Information processing apparatus, authentication system, and information processing method
By combining standard authentication and additional authentication functions in the information processing device, and utilizing additional authentication factors for multi-factor authentication, the problem of difficulty in implementing multi-factor authentication in already installed custom authentication applications is solved, thereby improving security and reducing the need for modification.
Patent Information
- Application Number
- CN202480031429.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-05-16
- Filing Date
- 2024-05-07
- Publication Date
- 2025-12-05
AI Technical Summary
In information processing devices with custom authentication applications already installed, it is difficult to implement multi-factor authentication without modifying existing additional authentication functions.
By providing standard authentication and additional authentication functions in the information processing device, multi-factor authentication is performed based on different authentication factors using the standard authentication function, including displaying an additional login screen and using additional authentication factors for authentication when the customized authentication application is invalid.
This enables multi-factor authentication without modifying the already installed additional authentication functionality, improving security and reducing the need to modify custom authentication applications.
Smart Images

Figure CN121079682A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to an information processing apparatus, an authentication system, and an information processing method. BACKGROUND
[0002] An information processing apparatus can require a user using the information processing apparatus to perform an authentication operation. A manufacturer of the information processing apparatus provides an additional authentication function such as a custom authentication application in addition to a standard authentication function as a mechanism for a customer and a sales company to customize a user authentication function. The customer can use the custom authentication application to adopt a unique authentication method or a customized user interface.
[0003] A technology capable of performing multi-factor authentication for security enhancement is known (for example, Patent Literature (PTL) 1). For example, PTL 1 discloses a technology of implementing multi-factor authentication by installing an additional application.
[0004] List of Citations
[0005] Patent Literature
[0006]
PTL 1
[0007] Technical Problem
[0008] However, in such known technology, it is difficult to implement multi-factor authentication without modifying an additional authentication function already installed in the information processing apparatus. In other words, in order to implement multi-factor authentication in an information processing apparatus in which a custom authentication application is installed, the existing custom authentication application needs to be modified.
[0009] In view of the above problem, one or more embodiments of the present disclosure provide a technology for implementing multi-factor authentication without modifying an additional authentication function already installed.
[0010] Solution to Problem
[0011] Specifically, one or more embodiments of the present disclosure provide an information processing apparatus including a standard authentication function and an additional authentication function provided in advance. The standard authentication function authenticates a user based on an authentication result obtained by the additional authentication function using a first authentication factor and an authentication result obtained by the standard authentication function using a second authentication factor.
[0012] An information processing apparatus according to an embodiment of the present disclosure includes a standard authentication function and an additional authentication function provided in advance. The standard authentication function authenticates a user based on a plurality of authentication results obtained by a plurality of additional authentication functions using different authentication factors.
[0013] Effects of the Invention
[0014] According to one or more embodiments of the present disclosure, multi-factor authentication is performed without modifying an installed additional authentication function. BRIEF DESCRIPTION OF DRAWINGS
[0015] A more complete understanding of embodiments of the present disclosure and the many attendant advantages thereof can be readily acquired as the same is more fully described in the following detailed description together with the accompanying drawings.
[0016] [ Figure 1 ]
[0017] Figure 1 is a diagram representing a comparative example of a process flow of custom authentication performed by a custom authentication application.
[0018] [ Figure 2 ]
[0019] Figure 2 is a diagram representing a process flow of an authentication method for performing multi-factor authentication using a custom authentication application.
[0020] [ Figure 3 ]
[0021] Figure 3 is a diagram representing a configuration of an authentication system.
[0022] [ Figure 4 ]
[0023] Figure 4 is a diagram representing a hardware structure of an image forming apparatus.
[0024] [ Figure 5 ]
[0025] Figure 5 is a block diagram representing a functional structure of an image forming apparatus.
[0026] [ Figure 6 ]
[0027] Figure 6 is a sequence diagram of a process or action in which a user is authenticated by an image forming apparatus.
[0028] [ Figure 7 ]
[0029] Figure 7 is a diagram representing an authentication factor selection screen displayed by an image forming apparatus.
[0030] [ Figure 8 ]
[0031] Figure 8is a flowchart of a process for determining authentication by a standard authentication application according to an authentication factor selected on an authentication factor selection screen.
[0032] [ Figure 9 ]
[0033] Figure 9 is a block diagram showing a functional configuration of an image forming apparatus.
[0034] [ Figure 10 ]
[0035] Figure 10 is a diagram showing a flow of an authentication process when two custom authentication applications are enabled.
[0036] [ Figure 11 ]
[0037] Figure 11 is a sequence diagram of a process or action in which an image forming apparatus performs user authentication using two custom authentication applications.
[0038] The accompanying drawings are intended to depict embodiments of the application and should not be interpreted to limit the scope thereof. The drawings are intended for use with the explanations in the detailed description and together with the embodiments described therein to help explain how the application works. The drawings show the following: DETAILED DESCRIPTION
[0039] In describing the embodiments illustrated in the drawings, specific terminology is employed for the sake of clarity. However, the disclosure of this specification is not intended to be limited to the specific terms so selected and it is to be understood that each specific element includes all technical equivalents that have a similar function, operate in a similar manner, and achieve a similar result.
[0040] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings. The singular forms "a", "an", and "the" as used herein are intended to include plural references unless the context clearly indicates otherwise.
[0041] A description will be made below of an information processing apparatus according to an embodiment of the present disclosure and an information processing method executed by the information processing apparatus.
[0042] First Embodiment
[0043] The image forming apparatus according to the present embodiment operates in accordance with a standard authentication application that provides a standard authentication function and a custom authentication application. When the image forming apparatus performs user authentication, the image forming apparatus executes the custom authentication application for allowing a user to customize an authentication factor (e.g., login information for authentication) in addition to the standard authentication application, to implement multi-factor authentication. When the custom authentication application is not installed, the standard authentication application can perform user authentication (single-factor authentication) with a standard authentication factor.
[0044] Hereinafter, the operation of the custom authentication application and the standard authentication application that are compared with the present embodiment will be described with reference to Figure 1 Figure 1 is a diagram of a comparative example that shows a processing flow of custom authentication performed by the custom authentication application. The image forming apparatus 100 includes an operation apparatus 20 (an example of a first apparatus) and a host apparatus 10 (an example of a second apparatus). In particular, in this example, the host apparatus 10 is an image forming apparatus that performs image formation. The operation apparatus 20 and the host apparatus 10 are independent apparatuses that operate under the control of independent operating systems (OSs). It is assumed that a standard authentication application 42 and a custom authentication application 41 are installed in the operation apparatus 20. Hereinafter, the operation of each step of Figure 1 will be described.
[0045] (1) A user inputs login information to the custom authentication application 41. The login information is an example of a first authentication factor of the user, such as a user ID and a password, biometric authentication information, or a card number of an integrated circuit (IC) card.
[0046] (2) The custom authentication application 41 transmits a login request to the standard authentication application 42 together with the login information. In this example, the standard authentication application 42 communicates with the host apparatus 10 to request authentication of the custom authentication application 41. In this way, the standard authentication application 42 receives the login information and requests the host apparatus 10 to log in, regardless of whether the custom authentication application 41 is active or inactive.
[0047] (3) The standard authentication application 42 transmits the login request to the host apparatus 10 together with the login information. When the custom authentication application 41 is inactive, the host apparatus 10 manages authentication information. The host apparatus 10 performs a job for a user who has logged in, and thus the host apparatus 10 performs an authentication process such as determining whether the job can be performed. When the custom authentication application 41 is active, the host apparatus 10 acquires information of success of authentication of the user (a response of whether to allow login) from the standard authentication application 42.
[0048] (4) In this example, since the main device 10 does not manage the authentication information (the user does not prepare the authentication information in the case where the custom authentication application 41 is effective), the main device 10 requests the standard authentication application 42 to inquire the user information management server 200 whether to permit login.
[0049] (5) The standard authentication application 42 requests the custom authentication application 41 whether to permit login, together with the login information received from the custom authentication application 41.
[0050] (6) The custom authentication application 41 requests the user information management server 200 for user authentication, together with the login information input by the user. The custom authentication application 41 can perform the user authentication internally.
[0051] (7) The custom authentication application 41 transmits the response of whether to permit login (authentication success or authentication failure) acquired from the user information management server 200 to the standard authentication application 42.
[0052] (8) The standard authentication application 42 transmits the response of whether to permit login to the main device 10.
[0053] (9) When the response of whether to permit login indicates that the user authentication is successful, the main device 10 transmits a login result notification indicating that the login is permitted to the standard authentication application 42. After step (9), the operation device 20 can use the login result notification to request the main device 10 to perform a job.
[0054] As described above, in the comparative example, the standard authentication application 42 mediates the information and the request or response for the authentication between the main device 10 and the custom authentication application 41. In this embodiment, the processing flow performed between the custom authentication application 41 and the standard authentication application 42 is not changed, and the multi-factor authentication using the custom authentication application 41 is realized as follows.
[0055] Figure 2 is a diagram indicating a processing flow of the authentication method of this embodiment using the custom authentication application 41 for the multi-factor authentication. The following description of Figure 2 mainly focuses on the difference from Figure 1
[0056] (2) -2 In this embodiment, the standard authentication application 42 interrupts the login request from the custom authentication application 41, and displays another login screen different from the screen of the custom authentication application 41 on the operation panel. The standard authentication application 42 performs the login processing using the login information (an example of the second authentication factor) input to the other login screen.
[0057] (7) The custom authentication application 41 notifies the standard authentication application 42 of the response of whether to permit login from the user information management server 200.
[0058] (8) The standard authentication application 42 adds the result of the standard authentication application 42 in the response from the customized authentication application 41 as to whether to allow login to notify the host device 10 of the response as to whether to allow login. In other words, when the authentication using the login information input to the other login screen succeeds and the login result notification indicates that login is allowed, the standard authentication application 42 transmits a response indicating that the user can log in (authentication succeeded) to the host device 10. As a result, similarly to Figure 1 the comparative example, the host device 10 transmits a login result notification indicating that login is allowed to the standard authentication application 42 at step (9). After step (9), the operation device 20 can use the login result notification to request the host device 10 to execute a job.
[0059] In the processing of Figure 2 , the customized authentication application 41 does not need to be corrected, and the customized authentication application 41 transmits a login request to the standard authentication application 42 in substantially the same manner as in the processing of Figure 1 . The standard authentication application 42 requests input of login information different from that of the customized authentication application 41, and performs user authentication. Thus, the standard authentication application 42 can implement multi-factor authentication without correcting the customized authentication application 41.
[0060] The standard authentication application 42 performs multi-factor authentication based on the authentication result of the customized authentication application 41, and thus can control the processing flow of user authentication similarly to the case where the user authentication is performed by the standard authentication application 42 alone. The standard authentication application 42 can perform authentication alone, and thus can implement multi-factor authentication together with the authentication result of the customized authentication application 41 in the case where the customized authentication application 41 is valid. Even if the standard authentication application 42 needs to be corrected, the degree of modification can be reduced.
[0061] Authentication refers to determination of whether a user is a legitimate authorized person. Login information is information input by a user to, for example, an image forming apparatus at the time of authentication, and is used by the image forming apparatus to authenticate the user. Examples of login information include, in addition to a user ID and a password, a card number of an IC card and biometric identification information such as a fingerprint or an iris. Information to be compared with login information, which is saved in advance, is referred to as authentication information. Login information and authentication information have the same information.
[0062] A standard authentication function is an authentication function that is provided in advance in, for example, an image forming apparatus that is an example of an information processing apparatus. The standard authentication function authenticates a user based on login information provided in advance. In the present embodiment, the information processing apparatus implements the standard authentication function by executing a standard authentication application.
[0063] The additional authentication function is an authentication function that allows customization of login information (authentication factors). The user can determine whether or not the user uses the additional authentication function. The user can also customize the user interface in addition to the login information. In the present embodiment, the information processing apparatus implements the additional authentication function by executing a customization authentication application.
[0064] The multi-factor authentication refers to performing a plurality of user authentications on the same user using different login information. For example, the multi-factor authentication corresponds to a user authentication using two or more items of login information (i.e., in addition to a user ID and a password, a card number of an IC card and biometric authentication information).
[0065] Figure 3 is a diagram showing a configuration of the authentication system 300. The authentication system 300 includes the image forming apparatus 100 and the user information management server 200. The user information management server 200 and the image forming apparatus 100 are connected to each other via a wide area network N1 such as the Internet to communicate with each other. The image forming apparatus 100 is disposed at a facility such as a company and connected to a network N2 disposed at the facility. The N2 can be a local area network, a Wi-Fi (registered trademark) network, a wide area Ethernet (registered trademark) network, or the like. When the image forming apparatus 100 includes another type of second apparatus that is a mobile device, the network N2 can be a cellular network such as 4G, 5G, or 6G.
[0066] The user information management server 200 is a server that manages user information and performs user authentication. The user information management server 200 can be implemented by one or a plurality of computers. The user information management server 200 can be implemented by cloud computing. Alternatively, the user information management server 200 can be implemented by a single information processing apparatus such as a computer. "Cloud computing" refers to a usage pattern of using or accessing resources on a network without identifying specific hardware resources. The user information management server 200 can exist on the Internet. Alternatively, the user information management server 200 can exist in a local environment.
[0067] The image forming apparatus 100 can have one or more of a scanner function, a facsimile function, a print function, and a copy function used by a user. The image forming apparatus 100 can also be, for example, an MFP (Multifunction Peripheral) or the like that has a plurality of different functions. The image forming apparatus 100 can be referred to as an image processing apparatus, a print apparatus, a printer, or a scanner apparatus. A user who uses the image forming apparatus 100 can be requested to log in. In the present embodiment, the image forming apparatus 100 is described as an example. However, the information processing apparatus according to the present disclosure can be any information processing apparatus that a user logs in and uses.
[0068] The information processing apparatus can be implemented by a projector, an interactive whiteboard (IWB; an electronic whiteboard having intercommunication capability), a digital signage, a head-up display (HUD), an industrial machine, an imaging device, a sound collecting device, a medical device, a network-connected home appliance, a car (a network-connected car), a laptop personal computer (PC), a mobile phone, a smartphone, a tablet terminal, a game machine, a personal digital assistant (PDA), a digital camera, a wearable PC, or a desktop PC, in addition to the image forming apparatus 100.
[0069] Figure 4 is a diagram showing a hardware structure of the image forming apparatus 100. As shown in Figure 4 , the image forming apparatus 100 includes a main device 10 and an operation device 20. The main device 10 and the operation device 20 can communicate with each other.
[0070] The main device 10 can perform an action according to an operation received by the operation device 20. The main device 10 can also communicate with an external device such as a client PC, and can perform an action according to an instruction received from the external device.
[0071] A description of a hardware configuration of the main device 10 will be made below. As shown in Figure 4 , the main device 10 includes a central processing unit (CPU) 11, a read only memory (ROM) 12, a random access memory (RAM) 13, a hard disk drive (HDD) 14, a communication interface (I / F) 15, a connection I / F 16, and an engine 17, which are connected to each other via a system bus 18. For the sake of explanation, in Figure 4 , a configuration in which the main device 10 has the HDD 14 is exemplified. However, for example, if a sufficient storage area is not needed, the configuration of the main device 10 can not include the HDD 14.
[0072] The CPU 11 controls the overall action of the main device 10. The CPU 11 executes a program stored in the ROM 12 or the HDD 14 using the RAM 13 as a work area, thereby controlling the overall action of the main device 10, and realizing various functions such as copying, scanning, facsimile communication, and printing.
[0073] The communication I / F 15 is an interface circuit for connecting the main device 10 to a network N2. The connection I / F 16 is an interface circuit for communicating with the operation device 20 via a communication line 30. When the communication I / F 15 uses, for example, a universal serial bus (USB), communication and charging can be performed with one cable.
[0074] Engine 17 is hardware that performs general information processing and processing other than communication for enabling copying, scanning, faxing, and printing functions. Engine 17 may include, for example, a scanner that scans and reads images of originals, a plotter (image forming unit) that performs printing on sheets of paper, and a fax machine that performs fax communication. Image forming apparatus 100 may also include optional devices such as a post-processor for sorting printed sheets and an ADF (Automatic Document Provider) for automatically feeding originals. Image forming can be electrophotographic or inkjet.
[0075] The hardware configuration of the operating device 20 is described below. For example... Figure 4 As shown, the operating device 20 includes a CPU 21, ROM 22, RAM 23, flash memory 24, communication I / F 25, connection I / F 26, and an operation panel 27 interconnected via a system bus 28. These components have the same or substantially the same functions as the components of the main device 10. Even if these components have functions different from those of the main device 10, this does not pose an obstacle to the description of this embodiment.
[0076] The operation panel 27 is a flat panel display such as a liquid crystal display (LCD) or an organic EL display, and preferably has a touch panel integrated with the display. The operation panel 27 serves as both a display device and an input device. The operation panel 27 displays soft keys and receives soft key presses. The operation panel 27 may also include physical keys.
[0077] For ease of description, Figure 4 In the description, the operating device 20 is described as including flash memory 24. However, the operating device 20 may not include flash memory 24.
[0078] The following reference Figure 5 A description of the functions of the image forming device 100 that performs multi-factor authentication. Figure 5 This is a block diagram illustrating the functional structure of the image forming apparatus 100 according to an embodiment of the present invention.
[0079] As described above, in the operation device 20, the custom authentication application 41 and the standard authentication application 42 act. More specifically, the CPU 21 executes processing according to the standard authentication application 42 or the custom authentication application 41 loaded on the RAM 23 from the ROM 22. The standard authentication application 42 is a standard application for user authentication installed in the image forming apparatus 100 at the time of shipment (or installed by a customer engineer at the time of installation). The custom authentication application 41 is an application for user authentication provided in order to make it easy to customize the user authentication function. When the standard authentication application 42 performs user authentication, the user needs to log in with predetermined login information. However, when the custom authentication application 41 performs user authentication, the user can adopt unique login information or a customized user interface. For example, the user can set a user ID and a password, biometric authentication information, or authentication using an IC card as login information in the custom authentication application 41.
[0080] The custom authentication application 41 can communicate with a user information management server 200 managed and operated by the user. The user information management server 200 stores, for example, authentication information for each user. When the user information management server 200 includes authentication information consistent with the login information transmitted by the custom authentication application 41, the user information management server 200 determines that user authentication is successful. By the successful authentication, the user is determined, and the operation device 20 can acquire a user ID.
[0081] The standard authentication application 42 includes a first communication unit 51, an authentication control unit 52, a second communication unit 53, and an authentication execution unit 54. These functions of the standard authentication application 42 are functions or means realized by operating one or more hardware components illustrated in cooperation with the instructions of the CPU 21 according to the program loaded from the ROM 22 to the RAM 23. Figure 4 The standard authentication application 42 and the custom authentication application 41 can be distributed from a server for program distribution or stored in a storage medium to be distributed.
[0082] The first communication unit 51 communicates with the custom authentication application 41, and transmits and receives information required for authentication between the custom authentication application 41.
[0083] The authentication control unit 52 performs control in accordance with the standard authentication application 42. Figure 1The authentication control unit 52 follows the same steps as the comparative example to control the authentication process. That is, the authentication control unit 52 controls the authentication process using the same procedure in any of the following cases: authentication using only the standard authentication application 42, authentication using only the customized authentication application 41, and multi-factor authentication. The authentication control unit 52 determines whether user authentication is successful based on the authentication results of all factors (e.g., two factors) of multi-factor authentication. The authentication control unit 52 determines that user authentication is successful if all authentication results are successful. However, if the customer has set the user authentication to succeed only when one authentication result is successful, the authentication control unit 52 may also determine that user authentication is successful if at least one authentication result is successful.
[0084] The second communication unit 53 communicates with the main device 10 to send and receive authentication information from the main device 10. Since the main device 10 can remain unchanged or be changed to a minimum in the case of multi-factor authentication, the second communication unit 53 sends and receives the same information to and from the main device 10 as in the comparative example.
[0085] The authentication execution unit 54 uses the login information input into a login screen displayed separately from the customized authentication application 41 to perform user authentication. Preferably, the authentication execution unit 54 requests login information from the user that is different from that in the customized authentication application 41, and uses this login information to authenticate the user. Therefore, even if the login information of the customized authentication application 41 is leaked, as long as the login information of the standard authentication application 42 is not leaked, it is difficult for third parties to log in to the image forming device 100, thus improving security.
[0086] The host device 10 may or may not manage authentication information. For example, authentication information may be included in the host device 10 or managed by a directory server on the network. When the authentication of the custom authentication application 41 is invalid, the host device 10 manages the authentication information. In this case, the host device 10 performs authentication processing. When the authentication of the custom authentication application 41 is valid, the host device 10 does not manage the authentication information (even if it does manage the authentication information, the host device 10 does not perform user authentication). In this case, since the host device 10 does not include authentication information, it returns a query asking whether login is allowed for login requests from the standard authentication application 42.
[0087] In this embodiment, since the case where the customized authentication application 41 is effective is described, the main device 10 does not manage authentication information. The standard authentication application 42 and the customized authentication application 41 perform user authentication separately.
[0088] The following is about Figure 2 The authentication process of this embodiment will be described below. Figure 2The number in the middle is dialed.
[0089] (1) The user inputs login information to the custom authentication application 41. The login information is, for example, a user ID and a password, biometric authentication information, or a card number of an IC card.
[0090] (2) The custom authentication application 41 sends a login request to the standard authentication application 42 together with the login information. The standard authentication application 42 performs communication with the main device 10 for authentication. The standard authentication application 42 receives the login information, requests the main device 10 to log in, regardless of whether the custom authentication application 41 is valid.
[0091] (2)-2 The standard authentication application 42 interrupts the login request from the custom authentication application 41 in a case where the multi-factor authentication is valid, and displays a login screen (an example of a second login screen) different from the login screen displayed by the custom authentication application 41. The user inputs login information (for example, a user ID and a password, biometric authentication information, or a card number of an IC card, which are examples of second login information) to the standard authentication application 42. The standard authentication application 42 authenticates the user using the input login information.
[0092] The timing at which the standard authentication application 42 authenticates the user can be any timing between the timing immediately after the login information is input to the second login screen and the timing after the response of whether to allow login is received from the user information management server 200. The standard authentication application 42 can perform authentication immediately after the login information is input to the second login screen, and can omit subsequent processing in a case where the authentication fails.
[0093] (3) The standard authentication application 42 sends a login request to the main device 10 together with the login information from the custom authentication application 41. The main device 10 manages authentication information when the custom authentication application 41 is not valid. The main device 10 performs a job on the logged-in user, and performs authentication processing of whether the job execution is possible. The main device 10 acquires information indicating that the user has been successfully authenticated (a response of whether to allow login) from the standard authentication application 42 when the custom authentication application 41 is valid.
[0094] (4) Since the main device 10 does not manage authentication information (the user does not prepare authentication information when the custom authentication application 41 is valid), the main device 10 requests the standard authentication application 42 to inquire the user information management server 200 of whether to allow login.
[0095] (5) The standard authentication application 42 requests the custom authentication application 41 of an inquiry of whether to allow login together with the login information received from the custom authentication application 41.
[0096] (6) The customized authentication application 41 requests user authentication to the user information management server 200 together with the login information input by the user. The customized authentication application 41 can perform user authentication internally.
[0097] (7) The customized authentication application 41 transmits the response of whether or not the login is allowed (authentication success or authentication failure) acquired from the user information management server 200 to the standard authentication application 42.
[0098] (8) The standard authentication application 42 determines that the user authentication to the image forming apparatus 100 is successful in a case where both the authentication result included in the response of whether or not the login is allowed and the authentication result of the standard authentication application 42 indicate the authentication success. More specifically, when the user ID included in the response of whether or not the login is allowed coincides with the user ID authenticated by the standard authentication application 42 (when it is determined that the user is the same user), the standard authentication application 42 determines that the user authentication to the image forming apparatus 100 is successful. The standard authentication application 42 transmits the response of whether or not the login is allowed including the authentication success or the authentication failure to the host device 10.
[0099] (9) When the response of whether or not the login is allowed indicates the user authentication success, the host device 10 transmits a login result notification indicating that the login is allowed to the standard authentication application 42. After step (9), the operation device 20 can request the host device 10 to execute a job using the login result notification.
[0100] (10) The standard authentication application 42 notifies the login result to the customized authentication application 41 to notify the final authentication result.
[0101] As described above, since the standard authentication application 42 performs user authentication using the second factor without changing the existing interfaces between the standard authentication application 42 and the customized authentication application 41 and between the standard authentication application 42 and the host device 10, multi-factor authentication can be implemented without modifying the existing customized authentication application 41.
[0102] Figure 6 is a time chart of a process or an action in which the image forming apparatus 100 performs user authentication. Figure 6 The following description of Figure 2 overlaps with the description of
[0103] In step S1 corresponding to (1), the customized authentication application 41 displays a login screen generated by the customized authentication application 41. The user inputs login information to the customized authentication application 41. In the following description, the login information input to the customized authentication application 41 is referred to as login information A.
[0104] In step S2 corresponding to (2), the customized authentication application 41 sends the login information A to the standard authentication application 42 together with the login request. For consistency of processing, the sending of the login information A from the customized authentication application 41 to the standard authentication application 42 is set in advance in the customized authentication application 41.
[0105] In step S3 corresponding to (2)-2, the first communication unit 51 receives the login request from the customized authentication application 41. The authentication control unit 52 judges to display a second login screen different from the login screen of the customized authentication application 41 according to the login request in the case where the multi-factor authentication is effective, and requests the authentication execution unit 54 to display the second login screen. The authentication execution unit 54 causes the operation panel 27 to display the second login screen. The second login screen can also be displayed after step S10.
[0106] In step S4 corresponding to (2)-2, the user inputs the login information to the standard authentication application 42. In the following description, the login information input to the standard authentication application 42 is referred to as login information B.
[0107] In step S5 corresponding to (3), the authentication control unit 52 decides to send the login request from the customized authentication application 41 to the host device 10 as in the comparative example. The second communication unit 53 sends the login request to the host device 10 together with the login information A from the customized authentication application 41. This sending of the login request from the second communication unit 53 to the host device 10 can be performed in parallel with the display of the second login screen.
[0108] In step S6 corresponding to (4), the host device 10 receives the login request. However, since the host device 10 does not include the authentication information, the host device 10 requests the standard authentication application 42 to inquire the user information management server 200 about whether the login is allowed.
[0109] In step S7 corresponding to (5), the second communication unit 53 of the standard authentication application 42 receives the inquiry about whether the login is allowed. The authentication control unit 52 causes the first communication unit 51 to send the inquiry about whether the login is allowed to the customized authentication application 41 together with the login information A upon receiving the inquiry about whether the login is allowed.
[0110] In step S8 corresponding to (6), the customized authentication application 41 requests the user authentication to the user information management server 200 together with the login information A input by the user. The customized authentication application 41 can perform the user authentication internally.
[0111] In step S9, the user information management server 200 determines whether the user authentication is successful or not based on whether the user information management server 200 stores the authentication information identical to the login information A. The user information management server 200 transmits a response of whether the login is allowed to the customization authentication application 41. The customization authentication application 41 receives the response of whether the login is allowed (authentication success or authentication failure) from the user information management server 200. In addition, the customization authentication application 41 can receive the user ID in the case where the user authentication is successful.
[0112] In step S10 corresponding to (7), the customization authentication application 41 transmits the response of whether the login is allowed (authentication success or authentication failure) to the standard authentication application 42.
[0113] In step Sll corresponding to (8), the first communication unit 51 of the standard authentication application 42 receives the response of whether the login is allowed (authentication success or authentication failure). When the response of whether the login is allowed indicates the authentication success, the authentication control unit 52 causes the authentication execution unit 54 to perform the user authentication using the login information B. In other words, when the pre-set authentication information includes the authentication information identical to the login information B, the authentication execution unit 54 determines that the user authentication is successful. On the other hand, when the pre-set authentication information does not include the authentication information identical to the login information B, the authentication execution unit 54 determines that the user authentication is failed. When the user authentication is successful, the authentication execution unit 54 specifies the user ID. The user authentication performed by the authentication execution unit 54 can be performed at any time after the login information B is received by the standard authentication application 42 in step S4.
[0114] When both the user authentication result included in the response of whether the login is allowed and the user authentication result of the authentication execution unit 54 indicate the authentication success, the authentication control unit 52 determines that the user authentication to the image forming apparatus 100 is successful. More specifically, when the user ID included in the response of whether the login is allowed coincides with the user ID authenticated by the authentication execution unit 54 (when it is determined that the user is the same user), the authentication control unit 52 determines that the user authentication to the image forming apparatus 100 is successful.
[0115] In step S12, the second communication unit 53 transmits the response of whether the login is allowed including the authentication success or the authentication failure to the host device 10.
[0116] In step S13 corresponding to (9), when the response of whether the login is allowed indicates the user authentication success, the host device 10 transmits the login result notification indicating that the login is allowed to the standard authentication application 42. After step S13, the operation device 20 can request the host device 10 to perform the job using the login result notification.
[0117] In Figure 6In step Sll, the standard authentication application 42 performs user authentication using the login information B after receiving the response of whether the login is permitted from the user information management server 200. However, the standard authentication application 42 can also perform user authentication immediately after step S4. In this case, in the case where the user authentication of the standard authentication application 42 fails, the process can also be suspended after step S5.
[0118] The standard authentication application 42 can display the second login screen after receiving the response of whether the login is permitted from the user information management server 200 in step Sll. In this case, the standard authentication application 42 can also not display the second login screen in the case where the login permission response from the user information management server 200 indicates that the user authentication has failed.
[0119] In the present embodiment, the custom authentication application 41 can also perform the same process as the comparative example, that is, the custom authentication application 41 transmits a login request to the standard authentication application 42. In addition, the standard authentication application 42 requests input of login information different from the custom authentication application 41, and performs authentication using the different login information, and thus the standard authentication application 42 can implement multi-factor authentication without modification of the custom authentication application 41. Even if the standard authentication application 42 needs to be modified, the degree of modification can be reduced.
[0120] Second Embodiment
[0121] Hereinafter, the image forming apparatus 100 of the present embodiment, which can implement multi-factor authentication by a user combining a plurality of custom authentication applications 41, will be described. In the case where three or more custom authentication applications 41 are installed in the image forming apparatus 100, the user can combine any two or more custom authentication applications 41. The image forming apparatus 100 displays an authentication factor selection screen on which two or more custom authentication applications 41 can be selected, and performs multi-factor authentication by combining any two or more of the custom authentication applications 41 selected by the user.
[0122] Figure 7 is a diagram showing an authentication factor selection screen 400 displayed by the image forming apparatus 100. The administrator of the image forming apparatus 100 can display the authentication factor selection screen 400, and ask the user to select which custom authentication application 41 to use. In the case where the user selects the custom authentication application 41, the image forming apparatus 100 displays the authentication factor selection screen 400 shown in Figure 7 In the example of, the login information (IC card, password, fingerprint) and the custom authentication application 41 are associated with each other. When the administrator selects the login information desired by the user, the custom authentication application 41 corresponding to the selected login information is also selected.
[0123] The authentication factor selection screen 400 includes single selection buttons 401 and 402 for selecting whether or not to use the custom authentication application 41. When the single selection button 402 for not using the custom authentication application 41 is selected, only the user authentication by the standard authentication application 42 is performed (multi-factor authentication is not performed). When the custom authentication application 41 is additionally installed, the user can select whether or not to perform multi-factor authentication.
[0124] When the single selection button 401 for using the custom authentication application 41 is selected, an authentication factor setting check box 403 is enabled (selected). The authentication factor setting check box 403 corresponds to the authentication factors (IC card, password, and fingerprint). The administrator makes a selection in the authentication factor setting check box 403 of the authentication factors that are to be set as login information in multi-factor authentication.
[0125] When the administrator selects two or more authentication factors (custom authentication application 41) using the authentication factor setting check box 403, multi-factor authentication can be performed even without authentication by the standard authentication application 42. That is, in the case where the administrator selects only one multi-factor authentication, the custom authentication application 41 and the standard authentication application 42 perform multi-factor authentication (as in the first embodiment), and in the case where the administrator selects two or more multi-factor authentications, two or more custom authentication applications 41 corresponding to the selected authentications perform multi-factor authentication.
[0126] Figure 8 is a flowchart of the determination of the authentication performed by the standard authentication application 42 according to the authentication factors selected on the authentication factor selection screen 400.
[0127] In step S101, the operation panel 27 of the image forming apparatus 100 displays the authentication factor selection screen 400, and receives the setting of multi-factor authentication.
[0128] In step S102, the authentication control unit 52 of the standard authentication application 42 determines whether or not multi-factor authentication (single selection button 401 for using the custom authentication application 41) is selected.
[0129] In the case where the single selection button 401 for using the custom authentication application 41 is not selected (step S102: No), in step S107, the authentication control unit 52 determines that the user authentication is performed only by the standard authentication application 42.
[0130] When the single selection button 401 for using the custom authentication application 41 is selected (step S102: Yes), in step S103, the authentication control unit 52 determines which authentication function is to be used according to the custom authentication application 41 that is enabled by the selection.
[0131] When the number of valid custom authentication applications 41 is one, the authentication control section 52 determines that the standard authentication application 42 and the custom authentication application 41 perform user authentication in step S104.
[0132] In step S105, the authentication control unit 52 determines that two custom authentication applications 41 selected by the user perform user authentication when the number of valid custom authentication applications 41 is two.
[0133] In step S106, the authentication control unit 52 determines that three custom authentication applications 41 selected by the user perform user authentication when the number of valid custom authentication applications 41 is three.
[0134] As described above, the image forming apparatus 100 of the present embodiment can implement user authentication using only the standard authentication application 42, user authentication using the standard authentication application 42 and the custom authentication application 41, or user authentication using the custom authentication application 41 without modifying the custom authentication application 41.
[0135] Figure 9 is a block diagram showing the functional structure of the image forming apparatus 100 according to the present embodiment. Refer to the description of Figure 9 for the details of the functional structure of the image forming apparatus 100. Figure 5 The description of mainly focuses on the differences from
[0136] Figure 9 In the operation device 20, the custom authentication applications 41A and 41B and the standard authentication application 42 are operating. Since two custom authentication applications 41 are selected by the user, the custom authentication applications 41A and 41B are indicated in
[0137] The standard authentication application 42 has the same functions as Figure 5 However, Figure 9 The authentication execution unit 54 in does not perform user authentication. When two or more custom authentication applications 41 are selected, the authentication control unit 52 skips user authentication by the authentication execution unit 54.
[0138] The custom authentication application 41A can communicate with the user information management server 200A managed and operated by the customer. The custom authentication application 41B can communicate with the user information management server 200B managed and operated by the customer. The user information management servers 200A and 200B respectively store authentication information of each user corresponding to the custom authentication applications 41A and 41B. Either of the user information management servers 200A and 200B can also store login information corresponding to the custom authentication applications 41A and 41B.
[0139] Figure 5 The functions of the host device 10 can be the same asThe function of the main device 10 in FIG. 2 is the same. When the user authentication of the custom authentication application 41 is enabled, the main device 10 does not manage the authentication information. In this case, since the main device 10 does not manage the authentication information, the main device 10 returns a query about whether or not to allow login in response to a login request from the standard authentication application 42.
[0140] Figure 10 is a diagram showing a flow of the authentication process when two custom authentication applications 41 are enabled. The following description is made in the order of the numbers in Figure 10
[0141] (1) The user inputs login information C (user ID and password, biometric information, or card number of an IC card) to the custom authentication application 41A.
[0142] (2) The custom authentication application 41A sends a login request to the standard authentication application 42 together with the login information C. The standard authentication application 42 communicates with the main device 10 for authentication. The standard authentication application 42 receives the login information, requests the main device 10 to log in, regardless of whether or not the custom authentication application 41 is enabled.
[0143] (3) The standard authentication application 42 sends the login request to the main device 10 together with the login information C from the custom authentication application 41A. When the custom authentication applications 41A and 41B are not enabled, the main device 10 manages the authentication information. The main device 10 performs a job on the user who logs in, and performs an authentication process of whether or not the job execution is possible. When the custom authentication applications 41A and 41B are enabled, the main device 10 acquires information indicating that the user has been successfully authenticated (response of whether or not to allow login) from the standard authentication application 42.
[0144] (4) Since the main device 10 does not manage the authentication information, the main device 10 requests the standard authentication application 42 to query the user information management server 200 (the main device 10 does not specify the user information management servers 200A and 200B) whether or not to allow login.
[0145] (5) The standard authentication application 42 requests the custom authentication application 41A to query whether or not to allow login together with the login information C received from the custom authentication application 41A.
[0146] (6) The custom authentication application 41A requests the user information management server 200A to authenticate the user together with the login information C input by the user. The custom authentication application 41A can also perform the user authentication internally.
[0147] (7) The custom authentication application 41A sends the response A of whether or not to allow login acquired from the user information management server 200A to the standard authentication application 42.
[0148] (8)-1, (8)-2 When set as the case where the custom authentication application 41B is valid, the standard authentication application 42 requests the display of a login screen (an example of a third login screen) to the custom authentication application 41B. The user inputs login information D (for example, a user ID and a password, biometric authentication information, or a card number of an IC card as examples of the third login information) to the custom authentication application 41B.
[0149] (9) The custom authentication application 41B transmits a login request to the standard authentication application 42 together with the login information D. The standard authentication application 42 performs authentication communication with the host device 10. The standard authentication application 42 receives the login information and requests login to the host device 10 when the custom authentication application 41A, 41B is valid or invalid.
[0150] (10) The standard authentication application 42 has received a query request on whether or not to allow login from the host device 10, and thus requests the custom authentication application 41B on whether or not to allow login with the received login information D.
[0151] (11) The custom authentication application 41B requests user authentication to the user information management server 200B together with the login information D input by the user. The custom authentication application 41B can perform user authentication internally.
[0152] (12) The custom authentication application 41B transmits a response B on whether or not to allow login acquired from the user information management server 200B to the standard authentication application 42.
[0153] (13) In a case where both the authentication result included in the response A on whether or not to allow login and the authentication result included in the response B on whether or not to allow login indicate that authentication is successful, the standard authentication application 42 determines that user authentication to the image forming apparatus 100 is successful. More specifically, in a case where the user ID included in the response A on whether or not to allow login coincides with the user ID included in the response B on whether or not to allow login (in a case where it is determined that it is the same user), the standard authentication application 42 determines that user authentication to the image forming apparatus 100 is successful. The standard authentication application 42 transmits a response on whether or not to allow login including authentication success or authentication failure to the host device 10.
[0154] (14) When the response on whether or not to allow login indicates that user authentication is successful, the host device 10 transmits a login result notification indicating that login is allowed to the standard authentication application 42. Thereafter, the operation device 20 can request the host device 10 to perform a job using the login result notification.
[0155] (15) The standard authentication application 42 notifies the custom authentication application 41A, 41B of the login result notification in order to notify the final authentication result.
[0156] As described above, even in the case where the operation device 20 includes a plurality of custom authentication applications 41, the standard authentication application 42 performs user authentication using the second factor without changing the existing interface between the standard authentication application 42 and the custom authentication application 41A, between the standard authentication application 42 and the custom authentication application 41B, and between the standard authentication application 42 and the host device 10. Thus, the multi-factor authentication can be implemented without revising the existing custom authentication applications 41A and 41B.
[0157] Figure 11 is a timing chart of a process or an action in which the image forming device 100 performs user authentication using two custom authentication applications 41A and 41B. Figure 11 The following description of Figure 10 overlaps with the description of
[0158] In step S21, the custom authentication application 41A displays a login screen generated by the custom authentication application 41A. The user inputs login information to the custom authentication application 41A. In the following description, the login information input to the custom authentication application 41A is referred to as login information C.
[0159] In step S22, the custom authentication application 41A transmits the login information C to the standard authentication application 42 together with a login request, but for consistency of the process, the transmission of the login information C from the custom authentication application 41A to the standard authentication application 42 is set in advance in the custom authentication application 41.
[0160] In step S23, the first communication unit 51 receives the login request from the custom authentication application 41A. Since two custom authentication applications are valid, the authentication control unit 52 does not display the second login screen. As in the process of the comparative example, the authentication control unit 52 causes the second communication unit 53 to transmit a login request designating the login information to the host device 10.
[0161] In step S24, the host device 10 manages authentication information when the custom authentication applications 41A and 41B are invalid. However, in the present embodiment, the host device 10 does not have authentication information, and thus the host device 10 requests the standard authentication application 42 to inquire of the user information management servers whether login is allowed (the host device 10 does not specify the user information management servers 200A and 200B).
[0162] In step S25, the second communication unit 53 of the standard authentication application 42 receives the inquiry about whether login is allowed. The authentication control unit 52, upon receiving the inquiry about whether login is allowed, causes the first communication unit 51 to transmit the inquiry about whether login is allowed to the custom authentication application 41A together with the login information C.
[0163] In step S26, the custom authentication application 41A requests user authentication to the user information management server 200A along with the login information C input by the user. The custom authentication application 41A can also internally perform user authentication.
[0164] In step S27, the user information management server 200A determines whether the user authentication is successful or not based on whether the user information management server 200A stores the same authentication information as the login information C. The custom authentication application 41A receives a response A of whether the login is permitted (authentication success or authentication failure) from the user information management server 200A. The custom authentication application 41A can also receive the user ID when the user authentication is successful.
[0165] In step S28, the custom authentication application 41A transmits the response A of whether the login is permitted (authentication success or authentication failure) to the standard authentication application 42.
[0166] In step S29, the first communication unit 51 of the standard authentication application 42 receives the response A of whether the login is permitted (authentication success or authentication failure). In the same sequence as the comparative example, the authentication control unit 52 transmits the login request to the main device 10. However, the inquiry about whether the login is permitted has been received from the main device 10. Since the user also activates the custom authentication application 41B, the authentication control unit 52 causes the custom authentication application 41B to display the third login screen.
[0167] In step S30, the custom authentication application 41B displays the login screen generated by the custom authentication application 41B.
[0168] In step S31, the user inputs the login information to the custom authentication application 41B. In the following description, the login information input to the custom authentication application 41B is referred to as login information D.
[0169] In step S32, the custom authentication application 41B transmits the login information D to the standard authentication application 42 along with the login request, but for consistency of processing, the transmission of the login information D from the custom authentication application 41B to the standard authentication application 42 is set in advance in the custom authentication application 41B.
[0170] In step S33, the first communication unit 51 receives the login request from the custom authentication application 41B. The authentication control unit 52, since the inquiry about the login permission has been received from the main device 10, causes the first communication unit 51 to transmit the login information D to the custom authentication application 41B along with the inquiry about whether the login is permitted, in accordance with the reception of the login request.
[0171] In step S34, the custom authentication application 41B requests user authentication to the user information management server 200B along with the login information D input by the user. The custom authentication application 41B can internally perform user authentication.
[0172] In step S35, the user information management server 200B determines whether user authentication is successful or not based on whether the user information management server 200B includes the same authentication information as the login information D. The custom authentication application 41B receives a response B of whether login is allowed (authentication success or authentication failure) from the user information management server 200B. In addition, the custom authentication application 41B can receive a user ID in the case where user authentication is successful.
[0173] In step S36, the custom authentication application 41B transmits the response B of whether login is allowed (authentication success or authentication failure) to the standard authentication application 42.
[0174] In step S37, the first communication unit 51 receives the response B of whether login is allowed (authentication success or authentication failure). After the authentication based on the two custom authentication applications 41A, 41B ends, the authentication control unit 52 determines that user authentication to the image forming apparatus 100 is successful in the case where both the authentication result included in the response A of whether login is allowed and the authentication result included in the response B of whether login is allowed are successful. More specifically, when the user ID included in the response A of whether login is allowed coincides with the user ID included in the response B of whether login is allowed (when it is determined that the user is the same user), the authentication control unit 52 determines that user authentication to the image forming apparatus 100 is successful.
[0175] In step S38, the second communication unit 53 transmits the response of whether login is allowed including authentication success or authentication failure to the host device 10.
[0176] In step S39, when the response of whether login is allowed indicates that user authentication is successful, the host device 10 transmits a login result notification indicating that login is allowed to the standard authentication application 42. Thereafter, the operation device 20 can request the host device 10 to perform a job using the login result notification.
[0177] In the present embodiment, even in the case where a plurality of custom authentication applications 41 are valid, the custom authentication application 41 can perform the same processing as in the comparative example, that is, the custom authentication application 41 transmits a login request to the standard authentication application 42. The standard authentication application 42 can comprehensively use the authentication results of the plurality of custom authentication applications 41 that are valid to determine whether login is allowed. Thereby, the standard authentication application 42 can implement multi-factor authentication without changing the custom authentication application 41.
[0178] The above-described embodiments are merely illustrative, and do not limit the present application. Numerous additional modifications and variations are possible in light of the above teachings. For example, elements and / or features of different illustrative embodiments can be combined with each other and / or substituted for each other within the scope of the present application. Any one of the above-described operations can be performed in various other manners, such as in an order different from the order described above.
[0179] For example, the operation device 20 and the main device 10 can not be separated, and the operation device 20 and the main device 10 can be included in one image forming apparatus in a form in which the operation device 20 and the main device 10 are not separated. The operation device 20 and the main device 10 can be operated by the same OS.
[0180] To facilitate understanding of the processing of the image forming apparatus 100, the processing is divided into, for example Figure 5 the configuration example illustrated. The scope of the present disclosure is not limited by how the processing units are divided or the names of the processing units. The processing of the image forming apparatus 100 is divided into more finely divided processing units depending on the processing content. One processing can be divided into a larger number of processes.
[0181] Each function of the above-described embodiments can be implemented by one or more processing circuits or circuitry. The processing circuit includes a programmed processor, and the processor includes a circuit. The processing circuit also includes devices such as an application specific integrated circuit (ASIC), a digital signal processor (DSP), a field programmable gate array (FPGA), and a circuit module configured to perform the described functions.
[0182] Some aspects of the present disclosure are described below.
[0183] Aspect 1
[0184] An information processing apparatus includes a standard authentication function provided in advance and an additional authentication function. The information processing apparatus authenticates a user based on an authentication result obtained by the additional authentication function using a first authentication factor and an authentication result obtained by the standard authentication function using a second authentication factor, or a plurality of authentication results obtained by a plurality of additional authentication functions including the additional authentication function using different authentication factors.
[0185] Aspect 2
[0186] An information processing apparatus includes a standard authentication function provided in advance and a plurality of additional authentication functions. The information processing apparatus authenticates a user based on a plurality of authentication results obtained by the plurality of additional authentication functions using different authentication factors.
[0187] Aspect 3
[0188] In the information processing apparatus according to aspect 1, the additional authentication function notifies the standard authentication function of an authentication result using the first authentication factor, and when one of the additional authentication functions is valid, the standard authentication function authenticates the user based on the authentication result notified from the one of the additional authentication functions and an authentication result based on the received second authentication factor.
[0189] Aspect 4
[0190] The information processing apparatus according to aspect 3 further includes a first device and a second device capable of communicating with each other. The first device executes a standard authentication function and an additional authentication function. The standard authentication function is configured to request a login to the second device. The additional authentication function notifies the standard authentication function of login information received from a user. The standard authentication function is configured to request the login to the second device using the login information. When the standard authentication function receives a query about whether to allow the login, the standard authentication function is configured to request the additional authentication function to perform authentication using the login information.
[0191] Aspect 5
[0192] In the information processing apparatus according to aspect 4, when the additional authentication function notifies the standard authentication function of the login information received from the user, the standard authentication function displays a second login screen for receiving second login information, and the information processing apparatus authenticates the user based on an authentication result obtained by the standard authentication function using the second login information and an authentication result obtained by the additional authentication function using the login information.
[0193] Aspect 6
[0194] In the information processing apparatus according to aspect 2, the additional authentication function notifies the standard authentication function of an authentication result obtained by the additional authentication function using the first authentication factor. When both of the additional authentication functions are valid, the standard authentication function does not perform authentication and authenticates the user based on authentication results obtained by the two additional authentication functions.
[0195] Aspect 7
[0196] In the information processing apparatus according to aspect 6, further includes a first device and a second device capable of communicating with each other. The first device executes a standard authentication function and two additional authentication functions. The standard authentication function requests a login to the second device. The first additional authentication function notifies the standard authentication function of login information received from a user. The standard authentication function requests the login to the second device using the login information. When the standard authentication function receives a query about whether to allow the login, the standard authentication function requests the first additional authentication function to perform authentication using the login information.
[0197] Aspect 8
[0198] In the information processing apparatus according to aspect 7, when the first additional authentication function notifies the standard authentication function of the authentication result, the standard authentication function requests the second additional authentication function to display a third log-in screen for accepting third log-in information. When the third log-in information is received from the second additional authentication function, the standard authentication function requests the second additional authentication function to perform authentication using the third log-in information, and performs authentication of the user based on the authentication result obtained by the first additional authentication function using the log-in information and the authentication result obtained by the second additional authentication function using the third log-in information.
[0199] Aspect 9
[0200] The information processing apparatus according to any one of aspects 1 to 8 is configured to perform or not to perform the multi-factor authentication. When the information processing apparatus is configured not to perform the multi-factor authentication, the standard authentication function performs the user authentication alone.
[0201] Aspect 10
[0202] The information processing apparatus according to aspect 9 accepts selection of an additional authentication function to be made active among the plurality of additional authentication functions. The standard authentication function performs the multi-factor authentication using the standard authentication function and the additional authentication function, or the plurality of additional authentication functions according to the selected additional authentication function.
[0203] Aspect 11
[0204] In the information processing apparatus according to any one of aspects 1 to 10, the additional authentication function customizes the authentication factor.
[0205] Aspect 12
[0206] The information processing apparatus according to any one of aspects 1 to 10 is an image forming apparatus.
[0207] The above-described embodiments are illustrative and not restrictive. Many additional modifications and variations therefore are possible within the scope of the application. For example, different illustrative embodiments can be combined with one another and / or integrated with one another. Any of the above-described operations can be performed in a variety of other ways. For example, the order of the above-described operations can be changed.
[0208] The present disclosure can be implemented in any convenient form, for example using dedicated hardware or a mixture of dedicated hardware and software. The present disclosure can be implemented as computer software which is applied to one or more networked processing apparatuses. The processing apparatuses can be suitably programmed using any conventional programming language. Each aspect of the present disclosure thus comprises computer software which is applied to a programmable apparatus. The computer software can be provided using any conventional carrier medium, such as a storage medium or a transmission medium. The storage medium can be a non-transitory storage medium, such as a floppy disk, a hard disk, a CD ROM, a DVD, a Blu-ray disc, a magnetic tape, a semiconductor memory, or any other conventional memory device. The transmission medium can be a non-transitory transmission medium, such as an electrical, optical, microwave, acoustic or radio-frequency signal carrying the computer software.
[0209] The functions of the embodiments of the present disclosure can be implemented using circuitry or processing circuitry comprising a general purpose processor, a special purpose processor, an integrated circuit, an application specific integrated circuit (ASIC), a digital signal processor (DSP), a field programmable gate array (FPGA), a conventional circuit, and / or a combination thereof configured or programmed to perform the disclosed functions. A processor is processing circuitry or circuitry that includes transistors and other circuitry. In the present disclosure, circuitry, units, or devices are hardware that perform or are programmed to perform the described functions. The hardware can be any hardware of the present disclosure or otherwise known in the art, programmed or configured to perform the described functions.
[0210] The memory stores a computer program comprising computer instructions. These computer instructions provide the hardware (e.g., processing circuitry or circuitry) with the ability to perform the methods disclosed herein. The computer program can be implemented in known formats, including a computer readable storage medium, a computer program product, a storage device, a recording medium such as a CD-ROM or DVD, and / or a memory of an FPGA or ASIC.
[0211] This patent application is based on and claims priority to Japanese Patent Application No. 2023-081121, filed May 16, 2023, to the Japanese Patent Office, the disclosure of which is incorporated herein in its entirety.
[0212] List of Reference Signs
[0213] 10: host device
[0214] 20: operation device
[0215] 100: image forming apparatus
Claims
1. An information processing apparatus comprising: a processor; and a memory that pre-stores a standard authentication application, wherein in a case where an additional authentication application is additionally stored in the memory, the processor is configured to: execute the additional authentication application, perform authentication of a user using a first authentication factor to generate a first authentication result, execute the standard authentication application, perform the authentication of the user using a second authentication factor to generate a second authentication result, and determine whether the user is authenticated based on the first authentication result and the second authentication result. 2.An information processing apparatus comprising: a processor; and a memory that pre-stores a standard authentication application, wherein, in a case where two or more additional authentication applications are additionally stored in the memory, the processor is configured to: execute the two or more additional authentication applications, perform authentication of a user using two or more authentication factors that are different from each other to generate two or more authentication results, and determine whether the user is authenticated based on the two or more authentication results. 3.The information processing apparatus according to claim 1, wherein the additional authentication application notifies the standard authentication application of the first authentication result, and when the additional authentication application is valid, the standard authentication application authenticates the user based on the first authentication result and the second authentication result. 4.The information processing apparatus according to claim 3, comprising: a first apparatus including the processor that executes the standard authentication application and the additional authentication application; and a second apparatus, the first apparatus and the second apparatus are configured to communicate with each other, wherein the additional authentication application notifies the standard authentication application of login information received from the user, the standard authentication application requests the second apparatus to log in using the login information, and wherein, in a case where the standard authentication application receives a query of whether to allow login, the standard authentication application requests the additional authentication application to perform authentication using the login information. 5.The information processing apparatus according to claim 4, wherein, the login information notified by the additional authentication application is first login information received via a first login screen displayed by the additional authentication application, wherein the standard authentication application displays a second login screen for receiving second login information, and the processor is configured to authenticate the user based on the second authentication result obtained by the standard authentication application using the second login information and the first authentication result obtained by the additional authentication application using the first login information. 6.The information processing apparatus according to claim 2, wherein each of the two or more additional authentication applications notifies the standard authentication application of the authentication result, and wherein the processor is configured to determine whether the user is authenticated based on the two or more authentication results when the two or more additional authentication applications are valid. 7.The information processing apparatus according to claim 6, further comprising: a first apparatus including the processor; and a second apparatus, the first device and the second device are configured to communicate with each other, wherein the processor is configured to execute the standard authentication application in addition to a first additional authentication application and a second additional authentication application among the two or more additional authentication applications, wherein the first additional authentication application notifies the standard authentication application of login information received from the user, wherein the standard authentication application requests the second device to log in using the login information, and wherein, in a case where the standard authentication application receives a query as to whether to allow login, the standard authentication application requests the first additional authentication application to perform authentication using the login information to generate a first authentication result.
8. The information processing apparatus according to claim 7, wherein when the first additional authentication application notifies the standard authentication application of the first authentication result, the standard authentication application requests the second additional authentication application to display a third login screen for receiving third login information, and wherein the standard authentication application requests the second additional authentication application to perform authentication using the third login information, and determines whether the user is authenticated based on the first authentication result obtained by the first additional authentication application and an authentication result obtained by the second additional authentication application using the third login information when the third login information is received from the second additional authentication application.
9. The information processing apparatus according to claim 1, wherein the processor is configured to receive a setting indicating whether to perform multi-factor authentication, and wherein, in a case where the setting indicates that the multi-factor authentication is not performed, the processor is configured to execute only the standard authentication application, perform authentication of the user to generate a second authentication result, and determine whether the user is authenticated based on the second authentication result.
10. The information processing apparatus according to claim 9, wherein the processor is configured to accept selection of an additional authentication application to be set as active among a plurality of additional authentication applications, and wherein the processor is configured to perform the multi-factor authentication using the standard authentication application and the selected additional authentication application.
11. The information processing apparatus according to claim 2, wherein the processor is configured to receive selection of an additional authentication application to be set as active among a plurality of additional authentication applications, and wherein the processor is configured to perform the multi-factor authentication using the selected two or more additional authentication applications.
12. The information processing apparatus according to any one of claims 1 to 11, wherein, the additional authentication application allows customization of the authentication factor.
13. The information processing apparatus according to claim 4 or 7, wherein, the second device is an image forming apparatus configured to perform image formation.
14. An authentication system comprising: the information processing apparatus according to any one of claims 1 to 13; and a server communicably connected to the information processing apparatus to perform authentication of the user.
15. An information processing method comprising: storing a standard authentication application in advance in a storage; storing an additional authentication application in the storage; executing the additional authentication application to perform authentication of the user using a first authentication factor to generate a first authentication result, executing the standard authentication application to perform authentication of the user using a second authentication factor to generate a second authentication result, and determining whether the user is authenticated based on the first authentication result and the second authentication result.
Citation Information
Patent Citations
Information processing apparatus, information processing system, information processing method, and information processing program
JP2017167621A
X-ray diagnostic apparatus and control method for x-ray diagnostic apparatus
JP2023081121A