Information processing system, control method of information processing system, and program

The information processing system addresses the challenge of managing network services for printers used for both business and personal purposes by determining and classifying print jobs based on user group affiliations, improving policy enforcement and convenience.

JP2025110082APending Publication Date: 2025-07-28CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024003805
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-01-15
Publication Date
2025-07-28

AI Technical Summary

Technical Problem

Existing systems fail to adequately manage network services for printers used for both business and personal purposes, leading to potential misuse and impaired convenience when policies are uniformly applied.

Method used

An information processing system that includes management means to determine permitted services for user groups, associating print jobs with classification information indicating in-group or out-of-group use, enabling more precise management of printing purposes.

Benefits of technology

Enables more suitable management of printing purposes, allowing organizations to enforce policies based on user group affiliations, enhancing convenience and control over network service usage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025110082000001_ABST
    Figure 2025110082000001_ABST
Patent Text Reader

Abstract

To make it possible to manage whether printing is for a special purpose or not in a more suitable manner when the printing is based on print data held in a network service.SOLUTION: A tenant information management unit 321 manages, for each group, services permitted to be used by users belonging to each group. When a print job is acquired from an external service in response to a print request from a user, the tenant information management unit 321 determines whether or not the use of the external service is permitted to a group to which the user belongs. When it is determined that the use of the external service is permitted for a target group, a device-by-device print job data management unit 301 manages the print job by associating classification information indicating an intended use with the print job, and when it is determined that the use of the external service is not permitted for the group, manages the print job by associating classification information indicating an unintended use with the print job.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing system, a control method for an information processing system, and a program.

Background Art

[0002] In recent years, a form of cloud computing in which a server provides services to clients via a network has attracted attention. The main feature of cloud computing is to distributively execute data collection and data analysis processing using a large number of computing resources, and to process requests from many clients in parallel by distributed parallel processing. Particularly in recent years, various vendors have provided a wide variety of services by implementing network services on a cloud computing environment that realizes this cloud computing. In the development of network services such as cloud services, it is also expected to have advantages such as an improvement in development speed and a reduction in development costs by effectively utilizing various services already provided on the network to provide new functions. In addition, in recent years, many devices have been connected to the Internet, and "IoT: Internet of Things", which controls various devices and transmits the operation data of the devices to the cloud and then uses it on the cloud, has begun to widely penetrate the general public. Even in an office environment, many devices such as multifunction printers, projectors, and network cameras are operating and sending data to cloud services.

[0003] In addition, with the diversification of work styles, the need for hybrid work is increasing. There are an increasing number of cases where cloud printing services, scanner services, consumable shipping services, etc., which are cloud services for printers or users, are used together with printers in shared offices or at home. There are also cases where employees of each organization use a common printer in a shared office together with the cloud service contracted by each organization. In addition, in the case of telecommuting, it is also conceivable that multiple employees in the same household work for different organizations but use the same household-owned printer together with the cloud services contracted by each organization. When one printer is used for both personal and business purposes due to telecommuting or the like, the method disclosed in Patent Document 1 can be cited as a method for distinguishing whether printing is for personal use or business use. In Patent Document 1, a method is proposed in which it is determined whether the corresponding image data is business data from the content of the image data and the data source, and in the case of business data, image data indicating business use is added to the print data. By applying such a technique, it becomes possible to determine whether the use of the printer is for personal use or business use.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] On the other hand, depending on the group such as a company, there are cases where network services available for specific purposes such as business are restricted according to the policies of the group. Under such circumstances, even when a privately used printer is used for a specific purpose such as business, control according to the policies of the target group (for example, a company) may be required. On the contrary, when the device such as a printer is used for other purposes other than a specific purpose such as business, such as when it is used personally, there is no restriction on the available network services. Therefore, when one printer is used for both a specific purpose such as business and other purposes other than such purpose such as private use due to telecommuting etc., if the available network services are uniformly restricted, the convenience may be impaired when using it for the other purposes.

[0006] In view of the above problems, the present invention enables more suitable management of whether printing based on print data held in network services is for a special purpose or not.

Means for Solving the Problems

[0007] The information processing system according to the present invention includes: a first management means for managing services permitted for use by users belonging to a group for each group defined in advance; a determination means for determining, in the first management means, whether use of the external service is permitted for the group to which the user belongs when a print job is acquired from an external service as a print target in response to a print request from the user; and a second management means for associating classification information indicating in-group use with the print job and managing it by associating classification information indicating out-of-group use with the print job when it is determined by the determination means that use of the external service is not permitted for the group to which the user belongs.

Effects of the Invention

[0008] According to the present invention, when performing printing based on print data held in a network service, it becomes possible to manage whether or not the printing is for a special enemy purpose in a more suitable manner.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Embodiments for Carrying Out the Invention

[0010] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. In this specification and the drawings, components having substantially the same functional configuration are denoted by the same reference numerals, and redundant description is omitted.

[0011] <First Embodiment> (System Configuration) Referring to FIG. 1, as an example of the system configuration of an information processing system according to an embodiment of the present disclosure, attention will be paid to the case where the information processing system is realized as a print control system and described.

[0012] Networks 100 and 101 are realized by various networks such as, for example, the Internet, LAN (Local Area Network), WAN (Wide Area Network), telephone lines, dedicated digital lines, etc. Further, Networks 100 and 101 may be realized by an ATM (Asynchronous Transfer Mode) line, a frame relay line, a cable TV line, a wireless line for data broadcasting, etc. In this embodiment, for convenience, the Internet is applied as Network 100 and a local network is applied as Network 101, and various explanations will be given on this assumption.

[0013] Each of the image forming apparatus 102 and the client terminal 103 can access various cloud services (network services) on the Internet 100 by accessing the Internet 100 via the local network 101. In the example shown in FIG. 1, as cloud services on the Internet 100, an IoT device management service 104, a print service 105, a tenant management service 106, and an application service 107 are illustrated.

[0014] The client terminal 103 is realized by a device that can access a network such as, for example, a personal computer or a mobile terminal, serves as a user input / output interface, and can execute various data processes in response to instructions from the user. Further, the client terminal 103 issues a print job transmission to the image forming apparatus 102, a print instruction to the print service 105, etc. in response to instructions from the user. The image forming apparatus 102 corresponds to a device having a printing function and can be realized, for example, by a so-called multifunction peripheral (MFP). Further, the image forming apparatus 102 may be configured to have a copy function, a scanner function, a fax transmission function, etc. in addition to the printing function. The local network 101 corresponds to the LAN to which the above-described client terminal 103 and the image forming apparatus 102 are connected. Each of the client terminal 103 and the image forming apparatus 102 is connected so as to be able to transmit and receive data to and from each other via the local network 101.

[0015] The IoT device management service 104 corresponds to a service that manages the registration information of the image forming apparatus 102, and notifies the image forming apparatus 102 that is the management target of a print job from the print service. Further, the IoT device management service 104 collects operation event data such as print processing from the image forming apparatus 102 and manages the operation event data. The print service 105 corresponds to a cloud service that provides various services related to printing of printed matter (so-called print service) to the users of the contracted tenant and the image forming apparatus 102. The print service 105 acquires image data from the client terminal 103 or the application service 107, and generates a print job based on the image data. Note that the print service 105 may be realized as a service that operates in cooperation with various services such as a scan service, a consumable automatic delivery service, a monitoring service, and a failure management service. The tenant management service 106 holds information on cloud services permitted for business use in units of tenants. The tenant management service 106 determines whether or not the business use of the application service 107 used by the print service 105 when creating print data is permitted based on the business use permitted cloud service information. The application service 107 corresponds to a cloud service that manages image data.

[0016] Here, each of the services described above with reference numerals 104 to 107 can be publicly provided on the Internet as a cloud service that is redundant with multiple servers. The functions of each service may be realized by a single server or a single virtual server, or may be realized by a plurality of servers or a plurality of virtual servers. Further, as another example, the functions of each service may be realized by a plurality of virtual servers operating on a single server. Also, each of the services described above with reference numerals 104 to 107 may be integrated and operated as one service.

[0017] (Hardware Configuration of Image Forming Apparatus) With reference to FIG. 2(a), an example of the hardware configuration of the image forming apparatus 102 according to the present embodiment will be described. Each component (device) of the image forming apparatus 102 to be described later with reference to FIG. 2(a) is connected so as to be able to transmit and receive information to and from each other via a system bus 200.

[0018] The CPU (Central Processing Unit) 201 corresponds to a control device (central processing unit) that controls the entire apparatus, and comprehensively controls access to various devices connected to the system bus 200. This control is realized based on, for example, a control program or resource data (resource information) stored in an external memory 206 connected to a ROM (Read Only Memory) 202 or a DKC (Disk Controller) 205. The RAM (Random Access Memory) 203 is a storage area that functions as a main memory, a work area, etc. of the CPU 201. Also, the RAM 203 may be configured such that the memory capacity can be expanded by an optional RAM connected to an expansion port (not shown). The storage device 210 is an external storage device that functions as a large-capacity storage area, and stores each program shown with reference numerals 340 to 347, the details of which will be described later with reference to FIG. 3(f).

[0019] The operation panel (operation unit) 209 corresponds to a so-called user interface, and presents information to the user by screen display and accepts instructions from the user via the screen. Further, the operation panel 209 may include various interfaces such as buttons and display panels for performing operations such as setting the operation mode of the image forming apparatus 102, displaying the operation status of the image forming apparatus 102, and specifying copying. The network controller 204 is realized by a so-called network interface card (NIC), and exchanges data with an external device.

[0020] The print engine 208 corresponds to a device that realizes various functions related to printing. In this embodiment, the print engine 208 can apply a known printing technology, and for example, an electrophotographic method (laser beam method), an inkjet method, a sublimation method (thermal transfer method), etc. can be applied. The raster controller 207 is a controller that converts print data described by PDL (Page Description Language) or PDF (Portable Document Format) into image data. The device I / F (Interface) 211 is a connection interface for connecting an external device based on a standard such as USB (Universal Serial Bus).

[0021] (Hardware Configuration of Client Terminal and Server) Referring to FIG. 2(b), an example of the hardware configuration of an information processing apparatus applicable as a server for realizing the client terminal 103 and each service indicated by reference numerals 104 to 106 in FIG. 1 will be described. As described above, the configuration for realizing each service indicated by reference numerals 104 to 106 is not particularly limited, and the method of applying a server having the hardware configuration illustrated in FIG. 2(b) for realizing these services is also not limited. Further, each component (device) of the information processing apparatus described later with reference to FIG. 2(b) is connected so as to be able to transmit and receive information to and from each other via the system bus 219.

[0022] The CPU 220 corresponds to a control device (central processing unit) that controls the entire apparatus, and executes an application program, an operating system (OS), and an IoT device management system program, the details of which will be described later, stored in the storage device 225. Further, the CPU 220 temporarily stores information, files, etc. used in the execution of each of the programs exemplified above in the RAM 222. The ROM 221 is a storage area that stores programs such as a basic I / O program and various data. The RAM 222 is a storage area that functions as the main memory and work area of the CPU 220. The network controller 223 is realized by a so-called network interface card and exchanges data with an external device. The input control unit 224 serves as an interface for exchanging data with an external device. The storage device 225 is an external storage device that functions as a large-capacity storage area, and stores programs such as application programs and OS, and various data.

[0023] (Software Configuration of IoT Device Management Service) Referring to FIG. 3(a), an example of the software configuration of the IoT device management service 104 will be described. Each software module is stored in the storage device 225 shown in FIG. 2(b) and is expanded and executed in the RAM 222 by the CPU 220 as described above.

[0024] The receiving unit 300 provides various interfaces of the IoT device management service 104 based on a predetermined communication protocol and verifies the validity of the received information. As the communication protocol, for example, HTTP (Hypertext Transfer Protocol) can be applied. HTTP corresponds to an example of a protocol standardly used on the Web and can be applied, for example, to the cooperation between servers or the cooperation between a Web Browser and a server. In addition, the receiving unit 300 may be connected to the image forming apparatus 102 by a protocol called MQTT (Message Queue Telemetry Transport). MQTT corresponds to an example of a protocol standardly used on the Web and can be applied to communication in IoT devices, such as performing Push notifications between IoT devices. In addition, the receiving unit 300 receives print job notification information and a notification request from the print service 105 to the image forming apparatus 102 and performs a print job notification to the image forming apparatus 102.

[0025] The per-device print job data management unit 301 manages the print job data to be notified to the image forming apparatus 102. An example of the per-device print job data is shown in Table 1.

[0026]

Table 1

[0027] The per-device print job data includes a job ID, a tenant ID, a device ID, a print job URL, and a classification. The job ID is an ID that uniquely identifies the per-device print job data and may be common with the ID that identifies the print job in the print service 105. The tenant ID is a tenant identifier managed by the tenant management service 106. The device ID is an ID that uniquely identifies the image forming apparatus 102. The print job URL is a URL for acquiring the print job from the print service 105. Note that depending on the configuration of the print service 105, the print job URL may not be stored and only the job ID may be managed. The per-device print job data is job notification information created by an external service that is cooperating with the IoT device management service, and is received by the receiving unit 300 of the IoT device management service 104 and stored in the storage 303. The classification is an identifier indicating whether the corresponding job is for business use or personal use. Note that the per-device print job data management unit 301 corresponds to an example of a second management unit that manages by associating classification information indicating whether the print job is for unauthorized use (e.g., business use) or authorized use (e.g., personal use).

[0028] The event data management unit 302 manages the event data transmitted from the image forming apparatus 102 and stores it in the storage 303. The event data is data in which an event that occurred in the image forming apparatus 102 is transmitted by the controller 346 described later to the IoT device management service 104 via the receiving unit 344 described later. The receiving unit 300 of the IoT device management service 104 receives this data and stores it in the storage 303 as event data. Table 2 shows an example of the event data.

[0029]

Table 2

[0030] Event data includes a job ID, a tenant ID, a device ID, a generation date and time, and a classification. The job ID and the tenant ID are IDs acquired from the IoT device management service. The device ID is an ID that uniquely identifies the image forming apparatus 102. The generation date and time is the date and time when an event occurred in the image forming apparatus 102, and in the present embodiment, it indicates the date and time when printing was executed. The classification is an identifier indicating whether the corresponding event is for use within a predetermined purpose or for use outside the purpose, and in the present embodiment, either business use (use within the purpose) or personal use (use outside the purpose) is set. Also, in the present embodiment, the same classification is applied with a common value as the classification information included in the print job. Note that the classification is not received from the device as event data, but may be added by referring to the per-device print job data based on the job ID when the IoT device management service stores the event data in the storage 303. Note that the event data management unit 302 corresponds to an example of a third management unit that manages logs related to the execution of printing for a print job.

[0031] (Software Configuration of Print Service) With reference to FIG. 3(b), an example of the software configuration of the print service 105 will be described. In the present embodiment, an example in which the print service is realized as a single service will be described. Each software module is stored in the storage device 225 shown in FIG. 2(b) and is developed and executed in the RAM 222 by the CPU 220 as described above.

[0032] The receiving unit 310 is realized by, for example, a web server, provides various interfaces of the print service 105 according to a predetermined protocol (for example, HTTP), and verifies the validity of the received information. The receiving unit 310 receives a print instruction or a job acquisition request from the client terminal 103 or the image forming apparatus 102. The job management unit 311 receives information specifying a document to be printed based on a print instruction from the client terminal 103, and acquires the specified document from the application service 107. Then, the job management unit 311 converts the acquired document into a print job and stores the print job in the storage 312. Here, the text stored in the storage of the print service 105 may be converted into a print job, or the text transmitted from the client terminal 103 may be converted into a print job. In addition, in response to a print job acquisition request from the image forming apparatus 102, the job management unit 311 creates a temporary signed URL of the storage 312 where the print job is stored, and returns the URL to the image forming apparatus 102.

[0033] (Software Configuration of Tenant Management Service) Referring to FIG. 3(c), an example of the software configuration of the tenant management service 106 will be described. Each software module is stored in the storage device 225 shown in FIG. 2(b), and is expanded and executed in the RAM 222 by the CPU 220 as described above.

[0034] The reception unit 320 is realized by, for example, a web server, provides various interfaces of the tenant management service 106 in a predetermined protocol (for example, HTTP), and verifies the validity of the received information. The tenant information management unit 321 manages tenant information and user information. Here, an example of tenant information is shown in Table 3, and an example of user information is shown in Table 4.

[0035]

Table 3

[0036] Tenant information includes a tenant ID, an organization name, and permitted sites. The tenant ID is an identifier used to manage users as tenants in units such as organizations or companies (group units classified according to various conditions). The organization name is a character string representing the organization. The permitted sites are a list of sites that the target tenant has permitted for business use. Note that instead of permitted sites, denied sites may be managed, or both permitted sites and denied sites may be managed. Also, the management of permitted sites is not limited to the form of management by domain name, and may be managed by site name, IP, certificate information, etc. User information includes a user ID, a password, and a tenant ID. The user ID is an identifier of the user. The password is a character string used for user authentication in combination with the user ID. The tenant ID indicates the tenant to which the target user belongs. Note that the tenant information management unit 321 corresponds to an example of a first management unit that manages services permitted for use by users belonging to a group defined in advance, such as a company.

[0037] (Software Configuration of Application Service) Referring to FIG. 3(d), an example of the software configuration of the application service 107 will be described. In this embodiment, an example in which the application service 107 is realized as a document management service will be described. Also, each software module is stored in the storage device 225 shown in FIG. 2(b) and is expanded and executed in the RAM 222 by the CPU 220 as described above.

[0038] The receiving unit 330 is realized by, for example, a web server, provides various interfaces of the application service 107 according to a predetermined protocol (for example, HTTP), and verifies the validity of the received information. The receiving unit 330 receives a document acquisition request from the client terminal 103 or the print service 105. Upon receiving an instruction to acquire a document from the client terminal 103, the Application Management Unit 331 receives information specifying the document, and based on this information, creates and returns a temporary signed URL for accessing the document data stored in the storage 332. Note that the Application Management Unit 331 may be configured to return an ID indicating the corresponding document instead of creating a signed URL.

[0039] (Software Configuration of Client Terminal) With reference to FIG. 3(e), an example of the software configuration of the client terminal 103 will be described. The client application 351 represents general electronic data processing software that creates, displays, and edits electronic data.

[0040] Here, a use case where a user uses the client application 351 to display electronic data stored in a cloud service in a predetermined display area and print the content thereof will be described. When the user performs printing using the print service 105 on the displayed electronic data, printing is executed by specifying the cloud print driver 350. When the authentication with the print service 105 is successful, the cloud print driver 350 accesses the receiving unit 310 and notifies the print service 105 of the identification information for specifying the electronic data to be printed. The print service 105 converts the electronic data to be printed into a print job, deploys it to the storage 312, and sends a print notification to the IoT device management service 104. The IoT device management service 104 sends a print job notification to the image forming apparatus 102. The image forming apparatus 102 accesses the print service based on the information in the print job notification, acquires the print job, and executes printing on the print job. In the present embodiment, the image forming apparatus 102 acquires the print job by accessing the temporary signed URL of the print service included in the print job notification.

[0041] Next, a use case where the user uses the client application 351 to display the electronic data stored in the client terminal 103 in a predetermined display area and print the content will be described. When the user specifies the cloud print driver 350 to execute printing, the cloud print driver 350 accesses the print service 105. When the authentication between the cloud print driver 350 and the application service 107 is successful, the cloud print driver 350 accesses the receiving unit 310 and transmits the data stored in the client terminal 103 to the print service 105. When the print service 105 receives the data to be printed, it converts the data into a print job and deploys it to the storage 312, and sends a print notification to the IoT device management service 104. Note that the subsequent operations are substantially the same as those when printing is performed on the electronic data stored in the cloud service.

[0042] (Software Configuration of the Image Forming Apparatus) With reference to FIG. 3(f), an example of the software configuration of the image forming apparatus 102 will be described. The image forming apparatus 102 controls the operation of each application by the CPU 201 executing the OS stored in the ROM 202 or the external memory 206.

[0043] The OS 340 is the basic software (Operating System) of the image forming apparatus 102. Generally, a real-time OS is used, but recently, a general-purpose OS such as Linux (registered trademark) may also be used. The virtual machine 341 is a virtual application execution environment that operates as an application controlled by the OS. For example, the Java (registered trademark) VM is well known.

[0044] The application management framework 342 has a function of managing the life cycle of an application to be managed that operates on the application execution environment provided by the virtual machine 341. Further, the application management framework 342 has an I / F for controlling the life cycle of the application and an I / F publishing function for mediating processing requests between applications. The life cycle is assumed to indicate the state of the application, including installation, startup, stop, and uninstallation of the application. The application management framework 342 according to the present embodiment will be described as OSGi (registered trademark) defined by the OSGi (Open Services Gateway initiative) alliance.

[0045] The IoT client 343 is an application that operates in the application execution environment provided by the virtual machine 341. These applications are identified by the ApplicationID, and the life cycle is managed by the application management framework 342. Note that the application operating in the application management framework 342 may be held by the image forming apparatus 102 by default. Further, an application may be installed later via the application management framework 342. The IoT client 343 is a client application of the IoT device management service 104 and controls communication between the image forming apparatus 102 and the IoT device management service 104. The IoT device receiving unit 344 connects to the IoT device management service 104 at startup. Further, the IoT device receiving unit 344 receives a print job notification from the IoT device management service 104. Note that the IoT device receiving unit 344 may be configured to communicate with the IoT device management service 104 periodically instead of receiving a notification from the IoT device management service 104.

[0046] The command control unit 345 acquires a print job according to an instruction from the IoT device reception unit 344. Also, the command control unit 345 transmits the event data generated by the job execution unit 347 to the IoT device management service 104. The controller 346 is control software that performs function processing and state management such as printing, copying, and FAX of the image forming apparatus 102. The job execution unit 347, for example, receives a print job from the client terminal 103, executes a print process, and generates data (event data) regarding an event generated by a change in the state of the print process or the device state.

[0047] (Sequence for printing from a cloud service) With reference to FIG. 4, an example of a sequence will be described in which printing is performed by an image forming apparatus on text data managed by a cloud service.

[0048] In S401, the client terminal 103 accesses the application service 107 and makes a request to acquire data to be printed. The application service 107 issues identification information for specifying the text designated as the print target, and notifies the client terminal 103 of the identification information as a response to the acquisition request. As this identification information, a temporary signed URL for accessing the corresponding text may be applied, or an individual ID may be applied. In this embodiment, it is assumed that a user with the user ID "User1" instructs the printing of text 001 of the application service 107, and the application service 107 issues a temporary signed URL "https: / / xxx.com / onetime1".

[0049] On the client terminal 103, the cloud print driver 350 performs print settings in S402 and issues a print instruction to the IoT device management service 104 in S403. When the authentication with the IoT device management service 104 is successful, the cloud print driver 350 accesses the receiving unit 310 and transmits the identification information issued by the application service 107 in S401 to the IoT device management service 104. In this embodiment, it is assumed that a print instruction is issued by specifying the device ID "XXX".

[0050] In S404, based on the print instruction information, the IoT device management service 104 determines whether the site that holds the target print data has been permitted for business use by the tenant (in other words, whether it is within the scope of intended use). Specifically, the IoT device management service 104 requests the tenant management service 106 to obtain the permitted site information of the tenant to which the user who issued the print instruction belongs. Based on the specified user information, the tenant management service 106 returns the permitted site information of the tenant to which the target user belongs to the IoT device management service 104 as a response to the above acquisition request. After that, the IoT device management service 104 determines whether the site for which the print instruction was given is available for business use based on the received permitted site information. In this embodiment, it is assumed that "User1" belongs to the tenant with the tenant ID "AAA", and it is determined that this service is available for business use from the domain "xxx.com" of "https: / / xxx.com / onetime1". Note that the determination of whether it is available for business use is not limited to the configuration performed by the IoT device management service 104. For example, a configuration may be applied in which the determination is made by the tenant management service 106 and whether it is available for business use is returned as a response in S404.

[0051] In S405, the IoT device management service 104 transmits the identification information to the print service 105 and issues a print job generation request. In S406, based on the acquired identification information, the print service 105 makes a request to the application service 107 to obtain print data. The application service 107 identifies the print data based on the specified identification information and returns the identified print data as a response to the above acquisition request. In this embodiment, it is assumed that the print service 105 accesses "https: / / xxx.com / onetime1" and obtains Article 001.

[0052] In S407, the print service 105 generates a print job using the acquired text data, saves it in the storage 312, and generates information for accessing the generated print job. In this embodiment, it is assumed that a temporary signed URL "https: / / xxx.com / job1" is issued as information for accessing the created job. In S408, the print service 105 notifies the IoT device management service 104 as a response to the print job generation request in S405, using the information for accessing the created print job as print job data. The IoT device management service 104 associates the category identified in S404 with the received print job data and saves it as device-specific print job data. In this embodiment, since print data is acquired from a cloud service that can be used for business in S404, the IoT device management service 104 saves it with the category set to "business" and associated with the print job URL "https: / / xxx.com / job1". Note that the notification of the print job may not be made as a response to the print job generation request in S405, but may be made as a response to an inquiry made by the IoT device management service 104 periodically to the print service 105.

[0053] In S409, the IoT device management service 104 identifies the target IoT client from the device ID for which printing is to be performed, and notifies the identified IoT client 343 of the print job.

[0054] In S410, based on the print job notification received by the IoT client, the image forming apparatus 102 acquires a print job from the print service 105. The print service 105 identifies the print job from the specified URL and transmits the print job to the image forming apparatus 102 as a response. In this embodiment, it is assumed that access is made to "https: / / xxx.com / job1" and a print job created from text 001 is acquired. In S411, the image forming apparatus 102 uses the acquired print job to execute printing.

[0055] (Print Job Creation Flow) Referring to FIG. 5, an example of the process when the IoT device management service 104 stores print job information as device-specific print job data in the process of S408 shown in FIG. 4 will be described.

[0056] When the IoT device management service 104 receives print job information in S501, it determines in S502 whether the target data is data of the cloud service. If the IoT device management service 104 determines in S502 that the target data is not data of the cloud service, the process proceeds to S503. In this case, in S503, the IoT device management service 104 determines that the target data is personal use data and stores the print job information as device-specific print job data with the classification "personal". On the other hand, if the IoT device management service 104 determines in S502 that the target data is data of the cloud service, the process proceeds to S504.

[0057] In S504, the IoT device management service 104 determines whether the business use of the target cloud service is permitted. If the IoT device management service 104 determines in S504 that the business use of the target cloud service is not permitted, the process proceeds to S503. In this case, in S503, the IoT device management service 104 determines that the target data is personal use data, and saves the print job information as "personal" in the device-specific print job data by category. On the other hand, if the IoT device management service 104 determines in S504 that the business use of the target cloud service is permitted, the process proceeds to S505. In this case, in S505, the IoT device management service 104 determines that the target data is business use data, and saves the print job information as "business" in the device-specific print job data by category.

[0058] Note that depending on the organization to which the user belongs, management may be performed on whether to permit business use of data other than cloud services. In that case, when it is determined in S502 that the print data is not data of a cloud service, it is possible to switch which of the processes of S503 and S505 to apply based on the information of the tenant to which the user belongs.

[0059] Regarding the category determination in the example shown in FIG. 5, although an example of the case where it is performed by the IoT device management service 104 in the process of S408 shown in FIG. 4 has been described, it may also be performed when generating a print job in S407 by the print service 105. In that case, the IoT device management service 104 may receive the category information together with the print job information from the print service 105, and save the category information in the device-specific print job data.

[0060] As described above, in this embodiment, when printing is performed on data managed by a cloud service, it is determined whether it is in-purpose use (e.g., business use) or out-of-purpose use (e.g., personal use) according to the policy of the organization to which the user belongs. By using the result of such determination, the organization can manage whether the target printing corresponds to in-purpose use or out-of-purpose use, and use the result for various controls. As a specific example, it is also possible to perform cost settlement for printing or perform printing control by analyzing the content of printing data for data used for business (in-purpose use). Also, by managing data for personal use (out-of-purpose use) together, controls such as excluding personal use from the settlement target can be performed during cost settlement, and management of the usage status of each of business use and personal use can be performed for the target image forming apparatus 102. Also, in the above description, the difference between business use and personal use has been focused on for explanation. However, if it is distinguished between the case of being used for a specific purpose (in-purpose use) such as a business purpose and the case of being used for purposes other than that (out-of-purpose use), the specific uses are not particularly limited. As a specific example, in a situation where a service is provided to members of a group, it is also possible to distinguish and manage whether the requested printing is associated with the use of the service as such a member or not. By performing such management, it is also possible to apply controls such as charging for the use as the above member.

[0061] <Second Embodiment> In the first embodiment described above, an example of the case where it is determined whether it is in-purpose use (e.g., business use) or out-of-purpose use (e.g., personal use) is described for each cloud service that manages printing data according to the policy of an organization (group). On the other hand, depending on the policy of the organization, the use of the printing function may be restricted under specific circumstances. In the second embodiment of the present disclosure, an example of a method for performing function restriction according to the policy of the organization to which the user belongs when printing is performed on data managed by a cloud service will be described.

[0062] Referring to FIG. 6, an example of the process when the IoT device management service 104 according to the present embodiment receives a print instruction from the client terminal 103 and issues a print job generation instruction to the print service 105 in S404 and S405 of FIG. 4 will be described.

[0063] In S601, the IoT device management service 104 determines whether the target print data is data of the cloud service. If the IoT device management service 104 determines in S601 that the target print data is not data of the cloud service, the process proceeds to S602. In this case, in S602, the IoT device management service 104 issues a print job generation instruction to the print service 105. On the other hand, if the IoT device management service 104 determines in S601 that the target print data is data of the cloud service, the process proceeds to S603. In this case, in S604, the IoT device management service 104 acquires tenant information from the tenant management service 106. Table 5 shows an example of the tenant information in the present embodiment.

[0064] [Table 4]

[0065] The tenant information includes a tenant ID, an organization name, a permitted site, and a print policy. The tenant ID, the organization name, and the permitted site are the same as the examples described above with reference to Table 3. The print policy indicates the print settings set during business use. Examples of the print settings include, for example, 2in1 printing, black and white / color printing, double-sided / single-sided printing, security printing, and the like.

[0066] In S604, the IoT device management service 104 determines whether the target cloud service is permitted for business use based on the received tenant information. If the IoT device management service 104 determines in S604 that the target cloud service is not permitted for business use, the process proceeds to S602. In this case, in S602, the IoT device management service 104 issues an instruction to generate a print job to the print service 105. On the other hand, if the IoT device management service 104 determines in S604 that the target cloud service is permitted for business use, the process proceeds to S605.

[0067] In S605, the IoT device management service 104 determines whether the content of the print instruction satisfies the organization's print policy. If the IoT device management service 104 determines in S605 that the content of the print instruction satisfies the organization's print policy, the process proceeds to S602. In this case, in S602, the IoT device management service 104 issues an instruction to generate a print job to the print service 105. On the other hand, if the IoT device management service 104 determines in S605 that the content of the print instruction does not satisfy the organization's print policy, the process proceeds to S606. In this case, in S606, the IoT device management service 104 changes the print settings so that the print settings satisfy the organization's print policy. Then, in S602, the IoT device management service 104 issues an instruction to generate a print job to the print service 105.

[0068] Regarding the classification determination in the example shown in FIG. 6, although an example of the case where it is performed by the IoT device management service 104 in the process of S408 shown in FIG. 4 has been described, it may also be performed when the print service 105 generates a print job in S407.

[0069] As described above, according to the present embodiment, when printing for business use is performed on data managed by a cloud service, it is possible to restrict the use of at least some of the functions related to printing according to the policy of the organization (group) to which the user belongs.

[0070] <Third Embodiment> In each of the above-described embodiments, an example has been described in the case where, according to the policy of the organization (group) to which the user belongs, management of whether it is for intended use (for example, business use) or unintended use (for example, personal use) is performed for each cloud service that manages print data. On the other hand, depending on the policy of the organization, it may be desirable to restrict the reference to the history of print jobs. In the third embodiment of the present disclosure, an example of a method for performing browsing restriction (acquisition restriction) on a print log for data managed by a cloud service according to the policy of the organization to which the user belongs will be described. Note that for components and processes denoted by the same reference numerals as those in the first embodiment, components and processes denoted by the same reference numerals in the first embodiment are applied as being substantially the same unless otherwise specified.

[0071] With reference to FIG. 7, an example of the system sequence in the present embodiment will be described. Note that since the processes of S401 to S411 are substantially the same as the example described with reference to FIG. 4, detailed description thereof will be omitted.

[0072] The IoT client 343 acquires event data by printing in S701, and creates transmission data based on the event data in S702. At this time, the IoT client 343 adds a classification to the event data based on the classification included in the print data acquired in S409. In S703, the IoT client transmits the created event data to the IoT device management service 104. The IoT device management service 104 performs display control according to the organization's policies for the event data it manages. Table 6 shows an example of tenant information according to this embodiment.

[0073]

Table 5

[0074] Tenant information includes a tenant ID, an organization name, a permitted site, and a display policy. The tenant ID, organization name, and permitted site are substantially the same as the examples described above with reference to Table 3. The display policy indicates the event information among a series of event information included in the event data for personal use that is permitted to be viewed (acquired). For example, for the tenant with the tenant ID "BBB" in Table 5, viewing of the number of printed sheets and printing time is permitted, and viewing (acquisition) by other users other than the target user (for example, the user who instructed printing for personal use) for other information is restricted. Note that the users to whom the display policy applies may be appropriately changed according to the use case. As a specific example, viewing may be permitted only for the user who instructed printing, or viewing may also be permitted for an administrator who has specific management authority in addition to the user. Also, when multiple types of target users can be assumed, the display policy may be applied individually for each type of user.

[0075] As described above, according to this embodiment, when printing of data managed by the cloud service is performed, it is possible to control the information (for example, items) that is permitted to be acquired from the print event according to the policies of the organization to which the user belongs.

[0076] <Other Embodiments> The present invention can also be implemented by supplying a program that realizes one or more functions of the above-described embodiments to a system or apparatus via a network or a storage medium, and causing one or more processors in a computer of the system or apparatus to read and execute the program. It can also be implemented by a circuit (for example, ASIC) that realizes one or more functions.

[0077] Further, the disclosure of this embodiment includes the following systems, methods, and programs. (System 1) First management means for managing services permitted for users belonging to a group defined in advance for each group; determination means for determining, in the first management means, whether or not use of an external service is permitted for the group to which the user belongs when a print job is acquired from the external service as a print target in response to a print request from the user; and second management means for associating classification information indicating that it is an in-purpose use with respect to the print job and managing it by associating classification information indicating that it is an out-of-purpose use with respect to the print job when it is determined by the determination means that use of the external service is not permitted for the group to which the user belongs. An information processing system characterized by comprising the above. (System 2) The information processing system according to System 1, further comprising restriction means for restricting use of at least a part of a series of functions related to execution of the print when classification information indicating that it is an out-of-purpose use with respect to the print job is associated with the print job when executing the print for the print job. (System 3) It has a third management means for managing logs related to the execution of printing for the printing job, and when the third management means receives a browsing request for the log corresponding to the printing job associated with classification information indicating that it is unauthorized use from a user other than the user who is the requester of the printing for the printing job, it restricts the browsing of at least some of the series of information included in the log. The information processing system according to System 1 or 2. (Method 1) A control method for an information processing system, including: a first management step of managing services permitted for use by users belonging to a group for each group defined in advance; a determination step of determining whether the use of the external service is permitted for the group to which the user belongs in the first management step when a printing job is obtained from an external service as a printing target in response to a printing request from a user; and a second management step of associating classification information indicating authorized use with the printing job when it is determined in the determination step that the use of the external service is permitted for the group to which the user belongs, and managing by associating classification information indicating unauthorized use with the printing job when it is determined that the use of the external service is not permitted for the group to which the user belongs. A control method for an information processing system, characterized by including these steps. (Program 1) A program for causing a computer to function as an information processing system, comprising: a first management means for managing services permitted for users belonging to a predefined group for each group; a determination means for determining, in the first management means, whether or not use of an external service is permitted for the group to which the user belongs when a print job is acquired from the external service as a print target in response to a print request from the user; and a second management means for associating classification information indicating that it is an in-purpose use with the print job when it is determined by the determination means that use of the external service is permitted for the group to which the user belongs, and for managing by associating classification information indicating that it is an out-of-purpose use with the print job when it is determined that use of the external service is not permitted for the group.

Explanation of Signs

[0078] 104 IoT Device Management Service 106 Tenant Management Service 301 Print Job Data Management Unit by Device 321 Tenant Information Management Unit

Claims

1. First management means for managing services permitted for use by users belonging to a predefined group for each such group; Determination means for determining, in the first management means, whether or not use of the external service is permitted for the group to which the user belongs when a print job is acquired from an external service as a print target in response to a print request from the user; Second management means for associating classification information indicating that it is an in-purpose use with the print job when it is determined by the determination means that use of the external service is permitted for the group to which the user belongs, and for managing by associating classification information indicating that it is an out-of-purpose use with the print job when it is determined that use of the external service is not permitted for the group; An information processing system, characterized by comprising the above.

2. The information processing system according to claim 1, further comprising restriction means for restricting use of at least some of a series of functions related to execution of the print when classification information indicating that it is an out-of-purpose use is associated with the print job when executing the print for the print job.

3. Having third management means for managing a log related to execution of the print for the print job, wherein when the third management means receives a request to view the log corresponding to the print job associated with classification information indicating that it is an out-of-purpose use from a user other than the user who is the requester of the print for the print job, the third management means restricts viewing of at least some of a series of information included in the log. The information processing system according to claim 1, characterized by the above.

4. A control method for an information processing system, comprising: A first management step of managing services permitted for use by users belonging to a predefined group for each such group; A determination step of determining, in the first management step, whether or not use of the external service is permitted for the group to which the user belongs when a print job is acquired from an external service as a print target in response to a print request from the user; When it is determined in the determination step that use of the external service is permitted for the group to which the user belongs, association information indicating that it is an in-purpose use is associated with the print job, and when it is determined that use of the external service is not permitted for the group, a second management step of managing by associating classification information indicating that it is an out-of-purpose use with the print job; A control method for an information processing system, characterized by including the above. **Claim 5** A computer, A first management means for managing services permitted for use by users belonging to a group, for each group defined in advance; When a print job is acquired from an external service as a print target in response to a print request from a user, a determination means for determining, in the first management means, whether use of the external service is permitted for the group to which the user belongs; When it is determined by the determination means that use of the external service is permitted for the group to which the user belongs, association information indicating that it is an in-purpose use is associated with the print job, and when it is determined that use of the external service is not permitted for the group, a second management means for managing by associating classification information indicating that it is an out-of-purpose use with the print job; A program for causing a computer to function as an information processing system having the above.

Citation Information

Patent Citations

  • Printing system, image formation device, printing management device, and control method

    JP2019123176A