory indicates the second value. (Item 5) The function performing device further comprises: 5. The function performing device according to any one of claims 1 to 4, comprising an interface to which an authenticator comprising the first memory is connected. (Item 6) the predetermined information is device identification information that identifies the authentication device, the function performing device, Item 6. The function executing device according to item 5, further comprising a predetermined information acquisition unit that acquires the predetermined information from the authentication device when the authentication device is connected to the interface. (Item 7) the server erases the predetermined information and the second public key stored in the server if the decryption of the second signature information is successful; 7. A function executing device according to any one of items 1 to 6, wherein even if the server successfully decrypts the first signature information, the account information and the first public key stored in the server are not erased. (Item 8) A computer program for a function-performing device that operates according to a predetermined authentication method using a pair of keys, comprising: the function performing device, A computer, a function execution engine for executing a specific function; The computer program causes the computer to: a first authentication request sending unit that sends a first authentication request including the specific account information to a server when the input of the specific account information is accepted; a first verification information receiving unit that receives first verification information from the server in response to the first authentication request being transmitted to the server; a first signature information acquisition unit that acquires first signature information generated by encrypting the first verification information using a first private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the first verification information is received from the server; and a first signature information transmission unit that transmits the first signature information to the server, the server decrypting the first signature information using a first public key that is associated with the specific account information and stored in the server; a first receiving unit that receives a first function execution instruction from the server when the first signature information is successfully decrypted by the server; a first engine control unit that causes the function execution engine to execute the specific function when the first function execution instruction is received from the server; a second authentication request sending unit that sends a second authentication request including predetermined information to the server without accepting input of account information; a second verification information receiving unit that receives second verification information from the server in response to the second authentication request being transmitted to the server; a second signature information acquisition unit that acquires second signature information generated by encrypting the second verification information using a second private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the second verification information is received from the server; and a second signature information transmission unit that transmits the second signature information to the server, wherein the server decrypts the second signature information using a second public key that is associated with the predetermined information and stored in the server; a second receiving unit that receives a second function execution instruction from the server when the second signature information is successfully decrypted by the server; a second engine control unit that causes the function execution engine to execute the specific function when the second function execution instruction is received from the server; A computer program that functions as a (Item 9) 1. A method performed by a function-performing device operating according to a predetermined authentication scheme utilizing a pair of keys, comprising: a first authentication request sending step of sending a first authentication request including the specific account information to a server when the input of the specific account information is accepted; a first verification information receiving step of receiving first verification information from the server in response to the first authentication request being sent to the server; a first signature information acquisition step of acquiring first signature information generated by encrypting the first verification information using a first private key in the first memory when authentication of the target user using the biometric authentication information in the first memory is successful and the first verification information is received from the server; a first signature information transmitting step of transmitting the first signature information to the server, wherein the server decrypts the first signature information by using a first public key stored in the server in association with the specific account information; a first receiving step of receiving a first function execution instruction from the server if the first signature information is successfully decrypted by the server; a first engine control step of causing a function executing engine of the function executing device to execute a specific function when the first function executing instruction is received from the server; a second authentication request sending step of sending a second authentication request including predetermined information to the server without accepting input of account information; a second verification information receiving step of receiving second verification information from the server in response to the second authentication request being sent to the server; a second signature information acquisition step of acquiring second signature information generated by encrypting the second verification information using a second private key in the first memory when authentication of the target user using the biometric authentication information in the first memory is successful and the second verification information is received from the server; a second signature information transmitting step of transmitting the second signature information to the server, wherein the server decrypts the second signature information by using a second public key stored in the server in association with the predetermined information; a second receiving step of receiving a second function execution instruction from the server if the second signature information is successfully decrypted by the server; a second engine control step of causing the function execution engine to execute the specific function when the second function execution instruction is received from the server; A method comprising: [Explanation of symbols]

[0113] 2: Communication system, 6: Internet, 10: Printer, 12: Operation unit, 14: Display unit, 16: Print engine, 18: USB I / F, 20: Communication I / F, 30: Control unit, 32: CPU, 34: Memory, 40: Program, 42: Setting information, 50: Authenticator, 60: Memory, 62: Fingerprint information, 100: PC, 112: Operation unit, 114: Display unit, 120: Communication I / F, 130: Control unit, 132: CPU, 134: Memory, 140: OS program, 200: Server, 220: Communication I / F, 230: Control unit, 232: CPU, 234: Memory, 240: Program, 242: Management table

Claims

1. A function performing device that operates according to a predetermined authentication method using a pair of keys, a function execution engine for executing a specific function; a first authentication request sending unit that sends a first authentication request including the specific account information to a server when the input of the specific account information is accepted; a first verification information receiving unit that receives first verification information from the server in response to the first authentication request being transmitted to the server; a first signature information acquisition unit that acquires first signature information generated by encrypting the first verification information using a first private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the first verification information is received from the server; and a first signature information transmission unit that transmits the first signature information to the server, the server decrypting the first signature information using a first public key that is associated with the specific account information and stored in the server; a first receiving unit that receives a first function execution instruction from the server when the first signature information is successfully decrypted by the server; a first engine control unit that causes the function execution engine to execute the specific function when the first function execution instruction is received from the server; a second authentication request sending unit that sends a second authentication request including predetermined information to the server without accepting input of account information; a second verification information receiving unit that receives second verification information from the server in response to the second authentication request being transmitted to the server; a second signature information acquisition unit that acquires second signature information generated by encrypting the second verification information using a second private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the second verification information is received from the server; and a second signature information transmission unit that transmits the second signature information to the server, the server decrypting the second signature information by using a second public key that is stored in the server in association with the predetermined information; a second receiving unit that receives a second function execution instruction from the server when the second signature information is successfully decrypted by the server; a second engine control unit that causes the function execution engine to execute the specific function when the second function execution instruction is received from the server; A function performing device comprising:

2. The function performing device further comprises: A display unit; a first display control unit that, when a predetermined operation is accepted, causes the display unit to display a selection screen for selecting whether or not to use account information; the first authentication request transmission unit transmits the first authentication request to the server when use of account information is selected on the selection screen and input of the specific account information is accepted; 2. The function executing device according to claim 1, wherein the second authentication request sending unit sends the second authentication request to the server without accepting input of account information when not using account information is selected on the selection screen.

3. the second authentication request transmission unit transmits the second authentication request to the server when a predetermined operation is accepted, without accepting input of account information; The function performing device further comprises: an error response receiving unit that receives an error response from the server in response to the second authentication request being transmitted to the server; 2. The function executing device according to claim 1, wherein the first authentication request transmitting unit transmits the first authentication request to the server when the error response is received from the server and the input of the specific account information is accepted.

4. The function performing device further comprises: a second memory for storing a setting value indicating either a first value indicating that use of account information is designated or a second value indicating that no use of account information is designated; the first authentication request transmission unit transmits the first authentication request to the server when the setting value in the second memory indicates the first value and the input of the specific account information is accepted; 2. The function executing device according to claim 1, wherein the second authentication request sending unit sends the second authentication request to the server without accepting input of account information when the setting value in the second memory indicates the second value.

5. The function performing device further comprises: The function performing device according to claim 1 , further comprising an interface to which an authenticator having the first memory is connected.

6. the predetermined information is device identification information that identifies the authentication device, the function performing device, The function executing device according to claim 5 , further comprising a predetermined information acquisition unit that acquires the predetermined information from the authentication device when the authentication device is connected to the interface.

7. the server erases the predetermined information and the second public key stored in the server if the decryption of the second signature information is successful; 2. The function executing device according to claim 1, wherein even if the server successfully decrypts the first signature information, the account information and the first public key stored in the server are not deleted.

8. A computer program for a function-performing device that operates according to a predetermined authentication method using a pair of keys, comprising: the function performing device, A computer, a function execution engine for executing a specific function; The computer program causes the computer to: a first authentication request sending unit that sends a first authentication request including the specific account information to a server when the input of the specific account information is accepted; a first verification information receiving unit that receives first verification information from the server in response to the first authentication request being transmitted to the server; a first signature information acquisition unit that acquires first signature information generated by encrypting the first verification information using a first private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the first verification information is received from the server; and a first signature information transmission unit that transmits the first signature information to the server, the server decrypting the first signature information using a first public key that is associated with the specific account information and stored in the server; a first receiving unit that receives a first function execution instruction from the server when the first signature information is successfully decrypted by the server; a first engine control unit that causes the function execution engine to execute the specific function when the first function execution instruction is received from the server; a second authentication request sending unit that sends a second authentication request including predetermined information to the server without accepting input of account information; a second verification information receiving unit that receives second verification information from the server in response to the second authentication request being transmitted to the server; a second signature information acquisition unit that acquires second signature information generated by encrypting the second verification information using a second private key stored in the first memory when authentication of the target user using the biometric authentication information stored in the first memory is successful and the second verification information is received from the server; and a second signature information transmission unit that transmits the second signature information to the server, the server decrypting the second signature information by using a second public key that is stored in the server in association with the predetermined information; a second receiving unit that receives a second function execution instruction from the server when the second signature information is successfully decrypted by the server; a second engine control unit that causes the function execution engine to execute the specific function when the second function execution instruction is received from the server; A computer program that functions as a

9. 1. A method performed by a function-performing device operating according to a predetermined authentication scheme utilizing a pair of keys, comprising: a first authentication request sending step of sending a first authentication request including the specific account information to a server when the input of the specific account information is accepted; a first verification information receiving step of receiving first verification information from the server in response to the first authentication request being sent to the server; a first signature information acquisition step of acquiring first signature information generated by encrypting the first verification information using a first private key in the first memory when authentication of the target user using the biometric authentication information in the first memory is successful and the first verification information is received from the server; a first signature information transmitting step of transmitting the first signature information to the server, wherein the server decrypts the first signature information by using a first public key associated with the specific account information and stored in the server; a first receiving step of receiving a first function execution instruction from the server if the first signature information is successfully decrypted by the server; a first engine control step of causing a function executing engine of the function executing device to execute a specific function when the first function executing instruction is received from the server; a second authentication request sending step of sending a second authentication request including predetermined information to the server without accepting input of account information; a second verification information receiving step of receiving second verification information from the server in response to the second authentication request being sent to the server; a second signature information acquisition step of acquiring second signature information generated by encrypting the second verification information using a second private key in the first memory when authentication of the target user using the biometric authentication information in the first memory is successful and the second verification information is received from the server; a second signature information transmitting step of transmitting the second signature information to the server, wherein the server decrypts the second signature information by using a second public key stored in the server in association with the predetermined information; a second receiving step of receiving a second function execution instruction from the server if the second signature information is successfully decrypted by the server; a second engine control step of causing the function execution engine to execute the specific function when the second function execution instruction is received from the server; A method comprising:

Citation Information

Patent Citations

  • Image processing device, image processing device control method, program, system and system control method

    JP2019086937A