Information processing device and password registration method in information processing device

The information processing device addresses the challenge of multiple password policies by comparing strengths and applying the most secure policy automatically, ensuring efficient and secure password registration.

JP2025119426APending Publication Date: 2025-08-14SHARP KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024014308
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-08-14

AI Technical Summary

Technical Problem

Existing information processing devices struggle to set secure passwords when multiple different password policies are in effect, requiring users to manually check and comply with varying requirements, which is time-consuming and inefficient.

Method used

An information processing device that stores multiple password policies and determines the applicable policy based on a strength comparison, ensuring compliance with the strongest policy for secure password registration.

Benefits of technology

Enables secure password setting without user intervention in determining the appropriate policy, resulting in stronger security compliance across varying regulations and device specifications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025119426000001_ABST
    Figure 2025119426000001_ABST
Patent Text Reader

Abstract

To provide an information processing device and the like that can implement the setting of a password with stronger security even if a plurality of different password policies exist.SOLUTION: An information processing device can communicate with an external device via a network based on the operating authority of an authenticated user. The information processing device includes: a storage unit that stores at least a first password policy and a second password policy different from the first password policy as password policies defined for user authentication using a password; and a control unit that determines whether or not an input password can be registered by determining whether or not the input password complies with the password policy to be applied. The control unit determines the password policy to be applied to the compliance determination based on a comparison of the strength of the security levels in the first password policy and the second password policy.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present disclosure relates to an information processing device and the like. [Background technology]

[0002] In recent years, as part of security measures for IoT (Internet of Things) devices, regions and countries such as Europe and the United States have been requiring the setting and management of secure passwords that comply with various laws and regulations (hereinafter, in this disclosure, the agreements, indicators, procedures, methods, etc. for setting passwords will be referred to as password policies).

[0003] On the other hand, in consumer IoT devices, passwords are sometimes set based on password policies that depend on the device and user settings, etc., in order to flexibly respond to device specifications and user usage purposes.

[0004] Even if there are multiple different password policies, it is preferable to be able to set a password that is as strong as possible in terms of security.

[0005] For example, Patent Document 1 describes a policy analysis service that analyzes the strengths and equivalences of multiple security policies. [Prior art documents] [Patent documents]

[0006] [Patent Document 1] Special Publication No. 2020-525898 Summary of the Invention [Problem to be solved by the invention]

[0007] The present disclosure aims to provide an information processing device and the like that can realize the setting of a password with stronger security even if multiple different password policies exist.

[0008] In order to solve the above problem, the information processing device disclosed herein is an information processing device that is capable of communicating with an external device via a network based on the operating authority of an authenticated user, and is equipped with a memory unit that stores at least a first password policy and a second password policy different from the first password policy as password policies defined for user authentication using a password, and a control unit that determines whether or not to register an input password by determining whether the input password complies with the password policy to be applied, and is characterized in that the control unit determines the password policy to be applied to the compliance determination based on a strength comparison between the first password policy and the second password policy.

[0009] In addition, the method for registering a password in an information processing device according to the present disclosure is a method for registering a password in an information processing device that is capable of communicating with an external device via a network based on the operating authority of an authenticated user, and is characterized in that it stores at least a first password policy and a second password policy different from the first password policy as password policies defined for user authentication using a password, determines whether the input password complies with the password policy to be applied, and determines whether the input password can be registered, and determines the password policy to be applied to the compliance determination based on a strength comparison between the first password policy and the second password policy. [Effects of the Invention]

[0010] According to the present disclosure, it is possible to provide an information processing device or the like that is capable of realizing the setting of a password that is more secure in terms of security, even if a plurality of different password policies exist. [Brief explanation of the drawings]

[0011] [Figure 1]1 is an external perspective view illustrating the overall configuration of a multifunction peripheral 10 according to a first embodiment. [Figure 2] FIG. 2 is a diagram illustrating the functional configuration of a multifunction peripheral 10 according to the first embodiment. [Figure 3] FIG. 10 is a diagram illustrating a password policy. [Figure 4] 1 is a flowchart illustrating a processing flow according to the first embodiment. [Figure 5] 1 is a flowchart illustrating a processing flow according to the first embodiment. [Figure 6] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 8] 10 is a flowchart illustrating a processing flow according to the second embodiment. [Figure 9] FIG. 10 is a diagram illustrating an example of operation according to the second embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of operation according to the second embodiment. [Figure 11] 10 is a flowchart illustrating a processing flow according to the third embodiment. [Figure 12] FIG. 10 is a diagram illustrating an example of operation according to the third embodiment. [Figure 13] FIG. 10 is a diagram illustrating the functional configuration of a multifunction peripheral 10 according to a fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. Note that the following embodiments are examples for explaining the present disclosure, and the technical content of the description set forth in the claims is not limited to the following description.

[0013] Legal frameworks for security standards for IoT devices are being established, such as the Cyber Resilience Act in Europe, the Product Security and Telecommunications Infrastructure Bill in the UK, and the IoT Cybersecurity Improvement Act in the US.

[0014] For example, the PSTI Act prohibits the use of default passwords or passwords that are easily guessed for terminal devices that can connect to the Internet, and requires that passwords used be unique.

[0015] Currently, consumer IoT devices, including multifunction peripherals, are sometimes set with a unique initial password or require users to set a unique password at the time of initial startup, and compliance requirements for these password settings may differ for each device.

[0016] There are multiple password policies for password settings that must comply with the requirements, such as those based on device specifications, those based on user settings, and those based on local laws and regulations. When these policies differ, in order to set a secure password, the user must check the password policy that applies and set the compliance requirements for that password policy, which is time-consuming.

[0017] In the present disclosure, the following embodiments provide an information processing device or the like that allows a password with stronger security to be set even if multiple different password policies exist.

[0018] [1 First Embodiment] In the first embodiment, a multifunction peripheral 10 that is capable of communicating with an external device (not shown) via a network based on the operation authority of an authenticated user will be described as one form of information processing device.

[0019] [1.1 Functional Configuration] FIG. 1 is a diagram illustrating the overall configuration of a multifunction peripheral 10 according to the first embodiment. FIG. 2 is a diagram illustrating the functional configuration of the multifunction peripheral 10. The multifunction peripheral 10 is an image forming device that can perform various types of jobs, such as printing, copying, faxing, and image transmission, in a single housing. Note that in the first embodiment, the multifunction peripheral 10 will be described as one form of information processing device, but the information processing device is not limited to the multifunction peripheral 10, and may be an image forming device such as a printer, copier, or fax machine, as long as it is capable of communicating with an external device (not shown) via a network based on the operation authority of an authenticated user.

[0020] The multifunction device 10 includes a control unit 11, a display unit 13, an operation input unit 15, a communication unit 17, a storage unit 19, and an image processing unit 21.

[0021] The control unit 11 controls the entire multifunction device 10. The control unit 11 can be configured with one or more processing devices (for example, a CPU (Central Processing Unit), an SoC (System on Chip), etc.). The control unit 11 realizes its functions by reading and executing various programs stored in the storage unit 19.

[0022] The display unit 13 is a display device that displays various information to the user, etc. The display unit 13 can be configured, for example, with an LCD (Liquid Crystal Display), an organic EL (Electro-Luminescence) display, etc. When the control unit 11 reads out a display control program 192 (described later), the display unit 13 displays, for example, a home screen (not shown) and operation screens such as setting screens related to the execution of each job, as well as a password setting screen (described later) at the time of initial startup, such as the first startup after installation of the multifunction peripheral 10 or the first startup after initialization of the storage unit 19.

[0023] The operation input unit 15 is an input device that accepts information input by a user or the like. The operation input unit 15 can be configured with various input devices, such as operation keys such as hard keys or software keys, buttons, etc. The operation input unit 15 can also be configured as a touch panel that allows input via the display unit 13. When configured as a touch panel, the operation input unit 15 can detect a user's touch, tap, swipe, etc. on an object displayed via the display unit 13, and acquire coordinate information, pressure-sensitive information, etc. on the touch panel. In this case, the input method of the touch panel can be, for example, a general input method such as a resistive film method, an infrared method, an electromagnetic induction method, or a capacitive method.

[0024] The communication unit 17 includes a wired / wireless interface or both for communicating with an external device (not shown) via a network NW such as a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, a telephone line, a FAX line, etc. Furthermore, the communication unit 17 may include an interface related to wireless communication technology such as Bluetooth (registered trademark), NFC (Near Field Communication), Wi-Fi (registered trademark), ZigBee (registered trademark), IrDA (Infrared Data Association), or wireless USB (Universal Serial Bus).

[0025] The storage unit 19 is one or more storage devices that store various programs and various data required for the operation of the multifunction device 10. The storage unit 19 can be configured with storage devices such as RAM (Random Access Memory), SSD (Solid State Drive), HDD (Hard Disk Drive), and ROM (Read Only Memory).

[0026] In the first embodiment, the memory unit 19 stores a control program 191, a display control program 192, a policy application determination program 193, a compliance determination program 194, a password registration program 195, and an authentication program 196, and reserves a password policy memory area 197 and an authentication information memory area 198.

[0027] The control program 191 is a program that is read by the control unit 11 when performing overall control of the multifunction device 10. The control unit 11 that reads the control program 191 functions as an OS (Operating System) and controls the operation of hardware such as the display unit 13, operation input unit 15, communication unit 17, and image processing unit 21.

[0028] The display control program 192 is a program that is read by the control unit 11 when controlling the output of an operation screen including a password setting screen displayed on a touch panel. The control unit 11 that reads the display control program 192 can display a password setting screen on the touch panel in accordance with a password policy that is applied to password setting (registration).

[0029] The policy application determination program 193 is a program that is read by the control unit 11 when determining a password policy to be applied to a password setting. After reading the policy application determination program 193, the control unit 11 determines the strength of the password policy stored in a password policy storage area 197 (described later) and determines the password policy to be applied to the password setting.

[0030] Here, the password policy according to the present disclosure will be explained with reference to FIG. 3. The password policy according to the present disclosure refers to conditions under which an input password can be recognized as a valid password if it satisfies the compliance of the password policy. In the present disclosure, the conditions that constitute the password policy and enable a password to be recognized as a valid password are referred to as compliance requirements. The password policy can include the number of characters, combinations of characters (character types), numbers, symbols, etc., the complexity of the character string combination, specific condition clauses, etc. as compliance requirements that must be met by the input password.

[0031] Here, characters may include full-width and half-width characters (English letters and characters from other languages other than English), kanji, and kana. Characters may also include the distinction between uppercase and lowercase letters of the same character. Numbers may include full-width and half-width numbers, and symbols may include full-width and half-width symbols.

[0032] The remarks also describe the source (issuer) of the password policy. Here, "region-dependent" refers to password policies that must be complied with by laws and regulations in regions or countries such as Europe and the United States. On the other hand, "device-dependent" refers to password policies that must be complied with based on the device specifications of the multifunction device 10 and user settings.

[0033] For example, Password Policy 1 in Fig. 3 is an example of a "region-dependent" password policy that has a compliance requirement of a combination of 12 or more characters including "English uppercase letters," "lowercase letters," and "symbols." Password Policy 1 can be configured to meet compliance with a combination of 12 or more characters using one of the following types of characters (symbols): "English uppercase letters," "lowercase letters," or "symbols." However, to improve the security level, it is desirable to use at least two or more types of characters (symbols), and it is even more desirable to use all three types of characters (symbols).

[0034] Furthermore, the control unit 11, which has read the policy application determination program 193, performs a strength comparison between the password policies illustrated in FIG. 3 to determine which password policy to apply to the compliance determination. Here, the strength of a password policy according to the present disclosure is an index for evaluating the security level of an input password, determined based on the applied password policy. Examples of indices related to the strength comparison include the number of characters (minimum number of characters; also referred to as the character limit) consisting of a combination of letters, numbers, symbols, etc., determined by the password policy, and specific character types. In the present disclosure, the number of characters and character types uniquely determined by the password policy are used as indices related to the strength comparison. Of course, the total number of combinations of letters, numbers, symbols, etc. may also be used as an index related to the strength comparison. For example, in the case of password policy 1 in FIG. 3, if English uppercase letters (26 characters), lowercase letters (26 characters), and symbols are set to 30 characters for convenience, and the character limit is set to 12 characters, the total number of passwords (also referred to as the password space) consisting of these letters and symbols is 8^12 (here, "^" indicates exponentiation). That is, if m is the character type, such as English uppercase letters, and n is the character limit, then m^n is the index for strength comparison. A specific conditional clause, such as "Old passwords cannot be used" in password policy 3 of FIG. 3, can also be used as an index for strength comparison. "Old passwords cannot be used" is a conditional clause that prohibits the use of user passwords previously set by users, default passwords set for convenience, and passwords that have been used in the past. A password policy that includes such a conditional clause can be considered stronger than a password policy that does not include such a conditional clause. When the password policies to be compared for strength are a first password policy and a second password policy different from the first password policy, the control unit 11 that reads the policy application determination program 193 determines which of the first and second password policies has the stronger strength as the password policy for determining compliance.In addition, if there are three or more password policies to be compared in strength (if three or more password policies are stored in the password policy storage area 197 described below), the control unit 11 can also determine the strongest (most robust) password policy among these password policies as the password policy for which compliance is to be determined.

[0035] 2, the compliance determination program 194 is a program that the control unit 11 reads out when determining whether an input password satisfies the compliance with the password policy applied by the policy application determination program 193. After reading out the compliance determination program 194, the control unit 11 compares the character string (character type and number of characters) that constitutes the input password with the compliance requirements stipulated in the applied password policy to determine the compliance of the password.

[0036] The password registration program 195 is a program that the control unit 11 reads out when accepting a password input by a user or when performing registration processing for a password that has been determined to be compliant by the compliance determination program 194. For example, the control unit 11 that reads out the password registration program 195 and the display control program 192 controls the display of an output screen on a touch panel to display a password setting screen or the like for accepting password input. The password accepted via the password setting screen or the like is subjected to compliance determination based on the compliance determination program 194.

[0037] The authentication program 196 is a program that the control unit 11 reads out when performing authentication processing using a password entered via a login screen or the like. The control unit 11 that reads out the authentication program 196 performs user login authentication processing by comparing the password entered via the login screen or the like (login password) with the password registered by the password registration method according to the present disclosure (registered password). If the login password and registered password match, the control unit 11 authenticates the user who entered the login password as a login user. If the login password and registered password do not match, the control unit 11 can, for example, display an error screen on the touch panel informing the user of a login error and prompt the user to re-enter the login password, etc.

[0038] The password policy storage area 197 is a storage area that stores at least one or more password policies (see FIG. 3). The one or more password policies stored in the password policy storage area 197 may be acquired via a network (NW) from an external server (not shown) that provides the password policies, or via a storage medium such as a USB (Universal Serial Bus) memory that stores the password policies. The one or more password policies may also be hard-coded in the policy application determination program 193.

[0039] The authentication information storage area 198 is a storage area for registering a password that is determined to comply with the password policy as a registered password. The registered password stored in the authentication information storage area 198 is associated with the identification information of the login user (for example, account information such as an identification ID, a user name, and an email address). The registered password stored (registered) in the authentication information storage area 198 can be used for login authentication to the multifunction peripheral 10.

[0040] Image processing unit 21 includes image forming unit 211 and image input unit 213. Image forming unit 211 feeds paper from paper feed unit 25, forms an image on the paper based on image data, and then discharges the paper to paper discharge unit 27. Image forming unit 211 can be configured, for example, by a laser printer that employs an electrophotographic method. In this case, image forming unit 211 forms an image using toner supplied from toner cartridges (not shown) that correspond to toner colors (for example, cyan, magenta, yellow, and black).

[0041] The image input unit 213 generates image data by scanning an original. The image input unit 213 may be configured as a scanner device equipped with an image sensor such as a CCD (Charge Coupled Device) or a CIS (Contact Image Sensor), as well as an automatic document feeder (ADF) and a flatbed for placing and reading an original. The image input unit 213 is not particularly limited in configuration as long as it is capable of reading a reflected light image from an original image using an image sensor. The image input unit 213 may also be configured as an interface capable of acquiring image data stored in a storage medium such as a USB memory or image data transmitted from a terminal device (not shown). The image processing unit 21 may be configured to perform, for example, shading correction or density correction on the image data input from the image input unit 213 to generate image data for image transmission.

[0042] [1.2 Processing flow] Next, the flow of processing according to the first embodiment will be described. Fig. 4 is a flowchart illustrating the flow of processing when registering the password (administrator password; authentication password) of an administrator with administrative authority over the multifunction peripheral 10 as an initial setup wizard when the multifunction peripheral 10 is started for the first time after installation or when the storage unit 19 is initialized (hereinafter, this startup timing will be referred to as initial startup), and when checking the administrator password at any timing other than initial startup. Note that Fig. 4 is described on the assumption that a password policy related to compliance determination of the input password (registered administrator password) has been applied by the policy application determination processing described in the next figure.

[0043] The processing described below is processing in which the control unit 11 reads and executes, among other things, the display control program 192, the policy application determination program 193, the compliance determination program 194, the password registration program 195, and the like.

[0044] First, the control unit 11 determines whether the device state of the multifunction device 10 is initial startup (step S100). If it is determined that the device state of the multifunction device 10 is initial startup, the control unit 11 displays a password setting screen on the touch panel that can accept password input, and accepts password input (step S100; Yes→step S110).

[0045] Next, the control unit 11 determines whether the entered password complies with the applied password policy (step S120). If the result of the compliance determination indicates that the entered password satisfies the compliance of the applied password policy, the control unit 11 registers the entered password as an administrator password and ends the process (step S130; Yes → step S140). If the entered password does not comply with the applied password policy, the control unit 11 returns the process to step S110 and accepts (re)entry of the password (step S130; No → step S110).

[0046] On the other hand, if the control unit 11 determines that the device state of the multifunction device 10 is not initial startup, but rather that the administrator password is being confirmed at any time other than initial startup, it performs a compliance check on the registered administrator password and determines whether an appropriate password has been registered as the administrator password (step S100; No → step S150).

[0047] If the result of the compliance determination process indicates that the registered administrator password satisfies compliance, the control unit 11 ends the process (step S160; Yes → "End"). On the other hand, if the control unit 11 determines that the registered administrator password does not satisfy compliance, the control unit 11 executes the processes from step S110 onwards (step S160; No → step S110). Note that if the administrator password registered at initial startup is changed and as a result compliance is no longer satisfied, the control unit 11 may prompt the user to reset the administrator password.

[0048] Next, the policy application determination process according to the first embodiment will be described using the flowchart in FIG. 5. Note that the same steps as those described in FIG. 4 will be assigned the same step numbers. In addition, the description in FIG. 5 will explain a processing example in which there are two password policies to be compared in strength: a first password policy and a second password policy different from the first password policy. Here, the first password policy will be described using password policy 1 exemplified in FIG. 3, and the second password policy will be described using password policy 2 exemplified in FIG. 3 as a specific example.

[0049] In step S110, control unit 11 accepts the input of a password. Upon accepting the input of a password, control unit 11 determines the strength of the password policy (step S200).

[0050] The control unit 11 reads out the policy application determination program 193 to determine the strength of the password policy (step S200). For example, as shown in the example of FIG. 3, the character limit for password policy 1 is 12 characters or more. On the other hand, the character limit for password policy 2 is 8 characters or more. In this case, the control unit 11 determines that password policy 1, which is the first password policy, is stronger than password policy 2, which is the second password policy.

[0051] If it is determined that the strength of the first password policy is stronger than the strength of the second password policy, the control unit 11 determines the first password policy as the password policy for which compliance determination for the password entered in step S110 is to be performed.The control unit 11 then reads the compliance determination program 194 to determine the compliance of the password with the first password policy (password policy 1) determined as the password policy for which compliance determination is to be performed (step S210; Yes→step S220).

[0052] If it is determined that the input password complies with the first password policy, the control unit 11 registers the password as an administrator password and ends the process (step S220; Yes → step S140). However, if it is determined that the input password does not comply with the first password policy, the control unit 11 returns the process to step S110 (step S220; No → step S110).

[0053] On the other hand, if it is assumed that the strength of the second password policy is stronger than that of the first password policy, the control unit 11 determines the second password policy as the target password policy for compliance determination for the password entered in step S110. Then, the control unit 11 reads the compliance determination program 194 to determine the compliance of the password with the second password policy (password policy 2) determined as the target password policy for compliance determination (step S210; No -> step S230).

[0054] If it is determined that the entered password complies with the second password policy, the control unit 11 registers the password as an administrator password and ends the process (step S230; Yes → step S140). However, if it is determined that the password does not comply with the second password policy, the control unit 11 returns the process to step S110 (step S230; No → step S110).

[0055] [1.3 Example of operation] Next, an example of operation according to the first embodiment will be described. Fig. 6 is a diagram illustrating an example of the configuration of a password setting screen W10 that is displayed on the touch panel by the control unit 11 that has read out the display control program 192 and the password registration program 195.

[0056] The password setting screen W10 includes a password input assistance area R10, a password input box Bx10, and an OK button B10. The password input assistance area R10 is a display area that assists the user in entering a password by displaying input conditions for satisfying compliance requirements stipulated in the password policy applied as the subject of compliance judgment. Note that FIG. 6 shows an example in which the message "Please enter a password of 12 or more characters, including English uppercase and lowercase letters and symbols" is displayed in the password input assistance area R10.

[0057] The password input box Bx10 is an input box that accepts a password entered by the user. The password input box Bx10 displays "New Password" and "New Password (Confirm)" as placeholders, prompting the user to enter a password into the password input box Bx10. The OK button B10 is an input button that accepts an instruction to confirm the password entered into the password input box Bx10. When the user enters a specific password into the password input box Bx10 and selects the OK button B10, the control unit 11 performs a compliance determination process for the accepted password.

[0058] If the control unit 11 determines that the entered password complies with the password policy as a result of the compliance determination process, it registers the password as a registered password and terminates the process. At this time, the control unit 11 may display a message screen (not shown) notifying the user that the password registration was successful. On the other hand, if the control unit 11 determines that the entered password does not comply with the password policy, it displays error screens W12 and W14, which are described in the following figures.

[0059] 7(a) shows an example of an error screen W12 that is displayed on the touch panel by the control unit 11 when the entered password does not meet the requirements (compliance) of the password policy. The error screen W12 notifies the user that the entered password does not meet the compliance requirements.

[0060] FIG. 7(b) is an example of an error screen W14 that the control unit 11 displays on the touch panel when the entered password contains characters that do not comply with the password policy requirements (characters that cannot be used in passwords). The error screen W14 notifies the user that characters that cannot be set as a password have been used. Both the error screen W12 and the error screen W14 may also be provided with an OK button B12 that accepts an instruction from the user to confirm the error content. When the user confirms the error content and accepts an instruction to select the OK button B12, the control unit 11 terminates the display of the error screen W12 and the error screen W14 and displays the password setting screen W10 illustrated in FIG. 6, allowing the user to re-enter the password.

[0061] As described above, according to the first embodiment, at least a first password policy and a second password policy different from the first password policy are stored as password policies defined for user authentication using a password, and the password policy to be applied to determine compliance is determined based on a comparison of the strength of the security levels of the first password policy and the second password policy, and compliance of the entered password is determined by determining whether it complies with the applied password policy, thereby making it possible to determine whether the entered password can be registered.

[0062] According to the first embodiment, by comparing the strength of password policies, it is possible to apply a password policy that is stronger in terms of security, so that users do not need to decide which password policy to apply themselves, and it is possible to set passwords that are stronger in terms of security.

[0063] [2 Second Embodiment] In the second embodiment, a first password policy and a second password policy are assigned a higher or lower priority for application as password policies, and the control unit requires compliance with the first password policy if the first password policy has a higher priority, and if the password entered by the user does not comply with the second password policy, which has a lower priority than the first password policy, the control unit prompts the user to reset the password so that compliance with the second password policy is satisfied.

[0064] The functional configuration of the second embodiment can be substantially the same as the functional configuration of the multifunction peripheral 10 of the first embodiment, and therefore a description thereof will be omitted here.

[0065] [2.1 Processing flow] Next, a processing flow according to the second embodiment will be described with reference to the flowchart of FIG. 8. Note that the same step numbers will be used to denote processes that can be the same as those described in the flowcharts of FIG. 4 or 5. Similarly to FIG. 5, FIG. 8 will also describe a processing example in which two password policies, a first password policy and a second password policy different from the first password policy, are the targets of strength comparison. Here, the first password policy will be password policy 4 illustrated in FIG. 3, and the second password policy will be password policy 2 illustrated in FIG. 3. Note that password policy 4 is a region-dependent password policy, and password policy 2 is a device-dependent password policy. In this example, it will be described assuming that password policy 4, which is a region-dependent password policy, has a higher priority than password policy 2, which is a device-dependent password policy. Note that the priority order is not limited to that described in the second embodiment; the second password policy (password policy 2) may have a higher priority than the first password policy (password policy 4).

[0066] In step S110, the control unit 11 accepts the input of a password. Upon accepting the input of a password, the control unit 11 determines whether the input password satisfies compliance with the first password policy. If it is determined that the input password satisfies compliance with the first password policy, the control unit 11 proceeds to step S230 (step S220; Yes→step S230). As shown in FIG. 3, the first password policy is a password policy requiring five or more characters consisting of uppercase and lowercase English letters. The control unit 11 performs compliance determination by treating the compliance requirement (five or more characters consisting of uppercase and lowercase English letters), which has a higher priority than the second password policy, as a mandatory requirement. On the other hand, if it is determined that the input password does not satisfy compliance with the first password policy, the control unit 11 returns the process to step S110 (step S220; No→step S110).

[0067] Next, the control unit 11 determines whether the input password satisfies the compliance of the second password policy. If the control unit 11 determines that the input password satisfies the compliance of the second password policy, it registers the password as an administrator password and ends the process (step S230; Yes → step S140).

[0068] On the other hand, if it is determined that the entered password does not satisfy the compliance of the second password policy, the control unit 11 notifies the user to reset the password to prompt the user to satisfy the compliance of the second password policy (step S230; No -> step S240). Here, as illustrated in FIG. 3, the second password policy, password policy 2, requires a password of at least eight characters consisting of English uppercase and lowercase letters. Therefore, if the entered password is at least five characters but less than eight characters consisting of English uppercase and lowercase letters, the control unit 11 prompts the user to reset the password to at least eight characters.

[0069] When the input of the reset password is accepted, the control unit 11 returns the process to step S230 (step S250 to step S230).

[0070] [2.2 Example of operation] Next, an example of operation according to the second embodiment will be described. Fig. 9 is a diagram illustrating an example of the configuration of a password setting screen W20 according to the second embodiment. The password setting screen W20 can have the same configuration as the password setting screen W10 illustrated in Fig. 6, and therefore a detailed description thereof will be omitted here. Fig. 9 shows an example in which input conditions (five or more English characters including uppercase and lowercase letters) for satisfying compliance with password policy 4 as the first password policy are displayed in the password input assistance area R10.

[0071] 10 is a diagram illustrating an example of the configuration of a notification screen W16 that urges the user to reset a password of eight characters or more when the entered password is five to eight characters long and consists of both uppercase and lowercase English letters. The notification screen W16 in FIG. 10 is an example in which the notification content to the user is, for example, "We recommend a password of eight characters or more, including both uppercase and lowercase English letters. Would you like to reset your password?"

[0072] The notification screen W16 is provided with a reset button B14 and a cancel button B16. The reset button B14 is an input button that accepts a user instruction to reset the password. When the control unit 11 accepts a user instruction to select the reset button B14, it displays the password setting screen W20 illustrated in FIG. 9 and accepts input for resetting the password. The cancel button B16 is an input button that accepts an instruction to cancel the password reset. When the control unit 11 accepts a user instruction to select the cancel button B16, it terminates the display of the notification screen W16.

[0073] As described above, according to the second embodiment, a priority is established between the first password policy and the second password policy, compliance requirements for the password policy with the higher priority are made mandatory, and the user is notified to also satisfy the compliance requirements for the second password policy, which has a lower priority than the first password policy. This makes it possible to set a password that is more secure than when the first password policy is applied.

[0074] [3 Third embodiment] The third embodiment is a form in which a comparison is made between the compliance requirements for a first password policy and the compliance requirements for a second password policy, and the password policy consisting of the compliance requirements that form the strongest combination is determined to be the password policy to be applied to the compliance determination.

[0075] The functional configuration of the third embodiment can be the same as the functional configuration of the multifunction peripheral 10 of the first embodiment, and therefore a description thereof will be omitted here.

[0076] [3.1 Processing flow] The processing flow according to the third embodiment will be described with reference to the flowchart in FIG. 11. Note that the same step numbers will be used to denote processes that can be the same as those described in the flowcharts in FIGS. 4, 5, and 8. Similarly to FIGS. 5 and 8, FIG. 11 also describes a processing example in which there are two password policies to be compared in strength: a first password policy and a second password policy different from the first password policy. Here, the first password policy will be password policy 1 exemplified in FIG. 3, and the second password policy will be password policy 3 exemplified in FIG. 3. Note that password policy 1 is a region-dependent password policy, and password policy 3 is a device-dependent password policy. In the third embodiment, the password policies will be described with the number of characters (character limit) and the character type (English uppercase letters, lowercase letters, numbers, symbols, etc.) as the targets of strength comparison.

[0077] In step S110, control unit 11 accepts the input of a password. Upon accepting the input of a password, control unit 11 starts determining the strength of the password policy (step S200).

[0078] The control unit 11 compares the character limit in password policy 1, which is the first password policy, with that in password policy 3, which is the second password policy. Here, the character limit in password policy 1 is 12 characters or more. On the other hand, the character limit in password policy 3 is 8 characters or more. Therefore, the control unit 11 determines that the first password policy is stronger in terms of character limit than the second password policy, and sets the character limit for the password policy to "12" (step S300; Yes).

[0079] Next, the control unit 11 determines whether the entered password complies with the first password policy (password policy 1) (step S310). If it determines that the entered password satisfies the character limit (12 characters) of the first password policy, the control unit 11 compares the character types in password policy 1 as the first password policy with those in password policy 3 as the second password policy (step S310; Yes → step S320). The character types in password policy 1 are three types: "English uppercase letters, lowercase letters, and symbols." On the other hand, the character types in password policy 3 are four types: "English uppercase letters, lowercase letters, numbers, and symbols." Therefore, the control unit 11 determines that the second password policy is stronger in terms of character types than the first password policy, and sets the character type "4" as the password policy (step S320; No).

[0080] Next, the control unit 11 determines whether the password complies with the second password policy (password policy 3) (step S360). If it is determined that the entered password satisfies the second password policy regarding the character types (four types), the control unit 11 determines whether the device state of the multifunction device 10 is initial startup (step S360; Yes→step S100).

[0081] If it is determined that the device state of the multifunction device 10 is the initial startup state, the control unit 11 registers the password as the administrator password and ends the process (step S100; Yes→step S140).

[0082] On the other hand, if it is determined that the device state of the multifunction device 10 is not initial startup, the control unit 11 determines whether the entered password is different from the previous (multiple) administrator password (step S100; No → step S380).

[0083] If it is determined that the input password is different from the previous (multiple) administrator passwords, the control unit 11 shifts the process to step S140 (step S380; Yes→step S140).

[0084] If it is determined that the second password policy has stronger character limit than the first password policy, the control unit 11 sets the character limit of the second password policy as the password policy (step S300; No).

[0085] Next, the control unit 11 determines whether the password complies with the second password policy (password policy 3) (step S340). If it is determined that the entered password satisfies the second password policy regarding the character length limit, the control unit 11 proceeds to step S320 (step S340; Yes→step S320).

[0086] Furthermore, if it is determined that the first password policy has stronger character types than the second password policy, the control unit 11 sets the character types related to the first password policy as the password policy (step S320; Yes).

[0087] In step S330, the control unit 11 determines whether the password complies with the first password policy (password policy 1). If it is determined that the entered password satisfies the first password policy regarding the character type, the control unit 11 proceeds to step S100 (step S330; Yes→step S100).

[0088] However, if it is determined that the entered password does not comply with the first password policy regarding the character length limit (step S310; No), or if it is determined that the entered password does not comply with the second password policy regarding the character length limit (step S340; No), the control unit 11 notifies the user that the character length limit is not met and returns the process to step S110 (step S350 → step S110).

[0089] Furthermore, if it is determined that the character type of the entered password does not comply with the first password policy (step S330; No), or if it is determined that the character type of the entered password does not comply with the second password policy (step S360; No), the control unit 11 notifies the user that the character type does not comply and returns the process to step S110 (step S370 → step S110).

[0090] Furthermore, if it is determined that the entered password is the same as the previous (multiple) administrator password (step S380; No), the control unit 11 notifies the user that the password is the same as the previous password, and returns the process to step S110 (step S390 → step S110).

[0091] [3.2 Example of operation] Next, an operation example according to the third embodiment will be described. Fig. 12(a) shows an example of the configuration of a notification screen W30 that the control unit 11 displays on the touch panel in step S350 of Fig. 11. Fig. 12(a) shows an example of a notification that the entered password does not meet the compliance requirements for the character length limit, and that "The password does not meet the compliance requirements. Please enter 12 characters or more."

[0092] Fig. 12(b) is an example of the configuration of the notification screen W32 that the control unit 11 displays on the touch panel in step S370 of Fig. 11. Fig. 12(b) shows an example of a notification that the entered password does not meet the compliance requirements for the character types, and that the message is "Password compliance requirements are not met. Please enter a password that includes English uppercase letters, lowercase letters, numbers, and symbols."

[0093] Fig. 12(c) is an example of the configuration of the notification screen W34 that the control unit 11 displays on the touch panel in step S390 in Fig. 11. Fig. 12(c) shows an example in which the entered password is the same as the previous password and is notified with the message "This password cannot be used. Please enter a different password."

[0094] As described above, according to the third embodiment, it is possible to set a password policy based on compliance requirements that are more secure in terms of security between password policies, and therefore the user can set a password safely.

[0095] [4 Fourth embodiment] The fourth embodiment is particularly an embodiment in which a password is automatically generated for compliance requirements that are not met in the second and third embodiments.

[0096] 13 is a diagram illustrating the functional configuration of a multifunction device 30 according to the fourth embodiment. The multifunction device 30 according to the fourth embodiment includes a storage unit 39 instead of the storage unit 19 included in the multifunction device 10.

[0097] The storage unit 39 includes a password generation program 391 in addition to the configuration of the storage unit 19. In the second and third embodiments, when the accepted password does not comply with the applied password policy, the control unit 11 that reads the password generation program 391 automatically generates a password that complies with the password policy. In this case, before the password is automatically generated, the user may be asked to confirm whether or not to automatically generate a password. Also, when the user instructs automatic password generation, the configuration may allow the user to select whether to generate the entire password or to complete a portion of the password. Note that the automatic password generation may be performed according to a known algorithm, and may generate an entire password that complies with the password policy, or may complete a character string that does not satisfy compliance.

[0098] As described above, according to the fourth embodiment, in addition to the effects of the second and third embodiments, it is possible to automatically generate a password that satisfies compliance, thereby reducing the effort required by the user to set a password that meets compliance requirements.

[0099] The present disclosure is not limited to the above-described embodiments, and various modifications are possible. In other words, embodiments obtained by combining technical means that are appropriately modified within the scope of the gist of the present disclosure are also included in the technical scope of the present disclosure.

[0100] Although the above-described embodiments are described separately for the sake of convenience, they may be combined and executed within the scope of technical feasibility.

[0101] In addition, the programs that run on each device in the embodiments are programs that control the CPU, etc. (programs that make a computer function) so as to realize the functions of the above-described embodiments. Information handled by these devices is temporarily stored in a temporary storage device (e.g., RAM) during processing, and then stored in various storage devices such as ROMs (Read Only Memories) and HDDs, and is read, modified, and written by the CPU as needed.

[0102] Here, the computer-readable non-transitory recording medium on which the program is recorded in the information processing device may be any of semiconductor media (e.g., ROM, non-volatile memory card, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray (registered trademark) Disc, etc.)), magnetic recording media (e.g., magnetic tape, flexible disk, etc.). In this case, the program recorded on the recording medium is read by the computer of the information processing device and executed by the computer, thereby realizing not only the functions of the above-mentioned embodiments, but also the functions of the present disclosure, which are realized by processing in cooperation with an operating system or other application programs, etc., based on instructions from the program.

[0103] Furthermore, when distributing the program on the market, the program can be stored in a portable recording medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is also included in the present disclosure.

[0104] Furthermore, each functional block or feature of the device used in the above-described embodiments can be implemented or performed by an electrical circuit, for example, an integrated circuit or multiple integrated circuits. The electrical circuit designed to realize the functions described herein may include a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gates or Tronistor logic, discrete hardware components, or a combination thereof. The general-purpose processor may be a microprocessor, or a conventional processor, controller, microcontroller, or state machine. The electrical circuit may be composed of digital circuits or analog circuits. Furthermore, as advances in semiconductor technology emerge, one or more aspects of the present disclosure may utilize new integrated circuits based on that technology. [Explanation of symbols]

[0105] 10,30 Information processing equipment 11 Control section 13 Display section 15 Operation input section 17 Communications Department 19,39 Storage section 191 Control Program 192 Display Control Program 193 Policy Application Judgment Program 194 Compliance Determination Program 195 Password Registration Program 196 Certification Program 197 Password Policy Storage 198 Authentication information storage area 391 Password Generator 21 Image processing section 211 Image forming unit 213 Image Input Unit

Claims

1. An information processing device capable of communicating with an external device via a network based on the operation authority of an authenticated user, a storage unit that stores at least a first password policy and a second password policy different from the first password policy as password policies defined for user authentication using a password; a control unit that determines whether or not the input password complies with the password policy to be applied, and determines whether or not the input password can be registered; The control unit an information processing apparatus for determining a password policy to be applied to said compliance determination based on a comparison of the strength of security levels between said first password policy and said second password policy;

2. The control unit 2. The information processing apparatus according to claim 1, wherein the password policy having the strongest strength is applied to the judgment of compliance based on the strength comparison.

3. 2. The information processing apparatus according to claim 1, wherein the first password policy is a password policy that depends on a region, and the second password policy is a password policy that depends on the information processing apparatus.

4. a priority order is set between the first password policy and the second password policy to be applied as the password policy; The control unit The information processing device described in claim 1, characterized in that if the first password policy has a higher priority, compliance with the first password policy is mandatory, and the user is prompted to reset the password so that compliance with the second password policy, which has a lower priority than the first password policy, is satisfied.

5. The control unit 2. The information processing device according to claim 1, further comprising: a comparison between items relating to the first password policy and items relating to the second password policy; and determining the password policy consisting of items that form the strongest combination as the password policy to be applied to the compliance determination.

6. The control unit If it is determined that the compliance is satisfied, the input password is registered as an authentication password; 2. The information processing apparatus according to claim 1, wherein, when it is determined that the compliance is not satisfied, registration of the input password as the authentication password is restricted, and the user is prompted to reset the password.

7. The control unit 2. The information processing apparatus according to claim 1, wherein, when it is determined that the compliance is not satisfied, a reset password for satisfying the compliance is automatically generated.

8. The control unit 2. The information processing apparatus according to claim 1, wherein the password registration process is performed at the time of initial startup of the information processing apparatus.

9. The control unit 9. The information processing apparatus according to claim 8, wherein, when the password registered at the time of the initial startup is changed and the compliance is no longer satisfied, the information processing apparatus prompts the user to reset the password.

10. A method for registering a password in an information processing device that is capable of communicating with an external device via a network based on the operation authority of an authenticated user, comprising: storing at least a first password policy and a second password policy different from the first password policy as password policies specified in user authentication using a password; determining whether the input password complies with the password policy to be applied, and determining whether the input password can be registered; A password registration method for an information processing device, comprising: determining a password policy to be applied to the judgment of compliance based on a strength comparison between the first password policy and the second password policy.

Citation Information

Patent Citations

  • Security Policy Analyzer Service and Satisfiability Engine

    JP2020525898A