Image forming apparatus and user authentication method
The image forming apparatus strengthens maintenance user authentication by requiring administrator intervention for password changes, addressing regulatory demands for unique passwords and enhancing security measures.
Patent Information
- Application Number
- JP2024014311
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-01
- Publication Date
- 2025-08-14
AI Technical Summary
Existing image forming devices lack sufficient security measures for authentication processing of maintenance users, despite increasing regulatory demands for strengthened security in user authentication, particularly for unique passwords.
The image forming apparatus includes a display unit, memory unit, and control unit to manage authentication processing, requiring administrator input for maintenance users to change their passwords, either by setting the administrator's password as the maintenance password or using a random password confirmable only by the administrator.
This enhances security by ensuring that maintenance user passwords are changed and managed securely, aligning with regulatory requirements for unique passwords and strengthening authentication processes.
Smart Images

Figure 2025119429000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an image forming apparatus and the like. [Background technology]
[0002] In recent years, in order to strengthen security in authentication processing in image forming apparatuses, there has been an increasing demand for unique passwords for user authentication.
[0003] In a typical image forming device, authentication processing using authentication information such as a password entered by the user is accompanied by identification of whether the user belongs to one of the user categories: general user, administrator user, or maintenance user (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2010-061579 Summary of the Invention [Problem to be solved by the invention]
[0005] The present disclosure aims to provide an image forming apparatus and the like that can strengthen security regarding authentication processing for a maintenance user in the image forming apparatus. [Means for solving the problem]
[0006] In order to solve the above problem, the image forming apparatus according to the present disclosure includes a display unit, a memory unit that stores authentication information of a user of the image forming apparatus, and a control unit that controls authentication processing for the user, and when the authentication information of an administrator user who manages the image forming apparatus is stored as authentication information of a maintenance user who performs maintenance on the image forming apparatus, the control unit controls the display unit to display a notification on an authentication screen for the maintenance user requesting the administrator user to input authentication information, and when the authentication processing for the maintenance user is successful, controls the display unit to display a notification prompting the maintenance user to change the authentication information, and when the authentication information of the maintenance user is changed, stores the changed authentication information of the maintenance user.
[0007] Furthermore, the user authentication method according to the present disclosure is characterized in that it stores authentication information of a user of an image forming device, and when authentication information of an administrator user who manages the image forming device is stored as authentication information of a maintenance user who performs maintenance on the image forming device, it controls a display device to display a notification on an authentication screen for the maintenance user requesting input of the administrator user's authentication information, and when the authentication process for the maintenance user is successful, it controls the display device to display a notification prompting a change of the maintenance user's authentication information, and when the authentication information of the maintenance user is changed, it stores the changed authentication information of the maintenance user. [Effects of the Invention]
[0008] According to the present disclosure, it is possible to provide an image forming apparatus and the like that can strengthen security regarding authentication processing of a maintenance user in the image forming apparatus. [Brief explanation of the drawings]
[0009] [Figure 1] 1 is a diagram illustrating the overall configuration of an image forming apparatus according to a first embodiment. [Figure 2] FIG. 2 is a diagram illustrating the functional configuration of the image forming apparatus according to the first embodiment. [Figure 3]10A and 10B are diagrams illustrating setting information stored in a setting information storage area. [Figure 4] FIG. 2 is a diagram illustrating a processing flow according to the first embodiment. [Figure 5] FIG. 1 is a diagram illustrating a conventional technique. [Figure 6] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 7] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 8] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 9] FIG. 2 is a diagram illustrating an example of operation according to the first embodiment. [Figure 10] FIG. 10 is a diagram illustrating an example of operation according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, embodiments of the present disclosure will be described with reference to the drawings. In this disclosure, a multifunction peripheral capable of performing jobs related to copying, faxing, email, etc. in a single housing will be described as one form of an image forming apparatus according to the present disclosure. Note that the following embodiment is an example for explaining the present disclosure, and the technical content of the description set forth in the claims is not limited to the following description.
[0011] In Europe, the United States, and Asian countries, including Japan, laws and regulations are being established to strengthen the security of IoT (Internet of Things) devices. Image forming devices introduced to the market in these regions and countries must comply with these laws and regulations, and some devices require users to configure the necessary settings.
[0012] For example, the UK's Product Security and Telecommunications Infrastructure Bill (PSTI) prohibits the use of default passwords or passwords that are easily guessed for terminal devices that can connect to the Internet, and requires that passwords used be unique.
[0013] In response to this trend, measures have been taken to strengthen security for authentication processes using passwords for general users, administrator users, etc., such as requiring users to change their default (or unset) password in the initial setup wizard when starting up the image forming device for the first time.
[0014] However, with regard to authentication processing using a password for a maintenance user, there are currently no measures that are equivalent to strengthening security for authentication processing for general users, administrator users, and the like.
[0015] Here, a general user according to the present disclosure is a user who has been granted operational authority to use functions realized by an image forming apparatus. An administrative user is a user who, in addition to the operational authority of a general user, has been granted operational authority to operate an image forming apparatus, such as user management settings, network settings, hardware settings, and system settings. In this disclosure, general users and administrative users may be referred to as end users. Unlike end users, users who belong to the image forming apparatus manufacturer, sales (agency), or equipment management department of a company or organization and who maintain and manage image forming apparatuses are referred to as maintenance users (non-end users) in this disclosure.
[0016] In the present disclosure, an image forming apparatus and the like capable of strengthening security regarding authentication processing of a maintenance user in the image forming apparatus is realized in the following embodiments.
[0017] [1 First Embodiment] In the first embodiment, a multifunction peripheral will be described as an example of the image forming device 10, but the image forming device 10 may also be a printer, copier, fax machine, etc. with limited job functions of various types, other than a multifunction peripheral.
[0018] [1.1 Functional Configuration] 1 is a diagram illustrating the overall configuration of an image forming apparatus 10 according to the first embodiment. FIG. 2 is a functional configuration diagram of the image forming apparatus 10.
[0019] The image forming apparatus 10 includes, as functional components, a control unit 11, a display unit 13, an operation input unit 15, a communication unit 17, a storage unit 19, and an image processing unit 21.
[0020] The control unit 11 controls the entire image forming apparatus 10. The control unit 11 can be configured with one or more processing devices (e.g., a CPU (Central Processing Unit), an SoC (System on Chip), etc.). The control unit 11 realizes its functions by reading and executing various programs stored in the storage unit 19.
[0021] The display unit 13 is a display device that displays various information to the user, etc. The display unit 13 can be configured, for example, with an LCD (Liquid Crystal Display), an organic EL (Electro-Luminescence) display, etc. Based on the control of the control unit 11 that reads out a display control program 193 (described later), the display unit 13 displays, for example, a home screen (not shown) and operation screens such as setting screens related to the execution of each job, as well as a login screen that accepts input of authentication information (login name, password) of a user attempting to log in to the image forming apparatus 10, a setting screen related to an initial setting wizard, etc.
[0022] The operation input unit 15 is an input device that accepts information input by a user or the like. The operation input unit 15 can be configured with various input devices, such as operation keys such as hardware keys or software keys, buttons, etc. The operation input unit 15 can also be configured as a touch panel that allows input via the display unit 13. When configured as a touch panel, the operation input unit 15 can detect a user's touch, tap, swipe, etc. on an object displayed via the display unit 13, and acquire coordinate information, pressure-sensitive information, etc. on the touch panel. In this case, the input method of the touch panel can be, for example, a general input method such as a resistive film method, an infrared method, an electromagnetic induction method, or a capacitive method.
[0023] The communication unit 17 has either a wired or wireless interface or both for communicating with other terminal devices (not shown) via a network NW such as a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, a telephone line, a FAX line, etc. Furthermore, for example, the communication unit 17 may have an interface related to wireless communication technology such as Bluetooth (registered trademark), NFC (Near Field Communication), Wi-Fi (registered trademark), ZigBee (registered trademark), IrDA (Infrared Data Association), or wireless USB (Universal Serial Bus).
[0024] The storage unit 19 is one or more storage devices that store various programs and various data required for the operation of the image forming apparatus 10. The storage unit 19 can be configured with storage devices such as a RAM (Random Access Memory), an SSD (Solid State Drive), an HDD (Hard Disk Drive), or a ROM (Read Only Memory).
[0025] In the first embodiment, the storage unit 19 stores a start control program 191, a control program 192, a display control program 193, a login authentication program 194, a maintenance management program 195, and a job control program 196, and reserves a setting information storage area 197.
[0026] The boot control program 191 is a program that is read by the control unit 11 when the image forming apparatus 10 is booted. The control unit 11 that has read the boot control program 191 controls the boot process of the image forming apparatus 10. Such a boot control program 191 may be included, for example, in boot firmware or main firmware that is booted based on verification by the boot firmware. Note that the boot control program 191 may be stored in another storage device (storage area) (not shown) different from the storage unit 19 in order to achieve secure boot, or may be stored in another terminal device (not shown) on the network NW.
[0027] The startup control program 191 includes a wizard setting program 1911. The control unit 11 reads out the wizard setting program 1911 when the image forming apparatus 10 is started up, for example, at the first startup after power-on (initial startup) or at the first startup after initialization of the storage unit 19, which requires initial settings.
[0028] The wizard setting program 1911 is a program that the control unit 11 reads out when performing the initial settings required for operating the device at the first start-up after power-on or at the start-up after device initialization. After reading out the wizard setting program 1911, the control unit 11 proceeds with the initial settings while displaying an operation screen on the display unit 13 (operation input unit 15) that assists with the initial settings and accepts input for device settings.
[0029] The control program 192 is a program that is read by the control unit 11 after the device is started up based on the startup control program 191. The control unit 11 that reads the control program 192 functions as an OS (Operating System) and controls the driving of hardware such as the display unit 13, the operation input unit 15, the communication unit 17, and the image processing unit 21. The control unit 11 that reads the control program 192 controls the operation of the image forming device 10 according to the user classification of the logged-in user.
[0030] The display control program 193 is a program that is read by the control unit 11 when performing output control of the operation screen displayed on the display unit 13 or the operation input unit 15 configured as a touch panel. The control unit 11 that reads the display control program 193 controls the display on the display unit 13 (operation input unit 15).
[0031] The login authentication program 194 is a program that is read by the control unit 11 in order to authenticate a user who attempts to log in to the image forming apparatus 10. The control unit 11 enables the user authentication function by reading the login authentication program 194. Note that the login authentication program 194 can be read, for example, automatically when the apparatus is started up, or by providing an operation button on a system setting screen or the like for switching the user authentication function on and off, and reading the login authentication program 194 when the user selects the operation button.
[0032] The control unit 11, which has read out the login authentication program 194, displays a login screen (described later) on the display unit 13. The control unit 11 stores a login name and a login password in advance in association with each other in a setting information storage area 197 (described later), and performs user authentication processing by comparing the login name and login password entered via the login screen.
[0033] The maintenance management program 195 is a program that is read by the control unit 11 when the user who has logged in to the image forming apparatus 10 is a maintenance user. The control unit 11 that reads the maintenance management program 195 provides the maintenance user with functions (for example, printing a test page and managing job and system logs) required for maintenance management of the image forming apparatus 10 via a maintenance (maintenance management) screen, which will be described later.
[0034] The job control program 196 is a program that the control unit 11 reads when executing a print job related to printing, copying, etc., or a transmission job related to faxing or image transmission. After reading the job control program 196, the control unit 11 transitions to a job mode (print mode, copy mode, fax mode, image transmission mode, etc.) for executing each job and executes the job. When executing a job, the control unit 11 can display an operation screen on the touch panel as necessary to accept selection of setting values and functions required for executing the job from the user. The control unit 11 can execute the job based on the setting values and functions accepted via the operation screen.
[0035] The setting information storage area 197 is a storage area that stores device settings of the image forming device 10. The setting information that can be stored in the setting information storage area 197 can include, for example, user management items for managing user authentication information, setting items for authentication processing for maintenance users, and the like.
[0036] Here, the setting items stored in the setting information storage area 197 will be described with reference to Fig. 3. Fig. 3 is a diagram illustrating an example of a setting information table that manages the setting information stored in the setting information storage area 197. Note that the setting information stored in the setting information storage area 197 may be managed in a database format.
[0037] 3 is an example of a setting information table that includes user management items and setting items for authentication processing for maintenance users as setting items. In addition to this information, the setting information table can also manage setting information related to network settings, hardware settings, system settings, etc.
[0038] The user management items are setting items for managing users who operate the image forming apparatus 10, and include, as setting contents, for example, an ID, a login name, a login password (PW), and a user classification.
[0039] The ID is an identifier for uniquely identifying a user of the image forming device 10. The login name indicates the login name of the user. The login password (PW) is the login password associated with the login name. The user category indicates the operating authority given to the user who has logged in to the image forming device 10.
[0040] For example, the user identified by ID "0001" has the login name "User A" and the password required for login authentication is "**********". The operation authority of the "user" is "administrator user". Also, the user identified by ID "0014" has the login name "User N" and the password required for login authentication is "********". The operation authority of "User N" is "general user".
[0041] On the other hand, the user identified by ID "00ZZ" has the login name "Service" and the password required for login authentication is "********". The operating authority for "Service" is "Maintenance User".
[0042] The setting items for the authentication process for the maintenance user are setting items related to the authentication process for the maintenance user, and include a pattern identifier and a reference password (PW).
[0043] Here, the following two patterns are explained as authentication processes for maintenance users. Pattern A: The administrator user password is set as the maintenance user password (maintenance password), and the maintenance user is prompted to enter the password when authenticating login. Pattern B: A password that can only be confirmed by the administrator user (for example, a random password in which the characters that make up the password are arranged randomly) is set as the password for the maintenance user, and the administrator user's password is required to be confirmed (entered) when the maintenance user attempts to log in and authenticate.
[0044] In both the authentication processes according to Pattern A and Pattern B, authentication assistance from the administrator user is requested when a maintenance user (for the first time) logs in to the image forming apparatus 10. Therefore, by applying either the authentication process according to Pattern A or Pattern B to the login authentication process for the maintenance user, the security of the image forming apparatus 10 can be strengthened.
[0045] Figure 3 shows that "Pattern A" has been set as the authentication process for the maintenance user, and that the password set as the maintenance password is the password for "Administrator (ID: 0001)."
[0046] Whether to apply the authentication process of Pattern A or Pattern B to the maintenance user as the authentication process can be set in advance, for example, before starting the initial setup wizard (for example, at the time of shipping from the factory, etc.). Then, by automatically applying the maintenance password related to the preset Pattern A or Pattern B after the processing of the initial setup wizard is completed, it is possible to reduce the effort and attention of the end user who actually processes the initial setup wizard.
[0047] Returning to FIG. 2 again, image processing unit 21 includes image forming unit 211 and image input unit 213. Image forming unit 211 feeds paper from paper feed unit 25, forms an image on the paper based on image data, and then discharges the paper to paper discharge unit 27. Image forming unit 211 can be configured, for example, by a laser printer that employs an electrophotographic method. In this case, image forming unit 211 forms an image using toner supplied from toner cartridges (not shown) that correspond to toner colors (for example, cyan, magenta, yellow, and black).
[0048] The image input unit 213 generates image data by scanning an original. The image input unit 213 may be configured as a scanner device equipped with an image sensor such as a CCD (Charge Coupled Device) or a CIS (Contact Image Sensor), as well as an automatic document feeder (ADF) and a flatbed for placing and reading an original. The image input unit 213 is not particularly limited in configuration as long as it is capable of reading a reflected light image from an original image using an image sensor. The image input unit 213 may also be configured as an interface capable of acquiring image data stored in a storage medium such as a USB memory or image data transmitted from a terminal device (not shown). The image processing unit 21 may be configured to perform, for example, shading correction or density correction on the image data input from the image input unit 213 to generate image data for image transmission.
[0049] [1.2 Processing flow] Next, a processing flow according to the first embodiment will be described. Fig. 4 is a flowchart illustrating authentication processing from login authentication by a maintenance user to password change according to the first embodiment. Note that the processing described in Fig. 4 is processing executed by reading out the control program 192, display control program 193, login authentication program 194, maintenance management program 195, etc.
[0050] First, the control unit 11 receives an instruction to display a login screen when the image forming apparatus 10 is started (whether it is the first time after power-on or not), when the image forming apparatus 10 is restored from sleep mode, etc. (step S100).
[0051] When the control unit 11 receives the instruction to display the login screen, the control unit 11 displays the login screen on the display unit 13 (operation input unit 15) (step S110).
[0052] Next, the control unit 11 determines authentication processing for the maintenance user by referring to the device settings stored in the setting information storage area 197 illustrated in Fig. 3 (step S120). Note that in step S120, if the login name entered on the login screen is the login name of the maintenance user, "service," it is also possible to configure the processing from step S130 onwards to be executed. In this case, if the login name entered on the login screen is that of an end user (a general user or an administrator user), the processing from step S130 onwards may be omitted, and the screen may transition to a home screen or a job setting screen (not shown).
[0053] If it is determined that the authentication process set for the maintenance user is pattern A, the control unit 11 displays a message stating that the password of the administrator user (administrator password) has been set as the maintenance password, and requests the administrator user to log in to the image forming device 10 (step S120; pattern A → step S130 → step S140).
[0054] The control unit 11 determines whether the administrator user has successfully logged in to the image forming apparatus 10. If it is determined that the login has been successful, the control unit 11 transitions the screen to a maintenance password change screen (step S150; Yes→step S160). On the other hand, if it is determined that the login has not been successful, the control unit 11 returns the process to step S140 (step S150; No→step S140).
[0055] The control unit 11 displays a message to the maintenance user urging them to change the maintenance password (step S170). Then, when the control unit 11 accepts a change of the maintenance password by the maintenance user, it stores the changed password as a new maintenance password and ends the process (step S180; Yes → step S190). Note that if the control unit 11 does not accept a change of the maintenance password by the maintenance user, it continues to display the message urging them to change the maintenance password (step S180; No → step S170). At this time, the control unit 11 may restrict screen transitions to other maintenance screens until the maintenance password is changed.
[0056] Meanwhile, if it is determined that the authentication process set for the maintenance user is pattern B, the control unit 11 displays a message indicating that a random password that can only be confirmed by the administrator user has been set as the maintenance password (step S120; pattern B; → step S200).
[0057] Next, the control unit 11 determines whether or not an instruction to confirm the random password from the maintenance user has been accepted. If it is determined that an instruction to confirm the random password from the maintenance user has been accepted, the control unit 11 displays an authentication screen for the administrator user (administrator authentication screen) (step S210; Yes→step S220). On the other hand, if the control unit 11 determines that an instruction to confirm the random password from the maintenance user has not been accepted, the process proceeds to step S160 (step S210; No→step S160).
[0058] The control unit 11 determines whether authentication of the administrator user via the displayed administrator authentication screen has been successful. If it is determined that authentication of the administrator user has been successful, the control unit 11 displays a random password confirmation screen including a random password (step S230; Yes → step S240). Once the administrative user has confirmed the random password, the control unit 11 proceeds to step S160. In this case, the control unit 11 may also proceed to step S160 if it receives a random password input by the administrative user and the received random password matches the random password displayed on the random password management screen. Furthermore, once the control unit 11 receives a change of the maintenance password by the maintenance user, it terminates display of the random password confirmation screen.
[0059] [1.3 Example of operation] Prior to describing an example of operation according to the first embodiment, the authentication process for a maintenance user according to the prior art will be described with reference to FIG. 5. FIG. 5(a) is a diagram illustrating an example of the configuration of a login screen W10 for a maintenance user. FIG. 5(b) is a diagram illustrating an example of the configuration of a maintenance screen W20 that the control unit 11 displays on the display unit 13 (operation input unit 15) when the authentication process for a maintenance user is successful. FIG. 5(c) is a diagram illustrating an example of the configuration of a maintenance password change screen W30 that accepts a change of the maintenance password.
[0060] The login screen W10 shown in FIG. 5(a) includes an authentication information input field R10 and a login button B10. The authentication information input field R10 is an input field that accepts input of the maintenance user's login name and login password. A maintenance user attempting to log in to the image forming apparatus 10 enters their login name and login password in the authentication information input field R10. The login button B10 is a selection button that accepts an instruction to confirm the input content in the authentication information input field R10. When the control unit 11 accepts an instruction to select the login button B10 by the maintenance user, it executes authentication processing for the maintenance user.
[0061] The maintenance screen W20 shown in FIG. 5(b) is a setting screen that provides functions required for maintenance management of the image forming apparatus 10 by a maintenance user who has successfully logged in to the image forming apparatus 10 (for example, printing a test page, managing job system logs, etc.). The maintenance screen W20 includes a password setting button B50 that accepts an instruction to change the maintenance password. When the control unit 11 accepts an instruction to select the password setting button B50 by the maintenance user, it displays the maintenance password change screen W30, which will be described in the next figure.
[0062] The maintenance password change screen W30 includes a password input field R12 and a Register (U) button B12. The password input field R12 is an input field that accepts input of a changed password. The Register (U) button B12 is a selection button that accepts an instruction to confirm the input content in the password input field R12. When the control unit 11 accepts an instruction to select the Register (U) button B12 by the maintenance user, the control unit 11 stores the changed password entered in the password input field R12 as the maintenance password.
[0063] Next, an operation example according to the first embodiment will be described. Fig. 6 is a diagram illustrating an example of the configuration of a login screen W101 that displays a message screen M10 indicating that the authentication process for the maintenance user is an authentication process according to pattern A and that the password of the administrator user (administrator password) has been set as the maintenance password. Fig. 6 is an operation example corresponding to step S130 in Fig. 4.
[0064] The message screen M10 includes a message such as "An administrator password has been set. Please have the administrator (administrator user) log in.", and an [OK] button B14. When the [OK] button B14 is selected, the control unit 11 displays a login screen for accepting authentication processing of the administrator user (not shown), and accepts input of authentication information by the administrator user. The control unit 11 executes authentication processing of the administrator user based on the accepted authentication information. When the administrator user successfully logs in, the control unit 11 skips displaying the maintenance screen W20 shown in FIG. 5(b) and displays a maintenance password change screen W301, which will be described in the next figure.
[0065] 7 is a diagram illustrating an example of the configuration of a maintenance password change screen W301 that displays a message screen M12 prompting the maintenance user to change the maintenance password. Note that FIG. 7 shows an example of the operation corresponding to step S170 in FIG.
[0066] The message screen M12 includes a message such as "Maintenance worker, please set a new password," and an [OK] button B16. When the control unit 11 receives an instruction to select the [OK] button B16, it ends the display of the message screen M12, displays the password input area R12 illustrated in FIG. 5(c), and accepts input of the changed password. When the maintenance user inputs the changed password and receives an instruction to select the register button B12, the control unit 11 stores the changed password as the maintenance password.
[0067] 8 is a diagram illustrating an example of the configuration of a login screen W103 that displays a message screen M14 indicating that the authentication process for the maintenance user is the authentication process related to pattern B and that a random password that can only be confirmed by the administrator user has been set. Note that FIG. 8 is an example of the operation corresponding to step S200 in FIG. 4.
[0068] The message screen M14 includes a message such as "A random password has been set. Only the administrator can view the random password. Do you want to confirm the random password?", a "Yes" button B18, and a "No" button B20. When the "Yes" button B18 is selected, the control unit 11 displays a login screen W105 that accepts authentication processing for the administrator user, which will be described in the next figure, Figure 9(a), and accepts input of authentication information by the administrator user. The control unit 11 executes authentication processing for the administrator user based on the accepted authentication information. When the administrator user successfully logs in, the control unit 11 displays a random password confirmation screen W303 that includes the random password, which will be described in the next figure, Figure 9(b).
[0069] FIG. 9(a) is a diagram illustrating an example of the configuration of a login screen W105 that accepts authentication processing for an administrator user. Note that FIG. 9(a) is an example of operation corresponding to the processing of step S220 in FIG. 4. The login screen W105 includes an authentication information input field R14 and a login button B22. The authentication information input field R14 is an input field that accepts input of the administrator user's login name and login password. An administrator user attempting to log in to the image forming apparatus 10 enters their login name and login password in the authentication information input field R14. The login button B22 is a selection button that accepts an instruction to confirm the input content in the authentication information input field R14. When the control unit 11 accepts an instruction to select the login button B22 by the administrator user, it executes authentication processing for the administrator user.
[0070] FIG. 9(b) is a diagram illustrating an example of the configuration of the random password confirmation screen W303. Note that FIG. 9(b) is an example of operation corresponding to the processing of step S240 in FIG. 4. The random password confirmation screen W303 includes a random password (maintenance password) display area R16 and an Update (R) button B24. The random password (maintenance password) display area R16 is a display area that displays a random password that can only be confirmed by an administrator user who has successfully logged in. The Update (R) button B24 is a selection button that accepts an instruction from the administrator user to confirm the random password. When the control unit 11 accepts an instruction to select the Update (R) button B24 from the administrator user, the control unit 11 skips the display of the maintenance screen W20 illustrated in FIG. 5(b) and executes the processing from step S160 onwards in FIG. 4 to change the maintenance password.
[0071] As described above, according to the first embodiment, by applying either of the following authentication processes for the maintenance user: Pattern A (the password of the administrator user is set as the password (maintenance password) of the maintenance user, and the administrator user is requested to enter the password when authenticating the maintenance user to log in) or Pattern B (a password that can only be confirmed by the administrator user (for example, a random password in which character strings constituting the password are randomly arranged) is set as the password (maintenance password) of the maintenance user, and the administrator user is requested to confirm (input) the password when authenticating the maintenance user to log in), it is possible to strengthen security regarding the authentication process of the maintenance user in the image forming device.
[0072] [2 Second Embodiment] In the first embodiment, a configuration has been described in which whether to apply authentication processing of pattern A or pattern B as authentication processing for a maintenance user is set in advance before starting the initial setting wizard (for example, at the time of shipping from the factory, etc.). In the second embodiment, an end user is allowed to select whether to apply password settings related to authentication processing of pattern A or pattern B as one setting item included in the initial setting wizard.
[0073] The functional configuration of the image forming apparatus 10 according to the second embodiment and the flow of processing such as authentication processing for a maintenance user are the same as those in the first embodiment, and therefore description thereof will be omitted here.
[0074] [2.1 Example of operation] FIG. 10 is a diagram illustrating an example of the configuration of a wizard screen that constitutes the initial setting wizard according to the second embodiment.
[0075] FIG. 10(a) shows an example of the configuration of a wizard screen W200 that notifies the end user that the initial setup wizard will begin. The wizard screen W200 includes a message with the notification content "Initial setup will begin. Do not turn off the device until setup is complete," as well as a Next button B26 and a Back button B28. After confirming that the initial setup wizard will begin, the end user can proceed with the initial setup wizard by selecting the Next button B26. When the control unit 11 receives an instruction from the end user to select the Back button B28, it terminates the initial setup wizard.
[0076] FIG. 10(b) shows an example of a wizard selection screen W210 that allows an end user to select whether to apply password settings related to either Pattern A or Pattern B authentication processing in the authentication processing for the maintenance user. The wizard selection screen W210 is configured to allow the end user to select either "(1) Set with the administrator user's password (Pattern A)" or "(2) Set with a random password that can only be confirmed by the administrator user (Pattern B)." After selecting the desired password setting, the end user can confirm the authentication processing (password setting) to be applied in the authentication processing for the maintenance user by selecting the Next button B26. The authentication processing (password setting) selected by the end user is stored in the setting information storage area 197 described in FIG. 3 and is read out during the authentication processing for the maintenance user. When the control unit 11 receives an instruction to select the Back button B28 by the end user, the control unit 11 transitions to the previous wizard screen without confirming the authentication processing selected by the end user.
[0077] FIG. 10(c) shows an example of the configuration of a wizard screen W220 that notifies the end user that the initial setup wizard will be terminated. The wizard screen W220 includes a message with the following notification content: "All settings are complete. You can now use the main functions. Select [Finish] to terminate. The device will automatically restart. Please wait without turning off the power.", as well as a Finish button B30 and a Back button B28. After confirming that the initial setup wizard will be terminated, the end user can terminate the initial setup wizard by selecting the Finish button B30. When the control unit 11 receives an instruction from the end user to select the Back button B28, it transitions the screen to the previous wizard screen.
[0078] As described above, according to the second embodiment, in addition to the effects of the first embodiment, the end user can select whether to apply password settings related to the authentication process of either Pattern A or Pattern B as one setting item included in the initial setting wizard, thereby providing an image forming device with greater operability in terms of enhanced security.
[0079] The present disclosure is not limited to the above-described embodiments, and various modifications are possible. In other words, embodiments obtained by combining technical means that are appropriately modified within the scope of the gist of the present disclosure are also included in the technical scope of the present disclosure.
[0080] Furthermore, although the above-described embodiments are described separately for the sake of convenience, they may of course be combined and executed within the scope of technical feasibility.
[0081] In addition, the programs that run on each device in the embodiments are programs that control the CPU, etc. (programs that make a computer function) so as to realize the functions of the above-described embodiments. Information handled by these devices is temporarily stored in a temporary storage device (e.g., RAM) during processing, and then stored in various storage devices such as ROMs (Read Only Memories) and HDDs, and is read, modified, and written by the CPU as needed.
[0082] Here, the computer-readable non-transitory recording medium on which the program is recorded in the information processing device may be any of semiconductor media (e.g., ROM, non-volatile memory card, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray (registered trademark) Disc, etc.)), magnetic recording media (e.g., magnetic tape, flexible disk, etc.). In this case, the program recorded on the recording medium is read by the computer of the information processing device and executed by the computer, thereby realizing not only the functions of the above-mentioned embodiments, but also the functions of the present disclosure, which are realized by processing in cooperation with an operating system or other application programs, etc., based on instructions from the program.
[0083] Furthermore, when distributing the program on the market, the program can be stored in a portable recording medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is also included in the present disclosure.
[0084] Additionally, each functional block or feature of the device used in the above-described embodiments may be implemented or performed by an electrical circuit, such as an integrated circuit or multiple integrated circuits. The electrical circuit designed to realize the functions described herein may include a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gates or Tronistor logic, discrete hardware components, or a combination thereof. The general-purpose processor may be a microprocessor, a conventional processor, a controller, a microcontroller, or a state machine. The electrical circuit may be composed of digital circuits or analog circuits. Furthermore, as advances in semiconductor technology emerge, one or more aspects of the present disclosure may utilize new integrated circuits based on that technology. [Explanation of symbols]
[0085] 11 Control section 13 Display section 15 Operation input section 17 Communications Department 19 Memory section 191 Startup Control Program 1911 Wizard Setup Program 192 Control Program 193 Display Control Program 194 Login Authentication Program 195 Maintenance Management Program 196 Job Control Program 197 Setting information storage area 21 Image processing section 211 Image forming unit 213 Image Input Unit
Claims
1. A display unit; a storage unit that stores authentication information of a user of the image forming apparatus; a control unit that controls authentication processing for the user, The control unit When authentication information of an administrator user who manages the image forming apparatus is stored as authentication information of a maintenance user who maintains the image forming apparatus, controlling the display unit to display a notification requesting input of authentication information by the administrator user on an authentication screen for the maintenance user; An image forming apparatus characterized in that, if the authentication process for the maintenance user is successful, the display unit is controlled to display a notification prompting the maintenance user to change their authentication information, and if the authentication information of the maintenance user is changed, the image forming apparatus stores the changed authentication information of the maintenance user.
2. The control unit If authentication information that can only be confirmed by the administrator user is stored as the authentication information of the maintenance user, The image forming apparatus according to claim 1 , wherein the display unit is controlled to display a notification requesting confirmation of authentication information that can only be confirmed by the administrator user by the administrator user.
3. The control unit 2. The image forming apparatus according to claim 1, wherein after the authentication information of the maintenance user is changed, a request for input of authentication information by the administrator user is restricted.
4. The control unit The image forming apparatus according to claim 2, characterized in that when a setting process is executed at the initial startup of the image forming apparatus, it is set whether to store the authentication information of the administrator user as the authentication information of the maintenance user or to store authentication information that can only be confirmed by the administrator user as the authentication information of the maintenance user.
5. The control unit 3. The image forming apparatus according to claim 1, wherein a screen transition from a screen for changing the authentication information of the maintenance user to another screen is restricted until the authentication information of the maintenance user is changed.
6. storing authentication information of a user of the image forming device; When authentication information of an administrator user who manages the image forming apparatus is stored as authentication information of a maintenance user who maintains the image forming apparatus, controlling a display device to display a notification requesting input of authentication information by the administrator user on an authentication screen for the maintenance user; A user authentication method characterized by controlling the display device to display a notification prompting the maintenance user to change their authentication information if the authentication process for the maintenance user is successful, and storing the changed authentication information for the maintenance user if the authentication information for the maintenance user is changed.
Citation Information
Patent Citations
Information processing apparatus
JP2010061579A