Device management system and method for the same
The device management system addresses unintended connections by issuing credential information and canceling existing connections, ensuring efficient management of network devices across multiple customer tenants.
Patent Information
- Application Number
- JP2024021708
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-02-16
- Publication Date
- 2025-08-28
AI Technical Summary
Conventional device management systems face issues with unintended and unnecessary connections when network devices with the same individual identification information are registered and linked to multiple customer tenants, leading to wastage of network resources.
A device management system that issues first credential information for network devices and executes processing to cancel connections if a connection using second credential information has already been enabled, based on individual identification information.
Prevents unintended and unnecessary connections when network devices with the same identification information are registered with multiple customer tenants, thereby optimizing resource utilization.
Smart Images

Figure 2025125650000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technology for registering and managing device information of network devices installed at a client company in association with customer information in a device management system on a network such as a cloud. [Background technology]
[0002] With the spread of cloud services and the Internet of Things (IoT), device management systems are emerging that collect operational data from network devices equipped with communication control devices, such as printers and multifunction peripherals, via the network and use that data to provide services to customers. These device management systems register device information for network devices installed and used by multiple client companies, making it available to service providers.
[0003] When providing a service for network devices to a customer company, a person in charge at the service provider creates a tenant for that customer (hereafter referred to as a customer tenant) on the storage system of the device management system. Then, in order to manage network devices for each customer company, the device management system registers device information (especially individual identification information) of the target network device, linking it to the customer tenant. The network device can establish a connection with the device management system and the customer tenant using the identification information registered in the device management system, and then the communication functions required to provide the service are activated. Each tenant on the storage system is logically and securely divided, and access control is performed.
[0004] The device management system also securely manages operational data of network devices collected via the network by linking it to the corresponding customer tenant, providing customer companies with a secure tenant-separated environment.
[0005] As a conventional technique, Patent Document 1 describes a system in which a connection code issued to a sales company that installs a network device is used to register the network device in association with a customer tenant. In the conventional technique, the connection code for registering the network device is issued not to the network device user or the customer tenant, but to the sales company that installs the network device. In the conventional technique, a step is taken to register device information for the network device in the sales company's tenant, and then the device information is automatically re-registered in the target customer tenant according to subsequent communication between the device management system and the network device. By performing such special installation work, the conventional technique contributes to reducing the effort required for network device users to register devices in a device management system. [Prior art documents] [Patent documents]
[0006] [Patent Document 1] Patent Publication No. 2021-125761 Summary of the Invention [Problem to be solved by the invention]
[0007] In some cases, a network device used by one customer is installed at another customer for reuse. In conventional technology, if the association between the customer tenant of the previous customer and the device information of the network device is not deleted in the device management system, the same individual identification information may be registered and associated with multiple customer tenants. Because manual work is involved, it is possible that duplicate device information for a network device may be registered without realizing that it has already been registered in a different customer tenant. In this case, if a network device installed at a new customer establishes a connection with the customer tenant of the previous customer that is no longer needed, the unnecessary connection may be maintained without being noticed. In this case, even if operational data is not being transmitted from the network device, the established connection wastes network resources.
[0008] Therefore, the present invention aims to propose a mechanism in a device management system that prevents unintended and unnecessary connections from occurring when network devices with the same individual identification information are registered and linked to multiple customer tenants. [Means for solving the problem]
[0009] The present invention is a device management system characterized by having an issuing means for issuing first credential information to a monitoring device to be used when transmitting operation data of a network device, and an execution means for executing processing to cancel the connection when the first credential information is issued, based on the individual identification information of the network device, if a connection between the monitoring device and the device management system using second credential information has already been enabled for the network device. [Effects of the Invention]
[0010] According to the present invention, a mechanism can be provided in a device management system that prevents unintended and unnecessary connections from being made when network devices with the same individual identification information are registered in association with multiple customer tenants. [Brief explanation of the drawings]
[0011] [Figure 1] 1 is a diagram illustrating an overall configuration of a network system including a device management system. [Figure 2] FIG. 2 is a diagram illustrating a hardware configuration of an information processing device that constitutes a device management system 130. [Figure 3] FIG. 2 is a diagram illustrating an example of the software configuration of each device according to the present embodiment. [Figure 4] 10 is a flowchart of a connection validation process performed by a connection permission unit 313. [Figure 5] 10 is a flowchart of a registration management unit 311 when receiving a connection validation notification in the first embodiment. [Figure 6] 10 is a flowchart of a registration management unit 311 when receiving a connection validation notification in the second embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings.
[0013] Example 1 1 is a diagram showing the overall configuration of a network system including a device management system, which includes a network device 110, a monitoring device 120, a device management system 130, a network 140, a client terminal 150, and the like.
[0014] The network device 110 is a processing device in a customer organization's network that is connected to the monitoring device 120. Specifically, the network device 110 is an image processing device such as a printer, copier, multifunction device, or scanner. In FIG. 1, as an example of a system configuration, only one network device 110 installed in a network of a certain customer organization is shown. However, in this embodiment, it is assumed that one or more network devices exist in each of the networks of multiple customer organizations.
[0015] The monitoring device 120 is a processing device within the client organization's network that is connected to the device management system 130 via a network 140 such as the Internet, and manages the connection with the device management system 130. A server connection application running on the monitoring device 120 connects to the device management system 130 and transmits configuration information and operation data of the network device 110 to the device management system 130. It is also possible for the network device 110 to be internally equipped with the functions of the monitoring device 120 and implemented so as to also perform the role of the monitoring device 120.
[0016] Here, the operational data includes log information of processes executed by the network device 110, processing counters, part usage counters, fault information such as errors, sensor information detected by internal sensors, etc. If the network device 110 is a printing device, the operational data includes job log information recorded in response to the execution of a print job and counter information indicating the number of printed sheets.
[0017] When transmitting configuration information and operational data of the network device 110, the monitoring device 120 performs device authentication with the device management system 130 and acquires access permission information such as an access token and a session ID from the device management system 130. The monitoring device 120 transmits the configuration information and operational data together with the acquired access permission information to the device management system 130. The transmitted data is managed by the customer tenant of the network device 110 within the device management system 130.
[0018] The device management system 130 is a server system that authenticates the monitoring device 120 that transmits the configuration information and operational data of the network device 110, and manages the information received via the network.
[0019] When connecting the monitoring device 120 to the device management system 130, device information of the network device 110 is registered in the device management system 130 in order to identify and manage the owner of the network device 110, who is a customer. The device management system 130 associates the customer company that owns the network device 110 with the device information of the network device 110, and prepares a customer tenant for each customer company to manage the information. Before receiving configuration information and operation data of the network device 110, the device management system 130 issues access permission information to the authenticated monitoring device 120.
[0020] The client terminal 150 is a client terminal directly operated by a user of the service provider company, and has a web browser installed. The user of the service provider company accesses the device management system 130 via the web browser of this client terminal 150, and the network device 110 is registered in association with the customer company that owns it.
[0021] FIG. 2 is a diagram showing the hardware configuration of an information processing device (server computer) that constitutes the device management system 130. As shown in FIG.
[0022] The server computer comprises an output I / F unit 201 that connects to an output device such as a display, an input I / F unit 202 that connects to an input device such as a keyboard, a storage device 203, a memory 204, a CPU 205, and a communication I / F unit 206. The storage device 203 stores an operating system (OS), an authentication program that performs authentication and connection processing, a management program that registers and manages network devices 110, registration information for client companies and network devices 110, received setting information and operation data, etc. The CPU 205 loads the authentication program and management program from the storage device 203 into the memory 204 and executes them. The communication I / F unit 206 is a network interface that is connected to the network 140 and controls communication with the monitoring device 120 that constitutes the network device management system.
[0023] The device management system 130 can also be realized using cloud computing technology, in which case it is built using the hardware resources of multiple information processing devices. The device management system 130 can also use a storage service system built on a network as the storage device 203. Customer tenants are built on the storage device 203 and the storage service system.
[0024] 2 is equivalent to a hardware block diagram of a general information processing device, and is also applied to the network device 110, monitoring device 120, and client terminal 150 of this embodiment. Therefore, the hardware configurations of the network device 110 and monitoring device 120 are also similar.
[0025] 3 is a diagram showing an example of the software configuration of each device according to this embodiment, which illustrates the main functional blocks of the monitoring device 120 and the device management system 130.
[0026] The monitoring apparatus 120 includes a connection target device specifying unit 301 , a connection code input receiving unit 302 , a connection establishing unit 303 , a connection management unit 304 , and a device monitoring unit 305 .
[0027] The connection target device identification unit 301 identifies the network device 110 that is to transmit configuration information and operation data to the device management system 130 based on device information, etc. The device information of the network device 110 includes a serial number, which is individual identification information of the network device 110 that is assigned a unique number when the network device 110 is manufactured. This serial number is particularly used to identify the network device 110 that is to be monitored. The network device 110 that is to be monitored is identified by receiving input of the serial number in the monitoring device 120 or by obtaining the serial number from a network device 110 that is in the same customer organization's network. If the network device 110 has a built-in function as the monitoring device 120 and is operating, the network device that is to be monitored will be identified by its own serial number.
[0028] The connection code input receiving unit 302 receives connection code input information from an operator. The connection code can be input by operating the hard keys or touch panel of the monitoring device 120 or the network device 110, or by reading a two-dimensional barcode or the like using the input I / F unit 202 with OCR (Optical Character Recognition). The connection code is a character string issued by the device management system 130 to identify the tenant to which the network device is to be connected and to allow the device management system 130 to permit the connection. Requiring the input of a connection code to connect to the device management system 130 prevents connections from monitoring devices 120 that do not enter a connection code, and allows connections only to the tenant specified when the connection code was issued.
[0029] The connection establishment unit 303 transmits the serial number identified by the connection target device identification unit 301 and the connection code input by the connection code input reception unit 302 to the device management system 130. Then, by receiving credential information from the device management system 130 in response, a connection with the device management system 130 is established.
[0030] The connection management unit 304 holds credential information issued by the device management system 130. Furthermore, the connection management unit 304 uses the credential information to authenticate the device management system 130 in order to transmit data such as configuration information and operational data required to provide services for the network device 110, and manages the connection status, such as the start of the connection.
[0031] The device monitoring unit 305 collects configuration information and operation data from the network device 110 to be monitored via the client organization's network. It then transmits this information to the connected device management system 130. When the network device 110 is equipped with the function of the monitoring device 120 and is operational, the network device 110 transmits its own configuration information and operation data to the device management system 130.
[0032] The device management system 130 includes a registration management unit 311 , a connection code issuing unit 312 , a connection permission unit 313 , and a device management unit 314 .
[0033] The registration management unit 311 registers information about the network devices 110 installed in the customer organization with the tenant (device registration), and manages data collected from the network devices 110 by logically separating them by tenant. Prior to this device registration, the device management system 130 creates a tenant for the customer organization that provides the service based on a registration request from the operator of the service provider using the client terminal 150, and registers the customer information by linking it to the tenant.
[0034] Table A shows an example of a device management information table that the registration manager 311 registers in the storage device 203.
[0035] [Table 1]
[0036] The tenant ID in Table A is key information for identifying a tenant that realizes logically separated data management. The device ID is ID information assigned by the device management system 130 when the network device 110 is registered in the device management system 130, in order to uniquely identify the network device 110 within the device management system 130. Multiple pieces of network device information can be registered under one tenant ID.
[0037] The serial number is information that identifies the individual network device 110 and is assigned when the network device 110 is manufactured. In this embodiment, the same serial number can be associated with and registered for multiple different tenants. In this case, different device IDs are assigned to the same network device registered to different tenants in order to distinguish them within the device management system 130.
[0038] The activation date and time is date and time information that indicates whether or not device data communication related to the network device 110 has been activated and the timing. The date and time is recorded upon receiving notification of activation from the connection permission unit 313. If there is no record of the father (blank in the table), it means that it has not been activated. In addition, although not shown in the table, the registration management unit 311 manages information such as the device name, registration date and time, information on the services used, and installation location information as information on the network device.
[0039] The connection code issuing unit 312 identifies a destination tenant that accepts data from the network device 110, and generates a connection code required for the device management system 130 to permit the connection. Table B shows an example of a connection code management table generated by the connection code issuing unit 312 and stored in the storage device 203 of the device management system 130.
[0040] [Table 2]
[0041] The tenant ID in Table B is key information similar to the tenant ID in Table A. It is also information for uniquely identifying a customer tenant assigned to a customer organization. The connection code is a code that is unique within the device management system 130, and one or more connection codes can be generated for each tenant ID. Alternatively, one connection code may be generated for each network device registered in the device management information table. In this embodiment, the connection code is generated in response to a tenant reconnection request from the network device 110. An expiration date may be set for the connection code to prevent the code from being leaked. Since the connection code is unique within the device management system 130, the tenant ID can be identified from the connection code.
[0042] The connection permission unit 313 plays the role of an authorization server for authorizing the provision of services to devices. By receiving a valid connection code and identifying the destination tenant from the connection code, the connection permission unit 313 issues key information to the network device 110 for transmitting data to the identified tenant in the device management system 130.
[0043] Table C shows an example of a device connection credential information table that the connection permission unit 313 manages in the storage device 203 of the device management system 130.
[0044] [Table 3]
[0045] The tenant ID in Table C is key information similar to the tenant ID in Table A. It is also information for uniquely identifying the customer tenant assigned to the customer organization. The device ID is ID information similar to the device ID in Table A.
[0046] The credentials are key information for authenticating the monitoring device 120 that transmits the configuration information and operational data of the network device 110. When a request to transmit the configuration information and operational data is received from the network device, the connection permission unit 313 authenticates the monitoring device 120 using the device ID and this key information. The connection permission unit 313 transmits to the monitoring device 120 authorization data for transmitting the configuration information and operational data of the network device that has been successfully authenticated.
[0047] The status is status information that indicates the status of issuance of key information to the monitoring device 120. When the key information is issued to the monitoring device 120, the connection between the device management system 130 and the monitoring device 120 is validated, and the status becomes "valid." The connection permission unit 313 may be configured as an authorization server, which is a server system independent from the device management system 130.
[0048] FIG. 4 is a flowchart showing the process performed by the connection permission unit 313 of the device management system 130 to enable connection to the monitoring apparatus 120 that transmits the setting information and operational data of the network device 110.
[0049] The program of the device management system 130 relating to this flow is stored in the storage device 203 of the device management system 130 , read into the memory 204 , and executed by the CPU 205 .
[0050] When the connection permission unit 313 receives a connection validation request from the monitoring device 120 (step S401), it authenticates the monitoring device 120 that sent the request (step S402). The connection permission unit 313 determines whether authentication of the monitoring device 120 has succeeded or failed (step S403). Here, the connection validation request received from the monitoring device 120 includes the serial number of the network device 110 and the connection code whose input has been accepted by the monitoring device 120.
[0051] If the authentication of the monitoring device 120 fails, the connection permission unit 313 does not grant connection permission to the monitoring device 120 and returns data indicating an authentication error to the monitoring device 120 (step S404).
[0052] If the authentication of the monitoring device 120 is successful, the connection permission unit 313 refers to the connection code management table in Table B and verifies whether the received connection code is a legitimate and valid one generated by the connection code issuing unit 312 (step S405). In determining whether the verification is successful or unsuccessful (step S406), the verification fails, particularly if the connection code has expired or has already been used and is therefore invalid.
[0053] If the verification of the connection code fails, the connection permission unit 313 does not grant permission for the connection and returns data indicating a verification error to the monitoring device 120 (step S407). Note that the monitoring device 120 that receives the error returns concludes that the validation of the connection has failed and ends the process.
[0054] If the connection code verification is successful, the connection permission unit 313 refers to the connection code management table in Table B and identifies the tenant ID of the tenant to which the connection is to be made from the connection code. Then, the connection permission unit 313 issues credential information to the monitoring apparatus 120 for transmitting various information about the network device 110 to that tenant (step S408). Furthermore, the connection permission unit 313 notifies the registration management unit 311 that device data communication related to the network device 110 has been enabled (step S409), and ends this process.
[0055] Upon receiving this credential information, the monitoring device 120 determines that the connection is successful and completes the connection activation process. Thereafter, the monitoring device 120 can connect to the device management system 130 using the credential information and transmit data necessary for providing services, such as configuration information and operation data for the network device 110, to the appropriate customer tenant.
[0056] 5 is a flowchart showing the device information registration management process in the registration management unit 311 of the device management system 130, particularly the process performed when a notification is received that device data communication has been enabled for the network device 110. The management program of the device management system 130 related to this flow is stored in the storage device 203 of the device management system 130, read into the memory 204, and executed by the CPU 205.
[0057] The registration management unit 311 receives a notification of the activation of device data communication based on the processing of S409 by the connection permission unit 313 (step S501).
[0058] The registration management unit 311 refers to the device management information table of Table A and searches using the serial number to see if there is any registered information about a network device with the same serial number (step S502). The registration management unit 311 determines whether a different tenant has information about a network device with the same serial number as the serial number of the network device that was the target of the notification in S501 (step S503). If a different tenant does not have information about a network device with the same serial number, the processing shown in FIG. 5 ends.
[0059] If a different tenant has information about a network device with the same serial number, the registration management unit 311 checks whether the connection has been validated for the network device of the different tenant (step S504). If the connection has not been validated, the process shown in FIG. 5 ends.
[0060] If the connection has already been validated, the registration management unit 311 instructs the cancellation of the connection permission for the network device of the different tenant (step S506).
[0061] The instruction to cancel the connection permission is given, for example, by instructing the connection permission unit 313 to delete (invalidate) the credential information issued to the monitoring device 120. Deletion of the credential information on the device management system 130 side will result in authentication failure in any subsequent connection from the monitoring device 120 to the device management system 130 using the credential information. As a result, transmission of configuration information and operational data of the network device 110 from the monitoring device 120 will also be stopped.
[0062] The instruction to cancel connection permission may also be realized by transmitting an instruction to delete a transmission data type to the monitoring device 120. When enabling a connection, the device management system 130 instructs the monitoring device 120 to transmit a transmission data type and a transmission schedule as the configuration information and operational data to be transmitted, and the instruction to cancel connection permission here means canceling that transmission instruction. By canceling the transmission instruction for a different tenant as described above, the monitoring device 120 will no longer connect to the different tenant of the device management system 130, and data transmission will also be stopped.
[0063] The instruction to cancel the connection permission may be switched depending on whether or not the monitoring device is built into the network device.
[0064] 5, by canceling connection permission for a previous network device with the same serial number, the configuration information and operation data of the network device 110 are prevented from being sent to multiple different tenants in duplicate. Also, a mechanism can be provided to prevent unintended and unnecessary connections to the previous tenant.
[0065] Example 2 Fig. 6 is a flowchart for explaining a process that is partially improved from Fig. 5. The process other than that shown in Fig. 6 is the same as that in the first embodiment, and therefore the explanation will be omitted.
[0066] In FIG. 6, processing after the registration management unit 311 determines Yes in S504 (determines that the connection has already been validated for the network device of a different tenant) is added.
[0067] There are cases where the configuration is such that the same network device 110 setting information and operation data are sent to different tenants, and each tenant provides a different service to the customer organization. In such a case, the registration management unit 311 checks whether the same service is being provided by the tenants in which the information of the same network device 110 is registered (step S505). If the same service is not included, the process shown in FIG. 6 ends without issuing an instruction to cancel the connection permission described above.
[0068] On the other hand, if the same service is included, the registration management unit 311 executes the instruction to cancel the connection permission described above (step S506).
[0069] (Application example) In some cases, the type of monitoring device 120 determines which monitoring device should be prioritized for connection. For example, there are old and new types of monitoring devices 120, and replacement of old models with new models is being promoted. In such cases, priority information based on the type of monitoring device is registered in advance, and a check is made to see if the monitoring device 120 that sent the activation notice has a higher or equal priority than a monitoring device that has already been activated for the same network device 110 information. Then, only if the priority is higher or equal, is a command to cancel connection permission issued in step S506? On the other hand, if the monitoring device 120 that sent the activation notice has a lower priority than a monitoring device that has already been activated for the same network device 110 information, a check is made to see if the reception of configuration information and operational data from the already activated monitoring device is continuing. If it is confirmed that the reception of configuration information and operational data from the already activated monitoring device is continuing, a command is issued to cancel the connection permission for the monitoring device 120 that sent the activation notice.
[0070] (Other Examples) The present invention also includes an apparatus or system configured by appropriately combining the above-described embodiments, and a method thereof.
[0071] Here, the present invention is a device or system that executes one or more pieces of software (programs) that realize the functions of the above-described embodiments. Also, a method for implementing the above-described embodiments executed by the device or system is also one aspect of the present invention. The program is supplied to the system or device via a network or various storage media, and is read into one or more memories and executed by one or more computers (CPUs, MPUs, etc.) of the system or device. In other words, the present invention also includes the program itself, or various storage media that store the program and are readable by a computer. The present invention can also be realized by a circuit (e.g., ASIC) that realizes the functions of the above-described embodiments. [Explanation of symbols]
[0072] 110 Network Devices 120 Monitoring equipment 130 Device Management System 140 Network 150 client terminals
Claims
1. 1. A device management system comprising: an issuing means for issuing first credential information to the monitoring device, the first credential information being used when transmitting operational data of the network device; an execution means for executing a process to cancel a connection between the monitoring device and the device management system using second credential information for the network device when the first credential information is issued and the connection has already been validated for the network device based on the individual identification information of the network device; A device management system comprising:
2. The device management system according to claim 1 , wherein the process for canceling the connection is a process for deleting the second credential information in the device management system.
3. The device management system according to claim 1 , wherein the process for canceling the connection is to transmit an instruction to stop data transmission to the monitoring device to which the second credential information has been issued.
4. 1. A method in a device management system, comprising: an issuing step of issuing first credential information to the monitoring device, the first credential information being used when transmitting operational data of the network device; an execution step of executing a process for canceling a connection between a monitoring device and the device management system using second credential information for the network device when the first credential information is issued, based on individual identification information of the network device; A method comprising:
Citation Information
Patent Citations
Registration management method of customer company's network device on device management server
JP2021125761A