Information processing device, control method, and program

The information processing apparatus addresses the need for secure access control by incorporating an operation unit, receiving unit, and first authentication unit to manage varying authentication levels, ensuring secure and appropriate access to remote UI screens.

JP2025091292APending Publication Date: 2025-06-18CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023206478
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-06
Publication Date
2025-06-18

AI Technical Summary

Technical Problem

There is a need for an information processing apparatus that can perform appropriate access control, particularly for devices like printers that require secure remote UI access but often face challenges with user proficiency in network setup and authentication.

Method used

The information processing apparatus includes an operation unit for user input, a receiving unit for remote connection requests, and a first authentication unit that performs authentication based on user operations on the operation unit, ensuring appropriate access control by varying authentication levels across different remote UI screens.

Benefits of technology

This solution enables secure and appropriate access control for information processing apparatuses, ensuring that only authorized users can access sensitive settings, thereby enhancing security and usability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025091292000001_ABST
    Figure 2025091292000001_ABST
Patent Text Reader

Abstract

To make it possible to perform appropriate access control according to a screen that constitutes a remote UI.SOLUTION: An information processing device capable of communicating with an external device is provided with: an operation unit provided on an outer surface of the information processing device so as to accept an operation by a user; reception means for receiving a request for remote connection to the information processing device from the external device; and first authentication means for performing a first authentication to permit the request based on the operation on the operation unit, when the request is received by the reception means.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing apparatus capable of setting the apparatus from an external device.

Background Art

[0002] Among information processing apparatuses connectable to a network, there are apparatuses that provide means for performing various settings from an external device connected via the network. Specifically, the information processing apparatus provides a screen necessary for various setting operations to the external device, receives the operation result performed on the external device, and reflects the operation result. Hereinafter, the operation means for the information processing apparatus provided by the information processing apparatus to the external device is referred to as "remote UI".

[0003] With the spread of the technologies of the Internet and wireless LAN, the number of cases where a printer as an information processing apparatus and an external device are connected by wireless LAN has been increasing. Along with this, when arranging the connection environment to the network, the number of cases where users who are not proficient in network environment construction introduce wireless LAN has been increasing. On the other hand, such users often cannot perform operations such as preparing remote UI or correctly inputting the password required for authentication and connecting.

[0004] Patent Document 1 discloses a method of making remote UI available.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] A technique for performing appropriate access control is required.

[0007] The present disclosure aims to provide an information processing apparatus that performs appropriate access control.

Means for Solving the Problem

[0008] An information processing apparatus according to an aspect of the present disclosure is an information processing apparatus capable of communicating with an external device, and includes an operation unit provided on an outer surface of the information processing apparatus that can receive an operation by a user, a receiving unit that receives a request for remote connection from the external device to the information processing apparatus, and a first authentication unit that performs a first authentication for permitting the request based on an operation on the operation unit when the receiving unit receives the request.

Advantages of the Invention

[0009] According to the present disclosure, appropriate access control can be performed.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Figure 13

Figure 14

Figure 15

Figure 16

Mode for Carrying Out the Invention

[0011] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the present disclosure, and not all of the combinations of features described in the following embodiments are essential for the solution means of the present disclosure. For the same configuration, the same reference numerals will be used for description.

[0012] In this embodiment, the information processing apparatus has a remote UI function. The remote UI function is a function of displaying a setting screen for performing various settings of the information processing apparatus on a display unit of an external device described later. Specifically, in order to execute the remote UI function, the user first inputs the IP address of the information processing apparatus to which the external device is connected via a wireless network, a wired network, or the like into the Web browser of the external device. Then, the external device accesses the information processing apparatus by using the input IP address and requests execution of the remote UI function. When the request is permitted by the information processing apparatus, the information processing apparatus provides the external device with information for displaying the above setting screen. The request is, for example, a password for executing the remote UI function, and is permitted when the password input to the external device and transmitted to the information processing apparatus is correct. The external device that has received the information for displaying the above setting screen displays the above setting screen on the Web browser. When an operation is performed by the user on the above setting screen, the external device transmits an instruction and information based on the operation to the information processing apparatus, and the information processing apparatus performs processing and settings based on the operation. Settings that can be executed by the remote UI function are, for example, various settings related to printing and scanning functions, and various settings related to the network of the information processing apparatus. According to the remote UI, even if the information processing apparatus does not have a display screen and input operation means, installation settings and parameter settings can be performed. However, there is a risk of being connected via the network by a malicious third party from the outside and having the settings viewed or changed illegally. Therefore, it is common to configure the use of the remote UI to provide password authentication so that only authorized administrators can use the remote UI. In particular, in recent years, the number of security attack cases has increased, and security has been emphasized as the awareness of the side that introduces and uses the device. In various information processing apparatuses, random passwords different for each device are set at the time of product shipment and the apparatuses are shipped.

[0013] In addition, with the spread of Internet and wireless LAN technologies, the types and numbers of network-connectable devices have increased exponentially. For example, printers, which used to need to be connected to external devices such as personal computers with connection cables such as Centronics and USB, can now be used without cables due to their wireless LAN compatibility in recent years. However, in the past, devices that could be used by connecting them to external devices with cables now require settings for wireless LAN connection. That is, in order to use the remote UI, the user has to go through the trouble of setting up the wireless LAN and entering the password for authentication. Therefore, a method that enables the use of the remote UI with simpler authentication is desired.

[0014] In the following embodiments, a printer will be described as an example of an information processing device that sets a required level that requests a predetermined authentication level on a plurality of screens constituting the remote UI. In addition, the processing of the printer and the external device that can appropriately control access from the external device will be described. Note that in the following embodiments, the information processing device is not limited to a printer. For example, the information processing device may be a device that provides a remote UI to an external device, as long as it is a device on which a setting operation for the processing executed by the information processing device is performed. Specifically, the information processing device may be a scanner, a smart speaker, a wireless LAN router, a camera, or other household appliances. In the following embodiments, a smartphone will be described as an example of the external device, but it is not limited to this. For example, the external device may be a device equipped with a general web browser, such as a desktop PC (Personal Computer), a notebook PC, a tablet terminal, or a television.

[0015] <<First Embodiment>> FIG. 1 is a diagram showing an example of the configuration of a system 100 according to a first embodiment of the present disclosure. The present system 100 is composed of a cloud server 300 and a device group 400 connected by a local area network 102 and the Internet 104. The device group 400 includes various devices capable of network connection. For example, the device group 400 includes a smartphone 500, a printer 200, a client terminal 401 such as a personal computer or a workstation, and a digital camera 402. However, the device group 400 is not limited to these types, and may include, for example, home appliances such as a refrigerator, a television, and an air conditioner.

[0016] These various devices of the device group 400 are interconnected by the local area network 102 and can be connected to the Internet 104 via a router 103 installed in the local area network 102. Here, the router 103 is illustrated as a device connecting the local area network 102 and the Internet 104, but it is also possible to provide a wireless LAN access point function constituting the local area network 102. In this case, in addition to connecting to the router 103 by a wired LAN, the various devices of the device group 400 can be configured to connect to an access point by a wireless LAN and participate in the local area network 102. For example, the printer 200 and the client terminal 401 can be configured to be connected by a wired LAN, and the smartphone 500 and the digital camera 402 can be configured to be connected by a wireless LAN.

[0017] Each device in device group 400 can communicate with cloud server 300 via the Internet 104 connected through router 103. Also, the various devices in device group 400 can communicate with each other via local area network 102. Further, smartphone 500 and printer 200 can communicate by short-range wireless communication 101. As the short-range wireless communication 101, wireless communication conforming to the Bluetooth (registered trademark) standard or NFC standard can be considered. Also, smartphone 500 is connected to the mobile phone line network 105 and can also communicate with cloud server 300 via this line network 105. Note that this configuration shows an example of the present disclosure, and even if a different configuration is adopted, the effects of the present disclosure do not change. For example, although an example in which router 103 has an access point function is shown, the access point may be configured by a device different from router 103.

[0018] Figure 2 is an external view showing an example of printer 200. In the present embodiment, a multifunction printer (MFP) having a scanner and other functions in addition to printing will be described as an example. Figure 2(a) shows the overall external view of printer 200. The document table 201 is a glassy transparent table and is used when placing a document and reading it with a scanner. The document table platen 202 is a cover for pressing the document against the document table so that the document does not float when reading with the scanner and for preventing external light from entering the scanner unit. The printing paper insertion slot 203 is an insertion slot for setting papers of various sizes. The papers set here are conveyed one by one to the printing unit, printed as desired, and discharged from the printing paper discharge port 204.

[0019] Figure 2(b) shows an external view of the upper surface of the printer 200. An operation panel 205 and a short-range wireless communication unit 206 are arranged above the original document table platen 202. The short-range wireless communication unit 206 is a unit for performing short-range wireless communication and can communicate with the short-range wireless communication unit of a communication partner within a predetermined distance. The wireless LAN unit 207 has an antenna embedded therein for connecting to and communicating with the local area network 102 using the wireless LAN.

[0020] Figure 3 is a diagram showing an example of the configuration of the operation panel 205 of the printer 200. With reference to Figure 3, the configuration of the operation panel 205 will be described. The operation panel 205 is composed of display lamps using light-emitting diodes (LEDs) and keys for receiving operations. Hereinafter, in this embodiment, an operation unit provided on the outer surface of the printer 200 and for receiving operations by the user is referred to as a key. The operation panel 205 of this embodiment shows an example without a liquid crystal screen capable of graphic display and a touch panel function. The power key 310 is a key for performing power-on and power-off operations. When the power key 310 is pressed in the power-off state, the printer 200 shifts to the power-on state. When the power key 310 is pressed in the power-on state, the printer 200 shifts to the power-off state. When the power key 310 is pressed during an operation such as printing, the printer 200 completes or aborts the processing during operation and then shifts to the power-off state. The power lamp 311 is a lamp indicating the power state of the printer 200. The power lamp 311 lights up in the power-on state and goes out in the power-off state. During operation, during power-on processing, during power-off processing, etc., the power lamp 311 may be configured to blink.

[0021] The copy number display unit 312 is a display that shows the number of printed copies, etc. The copy number display unit 312 is composed of 7-segment LEDs. The printer 200 can display numbers from 0 to 9, etc. on the copy number display unit 312 by controlling the lighting and extinguishing of each segment. Four paper selection lamps 313, 314, 315, and 316 are provided next to the copy number display unit 312. The A4 paper selection lamp 313 indicates that A4 paper is selected. The LTR paper selection lamp 314 indicates that letter paper is selected. The 4x6 paper selection lamp 315 indicates that 4x6-inch paper for photo printing is selected. The registered paper selection lamp 316 marked with "*" indicates that pre-registered paper is selected. Here, the physical notation of the paper size is printed or engraved on the operation panel 205, and an LED lamp is arranged next to the notation of the paper size, so that the selected paper can be explicitly displayed. However, the present invention is not limited to this. For example, a lamp may be incorporated in the notation of the paper size itself, and the selected paper may be displayed by lighting or extinguishing the notation. Also, a configuration other than an LED lamp may be adopted to display the selected paper.

[0022] The paper selection key 317 is a key for sequentially switching and selecting the above-mentioned four paper selections. The OK key 318 is used to confirm after switching the paper selection display with the paper selection key 317. In addition, the OK key 318 may also be used for other purposes depending on the device state of the printer 200. The monochrome start key 319 and the color start key 320 are keys for starting a printing operation that operates on the printer 200 alone, such as a copy function. When the monochrome start key 319 is pressed in the power-on standby state, the printer 200 executes a monochrome copy operation. When the color start key 320 is pressed in the power-on standby state, the printer 200 executes a color copy operation. In addition, the monochrome start key 319 and the color start key 320 may also be used to execute other operations and other processes depending on the device state of the printer 200 and the combined operation with other keys.

[0023] The stop key 321 is a key for interrupting the operations and processes being executed by the printer 200 and returning it to the standby state. When the user presses the stop key 321 while the printer 200 is in an error state, the user can cancel the error or cancel the job being executed. The error lamp 322 is a lamp that indicates the error state of the printer 200. The error lamp 322 is off in the normal state, but lights up or blinks when an error occurs. There are multiple types of errors, such as an out-of-ink error, a paper-out error, and a paper jam error. The error lamp 322 can notify the type of error based on the difference in the blinking pattern. Also, the printer 200 can show the user the type of error and the countermeasure method by controlling the display of the copy count display unit 312 in combination with the lighting and blinking of the error lamp 322.

[0024] FIG. 4 is a block diagram showing an example of the configuration of the printer 200. With reference to FIG. 4, the configuration of the printer 200 will be described. The printer 200 includes a main board 410 that controls the entire apparatus, a wireless LAN unit 207, a short-range wireless communication unit 206, and an operation panel 205. Also, the main board 410 includes a CPU 411, a program memory 413, a data memory 414, a scanner mechanism control circuit 415, a printing mechanism control circuit 417, a wireless LAN control circuit 418, a short-range wireless communication control circuit 419, and an operation unit control circuit 420.

[0025] The CPU 411 in the form of a microprocessor arranged on the main board 410 reads out the control program stored in the program memory 413 in the form of a ROM, which is connected via the internal bus 412, into the data memory 414 in the form of a RAM, and executes various controls. The CPU 411 controls the scanner mechanism control circuit 415 to read a document and stores it in the image memory 416 in the data memory 414. Further, the CPU 411 can control the printing mechanism control circuit 417 to print the image in the image memory 416 in the data memory 414 on a recording medium. The CPU 411 controls the wireless LAN unit 207 via the wireless LAN control circuit 418 to perform wireless LAN communication with other communication terminal devices. Also, the CPU 411 controls the short-range wireless communication unit 206 via the short-range wireless communication control circuit 419 to detect a connection with another short-range wireless communication terminal or to perform data transmission and reception with another short-range wireless communication terminal. The CPU 411 can perform control to display the status of the printer 200 and a function selection menu, etc. on the operation panel 205 via the operation unit control circuit 420, and can receive key operations, etc. by the user from the operation panel 205.

[0026] Figure 5 is a diagram showing an example of the module configuration of the software operating on the printer 200. With reference to Figure 5, the module configuration of the software of the printer 200 will be described. The software operating on the printer 200 operates on the embedded control operating system (OS) 510. Each module is classified into a system control layer 520, a job management layer 530, a middleware layer 540, and an application layer 550.

[0027] The embedded control OS 510 is an operating system (OS) that controls the basic operations of the control software of the printer 200, and generally a real-time OS with excellent responsiveness is used.

[0028] The system control layer 520 is a group of modules that mainly control the hardware of the printer 200. The print control module 521 is a control module for controlling the print mechanism control circuit 417 to execute the printing operation of the printer 200. The reading control module 522 is a control module for controlling the scanner mechanism control circuit 415 to execute the reading operation of the document placed on the document table 201. The panel control module 523 is a control module for controlling the display of the operation panel 205 of the printer 200 and detecting various key operations. The memory management module 524 is a control module for managing the dynamic allocation of the data memory 414 including the image memory 416. The power control module 525 is a control module for controlling the power supply of the printer 200, supplying the power required for operation to each block of the hardware, and performing power saving mode control. The proximity wireless communication control module 526 is a control module for controlling the short-range wireless communication unit 206 to communicate with a terminal device such as the smartphone 500. The network communication control module 527 is a control module for controlling the wireless LAN unit 207 to perform communication physical layer control for LAN communication with an external device.

[0029] The job management layer 530 is a group of modules that execute various operations using the system control layer 520 while performing resource allocation, exclusive control, scheduling, etc. of the hardware in response to a job execution request from the upper layer.

[0030] The middleware layer 540 is located between the application layer 550 and the job management layer 530, which will be described later, and is a collection of a group of modules commonly used by a plurality of functional modules in the application layer 550. The application framework 541 is a framework module commonly used when requesting job execution from the application layer 550 to the job management layer 530. The network protocol stack 542 is a module for performing communication in accordance with various network protocols such as HTTP or TCP / IP. The encryption processing module 543 is a module for performing encryption and decryption processing required for network communication and the like. The Web server 544 is a module for operating the printer 200 as a Web server in order to deliver remote UI content.

[0031] The application layer 550 is a group of applications that implement various functions of the printer 200. The copy application 551 is an application module for executing a copy operation of reading and printing a document. The driver printing application 552 is an application module for receiving a job from a printer driver such as the smartphone 500 and the client terminal 401 and executing an operation. Jobs from the driver include a printing job for executing a printing operation, a scan job for reading a document and outputting image data, and a maintenance job for exchanging information with an external device and setting and managing the printer 200. The standard printing application 553 is an application module for receiving a job from the standard printing service provided by the system of the smartphone 500 and executing an operation. Jobs from the standard printing service include a printing job for executing a printing operation and a scan job for reading a document and outputting image data. However, since the standard printing service is provided by a smartphone manufacturer or a standard OS vendor, there is a limitation that it cannot perform specific settings and management related to individual printer models of each manufacturer.

[0032] The remote UI module 554 is a module that uses the web server 544 to provide the remote UI function of the printer 200 to an external device. With the remote UI function of the printer 200, a user can set up and manage the printer 200 from a smartphone 500 or a client terminal 401. Here, depending on the type and functions of the printer, etc., the information that can be displayed on the operation panel of the printer and the information that can be set in the printer may be restricted. For example, as described above, even if the standard printing application 553 is installed in the printer 200, specific settings regarding individual printer models of each manufacturer may not be possible. In the printer 200 in this embodiment, the remote UI function can be used for more detailed settings and management. Also, when dedicated drivers are not prepared for the smartphone 500 and the client terminal 401, etc., only the standard printing service is available, so the use of the remote UI is essential for detailed settings and management.

[0033] FIG. 6 is a block diagram showing an example of the configuration of the smartphone 500. With reference to FIG. 6, the configuration of the smartphone 500 will be described. The smartphone 500 includes a main board 610 that controls the entire device, a wireless LAN unit 602, a short-range wireless communication unit 601, a line connection unit 603, and a touch panel display 604. The main board 610 includes a CPU 611, a program memory 613, a data memory 614, a wireless LAN control circuit 615, a short-range wireless communication control circuit 616, a line control circuit 617, an operation unit control circuit 618, a camera unit 619, and a non-volatile memory 621.

[0034] The CPU 611 in the form of a microprocessor arranged on the main board 610 reads out the control program stored in the program memory 613 in the form of a ROM, which is connected via the internal bus 612, to the data memory 614 in the form of a RAM, and executes various controls. The CPU 611 controls the wireless LAN unit 602 via the wireless LAN control circuit 615 to perform wireless LAN communication with other communication terminal devices. The CPU 611 can detect a connection with other short-range wireless communication terminals or perform data transmission and reception with other short-range wireless communication terminals by controlling the short-range wireless communication unit 601 via the short-range wireless communication control circuit 616. Also, the CPU 611 can connect to the mobile phone line network 105 and perform calls and data transmission and reception by controlling the line connection unit 603 via the line control circuit 617. The CPU 611 can perform a desired display on the touch panel display 604 and receive a user's operation input from the touch panel display 604 by controlling the operation unit control circuit 618.

[0035] The CPU 611 can control the camera unit 619 to take an image and store the taken image in the image memory 620 in the data memory 614. Also, in addition to the taken image, it is possible to store an image acquired from the outside through the mobile phone line, the local area network 102, or the short-range wireless communication 101 in the image memory 620. Furthermore, the CPU 611 can transmit the image acquired by shooting or the image acquired from the outside to the outside. The non-volatile memory 621 is composed of a flash memory or the like and stores data that needs to be saved even after the power is turned off. For example, in the non-volatile memory 621, in addition to phone book data, various communication connection information, and device information connected in the past, image data that needs to be saved, or application software that realizes various functions in the smartphone 500 is stored.

[0036] FIG. 7 is a diagram showing an example of the module configuration of software operating on the smartphone 500. Referring to FIG. 7, the module configuration of the software of the smartphone 500 will be described. The software operating on the smartphone 500 operates on an operating system (OS) 700. Each module is classified into a system control layer 710, a middleware layer 720, and an application layer 730.

[0037] The system control layer 710 is a group of modules that mainly control the hardware of the smartphone 500. The GUI control module 711 is a control module for controlling the display on the touch panel display 604 and detecting touch panel operations. The camera control module 712 is a module for controlling shooting by the camera unit 619. The proximity wireless communication control module 713 is a control module for controlling the short-range wireless communication unit 601 to perform proximity wireless communication with other devices. The network communication control module 714 is a control module for performing communication physical layer control for controlling the wireless LAN unit 602 to perform wireless LAN communication with an external device. The memory management module 715 is a control module for performing management such as dynamic allocation of the data memory 614 including the image memory 620. The power control module 716 is a control module for controlling the power supply of the smartphone 500, supplying the power required for operation to each block of the hardware, and performing power saving mode control.

[0038] The middleware layer 720 is located between the application layer 730 and the system control layer 710, which will be described later, and is a collection of a group of modules commonly used by a plurality of application modules in the application layer 730. The application framework 721 is a framework module commonly used by the applications in the application layer 730. The network protocol stack 723 is a module for performing communication in accordance with various network protocols such as HTTP or TCP / IP. The standard printing service 722 is a service module that provides the applications in the application layer 730 with the function of using the printer 200 corresponding to the standard printing service. The functions provided by the standard printing service 722 include a printing function for causing the printer 200 to execute a printing job, a scanning function for causing a scanning job to be executed, and the like. However, since the standard printing service is provided by a smartphone manufacturer or a standard OS vendor, there is a limitation that it cannot perform specific settings and management regarding the printer models of individual manufacturers.

[0039] The application layer 730 is a group of applications that implement various functions of the smartphone 500. Among the applications installed on the smartphone 500, there are those pre-installed at the time of product shipment and those that can be downloaded and introduced later by the user. In FIG. 7, App 1 (731) and App 2 (732) are shown, but the number and types of such applications are not limited to these. That is, the applications can be added or deleted as necessary by the user. The custom printing driver 733 is a dedicated driver corresponding to the model of the printer 200, and provides the function of executing print jobs and scan jobs to the corresponding printer 200. The user selects a dedicated driver corresponding to the model of the printer 200 that they use and installs it on the smartphone 500 for use. Here, although the custom printing driver 733 is described as being installed in the application layer, it is not limited to this. The custom printing driver 733 may be installed in the middleware layer and configured to operate upon receiving a print job request from an application. The web browser 734 is an application module that connects to a web server through a network, acquires web content, and displays it. It can also acquire and display the web content of the cloud server 300, or acquire and display remote UI content using the web server function of the printer 200.

[0040] FIG. 8 is a diagram showing an example of the page configuration of the remote UI. With reference to FIG. 8, the configuration of the page of the remote UI displayed on the web browser 734 when remotely connecting from the smartphone 500 to the printer 200 will be described. The remote UI becomes available by accessing the printer 200 by inputting the IP address set in the printer 200 or a URL including the IP address from the web browser 734 installed in the smartphone 500 or the like. The entire remote UI 800 is composed of a plurality of screens including a main screen 810, a printer status display screen 820, a printer operation setting screen 830, and a network connection setting screen 840. When the user inputs a URL including the IP address from the web browser 734 and accesses the remote UI, the main screen 810 is displayed on the web browser 734. As shown in FIG. 8, the required authentication level for accessing the main screen 810 is 0.

[0041] Here, the required level indicates that the printer 200 requests a predetermined authentication level given to the smartphone 500, and is an index indicating the ease of access to each screen constituting the page of the remote UI. Also, the authentication level is the level corresponding to the authentication given by the printer 200 when authentication is successful by a predetermined authentication method. In other words, when authentication is successful by a predetermined authentication method, the printer 200 sets the level of the smartphone 500's permission to access the screen to a predetermined authentication level and permits access to the screen. For example, when authentication is successful by the first authentication method, the printer 200 sets the level of the smartphone 500's permission to access the screen to authentication level 1 and permits access to the screen. Hereinafter, the printer 200 setting the level of the smartphone 500's permission to access the screen to a predetermined authentication level is referred to as "giving an authentication level". In the present embodiment, the smartphone 500 with authentication level 0 indicates a state not authenticated by the printer 200. That is, the smartphone 500 not authenticated by the printer 200 can access the main screen 810 with the required level 0 set. Note that details regarding whether or not a smartphone 500 given a predetermined authentication level can transition to a screen with a predetermined required level set will be described later.

[0042] The user can access each page other than the main screen 810 from the hyperlink placed on the main screen 810. In addition, the user can also directly specify and access the URL obtained by adding the relative path of each page to the URL of the main screen 810. When accessing each page, an authentication screen described later may be displayed as necessary. The authentication information resulting from the authentication performed by the printer 200 is passed to the web browser 734 as a Cookie issued from the web server 544 of the printer 200 and managed. In subsequent page transitions, when a request with the Cookie issued by the web server 544 is sent from the web browser 734 to the printer 200, access permission to each page is given to the smartphone 500 based on the inherited authentication information. Note that a method other than Cookie may be used for passing on the authentication information.

[0043] Hereinafter, a plurality of pages linked from the main screen 810 will be described. The printer status display screen 820 is a display screen for checking the device status of the printer 200. As shown in FIG. 8, the required authentication level for accessing the printer status display screen 820 is 0. Also, the URL for accessing the printer status display screen 820 is obtained by attaching the relative path “ / status.html” to the URL of the main screen 810.

[0044] The printer operation setting screen 830 is a screen for performing parameter settings necessary for using the functions of the printer 200. As shown in FIG. 8, the required authentication level for accessing the printer operation setting screen 830 is 1. Also, the URL for accessing the printer operation setting screen 830 is obtained by attaching the relative path “ / settins.html” to the URL of the main screen 810.

[0045] The network connection settings screen 840 is a screen for performing settings necessary to connect the printer 200 to a network. As shown in FIG. 8, the required authentication level for accessing the network connection settings screen 840 is 2. Also, the URL for accessing the network connection settings screen 840 is the URL of the main screen 810 with the relative path “ / config.html” appended thereto.

[0046] FIG. 9 is a diagram showing an example of a page screen of the remote UI. Referring to FIG. 9, a specific example of the screen shown in FIG. 8 described above will be explained. FIG. 9(a) is a diagram showing the display content of the main screen 810. The main screen 810 is a page that serves as an entrance to the entire remote UI 800, and buttons 901, 902, and 903 with hyperlinks for transitioning to other pages are arranged. Hereinafter, in the present embodiment, an element provided on the displayed screen that accepts execution of a predetermined process by the CPU through an operation by the user on the element will be referred to as a button. Note that the page screen of the remote UI may include a specific page other than the main screen 810 on which buttons for transitioning to a screen with a predetermined required level are arranged. Button 901 is a button for transitioning to the printer status display screen 820. Button 902 is a button for transitioning to the printer operation settings screen 830. Button 903 is a button for transitioning to the network connection settings screen 840. Since the main screen 810 is positioned as an entrance page as described above, a required level 0 that does not require authentication for access is set.

[0047] FIG. 9(b) is a diagram showing the display content of the printer status display screen 820. The printer status display screen 820 is a screen for checking the device status of the printer 200. In the printer name display section 911, when the user is using a plurality of printers, the name of the printer is displayed to determine which printer's status it is. Even when the user is using only one printer, the name of the printer being used may be displayed in the printer name display section 911. The name of the printer may be pre-assigned for each device, or may be configured to be set by the user. However, on the printer status display screen 820, it is desirable to configure it so that the printer name cannot be changed and only displayed for identification purposes. In the error status display section 912, a display of no ink, no paper, and errors that require handling such as paper jams in the printer 200, or no error occurrence, is shown. In the ink status display section 913, the remaining amount information of each color ink used in the printer 200 is displayed. The return button 914 is a button for returning to the main screen 810. Thus, on the printer status display screen 820, while the status of the printer 200 is displayed, setting changes cannot be made and important information of the user cannot be viewed, so a request level 0 that does not require authentication is set.

[0048] FIG. 9(c) is a diagram showing the display content of the printer operation setting screen 830. The printer operation setting screen 830 is a screen for performing parameter settings necessary for using the functions of the printer 200. Here, an example is shown in which the paper size and paper type used in the copy function can be set. The paper size setting section 921 displays the paper size used in the copy function. When the button with a triangular symbol displayed in the paper size setting section 921 is pressed, a list of available paper sizes is displayed. The user can select the paper size to be used from the list. The paper type setting section 922 displays the paper type used in the copy function. When the button with a triangular symbol displayed in the paper type setting section 922 is pressed, a list of available paper types is displayed. The user can select the paper type to be used from the list. The setting button 923 is a button for determining the selected paper size and paper type and setting them in the printer 200. The return button 924 is a button for returning to the main screen 810. In this way, the printer operation setting screen 830 is a screen for users who use the functions of the printer 200 to perform daily settings. While it is necessary to prevent the setting values from being changed arbitrarily by remote users through authentication, it is desirable to make it easily accessible to users. Therefore, the printer operation setting screen 830 is set to a required level 1 that allows access either by authentication by a simple operation on the keys provided on the operation panel 205 of the printer 200 or by password authentication.

[0049] FIG. 9(d) is a diagram showing the display content of the network connection setting screen 840. The network connection setting screen 840 is a screen for performing settings necessary to connect the printer 200 to a network. Here, an example in which wireless LAN connection settings can be performed is shown. In the SSID setting section 931, a Service Set Identifier (hereinafter referred to as SSID) for identifying a wireless LAN access point is displayed. Further, the user can set the SSID in the SSID setting section 931. In the password setting section 932, the user can set a password for authenticating the wireless LAN access point displayed in the SSID setting section 931. Here, for security reasons, an example is shown in which the set password is displayed in black dot notation so that it cannot be seen even if peeked at. In the security setting section 933, the user can set a method for encrypting communication between the wireless LAN access point and the printer 200. The setting button 934 is a button for determining the information set in the SSID setting section 931, the password setting section 932, and the security setting section 933. The back button 935 is a button for returning to the main screen 810. Thus, the network connection setting screen 840 is a screen for performing settings necessary to connect the printer 200 to a network. If the information set on the network connection setting screen 840 is inadvertently changed, the printer 200 may not be able to connect to the network, and the remote UI provided by the printer 200 may not be used normally. Also, even if no setting changes are made, if unauthorized access is made to the network connection setting screen 840 via the network, the SSID and security setting contents, which are important information for the user, may be peeked at. Therefore, a requirement level 2, which requires password authentication and has a higher security level, is set for the network connection setting screen 840.

[0050] FIG. 10 is a diagram showing an example of an authentication screen of the remote UI. With reference to FIG. 10, two types of remote UI authentication screens, a simple authentication screen 1000 and a password authentication screen 1010, will be described.

[0051] FIG. 10(a) is a diagram showing the content of the simple authentication screen 1000. The simple authentication screen 1000 is a screen transmitted from the printer 200 to the smartphone 500 in order to give access permission by either authentication by a simple operation on a key provided on the operation panel 205 of the printer 200 or password authentication. The simple authentication screen 1000 received from the printer 200 and displayed on the web browser 734 may be switched and displayed with the main screen 810 or may be displayed as a pop-up.

[0052] An account name for accessing the remote UI is input into the account name input section 1001. A password for accessing the remote UI is input into the password input section 1002. Here, for security reasons, an example is shown in which the input password is converted to black dot notation and displayed so that it cannot be seen even if peeked at. The content of the key operation for permitting access is displayed on the key operation display section 1003. When the key operation displayed on the key operation display section 1003 is performed on the operation panel 205 of the printer 200 while the simple authentication screen 1000 is being displayed, authentication level 1 is given and access is permitted.

[0053] Also, when an account name and password are entered on the simple authentication screen 1000 and the OK button 1004 is pressed, the printer 200 performs authentication processing for the entered account name and password. That is, when the OK button 1004 is pressed, the smartphone 500 sends an authentication request to the printer 200 that requests authentication of the password. If the entered account name and password match the information previously set in the use of the remote UI, authentication level 2 is given and access is permitted. On the other hand, if they do not match, or if the cancel button 1005 is pressed, access is not permitted. Here, when the cancel button 1005 is pressed, the web browser 734 cancels the display of the simple authentication screen 1000 and displays the main screen 810. In this case, when the cancel button 1005 is pressed, the smartphone 500 requests the printer 200 to transition to the main screen 810. Note that the key operation used for authentication may be fixed, or may be configured to be set in advance by the user of the printer 200. Also, in order to increase the security strength, the key operation used for authentication may be configured to be randomly changed each time authentication is performed. That is, the content of the key operation used for authentication may be configured to be different each time the simple authentication screen 1000 is transmitted.

[0054] Figure 10(b) is a diagram showing the content of the password authentication screen 1010. The password authentication screen 1010 is a screen transmitted from the printer 200 to the smartphone 500 in order to give access permission by password authentication. The password authentication screen 1010 received from the printer 200 and displayed on the web browser 734 may be switched and displayed with the main screen 810, or may be displayed as a pop-up.

[0055] In the account name input section 1011, an account name for accessing the remote UI is entered. In the password input section 1012, a password for accessing the remote UI is entered. Here, for security reasons, an example is shown where the entered password is converted to black dot notation and displayed so that it cannot be seen even if peeked at. When an account name and password are entered on the password authentication screen 1010 and the OK button 1013 is pressed, the printer 200 performs authentication processing for the entered account name and password. That is, when the OK button 1013 is pressed, the smartphone 500 sends an authentication request to the printer 200 that requests password authentication. If the entered account name and password match the authentication information set in advance when using the remote UI, authentication level 2 is given and access is permitted. On the other hand, if they do not match, or if the cancel button 1014 is pressed, access is not permitted. Here, when the cancel button 1014 is pressed, the web browser 734 stops displaying the password authentication screen 1010 and displays the main screen 810. In this case, when the cancel button 1014 is pressed, the smartphone 500 requests the printer 200 to transition to the main screen 810.

[0056] Note that, although the example has been described of entering and authenticating an account name and password on the simple authentication screen 1000 and the password authentication screen 1010, it is not limited to this. For example, in the case where there is only one user, etc., it may be configured to authenticate only with a password without using an account name.

[0057] FIG. 11 shows a state transition table 1100 representing the transition to a page screen with a certain required level when a certain authentication level is given from the printer 200 to the smartphone 500. In the leftmost column of the state transition table 1100, numbers from 0 to 2 are arranged in order as the given authentication level 1101. Also, in the uppermost row of the state transition table 1100, numbers from 0 to 2 are arranged in order as the required level 1102 set for the destination page screen. In the state transition table 1100, the display of page transition availability or the type of authentication required is shown in the corresponding cell 1103 according to the combination of the given authentication level 1101 and the required level 1102 set for the destination page screen. For example, when the authentication level is 0, that is, when not authenticated, it indicates that it is possible to transition to the page with the required level 0 set. Also, when the authentication level is 0, it indicates that for the transition to the screen with a required level higher than the authentication level, authentication according to each required level is necessary. Specifically, when the authentication level is 0, simple authentication is required for the transition to the page with the required level 1 set, and password authentication is required for the transition to the page with the required level 2 set. Next, when the authentication level is 1, that is, when authentication by key operation is performed, it is possible to transition to the page with the required level 0 or 1 set, but password authentication is required for the transition to the page with the required level 2 set. Finally, when the authentication level is 2, that is, when authentication by password input is performed, it indicates that it is possible to transition to any page with the required level 0 to 2 set.

[0058] FIG. 12 is a flowchart showing an example of the processing of the printer 200. The processing shown in FIG. 12 is realized by the CPU 411 of the printer 200 reading a control program stored in the program memory 413 in the form of a ROM into the data memory 414 in the form of a RAM and the CPU 411 executing it. Note that some or all of the functions of the steps in FIG. 12 may be realized by hardware such as an ASIC or an electronic circuit. The symbol "S" in the description of each process means that it is a step in the flowchart diagram (the same applies to the flowchart diagrams in this specification hereinafter). Also, the processing shown in FIG. 12 is started by the CPU 411 of the printer 200 when power is supplied to the printer 200.

[0059] In S1201, the CPU 411 performs initialization processing on each part of the hardware of the printer 200 and the data memory 414 and the like. Here, the printer 200 is in a power-off state waiting for a power-on operation.

[0060] In S1202, with the printer 200 in the power-off state, the CPU 411 waits for an event to occur. Here, examples of the event include pressing of the power key 310 by the user. Hereinafter, the CPU 411 performs necessary processing according to the generated event.

[0061] In S1203, the CPU 411 detects the occurrence of an event in the power-off state. If the CPU 411 detects pressing of the power key 310 in the power-off state (Yes), the process proceeds to S1204; otherwise (No), the process proceeds to S1202. That is, the CPU 411 continues the processing of S1202 and S1203 until it detects pressing of the power key 310 in the power-off state. In S1204, the CPU 411 shifts the printer 200 to the power-on state and then proceeds to the processing of S1205.

[0062] In S1205, when the printer 200 is powered on, the CPU 411 waits for an event to occur. Examples of events that occur in the powered-on state include key operations on the operation panel 205 by the user, job data reception from an external device via a network or proximity wireless communication, a remote UI access request from an external device to the Web server 544, and so on. Hereinafter, the CPU 411 performs necessary processing according to the occurred event.

[0063] In S1206, the CPU 411 detects the occurrence of an event in the powered-on state. If the CPU 411 detects the pressing of the power key 310 in the powered-on state (Yes), the process proceeds to the processing of S1207; otherwise (No), the process proceeds to the processing of S1208. In S1207, the CPU 411 shifts the printer 200 to the powered-off state, and then the process proceeds to the processing of S1202.

[0064] In S1208, if the CPU 411 detects the pressing of the color start key 320 (Yes), the process proceeds to the processing of S1209; otherwise (No), the process proceeds to the processing of S1210. In S1209, the CPU 411 executes a color copy operation using color ink and black ink, and then the process proceeds to the processing of S1205.

[0065] In S1210, if the CPU 411 detects the pressing of the monochrome start key 319 (Yes), the process proceeds to the processing of S1211; otherwise (No), the process proceeds to the processing of S1212. In S1211, the CPU 411 executes a monochrome copy operation using black ink, and then the process proceeds to the processing of S1205.

[0066] In S1212, when the CPU 411 detects the reception of job data from the custom print driver 733 of the external device (Yes), it proceeds to the process of S1213, and when not (No), it proceeds to the process of S1214. In S1213, the CPU 411 executes the driver job, and then proceeds to the process of S1205. The execution of the driver job includes, for example, executing printing on the paper stored in the paper feed unit according to the instructions received from the custom print driver 733.

[0067] In S1214, when the CPU 411 detects the reception of job data from the standard print service 722 of the external device (Yes), it proceeds to the process of S1215, and when not (No), it proceeds to the process of S1216. In S1215, the CPU 411 executes the standard job, and then proceeds to the process of S1205. The execution of the standard job includes, for example, executing printing on the paper stored in the paper feed unit according to the instructions received from the standard print service 722.

[0068] In S1216, when the CPU 411 detects the pressing of the paper selection key 317 (Yes), it proceeds to the process of S1217, and when not (No), it proceeds to the process of S1218. In S1217, the CPU 411 executes the paper selection process, and then proceeds to the process of S1205. The paper selection process is a process of changing the selection of the type of paper used during the printing process executed in the printer 200. Specifically, when A4 is set as the paper used during the printing process and the paper selection key 317 is pressed, the CPU 411 performs a process of changing the selection to a paper type different from A4. For example, when the paper type is changed from A4 to LTR, the CPU 411 sets the paper type to LTR. After that, when the OK key 318 is pressed, as described above, the paper type is set to LTR.

[0069] In S1218, when the CPU 411 detects the pressing of the OK key 318 (Yes), it proceeds to the process of S1219, and when not (No), it proceeds to the process of S1220. In S1219, the CPU 411 increases the number displayed on the copy quantity display unit 312 by 1, and then proceeds to the process of S1205. This copy quantity is used when the copying operation is executed. As described above, when the paper selection key 317 is pressed in the process immediately before the OK key is pressed, the CPU 411 performs the process of setting the paper type.

[0070] In S1220, when the CPU 411 detects the pressing of the stop key 321 (Yes), it proceeds to the process of S1221, and when not (No), it proceeds to the process of S1222. In S1221, the CPU 411 clears the number displayed on the copy quantity display unit 312, displays 1 as the initial value, and then proceeds to the process of S1205. In this case, the CPU 411 also sets the copy quantity to 1 in the same manner.

[0071] In S1222, when the CPU 411 detects the reception of a remote UI request from the Web browser 734 of the external device to the Web server 544 of the printer 200 (Yes), it proceeds to the process of S1223, and when not (No), it proceeds to the process of S1205. In S1223, the CPU 411 performs response processing for the request described later, and then proceeds to the process of S1205.

[0072] FIG. 13 is a flowchart showing an example of the processing of the printer 200 when a remote UI request is received. The processing shown in FIG. 13 is executed by the CPU 411 as a sub-flow of S1223 in the flowchart of FIG. 12. That is, it is started by the CPU 411 of the printer 200 when the reception of a remote UI request from the Web browser 734 of the external device to the Web server 544 of the printer 200 is detected.

[0073] In S1301, the CPU 411 determines the type of the received remote UI request, and then performs processing according to the type of the request as follows.

[0074] In S1302, the CPU 411 determines whether the request type determined in S1301 is a page request. Specifically, when the CPU 411 determines that the request type is a request for each page constituting the remote UI (Yes), the process proceeds to the process of S1303, and when it determines otherwise (No), the process proceeds to the process of S1309.

[0075] In S1303, the CPU 411 determines whether the authentication level is sufficient based on the authentication level given to the request source and the required level set for the requested page. This determination may be made according to the state transition table 1100 described in FIG. 11. When the CPU 411 determines that the authentication level is sufficient (Yes), that is, the transition is possible, the process proceeds to the process of S1304, and when it determines otherwise (No), the process proceeds to the process of S1305. In S1304, the CPU 411 transmits the data of the requested page screen to the request source and ends the process shown in FIG. 13.

[0076] In S1305, the CPU 411 determines whether it is a transition that can be simply authenticated. When the CPU 411 determines that it is a transition that can be simply authenticated (Yes), the process proceeds to the process of S1306, and when it determines otherwise (No), the process proceeds to the process of S1308. For example, in FIG. 11, when the authentication level given to the request source is 0 and the required level set for the requested page is 1, the CPU 411 proceeds to the process of S1306. In S1306, the CPU 411 transmits the data of the simple authentication screen 1000 to the request source and proceeds to the process of S1307. When transmitting the data of the simple authentication screen 1000, the CPU 411 also includes the information of the URL of the page of the transition destination requested in the original request in the response and transmits it. This enables it to be used as the information of the transition destination after successful authentication. After transmitting these data, in S1307, the CPU 411 starts the key operation authentication process described later, which monitors the presence or absence of an authentication operation on the operation panel 205 for simple authentication.

[0077] In S1308, the CPU 411 sends the data of the password authentication screen 1010 to the request source and ends the process shown in FIG. 13. When sending the data of the password authentication screen 1010, the CPU 411 also includes the URL information of the destination page requested in the original request in the response and sends it. This enables it to be used as the destination information after successful authentication.

[0078] In S1309, the CPU 411 determines whether the request type is an authentication request. If the CPU 411 determines that the request type is an authentication request (Yes), it proceeds to the process of S1310, and if it determines otherwise (No), it ends the process shown in FIG. 13. Here, the authentication request is a request received when the account name and password are entered and the OK button is pressed for the authentication screen sent to the request source in S1306 or S1308. The CPU 411 can obtain the entered account name, the entered password, and the URL of the page screen to transition to after authentication from the request parameters and message body of the authentication request.

[0079] In S1310, the CPU 411 determines whether the input account name and the input password match the pre-set information. If the CPU 411 determines that they match (Yes), it proceeds to the process of S1311. If it determines otherwise (No), it ends the process shown in FIG. 13. In S1311, the CPU 411 sends the data of the page screen to the request source based on the URL of the page screen to transition to, and ends the process shown in FIG. 13. In addition, in S1310, although it has been described that when the input account name and the input password do not match the pre-set information, the process shown in FIG. 13 ends, it is not limited to this. For example, when they do not match, the CPU 411 may send the main screen 810 to the request source. In this case, when the OK button on the authentication screen is pressed and the password authentication fails, the web browser 734 of the smartphone 500 of the request source stops displaying the authentication screen and displays the main screen 810.

[0080] FIG. 14 is a flowchart showing an example of the process of the printer 200 in the key operation authentication process during simple authentication. The process shown in FIG. 14 starts at S1307 in FIG. 13, but is executed in a separate process from the process shown in FIG. 13. That is, it can operate in parallel with the process for the request following FIG. 13. The process shown in FIG. 14 is realized by the CPU 411 of the printer 200 reading the control program stored in the program memory 413 in the form of ROM into the data memory 414 in the form of RAM and the CPU 411 executing it.

[0081] In S1401, the CPU 411 starts measuring the time for the timeout process. After that, the CPU 411 proceeds to the process of S1402.

[0082] In S1402, the CPU 411 detects that an operation has been performed on the operation panel 205 of the printer 200. Then, when the detected operation is a key operation, the CPU 411 determines whether the detected key operation matches a predetermined key operation. Examples of the predetermined key operation include an operation of pressing the OK key while pressing the paper setting key as shown in FIG. 10. If the CPU 411 determines that it matches (Yes) the predetermined key operation, it proceeds to the process of S1403, and if it determines otherwise (No), it proceeds to the process of S1404. Here, as examples of proceeding from S1402 to the process of S1404, there are cases where the key operation on the operation panel 205 does not match the predetermined key operation, and cases where the operation on the operation panel 205 is not detected in S1402.

[0083] In S1403, the CPU 411 sends the data of the page screen to the request source based on the URL of the page screen to be transitioned to after successful authentication that has been passed, and ends the process shown in FIG. 14. At this time, the web browser 734 of the smartphone 500 that is the request source stops displaying the simple authentication screen 1000 being displayed, and will display the page screen of the transition destination newly sent from the printer 200.

[0084] In S1404, the CPU 411 determines whether a predetermined timeout has elapsed in the time measurement started in S1401. If the CPU 411 determines that the predetermined timeout has elapsed (Yes), it proceeds to the process of S1405, and if it determines otherwise (No), it proceeds to the process of S1406.

[0085] In S1405, the CPU 411 sends the data of the password authentication screen 1010 to the request source and ends the process shown in FIG. 14. At this time, the web browser 734 of the smartphone 500 that is the request source stops displaying the simple authentication screen 1000 being displayed, and will display the password authentication screen 1010 newly sent from the printer 200.

[0086] In S1406, the CPU 411 determines whether it has received a page request or an authentication request. Specifically, the CPU 411 determines whether it has received an authentication request for the password due to the OK button 1004 on the simple authentication screen 1000 being pressed, or a request for page transition due to the cancel button 1005 being pressed. If the CPU 411 determines that it has received a page request or an authentication request (Yes), it ends the process shown in FIG. 14. If it determines otherwise (No), it proceeds to the process of S1402. Here, when the cancel button 1005 is pressed, the web browser 734 of the smartphone 500 that is the request source cancels the display of the simple authentication screen 1000 and displays the main screen 810. Also, when the OK button 1004 is pressed and the passwords match, the web browser 734 of the smartphone 500 that is the request source cancels the display of the simple authentication screen 1000 and displays the requested page. Note that, as described in S1310 of FIG. 13, when the OK button 1004 is pressed and the passwords do not match, the web browser 734 may cancel the display of the simple authentication screen 1000 and display the main screen 810.

[0087] Note that, here, an example is shown in which a timeout period is set for accepting key operations on the simple authentication screen 1000, but timeout processing is not necessarily required. For example, when timeout processing is not performed in the key operation authentication process, the CPU 411 starts from the process of S1402. Then, if the CPU 411 determines No in S1402, it proceeds to the process of S1406. That is, the key operation authentication process continues to be executed unless the CPU 411 determines Yes in S1402 or does not determine Yes in S1406. By incorporating timeout processing, it is possible to prevent authentication from being established unintentionally due to a predetermined key operation being performed on the operation panel 205 while the key operation authentication process is being executed for a long time.

[0088] FIG. 15 is a sequence diagram showing an example of information exchange between the printer 200 and the smartphone 500 at the time of authentication. FIG. 15(a) is a sequence diagram when the user 110 inputs a password on the simple authentication screen 1000 and the printer 200 performs password authentication.

[0089] In S1500, the user 110 operates the smartphone 500 to perform a page transition operation of the remote UI. Here, it is assumed that in a situation where the authentication level given to the smartphone 500 is 0, the user 110 performs an operation of pressing the button 902 on the main screen 810.

[0090] In S1501, the smartphone 500 sends a page request to the printer 200 based on the user's operation in S1500. Here, it is assumed that the smartphone 500 sends a page request to the printer 200 that requests a transition to the printer operation setting screen 830.

[0091] In S1502, the printer 200 sends the data of the simple authentication screen 1000 to the smartphone 500 in order to give the authentication level required for the requested page transition. Here, it is assumed that the printer 200 determines that the required level set on the printer operation setting screen 830 indicated by the page request received from the smartphone 500 is 1. Then, it is assumed that the printer 200 sends the data of the simple authentication screen 1000 to give one or more authentication levels to the smartphone 500. After that, the smartphone 500 displays the received simple authentication screen 1000 on the web browser 734.

[0092] In S1503, the user 110 performs an input operation of the account name and password on the simple authentication screen 1000. And it is assumed that the user 110 presses the OK button 1004 on the simple authentication screen 1000.

[0093] In S1504, based on the user's pressing operation in S1503, the smartphone 500 sends the input account name and password, and the password authentication request, to the printer 200.

[0094] In S1505, the printer 200 performs password authentication based on the received account name and password. Assume that the printer 200 determines that the received password matches the pre-set password as a result of the authentication.

[0095] In S1506, the printer 200 sends the data of the page screen requested in S1501 to the smartphone 500. Here, since a page transition to the printer operation setting screen 830 is requested, the smartphone 500 displays the printer operation setting screen 830 on the web browser 734.

[0096] Figure 15(b) is a sequence diagram when the user performs authentication by key operation on the simple authentication screen 1000. Note that the sequence from S1510 to S1512 is the same as the sequence from S1500 to S1502 in Figure 15(a), so the description is omitted.

[0097] In S1513, the user 110 looks at the key operation display section 1003 of the simple authentication screen 1000 displayed on the web browser 734 and performs a key operation on the operation panel 205 of the printer 200.

[0098] In S1514, the printer 200 performs key operation authentication upon receiving the key operation in S1513. Here, assume that the printer 200 determines that the key operation performed on the operation panel 205 of the printer 200 matches the predetermined key operation.

[0099] In S1515, the printer 200 transmits the data of the page screen requested in S1511 to the smartphone 500. Here, since a page transition to the printer operation setting screen 830 is requested, the smartphone 500 displays the printer operation setting screen 830 on the web browser 734.

[0100] As described above, according to the present embodiment, when accessing a screen with a low security level such as the printer operation setting screen 830, the simple authentication screen 1000 that gives access permission by either key operation authentication or password authentication is displayed. As a result, by using the remote UI function, it is possible to access a restricted remote UI page by authentication with a key operation that is simpler than password authentication. Also, when accessing a screen with a high security level such as the network connection setting screen 840, the password authentication screen 1010 that requires password authentication is displayed. As a result, appropriate access control can be performed according to the security level set for each page screen in accordance with the page configuration of the remote UI.

[0101] <<Other Embodiments>> FIG. 16 is a diagram showing an example of a remote UI authentication screen displayed on the web browser 734 of the smartphone 500. With reference to FIG. 16, a feasible remote UI authentication screen different from the authentication screen described in the above embodiment will be described.

[0102] FIG. 16(a) is a diagram showing an authentication screen 1600 including a key operation display section 1601 and a cancel button 1602. Since the key operation display section 1601 and the cancel button 1602 have the same functions as the key operation display section 1003 and the cancel button 1005, respectively, the description thereof will be omitted. FIG. 16(a) is a screen transmitted from the printer 200, for example, when an access request is made to a screen for which a request level requiring authentication level 1 is set.

[0103] In the above-described embodiment, as shown in FIG. 10(a), the authentication screen is described by way of example as a screen including a region for inputting an account name and a password and a region in which the content of the key operation for permitting access is displayed. On the other hand, FIG. 16(a) does not include a region for inputting an account name and a password, unlike FIG. 10(a). Since the authentication screen is configured in this way, it is not possible to input the account name and password themselves, so it is possible to reduce the risk that authentication is accidentally successful due to random input operations by remote attackers and the set values are changed.

[0104] FIG. 16(b) is a diagram showing an authentication screen 1610 including an account name input unit 1611, a password input unit 1612, a key operation display unit 1613, an OK button 1614, and a cancel button 1615. Since the account name input unit 1611, the password input unit 1612, and the key operation display unit 1613 have the same functions as the account name input unit 1001, the password input unit 1002, and the key operation display unit 1003, respectively, the description thereof is omitted. Similarly, the description of the OK button 1614 and the cancel button 1615 is also omitted. FIG. 16(b) is a screen transmitted from the printer 200 when, for example, an access request is made to a screen for which a required level requiring authentication level 1 and authentication level 2 is set.

[0105] In the above-described embodiment, password authentication is described by way of example as authentication having a higher security strength than authentication by key operation. That is, when password authentication is performed, access including the case where authentication by key operation is performed is permitted. However, even when password authentication is performed, it may be configured to require authentication by key operation. That is, as shown in FIG. 16(b), it may be configured not to permit access unless both key operation authentication and password authentication are performed. In this case, even if one authentication is successful, access is not permitted unless the other authentication is successful. Since this corresponds to a configuration called so-called two-factor authentication, it is possible to provide access restriction with higher security strength.

[0106] Also, as an example in which, for two-factor authentication, a region for inputting an account name and a password for password authentication and a region in which the details of a key operation are displayed for key operation authentication are included on one screen, the simple authentication screen 1610 was described, but the present invention is not limited to this. For example, as shown in FIGS. 16(c) and 16(d), the screens for performing respective authentications may be displayed separately. FIG. 16(c) is a diagram showing an authentication screen 1620 that is displayed to perform key operation authentication. FIG. 16(d) is a diagram showing an authentication screen 1630 that is displayed to perform password authentication. When taking such a configuration, first, the authentication screen 1620 is displayed on the web browser 734. Thereafter, when a key operation is performed by the user, the authentication screen 1630 is displayed on the web browser 734. Then, when an account name and a password are input and the OK button 1633 is pressed, key operation authentication and password authentication are performed by the printer 200. Note that the authentication screen 1630 may be configured to be displayed when the user performs an operation that matches the key operation shown in the key operation display unit 1621. Also, regarding the order in which the authentication screens are displayed, the authentication screen 1630 may be displayed first, and then the authentication screen 1620 may be displayed.

[0107] The present disclosure can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or apparatus via a network or a storage medium, and causing one or more processors in a computer of the system or apparatus to read and execute the program. Further, it can also be realized by a circuit (for example, ASIC) that realizes one or more functions.

[0108] The disclosure of the present embodiment includes configurations typified by the following information processing apparatus examples, control method examples, and program examples.

[0109] <Configuration 1> An information processing apparatus capable of communicating with an external device, an operation unit provided on an outer surface of the information processing apparatus, capable of receiving an operation by a user, Receiving means for receiving a request for remote connection from the external device to the information processing device; First authentication means for performing first authentication to permit the request based on an operation on the operation unit when the request is received by the receiving means; An information processing apparatus, characterized by comprising the above.

[0110] <Configuration 2> The information processing apparatus according to Configuration 1, further comprising transmission means for transmitting, to the external device, a screen indicated by the request when the first authentication is successful by the first authentication means.

[0111] <Configuration 3> The information processing apparatus according to Configuration 2, further comprising second authentication means for performing second authentication to permit the request based on an authentication operation performed in the external device.

[0112] <Configuration 4> The information processing apparatus according to Configuration 3, wherein when the receiving means receives the request, the transmission means transmits, to the external device, an authentication screen on which information regarding the first authentication is displayed.

[0113] <Configuration 5> The information processing apparatus according to Configuration 4, wherein for each transmission of the authentication screen by the transmission means, the content of the operation on the operation unit is made different as the information regarding the first authentication displayed on the authentication screen.

[0114] <Configuration 6> When the screen indicated by the request received by the receiving means is a specific page for accessing the information processing apparatus, the transmission means transmits the specific page to the external device, A plurality of elements for accessing respective ones of a plurality of setting screens capable of changing settings of the information processing apparatus are displayed on the specific page, The information processing apparatus according to configuration 4 or 5, wherein any one of a plurality of request levels that require different authentication levels is set for each of the plurality of setting screens.

[0115] <Configuration 7> The plurality of request levels are a first request level that requires a first authentication level, a second request level that requires a second authentication level, a third request level that requires either the first authentication level or the second authentication level, and a fourth request level that requires both the first authentication level and the second authentication level The information processing apparatus according to configuration 6, characterized in that it is part or all of.

[0116] <Configuration 8> When the first authentication means succeeds in the first authentication, it sets the level of the permission for the external device to access the setting screen to the first authentication level and permits access to the setting screen. The information processing apparatus according to configuration 7, wherein when the second authentication means succeeds in the second authentication, it sets the level of the permission for the external device to access the setting screen to the first authentication level and permits access to the setting screen.

[0117] <Configuration 9> On the specific page, an element for accessing a display screen that displays the state of the information processing apparatus and cannot change the settings of the information processing apparatus is displayed. The information processing apparatus according to configuration 7 or 8, wherein a request level that does not require either the first authentication level or the second authentication level is set on the display screen.

[0118] <Configuration 10> The second authentication level is higher than the first authentication level. When the receiving means receives a request for a setting screen in which a request level for requesting the first authentication level is set from the external device whose permission level for accessing the setting screen is the second authentication level, the transmitting means transmits a setting screen in which a request level for requesting the first authentication level is set. The information processing apparatus according to any one of configurations 7 to 9.

[0119] <Configuration 11> The content of the authentication screen transmitted by the transmitting means is varied according to the combination of the request level set in the screen indicated by the request received by the receiving means and the authentication level of the permission for accessing the screen indicated by the request of the external device. The information processing apparatus according to any one of configurations 6 to 10.

[0120] <Configuration 12> When the transmitting means transmits the authentication screen, it further includes a measuring means for starting the measurement of time. When the time measured by the measuring means has elapsed a predetermined time, the first authentication means ends the first authentication. The information processing apparatus according to any one of configurations 4 to 11.

[0121] <Configuration 13> The information processing apparatus is a printer. The information processing apparatus according to any one of configurations 1 to 12.

[0122] <Configuration 14> A control method for an information processing apparatus capable of communicating with an external device, A receiving step of receiving a request for remote connection from the external device to the information processing apparatus, A first authentication step of performing a first authentication for permitting the request based on an operation on an operation unit provided on an outer surface of the information processing apparatus, which can receive an operation by a user, when the request is received. A control method for an information processing apparatus, comprising:

[0123] <Configuration 15> A program for causing a computer to execute the control method of the information processing apparatus according to Configuration 14.

Explanation of Signs

[0124] 200 Printer 500 Smartphone

Claims

1. An information processing apparatus capable of communicating with an external device, an operation unit provided on an outer surface of the information processing apparatus, capable of receiving an operation by a user, receiving means for receiving a request for remote connection from the external device to the information processing apparatus, first authentication means for performing a first authentication for permitting the request based on an operation on the operation unit when the request is received by the receiving means An information processing apparatus characterized by comprising the above.

2. The information processing apparatus according to claim 1, further comprising transmission means for transmitting, to the external device, a screen indicated by the request when the first authentication is successful by the first authentication means.

3. The information processing apparatus according to claim 2, further comprising second authentication means for performing a second authentication for permitting the request based on an authentication operation performed in the external device.

4. The information processing apparatus according to claim 3, wherein when the receiving means receives the request, the transmission means transmits, to the external device, an authentication screen on which information regarding the first authentication is displayed.

5. The information processing apparatus according to claim 4, wherein for each transmission of the authentication screen by the transmission means, the content of the operation on the operation unit is made different as the information regarding the first authentication displayed on the authentication screen.

6. When the screen indicated by the request received by the receiving means is a specific page for accessing the information processing apparatus, the transmission means transmits the specific page to the external device, and a plurality of elements for accessing each of a plurality of setting screens capable of changing the settings of the information processing apparatus are displayed on the specific page, The information processing apparatus according to claim 4, wherein any one of a plurality of request levels that require different authentication levels is set for each of the plurality of setting screens.

7. The plurality of request levels are a first request level that requires a first authentication level, a second request level that requires a second authentication level, a third request level that requires either the first authentication level or the second authentication level, and a fourth request level that requires both the first authentication level and the second authentication level The information processing apparatus according to claim 6, characterized in that it is part or all of.

8. When the first authentication means succeeds in the first authentication, it sets the level of the permission for the external device to access the setting screen to the first authentication level and permits access to the setting screen. The information processing apparatus according to claim 7, characterized in that when the second authentication means succeeds in the second authentication, it sets the level of the permission for the external device to access the setting screen to the first authentication level and permits access to the setting screen.

9. On the specific page, an element for accessing a display screen that displays the state of the information processing apparatus, where the settings of the information processing apparatus cannot be changed, is displayed. The information processing apparatus according to claim 7, characterized in that a request level that does not require either the first authentication level or the second authentication level is set on the display screen.

10. The second authentication level is higher than the first authentication level. When the receiving means receives a request for a setting screen in which a request level for requesting the first authentication level is set from the external device whose permission level for accessing the setting screen is the second authentication level, the transmitting means transmits the setting screen in which the request level for requesting the first authentication level is set. The information processing apparatus according to claim 7, characterized in that.

11. The information processing apparatus according to claim 6, characterized in that the content of the authentication screen transmitted by the transmitting means is varied according to a combination of the request level set in the screen indicated by the request received by the receiving means and the authentication level of the permission for accessing the screen indicated by the request of the external device.

12. When the transmitting means transmits the authentication screen, it further comprises a measuring means for starting the measurement of time, The information processing apparatus according to claim 4, characterized in that when the time measured by the measuring means has elapsed a predetermined time, the first authentication means ends the first authentication.

13. The information processing apparatus according to any one of claims 1 to 12, characterized in that the information processing apparatus is a printer.

14. A control method for an information processing apparatus capable of communicating with an external device, A receiving step of receiving a request for remote connection from the external device to the information processing apparatus, A first authentication step of performing a first authentication for permitting the request based on an operation on an operation unit provided on an outer surface of the information processing apparatus, which can receive an operation by a user, when the request is received An information processing apparatus control method, characterized by comprising:

15. A program for causing a computer to execute the control method of the information processing apparatus according to claim 14.

Citation Information

Patent Citations

  • Information processing device and control method therefor, communication device, and program

    JP2020166736A