Image processing apparatus for digital signature and computer program

By employing passkey authentication and automatic DNS registration, the image processing device overcomes the limitations of FIDO 2.0, enabling secure password-less login even with IP address-based connections.

JP2025127531APending Publication Date: 2025-09-02CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024024274
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-02-21
Publication Date
2025-09-02

AI Technical Summary

Technical Problem

FIDO 2.0 does not allow connections using IP addresses, preventing the use of password-less login via WebAuthn when accessing the remote UI function of image processing devices like MFPs, which often utilize HTTP connections specified by IP addresses.

Method used

Implementing a digital signature verification technique using passkey authentication, allowing the image processing device to authenticate users via HTTP communication and generate a passkey authentication screen when an IP address is used for access, with automatic DNS registration of host names and IP addresses to facilitate password-less login.

Benefits of technology

Enables easy access to image processing devices using passkey authentication even when IP addresses are specified, ensuring seamless password-less login and enhancing security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025127531000001_ABST
    Figure 2025127531000001_ABST
Patent Text Reader

Abstract

To provide an image processing apparatus which makes it easy to make an access via passkey authentication even when the access is made using an IP address.SOLUTION: An image processing apparatus comprises: user authentication means which receives a digital signature from an information processing apparatus through HTTP communication and performs user authentication by verifying the digital signature using a passkey stored in advance in association with an identifier of a user; and control means which generates a cooperation authentication screen or a passkey authentication screen for prompting an access via passkey authentication using the passkey when an access to the user authentication means from the information processing apparatus is made using an IP address in a state in which the user authentication means is valid.SELECTED DRAWING: Figure 9
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an image processing device and a computer program for digital signatures. [Background technology]

[0002] In recent years, an increasing number of websites are offering password-less authentication due to issues with using passwords to authenticate users, such as the risk of fraud. Known technologies for password-less user authentication include FIDO2.0 and WebAuthn, defined by the FIDO (Fast IDentity Online) Alliance.

[0003] Patent document 1 also describes a technology in which, when a user logs in to a service provided by a service providing system, an authentication screen is displayed on the browser, and when the user requests authentication on the authentication screen, password-less authentication is performed using an external authentication device. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2022-71684 Summary of the Invention [Problem to be solved by the invention]

[0005] In addition, for example, image processing devices are equipped with a remote UI function that allows users to change settings and operate the image processing device via a browser from a PC. When accessing the remote UI function, in an office LAN environment, an HTTP connection is often made by specifying an IP address.

[0006] However, FIDO 2.0 does not allow connections using IP addresses, so if an IP address is used to connect to a FIDO service, a FIDO 2.0-compliant browser will return an error when attempting to execute WebAuthn.

[0007] Therefore, when providing password-less login using FIDO with the remote UI function of an image processing device or the like, there is a problem in that the FIDO function cannot be used if an IP address is specified and an HTTPS connection is made.

[0008] Therefore, one object of the present invention is to provide an image processing apparatus that can be easily accessed by passkey authentication even when an IP address is used for access. [Means for solving the problem]

[0009] The image processing device of the present invention comprises: a user authentication means for receiving a digital signature from the information processing device through HTTP communication and verifying the digital signature using a passkey previously stored in association with a user identifier, thereby authenticating the user; When the user authentication means is enabled and the information processing device accesses the user authentication means using an IP address, a control means for generating a link authentication screen or a passkey authentication screen that prompts access through passkey authentication using the passkey; The present invention is characterized by having the following. [Effects of the Invention]

[0010] It is possible to realize an image processing apparatus that allows easy access by passkey authentication even when an IP address is used for access. [Brief explanation of the drawings]

[0011] [Figure 1] 1 is a diagram illustrating an example of a system configuration according to a first embodiment of the present invention. [Figure 2]1A is a diagram showing an example of the hardware configuration of an MFP 101 according to the first embodiment, and FIG. 1B is a diagram showing an example of the hardware configuration of an information processing apparatus 105 according to the first embodiment. [Figure 3] FIG. 2 is a diagram illustrating an example of the software configuration of an MFP 101 and an information processing apparatus 105 according to the first embodiment. [Figure 4] 10 is a diagram showing an example of a user database stored in an HDD 204 of the MFP 101 according to the first embodiment. FIG. [Figure 5A] FIG. 10 is a diagram showing an example of a login screen displayed on a web browser 314 of the information processing device according to the first embodiment. [Figure 5B] FIG. 5 is a diagram showing an example of a device status screen 504 after login displayed on the web browser 314 of the information processing apparatus according to the first embodiment. [Figure 6A] FIG. 6 is a diagram showing an example of a login method setting screen 601 of the remote UI of the information processing apparatus according to the first embodiment. [Figure 6B] FIG. 6 is a diagram showing an example of a user account management screen 602 of the information processing apparatus according to the first embodiment. [Figure 6C] FIG. 6 is a diagram showing an example of a user account editing screen 603 of the information processing apparatus according to the first embodiment. [Figure 7A] 10 is a flowchart showing an example of a process for URL passkey authentication according to the first embodiment. [Figure 7B] 10 is a flowchart showing an example of a process for automatically registering a URL in DNS according to the first embodiment. [Figure 7C] 10 is a flowchart showing an example of a process for changing the IP address of a URL according to the first embodiment. [Figure 8A] FIG. 4 is a diagram illustrating an example of a sequence of passkey authentication according to the first embodiment. [Figure 8B] FIG. 8B is a diagram showing an example of a sequence following that of FIG. 8A. [Figure 9] 8C is a flowchart showing an example of URL verification processing in step S803 of FIG. 8B. [Figure 10] 8C is a flowchart showing an example of URL redirection processing in step S803 of FIG. 8B. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the present invention will be described with reference to the drawings. However, the present invention is not limited to the following embodiments. In each drawing, the same members or elements are designated by the same reference numerals, and duplicate descriptions will be omitted or simplified.

[0013] <Embodiment 1> In the first embodiment, an example of an image processing device will be described, which is an MFP (Multi Function Printer) having functions of copying, printing, scanning, etc. However, the image processing device may be, for example, an image generating device, an image editing device, etc., and is not limited to an MFP.

[0014] In this embodiment, a digital signature verification technique is adopted as an authentication mechanism for a user to use functions and services provided by the image processing device. Specifically, in the first embodiment, a passkey authentication is performed on the PC used by the user, and the digital signature data output as a result is verified on the image processing device side to authenticate the user.

[0015] In addition, in the first embodiment, a digital signature verification service function corresponding to the FIDO service of the FIDO technology is implemented in the image processing device. However, the digital signature verification method in this embodiment is not limited to FIDO, and may include other methods.

[0016] 1 is a diagram showing an example of the configuration of an authentication system according to a first embodiment of the present invention. 101 is an MFP to which this embodiment is applied. 102 is a mobile terminal such as a smartphone, for example, a terminal equipped with Apple's iOS or Google's Android (registered trademark).

[0017] The mobile terminal 102 can communicate with the MFP 101 via a wireless LAN (Local Area Network) access point 103, a wired LAN 104, or the like.

[0018] Furthermore, the information processing device 105 can also communicate with the MFP 101 via the wired LAN 104. Furthermore, if the MFP 101 has a wireless LAN access point function, the mobile terminal 102 may be configured to connect to the wireless LAN access point function of the MFP 101 and communicate directly.

[0019] 2A is a diagram showing an example of the hardware configuration of the MFP 101 according to the first embodiment. Reference numeral 201 denotes a CPU serving as a computer that controls the overall operation of the MFP 101. Reference numeral 203 denotes a RAM (Random Access Memory) that functions as a work area and is used as a temporary storage area for expanding various control programs stored in a ROM 202 or an HDD 204.

[0020] Reference numeral 202 denotes a ROM (Read Only Memory), which stores a boot program for the MFP 101. Reference numeral 204 denotes an HDD, which may include a non-volatile hard disk or flash storage, which stores a computer program for controlling the MFP. Computer programs such as an OS (Operating System) and application programs are also stored in the HDD 204.

[0021] The CPU 201 executes a boot program stored in the ROM 202 when the MFP 101 is started up. This boot program reads out the OS program stored in the HDD 204 and loads it on the RAM 203.

[0022] After executing the boot program, the CPU 201 subsequently executes the OS program expanded on the RAM 203 to control the MFP 101. The CPU 201 also stores data used for operations according to the control computer program in the RAM 203 and reads and writes the data.

[0023] Note that the MFP 101 is assumed to execute each process shown in the flowcharts described below using a single CPU 201, but it may also be configured such that, for example, multiple CPUs or microprocessors (MPUs) work together to execute each process shown in the flowcharts described below.

[0024] Furthermore, part of the processing described below may be executed using a hardware circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).

[0025] Reference numeral 205 denotes an operation panel including a touch-operable display (touch panel), and 206 denotes a printer that prints print data received from the outside via a communication unit 208 or digital data acquired from a scanner 207 .

[0026] Reference numeral 207 denotes a scanner that reads a paper document and converts it into digital data, and 208 denotes a communication unit that includes a network interface for connecting to the Internet or an office LAN (Local Area Network).

[0027] 2(B) is a diagram showing an example of the hardware configuration of the information processing device 105 according to embodiment 1. Reference numeral 211 denotes a CPU serving as a computer that controls the overall operation of the information processing device 105. Reference numeral 213 denotes a RAM, which is used as a temporary storage area for expanding various control programs stored in a ROM 212 and a flash storage 214.

[0028] Reference numeral 212 denotes a ROM that stores a boot program for the information processing device 105. A flash storage 214 is a non-volatile memory storage that stores a computer program for controlling the mobile terminal. The flash storage 214 also stores an OS and application programs.

[0029] Reference numeral 215 denotes a display, such as an LCD or organic EL display, that displays the UI displayed by the application program. Reference numeral 216 denotes a USB interface for USB connection. Reference numeral 217 denotes a communication unit for performing wired or wireless LAN communication.

[0030] Fig. 3 is a diagram showing an example of the software configuration of the MFP 101 and the information processing device 105 according to the first embodiment. Note that in the first embodiment, some of the functional blocks shown in Fig. 3 are realized by causing a CPU or the like serving as a computer included in the MFP 101 and the information processing device 105 to execute a computer program stored in a memory serving as a storage medium.

[0031] However, some or all of these functions may be implemented by hardware. As mentioned above, the hardware may be a dedicated circuit (ASIC) or a processor (reconfigurable processor, DSP). Furthermore, the functional blocks shown in Fig. 3 do not have to be built into the same housing, and may be configured as separate devices connected to each other via signal paths.

[0032] Reference numeral 301 denotes an authentication service unit for authenticating a user who uses the MFP 101, and includes a local login service unit 302, a remote login service unit 303, and a FIDO (Fast IDentity Online) service unit 304.

[0033] A local login service unit 302 displays a login screen on the operation panel 205, authenticates a user who uses the operation panel, and allows the user to log in via the operation panel. A remote login service unit 303 authenticates a user who accesses a Web service (remote UI) via the communication unit 217, and allows the user to log in to the remote UI.

[0034] The FIDO service unit 304 has a web server function that can communicate via HTTP (Hypertext Transfer Protocol) / HTTPS (Hypertext Transfer Protocol Secure) and also has an authentication function of WebAuthn defined by the FIDO Alliance and W3C.

[0035] The FIDO service unit 304 functions as a user authentication means that receives a digital signature from the information processing device 105 via HTTP communication or HTTPS and performs user authentication by verifying the digital signature using a passkey that has been previously stored in association with the user's identifier.

[0036] The local UI service unit 305 of the MFP 101 provides a user interface for providing functions to a user who has logged in to the operation panel. The local UI service unit 305 includes a menu from which the user selects functions, applications, a UI platform that controls screen transitions, and the like.

[0037] For example, it includes a "copy" application that controls the printer 206 and scanner 207 to provide the user with a copy function, and a "scan and send" application that controls the scanner 207 and communication unit 208 to provide the function of sending scanned documents.

[0038] The remote UI 306 provides a user who has logged in to the web service with a user interface that is displayed on the web browser of the information processing device 105. The remote UI 306 includes "personal settings," "management settings," "applications," "web server," and the like, which allow the user to change function settings.

[0039] The printer control unit 307 is a software module that controls the printer 206 , and the scanner control unit 308 is a software module that controls the scanner 207 .

[0040] These software modules provide applications with an API (Application Programming Interface) for operating a printer 206 and a scanner 207. The software configuration of the MFP 101 includes an operating system and driver software for controlling various hardware.

[0041] The OS 311 of the information processing device 105 is an operating system. The authenticator 312 is software that has a FIDO authenticator function defined by the FIDO Alliance. The function of the authenticator 312 may be incorporated into the operating system (OS 311) as one function of the operating system.

[0042] The web browser 314 is software that operates as a client function for HTTP communication, and is configured, for example, with Apple's Safari, Google's Chrome, or Microsoft's Edge.

[0043] Fig. 4 is a diagram showing an example of a user database stored in the HDD 204 of the MFP 101 according to the first embodiment. The MFP 101 stores and manages user account information in a user database 401 as shown in Fig. 4 in the HDD 204. Note that the database of another node on the network may be used after encrypting the communication path and storage and preventing tampering.

[0044] As shown in FIG. 4, the user database 401 according to the first embodiment stores user IDs, passwords, passkey information (credential ID and public key) used for FIDO authentication, roles, email addresses, and whether password authentication is enabled or disabled.

[0045] "User ID" is an identifier for identifying a user. "Password" is a password used for authentication. "Role" is information indicating the user's usage authority for MFP 101. Examples of each role and usage authority are shown in role information table 402.

[0046] In addition to the role definitions that are included in the MFP 101 when it is shipped from the factory, the user may be allowed to set detailed usage rights and create new roles. User account information is registered, edited, and deleted via the UI of a user account management screen 602 in Figure 6B or a user account edit screen 603 in Figure 6C, which will be described later.

[0047] The user database 401 is referenced by the user authentication service unit 301 to authenticate the user. In addition, passkey information such as a credential ID and a public key is stored via the FIDO service unit 304.

[0048] Next, a user authentication function of the MFP 101 will be described with reference to Fig. 5A, Fig. 5B, and Fig. 6A to Fig. 6C. Fig. 5A is a diagram showing an example of a login screen displayed on the web browser 314 of the information processing device according to the first embodiment, and Fig. 5B is a diagram showing an example of a device status screen 504 after login displayed on the web browser 314 of the information processing device according to the first embodiment.

[0049] FIG. 6A is a diagram showing an example of a login method setting screen 601 of the remote UI of the information processing apparatus according to the first embodiment, and FIG. 6B is a diagram showing an example of a user account management screen 602 of the information processing apparatus according to the first embodiment.

[0050] Fig. 6C is a diagram showing an example of a user account editing screen 603 of the information processing device according to embodiment 1. The screens shown in Fig. 6A to Fig. 6C are displayed by pressing the setting registration menu 511 shown in Fig. 5B, and the screen display is switched by selecting the switching menu 610.

[0051] The login method setting screen 601 of the remote UI allows the user to select a method for logging in to the remote login service unit 303. In this embodiment, "password authentication" is always enabled, and "passkey authentication (passwordless)" can be selected and enabled.

[0052] Password authentication provides a method for logging in by entering a user ID and password. Passkey authentication (passwordless authentication) authenticates a user using a PKI or the like defined by FIDO, called a passkey, in cooperation with the remote login service unit 303, FIDO service unit 304, and authenticator 312. PKI stands for Public Key Infrastructure.

[0053] If passkey authentication (passwordless) is enabled on the login method setting screen 601 in Figure 6A, that is, if the user authentication means is enabled, the passkey authentication screen 502 in Figure 5A is displayed on the web browser 314 as the login screen to authenticate the user.

[0054] If both password authentication and mobile authentication (passkey authentication) are enabled on the login method setting screen 601 in Figure 6A, the password authentication screen 501 with a passkey authentication link and the common authentication screen 503 will be displayed in the web browser 314 on the login screen in Figure 5A.

[0055] That is, when an HTTPS connection is made using an IP address, a password authentication screen 501 with a passkey authentication link is displayed, and when an HTTPS connection is made using a host name, a common authentication screen 503 is displayed. The password authentication screen 501 with a passkey authentication link functions as a cooperative authentication screen that prompts access by passkey authentication using a passkey.

[0056] The password authentication screen 501 with passkey authentication link has fields for inputting a user name and password, and a passkey authentication link 505 that displays "Use passkey" or the like.

[0057] The passkey authentication link 505 is linked with a URL for accessing passkey authentication using the host name. When the URL link (passkey authentication link 505) is pressed, the passkey authentication screen 502 is displayed. That is, the password authentication screen 501 with a passkey authentication link as the linked authentication screen displays the URL link (passkey authentication link 505) to the passkey authentication screen 502.

[0058] On the other hand, on the common authentication screen 503, it is possible to switch the login screen with a checkbox 506 such as "Use passkey". If not checked, the user can enter the username and password and log in with password authentication.

[0059] When a checkbox 506 such as "Use passkey" is checked, the password input field becomes non-editable, and the user can enter the username and log in with passkey authentication. Details of the authentication method using the passkey will be described later.

[0060] When the user's authentication is successful by password authentication or passkey authentication (passwordless), the remote login service unit 303 allows the user to log in to the screen displayed on the web browser 314. When the login is successful, the remote UI 306 that detected the user's login displays the device status screen 504 on the web browser 314.

[0061] <DNS Automatic Registration> In FIDO2.0, a connection using an IP address cannot be made. Therefore, in this embodiment, when accessing the FIDO service unit 304, access is made using the host name. Also, in order to access the FIDO service unit 304 using the host name, the host name and IP address of the MFP101 are registered in advance in the DNS server in the following manner.

[0062] When passkey authentication (passwordless) is enabled on the login method setting screen 601 in Fig. 6A, "Automatic registration to DNS" can be enabled. In other words, the login method setting screen 601 functions as DNS registration setting means that enables setting whether or not to automatically register to DNS when user authentication means is enabled.

[0063] When "Automatically register in DNS" is enabled, the remote login service unit 303 can register the host name and IP address of the MFP 101 in the DNS server.

[0064] This method will be explained using the flowcharts of Figures 7A and 7B. Figure 7A is a flowchart showing an example of a process for URL passkey authentication according to embodiment 1, and Figure 7B is a flowchart showing an example of a process for automatic DNS registration of a URL according to embodiment 1. Also, Figure 7C is a flowchart showing an example of a process for changing the IP address of a URL according to embodiment 1.

[0065] Each step shown in the flowcharts of FIGS. 7A to 7C is realized by a CPU 201 as a computer reading out a computer program stored in a ROM 202 or HDD 204 as a storage medium into a RAM 203 and executing the program.

[0066] In step S701 of Fig. 7A, when the update button on the login method setting screen 601 of Fig. 6A is pressed by the user, the DNS automatic registration process is executed in step S702. Next, the DNS automatic registration process will be described with reference to Fig. 7B.

[0067] In step S721, it is determined whether passkey authentication (passwordless) is enabled on the login method setting screen 601 in FIG. 6A. If Yes, the process proceeds to step S722; if No, the flow in FIG. 7B ends.

[0068] If passkey authentication (passwordless) is enabled in step S721, it is determined in step S722 whether "Automatic registration in DNS" is enabled. If Yes in step S722, the process proceeds to step S723, and if No, the flow in FIG. 7B ends.

[0069] In step S723, it is confirmed whether the host name of the MFP 101 and the IP address associated with it are registered in the DNS server. Next, in step S724, if it is determined as Yes, the process proceeds to step S725, and if it is determined as No, the process proceeds to step S727.

[0070] In step S725, it is determined whether the IP address associated with the host name acquired from the DNS server matches the IP address of the MFP 101. If No, the process proceeds to step S726; if Yes, the flow in FIG. 7B ends.

[0071] In step S726, the IP address associated with the host name already registered in the DNS server is changed to the IP address of the MFP 101. If the host name is not registered in the DNS server in step S724, the host name and IP address of the MFP 101 are registered in the DNS server in step S727.

[0072] In this way, in this embodiment, when automatic registration to the DNS is set by the DNS registration setting means, the host name and IP address are registered in the DNS in steps S726 and S727. Thereafter, the flow in Fig. 7B ends.

[0073] In this embodiment, the "Automatically register in DNS" setting may be automatically enabled in conjunction with the passkey authentication (passwordless) being enabled on the login method setting screen 601 in Fig. 6A. This prevents the user from accidentally disabling the "Automatically register in DNS" setting.

[0074] As described above, the flow of automatically registering the host name and IP address with the DNS server has been explained using FIG. 7B. On the other hand, the IP address assigned to the MFP101 may change. When the IP address of the MFP101 is changed in the state where "Automatically register with DNS" is valid in FIG. 6A, the IP address assigned to the MFP101 is re-registered with the DNS server. An example of the process will be described using FIG. 7C.

[0075] In step S731 of FIG. 7C, it is detected that the IP address of the MFP101 has been changed, and DNS automatic registration is performed in step S732. The DNS automatic registration is performed in the same manner as in FIG. 7B. By the processing method described above, the host name and IP address can be easily registered with the DNS server.

[0076] <FIDO Service Function> The FIDO service unit 304 has a web server function capable of communicating via HTTP and also has a WebAuthn authentication function defined by the FIDO Alliance and the W3C. Further, the FIDO service unit 304 is accessed from the web browser 314 of the information processing apparatus 105 via HTTPS communication, and provides access and functions to URLs 1 to 3 as follows, for example, as a web server. <​​​​​​​​​​

[0080] URL2(https: / / mfp101.office.local / RemoteUI / authentication / challenge)

[0081] The above URL2 is the URL of the REST API that responds with input JSON data to be input to the above navigator.credentials.get(). The input JSON data includes a challenge issued by the FIDO service unit 304. The challenge is a random number.

[0082] URL3(https: / / mfp101.office.local / RemoteUI / authentication / verification)

[0083] URL3 above is the RES TAPI URL that receives information for passkey authentication and receives the output JSON data output by the navigator.credentials.get() API. The output JSON data includes the passkey credential ID used for the digital signature, the challenge, the digital signature, etc.

[0084] <Passkey authentication sequence> Next, a process flow for logging in using a passkey will be described with reference to Fig. 8A and Fig. 8B. Fig. 8A is a diagram showing an example of a sequence of passkey authentication according to embodiment 1, and Fig. 8B is a diagram showing an example of a sequence subsequent to Fig. 8A.

[0085] Each step shown in the sequences of Figures 8A and 8B is realized by the CPUs serving as computers of information processing device 105 and MFP 101 executing a computer program stored in a memory serving as a storage medium in response to user operations.

[0086] In step S801, the user starts the web browser 314 of the information processing device 105. Next, in step S802, the web browser 314 accesses the address of URL1.

[0087] The FIDO service unit 304 verifies the accessed URL in step S803 of Fig. 8B. The URL verification process in step S803 will now be described with reference to the flowchart of Fig. 9.

[0088] Fig. 9 is a flowchart showing an example of the URL verification process in step S803 of Fig. 8B. Each step shown in the flowchart of Fig. 9 is realized by CPU 201 as a computer reading out a computer program stored in ROM 202 or HDD 204 into RAM 203 and executing it.

[0089] In step S901, the FIDO service unit 304 of the MFP 101 detects and accepts access to URL 1. In step S902, it is determined whether passkey authentication (passwordless) is enabled on the login method setting screen 601 of the remote UI.

[0090] If the determination in step S902 is Yes, then in step S903 it is verified whether the URL contains an IP address. On the other hand, if the determination in step S902 is No, then the process proceeds to step S906. If the determination in step S903 is that the URL does not contain an IP address, then in step S904 the HTML of the common authentication screen 503 is generated. After the processing of step S904, the flow in FIG. 9 ends.

[0091] On the other hand, if an IP address is included in step S903, HTML of password authentication screen 501 with passkey authentication link is generated in step S905. That is, if the digital signature verification service means is accessed from the information processing device using the IP address while the user authentication means is valid, password authentication screen 501 with passkey authentication link is generated to prompt access by passkey authentication using a passkey.

[0092] Thereafter, the flow of Fig. 9 ends. Here, step S905 and the like function as a control step (control means) for generating a linked authentication screen when an access is made using an IP address while the user authentication means is valid.

[0093] When the user accesses the passkey authentication link 505 on the password authentication screen 501 with passkey authentication link (linked authentication screen), the passkey authentication screen 502 is displayed and passkey authentication becomes available.

[0094] If the answer is No in step S902, an instruction to redirect to a URL for password authentication is issued in step S906, the web browser 314 displays a screen (not shown) for password authentication, and the flow of FIG. 9 ends.

[0095] 9 is completed, in step S804 of FIG. 8A, the HTML of the passkey authentication screen 502 generated in step S904 is sent to the information processing device 105. The HTML of the passkey authentication screen 502 includes JavaScript for accessing the REST APIs of URL2 and URL3, and the following WebAuthn JavaScript defined in FIDO2.0:

[0096] outputJSONdata = awaitnavigator.credentials.get(inputJSONdata).

[0097] In this embodiment, the header of the communication packet in step S804 includes a session ID to be saved in a cookie of the web browser 314. The session ID is used to confirm that access to URL2 and URL3 is being performed in the same session.

[0098] As a result, if URL2 or URL3 is accessed directly without a session ID in the cookie, the FIDO service unit 304 can return an error without processing the request.

[0099] In step S804, a text field for entering a user ID (user name) is included, as in the passkey authentication screen 502, and in step S805 the user is prompted to enter the user ID. In step S806, the web browser 314 of the information processing device 105 accesses the address of URL2. When accessing URL2 in step S806, the user ID is included.

[0100] Upon receiving the access to URL2, the FIDO service unit 304 obtains the credential ID associated with the user ID from the user database in step S807. Then, in step S808, a challenge is generated. The challenge is a random number.

[0101] Next, in step S809, the FIDO service unit 304 transmits input JSON data (including the credential ID and the challenge) to the information processing device 105. As a result, even if multiple passkeys are managed on the authenticator 312 side of the information processing device 105, it is possible to narrow down the passkey to be used from the credential ID to one.

[0102] The input JSON data includes server information (for example, a host name or domain name such as mfp101.office.local).

[0103] Next, in step S810, the web browser 314 of the information processing device 105 executes the following JavaScript of WebAuthn using the received input JSON data, and starts the authenticator 312.

[0104] outputJSONData = awaitnavigator.credentials.create(inputJSONData);

[0105] If the authenticator 312 manages a plurality of passkeys in association with server information, a screen for selecting one passkey from among the plurality of passkeys may be displayed.

[0106] Next, in step S811, the authenticator 312 of the information processing device 105 authenticates the user of the information processing device 105 by Windows Hello biometric authentication, a PIN, etc. Note that a USB key may be inserted into the USB 216 of the information processing device 105 to authenticate the user.

[0107] Next, in step S812, the authenticator 312 of the information processing device 105 acquires the passkey (PKI private key) stored in association with the server information (for example, mfp101.office.local), and then generates a digital signature using the private key for the data including the challenge received in step S809.

[0108] The authenticator 312 also returns output JSON data to the web browser. The output JSON data includes the digital signature and the credential ID of the passkey used for the digital signature.

[0109] Next, in step S813, the web browser 314 accesses URL3 and transmits output JSON data including the public key, the credential ID, and the digital signature to the FIDO service unit 304. Here, step S813 functions as a digital signature reception step in which the MFP 101 as an image processing device receives a digital signature from the information processing device 105 via HTTP communication.

[0110] Next, in step S814, the FIDO service unit 304 refers to the user database in the HDD 204 and obtains the user ID and public key of the account associated with the received credential ID.

[0111] Next, in step S815, the digital signature received in step S813 is verified using the challenge issued by the device itself in step S808 and the public key obtained from the user database in step S814. If the digital signature is successful, it is determined that authentication has been successful, and if verification fails, it is determined that authentication has failed.

[0112] Next, in step S816, a response is returned indicating whether the authentication was successful. If the authentication was successful, in step S817, the FIDO service unit 304 requests the remote login service unit 303 to log in to the operation panel. The login request includes the user ID.

[0113] Next, in step S818, the remote login service unit 303 performs login processing to allow the user with the user ID designated in step S817 to log in to the screen displayed on the web browser.

[0114] Specifically, the user database in the HDD 204 is referenced to acquire user information such as the user ID, role, and email address of the account to be logged in. Furthermore, a login occurrence event is notified to the remote UI 306. The login event includes the information of the user to be logged in.

[0115] Here, steps S815 to S818 function as a user authentication step (user authentication means) that performs user authentication by verifying the digital signature using a passkey (public key or the like) that is stored in advance in association with the user identifier.

[0116] If the verification is not successful in step S814, the information processing device 105 is notified of the failure in step S816. Verification is not successful when, for example, "the specified user ID is not registered in the user DB," "the public key of the passkey is not registered in association with the user ID," or "verification of the digital signature has failed" in step S815.

[0117] The passkey authentication (passwordless) described above has a higher security level than password authentication, so a configuration may be adopted in which users who have registered a passkey are given priority for logging in using passkey authentication (passwordless). This method is described below.

[0118] That is, when a passkey is registered using the web browser 314, a screen (not shown) is displayed to select whether or not to disable password authentication. If the user selects to disable password authentication on that screen, the invalidity of password authentication is stored in the user database in the HDD 204 in association with the user ID.

[0119] Users who have disabled password authentication will no longer be able to log in using their user ID and password, and will only be able to log in to the Remote UI using passkey authentication (passwordless).

[0120] The password authentication for each user can be enabled / disabled, and the registration status of the passkey can be confirmed or deleted on the user account editing screen 603 in Fig. 6C. On the user account management screen 602, the administrator selects the user to be edited by clicking the checkbox and then pressing the edit button to display the user account editing screen 603 for the selected user.

[0121] A general user can display a user account editing screen 603 for his / her own account by selecting "User Account Management" in the switching menu 610 that is displayed when the setting registration menu 511 is pressed.

[0122] On the user account editing screen 603, disabled password authentication can be re-enabled by pressing the enable button 604. If "passkey has been registered" and "password authentication is enabled", a disable button is displayed instead of the enable button 604, allowing password authentication to be disabled.

[0123] If "passkey is not registered," disabling "password authentication" would leave the user with no means of logging in. Therefore, it may be configured so that "password authentication" cannot be disabled if "passkey is not registered."

[0124] 6C, if the "Passkey Registration Status" is "Registered," the passkey registration can be deleted by pressing the "Delete Registration" button 605. Since deleting the passkey registration means that the user will no longer be able to log in with the passkey, the disabled "Password Authentication" may be automatically configured to be "enabled" as shown in 604.

[0125] If the passkey is not registered, "Not registered" is displayed in "Passkey registration status." If the passkey is not registered, the registration deletion button 605 may be configured to be grayed out or not displayed.

[0126] With the above configuration, password-less login can be provided when a user logs in to the Remote UI without being aware that they are accessing using a host name. Note that the user account edit screen 603 in Figure 6C functions as a user authentication switching means for switching the setting of user authentication means between enabled and disabled.

[0127] Furthermore, when passwordless login is enabled, the host name and IP address are automatically registered in the DNS server, which sets up the environment necessary for password login in a LAN environment, making it easy to use passwordless login with the Remote UI.

[0128] <Embodiment 2> In the first embodiment, a method was described in which, when a URL is accessed using an IP address, a link to access a host name is displayed, and the user can click the link to switch to host name access and perform password-less login.

[0129] In the second embodiment, a list of devices that have logged in without a password is registered in the information processing device 105, and if the next access to URL1 is made by specifying an IP address, the access is redirected to a URL access of the host name. This method will be described with reference to FIG.

[0130] Fig. 10 is a flowchart showing an example of the URL redirection process in step S803 in Fig. 8B. Each step shown in Fig. 10 is realized by CPU 201 as a computer executing a computer program stored in ROM 202 or HDD 204. Steps S1001 to S1006 in Fig. 10 correspond to steps S901 to S906 in Fig. 9, and only the differences will be explained.

[0131] In step S815 of FIG. 8, the digital signature is verified, and if the authentication is successful, the IP address of the information processing device 105 is added to the list of devices that have logged in without a password, which is stored in the HDD.

[0132] In the URL verification in step S803, if it is determined in step S1003 of Fig. 10 that the URL includes an IP address, the process proceeds to step S1007. In step S1007, it is determined whether the IP address of the information processing device 105 that is the access source is included in the list of devices that have logged in without a password.

[0133] If the determination in step S1007 is No, the process proceeds to step S1005, where HTML for the password authentication screen 501 with the passkey authentication link is generated, and the flow in FIG. 10 ends.

[0134] On the other hand, if the determination in step S1007 is Yes, an instruction to redirect to the URL (host name) for passkey authentication is issued in step S1008, and the web browser 314 displays the common authentication screen 503 as the passkey authentication screen. Note that the passkey authentication screen 502 may also be displayed in step S1008.

[0135] Here, step S1008 functions as a control step (control means) for generating a passkey authentication screen when the digital signature verification service means is accessed from the information processing device using an IP address while the user authentication means is valid.

[0136] In this way, in the second embodiment, when authentication is successful by the user authentication means, the identification information of the information processing device is registered in the list of devices that have logged in without a password. Then, when the user authentication means is accessed using an IP address, if the identification information is included in the list of devices that have logged in without a password, the access is redirected to a URL for a passkey authentication screen.

[0137] By configuring it in this way, a user who accesses passkey authentication using an IP address from the second time onwards will be able to display the passkey authentication screen without any operation and log in with the passkey.

[0138] Although the present invention has been described in detail above based on the preferred embodiments, the present invention is not limited to the above embodiments, and various modifications and combinations of the above embodiments are possible based on the spirit of the present invention, and are not excluded from the scope of the present invention. The present invention also includes the following combinations.

[0139] (Configuration 1) An image processing device comprising: a user authentication means for receiving a digital signature from an information processing device via HTTP communication and performing user authentication by verifying the digital signature using a passkey previously stored in association with a user identifier; and a control means for generating an associated authentication screen or a passkey authentication screen that prompts access via passkey authentication using the passkey when the user authentication means is valid and the information processing device accesses the user authentication means using an IP address.

[0140] (Configuration 2) The image processing device according to Configuration 1, further comprising a user authentication switching means for switching between valid and invalid settings of the user authentication means.

[0141] (Configuration 3) The image processing device according to configuration 1 or 2, wherein the linked authentication screen displays a URL link to the passkey authentication screen.

[0142] (Configuration 4) The image processing device according to Configuration 3, wherein when the URL link is pressed, the passkey authentication screen is displayed.

[0143] (Configuration 5) The image processing device according to any one of configurations 1 to 4, wherein when the user authentication means is enabled, it is possible to set whether or not to automatically register in DNS.

[0144] (Configuration 6) The image processing device according to configuration 5, wherein when automatic registration to the DNS is set, the host name and IP address are registered in the DNS.

[0145] (Configuration 7) An image processing device described in any one of configurations 1 to 6, characterized in that when authentication is successful by the user authentication means, identification information of the information processing device is registered in a list of devices that have logged in without a password, and when the user authentication means is accessed using an IP address, if the identification information is included in the list of devices that have logged in without a password, the image processing device is redirected to a URL to the passkey authentication screen.

[0146] (Configuration 8) An image processing device characterized by having a user authentication means for receiving a digital signature from an information processing device via HTTP communication and performing user authentication by verifying the digital signature using a passkey previously stored in association with a user identifier, and a DNS registration setting means for setting whether or not to automatically register in DNS when the user authentication means is enabled.

[0147] (Configuration 9) The image processing device according to configuration 8, wherein when automatic registration to the DNS is set by the DNS registration setting means, the host name and IP address are registered in the DNS.

[0148] (Program) A computer program for controlling each means of the image processing device according to any one of configurations 1 to 9 by a computer.

[0149] In order to realize part or all of the control in the above-described embodiments, a computer program that realizes the functions of the above-described embodiments may be supplied to an image processing device or the like via a network or various storage media. Then, a computer (or a CPU, MPU, or the like) in the image processing device or the like may read and execute the program. In this case, the program and the storage medium storing the program constitute the present invention. [Explanation of symbols]

[0150] 101...MFP 105 Information processing device 205···Operation panel 303···Remote Login Service Department 304···FIDO Services Department 312 Authenticator 314...Web Browser 501...Password authentication screen with passkey authentication link

Claims

1. a user authentication means for receiving a digital signature from the information processing device via HTTP communication and verifying the digital signature using a passkey previously stored in association with a user identifier, thereby authenticating the user; When the user authentication means is enabled and the information processing device accesses the user authentication means using an IP address, a control means for generating a link authentication screen or a passkey authentication screen that prompts access through passkey authentication using the passkey; 1. An image processing device comprising:

2. 2. The image processing apparatus according to claim 1, further comprising: a user authentication switching unit for switching between valid and invalid settings of the user authentication unit.

3. The image processing apparatus according to claim 1 , wherein the link authentication screen displays a URL link to the passkey authentication screen.

4. 4. The image processing apparatus according to claim 3, wherein when the URL link is pressed, the passkey authentication screen is displayed.

5. 2. The image processing apparatus according to claim 1, wherein when the user authentication means is enabled, it is possible to set whether or not to automatically register the image in the DNS.

6. 6. The image processing apparatus according to claim 5, wherein when automatic registration to the DNS is set, the host name and the IP address are registered in the DNS.

7. If authentication by the user authentication means is successful, registering identification information of the information processing device in a password-less login completed device list; 2. The image processing device according to claim 1, wherein when the user authentication means is accessed using an IP address, if the identification information is included in the password-less logged-in device list, the access is redirected to a URL to the passkey authentication screen.

8. a user authentication means for receiving a digital signature from the information processing device via HTTP communication and verifying the digital signature using a passkey previously stored in association with a user identifier, thereby authenticating the user; and a DNS registration setting means for setting whether or not to automatically register in DNS when the user authentication means is valid.

9. 9. The image processing apparatus according to claim 8, wherein when automatic registration to the DNS is set by the DNS registration setting means, the host name and IP address are registered in the DNS.

10. A computer program for controlling each unit of the image processing apparatus according to any one of claims 1 to 9 by a computer.

Citation Information

Patent Citations

  • Information processing device, method for controlling information processing device and program

    JP2022071684A