Authentication method, information processing device and program

The authentication method addresses the challenge of managing software usage rights by registering apparatus information and identification information in a server, allowing for secure and authorized execution of software functions.

JP2025095153APending Publication Date: 2025-06-26SEIKO EPSON CORP
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2023210967
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing authentication methods for software execution, such as those using dongles, can lead to issues where specific functions cannot be used unless the dongle is connected, resulting in inadequate management of software usage rights.

Method used

An authentication method that involves an information processing apparatus acquiring apparatus information from an external device, registering this information along with identification information in a server, and then using this registration to authenticate and permit the execution of software.

Benefits of technology

This solution effectively manages software usage rights by ensuring that only authorized devices can execute software functions, even when the external device is not connected, thereby preventing inappropriate use.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025095153000001_ABST
    Figure 2025095153000001_ABST
Patent Text Reader

Abstract

To allow a user to properly manage a use authority of software related to any device and suppress loss of the convenience of the user.SOLUTION: An authentication system 1 acquires device information including at least unique information as information unique to an external device 2. The authentication system 1 performs processing for registering at least identification information in association with the device information in a server 4. The server 4 thereby registers the identification information corresponding to an information processing device 10 in association with the device information. When software 2a is used by the information processing device 10, the authentication system 1 performs processing for permitting execution of the software 2a on the basis of authentication performed using the identification information and the device information registered in the server 4.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an authentication method, an information processing apparatus, and a program.

Background Art

[0002] Patent Document 1 discloses an image forming apparatus that operates in an operation mode according to an assigned license. Patent Document 1 discloses that a dongle that functions as a license key is connected to the image forming apparatus. Further, Patent Document 1 discloses that the dongle can be connected to the image forming apparatus via an interface such as USB (Universal Serial Bus).

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] In the technology according to Patent Document 1, there is a possibility that a specific function related to the image forming apparatus cannot be used unless the dongle is connected to the image forming apparatus. Therefore, in the technology according to Patent Document 1, there is a possibility that the usage right of software associated with some apparatus cannot be appropriately managed.

Means for Solving the Problems

[0005] The authentication method according to the present disclosure is an authentication method for authenticating the execution of software by an information processing apparatus. The software is associated with a predetermined external apparatus physically separate from the information processing apparatus, has a first function executable using at least the external apparatus, acquires apparatus information regarding the external apparatus, the apparatus information including at least information unique to the external apparatus, and performs a process for registering the apparatus information and at least identification information corresponding to the information processing apparatus in association with each other in a server. When the software is used by the information processing apparatus, a process for permitting the execution of the software is performed based on authentication performed using the identification information and the apparatus information registered in the server.

[0006] Further, the information processing apparatus according to the present disclosure includes at least a storage unit that stores software associated with a predetermined external apparatus physically separate from the information processing apparatus and having a first function executable using at least the external apparatus, a processing unit that executes at least the software, an apparatus information acquisition unit that acquires apparatus information regarding the external apparatus, the apparatus information including at least information unique to the external apparatus, a registration processing unit that performs a process for registering the apparatus information and at least identification information corresponding to the information processing apparatus in association with each other in a server, and a permission processing unit that performs a process for permitting the execution of the software based on authentication performed using the identification information and the apparatus information registered in the server when the software is used by the information processing apparatus.

[0007] Also, the program according to the present disclosure is software associated with a predetermined external device physically separate from the information processing device, and includes at least a function of executing at least software having a first function executable using the external device, a function of acquiring device information regarding the external device, the device information including at least information unique to the external device, and a function of performing a process for registering at least the identification information corresponding to the information processing device and the acquired device information in association with each other in a server, and a function of performing a process for permitting execution of the software based on authentication performed using the identification information and the device information registered in the server when the software is used by the information processing device. These functions are realized by a computer.

Brief Description of Drawings

[0008]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Figure 10

Figure 11

Figure 12

Mode for Carrying Out the Invention

[0009] (Outline of this Embodiment) Prior to the description of this embodiment, the outline of this embodiment will be described. FIG. 1 is a diagram showing the outline of the authentication system 1 according to this embodiment.

[0010] The authentication system 1 according to this embodiment includes an external device 2, a server 4, and an information processing device 10. The information processing device 10 can be communicably connected to the external device 2 and the server 4 via wire or wirelessly. The information processing device 10 is, for example, a computer. The information processing device 10 can be an information processing terminal owned by a user. Here, the information processing device 10 has identification information corresponding to the information processing device 10. The identification information may be information for identifying the information processing device 10 or information for identifying the user of the information processing device 10. The identification information is, for example, account information, but is not limited thereto.

[0011] The external device 2 is a predetermined device physically separate from the information processing device 10. The external device 2 may be, for example, a colorimeter or an image forming device such as a printer, but is not limited thereto. The external device 2 can be used while being connected to the information processing device 10. Also, the external device 2 may be used while not being connected to the information processing device 10. Here, software 2a associated with the external device 2 is introduced into the information processing device 10. Specifically, the software 2a is installed in the information processing device 10. The software 2a has at least a first function executable using the external device 2. The first function may include, for example, a function for controlling the external device 2. Also, different from the first function, the software 2a may have a second function executable without using the external device 2. Further, the external device 2 has unique information that is information unique to the external device 2. The unique information is, for example, the serial number of the external device 2, but is not limited thereto.

[0012] The server 4 is, for example, a computer. The server 4 may be realized by, for example, cloud computing. The server 4 may be realized by a plurality of computers. The server 4 is configured to register the external device 2 corresponding to the software 2a executed in the information processing device 10.

[0013] FIG. 2 is a flowchart showing an outline of the processing executed by the authentication system 1 according to the present embodiment. The flowchart shown in FIG. 2 shows the authentication method executed by the authentication system 1 according to the present embodiment. The authentication system 1 acquires device information regarding the external device 2 (step S12). Specifically, the information processing device 10 of the authentication system 1 acquires device information including at least unique information that is information unique to the external device 2. More specifically, the information processing device 10 may receive the device information from the external device 2 when the external device 2 is communicably connected to the information processing device 10. Note that the subject of the process of S12 may not be the information processing device 10.

[0014] The authentication system 1 performs a process (step S14) to ensure that at least the identification information and the device information are associated and registered in the server 4. Specifically, the information processing device 10 performs a process for registering the identification information corresponding to the information processing device 10 and the device information acquired in the process of S12 in the server 4 in an associated manner. More specifically, the information processing device 10 associates the identification information corresponding to the information processing device 10 and the device information and transmits them to the server 4. As a result, the server 4 registers the identification information corresponding to the information processing device 10 and the device information in an associated manner. In other words, the server 4 stores the identification information corresponding to the information processing device 10 and the device information in an associated manner.

[0015] When the software 2a is used by the information processing device 10 (YES in step S16), the authentication system 1 performs a process (step S18) to permit the execution of the software 2a. Specifically, when the software 2a is used by the information processing device 10, the information processing device 10 performs a process to make the software 2a executable. In response to that process, the authentication system 1 performs a process to permit the execution of the software 2a based on the authentication performed using the identification information and the device information registered in the server 4.

[0016] For example, the information processing device 10 may perform authentication using the identification information and the device information registered in the server 4, and permit the execution of the software 2a when the authentication is affirmed. As a result, the software 2a becomes executable on the information processing device 10. Also, for example, the server 4 may perform authentication using the identification information and the device information registered in the server 4, and transmit authentication information indicating that the execution of the software 2a is permitted to the information processing device 10 when the authentication is affirmed. As a result, the information processing device 10 permits the execution of the software 2a, and the software 2a becomes executable on the information processing device 10.

[0017] Suppose that a third party without the right to use the external device 2 installs the software 2a on their own terminal without permission. In this case, if the third party's terminal is connected to the external device 2 and the first function of the software 2a is executed, there is a risk that the external device 2 will be used inappropriately. Also, if the external device 2 is not near the information processing device 10 of a user who has the right to use the external device 2, the information processing device 10 may not be able to use the second function of the software 2a. Therefore, in the above cases, there is a risk that the usage rights of the software 2a associated with the external device 2 cannot be properly managed.

[0018] On the other hand, the authentication system 1 according to the present embodiment can appropriately manage the usage rights of the software 2a associated with the external device 2 with the above configuration. That is, the authentication system 1 can suppress a third party's terminal without the right to use the external device 2 from executing the software 2a. Also, even when the information processing device 10 that has the right to use the external device 2 is not connected to the external device 2, the information processing device 10 can execute the second function.

[0019] Note that the authentication method executed by the authentication system 1 according to the present embodiment can also appropriately manage the usage rights of the software 2a associated with the external device 2. Also, the program that realizes the authentication method can also appropriately manage the usage rights of the software 2a associated with the external device 2. Note that this program can be installed on the information processing device 10. And this program causes the information processing device 10, which is a computer, to realize the function of executing the software 2a, the function of executing the process of S12, the function of executing the process of S14, and the function of executing the process of S18.

[0020] (Embodiment 1) Next, Embodiment 1 will be described with reference to the drawings. For clarity of explanation, the following description and drawings are appropriately omitted and simplified. Also, in each drawing, the same elements are denoted by the same reference numerals, and redundant explanations are omitted as necessary. In Embodiment 1, an example in which the above-described external device 2 is a colorimeter will be described. However, the features in Embodiment 1 can be applied even when the external device 2 is other than a colorimeter. This also applies to Embodiment 2 described later.

[0021] FIG. 3 is a diagram showing an authentication system 20 according to Embodiment 1. The authentication system 20 according to Embodiment 1 includes a colorimeter 30, a server 200, and one or more information processing devices 100. The information processing device 100 corresponds to the information processing device 10 shown in FIG. 1. The information processing device 100 can be communicably connected to the colorimeter 30 and the server 200 via wire or wirelessly.

[0022] The colorimeter 30 corresponds to a specific example of the external device 2 shown in FIG. 1. In Embodiment 1, the colorimeter 30 has both an optical device having a color measurement function of measuring a color value by spectroscopy and a moving device for moving the optical device on a color chart. However, the colorimeter 30 may have only one of the optical device and the moving device. The colorimeter 30 has unique information that is information unique to each colorimeter 30. The unique information is, for example, the serial number of the colorimeter 30, but is not limited thereto. Also, the serial number may be set in association with the model name of the colorimeter 30. That is, the serial number may be set so that the model of the colorimeter 30 can be determined from the serial number.

[0023] The information processing device 100 corresponds to the information processing device 10 shown in FIG. 1. The information processing device 100 is, for example, a computer. The information processing device 100 can be an information processing terminal owned by a user who has the right to use the colorimeter 30. The information processing device 100 has identification information corresponding to the information processing device 100. The identification information may be information for identifying the information processing device 100 or information for identifying the user of the information processing device 100. The identification information is, for example, account information, but is not limited thereto. Also, software 30a associated with the colorimeter 30 is installed in the information processing device 100. The software 30a corresponds to the software 2a shown in FIG. 1. The software 30a has at least a first function executable using the colorimeter 30 and a second function executable without using the colorimeter 30. That is, the software 30a has a function that requires the use of the colorimeter 30 and a function that can be executed without using the colorimeter 30.

[0024] Also, the information processing device 100 has identification information corresponding to the information processing device 100. The identification information may be information for identifying the information processing device 100 or information for identifying the user of the information processing device 100. The identification information is, for example, account information. Here, an organization to which a plurality of users belong may own one colorimeter 30. In this case, the colorimeter 30 can be used by each of the plurality of users belonging to the organization. And, in this case, the authentication system 20 can have a plurality of information processing devices 100 in which the same software 30a is installed. That is, a plurality of users can each own an information processing device 100 in which the software 30a is installed. In this case, account information may be defined for each organization. In this case, the organization to which the corresponding user belongs can be distinguished by the account information.

[0025] Server 200 corresponds to server 4 shown in FIG. 1. Server 200 is, for example, a computer. Server 200 may be realized by, for example, cloud computing. Server 200 may be realized by a plurality of computers. Server 200 is configured to register colorimeter 30 corresponding to software 30a executed in information processing apparatus 100. And server 200 is configured to manage the usage rights of software 30a executed in information processing apparatus 100. Here, server 200 may register colorimeter 30 and manage the usage rights of software 30a for each organization that owns colorimeter 30. In this case, server 200 can determine the organization to which the owner of information processing apparatus 100 corresponding to the account information belongs based on the account information. Also, server 200 may be a server that provides Internet services such as a web server.

[0026] FIG. 4 is a diagram showing the configuration of information processing apparatus 100 according to Embodiment 1. Information processing apparatus 100 according to Embodiment 1 includes, as main hardware components, a processing unit 102, a storage unit 104, a communication unit 106, and an interface unit 108 (IF: Interface). The processing unit 102, the storage unit 104, the communication unit 106, and the interface unit 108 may be interconnected via a data bus or the like.

[0027] The processing unit 102 is a processor such as a CPU (Central Processing Unit), for example. The processing unit 102 may have a plurality of processors. The processing unit 102 functions as an arithmetic unit that performs control processing, arithmetic processing, and the like. The processing unit 102 controls the storage unit 104, the communication unit 106, and the interface unit 108. Also, the processing unit 102 executes at least software 30a.

[0028] The storage unit 104 is a storage device such as a memory or a hard disk. The storage unit 104 is, for example, a ROM (Read Only Memory) or a RAM (Random Access Memory). The storage unit 104 may have a plurality of memories. The storage unit 104 has a function of storing control programs, arithmetic programs, etc. executed by the processing unit 102. Also, the storage unit 104 has a function of temporarily storing processing data, etc. The storage unit 104 may include a database. The storage unit 104 stores the software 30a installed in the information processing apparatus 100.

[0029] The communication unit 106 performs processes necessary for the information processing apparatus 100 to communicate with other devices via a network. The communication unit 106 may include a communication port, a router, a firewall, etc. The communication unit 106 performs processes for the information processing apparatus 100 to communicate with the colorimeter 30. The communication unit 106 performs processes for the information processing apparatus 100 to communicate with the server 200 via the Internet.

[0030] The interface unit 108 is, for example, a user interface. The interface unit 108 has an input device such as a keyboard, a touch panel, or a mouse, and an output device such as a display or a speaker. The interface unit 108 may be configured such that the input device and the output device are integrated, such as a touch screen or a touch panel. The interface unit 108 receives an operation of inputting data by a user of the information processing apparatus 100 and outputs information to the user.

[0031] Also, the information processing apparatus 100 according to Embodiment 1 includes, as components, a software processing unit 110, a device information acquisition unit 130, an encrypted information generation unit 140, a registration processing unit 150, and a permission processing unit 160. Further, the software processing unit 110 includes, as components, a software storage unit 112, an encryption method storage unit 114, a model information storage unit 116, a first function execution processing unit 122, and a second function execution processing unit 124.

[0032] In addition, each of the above-described components can be realized, for example, by causing a program to be executed under the control of the processing unit 102. More specifically, each component can be realized by the processing unit 102 executing a program stored in the storage unit 104. Further, necessary programs may be recorded on an arbitrary non-volatile recording medium and installed as needed to realize each component. The above also applies to other embodiments.

[0033] In addition, each component is not limited to being realized by software according to a program, and may be realized by any combination of hardware, firmware, and software, etc. Further, each component may be realized using a user-programmable integrated circuit such as an FPGA (field-programmable gate array) or a microcomputer. In this case, a program composed of the above-described components may be realized using this integrated circuit. The above also applies to other embodiments.

[0034] The software processing unit 110 performs processing related to the software 30a. For example, the software processing unit 110 performs processing for executing the software 30a. Further, for example, the software processing unit 110 performs processing for controlling the colorimeter 30 using the software 30a. The software storage unit 112 can be realized by the storage unit 104. The software storage unit 112 stores the installed software 30a.

[0035] The encryption method storage unit 114 can be realized by the storage unit 104. The encryption method storage unit 114 stores an encryption method corresponding to the software 30a. The encryption method is, for example, a hash function, but is not limited thereto. The encryption method is an encryption method based on the software 30a. That is, the encryption method such as a hash function can be uniquely set for each software 30a. Therefore, if the installed software 30a is the same, the encryption method stored in the encryption method storage unit 114 can also be the same. On the other hand, if the installed software 30a is different, the encryption method stored in the encryption method storage unit 114 can also be different. Note that the encryption method such as a hash function is used in the process of the encryption information generation unit 140 described later.

[0036] The model information storage unit 116 can be realized by the storage unit 104. The model information storage unit 116 stores model information that is information indicating the model of the colorimeter 30 corresponding to the software 30a. Here, the model information may be associated with the serial number of the colorimeter 30. For example, when the model information indicates "XXX", the serial numbers of the colorimeters 30 of that model may be "XXX001", "XXX002",... and so on. That is, the serial number may be set to include the character string indicated by the model information of the colorimeter 30. In this case, the corresponding model of the software 30a corresponding to the colorimeter 30 can be determined from the serial number of the colorimeter 30. Further, the model information storage unit 116 may store, as model information, a model information table that is a table associating the model of the colorimeter 30 corresponding to the software 30a with a list of the serial numbers of the colorimeters 30 of that model.

[0037] The first function execution processing unit 122 performs processing for executing the first function. Specifically, when the execution of the software 30a is permitted by a permission processing unit 160 described later, the first function execution processing unit 122 performs processing for executing the first function in a state where the colorimeter 30 is communicably connected to the information processing apparatus 100. For example, the first function execution processing unit 122 may perform processing for controlling the colorimeter 30. Also, for example, the first function execution processing unit 122 may perform color adjustment processing using the colorimeter 30. For example, the first function execution processing unit 122 may transmit a control signal to the colorimeter 30 and receive a color measurement value from the colorimeter 30.

[0038] The second function execution processing unit 124 performs processing for executing the second function. Specifically, when the execution of the software 30a is permitted by a permission processing unit 160 described later, the second function execution processing unit 124 performs processing for executing the second function. Here, the second function execution processing unit 124 can perform processing for executing the second function even in a state where the colorimeter 30 is not communicably connected to the information processing apparatus 100. For example, the second function execution processing unit 124 may perform color adjustment processing that can be executed without using the colorimeter 30. Also, for example, the second function execution processing unit 124 may perform layout adjustment processing that can be executed without using the colorimeter 30. Also, for example, the second function execution processing unit 124 may perform print job execution processing that can be executed without using the colorimeter 30. The print job execution processing includes processing for transmitting a print job from the information processing apparatus 100 to a printer (not shown) and processing for editing an image to be printed before transmitting the print job.

[0039] The device information acquisition unit 130 performs a process corresponding to S12 in FIG. 2. The device information acquisition unit 130 acquires device information regarding the colorimeter 30 which is an external device 2. The device information includes at least the unique information regarding the colorimeter 30. For example, as described above, the unique information is the serial number of the colorimeter 30. Further, the device information may include usage status information indicating the usage status of the colorimeter 30 which is an external device 2. For example, the usage status information may include maintenance information used for the maintenance of the colorimeter 30. Also, for example, the usage status information may include history information such as the operation history or usage history of the colorimeter 30. Also, for example, the usage status information may include the log information of the colorimeter 30. More specifically, the usage status information is, for example, the number of times the colorimeter 30 has performed color measurement, the number of color charts the colorimeter has measured, and further information regarding the consumption status of the battery, light source, etc.

[0040] The device information acquisition unit 130 may acquire the device information by extracting or receiving the device information from the colorimeter 30 in a state where the colorimeter 30 is communicably connected to the information processing apparatus 100. Alternatively, the device information acquisition unit 130 may acquire the device information input by the user operating the interface unit 108. For example, when the user inputs the serial number of the colorimeter 30 using the interface unit 108, the device information acquisition unit 130 may acquire the serial number which is the unique information.

[0041] The encryption information generation unit 140 generates encryption information using the encryption method stored in the encryption method storage unit 114. Specifically, the encryption information generation unit 140 encrypts the unique information using the encryption method corresponding to the software 30a to generate encryption information which is information in which the unique information is encrypted. More specifically, the encryption information generation unit 140 generates encryption information by encrypting the serial number of the colorimeter 30 using the hash function corresponding to the software 30a. Note that when the serial number is encrypted using the hash function, the obtained encryption information is a hash value.

[0042] The registration processing unit 150 performs the process corresponding to S14 in FIG. 2. The registration processing unit 150 performs at least a process for registering the identification information corresponding to the information processing apparatus 100 and the apparatus information regarding the colorimeter 30 in the server 200 in a mutually associated manner. Further, the registration processing unit 150 may perform a process for registering the identification information, the apparatus information, and the encryption information in the server 200 in an associated manner. Specifically, the registration processing unit 150 transmits registration request information in which the identification information, the apparatus information, and the encryption information are associated to the server 200. As will be described later, the server 200 registers the identification information, the apparatus information, and the encryption information in an associated manner by receiving the registration request information. At this time, the server 200 stores the registration information in which the identification information, the apparatus information, and the encryption information are associated.

[0043] More specifically, when the server 200 is a server having a function of providing a service via the Internet, such as a web server, the registration processing unit 150 performs a process for logging in to the service via the Internet. The registration processing unit 150 transmits identification information such as account information to the server 200 by logging in to the service provided by the server 200. Further, the registration processing unit 150 transmits the above-described registration request information by uploading the apparatus information and the encryption information to the server 200 while logged in to the above-described service.

[0044] The permission processing unit 160 performs the process corresponding to S18 in FIG. 2. That is, when the software 30a is used by the information processing apparatus 100, the permission processing unit 160 performs a process for permitting the execution of the software 30a based on the authentication performed using the identification information and the device information registered in the server 200. At this time, the permission processing unit 160 may also perform a process for permitting the execution of the software 30a based on the authentication performed using the identification information, the device information, and the encrypted information registered in the server 200. In other words, when the software 30a is used by the information processing apparatus 100, the permission processing unit 160 makes a request to the server 200 to enable the execution of the software 30a. In the first embodiment, the permission processing unit 160 of the information processing apparatus 100 performs the above-described authentication process.

[0045] Specifically, when the software 30a is activated, the permission processing unit 160 performs a process for logging in to the service provided by the server 200 described above. As a result, the permission processing unit 160 transmits identification information such as account information to the server 200. Further, the permission processing unit 160 transmits a registration information request command, which is a command for requesting the server 200 to transmit registration information, to the server 200. In response to this, the registration information corresponding to the identification information is transmitted from the server 200. Then, the permission processing unit 160 receives the registration information corresponding to the identification information from the server 200. That is, the permission processing unit 160 downloads the registration information corresponding to the identification information from the server 200. As described above, the registration information includes device information including unique information such as a serial number and encrypted information such as a hash value.

[0046] The permission processing unit 160 performs an authentication process for determining whether the information processing apparatus 100 has the right to use the software 30a by using the device information and the encrypted information. The permission processing unit 160 determines whether both the first authentication and the second authentication as described below are affirmed.

[0047] As the first authentication, the permission processing unit 160 performs authentication using unique information. Specifically, the permission processing unit 160 determines whether the unique information included in the registration information corresponds to the model information regarding the software 30a to be used. When the unique information included in the registration information corresponds to the model information regarding the software 30a to be used, the permission processing unit 160 determines that the first authentication is affirmed. Specifically, the permission processing unit 160 refers to the model information stored in the model information storage unit 116 and determines whether the unique information included in the registration information corresponds to the model information regarding the software 30a to be used. For example, the permission processing unit 160 determines whether the serial number included in the registration information corresponds to the model information regarding the software 30a to be used. When the serial number included in the registration information corresponds to the model information regarding the software 30a to be used, the permission processing unit 160 determines that the first authentication is affirmed. Specifically, the permission processing unit 160 refers to the model information stored in the model information storage unit 116 and determines whether the serial number included in the registration information corresponds to the model information regarding the software 30a to be used.

[0048] For example, when the serial number included in the registration information contains the model information regarding the software 30a to be used, the permission processing unit 160 may determine that the serial number included in the registration information corresponds to the model information regarding the software 30a to be used. For example, when the serial number included in the registration information is "XXX001" and the model information regarding the software 30a to be used indicates "XXX", the permission processing unit 160 may determine that the first authentication is affirmed. On the other hand, for example, when the serial number included in the registration information does not contain the model information regarding the software 30a to be used, the permission processing unit 160 may determine that the serial number included in the registration information does not correspond to the model information regarding the software 30a to be used. For example, when the serial number included in the registration information is "XXX001" and the model information regarding the software 30a to be used indicates "YYY", the permission processing unit 160 may determine that the first authentication is denied.

[0049] Also, for example, when the serial number included in the registration information is included in the list shown in the model information table, the permission processing unit 160 may determine that the serial number included in the registration information corresponds to the model information regarding the software 30a to be used. On the other hand, when the serial number included in the registration information is not included in the list shown in the model information table, the permission processing unit 160 may determine that the serial number included in the registration information does not correspond to the model information regarding the software 30a to be used.

[0050] As the second authentication, the permission processing unit 160 performs authentication using the encrypted information. Specifically, the permission processing unit 160 determines whether the encrypted information included in the registration information is information obtained by encrypting the unique information by the encryption method corresponding to the software 30a to be used. Specifically, the permission processing unit 160 encrypts the unique information included in the registration information using the encryption method included in the encryption method storage unit 114, and determines whether the obtained encrypted information matches the encrypted information included in the registration information. For example, the permission processing unit 160 encrypts the serial number included in the registration information using the hash function included in the encryption method storage unit 114, and determines whether the obtained hash value matches the hash value included in the registration information. When the two pieces of encrypted information match, the permission processing unit 160 determines that the second authentication is affirmed.

[0051] When both the first authentication and the second authentication are affirmed, the permission processing unit 160 permits the execution of the software 30a. As a result, the first function execution processing unit 122 can execute the first function. Similarly, the second function execution processing unit 124 can execute the second function. On the other hand, when either the first authentication or the second authentication is negated, the permission processing unit 160 prohibits the execution of the software 30a. In this case, the permission processing unit 160 disables the first function execution processing unit 122 and disables the second function execution processing unit 124.

[0052] Furthermore, the permission processing unit 160 may receive the registration information with the notification information added thereto from the server 200. The notification information is generated by the server 200 based on the usage information. The notification information is information to be notified to the user according to the usage status of the colorimeter 30. The notification information may be, for example, maintenance information. The maintenance information may indicate the degree of wear of the parts of the colorimeter 30 or the replacement time of the consumables of the colorimeter 30. Also, when the above authentication is affirmed, the permission processing unit 160 may perform processing to present the notification information to the user.

[0053] FIG. 5 is a diagram showing the configuration of the server 200 according to Embodiment 1. The server 200 according to Embodiment 1 includes, as its main hardware configuration, a processing unit 202, a storage unit 204, a communication unit 206, and an interface unit 208 (IF). The processing unit 202, the storage unit 204, the communication unit 206, and the interface unit 208 may be interconnected via a data bus or the like.

[0054] The processing unit 202 is a processor such as a CPU, for example. The processing unit 202 may have a plurality of processors. The processing unit 202 functions as an arithmetic unit that performs control processing, arithmetic processing, and the like. The processing unit 202 controls the storage unit 204, the communication unit 206, and the interface unit 208.

[0055] The storage unit 204 is a storage device such as a memory or a hard disk, for example. The storage unit 204 is, for example, a ROM or a RAM. The storage unit 204 may have a plurality of memories. The storage unit 204 has a function for storing control programs, arithmetic programs, and the like executed by the processing unit 202. Also, the storage unit 204 has a function for temporarily storing processing data and the like. The storage unit 204 may include a database.

[0056] The communication unit 206 performs the processing necessary for the server 200 to communicate with other devices via a network. The communication unit 206 may include a communication port, a router, a firewall, and the like. The communication unit 206 performs the processing for the server 200 to communicate with the information processing device 100.

[0057] The interface unit 208 is, for example, a user interface. The interface unit 208 has an input device such as a keyboard, a touch panel, or a mouse, and an output device such as a display or a speaker. The interface unit 208 may be configured such that the input device and the output device are integrated, such as a touch screen or a touch panel. The interface unit 208 receives an operation of inputting data by a user such as an operator or a worker, and outputs information to the user.

[0058] Also, the server 200 according to Embodiment 1 includes, as components, a service providing processing unit 210, a registration processing unit 220, a registration information storage unit 222, a usage management unit 230, a notification generation unit 232, and a registration information transmission unit 240. Each of the above-described components can be realized, for example, by executing a program under the control of the processing unit 202. More specifically, each component can be realized by the processing unit 202 executing a program stored in the storage unit 204. Further, by recording a necessary program on an arbitrary non-volatile recording medium and installing it as needed, each component may be realized. The same applies to other embodiments.

[0059] Also, each component is not limited to being realized by software by a program, and may be realized by any combination of hardware, firmware, and software. Further, each component may be realized using a user-programmable integrated circuit such as an FPGA or a microcomputer. In this case, a program composed of the above-described components may be realized using this integrated circuit. The same applies to other embodiments.

[0060] The service providing processing unit 210 performs processing for providing services via the Internet. Specifically, the service providing processing unit 210 performs processing for the information processing apparatus 100 to log in to a service via the Internet. Also, the service providing processing unit 210 performs processing for providing a service to the information processing apparatus 100 via the Internet. For example, the service providing processing unit 210 may perform processing for providing a service by a website to a web browser executed on the information processing apparatus 100.

[0061] The registration processing unit 220 performs processing for registering the colorimeter 30 (external device 2) corresponding to the identification information regarding the information processing apparatus 100. Specifically, when registration request information is received from the information processing apparatus 100, the registration processing unit 220 uses the registration request information to register by associating the identification information, device information, and encrypted information. Then, the registration processing unit 220 generates registration information in which the identification information, device information, and encrypted information are associated.

[0062] Also, in a state where the information processing apparatus 100 has logged in to the service provided by the service providing processing unit 210, the registration processing unit 220 may receive registration request information from the information processing apparatus 100. In this case, the registration processing unit 220 generates registration information by associating the account information acquired at the time of login with the device information and encrypted information included in the registration request information.

[0063] The registration information storage unit 222 can be realized by the storage unit 204. The registration information storage unit 222 stores the registration information. Here, the registration information storage unit 222 may store the registration information for each identification information. That is, the registration information storage unit 222 may store the registration information for each individual account. In this case, the colorimeter 30 having unique information regarding the registration information is regarded as being owned by the user having the identification information regarding the registration information. In this case, the information processing apparatus 100 of that user may be able to execute the software 30a corresponding to the colorimeter 30.

[0064] Further, the registration information storage unit 222 may store registration information for each organization. That is, the registration information storage unit 222 may store registration information for each organization account. In this case, the colorimeter 30 having unique information regarding the registration information is regarded as being owned by the organization in the registration information. In this case, the information processing apparatuses 100 of one or more users belonging to the organization may be able to execute the software 30a corresponding to the colorimeter 30.

[0065] Also, assume that registration request information is received from an information processing apparatus 100 of a user or organization different from the user or organization related to the registration information for the same colorimeter 30 corresponding to the stored registration information. In this case, the registration processing unit 220 may perform an overwrite process of changing the registration information stored in the registration information storage unit 222. Details will be described later.

[0066] The usage management unit 230 manages the usage status of the colorimeter 30 which is an external device 2. Specifically, the usage management unit 230 manages the usage status of the colorimeter 30 related to the registration information generated by the registration processing unit 220 using the usage status information included in the device information included in the registration request information. For example, the usage management unit 230 may manage the operation history or usage history of the colorimeter 30. Also, for example, the usage management unit 230 may manage the maintenance timing of the colorimeter 30. Also, for example, the usage management unit 230 may manage information for maintaining the colorimeter 30.

[0067] The notification generation unit 232 generates notification information regarding the colorimeter 30 which is the external device 2. Specifically, the notification generation unit 232 generates notification information indicating information to be notified to the user about the colorimeter 30 as described above according to the process by the usage management unit 230. The generated notification information may be added to the registration information registered for the corresponding colorimeter 30 and stored in the registration information storage unit 222.

[0068] The registration information transmission unit 240 transmits the registration information associated with the identification information corresponding to the information processing apparatus 100 to the information processing apparatus 100 in response to a request from the information processing apparatus 100. Specifically, in a state where the information processing apparatus 100 has logged in to the service provided by the service providing processing unit 210, the registration information transmission unit 240 receives a registration information request command from the information processing apparatus 100. In this case, the registration information transmission unit 240 transmits the registration information corresponding to the identification information of the account information acquired at the time of login to the information processing apparatus 100. Further, when transmitting the registration information, the registration information transmission unit 240 may transmit the registration information including the notification information regarding the colorimeter 30 corresponding to the registration information to the information processing apparatus 100.

[0069] FIG. 6 and FIG. 7 are diagrams illustrating a state in which registration information is stored in the registration information storage unit 222 according to the first embodiment. In the examples of FIGS. 6 and 7, the registration information storage unit 222 has an area for storing registration information for each organization. And in the registration information storage unit 222, an organization and the identification information regarding the users belonging to the organization are associated with each other. In the examples of FIGS. 6 and 7, an area for storing registration information is provided for each of organization A and organization B. And in organization A, users regarding identification information A1, users regarding identification information A2, and users regarding identification information A3 belong. Also, in organization B, users regarding identification information B1, users regarding identification information B2, and users regarding identification information B3 belong. And in the registration information storage unit 222, organization A and the identification information regarding the users belonging to organization A are associated with each other. Similarly, in the registration information storage unit 222, organization B and the identification information regarding the users belonging to organization B are associated with each other.

[0070] Also, in the example of FIG. 6, Organization A owns the colorimeter 30, which is an external device 2 related to Device X. And in the area related to Organization A, the registration information RgXa related to Device X is stored. In this case, the users belonging to Organization A, that is, the users related to identification information A1, the users related to identification information A2, and the users related to identification information A3 can use Device X and the software 30a related to Device X. On the other hand, the users belonging to Organization B, that is, the users related to identification information B1, the users related to identification information B2, and the users related to identification information B3 cannot use Device X and the software 30a related to Device X.

[0071] The registration information RgXa includes the unique information Xs related to Device X, the encrypted information Xc related to Device X, the usage status information Xu related to Device X, and the notification information Xn related to Device X. The unique information Xs indicates, for example, the serial number of Device X. The encrypted information Xc may be included in the registration request information transmitted from the information processing device 100 that performed the registration at the time of registration of Device X. The encrypted information Xc is, for example, a hash value obtained by encrypting the serial number of Device X with a hash function associated with the software 30a. The usage status information Xu may be included in the registration request information transmitted from the information processing device 100 that performed the registration at the time of registration of Device X. The notification information Xn can be generated by the notification generation unit 232 using the usage status information Xu.

[0072] Here, the overwriting process performed by the registration processing unit 220 will be described with reference to FIG. 7. Assume that device X is transferred from organization A to organization B. In this case, software 30a is installed in the information processing apparatuses 100 corresponding to the identification information B1, B2, and B3 respectively. Note that the software 30a installed in the information processing apparatuses 100 corresponding to the identification information A1, A2, and A3 respectively is usually uninstalled. Then, assume that registration request information is received from the information processing apparatus 100 corresponding to any of the identification information B1, B2, and B3 of the users belonging to organization B. In this case, the registration processing unit 220 determines that the unique information of device X included in the registration request information matches the unique information Xs included in the registration information RgXa stored in the area related to organization A in the registration information storage unit 222. In this case, the registration processing unit 220 determines that the ownership of device X has been transferred from organization A to organization B. Then, as shown in FIG. 7, the registration processing unit 220 deletes the registration information RgXa stored in the area related to organization A in the registration information storage unit 222, and newly stores the registration information RgXb related to device X in the area related to organization B.

[0073] The registration information RgXb includes, similarly to the registration information RgXa, the unique information Xs related to device X, the encrypted information Xc related to device X, the usage status information Xu related to device X, and the notification information Xn related to device X. Note that the unique information Xs shown in FIG. 7 is the same as the unique information Xs shown in FIG. 6. Also, the encrypted information Xc is obtained by encrypting the unique information Xs with a hash function associated with the software 30a. Then, the same software 30a as the software 30a installed in the information processing apparatus 100 of the users belonging to organization A is installed in the information processing apparatus 100 of the users belonging to organization B. Therefore, the encrypted information Xc shown in FIG. 7 is the same as the encrypted information Xc shown in FIG. 6. Note that the usage status of device X may change over time. Therefore, the usage status information Xu shown in FIG. 7 may be different from the usage status information Xu shown in FIG. 6. Therefore, the notification information Xn shown in FIG. 7 may also be different from the notification information Xn shown in FIG. 6.

[0074] Also, in the example of FIG. 7, Organization B owns a colorimeter 30, which is an external device 2 related to Device X. And in the area related to Organization B, registration information RgXb related to Device X is stored. In this case, users belonging to Organization B, that is, users related to identification information B1, users related to identification information B2, and users related to identification information B3, can use Device X and software 30a related to Device X. On the other hand, users belonging to Organization A, that is, users related to identification information A1, users related to identification information A2, and users related to identification information A3, cannot use Device X and software 30a related to Device X.

[0075] FIGS. 8 and 9 are flowcharts showing an authentication method executed by the authentication system 20 according to Embodiment 1. FIG. 8 shows the registration process of the colorimeter 30 performed by the authentication system 20 according to Embodiment 1. When the colorimeter 30 is communicably connected to the information processing apparatus 100 (YES in step S102), the information processing apparatus 100 acquires device information related to the colorimeter 30 (step S104). Specifically, as described above, the device information acquisition unit 130 acquires device information including unique information related to the colorimeter 30 and usage status information related to the colorimeter 30.

[0076] The information processing apparatus 100 generates encrypted information (step S106). Specifically, as described above, the encrypted information generation unit 140 generates encrypted information by encrypting unique information using an encryption method corresponding to the software 30a. More specifically, as described above, the encrypted information generation unit 140 generates a hash value, which is encrypted information, by encrypting the serial number using a hash function corresponding to the software 30a.

[0077] Also, communication processing is performed between the server 200 and the information processing apparatus 100 (step S110). Specifically, the information processing apparatus 100 performs communication processing with the server 200. More specifically, as described above, the registration processing unit 150 of the information processing apparatus 100 performs processing for logging in to the service provided by the server 200. Thereby, the registration processing unit 150 transmits the identification information corresponding to the information processing apparatus 100 to the server 200. That is, the registration processing unit 150 transmits the identification information included in the account information used at the time of logging in to the server 200 by logging in to the service provided by the server 200. Note that the processing of S110 may be performed at an arbitrary timing before the processing of S106.

[0078] The information processing apparatus 100 transmits registration request information in which the identification information, the device information, and the encrypted information are associated with each other to the server 200 (step S112). Specifically, as described above, the registration processing unit 150 of the information processing apparatus 100 transmits registration request information in which the identification information, the unique information of the colorimeter 30, and the hash value are associated with each other to the server 200.

[0079] The server 200 registers the identification information, the device information, and the encrypted information in association with each other (step S120). Specifically, as described above, the registration processing unit 220 of the server 200 uses the registration request information received from the information processing apparatus 100 to generate registration information in which the identification information, the device information, and the encrypted information are associated with each other. The registration processing unit 220 stores the generated registration information in the registration information storage unit 222. Here, as described above, when the unique information included in the received registration request information, for example, the serial number of the external device 2, matches the unique information included in the already registered registration information, the registration processing unit 220 performs the overwrite processing as described above.

[0080] Server 200 generates notification information (step S122). Specifically, as described above, the notification generation unit 232 generates notification information regarding the registered colorimeter 30 by using the usage status information of the device information included in the registration request information. Further, the notification generation unit 232 stores the generated notification information in the registration information storage unit 222 in association with the corresponding registration information.

[0081] FIG. 9 shows the usage permission process of the software 30a corresponding to the colorimeter 30 performed by the authentication system 20 according to Embodiment 1. The information processing apparatus 100 activates the software 30a (step S140). Specifically, the software processing unit 110 of the information processing apparatus 100 activates the software 30a by a user operation.

[0082] At this time, communication processing is performed between the server 200 and the information processing apparatus 100 (step S142). Specifically, the information processing apparatus 100 performs communication processing with the server 200. More specifically, as described above, the permission processing unit 160 of the information processing apparatus 100 performs processing for logging in to the service provided by the server 200. As a result, the information processing apparatus 100 logs in to the service provided by the server 200. At this time, the permission processing unit 160 transmits the identification information corresponding to the information processing apparatus 100 to the server 200. That is, the permission processing unit 160 transmits the identification information included in the account information used at the time of login to the server 200 by logging in to the service provided by the server 200.

[0083] The information processing apparatus 100 acquires the registration information associated with the transmitted identification information from the server 200 (step S144). Specifically, as described above, the registration information transmission unit 240 of the server 200 transmits the registration information associated with the identification information transmitted from the information processing apparatus 100 at the time of login to the information processing apparatus 100. In this way, the permission processing unit 160 downloads the registration information associated with the transmitted identification information from the server 200.

[0084] The information processing apparatus 100 performs authentication regarding permission to execute the software 30a (S150, S152). The permission processing unit 160 of the information processing apparatus 100 performs the first authentication (step S150). Specifically, the permission processing unit 160 makes a determination using unique information as the first authentication. More specifically, as described above, the permission processing unit 160 determines whether the unique information included in the registration information corresponds to the model information regarding the software 30a to be used. When the first authentication is affirmed (YES in S150), the permission processing unit 160 performs the second authentication (step S152). Specifically, the permission processing unit 160 makes a determination using encrypted information as the second authentication. More specifically, as described above, the permission processing unit 160 determines whether the encrypted information included in the registration information is information obtained by encrypting the unique information by the encryption method corresponding to the software 30a to be used. Note that the process of S152 may be executed before the process of S150, or the processes of S150 and S152 may be executed in parallel.

[0085] When the first authentication and the second authentication are affirmed (YES in S152), the permission processing unit 160 permits the execution of the software 30a (step S154). On the other hand, when the first authentication is denied (NO in S150) or when the second authentication is denied (NO in S152), the permission processing unit 160 prohibits the execution of the software 30a (step S160).

[0086] When the execution of the software 30a is permitted (S154), the information processing apparatus 100 executes the first function using the colorimeter 30 (step S162). Specifically, as described above, the first function execution processing unit 122 executes the function using the colorimeter 30 in a state where the colorimeter 30 is communicably connected to the information processing apparatus 100. For example, the first function execution processing unit 122 executes the first function, controls the colorimeter 30, and measures the color patches printed on the color chart.

[0087] Further, the information processing apparatus 100 executes a second function without using the colorimeter 30 (step S164). Specifically, as described above, the second function execution processing unit 124 executes a function that can be executed without using the colorimeter 30. For example, the second function execution processing unit 124 executes the second function to perform color adjustment processing or print job execution processing. At this time, the colorimeter 30 does not necessarily need to be communicably connected to the information processing apparatus 100.

[0088] As described above, the information processing apparatus 100 according to the first embodiment acquires device information including at least the unique information of the colorimeter 30 which is an external device 2. Further, the information processing apparatus 100 according to the first embodiment performs processing so that at least the identification information corresponding to the information processing apparatus 100 and the acquired device information are associated with each other and registered in the server 200. Further, when the software 30a is used by the information processing apparatus 100, the information processing apparatus 100 according to the first embodiment performs processing for permitting the execution of the software 30a based on the authentication performed using the identification information and the device information registered in the server 200. With such a configuration, the usage right of the software 2a associated with the colorimeter 30 which is the external device 2 can be appropriately managed. These are the same also in the second embodiment described later.

[0089] Further, the information processing apparatus 100 according to Embodiment 1 may be configured to permit the execution of the software 30a in a state where the information processing apparatus 100 and the colorimeter 30 as the external device 2 do not communicate with each other based on the above authentication. Specifically, the information processing apparatus 100 may be configured to permit the execution of the software 30a so that the second function can be executed in a state where the information processing apparatus 100 and the colorimeter 30 as the external device 2 do not communicate with each other based on the above authentication. With such a configuration, it becomes possible to execute the software 30a even when the colorimeter 30 as the external device 2 is not connected to the information processing apparatus 100. Therefore, it is not necessary for the user to carry the colorimeter 30 as the external device 2 in order to execute the software 30a. Therefore, the convenience of the user is improved. The same applies to Embodiment 2 described later.

[0090] Further, the information processing apparatus 100 according to Embodiment 1 may be configured to permit the execution of the software 30a so that at least the first function can be executed in a state where the information processing apparatus 100 and the colorimeter 30 as the external device 2 communicate with each other based on the above authentication. With such a configuration, even if a third party who does not have the right to use the colorimeter 30 installs the software 30a on their own terminal without permission and the third party's terminal is connected to the colorimeter 30, the execution of the first function of the software 30a is suppressed. Therefore, it is possible to suppress the inappropriate use of the functions of the software 30a using the colorimeter 30 as the external device 2. The same applies to Embodiment 2 described later.

[0091] Further, the information processing apparatus 100 according to Embodiment 1 may perform processing for registering, in the server 200, the encrypted information obtained by encrypting the unique information by an encryption method corresponding to the software 30a, the identification information, and the device information in association with each other. Further, when the software 30a is used, the information processing apparatus 100 according to Embodiment 1 may permit the execution of the software 30a based on authentication performed using the identification information, the device information, and the encrypted information registered in the server 200. With such a configuration, when information is tampered with in the communication path between the server 200 and the information processing apparatus 100, the authentication using the encrypted information can be denied. Therefore, the authentication system 20 according to Embodiment 1 can detect tampering made to the communication path. Therefore, it is possible to improve the security of communication when the colorimeter 30, which is an external device 2, and the software 30a related to the colorimeter 30 are used. These are the same in Embodiment 2 described later.

[0092] Also, as described above, the device information may include usage status information indicating the usage status of the colorimeter 30, which is an external device 2. With such a configuration, since the usage status information is transmitted to the server 200, the server 200 can store the usage status information. Therefore, it becomes possible to manage the usage status of the colorimeter 30, which is an external device 2, in the server 200. In particular, when the colorimeter 30 is owned by an organization and shared by a plurality of users belonging to the organization, if the information processing apparatus 100 of a certain user manages the usage status of the colorimeter 30, there is a possibility that the information processing apparatus 100 of other users cannot grasp the usage status of the colorimeter 30. On the other hand, by the server 200 managing the usage status of the colorimeter 30, each of the information processing apparatuses 100 of a plurality of users can appropriately grasp the usage status of the colorimeter 30. Further, the manufacturer of the colorimeter 30 can grasp the usage status of the colorimeter 30 via the server 200, and can provide services according to the usage status to the users who use the colorimeter 30. These are the same in Embodiment 2 described later.

[0093] In addition, the server 200 according to Embodiment 1 may transmit a notification indicating the state of the colorimeter 30, which is an external device 2, to the information processing apparatus 100 using the usage status information. With such a configuration, it becomes possible to appropriately notify the user of the information to be notified to the user regarding the colorimeter 30. Further, with such a configuration, the server 200 can transmit the notification to the information processing apparatus 100 together with the information transmitted to the information processing apparatus 100 for the above authentication. Therefore, compared with the case where such a notification is transmitted alone, the communication between the information processing apparatus 100 and the server 200 can be made more efficient. The same applies to Embodiment 2 described later.

[0094] Also, as described above, the external device 2 may be the colorimeter 30. Therefore, the authentication system 20 according to Embodiment 1 can appropriately manage the usage rights of the software 30a associated with the colorimeter 30. Also, as described above, the software 30a may have a function that requires the use of the colorimeter 30 and a function that can be executed without using the colorimeter 30. Therefore, the authentication system 20 according to Embodiment 1 can appropriately manage the usage rights of the function that requires the use of the colorimeter 30 and the function that can be executed without using the colorimeter 30. The same applies to Embodiment 2 described later.

[0095] In addition, when the software 30a is used, the information processing apparatus 100 according to Embodiment 1 may transmit identification information to the server 200 and acquire at least device information registered in the server 200 corresponding to the transmitted identification information. Then, the information processing apparatus 100 according to Embodiment 1 may perform the above authentication using the acquired device information and perform processing for permitting the execution of the software 30a. With such a configuration in which the information processing apparatus 100 performs authentication, it becomes unnecessary for the server 200 to perform authentication. Therefore, it becomes unnecessary to provide a function for performing authentication in the server 200. Therefore, when realizing the authentication system 20, a highly versatile server 200 can be used.

[0096] (Embodiment 2) Next, Embodiment 2 will be described with reference to the drawings. For clarity of explanation, the following description and drawings are appropriately omitted and simplified. Also, in each drawing, the same reference numerals are assigned to the same elements, and redundant explanations are omitted as necessary. Note that the configuration of the authentication system 20 is substantially the same as that shown in FIG. 3 described above, and thus the description thereof is omitted. Also, Embodiment 2 is different from Embodiment 1 in that the above authentication is performed by the server 200.

[0097] FIG. 10 is a diagram showing the configuration of the information processing apparatus 100 according to Embodiment 2. Similar to the information processing apparatus 100 according to Embodiment 1, the information processing apparatus 100 according to Embodiment 2 includes, as main hardware components, a processing unit 102, a storage unit 104, a communication unit 106, and an interface unit 108. Also, the information processing apparatus 100 according to Embodiment 2 includes, as components, a software processing unit 110, a device information acquisition unit 130, a unique information storage unit 132, an encryption information generation unit 140, a registration processing unit 150, and a permission processing unit 162. Further, the software processing unit 110 includes, as components, a software storage unit 112, an encryption method storage unit 114, a model information storage unit 116, a first function execution processing unit 122, and a second function execution processing unit 124.

[0098] In the information processing apparatus 100 according to the second embodiment, the operations of the components other than the unique information storage unit 132 and the permission processing unit 162 are substantially the same as those of the components of the information processing apparatus 100 according to the first embodiment described above, and thus the description thereof is omitted. The first function execution processing unit 122 performs processing for executing the first function in a state where the colorimeter 30 is communicably connected to the information processing apparatus 100 when the execution of the software 30a is permitted by the permission processing unit 162. Further, the second function execution processing unit 124 performs processing for executing the second function when the execution of the software 30a is permitted by the permission processing unit 162.

[0099] The unique information storage unit 132 can be realized by the storage unit 104. The unique information storage unit 132 stores the acquired unique information when the unique information such as the serial number is acquired by the device information acquisition unit 130.

[0100] The permission processing unit 162 performs processing corresponding to S18 in FIG. 2. That is, when the software 30a is used by the information processing apparatus 100, the permission processing unit 162 performs processing for permitting the execution of the software 30a based on the authentication performed using the identification information and the device information registered in the server 200. In other words, when the software 30a is used by the information processing apparatus 100, the permission processing unit 162 makes a request to the server 200 to enable the execution of the software 30a. In the second embodiment, the server 200 performs the authentication process.

[0101] Specifically, when the software 30a is activated, the permission processing unit 162 performs a process for logging in to the service provided by the server 200 described above. As a result, the permission processing unit 162 transmits identification information such as account information to the server 200. Further, the permission processing unit 162 transmits permission request information, which is information for requesting the server 200 to permit the execution of the software 30a. Note that the permission request information may include unique information such as a serial number and encrypted information such as a hash value. Here, the unique information is stored in the unique information storage unit 132 described above. Also, the encrypted information is generated by the encryption information generation unit 140 encrypting the unique information.

[0102] When the server 200 receives the permission request information from the information processing apparatus 100, the server 200 performs an authentication process as described later. Then, the server 200 transmits authentication information indicating the result of the authentication to the information processing apparatus 100 as described later.

[0103] When the authentication information acquired from the server 200 indicates that the execution of the software 30a is permitted, the permission processing unit 162 permits the execution of the software 30a. As a result, the first function execution processing unit 122 becomes able to execute the first function. Similarly, the second function execution processing unit 124 becomes able to execute the second function. On the other hand, when the authentication information acquired from the server 200 indicates that the execution of the software 30a is prohibited, the permission processing unit 162 disables the first function execution processing unit 122 from functioning and disables the second function execution processing unit 124 from functioning.

[0104] Furthermore, the permission processing unit 162 may receive the registration information to which the above-described notification information is added from the server 200. Also, when the authentication information indicates that the execution of the software 30a is permitted, the permission processing unit 162 may perform a process to present the notification information to the user.

[0105] FIG. 11 is a diagram showing the configuration of the server 200 according to Embodiment 2. Similar to the server 200 according to Embodiment 1, the server 200 according to Embodiment 2 includes, as main hardware components, a processing unit 202, a storage unit 204, a communication unit 206, and an interface unit 208. Further, the server 200 according to Embodiment 2 includes, as components, a service provision processing unit 210, a registration processing unit 220, a registration information storage unit 222, a usage status management unit 230, a notification generation unit 232, an authentication processing unit 250, and an authentication information transmission unit 260. Note that, in the server 200 according to Embodiment 2, the operations of the components other than the authentication processing unit 250 and the authentication information transmission unit 260 are substantially the same as the operations of the components of the server 200 according to Embodiment 1 described above, and thus the description thereof is omitted.

[0106] The authentication processing unit 250 and the authentication information transmission unit 260 perform processing corresponding to S18 in FIG. 2. When the software 30a is used by the information processing apparatus 100, the authentication processing unit 250 performs authentication using the identification information and the device information registered in the server 200. The authentication processing unit 250 performs authentication processing for determining whether the information processing apparatus 100 has the right to use the software 30a in response to the permission request information from the information processing apparatus 100.

[0107] Specifically, in a state where the information processing apparatus 100 has logged in to the service provided by the service provision processing unit 210, the authentication processing unit 250 receives permission request information from the information processing apparatus 100. In this case, the authentication processing unit 250 compares the content of the registration information corresponding to the identification information of the account information acquired at the time of login with the content of the received permission request information, and performs authentication. The authentication processing unit 250 determines whether both the first authentication and the second authentication as described below are affirmed.

[0108] As the first authentication, the authentication processing unit 250 performs authentication using unique information. The authentication processing unit 250 determines whether the unique information included in the registration information corresponding to the identification information acquired at the time of login matches the unique information included in the permission request information. When the unique information included in the registration information corresponding to the identification information matches the unique information included in the permission request information, the authentication processing unit 250 determines that the first authentication is affirmed. For example, the authentication processing unit 250 determines whether the serial number included in the registration information corresponding to the identification information acquired at the time of login matches the serial number included in the permission request information. When the serial number included in the registration information corresponding to the identification information matches the serial number included in the permission request information, the authentication processing unit 250 determines that the first authentication is affirmed.

[0109] As the second authentication, the authentication processing unit 250 performs authentication using encrypted information. Specifically, the authentication processing unit 250 determines whether the encrypted information included in the registration information corresponding to the identification information acquired at the time of login matches the encrypted information included in the permission request information. When the two pieces of encrypted information match, the authentication processing unit 250 determines that the second authentication is affirmed. For example, the authentication processing unit 250 determines whether the hash value included in the registration information corresponding to the identification information acquired at the time of login matches the hash value included in the permission request information. When the two hash values match, the authentication processing unit 250 determines that the second authentication is affirmed.

[0110] The authentication processing unit 250 generates authentication information indicating the authentication result. Specifically, when both the first authentication and the second authentication are affirmed, the authentication processing unit 250 generates authentication information indicating permission to execute the software 30a. On the other hand, when at least one of the first authentication and the second authentication is negated, the authentication processing unit 250 generates authentication information indicating prohibition of execution of the software 30a.

[0111] The authentication information transmission unit 260 transmits the authentication information generated by the authentication processing unit 250 to the information processing apparatus 100 that has logged in to the service. Note that when transmitting the authentication information, the authentication information transmission unit 260 may transmit, to the information processing apparatus 100, authentication information including notification information regarding the colorimeter 30 corresponding to the registration information used in the above-described authentication.

[0112] FIG. 12 is a flowchart showing an authentication method executed by the authentication system 20 according to Embodiment 2. Note that in Embodiment 2, the registration process of the colorimeter 30 is substantially the same as the process shown in FIG. 8 described above, and thus the description thereof is omitted. Note that in the registration process in Embodiment 2, the unique information may be stored by the unique information storage unit 132 of the information processing apparatus 100 during the process of S104.

[0113] FIG. 12 shows the use permission process of the software 30a corresponding to the colorimeter 30 performed by the authentication system 20 according to Embodiment 2. The information processing apparatus 100 activates the software 30a (step S240) in the same manner as the process of S140 described above. At this time, communication processing is performed between the server 200 and the information processing apparatus 100 (step S242) in the same manner as the process of S142 described above. As a result, the permission processing unit 162 transmits the identification information corresponding to the information processing apparatus 100 to the server 200. Further, the information processing apparatus 100 transmits permission request information to the server 200 (step S244). Specifically, as described above, the permission processing unit 162 transmits permission request information including the unique information and the encrypted information to the server 200.

[0114] Server 200 authenticates the permission for the execution of software 30a by information processing apparatus 100 (S250, S252). The authentication processing unit 250 of server 200 performs the first authentication (step S250). Specifically, the authentication processing unit 250 makes a determination using unique information as the first authentication. More specifically, as described above, the authentication processing unit 250 determines whether the unique information included in the registration information corresponding to the received identification information matches the unique information included in the permission request information. When the first authentication is affirmed (YES in S250), the authentication processing unit 250 performs the second authentication (step S252). Specifically, the authentication processing unit 250 makes a determination using encrypted information as the second authentication. More specifically, as described above, the authentication processing unit 250 determines whether the encrypted information included in the registration information corresponding to the received identification information matches the encrypted information included in the permission request information. Note that the process of S252 may be executed before the process of S250, or the processes of S250 and S252 may be executed in parallel.

[0115] When the first authentication and the second authentication are affirmed (YES in S252), information processing apparatus 100 receives authentication information indicating permission to execute software 30a from server 200 (step S254). Specifically, when both the first authentication and the second authentication are affirmed, as described above, the authentication processing unit 250 generates authentication information indicating permission to execute software 30a. The authentication information transmission unit 260 transmits the authentication information to information processing apparatus 100. Thereby, the permission processing unit 162 receives the authentication information indicating permission to execute software 30a and permits the execution of software 30a.

[0116] On the other hand, when the first authentication is denied (NO in S250) or the second authentication is denied (NO in S252), the information processing apparatus 100 receives authentication information indicating prohibition of execution of the software 30a from the server 200 (step S260). Specifically, when at least one of the first authentication and the second authentication is denied, as described above, the authentication processing unit 250 generates authentication information indicating prohibition of execution of the software 30a. The authentication information transmission unit 260 transmits the authentication information to the information processing apparatus 100. Thereby, the permission processing unit 162 receives the authentication information indicating prohibition of execution of the software 30a, and prohibits the execution of the software 30a.

[0117] When the execution of the software 30a is permitted (S254), the information processing apparatus 100 executes the first function using the colorimeter 30 (step S262) in the same manner as the process of S162 described above. Also, the information processing apparatus 100 executes the second function without using the colorimeter 30 (step S264) in the same manner as the process of 164 described above.

[0118] As described above, in the authentication system 20 according to the second embodiment, when the software 30a is used by the information processing apparatus 100, the information processing apparatus 100 transmits the corresponding identification information to the server 200. The server 200 receives the corresponding identification information from the information processing apparatus 100. The server 200 performs authentication using the received identification information and the device information registered in the server 200. The server 200 generates authentication information for permitting execution of the software 30a associated with the colorimeter 30 which is an external device 2 regarding the device information, and transmits the authentication information to the information processing apparatus 100. The information processing apparatus 100 receives this authentication information from the server 200, and performs processing for permitting execution of the software 30a based on the authentication information. Thus, with the configuration in which the server 200 performs authentication, it becomes unnecessary for the information processing apparatus 100 to perform authentication. Therefore, it becomes unnecessary to provide a function for the information processing apparatus 100 to perform authentication. Therefore, the load on the information processing apparatus 100 can be reduced.

[0119] (Modification example) Note that the present invention is not limited to the above-described embodiments, and can be appropriately modified without departing from the gist. For example, one or more of the processes in the above-described flowchart can be appropriately omitted. Also, the order of the processes in the above-described flowchart can be appropriately changed.

[0120] Also, in the above-described Embodiment 1 and Embodiment 2, when the first authentication and the second authentication are affirmed, the execution of the software 30a is permitted. However, the present invention is not limited to such a configuration. The execution of the software 30a may be permitted when at least the first authentication is affirmed.

[0121] Also, in Embodiment 1, when the information processing apparatus 100 acquires the apparatus information regarding the colorimeter 30, the information processing apparatus 100 may store the unique information included in the apparatus information. Then, when the permission processing unit 160 according to Embodiment 1 performs the first authentication, it may be determined whether the unique information included in the registration information received from the server 200 matches the stored unique information. Then, the permission processing unit 160 may determine that the first authentication is affirmed when these two pieces of unique information match.

[0122] Also, in Embodiment 2, the permission request information may include model information regarding the software 30a instead of the unique information. Then, when the authentication processing unit 250 according to Embodiment 2 performs the first authentication, it may be determined whether the unique information included in the registration information corresponding to the identification information corresponds to the model information included in the permission request information. Then, the authentication processing unit 250 may determine that the first authentication is affirmed when the unique information included in the registration information corresponding to the identification information corresponds to the model information included in the permission request information. At this time, the authentication processing unit 250 may perform the first authentication by substantially the same method as the permission processing unit 160 according to Embodiment 1.

[0123] Also, in Embodiment 2, during the registration process, the registration information storage unit 222 of the server 200 may store an encryption method for the software 30a corresponding to the colorimeter 30 to be registered. Then, during the second authentication, the authentication processing unit 250 according to Embodiment 2 may determine whether the encrypted information obtained by encrypting the unique information included in the permission request information using the stored encryption method matches the encrypted information included in the registration information. And the authentication processing unit 250 may determine that the second authentication is affirmed when these two pieces of encrypted information match.

[0124] In the above example, the program includes a set of instructions (or software code) for causing a computer to perform one or more functions described in the embodiment when loaded into the computer. The program may be stored in a non-transitory computer-readable medium or a tangible storage medium. By way of example and not limitation, the computer-readable medium or tangible storage medium includes random-access memory (RAM), read-only memory (ROM), flash memory, solid-state drive (SSD), or other memory technologies, CD-ROM, digital versatile disk (DVD), Blu-ray (registered trademark) disk, or other optical disk storage, magnetic cassette, magnetic tape, magnetic disk storage, or other magnetic storage devices. The program may also be transmitted on a transient computer-readable medium or a communication medium. By way of example and not limitation, the transient computer-readable medium or communication medium includes electrical, optical, acoustic, or other forms of propagated signals.

Explanation of Reference Numerals

[0125] 1… Authentication system, 2… External device, 2a… Software, 4… Server, 10… Information processing device, 20… Authentication system, 30… Colorimeter, 30a… Software, 100… Information processing device, 102… Processing unit, 104… Memory unit, 106… Communication unit, 108… Interface unit, 110… Software processing unit, 112… Software storage unit, 114… Encryption method storage unit, 116… Model information storage unit, 122… First function execution processing unit, 124… Second function execution processing unit, 130… Device information acquisition unit, 132… Unique information storage unit, 140… Encryption information generation unit, 150… Registration processing unit, 160… Permission processing unit, 162… Permission processing unit, 200… Server, 202… Processing unit, 204… Memory unit, 206… Communication unit, 208… Interface unit, 210… Service provision processing unit, 220… Registration processing unit, 222… Registration information storage unit, 230… Usage management unit, 232… Notification generation unit, 240… Registration information transmission unit, 250… Authentication processing unit, 260… Authentication information transmission unit

Claims

Claim 1 An authentication method for authenticating the execution of software by an information processing device, wherein the software is associated with a predetermined external device physically separate from the information processing device and has a first function executable using at least the external device, obtain device information regarding the external device, the device information including at least information unique to the external device, perform processing so that at least identification information corresponding to the information processing device and the obtained device information are associated with each other and registered in a server, when the software is used by the information processing device, perform processing to permit the execution of the software based on authentication performed using the identification information and the device information registered in the server, authentication method. Claim 2 Based on the authentication, perform processing to permit the execution of the software in a state where the information processing device and the external device do not communicate with each other, The authentication method according to claim 1. Claim 3 The software has the first function and a second function different from the first function and executable without using the external device, Based on the authentication, perform processing to permit the execution of the software so that the second function can be executed in a state where the information processing device and the external device do not communicate with each other, The authentication method according to claim 2. Claim 4 Based on the authentication, perform processing to permit the execution of the software so that at least the first function can be executed in a state where the information processing device and the external device communicate with each other, The authentication method according to claim 1. Claim 5 Perform processing so that encrypted information obtained by encrypting information unique to the external device among the device information using an encryption method corresponding to the software, the identification information, and the device information are associated with each other and registered in a server, when the software is used by the information processing device, perform processing to permit the execution of the software based on authentication performed using the identification information, the device information, and the encrypted information registered in the server, The authentication method according to claim 1. Claim 6 When the software is used by the information processing apparatus, the information processing apparatus transmits the identification information corresponding to the information processing apparatus to the server, acquires at least the device information registered in the server corresponding to the transmitted identification information, performs the authentication using the acquired device information, and performs a process for permitting the execution of the software. The authentication method according to claim 1.

7. When the software is used by the information processing apparatus, the server receives the identification information corresponding to the information processing apparatus from the information processing apparatus, performs the authentication using the received identification information and the device information registered in the server, and transmits authentication information for permitting the execution of the software associated with the external device related to the device information to the information processing apparatus. The information processing apparatus performs a process for permitting the execution of the software based on the authentication information. The authentication method according to claim 1.

8. The external device is a colorimeter. The authentication method according to claim 1.

9. The software has a function that requires the use of the colorimeter and a function that can be executed without using the colorimeter. The authentication method according to claim 8.

10. The device information includes usage status information indicating the usage status of the external device. The authentication method according to claim 1.

11. The server transmits a notification indicating the state of the external device to the information processing apparatus using the usage status information. The authentication method according to claim 10.

12. An information processing apparatus, a storage unit that stores at least software associated with a predetermined external device physically separate from the information processing apparatus and having at least a first function executable using at least the external device; a processing unit that executes at least the software; a device information acquisition unit that acquires device information regarding the external device and including at least information unique to the external device; a registration processing unit that performs a process for registering at least the identification information corresponding to the information processing apparatus and the acquired device information in association with each other in a server. A permission processing unit that performs a process for permitting the execution of the software based on authentication performed using the identification information and the device information registered in the server when the software is used by the information processing apparatus; An information processing apparatus having the same. **Claim 13** When the software is used by the information processing apparatus, the permission processing unit transmits the identification information corresponding to the information processing apparatus to the server, acquires at least the device information registered in the server corresponding to the transmitted identification information, performs the authentication using the acquired device information, and performs a process for permitting the execution of the software. The information processing apparatus according to claim 12. **Claim 14** When the software is used by the information processing apparatus, the permission processing unit transmits the identification information corresponding to the information processing apparatus to the server, receives from the server authentication information for permitting the execution of the software associated with the external device related to the device information, which is generated from the authentication performed by the server using the transmitted identification information and the device information registered in the server, and performs a process for permitting the execution of the software based on the authentication information. The information processing apparatus according to claim 12. **Claim 15** A program for causing a computer to realize a function of at least executing software associated with a predetermined external device physically separate from the information processing apparatus and having at least a first function executable using the external device, a function of acquiring device information regarding the external device, the device information including at least information unique to the external device, a function of performing a process for registering at least the identification information corresponding to the information processing apparatus and the acquired device information in association with each other in a server, and a function of performing a process for permitting the execution of the software based on authentication performed using the identification information and the device information registered in the server when the software is used by the information processing apparatus. ​

Citation Information

Patent Citations

  • Image forming apparatus, control method of image forming apparatus, and control program of image forming apparatus

    JP2014104666A