Information processing apparatus, method for registering device connected to information processing apparatus on server, and program
Patent Information
- Application Number
- JP2022165022
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-10-13
- Publication Date
- 2025-09-29
- Estimated Expiration
- 2042-10-13
AI Technical Summary
Existing information processing systems face security risks due to devices with inappropriate security settings connecting to cloud services, leading to potential vulnerabilities in communication security.
An information processing apparatus that applies necessary security setting information to devices before they communicate with a server, including a login mechanism, search for connected devices, request and verify setting information, and register devices only after successful reflection of this information.
Enhances communication security between devices and servers by ensuring devices are in a secure state before connecting, reducing the risk of cyber attacks and ensuring proper configuration.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates to an information processing apparatus, and a method and program for registering a device connected to the information processing apparatus in a server. [Background technology]
[0002] In recent years, information processing systems have been proposed that use cloud services (hereafter referred to as CS) provided on the Internet to manage devices such as multifunction printers. In such systems, first, an administrator of a CS tenant (a unit of user group) registers a device to the tenant to which the administrator belongs. Next, the administrator distributes various setting information, including security-related setting information operated within the tenant, to the registered device, thereby reducing the security risk of communication between the device and the CS.
[0003] Patent Document 1 describes a form in which, when one or more devices start communication with a CS, they first connect to a concierge service of the CS. The CS concierge service provides a communication channel according to the security function of the device, and the device starts communication with the CS using this communication channel. After communication starts, the CS can distribute setting information to the device. [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Special Publication No. 2019-537381 Summary of the Invention [Problem to be solved by the invention]
[0005] However, in the case of Patent Document 1, when a device with inappropriate security settings is connected to a CS, the concierge service of the CS will provide a communication channel with low security accordingly, which may result in the security of communication being compromised in the information processing system to which the device and the CS belong.
[0006] An object of the present invention is to solve at least one of the problems of the prior art described above.
[0007] An object of the present invention is to provide a technique that can put a device into a security state required by a server before the device starts communication with the server. [Means for solving the problem]
[0008] In order to achieve the above object, an information processing device according to one aspect of the present invention has the following configuration. An information processing device that registers a device in a server, A login means for transmitting authentication information to the server; a search means for searching for a device connected to the information processing apparatus when the login means has successfully logged in to the server; a first request means for requesting, in response to an instruction to register the device searched for by the search means, setting information including security setting information for communication between the server and the device to be registered from the server; a first transmission means for transmitting the setting information acquired from the server in response to a request made by the first request means to the device to be registered; a determination means for determining whether the setting information has been reflected in the device to be registered; The method is characterized in that it has a second request means for sending identification information of the device to be registered to the server and requesting registration to the server when the determination means determines that the setting information has been reflected. Effect of the Invention
[0009] According to the present invention, necessary security setting information is applied to a device before the device starts communication with a server, thereby making it possible to improve the security of communication between the device and the server.
[0010] Other features and advantages of the present invention will become apparent from the following description taken in conjunction with the accompanying drawings, in which the same reference numerals are used to designate the same or similar components throughout the drawings. [Brief description of the drawings]
[0011] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention. [Figure 1] FIG. 1 is a diagram showing the configuration of an information processing system according to a first embodiment of the present invention. [Diagram 2] FIG. 2A is a block diagram showing the hardware configuration of an information processing device such as a client terminal or a CS according to the first embodiment, and FIG. 2B is a block diagram explaining the internal configuration of a multifunction peripheral, which is an example of a device according to the first embodiment. [Diagram 3] FIG. 1A is a functional block diagram showing an example of the functional configuration of a CS program that runs on a CS in accordance with the first embodiment, and FIG. 1B is a functional block diagram showing an example of the functional configuration of a printer management application that runs on a client terminal in accordance with the first embodiment. [Figure 4] FIG. 2 is a diagram showing an example of the software configuration of a multifunction peripheral which is an example of a device according to the first embodiment. [Diagram 5] FIG. 4 is a diagram showing an example of a table managed by the CS according to the first embodiment. [Figure 6] 4 is a diagram for explaining a setting information file handled in the first embodiment. FIG. [Figure 7] 4 is a diagram showing an example of a UI screen displayed by a UI control unit of the CS program according to the first embodiment. [Figure 8] 6 is a flowchart for explaining the processing of a CS, a client terminal, and a device when registering the device in the CS according to the first embodiment. [Figure 9]FIG. 4 is a diagram showing an example of a UI screen of a printer management application executed on the client terminal according to the first embodiment. [Figure 10] 13A shows an example of a serial number management table managed by a CS according to the second embodiment, and FIG. 13B shows an example of a registration screen displayed on the CS according to the second embodiment. [Figure 11] 10 is a flowchart for explaining the processing of a CS, a client terminal, and a device when registering the device in the CS according to the second embodiment. [Figure 12] 13A shows an example of a serial number management table managed by a CS according to the third embodiment, and FIG. 13B shows an example of a deletion screen displayed on the CS according to the third embodiment. [Figure 13] 11 is a flowchart for explaining the processing of a CS, a client terminal, and a device when registering the device in the CS according to the third embodiment. [Figure 14] 13 is a flowchart for explaining a device deletion process performed by a CS and a device according to the third embodiment. [Figure 15] 13 is a flowchart for explaining a process of registering devices in bulk to a CS by a client terminal and devices according to a fourth embodiment. [Figure 16] 13 is a diagram showing an example of a UI screen of a printer management application executed on a client terminal according to the fourth embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Hereinafter, the embodiments of the present invention will be described in detail with reference to the attached drawings. Note that the following embodiments do not limit the invention according to the claims. Although the embodiments describe a number of features, not all of these features are essential to the invention, and the features may be combined in any manner. Furthermore, in the attached drawings, the same reference numbers are used for the same or similar configurations, and duplicated descriptions are omitted.
[0013] [Embodiment 1] FIG. 1 is a diagram showing a configuration of an information processing system according to the first embodiment of the present invention.
[0014] This information processing system includes client terminals 101 and 106, and devices 102, 103, 104, and 107, which are connected to a cloud service (CS) 109 via the Internet 110. In the first embodiment, a PC or a mobile device is assumed as an example of the client terminal 101, but the present invention is not limited to this. In addition, a multifunction device having a printing function, a scanning function, a network communication function, and the like is assumed as an example of the devices 102 to 104 and 107, but the present invention is not limited to this. For example, the device may be a single-function printer having only a printing function. Here, the client terminal 101 and the devices 102 to 104 are connected to a LAN 105, and the client terminal 106 and the device 107 are connected to a LAN 108. The CS 109 has a cloud server, and in cooperation with the client terminals 101 and 106, executes registration processing of the devices 102 to 104 and 107 to the CS 109, and manages various information held by the devices. Each device connected to the LANs 105 and 108 is connected to a CS 109 via the Internet 110 .
[0015] Data exchanged between the CS 109 and client terminals and devices (various types of device information and setting information) is stored in a dedicated storage area for each tenant. Data stored in a tenant can only be referenced by users and devices that have access rights to that tenant. For example, assume that on the CS 109, client terminal 101 and devices 102 to 104 belong to tenant 1, and client terminal 106 and device 107 belong to tenant 2. In this case, client terminal 101 and devices 102 to 104 cannot access data in tenant 2. Similarly, client terminal 106 and device 107 cannot access data in tenant 1.
[0016] FIG. 2A is a block diagram showing the hardware configuration of an information processing device represented by a client terminal or a server of the CS 109 according to the first embodiment.
[0017] A hard disk (HDD) 212 stores a program according to this embodiment (for example, a CS program in the CS 109) which will be the subject of operation in all the following descriptions. In all the following descriptions, unless otherwise specified, the CPU 201 is the subject of execution on the hardware. On the other hand, the subject of control on the software is a program stored in the hard disk (HDD) 212. The ROM 202 stores a BIOS, a boot program, etc. The RAM 203 functions as the main memory, work area, etc. of the CPU 201. The KBC 205 is a keyboard controller (KBC) which controls instruction input from the keyboard (KB) 209, the pointing device (PD) 210, etc. The display controller (DSPC) 206 controls the display of the display (DSP) 211. The disk controller (DKC) 207 controls access to storage devices such as the hard disk (HDD) 212 and the CD-ROM (CD) 213. A hard disk (HDD) 212 and a CD-ROM (CD) 213 store a boot program, an operating system, a database, a CS program, and other programs and other data. An interface controller (IFC) 208 transmits and receives information to and from other network devices via the LAN. Each of these components is connected to a system bus 204.
[0018] The program according to this embodiment may be supplied in a form stored in a storage medium such as a CD-ROM. In that case, the program is read from the storage medium by a CD-ROM (CD) 213 shown in FIG. 2A and installed in a hard disk (HDD) 212.
[0019] FIG. 2B is a block diagram illustrating the internal configuration of a multifunction peripheral, which is an example of the device 102 according to the first embodiment.
[0020] The CPU 251 controls the entire multifunction device. The ROM 252 stores the serial number of the multifunction device, etc. The RAM 253 is used as a work area for the CPU 251, a receiving buffer, and image drawing. The HDD 254 is a hard disk (HDD) that records firmware, expansion programs, font data, etc. The operation unit 255 has various switches and buttons, as well as a display unit for displaying messages. The network interface 256 is a network interface for connecting to a network, and transmits and receives information to and from other network devices via a LAN. The print engine 257 prints on recording paper. The scanner 258 reads documents. The facsimile communication unit 259 transmits and receives facsimiles. Each of these components is connected to a system bus 260.
[0021] 3A is a functional block diagram showing an example of the functional configuration of a CS program 300 that runs on the CS 109 according to embodiment 1. Each function of the CS 109 is realized by the CPU 201 executing this program.
[0022] The UI control unit 301 provides a graphical user interface for the user to operate this program. The graphical user interface is configured as a Web page that can be displayed on other client terminals using HTTP (HyperText Transfer Protocol). Alternatively, it may be configured to be displayed on a display 211 provided on the CS 109. The function control unit 302 instructs each function in the CS program 300 to perform various processes according to the instruction of the UI control unit 301 or a request received by the communication unit 305. The setting management unit 303 stores various setting information related to the CS program 300 and information on devices registered in the CS 109 in the DB 308 and controls the CS program 300. The authentication unit 304 uses user information for each tenant stored in the DB 308 to perform authentication processing of a user who has requested to log in to the CS 109. The communication unit 305 receives a request from the client terminal 101, the device 102, etc., and transmits the request contents to the function control unit 302. Furthermore, the communication unit 305 receives a processing result for the request from the function control unit 302, creates response data for the request, and transmits the response to the sender of the request. It also manages HTTP communication and, as necessary, transmits Web pages received from the UI control unit 301 to the client terminal. The DB management unit 307 instructs the DB 308 to store, delete, update, and acquire various settings and user information, etc., according to instructions from the function control unit 302. It also manages various tables used by the CS program 300. The DB 308 is a database that holds various data and various tables. The data held in the DB 308 is managed for each tenant. Users can only access data of the tenant to which they belong, and access to data of other tenants is restricted.
[0023] FIG. 3B is a functional block diagram showing an example of the functional configuration of the printer management application 300 that operates on the client terminal 101 according to the first embodiment.
[0024] The functions of the UI control unit 351 and the function control unit 352 are similar to those of the UI control unit 301 and the function control unit 302 in FIG. 3A, and therefore the description thereof will be omitted. The setting management unit 353 manages various setting information related to the printer management application 300, and temporarily stores the setting information in association with the serial number of the device. The authentication unit 354 performs authentication processing for logging in to the CS 109 using account information input by the user. The communication unit 355 receives requests and responses from the CS 109 and the device 102, and transmits the request contents and response contents to the function control unit 352. Furthermore, the communication unit 355 receives processing results for the requests and responses from the function control unit 352, creates response data for the requests, and transmits the response to the sender of the requests. The communication unit 355 also manages HTTP communication, and transmits Web pages received from the UI control unit 351 to the client terminal as necessary.
[0025] FIG. 4 is a diagram illustrating an example of a software configuration of a multifunction peripheral that is an example of a device according to the first embodiment.
[0026] In the multifunction device software 400 of the multifunction device, an MFP control program 401, which is a control program originally provided for a printer, FAX, scanner, etc., runs on an OS 410. An extension program execution platform 402, which is an extension program execution platform, also runs. Furthermore, a firmware update service 403, a function activation service 404, and a setting management service 405 run on the MFP control program 401. Also, an extension program system service 406 and an extension program 407 run on the extension program execution platform 402.
[0027] The firmware update service 403 is a service that provides various functions for updating firmware. For example, the firmware update service 403 refers to firmware specified by a user and determines whether or not the firmware of this multifunction device needs to be updated. The firmware is also updated via the MFP control program 401.
[0028] The function activation service 404 is a service for enabling functions that are incorporated in advance in the MFP control program 401. The function activation service 404 identifies and enables functions specified by a function license file specified by the user. The setting management service 405 is a service for managing various setting information for printers, scanners, etc. The setting management service 405 has a UI, and the user can instruct settings changes via the operation unit 255 (FIG. 2(B)) of the multifunction device. The setting management service 405 also provides a function for rewriting the setting information of the MFP control program 401 when a setting information file is specified by the user. This setting information file also includes security settings.
[0029] The extension program system service 406 is a utility library useful for all extension programs and is provided by the system. The extension program 407 can call the functions of the extension program system service 406, thereby saving the effort of developing the extension program. The extension program 407 can access each module of the multifunction device, such as other extension programs 407, only via the extension program execution platform 402 or the extension program system service 406. Furthermore, the extension program 407 having a UI can display an icon on the main menu screen displayed on the operation unit 255 of the multifunction device. When the user selects this icon, the operation unit 255 transmits a notification to that effect to the CPU 251 of the device. After that, the CPU 251 displays the UI of the extension program selected by the user on the operation unit 255.
[0030] Note that the software configuration in Fig. 4 shows only the basic parts, and other services may be included depending on the implementation environment. Also, unnecessary services may be omitted due to reasons such as setting restrictions.
[0031] Fig. 5 is a diagram showing an example of a table managed by the CS 109 according to embodiment 1. Note that the table configuration in Fig. 5 is only an example, and the table configuration may be different from this example.
[0032] FIG. 5A shows an authentication information management table 510, which includes columns from an account 511 to a password 515, and one record in the row direction represents one piece of authentication information. The account 511 is an ID for uniquely identifying a user who accesses the CS 109. The tenant 512 is information on the tenant to which the user of the account 511 belongs. The user name 513 is the name of the user identified by the account 511. The role 514 is a role assigned to the account 511. Here, in the first embodiment, as examples of roles, "admin" indicating that the user has administrator authority in the tenant and "general" indicating that the user is a general user are described, but are not limited to these. Note that at least one account with the "admin" role must belong to each tenant. The password 515 is a password entered when the account 511 logs in to the CS 109.
[0033] 5(A) indicates the account of the administrator of the entire CS 109. This can be determined by the fact that the value of the Tenant 512 is "common" (common to the server) and that a special role (in the embodiment, "CS admin" indicating the administrator of the entire CS) is stored in the Role 514.
[0034] 5B shows a setting information management table 530, which includes columns from ID 531 to other CS connection 540. One record in the row direction represents one piece of setting information. In the first embodiment, it is assumed that this setting information is mainly composed of security settings, but is not limited to this.
[0035] The ID (identification information) 531 is an ID that uniquely identifies the setting information. In the first embodiment, numbers starting with 0 are stored, but this is not limited to this. The belonging tenant 532 is the value of the tenant to which each setting information belongs. The setting name 533 is the name of the setting information. In the case where there are multiple records with the same value of the belonging tenant 532, the priority setting information 534 is specified as "TRUE" for the setting information prioritized in the belonging tenant. There is one setting information for each tenant to which "TRUE" is specified. In the example of FIG. 5(B), it can be seen that there are multiple records with the value of the belonging tenant 532 being "common", and the setting information prioritized in the belonging tenant is the setting name "S0-1". Even if there is no other record with the same value of the belonging tenant 532, the value of the priority setting information 534 of that record is specified as "TRUE".
[0036] FW version 535 to other CS connection 540 lists security setting items as an example of setting information. Note that the setting information is not limited to the examples shown here. In some records, the value of FW version 535 to other CS connection 540 is blank. This indicates that the setting information of that record does not have those setting items.
[0037] 5B, the value of the Tenant 532 of the records in the first and second rows (setting information whose ID 531 values are "0" and "1") is "common." This indicates that the setting information does not belong to a specific tenant, but can be referenced by all tenants as common setting information in CS 109 (hereinafter referred to as common setting information).
[0038] Here, individual setting items are assigned to each column from FW version 535 onwards in the setting information management table 530, but it may be configured to store the entity of a setting information file created in a format as shown in Fig. 6, which will be described later. Also, instead of storing the entity, it may be possible to store the path to the entity. In this case, the entity is configured to be placed as a file in a different location.
[0039] FIG. 5C shows a serial number management table 550 , which includes a serial number 551 and an associated tenant 552 .
[0040] The serial number 551 is the serial number of the device registered in the CS 109. The belonging tenant 552 is the value of the tenant to which the device having the serial number stored in the serial number 551 belongs.
[0041] Although not described in the first embodiment, the serial number management table 550 in FIG. 5C can also include the name of the device, a model ID for uniquely identifying the model, or network information such as an IP address. Fig. 6 is a diagram for explaining a setting information file handled in embodiment 1. In Fig. 6, a setting information file 600 shows an example of a setting information file in ML format.
[0042] The setting information area 601 lists setting information to be set in the device. In the first embodiment, tags and their values representing each setting item described in the setting information for ID=0 in the setting information management table 530 from FW version 535 to other CS connection 540 are listed.
[0043] In the first embodiment, the setting information file is expressed in an XML (Extensible Markup Language) format, but may be expressed in, for example, a JSON (JavaScript Object Notation) format.
[0044] FIG. 7 is a diagram showing an example of a UI screen displayed by the UI control unit 301 of the CS program 300 according to the first embodiment.
[0045] FIG. 7A shows an edit screen 700 , which is used by the administrator of the CS 109 or the administrator of each tenant of the CS 109 to create setting information to be applied to devices connected to the CS 109 .
[0046] In the editing screen 700, reference number 701 indicates the belonging tenant. For example, the UI control unit 301 obtains the belonging tenant name associated with the account used when the client terminal 101 logged in to the CS 109 from the belonging tenant 512 in the authentication information management table 510, and displays this belonging tenant 701. In FIG. 7, "Common" is displayed. Reference number 702 is an input area for the setting name of the setting information. The UI control unit 301 obtains the name of the setting information to be edited from the setting name 533 in the setting information management table 530, and displays it as the initial value.
[0047] The edit screen 700 further includes an input area 708 for FW (firmware) version 703, FW automatic update 704, PW setting 705, USB connection 706, IPP printing 707, and other CS connection. These correspond to the FW version 535 to other CS connection 540 in the setting information management table 530, respectively. A check box is added to the beginning of each setting item, and the user can select the setting item to be added to the setting information by checking the check box. When the OK button 709 is pressed, the CS program 300 stores the editing result of this edit screen 700 in the setting information management table 530 and ends the edit screen 700. Note that if the user has input a new setting name in the setting name 702, when the OK button 709 is pressed, the DB management unit 307 adds a new record to the setting information management table 530 and stores various information in the record. When the cancel button 710 is pressed, the CS program 300 discards the editing result of this edit screen 700 and ends the edit screen 700.
[0048] FIG. 7B is a diagram showing an example of a priority setting screen 720. As shown in FIG.
[0049] The administrator of the CS109 or the administrator of each tenant of the CS109 uses this priority setting screen 720 to specify setting information that is shared or prioritized in the tenant to which the administrator belongs. In this priority setting screen 720, reference numeral 721 indicates the belonging tenant. The contents displayed in the belonging tenant 721 are the same as those in the belonging tenant 701 in FIG. 7(A), and therefore the description is omitted. The value displayed as an option in the priority setting information selection area 722 is the value of the setting name 533 in the record having the value displayed in the belonging tenant 721 as the value of the belonging tenant 532. Here, it is sufficient to focus on the record in which the value of the belonging tenant 532 is "common". Here, it can be seen that the values "S0-1" and "S0-2" of the setting name 533 in which the value of the belonging tenant 532 in FIG. 5(B) is "common" are the options in the priority setting information selection area 722. In addition, when the priority setting screen 720 is displayed, the setting name of the record in which "TRUE" is set in the priority setting information 534 as the initial value is selected. In this priority setting information selection area 722, the user selects the setting information to be prioritized for the affiliated tenant 721. When the OK button 723 is pressed, the CS program 300 enters "TRUE" in the priority setting information 534 of the setting information having the setting name selected in the priority setting information selection area 722. Furthermore, it enters "FALSE" in other priority setting information 534 of the same tenant, and then closes the priority setting screen 720. When the cancel button 724 is pressed, the CS program 300 discards the editing results of the priority setting screen 720 and closes the priority setting screen 720.
[0050] Next, the device registration process in the CS 109 will be described with reference to Fig. 8 and Fig. 9. The device registration process in the CS 109 is started when a user who registers a device starts a printer management application 300 such as that shown in Fig. 9 on the client terminal 101.
[0051] In the first embodiment, an example is described in which the printer management application 300 and the CS 109 communicate with the device 102, but as shown in Fig. 1, multiple devices may exist in this system. A similar explanation can be given for the case in which the printer management application 300 and the CS 109 communicate with multiple devices (e.g., the device 103 and the device 104).
[0052] FIG. 8 is a flowchart for explaining the processing of the CS 109, the client terminal 101, and the device 102 when registering a device in the CS 109 according to the first embodiment.
[0053] Prior to the device registration process, first in S801, the administrator of the CS 109 creates common setting information for the CS 109 using the edit screen 700 and registers it in the setting information management table 530. Also, in S802, the administrator of each tenant may also create setting information for the tenant that he or she manages using the edit screen 700 as necessary, and register it in the setting information management table 530. Now, when the printer management application 300 is started, the application screen 901 in FIG. 9 is displayed first.
[0054] FIG. 9 is a diagram showing an example of a UI screen of the printer management application 300 executed on the client terminal 101 according to the first embodiment.
[0055] When the user presses the login button on the application screen 901, the printer management application 300 displays a login screen 902. Then, in S803, the user enters an account and password in a predetermined area on the login screen 902 and presses the login button, and authentication information is sent to the CS 109. In S804, the CS 109, which has received the authentication information from the client terminal 101 in this manner, refers to the authentication information management table 510 to determine whether authentication is possible with the received authentication information, and sends the result to the client terminal 101. If the authentication is successful, the tenant identifier (hereinafter referred to as TID) of the tenant to which the user belongs is also sent.
[0056] If the authentication is successful, the printer management application 300 of the client terminal 101 displays a device registration screen 903. If the user presses an OK button on the screen 903, the printer management application 300 searches for devices connected to the network in S805. This search process can be realized using SNMP (Simple Network Management Protocol), but it is also possible to use NFC (Near Field Communication) or other means.
[0057] The device 102 that receives this search request returns device information in S806. The device information returned here must include at least the serial number of the device. In addition, it may also include the device name, model ID, network information, etc. In this way, when the printer management application 300 receives the device information returned by the device 102 in S807, it displays the search results on the registered device list screen 904. Here, two devices named "Multifunction Device A" and "Printer B" are displayed as the search results.
[0058] Next, in S808, when the user selects one or more devices to be registered on the registered device list screen 904 and presses the OK button, the process proceeds to S809. On the other hand, when the user presses the Cancel button, the printer management application 300 ends this flowchart. When the OK button on the registered device list screen 904 is pressed, the printer management application 300 sends, in S809, to the CS 109 a request to obtain setting information for the device selected in S808. At that time, the tenant identifier (TID) of the tenant to which the user of the client terminal 101 belongs, received in S803, is also sent to the CS 109.
[0059] Thus, when the CS 109 receives the request to obtain the setting information in S810, it determines in S811 whether the setting information is registered in the tenant corresponding to the received TID. Specifically, it is confirmed whether the same tenant as the received TID is registered in the belonging tenant 532 of the setting information management table 530. If it is determined that the same tenant is registered here, the process proceeds to S812, and if not, the process proceeds to S813. In S812, the CS 109 specifies the setting information of the tenant corresponding to the TID as the setting information to be applied to the device. Specifically, the CS 109 extracts a record in which the value of the belonging tenant 532 matches the TID from each record in the setting information management table 530, and checks the value of the priority setting information 534. Then, the CS 109 identifies a record in which the value of the priority setting information 534 is "TRUE". Finally, the CS 109 extracts the setting information of the other CS connection 540 from the FW version 535 of the record, and generates a setting information file 600 as shown in FIG. 6, for example. FIG. 6 shows an example of a setting information file based on a record in the setting information management table 530 in which the associated tenant 532 is "common" and the value of the priority setting information 534 is "TRUE."
[0060] Meanwhile, in S813, the CS 109 specifies common setting information as setting information to be applied to the device. Specifically, the CS 109 extracts a record in which the value of the belonging tenant 532 is "common" from among the records in the setting information management table 530, and checks the value of the priority setting information 534. Then, the CS 109 identifies a record in which the value of the priority setting information 534 is "TRUE". Finally, the CS 109 extracts setting information of the other CS connection 540 from the FW version 535 of that record to generate the setting information file 600.
[0061] After creating the setting information file in S812 or S813, the CS 109 proceeds to S814, where it returns the setting information to the printer management application 300 as a response to the setting information acquisition request in S809. At that time, it obtains the value of the setting name 533 corresponding to the setting information from the setting information management table 530, and returns the value to the printer management application 300.
[0062] As a result, when the printer management application 300 receives the setting information and the setting name in S815, it displays the device to which the setting information is to be reflected and the setting name of the setting information to be reflected on the setting information reflection screen 905 of Fig. 9. If the user presses the OK button on the setting information reflection screen 905, the process proceeds to S816. On the other hand, if the user presses the Cancel button, the printer management application 300 returns to the registered device list screen 904. In S816, the printer management application 300 sends the setting information received in S815 to the device selected in S808 (e.g., device 102).
[0063] When the device 102 receives the setting information in step S817, it reflects the received setting information in itself. This setting information is reflected in the setting information of the MFP control program 401 of the device through the setting management service 405 of the multifunction device software 400. Thereafter, the device 102 returns the reflection result to the printer management application 300.
[0064] When the printer management application 300 receives the reflection result from the device 102 in S816, it determines in S818 whether or not the setting information was reflected in the device 102. If the reflection of the setting information was successful, the process proceeds to S819, where a reflection success screen 906 is displayed. On the other hand, if it is determined that the reflection of the setting information failed, the process proceeds to S820, where a reflection failure screen 907 is displayed. If the back button is pressed on this reflection failure screen 907, the process returns to the registered device list screen 904. Then, if the registration button on the reflection success screen 906 is pressed in S819, the printer management application 300 sends a device registration request to the CS 109. At that time, the printer management application 300 also sends device information including the TID received in S803 and the serial number obtained in S805 to the CS 109.
[0065] When the CS 109 receives this device registration request, in S821 it registers the device information in the tenant to which the received TID belongs. Specifically, it adds a new record to the serial number management table 550, and stores the received serial number as the value of the serial number 551 of that record. Similarly, it stores the received TID as the value of the tenant 552 to which it belongs. If the serial number can be stored in the serial number management table 550 in this way, the registration result is "success". On the other hand, if the serial number cannot be stored in the serial number management table 550 due to an access error to the DB 308 or some other reason, the registration result is "failure". Then, it returns the registration result to the printer management application 300.
[0066] In this way, when the printer management application 300 receives a reply from the CS 109, it displays a registration success screen 908 (if registration is successful) or a registration failure screen 909 (if registration is unsuccessful). When the end button is pressed on the registration success screen 908, in S822, the printer management application 300 sends a CS registration completion notification to the device 102 and returns to the application screen 901. As a result, when the device 102 receives a CS registration completion notification from the printer management application 300 in S823, it starts communication with the CS 109. In general, the device 102 executes a polling process on the CS 109 at a predetermined cycle (S824, S825). On the other hand, when the end button is pressed on the registration failure screen 909, it returns to the application screen 901. This concludes the explanation of the flowchart in FIG. 8.
[0067] As described above, according to the first embodiment, by executing S809 to S817 in Fig. 8, the device 102 is placed in a state in which appropriate security setting information has been applied before being connected to the CS 109. As a result, the device 102 is able to communicate with the CS 109 in a state of high security from the stage of first communication with the CS 109. In addition, since the device 102 to which the security setting information has been applied is connected to the CS 109, it is also possible to reduce the risk of various cyber attacks on the CS 109 that may be carried out via the device.
[0068] [Embodiment 2] In the first embodiment, the user can select any device from one or more devices searched for by the printer management application 300, and can reflect the setting information and register the device in the CS 109. However, since this depends on the user's manual selection, if the user selects an incorrect device, there are cases where unnecessary setting information is reflected in a device that is not to be registered in the CS 109, or unnecessary device registration is performed in the CS 109.
[0069] Therefore, in the second embodiment, an example will be described in which the user of the printer management application 300 can register only the devices he or she wishes to register in the CS 109, and the setting information can be reflected only in those devices. The following will focus on the differences from the first embodiment. Note that the system configuration and the hardware configuration of each device according to the second embodiment are the same as those of the first embodiment, and therefore the description thereof will be omitted.
[0070] Fig. 10(A) is a diagram showing an example of a serial number management table 1000 managed by the CS 109 according to the second embodiment. Note that the configuration of the serial number management table 1000 in Fig. 10(A) is merely an example, and the table may have a different configuration from this example. Note that this serial number management table 1000 is obtained by adding a registration status 1001 to the serial number management table 550 of the first embodiment.
[0071] The registration status 1001 indicates the registration status of the device having the serial number stored in each record in the CS 109. Either a value of "completed" or "pre-registered" is stored in the registration status 1001. "Completed" indicates that the device corresponding to the serial number has already been registered in the CS 109, and "pre-registered" indicates that the device corresponding to the serial number is not currently registered in the CS 109, but is scheduled to be registered in the future.
[0072] FIG. 10B is a diagram showing an example of a registration screen 1020 displayed on the CS 109 according to the second embodiment. When an administrator of each tenant of the CS 109 registers a device in the CS 109, the administrator uses this screen to pre-register the serial number of the device. In this screen, the contents displayed in the belonging tenant 1021 are the same as those in the belonging tenant 701 in FIG. 7A described above, and therefore the description thereof will be omitted. The user inputs the serial number of the device to be registered in the belonging tenant 1021 (tenant 1 in this case) in the serial number input field 1022. When the OK button 1023 is pressed on this screen, the CS program 300 adds a new record to the serial number management table 1000. Then, the value of the serial number input field 1022 (SN11 in this case) is stored in the serial number 551, and the value of the belonging tenant 1021 (tenant 1) is stored in the belonging tenant 552. In addition, "pre-registration" is stored in the registration status 1001, which indicates that the target device is scheduled to be registered in the future. The information registered in this way is shown in the record 1002 in FIG. 10A. Thereafter, the user closes the registration screen 1020. On the other hand, when the user presses the cancel button 1024, the CS program 300 discards the editing results of the registration screen 1020 and closes the registration screen 1020.
[0073] Next, a device registration process in the CS 109 according to the second embodiment will be described with reference to FIG.
[0074] Fig. 11 is a flowchart for explaining the processing of the CS 109, the client terminal 101, and the device 102 when registering a device in the CS 109 according to the second embodiment. Note that in Fig. 11, steps S801 to S802 are similar to the processing described in Fig. 8 in the first embodiment, and therefore the explanation thereof will be omitted.
[0075] In S1101, the CS 109 (CS program 300) displays a registration screen 1020 (FIG. 10B) based on instructions from the user. When the user inputs the serial number of the device to be pre-registered on this screen and presses the OK button 1023, the CS 109 stores the serial number and the tenant to which the user inputs the registration status value "pre-registered" in the serial number management table 1000. Note that this process is not essential and may be performed as necessary.
[0076] The processes of S803 to S806 that are executed when the printer management application 300 is started are similar to the processes described in FIG. 8 of the first embodiment, and therefore will not be described.
[0077] Then, following S805 and S806, in S1102, the printer management application 300 sends a request to the CS 109 to obtain serial number information of the registered device. At this time, the TID received in S803 is also sent to the CS 109.
[0078] Thus, when the CS 109 receives a request to obtain serial number information in S1103, it extracts records in the serial number management table 1000 where the value of the assigned tenant 552 matches the received TID. Then, it obtains the value of the serial number 551 and the value of the registered attribute 1001 of the extracted record. Finally, it makes a list of the obtained serial numbers and registered attributes and sends it to the printer management application 300.
[0079] As a result, in S1104, the printer management application 300 receives the device information returned by one or more devices such as the device 102 in S806, and the list of serial numbers and registered attributes (hereinafter, simply referred to as the list) returned by the CS 109 in S1103. After that, it is determined whether or not there is a combination in which the value of the registered attribute is "advance" in the list. If it is determined that there is a combination in which the value of the registered attribute is "advance" in the list, the process proceeds to S1105, and if not, the process proceeds to S1107. In S1105, the printer management application 300 extracts serial numbers included in the device information returned in S806 that match the serial numbers in the list whose registered attribute value is "advance". Then, the process proceeds to S1106, where only the devices having the extracted serial numbers are displayed on the registered device list screen 904 in FIG. 9, and the process proceeds to S808 in FIG. 8.
[0080] On the other hand, in S1107, the printer management application 300 extracts, from among the serial numbers included in the device information returned in S806, those that match the serial numbers in the list whose registration attribute 1101 has the value "Complete."Then, the process proceeds to S1108, where the printer management application 300 displays devices other than those having the extracted serial numbers on the registered device list screen 904, and proceeds to S808 in FIG.
[0081] In this way, when the printer management application 300 performs the procedures of S1105 and S1106, only devices that have been pre-registered in the CS 109 are displayed on the registered device list screen 904. On the other hand, when the printer management application 300 performs the procedures of S1107 and S1108, devices other than those that have completed registration in the CS 109 are displayed on the registered device list screen 904.
[0082] When the steps of S1105 and S1106 are performed, the user has to take the trouble of performing S1101 to pre-register the serial numbers of the devices in CS109, but can correctly select only the devices to be registered on the registered device list screen 904. On the other hand, when the steps of S1107 and S1108 are performed, devices that have already been registered in CS109 can be excluded in advance from being displayed on the registered device list screen 904, making it possible to prevent a registered device from being accidentally registered twice. At the same time, the trouble of pre-registering devices as in S1101 is no longer necessary, and the procedure for registering devices in CS109 can be simplified.
[0083] In either case, it becomes possible for the user of the printer management application 300 to register in the CS 109 only the devices that he or she wishes to register, as described at the beginning of the second embodiment. The process of S1107 executed after the registered device list screen 904 is displayed corresponds to the processes of S808 to S825 in Fig. 8, which are similar to the processes described in Fig. 8 of the first embodiment, and therefore will not be described again. This concludes the description of this flowchart.
[0084] As described above, according to the second embodiment, the processes of S1101 to S1108 are executed, thereby enabling the user of the printer management application 300 to avoid selecting an incorrect device. As a result, it is possible to avoid applying unnecessary setting information to a device that is not to be registered in the CS 109, and to avoid registering an unnecessary device in the CS 109.
[0085] [Embodiment 3] In the above-described first and second embodiments, the user can use the printer management application 300 to reflect setting information in a selected device, and then register the device in the CS 109. However, in these first and second embodiments, the printer management application 300 reflects setting information in the device before registration in the CS 109. For this reason, if the registration is cancelled after registration in the CS 109, unnecessary setting information remains reflected in the device.
[0086] Therefore, in the third embodiment, an example will be described in which unnecessary setting information of a device can be restored when the user cancels the registration after the device is registered in the CS 109. The following will mainly describe the differences from the first and second embodiments. Note that the system configuration and the hardware configuration of each device according to the third embodiment are the same as those of the first and second embodiments, and therefore the description thereof will be omitted.
[0087] Fig. 12(A) is a diagram showing an example of a serial number management table 1200 managed by the CS 109 according to the third embodiment. Note that the table configuration in Fig. 12(A) is merely an example, and the table configuration may be different from that of this example. This serial number management table 1200 is obtained by adding saved information 1201 to the serial number management table 1000 of the second embodiment, but the registration status 1001 is not essential in the third embodiment. For example, it can also be explained by adding saved information 1201 to the serial number management table 550 of the first embodiment.
[0088] The saved information 1201 stores the setting information immediately before the target device is registered in the CS 109. Here, it is assumed that the actual file in the format of the setting information file 600 is stored, but instead of storing the actual file, the path to the actual file may be stored. In this case, the actual file is placed in a different location as a file. Also, each setting item may be defined in an individual column, such as FW version 535 to other CS connection 540 in the setting information management table 530 in FIG. 5(B).
[0089] FIG. 12B is a diagram showing an example of a device deletion screen 1220 displayed on the CS 109 according to the third embodiment. When deleting a device registered in the CS 109, the administrator of each tenant of the CS 109 deletes the serial number of the device using this screen. Note that the content displayed in the belonging tenant 1221 on this screen is the same as that of the belonging tenant 701 in FIG. 7A, and therefore the description is omitted. The value displayed as an option in the serial number area 1222 is the value of the serial number 551 of a record that has the value displayed in the belonging tenant 1221 as the value of the belonging tenant 532 in the setting information management table 530 and has the value of the registration status 1001 as "completed". However, if the registration status 1001 does not exist in the serial number management table 1200, the registration status 1001 is not referenced. In the example of the serial number management table 1200 in FIG. 12A, "SN11" and "SN12" whose belonging tenant is "tenant 1" are options. The user selects the serial number of the device to be deleted in this serial number area 1222. In Fig. 12(B), serial number "SN11" is selected. When the OK button 1223 is pressed, the CS program 300 transmits a delete command to the device having the serial number selected in the serial number area 1222. When the Cancel button 1224 is pressed, the CS program 300 discards the editing results of the delete screen 1220 and closes the delete screen 1220.
[0090] Next, the device registration process in the CS 109 in the third embodiment will be described with reference to FIG.
[0091] Fig. 13 is a flowchart for explaining the processing of the CS 109, the client terminal 101, and the device 102 when registering a device in the CS 109 according to the third embodiment. In Fig. 13, steps S801 to S815 and S1101 to S1108 executed in S1300 are similar to the processing described in the first and second embodiments, and therefore the explanation will be omitted. After executing these processes, the printer management application 300 executes steps S1301 to S1308. These processes are executed before the printer management application 300 sends setting information to the selected device in S816.
[0092] The processing in S1301 to S1308 is processing in which the printer management application 300 transmits a setting information save request to the device 102 and receives the result from the device 102. First, in S1301, the printer management application 300 receives device setting information from the CS 109 in S815. Thereafter, upon detecting that the OK button on the setting information reflection screen 905 in Fig. 9 has been pressed, the printer management application 300 sends a setting information save request to the device selected in S808 (e.g., the device 102).
[0093] As a result, the device 102 receives the request to save the setting information, and in S1303, it is determined whether or not the device itself has a save area for the setting information. This save area is assumed to be provided in the setting management service 405, but an independent area may be provided. If it is determined that there is a save area, the process proceeds to S1304, where the current setting information is saved as save information in the save area, and the process proceeds to S1306. On the other hand, if it is determined that there is no save area, the process proceeds to S1305, where the current setting information is converted into a file as save information and temporarily saved in the setting management service 405, and the process proceeds to S1306. Note that it is assumed that the save information has the format of a setting information file 600 as shown in FIG. 6, but the format is not limited to this.
[0094] In this way, when the device 102 determines how to handle the saved information in S1304 or S1305, in S1306 it returns the result of saving the setting information to the printer management application 300 as a response to S1301. Note that if S1305 is selected here, the device 102 also returns the serial number of the device itself and the saved information file.
[0095] As a result, in S1307, the printer management application 300 receives the result of saving the setting information and determines whether the saving was successful. If the saved information file was also received when the result was received in S1307, the printer management application 300 associates the saved information file with the serial number and temporarily stores it in the setting management unit 353. Then, the printer management application 300 proceeds to S1308, and if the saving was successful, the printer management application 300 proceeds to S816, and if the saving was unsuccessful, the printer management application 300 proceeds to S820. The processes of S816 to S818 executed in S1315 are the same as those described in the first and second embodiments, and therefore will not be described.
[0096] Then, in S818, the printer management application 300 executes S1309 if it determines that the setting information has been successfully reflected in the device 102. In addition to the process of S819 in the first and second embodiments described above, in the process of S1309, if there is a saved information file that was temporarily saved in S1307, the saved information file is also sent to the CS 109.
[0097] As a result, in S1310, the CS 109 receives a device registration request. Then, the process proceeds to S1311, where the CS 109 determines whether or not the saved information file has also been received. If the saved information file has been received, the process proceeds to S1312, where the received saved information file is stored in the saved information 1201 of the serial number management table 1200, and the process proceeds to S1313. The record to be stored here is a record in which the value of the serial number 551 in the serial number management table 1200 matches the serial number included in the device information received in S1310. Then, in S1313, the CS 109 executes the device registration process described in S821 in the first and second embodiments, and in S1314 returns the device registration result to the client terminal 101, and the process proceeds to S1316.
[0098] When the printer management application 300 receives the reply from the CS 109, in S1315, it displays a registration success screen 908 (if registration is successful) or a registration failure screen 909 (if registration is unsuccessful), notifies the user of whether the device registration was successful or unsuccessful, and proceeds to S1316. Since S1316 is the same as the processes of S822 to S825 in the first and second embodiments, a description thereof will be omitted.
[0099] Next, the process of deleting a device from the CS 109 will be described with reference to FIG.
[0100] FIG. 14 is a flowchart illustrating a device deletion process performed by the CS 109 and the device 102 according to the third embodiment.
[0101] The device deletion process from the CS 109 is started when the administrator of the tenant to which the device to be deleted belongs specifies the serial number of the device to be deleted in the serial number area 1222 of the deletion screen 1220 and presses the OK button 1223. Here, it is assumed that the serial number of the device 102 has been specified.
[0102] When the OK button 1223 is pressed, in S1401, the CS 109 extracts a record in which the value of the serial number 551 in the serial number management table 550 matches the serial number selected in the serial number area 1222. Then, it is determined whether or not a save information file is stored in the save information 1201 of that record. If a save information file is stored, the process proceeds to S1402, where the CS 109 extracts the save information file from the corresponding record in the save information 1200, generates a device deletion request including that file, and proceeds to S1404. On the other hand, if a save information file is not stored, the process proceeds to S1403, where the CS 109 generates a device deletion request that does not include the save information file, and proceeds to S1404. Then, in S1404, the CS 109 transmits the device deletion request to the device 102.
[0103] Thus, when the device 102 receives the device deletion request in S1405, the process proceeds to S1406, where it is determined whether or not the device deletion request includes a saved information file. If the saved setting file is included, the process proceeds to S1407, where the device 102 reflects the received saved information file in itself, and proceeds to S1409. On the other hand, if the saved information file is not included, the process proceeds to S1408, where the device 102 takes out the saved information file saved in the save area in S1304, reflects it in itself, and proceeds to S1409. Note that the process of reflecting the saved information file executed in S1407 or S1408 is the same as S817 in the first embodiment, and therefore a description thereof will be omitted. By executing S1406 to S1408 in this way, the device 102 can return its own setting information to the state before the device was registered in the CS 109. Then, in S1409, the device 102 executes a device deletion process. In this deletion process, the device 102 at least stops polling the CS 109. In addition, access information (authentication information, URL, etc.) to the CS 109 may also be deleted. Thereafter, the process proceeds to S1410, where the device 102 returns the result of the device deletion process to the CS 109 as a response to the device deletion request in S1404.
[0104] Thus, when the CS 109 receives the result of the device deletion request in S1411, the process proceeds to S1412, where it determines whether or not the result was successful. If the result is successful, the process proceeds to S1413, where the CS 109 deletes the record in which the serial number of the corresponding device is stored from the serial number management table 1200, and ends this process. On the other hand, if the result is unsuccessful, the CS 109 does not change the serial number management table 1200, and ends this process as it is.
[0105] As described above, according to the third embodiment, when the administrator of each tenant of the CS 109 deletes the registration of a device on the CS 109, the administrator can restore the setting information of the device to the state before the device was registered on the CS 109. As a result, it is possible to prevent unnecessary setting information from remaining reflected on the device.
[0106] [Embodiment 4] In the above-described first to third embodiments, the printer management application 300 independently executes the device registration process for each device that is to be registered in the CS 109. In other words, when a user selects multiple devices and executes the registration process in the CS 109, the printer management application 300 processes the success or failure of the registration in the CS 109 for each individual device.
[0107] However, when multiple devices in a user environment are to be handled in a unified manner, if registration of some devices to the CS 109 fails, devices that have been successfully registered to the CS 109 and devices that have failed to be registered will coexist in the user environment, making it impossible to handle the user's devices in a unified manner on the CS 109.
[0108] Therefore, in the fourth embodiment, an example will be described in which the printer management application 300 can collectively register multiple devices in the CS 109 in accordance with a user's instruction. In the following, to simplify the explanation, the differences from the first embodiment will be mainly described. Note that the system configuration and the hardware configuration of each device according to the fourth embodiment are the same as those of the first to third embodiments, and therefore the explanation thereof will be omitted.
[0109] FIG. 15 is a flowchart for explaining a batch registration process of devices in the CS 109 by the client terminal 101 and the device 102 according to the fourth embodiment.
[0110] Fig. 16 is a diagram showing an example of a UI screen of the printer management application 300 executed on the client terminal 101 according to the fourth embodiment. Most of the screens in Fig. 16 are the same as those in Fig. 9, but some of the screens have been modified for bulk registration processing.
[0111] For example, a registered device list screen 1601 adds a check box 1607 for the user to specify bulk registration to the registered device list screen 904 in Fig. 9. Also, screens 1602 to 1606 change the display wording of the registration failure screen 909 from the setting information reflection screen in Fig. 9 to one for bulk registration processing.
[0112] The bulk device registration process in the CS 109 shown in Fig. 15 is started when a user who registers devices launches a printer management application 300 as shown in Fig. 16 on the client terminal 101. In S1501 in Fig. 15, the same processes as S801 to S807 in Fig. 8 described above are executed. This process is similar to that described in the first embodiment, and therefore will not be described.
[0113] Next, in S1502, when the printer management application 300 detects that the user has selected multiple devices to be registered on the registered device list screen 1601, made appropriate inputs in the batch registration checkbox 1607, and pressed the OK button, the process proceeds to S1503, and executes S809 to S815 in FIG. 8. These processes are the same as those described in the first embodiment, and therefore their explanations are omitted. Then, the process proceeds to S1504, and the printer management application 300 determines whether the batch registration checkbox 1607 is checked in S1502. If it is determined that the batch registration checkbox 1607 is checked, the process proceeds to S1505, and executes the processes of S1301 to S1308 in FIG. 13 and S816 to S817 in FIG. 8. These processes are the same as those described in the third and first embodiments, and therefore their explanations are omitted. Then, the process proceeds to S1507. On the other hand, if it is determined in S1504 that the checkbox 1607 for bulk registration is not checked, the process proceeds to S1506, where S816 to S825 in Fig. 8 are executed, and the process ends. These processes are similar to those described in the first embodiment, and therefore the description thereof will be omitted.
[0114] In S1507, the printer management application 300 determines whether the setting information has been reflected in all devices selected in S1502. If it is determined that the setting information has been reflected in all devices, the process proceeds to S1509, where the printer management application 300 executes S819 to S825 for each selected device, registers the target device in the CS 109, and ends this process.
[0115] On the other hand, in other cases, the process proceeds to S1508, and the printer management application 300 sends a save information reflection request to the device whose setting value has been changed. Specifically, the printer management application 300 extracts save information that matches the serial number of the device whose setting information has been reflected from the setting management unit 353. If the save information has been acquired from the device in advance in S1307, the printer management application 300 should have temporarily saved the save information in the setting management unit 353. If the save information exists, the printer management application 300 sends a save information reflection request to the device with the serial number, to which the save information has been added. If the save information does not exist, the printer management application 300 sends only a save information reflection request to the device with the serial number. In this way, the device (for example, the device 102) receives the save information reflection request from the printer management application 300 in S1510. Next, in S1511, steps S1406 to S1408 in FIG. 14 are executed to reflect the save information in the device itself. These processes are the same as those described in the third embodiment, and therefore will not be described. Thereafter, the process proceeds to S1512, in which the device returns the result of the saved information reflection request to the printer management application 300, and ends the process.
[0116] Furthermore, when the printer management application 300 receives the result of the saved information reflection request in S1513, the process proceeds to S1514, where it displays a batch registration failure screen 1606 to notify the user that the batch device registration has failed. When the end button is pressed on this screen 1606, the screen returns to the application screen 901. This concludes the explanation of this flowchart.
[0117] As described above, according to the fourth embodiment, only when the setting information is successfully reflected in all devices selected by the user, the user can register the target device in the CS 109. As a result, it becomes possible to handle multiple devices in the user environment in a unified manner on the CS 109.
[0118] Furthermore, according to the above first to fourth embodiments, since a device with security settings is connected to the CS, there is an advantage that the risk of various cyber attacks on the CS that may be carried out via the device can be reduced.
[0119] (Other embodiments) The present invention can also be realized by a process in which a program for implementing one or more of the functions of the above-described embodiments is supplied to a system or device via a network or a storage medium, and one or more processors in a computer of the system or device read and execute the program. The present invention can also be realized by a circuit (e.g., ASIC) that implements one or more of the functions.
[0120] The disclosure of this specification and the drawings includes the following information processing device, and a method and program for registering a device connected to the information processing device in a server.
[0121] [Item 1] An information processing device that registers a device in a server, A login means for transmitting authentication information to the server; a search means for searching for a device connected to the information processing apparatus when the login means has successfully logged in to the server; a first request means for requesting, in response to an instruction to register the device searched for by the search means, setting information including security setting information for communication between the server and the device to be registered from the server; a first transmission means for transmitting the setting information acquired from the server in response to a request made by the first request means to the device to be registered; a determination means for determining whether the setting information has been reflected in the device to be registered; a second request means for sending identification information of the device to be registered to the server when the determination means determines that the setting information has been reflected; and 13. An information processing device comprising:
[0122] [Item 2] 2. The information processing device according to item 1, wherein the searching means displays a registration screen when login to the server is successful, and searches for devices in response to a user's instruction via the registration screen.
[0123] [Item 3] 3. The information processing device according to item 1 or 2, wherein the login means, when successfully logging in to the server, acquires information on a tenant to which the user of the information processing device belongs from the server based on the authentication information.
[0124] [Item 4] 4. The information processing device according to item 3, wherein the first request means includes information about the tenant in the request.
[0125] [Item 5] 5. The information processing device according to item 4, wherein the tenant information includes information common to the server and information for each tenant.
[0126] [Item 6] The setting information includes setting information common to the servers and setting information for each tenant, 6. The information processing device according to item 5, wherein the setting information acquired from the server in response to a request by the first request means is setting information corresponding to information of the tenant included in the request.
[0127] [Item 7] The information processing device described in item 5, characterized in that the setting information acquired from the server in response to a request by the first request means is setting information of the tenant if the server holds setting information of the tenant linked to authentication information of the information processing device, and is setting information common to the servers if the server does not hold setting information of the tenant.
[0128] [Item 8] The information processing device according to any one of items 1 to 7, further comprising: a means for displaying a screen indicating that the setting information has failed to be reflected in the device to be registered when the determination means determines that the setting information cannot be reflected in the device to be registered.
[0129] [Item 9] 9. The information processing apparatus according to any one of items 1 to 8, wherein the second request means further transmits information about a tenant of the device to be registered to the server.
[0130] [Item 10] The information processing device according to any one of items 1 to 9, further comprising a means for displaying a screen for displaying information of the device searched for by the search means, and wherein an instruction to register the device is given by selecting information of the device on the screen.
[0131] [Item 11] a determination means for determining whether or not identification information preregistered in the server is present among the identification information of the device searched for by the search means; a selection means for selecting only a device corresponding to the identification information determined by the determination means to have been preregistered as a device to be registered; 11. The information processing device according to any one of items 1 to 10, further comprising:
[0132] [Item 12] The information processing device described in item 11, characterized in that, when the pre-registered identification information does not exist, the selection means selects a device corresponding to identification information that is not identification information of a device already registered in the server as the device to be registered.
[0133] [Item 13] a first save request means for requesting the device to be registered to save current setting information; 13. The information processing apparatus according to any one of items 1 to 12, further comprising: a receiving unit configured to receive save information in the device to be registered in response to a request made by the first save request unit.
[0134] [Item 14] a third request means for requesting, when an instruction to collectively register the plurality of devices searched for by the search means in the server, setting information including security setting information for communication between the server and the plurality of devices from the server; a second transmission means for transmitting the setting information acquired from the server in response to a request by the third request means to the plurality of devices; a fourth request means for sending identification information of the plurality of devices to the server and requesting registration of the plurality of devices in the server when it is determined that the setting information has been reflected in the plurality of devices; 14. The information processing device according to any one of items 1 to 13, further comprising:
[0135] [Item 15] Item 15. The information processing device according to item 14, further comprising a second save request means for requesting a device to which the setting information has been reflected to save current setting information if the setting information has not been reflected in all of the plurality of devices.
[0136] [Item 16] 15. The information processing device according to item 14, further comprising a means for displaying a failure of batch registration when the setting information cannot be reflected in all of the plurality of devices.
[0137] [Item 17] A method for registering a device connected to an information processing device to a server, comprising: logging in the information processing device to the server; a search step in which the information processing device searches for connected devices when the login is successful; an acquisition step of acquiring setting information including security setting information for the device searched for in the search step to communicate with the server from the server; a sending step of sending the setting information acquired in the acquiring step to the device; a determination step of determining whether the setting information sent to the device in the sending step has been reflected in the device; a request step of requesting the server to register the device when it is determined in the determination step that the setting information has been reflected in the device; 23. A method comprising:
[0138] [Item 18] 18. The method according to claim 17, wherein the configuration information includes security configuration information of a tenant to which the discovered device belongs.
[0139] [Item 19] A program for causing a computer to function as each of the means of the information processing device according to any one of items 1 to 16.
[0140] The present invention is not limited to the above-described embodiments, and various modifications and variations can be made without departing from the spirit and scope of the present invention. Therefore, the following claims are appended to apprise the public of the scope of the present invention. [Explanation of symbols]
[0141] 101, 106... client terminal, 102 to 104, 107... device, 109... cloud service (CS), 300... CS program, 350... printer management application, 303... setting management unit (CS), 353... setting management unit (client terminal), 510... authentication information management table, 530... setting information management table, 550... serial number management table
Claims
1. An information processing device that registers a device in a server, A login means for transmitting authentication information to the server; a search means for searching for a device connected to the information processing apparatus when the login means has successfully logged in to the server; a first request means for requesting, in response to an instruction to register the device searched for by the search means, setting information including security setting information for communication between the server and the device to be registered from the server; a first transmission means for transmitting the setting information acquired from the server in response to a request made by the first request means to the device to be registered; a determination means for determining whether the setting information has been reflected in the device to be registered; a second request means for sending identification information of the device to be registered to the server when the determination means determines that the setting information has been reflected; and 13. An information processing device comprising:
2. 2 . The information processing apparatus according to claim 1 , wherein the search means displays a registration screen when login to the server is successful, and searches for devices in response to a user's instruction via the registration screen.
3. The information processing apparatus according to claim 1 , wherein the login unit, when successfully logging in to the server, acquires information on a tenant to which the user of the information processing apparatus belongs from the server based on the authentication information.
4. The information processing apparatus according to claim 3 , wherein the first requesting unit includes information about the tenant in the request.
5. The information processing apparatus according to claim 4 , wherein the tenant information includes information common to the server and information for each tenant.
6. The setting information includes setting information common to the servers and setting information for each tenant, The information processing apparatus according to claim 5 , wherein the setting information acquired from the server in response to the request by the first request means is setting information corresponding to information on the tenant included in the request.
7. The information processing device according to claim 5, characterized in that the setting information acquired from the server in response to a request by the first request means is setting information of the tenant if the server holds setting information of the tenant linked to authentication information of the information processing device, and is setting information common to the servers if the server does not hold setting information of the tenant.
8. 2. The information processing apparatus according to claim 1, further comprising: means for displaying a screen indicating that the setting information has failed to be reflected in the device to be registered, when the determination means determines that the setting information cannot be reflected in the device to be registered.
9. The information processing apparatus according to claim 1 , wherein the second request means further transmits information on a tenant of the device to be registered to the server.
10. 2. The information processing apparatus according to claim 1, further comprising: a screen displaying means for displaying information of the device searched for by the searching means; and an instruction to register the device is given by selecting the information of the device on the screen.
11. a determination means for determining whether or not identification information preregistered in the server is present among the identification information of the device searched for by the search means; a selection means for selecting only a device corresponding to the identification information determined by the determination means to have been preregistered as a device to be registered; 2. The information processing apparatus according to claim 1, further comprising:
12. The information processing device according to claim 11, characterized in that, when the pre-registered identification information does not exist, the selection means selects a device corresponding to identification information that is not identification information of a device already registered in the server as the device to be registered.
13. a first save request means for requesting the device to be registered to save current setting information; 2. The information processing apparatus according to claim 1, further comprising: a receiving unit configured to receive save information in the device to be registered in response to a request made by the first save request unit.
14. a third request means for requesting, when an instruction to collectively register the plurality of devices searched for by the search means in the server, setting information including security setting information for communication between the server and the plurality of devices from the server; a second transmission means for transmitting the setting information acquired from the server in response to a request made by the third request means to the plurality of devices; a fourth request means for sending identification information of the plurality of devices to the server and requesting registration of the devices in the server when it is determined that the setting information has been reflected in the plurality of devices; 2. The information processing apparatus according to claim 1, further comprising:
15. 15. The information processing apparatus according to claim 14, further comprising a second save request means for requesting, when the setting information cannot be reflected in all of the plurality of devices, that the current setting information be saved from the devices to which the setting information can be reflected.
16. 15. The information processing apparatus according to claim 14, further comprising: a display unit that displays a message indicating that the batch registration has failed if the setting information cannot be reflected in all of the plurality of devices.
17. A method for registering a device connected to an information processing device to a server, comprising: logging in the information processing device to the server; a search step in which the information processing device searches for connected devices when the login is successful; an acquisition step of acquiring setting information including security setting information for the device searched for in the search step to communicate with the server from the server; a sending step of sending the setting information acquired in the acquiring step to the device; a determination step of determining whether the setting information sent to the device in the sending step has been reflected in the device; a request step of requesting the server to register the device when it is determined in the determination step that the setting information has been reflected in the device; 16. A method comprising:
18. The method of claim 17 , wherein the configuration information includes security configuration information for a tenant to which the discovered device belongs.
19. A program for causing an information processing device to execute a method for registering a device connected to the information processing device to a server, The method comprises: logging in the information processing device to the server; a search step in which the information processing device searches for connected devices when the login is successful; an acquisition step of acquiring setting information including security setting information for the device searched for in the search step to communicate with the server from the server; a sending step of sending the setting information acquired in the acquiring step to the device; a determination step of determining whether the setting information sent to the device in the sending step has been reflected in the device; a request step of requesting the server to register the device when it is determined in the determination step that the setting information has been reflected in the device; A program comprising: