Device control system and processing method of device control system
The device management system maintains connection credentials for network devices, ensuring seamless reconnection to new tenants after deletion, addressing the issue of severed connections in existing systems.
Patent Information
- Application Number
- JP2024003224
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-01-12
- Publication Date
- 2025-07-25
AI Technical Summary
Existing device management systems sever connections between network devices and the device management server when a customer tenant is deleted, requiring manual reconnection operations and losing authentication information.
A device management system that retains key information and allows network devices to reconnect to a new tenant by maintaining connection credentials even after a tenant deletion, enabling seamless transition to a new connection destination.
Ensures continuous connectivity of network devices to the device management server by allowing them to reconnect to new tenants without manual reconnection operations, even after tenant deletion.
Smart Images

Figure 2025109376000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a device management system and a method for processing a device management system.
Background Art
[0002] With the spread of cloud services and the Internet of Things (IoT), systems have emerged that collect data on network devices such as image forming devices equipped with communication control devices via a network and use the data to provide services to customers. Here, IoT stands for Internet of Things. In such a system, by registering information on network devices in a device management server that manages connections of network devices of multiple customer companies, it becomes available for service providers.
[0003] When providing services for network devices to a certain customer company, a person in charge at the service provider creates a new tenant and assigns it to that customer company. Then, in order to manage network devices for each customer company, the network devices are registered in the device management server in association with the tenant assigned to the customer company (hereinafter referred to as the customer tenant). The network device establishes a connection by performing authentication using information for identifying the network device registered in the device management server, and activates the communication functions necessary for service provision. By associating the network device with the customer tenant, the data of the network device collected via the network can also be managed in a logically separated area for each customer in association with the customer tenant, providing a secure tenant separation environment for the customer company.
[0004] The technology disclosed in Patent Document 1 is a network device installed in a customer company that identifies a destination customer company from among a plurality of customer companies managed by a service provider and registers it with a device management server. In particular, the technology disclosed in Example 3 of Patent Document 1 is such that the device management server issues a connection code for each customer tenant, and the network device transmits the input connection code to the device management server, thereby registering the network device in association with the customer tenant. Since the network device cannot be connected to the device management server unless the connection code is known, unnecessary connections and connections to the wrong customer tenant can be prevented.
[0005] The technology disclosed in Patent Document 2 provides a system that can perform an installation operation using a connection code issued to a sales company that performs the installation when registering a network device in association with a customer tenant. Instead of issuing a connection code for connecting a network device for each user of the network device or each customer tenant, a connection code issued to the sales company that performs the installation is used. After the step of registering in association with the tenant of the sales company, by enabling the device management server to send an instruction to re-associate with the customer tenant to the network device, the trouble of issuing and distributing connection codes for each user of the network device and each customer tenant is reduced.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Patent Document 2
Summary of the Invention
Problems to be Solved by the Invention
[0007] The technology disclosed in Patent Document 1 can manage network devices and the data of network devices in a logically separated area for each customer by registering the network devices in association with customer tenants. However, precisely because it is managed in a separated area, when a customer tenant is deleted from the device management server, not only does the destination for transmitting the data of the network device disappear, but also the information of the registered network devices is deleted.
[0008] In addition to the deletion of the information of the network device, the authentication information for the network device to establish a connection with the device management server is also deleted, and the connection between the network device and the device management server is also severed. In cases where a customer tenant is once deleted in order to continue using the network device with different customers, or in cases where a customer tenant is deleted due to an accidental operation, the connection of the network device is severed by an operation on the device management server. Once the authentication information is deleted and the connection is severed, simply creating a customer tenant or registering the information of the network device will not resume the connection with the device management server, and an operation of inputting a connection code to the network device will be required.
[0009] The technology disclosed in Patent Document 2 allows the installation work for establishing a connection with the device management server to be completed even if a customer tenant has not been created because it can be switched to a connection to the customer tenant after being registered once in the tenant of the sales company. However, after switching to a connection to the customer tenant, similar to the technology disclosed in Patent Document 1, when a customer tenant is deleted from the device management server, the connection between the network device and the device management server is severed.
[0010] An object of the present disclosure is to enable a device to connect to another connection destination organization even when deletion of the connection destination organization is instructed.
Means for Solving the Problem
[0011] The device management system is a device management system including a device and a device management server. The device management server includes: device information registration means for registering by associating the device with a destination organization in the device management server in response to a registration request; connection code issuance means for issuing a connection code for specifying the destination organization; when the connection code received from the device is the same as the connection code for specifying the destination organization associated with the device, key information for connecting to the destination organization specified from the connection code is issued to the device, and connection permission means for permitting the device to connect to the destination organization when authentication of the key information received from the device is successful. The device information registration means, when deletion of the destination organization is instructed, holds the key information of the device associated with the destination organization without deleting it, registers the destination organization of the change destination, and the connection permission means, when authentication of the key information received from the device is successful and the destination organization of the change destination is registered, transmits a connection code for specifying the destination organization of the change destination to the device, and when authentication of the key information received from the device is successful and the destination organization of the change destination is not registered, permits the device to connect to the destination organization.
Effect of the Invention
[0012] According to the present disclosure, even when deletion of the destination organization is instructed, the device can connect to another destination organization.
Brief Description of the Drawings
[0013]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Mode for Carrying Out the Invention
[0014] Hereinafter, this embodiment will be described with reference to the drawings.
[0015] FIG. 1 is a diagram showing a configuration example of a device management system 100 according to this embodiment. The device management system 100 of this embodiment includes a network device 110, a device management server 120, a network 130, and a client terminal 140.
[0016] The network device 110 is a processing device in the network of a customer company connected to the device management server 120 via a network 130 such as the Internet, and includes image processing devices such as printers, copiers, and scanners. Although only one network device 110 is shown in FIG. 1, there may be multiple network devices in the network of the customer company, or network devices of multiple customer companies.
[0017] The network device 110 connects to the device management server 120 through a server connection application operating on the network device 110, and transmits the setting information and operation information of the network device 110 to the device management server 120. When transmitting the setting information and operation information, the network device 110 authenticates with the device management server 120 and obtains connection permission information such as an access token and a session ID. The network device 110 attaches the obtained connection permission information and transmits the setting information and operation information to the device management server 120.
[0018] The device management server 120 is a server device that authenticates the network device 110 on the cloud, receives and manages the configuration information and operation information. When connecting the network device 110 to the device management server 120, in order to identify and manage the owner of the network device 110, the network device 110 is registered with the device management server 120 in advance.
[0019] The device management server 120 associates the customer company that owns the network device 110 or the service provider company that manages it with the network device 110, and logically separates and manages the information for each customer company and service provider company. When receiving the configuration information and operation information, the device management server 120 authenticates the device management server 120 based on the registered information, issues connection permission information, and waits for the reception of the configuration information and operation information.
[0020] The client terminal 140 is a client terminal directly operated by the user of the service provider company, and a web browser is installed.
[0021] Figure 2 is a diagram showing a hardware configuration example of the server computer that realizes the device management server 120 according to the present embodiment. The device management server 120 includes an output I / F unit 201 connected to an output device such as a display, an input I / F unit 202 connected to an input device such as a keyboard, a storage device 203, a memory 204, a CPU 205, and a communication I / F unit 206.
[0022] The storage device 203 stores an OS, an authentication program for performing authentication and connection processing, a management program for registering and managing the network device 110, registration information of customer companies and network devices 110, received configuration information and operation information, etc. Here, the OS is the Operating System.
[0023] The CPU 205 loads the authentication program and the management program from the storage device 203 into the memory 204 and executes them.
[0024] The communication I / F unit 206 is connected to the network 130 in FIG. 1 and is a network interface that controls communication with the network device 110 that constitutes the device management system 100.
[0025] Note that the figure showing the hardware configuration shown in FIG. 2 corresponds to the hardware block diagram of a general information processing apparatus and is also applicable to the network device 110 and the client terminal 140 of the present embodiment. Therefore, the hardware configuration of the network device 110 is the same.
[0026] FIG. 3 is a diagram showing a functional configuration example of the network device 110 and the device management server 120 that constitute the device management system 100.
[0027] The network device 110 includes a connection code input reception unit 301, a connection establishment unit 302, and a connection management unit 303.
[0028] The device management server 120 creates a tenant, which is a virtual organization within the device management server 120, in order to manage data logically separated for each organization of a customer company or a service providing company, and assigns the created tenant to the customer company or the service providing company. The device management server 120 can manage the data of the network device 110 separately in units of tenants by registering the network device 110 in advance in the tenant assigned to the customer company or the service providing company.
[0029] The connection code input reception unit 301 receives the input of a connection code. The input of the connection code is performed by reading, such as OCR (Optical Character Recognition) or a two-dimensional barcode using the input I / F unit 202, in addition to input by a hard key or touch panel operation of the network device 110.
[0030] The connection code is a character string that identifies the tenant to which the network device 110 is connected within the device management server 120 and for which the device management server 120 permits the connection. By requiring the input of the connection code in the connection to the device management server 120, it prevents connections from the network device 110 without the input of the connection code and enables connection only to the tenant specified at the time of issuance of the connection code.
[0031] The connection establishment unit 302 sends the connection code input by the connection code input reception unit 301 to the device management server 120, and receives the issuance of credential information from the device management server 120, thereby establishing a connection with the device management server 120.
[0032] The connection management unit 303 holds the credential information issued by the device management server 120, authenticates the device management server 120 using the credential information to send data such as setting information and operation information necessary for service provision, and manages the connection state.
[0033] Also, in the present embodiment, particularly when tenant reconnection information is registered in the device management server 120 at the time of authentication to the device management server 120, the connection management unit 303 receives a connection code for performing tenant reconnection from the device management server 120.
[0034] The device management server 120 includes a device information registration unit 311, a connection code issuance unit 312, and a connection permission unit 313.
[0035] The device information registration unit 311 is a functional block that registers information on the network device 110 installed in the customer organization in the tenant and manages the network device 110 logically separated in units of tenants. Based on a registration request from the user, the device information registration unit 311 registers information on the customer organization providing the service in association with the tenant, and registers information on the network device 110 providing the service in the tenant associated with the customer organization.
[0036] When the service ends, the device information registration unit 311 also deletes the information of the network device 110 from the tenant, or deletes the information of the network device 110 for each tenant associated with the customer organization.
[0037] FIG. 6 shows an example of a device management information table 600 registered by the device information registration unit 311 in the storage device 203 of the device management server 120.
[0038] The tenant ID in FIG. 6 is key information for logically separating and managing in units of tenants, and is a tenant ID indicating the tenant that registered the network device 110.
[0039] The device ID is ID information assigned by the device management server 120 when registering the network device 110 in the device management server 120 in order to uniquely identify the network device 110 within the device management server 120. Information on the network device 110 can be registered multiple times under one tenant ID.
[0040] The serial number is individual identification information of the network device 110 assigned at the time of manufacturing the network device 110.
[0041] In addition, the device management information table 600 in FIG. 6 has information such as a device name, a management form, a registration date and time, or installation location information as information on the network device 110.
[0042] The management form is the management form of the network device 110, and is either individual management or centralized management. Individual management represents information that classifies a management method in which each network device 110 manages its connection to the device management server 120, for example. Centralized management represents information that classifies a management method in which a plurality of network devices 110 are centrally managed by another management device for connection, for example.
[0043] In response to a registration request, the device information registration unit 311 registers by associating a tenant ID, a device ID, a serial number, a device name, and a management form as in the device management information table 600. The tenant indicated by the tenant ID is an example of a connected organization within the device management server 120.
[0044] The connection code issuing unit 312 identifies the tenant to which the network device 110 is connected and generates a connection code necessary for the device management server 120 to permit the connection. The connection code issuing unit 312 issues a connection code for identifying the tenant.
[0045] FIG. 7 shows an example of a connection code management table 700 that is generated by the connection code issuing unit 312 and held in the storage device 203 of the device management server 120.
[0046] The tenant ID in FIG. 7 is key information for logically separating and managing in units of the same tenants as the tenant ID in FIG. 6, and is ID information for uniquely identifying the tenant assigned to the customer organization.
[0047] The connection code is a code that is unique within the device management server 120, and one or more can be generated for each tenant ID. Alternatively, the connection code may be generated one for each of the network devices 110 registered in the device management information table 600.
[0048] In this embodiment, the generation of the connection code is performed in response to a reconnection request of the tenant from the network device 110 and often has an expiration date. Since the connection code is unique within the device management server 120, the tenant ID can be identified from the connection code.
[0049] The connection permission unit 313 acts as an authorization server. By receiving a valid connection code and identifying the tenant at the connection destination from the connection code, it issues key information for the device management server 120 to transmit data to the tenant identified by the device management server 120 to the network device 110.
[0050] FIG. 8 shows an example of a device connection credential information table 800 managed by the storage device 203 of the device management server 120 by the connection permission unit 313.
[0051] The tenant ID in FIG. 8 is key information for logically separating and managing in units of the same tenant as the tenant ID in FIG. 6, and is ID information for uniquely identifying the tenant assigned to the customer organization.
[0052] The device ID is ID information for uniquely identifying the network device 110 within the device management server 120 similar to the device ID in FIG. 6.
[0053] The credential is key information for authenticating the network device 110. When receiving a data transmission request from the network device 110, the connection permission unit 313 authenticates the network device 110 using the device ID and this key information, and gives authorization for connection to the network device 110.
[0054] The status is status information indicating the issuance status of the key information to the network device 110. By issuing the key information to the network device 110, the connection permission unit 313 enables the connection to the network device 110, and the status becomes "valid". If the key information has not been issued to the network device 110, the status becomes "invalid".
[0055] The reconnection destination tenant is a tenant ID indicating the destination tenant when the tenant to which the network device 110 is connected is to be re-registered to another tenant. The reconnection destination tenant is usually empty, but the destination tenant can be registered. When the destination tenant is registered, the connection permission unit 313 instructs the network device 110 to reconnect to the tenant specified in the reconnection destination tenant instead of giving permission to connect to the network device 110 when the network device 110 is authenticated.
[0056] The client terminal 140 can refer to the information of the network device 110 of the tenant of the customer company managed by the service provider company, which is created under the tenant of the service provider company of the device management server 120, according to the operation of the user of the service provider company. Thus, the service provider company can provide device management services such as maintenance services for the network device 110 of the customer company to the customer company.
[0057] When the connection code received from the network device 110 is the same as the connection code for identifying the tenant associated with the network device 110, the connection permission unit 313 issues key information (credentials) for connecting to the tenant specified from the connection code to the network device 110.
[0058] When the authentication of the key information received from the network device 110 is successful, the connection permission unit 313 permits the network device 110 to connect to the tenant.
[0059] Figure 4 is a flowchart showing the processing method of the device management server 120 according to the present embodiment. Figure 4 is a flowchart showing the process of deleting the information of the network device 110 for each tenant associated with the customer organization, particularly in the device information registration unit 311 of the device management server 120.
[0060] Next, according to the flowchart of FIG. 4, the tenant deletion process in the device information registration unit 311 when the deletion operation of the tenant associated with the customer organization is performed will be described. The management program of the device management server 120 according to the flowchart of FIG. 4 is stored in the storage device 203 of the device management server 120, read into the memory 204, and executed by the CPU 205.
[0061] In the tenant deletion process in the device information registration unit 311, first, when the deletion of the tenant is instructed, the process of step S401 is performed.
[0062] In step S401, the device information registration unit 311 acquires information on one or more network devices 110 belonging to the tenant of the customer organization instructed in the deletion operation from the information on the network device 110 of FIG. 6 managed by the device information registration unit 311.
[0063] In step S402, the device information registration unit 311 determines whether there is information on an unprocessed network device 110 among the information on the one or more network devices 110 acquired in step S401. If there is information on an unprocessed network device 110, the process proceeds to step S403. If there is no information on an unprocessed network device 110, the process of the flowchart of FIG. 4 ends.
[0064] In step S403, the device information registration unit 311 determines whether the status of the device connection credential information table 800 of FIG. 8 corresponding to the network device 110 to be processed is valid. If the status is valid, since key information has been issued to the network device 110, the process proceeds to step S404. If the status is invalid, since key information has not been issued to the network device 110, it is determined that the connection does not need to be maintained for that network device 110, and the process proceeds to step S406.
[0065] In step S404, the device information registration unit 311 determines whether the management form of the device management information table 600 in FIG. 6 corresponding to the network device 110 to be processed is a management form that requires maintaining the connection of the network device 110. For example, when the management form of the device management information table 600 is centralized management, the device information registration unit 311 determines that it is a management form that does not require maintaining the connection of the network device 110. Also, when the management form of the device management information table 600 is individual management, the device information registration unit 311 determines that it is a management form that requires maintaining the connection of the network device 110.
[0066] If it is a management form that requires maintaining the connection of the network device 110, the process proceeds to step S405. If it is a management form that does not require maintaining the connection of the network device 110, the process proceeds to step S406.
[0067] In step S405, even if the tenant to which the network device 110 belongs is deleted, the device information registration unit 311 exceptionally retains the information of the network device 110 in the device connection credential information table 800 without deletion in order to maintain the connection. Since the device information registration unit 311 cannot connect the network device 110 to the tenant that should have been deleted, it registers the changed destination tenant in the reconnection destination tenant so as to change the connection destination to the tenant of the organization that manages the tenant of the customer organization to be deleted. That is, the device information registration unit 311 retains the key information, etc. of the network device 110 associated with the tenant without deletion and registers the changed destination tenant as the reconnection destination tenant. Thereafter, the process returns to step S402, and the process for the next network device 110 is repeated.
[0068] In step S406, the device information registration unit 311 deletes the information of the network device 110 from the device management information table 600 and the device connection credential information table 800, together with the deletion of the tenant. That is, the device information registration unit 311 deletes the key information etc. of the network device 110 associated with the tenant. Thereafter, the process returns to step S402, and the process for the next network device 110 is repeated.
[0069] FIG. 5 is a flowchart showing a processing method of the device management server 120 according to the present embodiment. FIG. 5 is a flowchart showing a process of permitting connection from the network device 110 for which key information has already been issued, among the connection permission processes of the network device 110 in the connection permission unit 313 of the device management server 120.
[0070] Hereinafter, according to the flowchart of FIG. 5, the connection permission process of the connection permission unit 313 that authenticates the network device 110 and permits connection to or instructs re-registration of the network device 110 will be described. Note that the management program of the device management server 120 according to the flowchart of FIG. 5 is stored in the storage device 203 of the device management server 120, read into the memory 204, and executed by the CPU 205.
[0071] In the connection permission process from the network device 110 for which key information has already been issued in the connection permission unit 313, first, the process of step S501 is performed.
[0072] In step S501, the connection permission unit 313 receives a connection request from the network device 110, and authenticates the network device 110 based on the key information and the device ID received from the network device 110.
[0073] In step S502, the connection permission unit 313 determines whether or not the authentication in step S501 is successful. If the authentication is successful, the process proceeds to step S503. If the authentication fails, the process proceeds to step S506.
[0074] In step S503, the connection permission unit 313 acquires information on the reconnection destination tenant of the network device 110 from the device connection credential information table 800. Then, the connection permission unit 313 determines whether or not the new destination tenant is registered as the reconnection destination tenant. If the new destination tenant is registered, the process proceeds to step S504. If the new destination tenant is not registered, the process proceeds to step S505.
[0075] In step S504, the connection permission unit 313 instructs the network device 110 to reconnect to the changed-to tenant registered as the re-connection destination tenant, instead of issuing permission in response to the connection request from the network device 110. Specifically, in response to the connection request from the network device 110, the connection permission unit 313 has the connection code issuing unit 312 issue a connection code for identifying the changed-to tenant registered as the re-connection destination tenant, and returns (transmits) the connection code to the network device 110.
[0076] Alternatively, the connection permission unit 313 returns a response prompting the network device 110 to make a request for issuance of a connection code. Then, when the connection permission unit 313 receives a subsequent request for issuance of a connection code from the network device 110, the connection permission unit 313 issues to the network device 110 a connection code for connecting to the tenant specified as the re-connection destination tenant.
[0077] The network device 110 switches the connection destination tenant by receiving issuance of key information for transmitting data to the tenant specified as the re-connection destination tenant using the issued connection code from the connection permission unit 313. After that, the network device 110 transmits a connection request including the issued key information of the re-connection destination tenant and the device ID to the device management server 120, and the device management server 120 becomes connectable by the processing in Fig. 5. After that, the processing in the flowchart in Fig. 5 ends.
[0078] In step S505, the connection permission unit 313 issues connection permission information such as an access token for the connection request from the network device 110, and returns it to the network device 110. The connection permission information is information for permitting connection to the tenant corresponding to the above key information. Thereby, the network device 110 can send the setting information and the operation information to the device management server 120 with the connection permission information attached. Thereafter, the process of the flowchart in FIG. 5 ends.
[0079] In step S506, the connection permission unit 313 returns an authentication error to the network device 110. Thereafter, the process of the flowchart in FIG. 5 ends.
[0080] In the present embodiment described in detail above, even when the tenant associated with the customer organization is deleted from the device management server 120, the connection between the network device 110 and the device management server can be maintained. Thereby, without the network device 110 performing a connection operation again, by registering the information of the network device 110 in a new tenant of the device management server 120, it can be connected to the new tenant.
[0081] The device management server 120 enables the connection between the network device 110 and the device management server 120 to be maintained even when a tenant is deleted from the device management server 120. Thereby, the device management server 120 can connect to the changed tenant of the network device 110 by registering the changed tenant of the network device 110 without the network device 110 performing a connection operation again.
[0082] (Other Embodiments) The present disclosure can also be implemented by supplying a program that implements one or more functions of the above-described embodiments to a system or apparatus via a network or a storage medium, and causing one or more processors in a computer of the system or apparatus to read and execute the program. It can also be implemented by a circuit (for example, ASIC) that implements one or more functions.
[0083] Note that the above-described embodiments are merely specific examples for implementing the present disclosure, and the technical scope of the present disclosure is not limitedly interpreted by these. That is, the present disclosure can be implemented in various forms without departing from its technical idea or its main features.
[0084] The disclosure of the present embodiment includes the following configurations and methods. (Configuration 1) A device management system including a device and a device management server, wherein the device management server has device information registration means for registering by associating the device with a destination organization in the device management server in response to a registration request; connection code issuance means for issuing a connection code for specifying the destination organization; when the connection code received from the device is the same as the connection code for specifying the destination organization associated with the device, issues key information for connecting to the destination organization specified from the connection code to the device, and when authentication of the key information received from the device is successful, has connection permission means for permitting the device to connect to the destination organization; the device information registration means, when deletion of the destination organization is instructed, retains the key information of the device associated with the destination organization without deleting it, and registers the destination organization of the change destination; the connection permission means If the authentication of the key information received from the device is successful and the connection destination organization of the change destination is registered, a connection code for specifying the connection destination organization of the change destination is transmitted to the device. A device management system characterized in that, if the authentication of the key information received from the device is successful and the connection destination organization of the change destination is not registered, the device is permitted to connect to the connection destination organization. (Configuration 2) The device information registration means If the deletion of the connection destination organization is instructed and key information has been issued to the device, the key information of the device associated with the connection destination organization is retained without being deleted, and the connection destination organization of the change destination is registered. The device management system according to Configuration 1, characterized in that, if the deletion of the connection destination organization is instructed and key information has not been issued to the device, the key information of the device associated with the connection destination organization is deleted. (Configuration 3) The device information registration means If the deletion of the connection destination organization is instructed and the management form of the device is the first management form, the key information of the device associated with the connection destination organization is retained without being deleted, and the connection destination organization of the change destination is registered. The device management system according to Configuration 1 or 2, characterized in that, if the deletion of the connection destination organization is instructed and the management form of the device is the second management form, the key information of the device associated with the connection destination organization is deleted. (Configuration 4) The first management form is individual management. The device management system according to Configuration 3, characterized in that the second management form is centralized management. (Configuration 5) The device information registration means When the deletion of the destination organization is instructed, the key information for the device has been issued to the device, and the management form of the device is individual management, the key information of the device associated with the destination organization is retained without being deleted, and the destination organization of the change destination is registered. When the deletion of the destination organization is instructed, the key information has not been issued to the device, or the management form of the device is centralized management, the device management system according to any one of Configurations 1 to 4, characterized in that the key information of the device associated with the destination organization is deleted. (Configuration 6) When the connection permission means successfully authenticates the key information received from the device and the destination organization of the change destination is not registered, the connection permission information for permitting the device to connect to the destination organization is transmitted to the device. The device management system according to any one of Configurations 1 to 5. (Method 1) A processing method of a device management system including a device and a device management server, A device information registration step in which the device management server registers by associating the device with a destination organization in the device and the device management server in response to a registration request; A connection code issuance step in which the device management server issues a connection code for specifying the destination organization; When the connection code received from the device is the same as the connection code for specifying the destination organization associated with the device, key information for connecting to the destination organization specified from the connection code is issued to the device, and when the authentication of the key information received from the device is successful, a connection permission step of permitting the device to connect to the destination organization. In the device information registration step, when the deletion of the destination organization is instructed, the key information of the device associated with the destination organization is retained without being deleted, and the destination organization of the change destination is registered. In the connection permission step, If the authentication of the key information received from the device is successful and the destination connection organization is registered, a connection code for identifying the destination connection organization is transmitted to the device. A processing method for a device management system, characterized in that when the authentication of the key information received from the device is successful and the destination connection organization is not registered, the device is permitted to connect to the connection organization.
Description of Signs
[0085] 110 Network device, 120 Device management server, 130 Network, 140 Client terminal, 301 Connection code input reception unit, 302 Connection establishment unit, 303 Connection management unit, 311 Device information registration unit, 312 Connection code issuance unit, 313 Connection permission unit
Claims
1. A device management system including a device and a device management server, wherein the device management server includes: device information registration means for registering, in response to a registration request, by associating the device with a destination organization within the device management server; connection code issuing means for issuing a connection code for specifying the destination organization; connection permission means for, when the connection code received from the device is the same as the connection code for specifying the destination organization associated with the device, issuing key information for connecting to the destination organization specified from the connection code to the device, and permitting connection of the device to the destination organization when authentication of the key information received from the device is successful; wherein the device information registration means, when deletion of the destination organization is instructed, retains the key information of the device associated with the destination organization without deleting it, and registers a new destination organization; wherein the connection permission means: when authentication of the key information received from the device is successful and the new destination organization is registered, transmits a connection code for specifying the new destination organization to the device; when authentication of the key information received from the device is successful and the new destination organization is not registered, permits connection of the device to the destination organization. A device management system according to claim 1, characterized in that:
2. wherein the device information registration means: when deletion of the destination organization is instructed and key information has been issued to the device, retains the key information of the device associated with the destination organization without deleting it, and registers a new destination organization; when deletion of the destination organization is instructed and key information has not been issued to the device, deletes the key information of the device associated with the destination organization.
3. wherein the device information registration means: when deletion of the destination organization is instructed and the management mode of the device is the first management mode, retains the key information of the device associated with the destination organization without deleting it, and registers a new destination organization; The device management system according to claim 1, wherein when deletion of the destination organization is instructed and the management mode of the device is the second management mode, key information of the device associated with the destination organization is deleted.
4. The first management mode is individual management, The device management system according to claim 3, wherein the second management mode is centralized management.
5. The device information registration means, when deletion of the destination organization is instructed, key information has been issued for the device, and the management mode of the device is individual management, the key information of the device associated with the destination organization is retained without being deleted, and the destination organization of the change destination is registered, The device management system according to claim 1, wherein when deletion of the destination organization is instructed, key information has not been issued for the device, or the management mode of the device is centralized management, the key information of the device associated with the destination organization is deleted.
6. The connection permission means transmits connection permission information for permitting the device to connect to the destination organization when authentication of the key information received from the device is successful and the destination organization of the change destination is not registered, the device management system according to claim 1.
7. A processing method of a device management system including a device and a device management server, a device information registration step in which the device management server registers by associating the device with a destination organization in the device and the device management server in response to a registration request; a connection code issuance step in which the device management server issues a connection code for specifying the destination organization; when the connection code received from the device is the same as the connection code for specifying the destination organization associated with the device, key information for connecting to the destination organization specified from the connection code is issued to the device, and when authentication of the key information received from the device is successful, a connection permission step of permitting the device to connect to the destination organization; In the device information registration step, when deletion of the destination organization is instructed, the key information of the device associated with the destination organization is retained without being deleted, and the destination organization of the change destination is registered, In the connection permission step, if the authentication of the key information received from the device is successful and the destination connection organization is registered, a connection code for identifying the destination connection organization is transmitted to the device. if the authentication of the key information received from the device is successful and the destination connection organization is not registered, the device is permitted to connect to the connection organization. A processing method for a device management system is characterized by this.
Citation Information
Patent Citations
Device management system, peripheral device, and control method therefor
JP2014081779A
Registration management method of customer company's network device on device management server
JP2021125761A