Image forming apparatus, control method for image forming apparatus, and control program for image forming apparatus
The image forming apparatus enhances biometric authentication by using external device data to adjust authentication criteria, balancing convenience and security by reducing false rejections without increasing false acceptances.
Patent Information
- Application Number
- JP2024017979
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-08
- Publication Date
- 2025-08-21
AI Technical Summary
Biometric authentication systems face a trade-off between convenience and security, with lower false rejection rates increasing the risk of false acceptance and vice versa, particularly in fingerprint-based methods which are less secure due to environmental and individual variations.
An image forming apparatus that integrates biometric authentication with an external device to gather identity probability information, adjusting authentication criteria based on user proximity and recent job commands to enhance security without compromising convenience.
The system reduces false rejections without increasing false acceptances by relaxing authentication levels for users who have recently issued job commands, thereby improving user experience while maintaining high security standards.
Smart Images

Figure 2025122467000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an image forming apparatus, a control method for an image forming apparatus, and a control program for an image forming apparatus. [Background technology]
[0002] Various proposals have been made in the past regarding biometric authentication technologies that use physical characteristics (hereinafter referred to as "biometric information") that vary from person to person, such as fingerprints, veins, and faces, as keys. For example, Patent Document 1 discloses a biometric authentication device that suggests an appropriate positioning of a biometric object to be authenticated. Patent Document 2 discloses a biometric authentication device that determines whether a biometric object to be authenticated is positioned using a template. Patent Document 3 discloses a biometric pattern imaging device that has a housing with an opening large enough to be covered in a sealed state when a biometric part is placed in the opening, and that captures an image of the biometric part placed in the opening.
[0003] Typically, when biometric authentication is implemented, the biometric information of each user is registered in a database in advance. Then, during authentication, a device equipped with biometric authentication compares the biometric information registered in the database with the biometric information acquired from the user to be authenticated and determines whether the user is the actual user based on the degree of similarity. That is, if the degree of match between the biometric information registered in the database and the biometric information acquired from the user to be authenticated is equal to or greater than a predetermined threshold, the device determines that the user to be authenticated is one of the users in the registered user group. On the other hand, if the degree of match with the biometric information acquired from the user to be authenticated is less than the predetermined threshold, the device determines that the user to be authenticated does not belong to any of the registered user groups.
[0004] Generally, the authentication accuracy of biometric authentication depends on the false rejection rate and the false acceptance rate. The false rejection rate (FRR) is the probability that a person is determined to be a false identity even though they are the person in question. On the other hand, the false acceptance rate (FAR) is the probability that a person who is not the person in question is mistakenly recognized as the person in question.
[0005] These can be adjusted by changing the threshold used for biometric authentication judgment, but there is a trade-off relationship, and reducing one increases the other. For example, by setting a small threshold, the probability of falsely rejecting the correct person can be reduced, but the probability of falsely identifying a different person as the correct person increases. Conversely, by setting a large threshold, the probability of falsely identifying a different person as the correct person can be reduced, but the probability of falsely rejecting the correct person increases. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-001843 [Patent Document 2] Japanese Patent Application Laid-Open No. 2014-146080 [Patent Document 3] Japanese Patent Application Laid-Open No. 2009-276860 Summary of the Invention [Problem to be solved by the invention]
[0007] The false rejection rate is directly linked to convenience, while the false acceptance rate is directly linked to security risks such as impersonation, but achieving both is a challenge in biometric authentication. For example, setting a low threshold value allows for a slightly lower degree of match with the biometric information, which shortens the time it takes for the biometric authentication device to acquire biometric information from the user to be authenticated. This also reduces the probability of authentication failure despite the person being the true identity. This situation is favorable in terms of convenience. However, this situation directly leads to security risks, as authentication may be successful even if the person is not the true identity.
[0008] There are various types of biometric authentication, and this issue may become more pronounced depending on the biometric authentication method. For example, fingerprint-based authentication methods are preferable from the perspective of convenience because they require less time to acquire biometric information than vein-based authentication methods. However, fingerprint-based authentication methods produce less authentication data than vein-based authentication methods. In addition, fingerprint-based authentication methods are susceptible to individual and environmental differences such as rough skin, dryness, and sweating, resulting in a larger noise component in the authentication data. Therefore, fingerprint-based authentication methods tend to have lower authentication accuracy than vein-based authentication methods. In other words, switching from the traditional vein-based authentication method to fingerprint-based authentication methods from the perspective of convenience may worsen the security risks described above.
[0009] The present disclosure has been made in consideration of the above-mentioned problems. It is an object of the present disclosure to provide an image forming apparatus that enables improved convenience without lowering the security level during biometric authentication. Another object of the present disclosure is to provide a control method for the image forming apparatus. Another object of the present disclosure is to provide a control program for the image forming apparatus. [Means for solving the problem]
[0010] The present disclosure mainly solves the above-mentioned problems by: An image forming apparatus connected to a biometric authentication device, which restricts use of the apparatus by unregistered users other than users registered in advance in a database, a first acquisition unit that acquires biometric information of the user to be authenticated via the biometric authentication device; an authentication unit that determines whether the user to be authenticated is any one of a group of registered users pre-registered in the database by biometric authentication processing of the biometric information of the user to be authenticated; a second acquisition unit that acquires, from an external device, information related to at least some of the registered users, identity probability information that indicates whether the users are present near the image forming device; a change unit that changes processing of the authentication unit related to conditions for accepting use of the image forming apparatus for at least some of the users based on the identity probability information; The image forming apparatus includes:
[0011] Also, from another point of view, 1. A control method for an image forming apparatus that is connected to a biometric authentication device and restricts use of the apparatus by unregistered users other than users pre-registered in a database, comprising: a first process of acquiring biometric information of a user to be authenticated via the biometric authentication device; a second process of determining whether the user to be authenticated is any user of a group of registered users pre-registered in the database through a biometric authentication process on the biometric information of the user to be authenticated; a third process of acquiring, from an external device, information relating to at least some of the registered users, the identity probability information indicating whether the users are present in the vicinity of the image forming device; a fourth process of changing the second process related to the conditions for accepting use of the image forming apparatus for at least some of the users based on the identity probability information; The present invention relates to a method for controlling an image forming apparatus that performs the above.
[0012] Also, from another point of view, A control program for an image forming apparatus that is connected to a biometric authentication device and restricts use of the apparatus to unregistered users other than users pre-registered in a database, comprising: On the computer, a first process of acquiring biometric information of a user to be authenticated via the biometric authentication device; a second process of determining whether the user to be authenticated is any user of a group of registered users pre-registered in the database through a biometric authentication process on the biometric information of the user to be authenticated; a third process of acquiring, from an external device, information relating to at least some of the registered users, the identity probability information indicating whether the users are present in the vicinity of the image forming device; a fourth process of changing the second process related to the conditions for accepting use of the image forming apparatus for at least some of the users based on the identity probability information; The control program for the image forming apparatus is a program for controlling the image forming apparatus. [Effects of the Invention]
[0013] According to the image forming apparatus according to the present disclosure, it is possible to improve convenience in biometric authentication without lowering the security level. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 1 is a diagram showing an example of the overall configuration of a printing system including an image forming apparatus according to a first embodiment; [Figure 2] FIG. 1 is a diagram showing an example of a hardware configuration of an image forming apparatus according to a first embodiment. [Figure 3] FIG. 1 is a diagram showing an example of a hardware configuration of a biometric authentication device according to a first embodiment. [Figure 4] FIG. 1 is a diagram showing an example of the functional configuration of a control unit according to a first embodiment; [Figure 5] FIG. 10 is a diagram showing an example of the configuration of a user information database according to the first embodiment; [Figure 6] FIG. 10 is a diagram showing an example of the configuration of accumulated job data according to the first embodiment; [Figure 7] FIG. 10 is a flowchart showing an example of a process of registering biometric information in a user DB by a control unit according to the first embodiment; [Figure 8] FIG. 1 is a diagram showing a basic flow of biometric authentication according to the first embodiment. [Figure 9] FIG. 1 is a flowchart illustrating an example of biometric authentication processing performed by a control unit according to a first embodiment. [Figure 10] FIG. 10 is a diagram showing an example of the functional configuration of a control unit according to a second embodiment; [Figure 11] FIG. 10 is a diagram showing a basic flow of biometric authentication according to a second embodiment. [Figure 12] FIG. 10 is a flowchart showing an example of biometric authentication according to a second embodiment. [Figure 13] FIG. 11 is a diagram showing an example of the functional configuration of a control unit according to a third embodiment; [Figure 14] FIG. 13 is a diagram showing an example of the functional configuration of a control unit according to a fourth embodiment; [Figure 15] FIG. 13 is a diagram showing an example of the configuration of entry and exit data according to the fourth embodiment; [Figure 16] FIG. 10 is a flowchart illustrating an example of biometric authentication processing according to a fourth embodiment. [Figure 17] FIG. 10 is a flowchart showing a modified example of biometric authentication processing according to the fourth embodiment. [Figure 18] FIG. 13 is a diagram showing an example of the functional configuration of a control unit according to a fifth embodiment; [Figure 19] FIG. 13 is a diagram showing an example of the configuration of radio wave intensity data according to the fifth embodiment; [Figure 20] FIG. 13 is a diagram showing an example of the functional configuration of a control unit according to a sixth embodiment; [Figure 21] FIG. 20 is a diagram showing an example of the configuration of user location data according to the sixth embodiment; DETAILED DESCRIPTION OF THE INVENTION
[0015] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. In this specification and drawings, components having substantially the same functional configurations are designated by the same reference numerals, and redundant description will be omitted.
[0016] [First embodiment] <Overall configuration of the printing system> First, an example of the overall configuration of a printing system (hereinafter referred to as a "printing system U") to which an image forming apparatus according to an embodiment of the present invention is applied will be described.
[0017] Fig. 1 is a diagram showing an example of the overall configuration of a printing system U including an image forming apparatus 1. Fig. 2 is a diagram showing an example of the hardware configuration of the image forming apparatus 1. Fig. 3 is a diagram showing an example of the hardware configuration of a biometric authentication device F.
[0018] The printing system U is configured by connecting a plurality of user terminals N1, N2, and N3 and an image forming apparatus 1 via a communication network M such as a LAN (Local Area Network) or a WAN (Wide Area Network).
[0019] User terminals N1, N2, and N3 are, for example, personal computers used individually by each user. Each of user terminals N1, N2, and N3 is configured to be able to send job execution commands, such as print instructions, to image forming apparatus 1 via communication network M. In the following, each of user terminals N1, N2, and N3 will be referred to as "user terminal N" as they have the same configuration. In this embodiment, "user terminal N" corresponds to the "external device" of the present invention.
[0020] The user terminal N includes a storage unit, a display unit, an operation unit, a communication unit, a control unit, etc. The user terminal N is capable of, for example, converting document data into print data in a page description language and issuing a print instruction to the image forming device 1.
[0021] The image forming apparatus 1 is, for example, a multifunction peripheral (MFP) that has a copy function, a facsimile function, a printer function, a scanner function, etc. The image forming apparatus 1 is installed, for example, in an office or a public facility.
[0022] The image forming apparatus 1 includes a control unit 10, a storage unit 20, an input unit 30, a display unit 40, a printing unit 50, a communication unit 60, an IF unit 70, an image processing unit 80, an image reading unit 90, and the like.
[0023] The control unit 10 comprehensively controls the processing operations of each unit of the image forming apparatus 1. The control unit 10 is composed of a CPU and the like, and reads out various programs and data stored in the storage unit 20 to execute various processes.
[0024] The storage unit 20 is composed of a ROM, a RAM, a hard disk, and the like that store various data and programs.
[0025] The input unit 30 is configured to include, for example, a keyboard and a pointing device. The input unit 30 outputs operation signals input by key operations on the keyboard or mouse operations to the control unit 10. The input unit 30 may also include a magnetic card reader or an IC card reader that reads ID cards held by each user.
[0026] The display unit 40 is configured, for example, by an LCD, and displays various operation screens and various processing results according to instructions from the control unit 10. The input unit 30 and the display unit 40 may be configured integrally as a touch panel.
[0027] The printing unit 50 prints on paper the print data that has been subjected to image processing by the image processing unit 80. The printing unit 50 is equipped with, for example, an inkjet or electrophotographic image forming mechanism. The printing unit 50 then prints the print data received from the user terminal N.
[0028] The communication unit 60 transmits and receives data to and from the user terminal N and other external devices via the communication network M.
[0029] The IF unit 70 is configured by a USB connector or the like, and enables the image forming apparatus 1 to directly communicate data with an external device. To the IF unit 70, for example, a biometric authentication device F is connected.
[0030] The image processing unit 80 creates intermediate data from the print data transferred from the user terminal N and develops it into bitmap data.
[0031] The image reading unit 90 optically scans an original placed on the contact glass, and then forms an image of the original on the light receiving surface of the CCD sensor using the light reflected from the original, and generates input image data based on the reading results.
[0032] The biometric authentication device F is a device that reads biometric information of a user. The biometric authentication device F includes, for example, a control unit F1 that controls each unit, a storage unit F2, a biometric information acquisition unit F3, and an IF unit F4. The biometric authentication device F has, for example, a CCD sensor and is configured to be able to acquire fingerprint image information as biometric information.
[0033] The biometric authentication device F transmits the acquired biometric information to the image forming apparatus 1 via the IF unit F4 (for example, USB connection).
[0034] The image forming apparatus 1 according to this embodiment is configured to perform biometric authentication processing using a fingerprint authentication method. However, the biometric authentication processing may be performed using biometric information other than fingerprints, such as palm prints, retinal patterns, voiceprint patterns, or facial features.
[0035] <Detailed Configuration of the Control Unit 10 of the Image Forming Apparatus 1> Here, the detailed configuration of the control unit 10 of the image forming apparatus 1 will be described.
[0036] The control unit 10 according to this embodiment is configured to request the user to log in based on biometric authentication every time permission is granted to use (for example, print) the image forming apparatus 1. That is, the control unit 10 locks the execution of various functions of the image forming apparatus 1 when the user is not logged in, so that only users who have logged in using biometric authentication can use the image forming apparatus 1.
[0037] Fig. 4 is a diagram showing an example of the functional configuration of the control unit 10. Fig. 5 is a diagram showing an example of the configuration of the user information database 21. Fig. 6 is a diagram showing an example of the configuration of the accumulated job list 22.
[0038] The control unit 10 according to this embodiment functions as a first acquisition unit 11, a registration unit 12, an authentication unit 13, a second acquisition unit 14, and a change unit 15.
[0039] The user information database 21 shown in Fig. 4 is a database that accumulates authentication information of a plurality of registered users stored in the storage unit 20 by a registration process described below. The user information database 21 typically registers biometric information of a plurality of users (hereinafter referred to as a registered user group) who use the image forming apparatus 1. The user information database 21 stores, for example, the ID and biometric information of each user in the registered user group in association with each other. Hereinafter, the user information database 21 will be abbreviated as "user DB21."
[0040] 4 is a list of job data that is temporarily stored in the storage unit 20 when a job execution command is issued from the user terminal N to the image forming apparatus 1. The stored job list 22 stores, for example, the ID of each user in the registered user group, the command content of the job execution command, and the time when the job execution command was received in association with each other.
[0041] When the control unit 10 according to this embodiment receives a job execution command (for example, a print execution command) from the user terminal N, it stores the job execution command in a pending state in the accumulated job list 22. Then, when the user who issued the job execution command logs in to the image forming apparatus 1, the control unit 10 enables execution of the job (for example, printing) related to the job execution command. Each job data in the accumulated job list 22 is deleted, for example, when the job related to the job execution command is executed on the image forming apparatus 1.
[0042] The first acquisition unit 11 acquires biometric information of a user from the biometric authentication device F. When registering the biometric information of a user in the user DB 21, the first acquisition unit 11 acquires the biometric information of the user to be registered via the biometric authentication device F. Furthermore, during authentication, the first acquisition unit 11 acquires the biometric information of the user to be authenticated via the biometric authentication device F.
[0043] The registration unit 12 performs a process of registering biometric information of a user. The registration unit 12 acquires the biometric information of the user to be registered from the first acquisition unit 11, associates the user ID of the user to be registered with the biometric information, and registers the biometric information in the user DB 21.
[0044] The authentication unit 13 executes biometric authentication processing on the biometric information of the user to be authenticated, with reference to the user DB 21. That is, the authentication unit 13 compares the biometric information of the user to be authenticated with the biometric information of a registered user group pre-registered in the user DB 21, and determines whether the user to be authenticated corresponds to any user in the registered user group.
[0045] The biometric authentication process itself in the authentication unit 13 is similar to conventionally known processes. For example, the authentication unit 13 calculates the degree of match between the biometric information of the user to be authenticated and the biometric information of each of a group of registered users pre-registered in the user DB 21. Then, the authentication unit 13 extracts a corresponding candidate user from the group of registered users based on the degree of match. Furthermore, if the degree of match is equal to or greater than a predetermined threshold, the authentication unit 13 authenticates the user to be authenticated as the corresponding candidate user.
[0046] That is, if there is no corresponding candidate user, the authentication unit 13 recognizes the user to be authenticated as an unregistered user and disallows use of the image forming device 1. On the other hand, if there is a corresponding candidate user, the authentication unit 13 recognizes the user to be authenticated as a registered user and allows use of the image forming device 1. Here, if there are multiple corresponding candidate users, the authentication unit 13 may recognize the candidate user with the highest degree of match as the user to be authenticated.
[0047] The method for calculating the degree of match of the biometric information may be any conventionally known method. For example, the authentication unit 13 extracts feature points of the biometric information (here, a fingerprint) captured in the image and compares the two by comparing the feature points. This method is also called AFIS (Automated Fingerprint Identification System).
[0048] The second acquisition unit 14 receives a job execution command from the user terminal N via the communication unit 60. The second acquisition unit 14 stores the acquired job execution commands in the accumulated job list 22 in order.
[0049] Here, the job execution command is, for example, a print execution command, a FAX transmission command, etc. The job execution command may also be, for example, an execution command for registering the user terminal N as a shortcut as a destination of data from the image forming device 1.
[0050] A job execution command sent from the user terminal N is assigned, for example, a user ID, and the user ID and the job execution command are stored in association with each other in the stored job list 22. The user ID in the user DB 21 can be associated with the user ID in the stored job list 22. However, the configuration may be such that the association with the user ID in the user DB 21 is made based on the terminal ID of the user terminal N that sent the job execution command.
[0051] During authentication processing in the authentication unit 13, the change unit 15 refers to the stored job list 22 to check whether data related to a job execution command is stored. If data related to a job execution command exists in the stored job list 22, the change unit 15 changes the judgment criteria of the authentication unit 13 to ease the authentication level for the user who issued the job execution command. Note that the "authentication level" refers to the strictness of identity check in the biometric authentication processing.
[0052] Specifically, for example, for a user who has issued a job execution command, the change unit 15 instructs the authentication unit 13 to reduce the threshold value to be compared with the degree of match in the biometric authentication process for a predetermined time after receiving the job execution command. Alternatively, the change unit 15 may increase the score corresponding to the degree of match for the user who issued the job execution command.
[0053] Here, the "predetermined time" is a time set to determine the probability that the user to be authenticated is the same user who issued the job execution command. After transmitting a job execution command from the user terminal N to the image forming device 1, the user generally comes to the image forming device 1 and executes printing, etc., within 30 minutes. From this perspective, the "predetermined time" is set to, for example, any time equal to or less than 30 minutes.
[0054] It is preferable that the shorter the time that has elapsed since the job execution command was received until the biometric authentication process was executed, the more the change unit 15 relaxes the authentication level. For example, if the elapsed time is less than five minutes, the change unit 15 may lower the authentication threshold by two levels, and if the elapsed time is less than five minutes but not more than 30 minutes, the change unit 15 may lower the authentication threshold by one level.
[0055] In this embodiment, the "job execution command" corresponds to the "identity probability information" of the present invention. That is, a user who sends a job execution command (e.g., a print execution command) from a user terminal N to the image forming device 1 is highly likely to visit the image forming device 1 thereafter to execute printing or the like. Therefore, the change unit 15 according to this embodiment changes the determination criteria of the authentication unit 13 based on the "job execution command" so as to relax the authentication level only for some users among the registered user group.
[0056] In this way, the image forming device 1 of this embodiment infers the possibility that the person is the actual person from information obtained from an external device (here, user terminal N), and adjusts the criteria for determining the similarity of biometric information data during authentication or rejects acceptance based on that possibility.
[0057] In other words, if there is information that increases the likelihood that the user is the actual user, the authentication level of the authentication process for that user is relaxed. On the other hand, if there is information that decreases the likelihood that the user is the actual user, the authentication level of the authentication process for that user is tightened, or a warning is displayed and acceptance is refused. This makes it possible to lower the false rejection rate without increasing the false acceptance rate, or to lower the false acceptance rate without lowering the false rejection rate. This makes it possible to achieve both convenience and improved security.
[0058] In the present invention, such information that increases the possibility that the person is the same person or decreases the possibility that the person is the same person is defined as "identity probability information."
[0059] <Registration process of biometric information to user DB 21> 7 is a flow diagram showing an example of a process of registering biometric information in the user DB 21 by the control unit 10 (registration unit 12). The registration process is performed in cooperation with the image forming apparatus 1 and the biometric authentication device F. Note that the registration process is executed, for example, when an operation input related to a registration process request is made by the administrator of the image forming apparatus 1.
[0060] In step S1, first, the control unit 10 displays a biometric information registration screen on the display unit 40 and waits for an operation from the user to be registered. At this time, the control unit 10 displays an input field for accepting input of a user ID on the biometric information registration screen. Then, when registering the biometric information in the user DB 21, the control unit 10 accepts setting of a user ID to be linked to the biometric information.
[0061] In step S2, when the control unit 10 detects that the user has pressed the biometric information reading start button, it transmits a command to the biometric authentication device F to read biometric information.
[0062] Here, the biometric authentication device F reads the biometric information in response to receiving a command to read the biometric information from the image forming device 1 (step T1). Then, the biometric authentication device F generates biometric information data for registration and transmits it to the image forming device 1 (step T2).
[0063] In step S3, upon receiving the biometric information data from the biometric authentication device F, the control unit 10 registers the biometric information and the user ID in the user DB 21 in association with each other.
[0064] Through the above-described series of flows, the control unit 10 according to this embodiment executes the process of registering biometric information in the user DB 21.
[0065] <Basic flow of biometric authentication> Fig. 8 is a diagram showing the basic flow of biometric authentication. The basic flow shown in Fig. 8 is the same as the flow of biometric authentication according to the conventional technology. The flow of biometric authentication according to this embodiment will be described later with reference to Fig. 9.
[0066] 8, it is assumed that the number of users registered in the user DB 21 is m. In the following, for convenience of calculation processing, the degree of match between the biometric information of a registered user and the biometric information of the user to be authenticated is defined and treated as a "similarity score."
[0067] In step S11, the control unit 10 first displays a login screen and waits for the user to press a biometric information reading start button. When the user presses the biometric information reading start button, the control unit 10 transmits a biometric information reading instruction to the biometric authentication device F.
[0068] Here, the biometric authentication device F receives a biometric information reading instruction from the image forming device 1 and executes biometric information reading (step T11). Then, the biometric authentication device F transmits the read biometric information data to the image forming device 1 (step T12).
[0069] In step S12, the control unit 10 first sets the first registered user in the user DB 21 as a comparison target (n=1). Then, in the processes of steps S13 to S18, the control unit 10 sequentially compares the biometric information of each user in the registered user group registered in the user DB 21 with the biometric information of the user to be authenticated read by the biometric authentication device F in T11.
[0070] In step S13, the control unit 10 acquires the biometric information of the nth registered user. Hereinafter, this user will be referred to as "registered user n."
[0071] In step S14, the control unit 10 compares the biometric information of the registered user n with the biometric information of the user to be authenticated read by the biometric authentication device F in step T11, and calculates a similarity score.
[0072] In step S15, the control unit 10 determines whether the similarity score obtained at this time is equal to or greater than a predetermined threshold. If the similarity score obtained at this time is equal to or greater than the predetermined threshold (S15: YES), the control unit 10 proceeds to S16. On the other hand, if the similarity score obtained at this time is less than the predetermined threshold (S15: NO), the control unit 10 proceeds to S17.
[0073] In step S16, the control unit 10 adds the registered user n to the corresponding candidate list.
[0074] In step S17, the control unit 10 determines whether or not the above comparison process has been performed for all m users registered in the user DB 21. If the control unit 10 has not performed the above comparison process for all m users registered in the user DB 21 (S17: NO), the control unit 10 proceeds to S18. On the other hand, if the control unit 10 has performed the above comparison process for all m users registered in the user DB 21 (S17: YES), the control unit 10 proceeds to S19.
[0075] In step S18, the control unit 10 increments n and continues the process of comparing the biometric information of the enrolled user with the biometric information of the user to be authenticated.
[0076] In step S19, the control unit 10 extracts the registered user with the highest similarity score of the biometric information from among the registered users extracted in the relevant candidate list.
[0077] In step S20, the control unit 10 identifies the user to be authenticated as the registered user whose biometric information matches the most closely, and performs the log-in process. That is, the control unit 10 recognizes the user to be authenticated as one of the registered users, and allows the user to use the image forming apparatus 1.
[0078] If the candidate user does not exist in the candidate list, the control unit 10 recognizes the user to be authenticated as an unregistered user and sets the image forming apparatus 1 in a state where use of the image forming apparatus 1 is not permitted.
[0079] <Biometric authentication processing flow according to this embodiment> FIG. 9 is a flowchart showing an example of biometric authentication processing by the control unit 10 according to this embodiment.
[0080] The flow chart shown in FIG. 9 is the same as the flow chart shown in FIG. 8, except that the processes of steps Sa1 to Sa5 are executed between step S14 and step S15.
[0081] In step Sa1, the control unit 10 acquires data from the stored job list 22. As described above, when the control unit 10 receives a job execution command from the user terminal N, the control unit 10 stores the job execution command in a pending state in the stored job list 22. Then, when the user who issued the job execution command logs in to the image forming apparatus 1, the control unit 10 enables execution of the job (e.g., printing) related to the job execution command.
[0082] In step Sa2, the control unit 10 checks whether or not a job execution command for registered user n exists in the accumulated job list 22 (step Sa2). If a job execution command for registered user n exists in the accumulated job list 22 (Sa2: YES), the control unit 10 proceeds to step Sa3. On the other hand, if a job execution command for registered user n does not exist in the accumulated job list 22 (Sa2: NO), the control unit 10 proceeds to step S15 without performing any particular processing.
[0083] In step Sa3, the control unit 10 adds a predetermined number of points to the similarity score with the registered user n. This is because, if a job execution command related to the registered user n exists, the user to be authenticated who requests this authentication process is likely to be the registered user n himself.
[0084] In step Sa4, the control unit 10 determines whether the job execution command for the registered user n was issued within a reference time from the biometric authentication process. If the job execution command for the registered user n was issued within the reference time from the biometric authentication process (Sa4: YES), the control unit 10 proceeds to step Sa5. On the other hand, if the job execution command for the registered user n was not issued within the reference time from the biometric authentication process (Sa4: NO), the control unit 10 proceeds to step S15 without performing any particular processing. Note that the "reference time" here is the time for determining whether the elapsed time from the issuance of the job execution command to the execution of the biometric authentication process is short, and is, for example, about 5 minutes.
[0085] In step Sa5, the control unit 10 further adds a predetermined number of points to the similarity score of the registered user n. This is because if a job execution command related to the registered user n has recently been issued, the user to be authenticated who requests this authentication process is more likely to be the registered user n himself.
[0086] The control unit 10 according to this embodiment uses the similarity scores updated in Sa1 to Sa5 to perform a comparison process with a predetermined threshold in the subsequent step S15. Then, the control unit 10 performs the above comparison process for all m users registered in the user DB 21.
[0087] The control unit 10 according to the present embodiment selectively relaxes the authentication level for registered users who issue job execution commands through this process, thereby improving convenience without lowering the security level.
[0088] <Effects> As described above, the image forming apparatus 1 according to this embodiment: a first acquisition unit 11 that acquires biometric information of a user to be authenticated via a biometric authentication device F; an authentication unit 13 that determines whether the user to be authenticated is any of the users in a group of registered users pre-registered in a database by biometric authentication processing of the biometric information of the user to be authenticated; a second acquisition unit (14) that acquires, from an external device, information relating to at least some of the users in the registered user group, identity probability information that indicates whether the users are present in the vicinity of the image forming device (1); a change unit that changes a process of an authentication unit related to conditions for accepting use of the image forming device for at least some of the users based on the identity probability information; Equipped with.
[0089] This makes it possible to reduce the probability of falsely rejecting a person due to an insufficient amount of biometric information, without increasing the false acceptance rate, through simple processing. In other words, this makes it possible to improve convenience without lowering the security level.
[0090] In particular, the image forming apparatus 1 according to this embodiment uses the presence or absence of a job execution command issued from the user terminal N to the image forming apparatus 1 as identity probability information. Considering the general usage of the image forming apparatus, the presence or absence of a job execution command is extremely useful as information that increases the likelihood that the user to be authenticated is the registered user. In other words, this makes it possible to more effectively reduce the false rejection rate without increasing the false acceptance rate.
[0091] [Second embodiment] The image forming apparatus 1 according to this embodiment differs from the image forming apparatus 1 according to the above embodiment in terms of the biometric authentication processing procedure. Note that a description of the configuration common to the image forming apparatus 1 according to the first embodiment will be omitted (the same applies to the other embodiments below).
[0092] In the image forming apparatus 1 according to this embodiment, first, the user is prompted to input their own identification information into the input unit 30. Based on the identification information, one candidate user is identified from the registered user group. This makes it possible to prevent erroneous determination of biometric authentication even when the biometric information reading accuracy of the biometric authentication device F is low.
[0093] FIG. 10 is a diagram showing an example of the functional configuration of the control unit 10 according to this embodiment.
[0094] The control unit 10 according to this embodiment further includes a third acquisition unit 16 in addition to the configuration of the control unit 10 shown in the first embodiment.
[0095] The third acquisition unit 16 acquires the identification information of the user to be authenticated input to the input unit 30. Then, the third acquisition unit 16 sends the acquired identification information of the user to be authenticated to the authentication unit 13.
[0096] Here, the user's identification information (hereinafter referred to as input user ID) is, for example, an identification number assigned to each user, or the user name of each user. The input format to the input unit 30 is arbitrary, and keyboard input, for example, can be used. On the other hand, from the viewpoint of simplifying the input operation, a magnetic card reader or an IC card reader that reads an ID card held by each user may be used as the input unit 30.
[0097] The user identification information input to the input unit 30 is the same as or corresponds to the identification information assigned to each user in the registered user group of the user DB 21.
[0098] The authentication unit 13 extracts a candidate user from the group of registered users based on the identification information entered by the user to be authenticated, and determines whether the user to be authenticated is the candidate user himself or herself based on whether the similarity score (i.e., degree of match) of the biometric information between the user to be authenticated and the candidate user is above a predetermined threshold.
[0099] <Basic flow of biometric authentication> Fig. 11 is a diagram showing the basic flow of biometric authentication used in this embodiment. The basic flow shown in Fig. 11 is the same as the flow of biometric authentication according to the conventional technology. The flow of biometric authentication according to this embodiment will be described later with reference to Fig. 12.
[0100] In step S31, the control unit 10 displays a screen for inputting a user ID.
[0101] In step S32, the control unit 10 waits for input of a user ID.
[0102] In step S33, the control unit 10 determines whether the input user ID exists in the user DB 21. If the input user ID exists in the user DB 21 (S33: YES), the control unit 10 identifies the user corresponding to the input user ID as a candidate user, and proceeds to S34. On the other hand, if the input user ID does not exist in the user DB 21 (S33: NO), the control unit 10 treats the input of this user ID as invalid, returns to S31, and displays the user ID input screen again.
[0103] In step S34, the control unit 10 acquires, from the user DB 21, the biometric information of the user corresponding to the input user ID.
[0104] In step S35, the control unit 10 displays a standby screen for biometric authentication, prompting the user to input biometric information, and then issues an instruction to the biometric authentication device F to read the biometric information.
[0105] In response to receiving the read instruction from the control unit 10, the biometric authentication device F reads the biometric information (step T31). Then, the biometric authentication device F sends the read biometric information data to the image forming apparatus 1 (step T32).
[0106] In step S36, the control unit 10 compares the biometric information of the user corresponding to the input user ID acquired in S34 with the biometric information acquired from the biometric authentication device F, and calculates a similarity score (i.e., degree of match) between the two.
[0107] In step S37, the control unit 10 determines whether the similarity score calculated in S36 is equal to or greater than a predetermined threshold. If the similarity score is equal to or greater than the predetermined threshold (S37: YES), the control unit 10 proceeds to S38. On the other hand, if the similarity score is less than the predetermined threshold (S37: NO), the control unit 10 returns to S35 and prompts the user to input biometric information again.
[0108] In step S38, the control unit 10 determines that the user to be authenticated is the candidate user specified by the input user ID, and performs login processing as the candidate user.
[0109] <Biometric authentication flow according to this embodiment> FIG. 12 is a flow diagram showing an example of biometric authentication according to this embodiment.
[0110] The flow diagram in Fig. 12 differs from the flow diagram in Fig. 11 only in that steps Sa1 to Sa5 relating to the processing for changing the authentication level by the change unit 15 are added. Steps Sa1 to Sa5 relating to the processing for changing the authentication level by the change unit 15 are exactly the same as the processing of steps Sa1 to Sa5 described in Fig. 9.
[0111] That is, the image forming apparatus 1 temporarily holds the job execution command input from the user terminal N. Then, using such information that increases the likelihood that the user is the correct person as identity affirmation information, the similarity score is adjusted (for example, points are added) depending on the reliability of the information. The adjusted similarity score is then compared with a predetermined threshold to determine whether the user is the correct person.
[0112] As described above, the image forming apparatus 1 of this embodiment, like the image forming apparatus 1 of the first embodiment, can realize a biometric authentication function with improved convenience without lowering the security level.
[0113] [Third embodiment] The image forming device 1 according to this embodiment differs from the image forming device 1 according to the above embodiment in that the user can change the settings to select whether to use the authentication method shown in the first embodiment or the authentication method shown in the second embodiment.
[0114] In the following, the function of the authentication unit 13 using the authentication method described in the first embodiment will be referred to as the "first method authentication unit." Also, the function of the authentication unit 13 using the authentication method described in the second embodiment will be referred to as the "second method authentication unit."
[0115] FIG. 13 is a diagram showing an example of the functional configuration of the control unit 10 according to this embodiment.
[0116] The control unit 10 according to this embodiment is configured so that the authentication unit 13 can switch between a first authentication method and a second authentication method. The control unit 10 has a setting unit 10a for setting the authentication unit 13 to switch between the first authentication method and the second authentication method. The processing of the first authentication method is as described with reference to FIG. 9. The processing of the second authentication method is as described with reference to FIG. 12.
[0117] Here, the first authentication method unit is convenient for some users because it can perform authentication without inputting identification information into the input unit 30. On the other hand, in the first authentication method unit, the biometric information generated by the biometric authentication device F needs to have a certain degree of accuracy in order to avoid erroneous determination of the user to be authenticated.
[0118] Furthermore, the second authentication method requires the user to input identification information into the input unit 30, which may be cumbersome for some users. On the other hand, the second authentication method is convenient in that it reduces the possibility of erroneous determination even when the accuracy of the biometric information generated by the biometric authentication device F is low.
[0119] The setting unit 10a accepts an input operation by the administrator user and sets whether the authentication unit 13 is to function as a first authentication method unit or a second authentication method unit.
[0120] Furthermore, the setting unit 10a may automatically select the second authentication method when a card reader is attached as the input unit 30. This is because when a card reader for reading a user ID is installed, it is easy to input identification information into the input unit 30.
[0121] As described above, according to the image forming apparatus 1 of this embodiment, the user can switch the authentication method of the authentication unit 13 in accordance with the manner in which the image forming apparatus 1 is used. This makes it possible to realize a biometric authentication function that improves convenience without lowering the security level, taking into consideration the manner in which the image forming apparatus 1 is used by each user.
[0122] [Fourth embodiment] The image forming apparatus 1 according to this embodiment differs from the image forming apparatus 1 according to the second embodiment in that, during biometric authentication processing, processing for changing the authentication level based on entry / exit data or attendance data is performed.
[0123] As described above, in order to reduce the false rejection rate without increasing the false acceptance rate, it is effective to relax the authentication level of the authentication process for a user when there is information that increases the likelihood that the user is the real person.Similarly, it is effective to tighten the authentication level of the authentication process for a user when there is information that decreases the likelihood that the user is the real person.
[0124] In recent years, many offices and factories have adopted a system in which each user carries an IC card with a user ID and uses the IC card to register their location in a management device.
[0125] In this regard, the entry / exit data indicating whether or not a person is entering the location or facility where the image forming device 1 is installed is useful as identity probability information. From this perspective, the image forming device 1 according to this embodiment changes the authentication level using the entry / exit data.
[0126] FIG. 14 is a diagram showing an example of the functional configuration of the control unit 10 according to this embodiment.
[0127] The control unit 10 according to this embodiment further includes a fourth acquisition unit 17 in addition to the configuration of the control unit 10 according to the second embodiment.
[0128] The fourth acquisition unit 17 acquires, from the management device NN, entry and exit data 23 for the location or facility where the image forming device 1 is installed, which data relates to at least some users among the registered user group.
[0129] FIG. 15 is a diagram showing an example of the configuration of the entry and exit data 23. As shown in FIG.
[0130] The entry / exit data 23 is data in which, for example, a user ID is associated with entry / exit information. The entry / exit information is, for example, information indicating whether a user is currently in the location or facility where the image forming device 1 is installed. The entry / exit information is information relating to the time when a user entered or left the location or facility where the image forming device 1 is installed. The user ID stored in the entry / exit data 23 is the same as or corresponds to the user ID assigned to each user in the registered user group of the user DB 21.
[0131] The change unit 15 refers to the entry and exit data 23 and searches for users from the registered user group who are presumed not to be present in the location or facility where the image forming device 1 is installed. Then, for users who are presumed not to be present in the location, the change unit 15 changes the determination criteria of the authentication unit 13 to make the authentication level stricter.
[0132] Fig. 16 is a flow diagram showing an example of biometric authentication processing according to this embodiment. The flow diagram of Fig. 16 differs from the flow diagram of Fig. 12 only in that steps Sb1 to Sb3 relating to the processing of changing the authentication level by the change unit 15 are added.
[0133] In step Sb1, the control unit 10 requests the management device NN for the entry and exit data of the registered user n (that is, the relevant candidate user) identified in S33.
[0134] When the management device NN receives a request for entry and exit data from the image forming device 1, the management device NN extracts the entry and exit data of the registered user n from its own database and transmits it to the image forming device 1 (step U31).
[0135] In step Sb2, the control unit 10, upon acquiring the entry / exit data of registered user n from the management device NN, determines whether registered user n is present at the installation location of the image forming device 1. If registered user n is not present at the installation location of the image forming device 1 (Sb2: NO), the control unit 10 proceeds to Sb3. On the other hand, if registered user n is present at the installation location of the image forming device 1 (Sb2: YES), the control unit 10 proceeds to threshold determination in step S37.
[0136] In step Sb3, the control unit 10 subtracts a predetermined number of points from the similarity score of the registered user n. This is because if the registered user n is not present at the installation location of the image forming device 1, the user to be authenticated is likely not the registered user n himself / herself.
[0137] The control unit 10 according to this embodiment uses the similarity scores updated in steps Sb1 to Sb3 to perform a comparison process with a predetermined threshold in the following step S37.
[0138] The control unit 10 according to the present embodiment selectively sets a stricter authentication level for registered users who issue job execution commands through this process, thereby improving convenience without lowering security.
[0139] FIG. 17 is a flowchart showing a modified example of the biometric authentication process according to this embodiment.
[0140] 17, the control unit 10 is configured to display a warning (step Sb4) and not accept biometric authentication processing if the registered user n is not present at the installation location of the image forming device 1 (Sb2: NO). That is, in this case, the control unit 10 restricts the use of the image forming device 1 regardless of the degree of match of the biometric authentication.
[0141] This is because if the registered user n is not present at the location where the image forming apparatus 1 is installed, there is no need to perform biometric authentication processing, and it is highly likely that the user to be authenticated is not the registered user himself / herself.
[0142] As described above, the image forming device 1 according to this embodiment uses the entry / exit data or the clock-in / clock-out data as identity probability information that suggests whether or not a user is present near the image forming device 1. If there is information that makes it less likely that the user is the identity of the user, the device will check the user more strictly or display a warning and refuse to accept the user.
[0143] This makes it possible to realize a biometric authentication function with improved convenience without lowering the security level, similar to the image forming apparatus 1 according to the above embodiment.
[0144] Although FIGS. 14 to 17 show the mode in which entry and exit data is used as identity probability information, attendance data may be used instead of or in addition to this.
[0145] [Fifth embodiment] The image forming apparatus 1 according to this embodiment acquires radio waves from a mobile terminal carried by each user, and differs from the image forming apparatus 1 according to the second embodiment in that, during biometric authentication processing, the authentication level is changed based on the radio wave intensity of the radio waves.
[0146] Recent mobile devices such as smartphones have the ability to transmit radio waves (e.g., Wi-Fi radio waves, NFC radio waves) to the outside world, and also function as wireless transmitters. These radio waves typically carry the ID information of the mobile device.
[0147] In this regard, the radio waves transmitted from the mobile terminal are useful as identity probability information indicating whether the mobile terminal is present near the installation location of the image forming device 1. From this perspective, the image forming device 1 according to this embodiment changes the authentication level using the radio waves transmitted from the mobile terminal.
[0148] 18 is a diagram showing an example of the functional configuration of the control unit 10 according to this embodiment. FIG. 19 is a diagram showing an example of the configuration of radio wave intensity data 24.
[0149] The control unit 10 according to this embodiment further includes a fifth acquisition unit 18 in addition to the configuration of the control unit 10 according to the second embodiment.
[0150] The fifth acquisition unit 18 acquires radio waves from the portable terminals Na1, Na2, and Na3 present near the image forming apparatus 1 and stores the radio wave intensity data 24. The radio wave intensity data 24 is data that associates, for example, a user ID with the intensity of radio waves emitted from the portable terminal held by the user of the user ID. The user IDs stored in the radio wave intensity data 24 are the same as or correspond to the user IDs assigned to each user in the registered user group of the user DB 21.
[0151] The change unit 15 refers to the radio wave intensity data 24 and searches for users from the registered user group who are presumed to be near the installation location or facility of the image forming device 1. Then, for users who are presumed to be near the installation location or facility, the change unit 15 changes the judgment criteria of the authentication unit 13 to ease the authentication level. Note that the change unit 15 determines whether a user is present near the installation location or facility of the image forming device 1, for example, based on whether the radio wave intensity is above a threshold.
[0152] This makes it possible to realize a biometric authentication function with improved convenience without lowering the security level, similar to the image forming apparatus 1 according to the above embodiment.
[0153] [Sixth embodiment] The image forming apparatus 1 according to this embodiment acquires location information from a mobile terminal carried by each user, and then performs a process of changing the authentication level based on the location information during biometric authentication processing, which is different from the image forming apparatus 1 according to the second embodiment.
[0154] Recently, mobile terminals such as smartphones have a function that enables them to periodically transmit location information (e.g., latitude and longitude information) to the outside. Such location information typically includes ID information of the mobile terminal.
[0155] In this regard, the location information transmitted from the mobile terminal is useful as identity probability information indicating whether the mobile terminal is located near the installation location of the image forming device 1. From this perspective, the image forming device 1 according to this embodiment changes the authentication level using the location information transmitted from the mobile terminal.
[0156] 20 is a diagram showing an example of the functional configuration of the control unit 10 according to this embodiment. FIG. 21 is a diagram showing an example of the configuration of user location data 25. As shown in FIG.
[0157] The control unit 10 according to this embodiment further includes a sixth acquisition unit 19 in addition to the configuration of the control unit 10 according to the second embodiment.
[0158] The sixth acquisition unit 19 acquires location information from the mobile terminals Na1, Na2, and Na3 held by at least some of the users in the registered user group in the user DB 21, and stores the information as user location data 25. The user location data 25 is, for example, data that associates a user ID with location information of the mobile terminal held by the user of the user ID. The user ID stored in the user location data 25 is the same as or corresponds to the user ID assigned to each user in the registered user group in the user DB 21.
[0159] The change unit 15 refers to the user location data 25 and searches for users from the registered user group who are presumed to be near the installation location or facility of the image forming device 1. Then, for users who are presumed to be near the location or facility, the change unit 15 changes the judgment criteria of the authentication unit 13 to ease the authentication level. Note that the change unit 15 determines whether a user is near the installation location or facility of the image forming device 1, for example, based on whether the distance between the image forming device 1 and the user's location is less than a threshold.
[0160] This makes it possible to realize a biometric authentication function with improved convenience without lowering the security level, similar to the image forming apparatus 1 according to the above embodiment.
[0161] <Other embodiments> The present invention is not limited to the above-described embodiment, and various modifications are possible.
[0162] For example, in addition to the above functions, the change unit 15 may additionally have a function of changing the judgment criteria of the authentication unit 13 set for each user of the registered user group so as to ease the authentication level based on the frequency with which each user of the registered user group uses the image forming device 1. This is because a user who frequently uses the image forming device 1 is likely to use the image forming device 1 again.
[0163] Although specific examples of the present invention have been described above in detail, these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and alterations of the specific examples exemplified above. [Industrial Applicability]
[0164] According to the image forming apparatus according to the present disclosure, it is possible to improve convenience in biometric authentication without lowering the security level. [Explanation of symbols]
[0165] U Printing System 1. Image forming device 10 Control Unit 10a Setting section 11 First acquisition part 12 Registration Department 13 Authentication Section 14 Second acquisition part 15 Changes 16 Third acquisition part 17 4th acquisition part 18 5th acquisition part 19 6th acquisition part 20 Memory section 21 User Information Database 22 Accumulated Job List 23 Entry and exit data 24 Signal strength data 25 User Location Data 30 Input section 40 Display section 50 Printing Department 60 Communications Department 70 IF Section 80 Image processing section 90 Image reading unit F Biometric authentication device N1, N2, N3 user terminals Na1, Na2, Na3 mobile devices NN management device
Claims
1. An image forming apparatus connected to a biometric authentication device, which restricts use of the apparatus by unregistered users other than users registered in advance in a database, a first acquisition unit that acquires biometric information of the user to be authenticated via the biometric authentication device; an authentication unit that determines whether the user to be authenticated is any one of a group of registered users pre-registered in the database by biometric authentication processing of the biometric information of the user to be authenticated; a second acquisition unit that acquires, from an external device, information related to at least some of the registered users, identity probability information that indicates whether the users are present near the image forming device; a change unit that changes processing of the authentication unit related to conditions for accepting use of the image forming apparatus for at least some of the users based on the identity probability information; An image forming apparatus comprising:
2. the identity probability information is information related to a job execution command issued to the image forming apparatus from a user terminal used by at least some of the registered users; When the change unit receives the job execution command, the change unit changes the determination criteria of the biometric authentication process so as to ease the authentication level in the biometric authentication process for a predetermined time period after receiving the job execution command, for the user who issued the job execution command among the registered users. The image forming apparatus according to claim 1 .
3. The change unit changes the determination criterion so that the shorter the elapsed time from when the second acquisition unit receives the job execution command to when the biometric authentication process is executed, the greater the degree to which the authentication level in the biometric authentication process is relaxed. The image forming apparatus according to claim 2 .
4. the identity probability information is entry / exit information or attendance / leave information of at least some of the users among the registered user group at a location where the image forming apparatus is installed, the entry / exit information being acquired from a management device; The change unit changes the determination criteria of the biometric authentication process so as to make the authentication level in the biometric authentication process stricter for a user who is estimated not to be present near the installation location based on the entry / exit data or the attendance data, or changes the processing of the authentication unit so as to restrict use of the image forming apparatus without using the biometric authentication process. The image forming apparatus according to claim 1 .
5. the identity probability information is a radio signal transmitted from a mobile terminal carried by each of the at least some of the users among the registered user group, The change unit changes the determination criteria of the biometric authentication process so as to ease the authentication level in the biometric authentication process for a user who is estimated to be present near a location where the image forming apparatus is installed based on the radio wave intensity of the radio wave signal. The image forming apparatus according to claim 1 .
6. the identity probability information is location information transmitted from a mobile terminal carried by each of the at least some of the users among the registered user group, The change unit changes the determination criteria of the biometric authentication process so as to ease the authentication level in the biometric authentication process for a user who is estimated to be present in the vicinity of an installation location of the image forming apparatus based on the location information. The image forming apparatus according to claim 1 .
7. The authentication unit extracts a candidate user from the group of registered users based on a degree of coincidence of the biometric information of the user to be authenticated with the biometric information of each of the group of registered users pre-registered in the database, and determines whether the user to be authenticated is the candidate user himself / herself. The image forming apparatus according to claim 1 .
8. The authentication unit extracts a candidate user from the registered user group based on the identification information of the user to be authenticated input to an input unit of the image forming apparatus, and determines whether the user to be authenticated is the candidate user himself / herself based on the degree of agreement of the biometric information between the user to be authenticated and the candidate user. The image forming apparatus according to claim 1 .
9. The authentication unit a first authentication method unit that extracts a candidate user from the group of registered users based on a degree of coincidence between the biometric information of the user to be authenticated and the biometric information of each of the group of registered users pre-registered in the database, and determines whether the user to be authenticated is the candidate user himself / herself; a second authentication method unit that extracts the candidate user from the registered user group based on the identification information of the user to be authenticated input to an input unit of the image forming apparatus, and determines whether the user to be authenticated is the candidate user himself / herself based on the degree of coincidence of the biometric information between the user to be authenticated and the candidate user; The first authentication method unit and the second authentication method unit are switchable. The image forming apparatus according to claim 1 .
10. 1. A control method for an image forming apparatus that is connected to a biometric authentication device and restricts use of the apparatus by unregistered users other than users pre-registered in a database, comprising: a first process of acquiring biometric information of a user to be authenticated via the biometric authentication device; a second process of determining whether the user to be authenticated is any user of a group of registered users pre-registered in the database through a biometric authentication process on the biometric information of the user to be authenticated; a third process of acquiring, from an external device, information relating to at least some of the registered users, and identity probability information indicating whether the users are present in the vicinity of the image forming device; a fourth process of changing the second process related to the conditions for accepting use of the image forming apparatus for at least some of the users based on the identity probability information; A control method for an image forming apparatus that performs the above.
11. A control program for an image forming apparatus that is connected to a biometric authentication device and restricts use of the apparatus to unregistered users other than users pre-registered in a database, comprising: On the computer, a first process of acquiring biometric information of a user to be authenticated via the biometric authentication device; a second process of determining whether the user to be authenticated is any user of a group of registered users pre-registered in the database through a biometric authentication process on the biometric information of the user to be authenticated; a third process of acquiring, from an external device, information relating to at least some of the registered users, and identity probability information indicating whether the users are present in the vicinity of the image forming device; a fourth process of changing the second process related to the conditions for accepting use of the image forming apparatus for at least some of the users based on the identity probability information; A control program for an image forming apparatus that causes the image forming apparatus to execute the above steps.
Citation Information
Patent Citations
Biological pattern imaging device, biological pattern imaging method, and biological pattern imaging program
JP2009276860A
Biometric authentication device and biometric authentication method employing the same
JP2014146080A
Biometric authentication device
JP2015001843A