Information processing method, server device, and information processing device
The server device associates device and user identification with passwords to streamline authentication, reducing login time and ensuring security in image display devices by allowing direct input of disposable passwords.
Patent Information
- Application Number
- JP2024044842
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-10-03
AI Technical Summary
Existing image display devices require users to log in to the device after logging in to a terminal device, which is time-consuming.
A server device associates device identification information with a first password, transmitting it to an output device, and a terminal device displays a second password based on a common key and encryption algorithm, allowing direct input of the second password to authenticate and control the output device.
Reduces the time required for user authentication by allowing direct input of a disposable password on the output device, enhancing security and efficiency in sharing and maintaining the device.
Smart Images

Figure 2025144920000001_ABST
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing method, a server device, and an information processing device. [Background technology]
[0002] Various technologies have been proposed for allowing only pre-authenticated users to operate image display devices such as projectors, and one example is the technology disclosed in Patent Document 1. The password generation device disclosed in Patent Document 1 has an operator authentication means for authenticating an operator who operates the image display device, and a password generation means for generating a disposable password for the authenticated operator to use the image display device. The image display device disclosed in Patent Document 1 has a password authentication means for authenticating a disposable password input by an operation device that operates the image display device, and an operation control means for controlling the operation of the image display device depending on the authentication result by the password authentication means. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2013-061881 Summary of the Invention [Problem to be solved by the invention]
[0004] When an image display device is connected to a network and a terminal device such as a personal computer connected to the network is used as an operating device, the method disclosed in Patent Document 1 requires the user to log in the image display device to the service after logging in the terminal device to the service, which is time-consuming for the user. [Means for solving the problem]
[0005] An aspect of an information processing method of the present disclosure includes a server device providing a service via a network associating device identification information indicating an output device with a first password, the server device transmitting the first password to the output device, the output device outputting information including the first password, a first terminal device that has logged in to the service using user identification information transmitting the first password to the server device, the server device associating the user identification information with the device identification information based on the first password, the server device transmitting a common key associated with the user identification information to the first terminal device, the first terminal device displaying a second password based on the common key and an encryption algorithm, the output device accepting input of the second password, the output device obtaining the user identification information corresponding to the common key from the server device based on the second password and the encryption algorithm, and the output device executing processing based on the user identification information.
[0006]
[0013] One aspect of a server device of the present disclosure includes a communication device that communicates with each of an output device and a first terminal device, and at least one processor, wherein the at least one processor performs the following operations: providing a service over a network; associating device identification information indicating the output device with a first password; transmitting the first password to the output device using the communication device; receiving the first password from the first terminal device that has logged in to the service using user identification information using the communication device; associating the user identification information with the device identification information based on the first password; transmitting a common key associated with the user identification information to the first terminal device using the communication device, thereby causing the first terminal device to output a second password based on the common key and a predetermined encryption algorithm; authenticating the second password based on the encryption algorithm; and, if the authentication is successful, transmitting the user identification information corresponding to the common key to the output device.
[0007] Furthermore, one aspect of an information processing device of the present disclosure includes a communication device that communicates with each of a server device that provides a service and a circuit board of an output device, and at least one processor, wherein the at least one processor executes the following operations: sending device identification information indicating the output device to the server device using the communication device; obtaining from the server device a first password for associating the device identification information with user identification information indicating a user who has logged in to the service; causing the output device to output information including the first password; receiving from the server device a common key associated with the user identification information in the server device; accepting input of a second password based on the common key and an encryption algorithm; authenticating the second password based on the common key and the encryption algorithm; and, if the authentication is successful, obtaining from the server device the user identification information corresponding to the common key; and causing the output device to execute processing based on the user identification information. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a diagram illustrating a configuration example of an information system 1 according to an embodiment of the present disclosure. [Figure 2] 2 is a diagram illustrating an example of the configuration of a server device 30 included in the information system 1. FIG. [Figure 3] 10 is a diagram showing an example of a management table TBL stored in a storage device 350 of a server device 30. FIG. [Figure 4] 10 is a diagram showing an example of a UI screen G1 output by the output device 10 under the control of the information processing device 20. FIG. [Figure 5] 1 is a diagram illustrating an example of the configuration of an information processing device 20 included in an information system 1. FIG. [Figure 6] 1 is a diagram showing a process flow in an information processing method executed in the information system 1. FIG. [Figure 7] FIG. 10 is a diagram showing an example of a support screen G2 according to another embodiment. [Figure 8] FIG. 10 is a diagram showing an example of a UI screen G3 according to a modified example (2). DETAILED DESCRIPTION OF THE INVENTION
[0009] The embodiments described below are subject to various technically preferable limitations, but the embodiments of the present disclosure are not limited to the following embodiments. 1. Embodiment FIG. 1 is a diagram illustrating an example configuration of an information system 1 that executes an information processing method according to an embodiment of the present disclosure. As illustrated in FIG. 1, the information system 1 includes an output device 10, a terminal device 40(1), a terminal device 40(2), and a server device 30. The output device 10 includes an information processing device 20. The information processing device 20, the terminal device 40(1), the terminal device 40(2), and the server device 30 are each connected to a network NW, such as the Internet. In this embodiment, to ensure security, communication between the terminal device 40(1) or the terminal device 40(2) and the server device 30, and communication between the server device 30 and the information processing device 20, are both compliant with HTTPS (HyperText Transfer Protocol Secure). Specifically, these communications are realized using a WebAPI (Web Application Programming Interface).
[0010] The information processing device 20 is a computer device that operates according to, for example, the Android OS (Operating System), and is a device that performs at least part of the operation control of the output device 10 in response to instructions provided from the server device 30 via the network NW. In this embodiment, the information processing device 20 is disposed inside the housing of the output device 10, but the information processing device 20 may be a separate device from the output device 10 and may be connected to the output device 10 via a wire from outside the output device 10. Even when the information processing device 20 is connected to the output device 10 from outside, the information processing device 20 functions integrally with the output device 10 and can therefore be considered as part of the output device 10.
[0011] The output device 10 is an image display device that displays an image, and more specifically, a projector that displays an image on a projection object such as a projection screen by projecting the image onto the projection object. The output device 10 is installed, for example, in a school classroom, and projects images of teaching materials or the like onto the projection screen. The output device 10 pre-stores a device ID (for example, a character string representing a serial number or the like) that is identification information for uniquely identifying the output device 10. The device ID is an example of device identification information in the present disclosure.
[0012] Each of the terminal devices 40(1) and 40(2) is a smartphone used by a teacher or a student, and in the information system 1, it serves as an operating device for operating the output device 10. Hereinafter, when there is no need to distinguish between the terminal devices 40(1) and 40(2), the terminal devices 40(1) and 40(2) will be referred to as "terminal devices 40." Although detailed illustration is omitted in FIG. 1 , the terminal device 40 includes a touch panel display for displaying and inputting various information and a camera for capturing various images. The terminal device 40 also includes a web browser and can access various websites using the web browser. An example of a website accessed by the terminal device 40 using the web browser is a portal site for logging in to services provided by the server device 30. The terminal device 40 also has a web storage mechanism for storing data within the web browser while ensuring security. While FIG. 1 illustrates two terminal devices 40, the information system 1 may include one or more terminal devices 40. The terminal device 40 is an example of a first terminal device in the present disclosure.
[0013] The server device 30 is a device that provides a service (hereinafter, a shared service) that allows users of the terminal devices 40(1) and 40(2) to share the output device 10. The user of the terminal device 40 can share the output device 10 by accessing the portal site using the terminal device 40 and logging in to the shared service. Specifically, a user who has already logged in to the service can have the output device 10 output an image specified by the user when the server device 30 associates the terminal device 40 with the output device 10. In a shared service, logging in is generally performed by entering a user ID and password. In conventional shared services, users must log in to the shared service using the terminal device 40 and then log in to the shared service using the output device 10, which is time-consuming for the user. The information system 1 of this embodiment can reduce this time-consuming process. The following description focuses on the information processing device 20 and the server device 30, which play central roles in the information system 1.
[0014] 2 is a diagram showing an example of the configuration of the server device 30. As shown in FIG. 2, the server device 30 includes a processing device 310, a communication device 320, and a storage device 250.
[0015] The processing device 310 is one or more processors. The processing device 310 is, for example, a CPU (Central Processing Unit). The processing device 310 functions as the control center of the server device 30 by operating in accordance with the program PRA stored in the storage device 350. The communication device 320 is a device that performs wireless or wired communication with other devices, and includes, for example, an interface circuit. Specific examples of other devices that communicate with the communication device 320 include the terminal device 40 and the information processing device 20.
[0016] The storage device 350 is a recording medium that can be read by the processing device 310. The storage device 350 includes, for example, a nonvolatile memory and a volatile memory. The nonvolatile memory is, for example, a ROM (Read Only Memory), an EPROM (Erasable Programmable Read Only Memory), or an EEPROM (Electrically Erasable Programmable Read Only Memory). The volatile memory is, for example, a RAM (Radom Access Memory). The nonvolatile memory of the storage device 350 stores various programs and a management table TBL.
[0017] FIG. 3 is a diagram showing an example of the management table TBL. The management table TBL stores data for associating users of the terminal devices 40 with the output devices 10. More specifically, as shown in FIG. 3, the management table TBL stores a device ID that uniquely identifies the output device 10 and a first password (e.g., a random number sequence) for associating a user with the output device 10, in association with each other. Furthermore, when a user is associated with the output device 10, the management table TBL stores a user ID, which is identification information uniquely identifying the user and was used when logging in to the shared service, in association with the device ID and the first password. The user ID is identification information for uniquely identifying a user in the shared service.
[0018] Examples of various programs stored in nonvolatile memory include a kernel program and a program PRB. The kernel program is not shown in FIG. 2 . When the server device 30 is powered on, the processing device 310 reads the kernel program from the nonvolatile memory to the volatile memory and starts executing the read kernel program. The processing device 210, which operates according to the kernel program, starts executing another program when instructed to do so. For example, when instructed to start executing a program PRB, the processing device 310 reads the program PRB from the nonvolatile memory to the volatile memory and starts executing the program PRB read into the volatile memory.
[0019] Processing device 310 operating in accordance with program PRB functions as first management unit 311, first transmission unit 312, second management unit 313, and second transmission unit 314 shown in Fig. 2. In other words, each of first management unit 311, first transmission unit 312, second management unit 313, and second transmission unit 314 shown in Fig. 2 is a software module realized by operating processing device 210 in accordance with program PRB. The roles of each of first management unit 311, first transmission unit 312, second management unit 313, and second transmission unit 314 shown in Fig. 2 are as follows.
[0020] The first management unit 311 generates a first password upon receiving the device ID of the output device 10 from the information processing device 20 via the network NW. The first management unit 311 associates the generated first password with the device ID received via the network NW. Specifically, the first management unit 311 associates the first password with the device ID received via the network NW and writes them in the management table TBL.
[0021] The first transmission unit 312 transmits the first password to the information processing device 20 by communicating with the information processing device 20 using the communication device 320. The information processing device 20, which has received the first password, causes the output device 10 to output a UI screen including the first password. In other words, the output device 10 displays the UI screen G1 on the projection target. The UI screen G1 may be generated by the information processing device 20 or the output device 10. The transmission of the first password to the information processing device 20 by the first transmission unit 312 is an example of the server device 30 transmitting the first password to the output device 10.
[0022] FIG. 4 is a diagram illustrating an example of a UI screen G1 output by the output device 10. As illustrated in FIG. 4, the UI screen G1 includes an input box A1 for inputting a code sequence, address information A2, a PIN (Personal Identification Number) code A3 added to the address information A2 in the form of a query string, and a QR code A4 obtained by combining the address information A2 and the PIN code A3 and encoding them in a format compliant with ISO / IEC 18004. The address information A2 is, for example, a URL of the server device 30. The PIN code A3 is an example of a first password. Note that QR codes are registered trademarks. As will be described in detail later, a second password, which will be described later, is input into the input box A1. The UI screen G1 is an example of information including the first password. In the UI screen G1, any one of the address information A2, the PIN code A3, and the QR code A4 may be omitted.
[0023] The user of the terminal device 40 uses the camera of the terminal device 40 to have the terminal device 40 read the QR code A4 included in the UI screen G1 output by the output device 10. The terminal device 40 decodes the QR code A4 to obtain address information A2 and a first password. The address information A2 and the first password obtained by decoding the QR code A4 are stored in the web storage mechanism described above. The user of the terminal device 40 accesses the portal site indicated by the address information A2 using a web browser and logs in to the shared service using their own user ID and a password they have set. The terminal device 40 also transmits the first password obtained by decoding the QR code A4 to the server device 30 together with their own user ID. The user ID is an example of user identification information in the present disclosure.
[0024] Upon receiving the user ID and first password of a terminal device 40 from the terminal device 40 that has logged in to the shared service, the second management unit 313 associates the user ID with the device ID stored in the management table TBL in association with the first password. Specifically, the second management unit 313 writes the user ID in association with the first password and the device ID into the management table TBL. Hereinafter, associating the user ID that uniquely identifies the user of the terminal device 40 with the device ID, in other words, associating the user of the terminal device 40 with the output device 10, is referred to as "pairing." There may be multiple users paired with each output device 10, which allows multiple users to switch between using one output device 10.
[0025] The second transmission unit 314 transmits a common key for generating a second password to the terminal device 40 paired with the output device 10 by the second management unit 313, and stores the common key in the management table TBL in association with the user ID of the user paired with the output device 10. In this embodiment, the common key is a random hash character string. The hash character string is generated in the server device 30 because it must be unique for each pairing.
[0026] Upon receiving the shared key, the terminal device 40 generates and displays a second password based on the shared key and a predetermined encryption algorithm. In this embodiment, the encryption algorithm is the TOTP (Time-based One-Time Password) algorithm, but other encryption algorithms may be used. While the TOTP standard recommends that the second password be updated approximately every 30 seconds, the second password may be updated every 60 to 120 seconds due to the shared use of projectors. The user of the terminal device 40 enters the second password displayed on the terminal device 40 by operating the information processing device 20. This input is not performed over a network and is therefore not susceptible to eavesdropping by a MitM (Man-in-the-Middle). While the TOTP sequence is inherently disposable and therefore resistant to eavesdropping, brute-force attacks are a concern when entering the password over a network. Therefore, it is desirable to enter the second password directly into the information processing device 20, such as by operating the information processing device 20. A brute-force attack is an attack that increases the probability of successful authentication by attempting multiple different inputs in a short period of time. Furthermore, since direct input to a physical device must be performed at the location where the physical device is installed, direct input to a physical device is expected to be more effective in deterring unauthorized use of the physical device than input over a network. For this reason, in this embodiment, direct input is used to input the second password to the information processing device 20.
[0027] The information processing device 20 communicates with the server device 30 to authenticate the input second password. Specifically, the information processing device 20 transmits the input second password to the server device 30. The server device 30 authenticates the second password based on whether the received second password can be reproduced when the password is generated based on one of the common keys stored in the management table TBL and the encryption algorithm used by the information processing device 20. That is, if the second password can be reproduced based on one of the common keys stored in the management table TBL and the encryption algorithm, authentication is successful. If the second password cannot be reproduced, authentication is unsuccessful. If the information processing device 20 successfully authenticates the second password, the information processing device 20 communicates with the server device 30 to obtain a user ID stored in the management table TBL in association with the common key used to reproduce the second password, and causes the output device 10 to output an image specified using the user ID. The above is the configuration of the server device 30.
[0028] FIG. 5 is a diagram showing an example of the configuration of the information processing device 20. As shown in FIG. 5, the information processing device 20 includes a processing device 210, a communication device 220, an input device 240, and a storage device 250. Like the processing device 310, the processing device 210 is one or more processors. Specifically, the processing device 210 is a central processing unit (CPU). The processing device 210 functions as the control center of the information processing device 20 by operating in accordance with a program PRB stored in the storage device 250. Like the communication device 320, the communication device 220 includes an interface circuit and performs wireless or wired communication with other devices. Specific examples of other devices that communicate with the communication device 220 include a circuit board included in the output device 10 and the server device 30.
[0029] The input device 240 provides data representing the content of a user's operation to the processing device 210. In this embodiment, the input device 240 is used to input a second password. In this embodiment, the input device 240 is a light receiving unit of a remote control, and the second password is input by operating a remote control or the like for remotely operating the information processing device 20. The information processing device 20 does not need to be equipped with the input device 240. For example, the information processing device 20 may accept input of the second password via the communication device 220, which is an operation signal of an operator equipped in the output device 10, or an operation signal received in the output device 10 via a light receiving unit of a remote control provided outside the information processing device 20. The information processing device 20 accepting input of the second password is an example of the output device 10 accepting input of the second password.
[0030] The storage device 250 is a recording medium that can be read by the processing device 210. Like the storage device 350, the storage device 250 includes a nonvolatile memory and a volatile memory. The nonvolatile memory is, for example, a ROM (Read Only Memory), an EPROM (Erasable Programmable Read Only Memory), or an EEPROM (Electrically Erasable Programmable Read Only Memory). The volatile memory is, for example, a RAM (Radom Access Memory). Various programs are stored in the nonvolatile memory of the storage device 250.
[0031] Examples of various programs stored in the nonvolatile memory include a kernel program, a web browser, and a program PRA. The kernel program and the web browser are not shown in FIG. 5 . The kernel program is a program that causes the processing device 210 to execute the OS. When the output device 10 is powered on, the processing device 210 reads the kernel program from the nonvolatile memory to the volatile memory and begins executing the read kernel program. The processing device 210, operating according to the kernel program, begins executing another program when instructed to do so. For example, when instructed to start executing the program PRA, the processing device 210 reads the program PRA from the nonvolatile memory to the volatile memory and begins executing the program PRA read into the volatile memory.
[0032] Processing device 210 operating in accordance with program PRA functions as acquisition unit 211, first output control unit 212, authentication unit 213, and second output control unit 214 shown in Fig. 5. In other words, each of acquisition unit 211, first output control unit 212, authentication unit 213, and second output control unit 214 shown in Fig. 5 is a software module realized by operating processing device 210 in accordance with program PRA. The roles of each of acquisition unit 211, first output control unit 212, authentication unit 213, and second output control unit 214 shown in Fig. 5 are as follows.
[0033] The acquisition unit 211 transmits the device ID of the output device 10 to the server device 30 using the communication device 220 and acquires the first password returned from the server device 30. The first output control unit 212 causes the output device 10 to output a UI screen G1 including the first password acquired by the acquisition unit 211. The authentication unit 213 accepts input of a second password and authenticates the second password by transmitting the second password entered in the input box A1 to the server device 30. If authentication of the second password is successful, the second output control unit 214 communicates with the server device 30 to acquire the user ID stored in the management table TBL in association with the common key used to reproduce the second password, and causes the output device 10 to output according to the user ID, i.e., output an image specified using the user ID.
[0034] Next, the operation of this embodiment will be described with reference to FIG. 6. FIG. 6 is a diagram showing the flow of processing in an information processing method executed in the information system 1. As shown in FIG. 6, this information processing method includes each process from a first transmission process SA100 to an output control process SA200. The execution entity and processing content of each process from the first transmission process SA100 to the output control process SA200 are as follows. The information processing device 20 executes the first transmission process SA100, for example, when the output device 10 is powered on. In the first transmission process SA100, the processing device 210 of the information processing device 20 functions as an acquisition unit 211. In the first transmission process SA100, the processing device 210 acquires the device ID of the output device 10 and transmits the acquired device ID to the server device 30.
[0035] The processing device 310 of the server device 30 executes a first association process SA110 upon receiving the device ID via the network NW. In the first association process SA110, the processing device 310 functions as a first management unit 311. In the first association process SA110, the processing device 310 generates the first password described above, associates the first password with the received device ID, and stores the first password in the management table TBL, thereby associating the first password with the device ID.
[0036] In the second transmission process SA120 subsequent to the first association process SA110, the processing device 310 functions as a first transmission unit 312. In the second transmission process SA120, the processing device 310 transmits a first password to the information processing device 20. Note that in FIG. 6, the first password is abbreviated as "first PWD".
[0037] Upon receiving the first password, the information processing device 20 executes a UI screen display process SA130. In the UI screen display process SA130, the information processing device 20 functions as the first output control unit 212 described above, and causes the output device 10 to output a UI screen G1.
[0038] The user of the terminal device 40 instructs the terminal device 40 to use its camera to read the QR code A4 included in the UI screen G1 output by the output device 10. This instruction triggers the terminal device 40 to execute an acquisition process SA140. In the acquisition process SA140, the terminal device 40 decodes the QR code A4 included in the image captured by the camera to acquire address information A2 and a PIN code A3, which is a first password. The terminal device 40 then uses a web browser to access the access destination indicated by the address information A2, i.e., the portal site for the shared service, and prompts the user to log in to the shared service. The terminal device 40 determines whether the user has previously accessed the portal site based on whether a user ID is stored in web storage, and if this is the user's first access, redirects the portal site screen and prompts the user to log in using their own user ID. After completing the login to the shared service, the terminal device 40 executes a third transmission process SA150.
[0039] In the third transmission process SA150, the terminal device 40 transmits the first password and the user ID of the terminal device 40 acquired in the acquisition process SA140 to the server device 30. Upon receiving the first password and the user ID, the processing device 310 of the server device 30 executes the second association process SA160.
[0040] In the second association process SA160, the processing device 310 functions as a second management unit 313. In the second association process SA160, the processing device 310 associates the received user ID with the device ID stored in the management table TBL in association with the received first password.
[0041] In a fourth transmission process SA170 subsequent to the second association process SA160, the processing device 310 functions as a second transmission unit 314. In the fourth transmission process SA170, the processing device 310 transmits a common key for generating a second password to the terminal device 40 paired with the output device 10, and stores the common key in the management table TBL in association with the user ID of the user paired with the output device 10.
[0042] Upon receiving the common key, the terminal device 40 executes a display process SA180. In the display process SA180, the terminal device 40 receives the common key transmitted from the server device 30 via the network NW, generates a second password based on the common key and a predetermined encryption algorithm, and displays the generated second password. The user of the terminal device 40 can input the second password displayed on the terminal device 40 into the information processing device 20.
[0043] The processing device 210 of the information processing device 20 executes the authentication process SA190 when the second password is input into the input box A1 by an input operation on the input device 240. In the authentication process SA190, the processing device 210 functions as the authentication unit 213 and transmits the input second password to the server device 30, thereby authenticating the second password.
[0044] In the output control process SA200 subsequent to the authentication process SA190, the processing device 210 functions as a second output control unit 214. In the output control process SA200, if the authentication of the second password is successful, the processing device 210 communicates with the server device 30 to obtain the user ID stored in the management table TBL in association with the common key used to reproduce the second password, and causes the output device 10 to execute output according to the user ID, i.e., output of an image specified using the user ID. The output device 10 outputting an image specified using the user ID is an example of the output device 10 executing processing based on user identification information.
[0045] According to this embodiment, the user inputs a user ID and password to log in to the shared service into the terminal device 40 at hand. On the other hand, the second password input into the UI screen G1 of the output device 10 is a disposable password that is generated each time. Because the login password is not input into the output device 10, it will not be leaked even if the UI screen G1 is viewed by others. Therefore, the information system 1 can switch users of the output device 10 while ensuring security, even when the user is in the public eye.
[0046] Furthermore, according to this embodiment, a user can share the output device 10 simply by logging in to the shared service and inputting the second password to the information processing device 20, and there is no need to log in the output device 10 to the shared service. This reduces the effort required to use the shared service on the output device 10 compared to when the terminal device 40 and the output device 10 are each logged in to the shared service. Furthermore, in cases where there is a problem that students' attention may decrease if the time required for setting up the output device 10 to log in to the shared service during school classes, for example, is long, the time required for setting up the output device 10 to log in to the shared service can be reduced, thereby achieving the effect of preventing a decrease in students' attention.
[0047] In addition, this embodiment employs a so-called zero-trust configuration in which data and keys are distributed among the physical devices, namely, the terminal device 40, the information processing device 20, the output device 10, and the server device 30. Therefore, even if the server device 30 is hacked or the terminal device 40 is lost, information cannot be obtained by anyone who does not have the means to physically access the output device 10. Similarly, even if the second password displayed by the terminal device 40 is intercepted, there is no impact because the second password is disposable. Furthermore, communication between the server device 30 and the terminal device 40 and communication between the server device 30 and the information processing device 20 is end-to-end encrypted and conforms to HTTPS, which has the advantage of making it difficult to intercept the communication path.
[0048] In this embodiment, the UI screen G1, which serves as a guide to pairing, is projected onto a projection screen or the like by the output device 10, allowing multiple users to simultaneously view the UI screen G1. Therefore, in this embodiment, a single UI screen G1 can be used regardless of the number of users sharing the output device 10, allowing all users to pair at once with a single QR code. In a system that issues QR codes to individual users, 50 different QR codes would be required if 50 users shared the output device 10. Displaying these 50 QR codes on the UI screen would result in the QR code being too small. However, this embodiment does not present such a problem. Furthermore, when registering a user via an app, the server device 30 requires storage on the OS for app management for each registration, which requires significant OS resources. However, in this embodiment, OS resources are only required once a PIN code is actually entered, allowing for efficient OS management, since resources are only required for the number of users who actually use the app.
[0049] 2. Other embodiments (1) In the above embodiment, the service provided by the server device 30 is a shared service that allows multiple users to share the output device 10. However, the service may also be a process of restoring information about the usage environment of the output device 10, which is set for each user. The process of restoring the information about the usage environment may be, for example, switching a user management mechanism of the OS or switching user storage for a specific application. The service provided by the server device 30 may also be a service (hereinafter, a maintenance support service) that supports maintenance work to address a malfunction of the output device 10 by periodically remotely referencing information about the operation or status of the output device 10. In other words, the process performed by the output device 10 based on the user ID may include displaying information, changing settings on the output device 10, transmitting information to the server device, and so on, based on the user ID. When the service provided by the server device 30 is a maintenance support service, the user of the terminal device 40 is a technician stationed at a call center or the like separate from the location of the output device 10, who receives inquiries from the user of the output device 10 via telephone, email, SMS (Short Message Service), or the like.
[0050] For example, if a problem occurs with the output device 10, the output device 10 outputs a support screen by operating the output device 10. The operation for outputting the support screen is preferably as simple as possible, for example, by operating a predetermined button provided in advance on the main screen. FIG. 7 is a diagram showing an example of a support screen G2. The support screen G2 includes an input box A1 for inputting a code sequence, a PIN code A3, and address information A2 for accessing a call center. In this embodiment, the address information A2 is the telephone number of the support desk at the call center, and inquiries are made by telephone. The PIN code A3 is preferably a number of about 6 to 9 digits, and the input box A1 preferably allows for input of a number of about 6 to 9 digits.
[0051] More specifically, in response to the operation of the predetermined button, the output device 10 registers its own device ID with the server device 30 via the information processing device 20 prior to outputting the support screen G2. In response to receiving the device ID, the server device 30 issues a PIN code, which is a random number sequence, to each output device 10 that needs to be remotely controlled, and stores the device ID and the PIN code in association with each other in the management table TBL. The PIN code corresponds to the first password in the above embodiment. The server device 30 then returns the issued PIN code associated with the device ID to the output device 10, and the output device 10 outputs the support screen G2 including the PIN code.
[0052] The user of the output device 10 makes an inquiry to the call center by telephone, referring to the address information A2 included in the support screen G2. The maintenance person at the call center asks for the PIN code displayed on the support screen G2 and transmits the PIN code obtained from the user of the output device 10 to the server device 30 using the terminal device 40 used by the user, along with one of multiple maintenance IDs pre-assigned to the call center. The maintenance ID corresponds to the user ID in the above embodiment. If the PIN code received from the terminal device 40 is stored in the management table TBL, the server device 30 adds the maintenance ID received together with the PIN code to the management table TBL in association with the device ID of the output device 10. This achieves pairing between the terminal device 40 of the maintenance person and the output device 10 requiring support. After pairing, the server device 30 transmits a common key to the terminal device 40 used by the maintenance person that is paired with the output device 10 requiring support.
[0053] The terminal device 40 generates a second password based on the common key received from the server device 30 and a predetermined encryption algorithm, and displays the generated second password. The maintenance staff communicates the second password displayed on the terminal device 40 to the user of the output device 10 and prompts the user to enter the second password into the input box A1. When the user enters the second password, the output device 10 authenticates the second password by communicating with the server device 30. If the second password authentication is successful, the output device 10 transmits log information, which is information about the operation or status of the output device 10, along with the second password to the server device 30. The server device 30 stores the log information in a predetermined storage area in the storage device 250 and allows access to the storage area only to users identified by the maintenance ID corresponding to the common key used to generate the second password received together with the log information. The maintenance staff of the output device 10 accesses the storage area using the terminal device 40 to analyze problems occurring in the output device 10. It should be noted that only maintenance personnel of the output device 10 are permitted to access the storage area, so that access to the log information by a third party can be prevented.
[0054] According to this embodiment, log information from a remote output device 10 can be collected simply by exchanging two types of number sequences, thereby enabling users who are not familiar with device operation to easily identify issues. Furthermore, this embodiment also employs a zero-trust configuration using disposable number sequences, enabling spot investigations to be conducted without causing users of the output device 10 anxiety that their device may be remotely controlled in the future, thereby enhancing their sense of security. Furthermore, since the main processing can be performed by the server device 30, a large system does not need to be built on the output device 10 side, and a lightweight embedded OS or an inexpensive OS can be used as the output device 10's OS. Furthermore, according to this embodiment, incident information indicating the nature and frequency of the problem, along with the maintenance ID, device ID, and log information, may be managed by the server device 30. This management allows for quick identification of past problem occurrences for each user for each output device 10, and allows for continuous operational management by using the same maintenance ID even when a problem recurs.
[0055] (2) In the above embodiment, the authentication of the second password was performed by the server device 30. However, the server device 30 may transmit a common key generated in association with a user ID to the information processing device 20, and the information processing device 20 may authenticate the second password. In this case, the information processing device 20 authenticates the second password based on whether a password generated based on the common key and the encryption algorithm described above matches the second password entered in the input box A1 of the UI screen G1. That is, if the generated password matches the second password, the authentication is successful; if they do not match, the authentication is unsuccessful. If the authentication is successful, the information processing device 20 transmits the common key that was used to reproduce the second password to the server device 30. The server device 30 obtains the user ID associated with the common key received from the information processing device 20 from the management table TBL.
[0056] 3. Transformation The above embodiment can be modified as follows. (1) In the above embodiment, the output device 10 was a projector, but the present disclosure may also be applied to the sharing of equipment whose operation needs to be switched in public by multiple people, such as a large-screen television or audio equipment, or an IoT (Internet of Things) device that operates confidentially in a public place. For example, when providing a user with a key for a private lodging, the configuration of the present disclosure may be used to solve the problem of the number on a touch-screen key being spied on.
[0057] (2) The processing device 310 may store a recovery key in the management table TBL in association with the user ID and the common key of a user who has successfully logged in to the shared service, and may also transmit the recovery key to the terminal device 40. The recovery key is a random number sequence, similar to the first password. When a new terminal device other than the terminal device 40 logs in to the shared service using the user ID, the processing device 310 may request input of the recovery key. Upon receiving the recovery key, the processing device 310 may transmit the common key associated with the recovery key to the new terminal device. The new terminal device other than the terminal device 40 is an example of a second terminal device. In an aspect using a recovery key, instead of the UI screen G1 described above, a UI screen G3 having an input box A5 for inputting the recovery key, as shown in FIG. 8, may be used. According to this aspect, by recording the recovery key transmitted from the server device 30, for example, in a memo, the user can use the recovery key to allow the server device 30 to confirm that the login to the shared service is by a legitimate user when logging in to the shared service using a new terminal device, even if the terminal device 40 is lost. Therefore, the information system 1 can provide a service based on a user ID registered in the management table TBL to a user using a new terminal device while ensuring security.
[0058] (3) In the above embodiment, the acquisition unit 211, the first output control unit 212, the authentication unit 213, and the second output control unit 214 are software modules. However, any one, any two, any three, or all of the acquisition unit 211, the first output control unit 212, the authentication unit 213, and the second output control unit 214 may be hardware modules such as an ASIC (Application Specific Integrated Circuit). Even if at least one of the acquisition unit 211, the first output control unit 212, the authentication unit 213, and the second output control unit 214 is a hardware module, the same effects as those of the above embodiment can be achieved. Similarly, at least one of the first management unit 311, the first transmission unit 312, the second management unit 313, and the second transmission unit 314 may be a hardware module.
[0059] (4) The program PRA may be manufactured as a standalone program or provided free of charge or for a fee. Specific examples of providing the program PRA include providing the program PRA by writing it to a computer-readable recording medium such as a flash ROM, or providing the program PRA by downloading it via a telecommunications line such as the Internet. By operating a general computer in accordance with the program PRA provided in these ways, it becomes possible to cause the computer to execute the display method of the present disclosure. Similarly, the program PRB may be manufactured as a standalone program or provided free of charge or for a fee.
[0060] 4. Summary of this disclosure The present disclosure is not limited to the above-described embodiments and modifications, and can be realized in various forms without departing from the spirit thereof. For example, the present disclosure can also be realized in the following forms. The technical features in the above embodiments corresponding to the technical features in each form described below can be replaced or combined as appropriate to solve some or all of the problems of the present disclosure or to achieve some or all of the effects of the present disclosure. Furthermore, if a technical feature is not described as essential in this specification, it can be deleted as appropriate. A summary of this disclosure is provided below.
[0061] (Appendix 1) The information processing method disclosed herein includes a server device that provides a service via a network associating device identification information indicating an output device with a first password, the server device transmitting the first password to the output device, the output device outputting information including the first password, a first terminal device that has logged in to the service using user identification information transmitting the first password to the server device, the server device associating the user identification information with the device identification information based on the first password, the server device transmitting a common key associated with the user identification information to the first terminal device, the first terminal device displaying a second password based on the common key and an encryption algorithm, the output device accepting input of the second password, the output device obtaining the user identification information corresponding to the common key from the server device based on the second password and the encryption algorithm, and the output device executing processing based on the user identification information. According to this aspect, the user can be linked to the output device via the network by performing two simple input operations: inputting user identification information when logging in to the service and inputting a second password for the output device. This reduces the user's effort compared to logging in the output device to the service after logging in the terminal device to the service.
[0062] (Appendix 2) A more preferred aspect of the information processing method is the information processing method described in (Supplementary Note 1), further comprising: the information including the first password includes address information of a website that provides the service; the first terminal device accessing the website using the address information; and the first terminal device logging in to the service from the website using the user identification information. According to this aspect, a user can access a website that provides a predetermined service using the address information included in the information output from an output device.
[0063] (Appendix 3)
[0013] A further preferred aspect of the information processing method is the information processing method described in (Supplementary Note 2), further comprising: when the first terminal device has completed logging in to the service, the server device storing a recovery key in association with the user identification information and the common key; the server device transmitting the recovery key to the first terminal device; when a second terminal device different from the first terminal device logs in to the service using the user identification information, the server device requesting input of the recovery key; and when the server device receives the recovery key from the second terminal device, transmitting the common key associated with the recovery key to the second terminal device. According to this aspect, when a user uses a second terminal device instead of or in addition to the first terminal device, the user can easily recover the association between the user and the output device via a network.
[0064] (Appendix 4) Another preferred embodiment of the information processing method is the information processing method described in any one of (Supplementary Note 1) to (Supplementary Note 3), further including the server device transmitting the common key to the output device, and the output device authenticating the second password based on the common key and the encryption algorithm, and the output device obtaining the user identification information from the server device means obtaining the user identification information if the authentication is successful. According to this embodiment, authentication of a user linked to the output device via a network can be performed by the output device.
[0065] (Appendix 5) Another preferred embodiment of the information processing method is the information processing method according to any one of (Supplementary Note 1) to (Supplementary Note 4), in which the encryption algorithm is a Time-based One-Time Password algorithm. According to this embodiment, a second password generated using the Time-based One-Time Password algorithm can be used to authenticate a user associated with an output device via a network.
[0066] (Appendix 6) Another preferred embodiment of the information processing method is the information processing method according to any one of (Supplementary Note 1) to (Supplementary Note 5), in which the output device is an image display device that displays an image, and the processing based on the user identification information is to display an image corresponding to the user identification information. According to this embodiment, an image corresponding to the user can be displayed on an output device linked to the user via a network.
[0067] (Appendix 7) Another preferred embodiment of the information processing method is the information processing method according to any one of (Supplementary Note 1) to (Supplementary Note 5), in which the processing based on the user identification information is transmitting information about the operation or status of the output device to the server device. According to this embodiment, information about the operation or status of an output device linked to a user is transmitted to the server device via a network, and the user can refer to the information by accessing the server device.
[0068] (Appendix 8) The server device of the present disclosure includes a communication device that communicates with each of an output device and a first terminal device, and at least one processor, and the at least one processor performs the following operations: providing a service over a network; associating device identification information indicating the output device with a first password; transmitting the first password to the output device using the communication device; receiving the first password from the first terminal device that has logged in to the service using user identification information using the communication device; associating the user identification information with the device identification information based on the first password; transmitting a common key associated with the user identification information to the first terminal device using the communication device, thereby causing the first terminal device to output a second password based on the common key and a predetermined encryption algorithm; authenticating the second password based on the encryption algorithm; and, if the authentication is successful, transmitting the user identification information corresponding to the common key to the output device. According to this aspect, the user can be linked to the output device via the network by performing two simple input operations: inputting user identification information when logging in to the service and inputting a second password for the output device. This reduces the user's effort compared to logging in the output device to the service after logging in the terminal device to the service.
[0069] (Appendix 9) The information processing device of the present disclosure includes a communication device that communicates with each of a server device that provides a service and a circuit board of an output device, and at least one processor, wherein the at least one processor performs the following operations: sending device identification information indicating the output device to the server device using the communication device; obtaining from the server device a first password for associating the device identification information with user identification information indicating a user who has logged in to the service; outputting information including the first password to the output device; receiving from the server device a common key associated with the user identification information in the server device; accepting input of a second password based on the common key and an encryption algorithm; authenticating the second password based on the common key and the encryption algorithm; and, if the authentication is successful, obtaining from the server device the user identification information corresponding to the common key; and causing the output device to perform processing based on the user identification information. According to this aspect, the user can be linked to the output device via the network by performing two simple input operations: inputting user identification information when logging in to the service and inputting a second password for the output device. This reduces the user's effort compared to logging in the output device to the service after logging in the terminal device to the service. [Explanation of symbols]
[0070] 1...information system, 10...output device, 20...information processing device, 30...server device, 40,40(1),40(2)...terminal device, 310,210...processing device, 211...acquisition unit, 212...first output control unit, 213...authentication unit, 214...second output control unit, 311...first management unit, 312...first transmission unit, 313...second management unit, 314...second transmission unit, 320,220...communication device, 340...input device, 350,250...storage device, PRA,PRB...program.
Claims
1. a server device that provides a service via a network associating device identification information indicating the output device with a first password; the server device transmitting the first password to the output device; the output device outputs information including the first password; a first terminal device that has logged in to the service using user identification information transmitting the first password to the server device; the server device associating the user identification information with the device identification information based on the first password; the server device transmits a common key associated with the user identification information to the first terminal device; the first terminal device displays a second password based on the common key and an encryption algorithm; the output device accepts input of the second password; the output device acquires the user identification information corresponding to the common key from the server device based on the second password and the encryption algorithm; the output device executes processing based on the user identification information; An information processing method, including:
2. the information including the first password includes address information of a website that provides the service; the first terminal device accessing the website using the address information; the first terminal device logging in to the service from the website using the user identification information; The information processing method according to claim 1 .
3. When the first terminal device has completed logging in to the service, the server device stores a recovery key in association with the user identification information and the common key; the server device transmitting the recovery key to the first terminal device; When a second terminal device different from the first terminal device logs in to the service using the user identification information, the server device requests input of the recovery key; and when the server device receives the recovery key from the second terminal device, transmitting the common key associated with the recovery key to the second terminal device. The information processing method according to claim 2 .
4. the server device transmitting the common key to the output device; the output device authenticating the second password based on the common key and the encryption algorithm; The output device acquiring the user identification information from the server device means acquiring the user identification information if the authentication is successful. The information processing method according to any one of claims 1 to 3.
5. 4. The information processing method according to claim 1, wherein the encryption algorithm is a Time-based One-Time Password algorithm.
6. the output device is an image display device that displays an image, and the processing based on the user identification information is to display an image corresponding to the user identification information. The information processing method according to any one of claims 1 to 3.
7. the processing based on the user identification information is transmitting information about the operation or status of the output device to the server device; The information processing method according to any one of claims 1 to 3.
8. a communication device that communicates with each of the output device and the first terminal device; at least one processor; The at least one processor Providing services over a network; associating device identification information indicating the output device with a first password; transmitting the first password to the output device using the communication device; receiving, by the communication device, the first password from the first terminal device that has logged in to the service using user identification information; associating the user identification with the device identification based on the first password; transmitting a common key associated with the user identification information to the first terminal device using the communication device, thereby causing the first terminal device to output a second password based on the common key and a predetermined encryption algorithm; authenticating the second password based on the encryption algorithm; If the authentication is successful, transmitting the user identification information corresponding to the common key to the output device. Server device.
9. a communication device that communicates with each of the circuit boards of the server device and the output device that provide the service; at least one processor; The at least one processor transmitting device identification information indicating the output device to the server device using the communication device; obtaining, from the server device, a first password for associating the device identification information with user identification information indicating a user who has logged in to the service; outputting information including the first password to the output device; receiving, from the server device, a common key associated with the user identification information at the server device; accepting input of a second password based on the common key and an encryption algorithm; authenticating the second password based on the common key and an encryption algorithm; If the authentication is successful, acquiring the user identification information corresponding to the common key from the server device; causing the output device to execute a process based on the user identification information; Information processing device.
Citation Information
Patent Citations
Image display system, image display device, and password generation device
JP2013061881A