Information processing system and program
The information processing system improves user authentication by dynamically selecting methods based on stayer information, enhancing accuracy and security through sensor-based adjustments.
Patent Information
- Application Number
- JP2024044899
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-10-03
AI Technical Summary
Existing authentication methods based on calendar, time, or location fail to accurately authenticate users near a device, particularly when a person is standing still, leading to potential misuse of user authentication information.
An information processing system that acquires stayer information using multiple human presence sensors to dynamically select an appropriate authentication method based on the number, status, and orientation of individuals near the device, adjusting security levels accordingly.
Enhances user authentication accuracy by selecting appropriate methods based on real-time conditions, reducing the risk of unauthorized access and simplifying operations while maintaining security.
Smart Images

Figure 2025144956000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system and a program. [Background technology]
[0002] Patent document 1 describes an image processing device that stores an authentication level set based on the amount of image processing predicted according to at least one of the calendar and the time, and when image processing is requested for image data, switches the authentication level based on at least one of the calendar and the time to authenticate the user, and performs the requested image processing according to the result of this authentication. Patent Document 2 describes an authentication method in which a device accepts input of first authentication information, receives the first authentication information from the device, performs user authentication based on the first authentication information, determines whether second authentication information is required based on location information of the device, and if it is determined that the second authentication information is required, transmits security information to the device to request input of the second authentication information, receives the security information, accepts input of the second authentication information, receives the second authentication information from the device, and performs user authentication based on the second authentication information. [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Laid-Open No. 2004-102708 [Patent Document 2] Japanese Patent Application Publication No. 2019-160058 Summary of the Invention [Problem to be solved by the invention]
[0004] If a device authenticates a user using an authentication method based on at least one of the calendar and the time, or an authentication method based on the location where the device is located, the device will not be able to authenticate a user using an appropriate authentication method based on information about a person standing still near the device.
[0005] An object of the present invention is to enable a device to authenticate a user using an appropriate authentication method according to information on a person standing still in the vicinity of the device. [Means for solving the problem]
[0006] The invention described in claim 1 is an information processing system comprising one or more processors, which acquire stayer information regarding stayers who are standing still in the vicinity of a device, and select a specific authentication method from among multiple authentication methods to be used by the device when authenticating a user, depending on the stayer information. A second aspect of the present invention is the information processing system according to the first aspect, wherein the plurality of authentication methods are predetermined for the user. The invention described in claim 3 is an information processing system described in claim 1, wherein the one or more processors acquire the number of stayers as the stayer information, and if the number of stayers is a first number, select a first authentication method as the specific authentication method, and if the number of stayers is a second number greater than the first number, select a second authentication method having a higher security level than the first authentication method as the specific authentication method. The invention described in claim 4 is an information processing system described in claim 1, wherein the one or more processors acquire the status of the stayer as the stayer information, and when the status of the stayer is a first state, select a first authentication method as the specific authentication method, and when the status of the stayer is a second state that poses a higher threat to authentication than the first state, select a second authentication method that has a higher security level than the first authentication method as the specific authentication method. The invention described in claim 5 is an information processing system described in claim 4, wherein the state of the person staying is the orientation of the person staying, the first state is a state in which the person staying is not facing the direction of the device, and the second state is a state in which the person staying is facing the direction of the device. The invention described in claim 6 is the information processing system described in claim 1, wherein the one or more processors further acquire present person information regarding present persons present in the vicinity of the device, and select the specific authentication method from the multiple authentication methods further depending on the present person information. The invention described in claim 7 is an information processing system described in claim 6, in which the stayer information is information detected by a first type of sensor, and the present person information is information detected by a second type of sensor different from the first type. The invention described in claim 8 is an information processing system described in claim 6, in which the stayer information is information detected by a sensor, and the present person information is information pre-stored for the device. The invention described in claim 9 is an information processing system comprising one or more processors, wherein the one or more processors, when stayer information regarding a stayer who is standing still near a device, is first information, select a first authentication method from among a plurality of authentication methods as a specific authentication method to be used by the device when authenticating a user, and when the stayer information is second information, select a second authentication method from among the plurality of authentication methods as the specific authentication method. The invention described in claim 10 is a program for enabling a computer to acquire stayer information regarding a stayer who is standing still near a device, and to select a specific authentication method to be used by the device to authenticate a user from among multiple authentication methods according to the stayer information. [Effects of the Invention]
[0007] According to the invention of claim 1, the device can authenticate the user using an appropriate authentication method according to information on the person standing still around the device. According to the invention of claim 2, an appropriate authentication method according to information on a person standing around the device can be selected from a plurality of authentication methods predetermined for the user. According to the invention of claim 3, the device can authenticate users using an appropriate authentication method according to the number of people standing around the device. According to the invention of claim 4, the device can authenticate the user using an appropriate authentication method according to the state of the person standing still around the device. According to the invention of claim 5, the device can authenticate the user using an appropriate authentication method according to the orientation of the person standing still around the device. According to the invention of claim 6, it is possible to reduce the possibility that an inappropriate authentication method will be selected due to erroneous recognition of a person standing still near the device. According to the invention of claim 7, even if information is not stored in advance, it is possible to reduce the possibility of an inappropriate authentication method being selected due to the false recognition of a person standing still near the device. According to the invention of claim 8, even without using two different types of sensors, it is possible to reduce the possibility of an inappropriate authentication method being selected due to the false recognition of a person standing still near the device. According to the invention of claim 9, the device can authenticate the user using an appropriate authentication method according to information on the person standing still around the device. According to the invention of claim 10, the device can authenticate the user using an appropriate authentication method according to information on the person standing still around the device. [Brief explanation of the drawings]
[0008] [Figure 1] 1 is a diagram illustrating an example of the overall configuration of an image processing system according to an embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of a hardware configuration of a cloud server according to the present embodiment. [Figure 3] FIG. 1 is a diagram illustrating an example of a hardware configuration of an image processing device according to an embodiment of the present invention. [Figure 4] 10A and 10B are diagrams illustrating an example of a user's operation on the image processing system according to the first embodiment. [Figure 5]10A and 10B are diagrams illustrating an example of a user's operation on an image processing system according to a second embodiment. [Figure 6] 10A and 10B are diagrams illustrating an example of a user's operation on an image processing system according to a third embodiment. [Figure 7] FIG. 10 is a diagram showing an example of a user's operation on an image processing system according to a fourth embodiment. [Figure 8] FIG. 2 is a block diagram illustrating an example of a functional configuration of a cloud server according to the present embodiment. [Figure 9] FIG. 4 is a sequence diagram showing an example of the operation of the image processing system according to the first embodiment. [Figure 10] FIG. 10 is a sequence diagram showing an example of the operation of the image processing system according to the second embodiment. [Figure 11] FIG. 10 is a sequence diagram showing an example of the operation of the image processing system according to the third embodiment. [Figure 12] FIG. 10 is a sequence diagram showing an example of the operation of the image processing system of the fourth aspect. DETAILED DESCRIPTION OF THE INVENTION
[0009] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0010] [Outline of this embodiment] This embodiment provides an information processing system that acquires stayer information about people who are standing still near a device (hereinafter referred to as "stayers") and selects a specific authentication method from multiple authentication methods to be used by the device when authenticating a user, based on the stayer information.
[0011] Here, the "system" may be composed of a single device or multiple devices. In the following, an information processing system composed of a single device will be described as an example, and the single device will be a cloud server. Furthermore, the device may be a device that performs any processing, but the following description will be given taking an image processing device that performs image processing as an example.
[0012] [Overall configuration of image processing system] 1 is a diagram showing an example of the overall configuration of an image processing system 1 according to the present embodiment. As shown in the figure, the image processing system 1 is configured by connecting a terminal device 10, a cloud server 20, and an image processing device 40 via a communication line 80.
[0013] The terminal device 10 is a computer used by a user. The terminal device 10 is used by the user to create document data (sometimes simply called a "document") and register this document data in the cloud server 20. The terminal device 10 may be, for example, a desktop PC, a notebook PC, a personal digital assistant, or the like. Although only one terminal device 10 is shown in the figure, multiple terminal devices 10 may be provided.
[0014] Cloud server 20 is a server computer that provides a cloud service that stores document data registered by a user from terminal device 10 and transmits the document data to image processing device 40 in response to a request from image processing device 40. Although only one cloud server 20 is shown in the figure, multiple cloud servers 20 may be provided. Also, instead of cloud server 20, a normal server computer may be used.
[0015] The image processing device 40 is a device that performs image processing such as forming an image on a recording medium such as paper, reading an image from a recording medium such as paper, transmitting an image to a public line, and receiving an image from a public line. The image processing device 40 is a printer from the viewpoint of only forming an image, a copier from the viewpoint of reading an image and forming an image, and a facsimile from the viewpoint of reading an image and transmitting an image or receiving an image and forming an image. Although only one image processing device 10 is shown in the figure, multiple image processing devices 40 may be provided.
[0016] The communication line 80 is a line used for information communication between the terminal device 10 and the cloud server 20, and between the image processing device 40 and the cloud server 20. As the communication line 80, for example, the Internet or a LAN (Local Area Network) may be used.
[0017] [Cloud server hardware configuration] 2 is a diagram illustrating an example of the hardware configuration of cloud server 20 according to the present embodiment. As illustrated, cloud server 20 includes processor 21, main memory 22, HDD (Hard Disk Drive) 23, communication interface (hereinafter referred to as "communication I / F") 24, display device 25, and input device 26. The processor 21 executes various software such as an OS (Operating System) and applications, and realizes the functions described below. The main memory 22 is a memory used as a working memory for the processor 21, etc. The HDD 23 is, for example, a magnetic disk device that stores input data for various software programs and output data from various software programs. The communication I / F 24 transmits and receives various information to and from the terminal device 10 via the communication line 80, and also transmits and receives various information to and from the image processing device 40. The display device 25 is, for example, a display that displays various types of information. The input device 26 is, for example, a keyboard or a mouse that the user uses to input information.
[0018] 2 can also be regarded as the hardware configuration of the terminal device 10. However, when describing the terminal device 10, the processor 21, main memory 22, HDD 23, communication I / F 24, display device 25, and input device 26 in FIG. 2 will be referred to as the processor 11, main memory 12, HDD 13, communication I / F 14, display device 15, and input device 16, respectively.
[0019] [Hardware configuration of image processing device] 3 is a diagram showing an example of the hardware configuration of an image processing device 40 according to the present embodiment. As shown in the figure, the image processing device 40 includes a processor 41, a RAM (Random Access Memory) 42, a ROM (Read Only Memory) 43, an HDD 44, an operation panel 45, an image reading unit 46, an image forming unit 47, a communication I / F 48, and a human presence sensor 49.
[0020] The processor 41 loads various programs stored in the ROM 43 or the like into the RAM 42 and executes them to realize various functions, which will be described later. The RAM 42 is a memory used as a working memory for the processor 41, etc. The ROM 43 is a memory that stores various programs executed by the processor 41. The HDD 44 is, for example, a magnetic disk device that stores image data read by the image reading unit 46 and image data used in image formation by the image forming unit 47 . The operation panel 45 is, for example, a touch panel that displays various information and accepts operation inputs from the user. Here, the operation panel 45 is composed of a display that displays various information and a position detection sheet that detects a position indicated by an indication means such as a finger or a stylus pen. Alternatively, a display and a keyboard may be used instead of the touch panel.
[0021] The image reading unit 46 reads an image recorded on a recording medium such as paper. Here, the image reading unit 46 is, for example, a scanner, and may be of a CCD type in which light irradiated onto an original from a light source is reduced by a lens and reflected light is received by a CCD (Charge Coupled Device), or of a CIS type in which light irradiated onto an original in sequence from an LED light source is received by a CIS (Contact Image Sensor). The image forming unit 47 forms an image on a recording medium such as paper. Here, the image forming unit 47 is, for example, a printer, and it is preferable to use an electrophotographic system that forms an image by transferring toner attached to a photosensitive member onto a recording medium, or an inkjet system that forms an image by ejecting ink onto a recording medium. The communication I / F 48 transmits and receives various information to and from the cloud server 20 via the communication line 80 . The human presence sensor 49 detects people present around the image processing device 40. A specific example of the human presence sensor 49 will be described in detail later.
[0022] [Issues and solutions for image processing systems] In the image processing system 1 described above, the image processing device 40 may be installed in a public area where there are many unauthorized people who can connect wirelessly. In such a case, the multi-factor authentication that allows a legitimate user (user A) to operate the image processing device 40 and execute printing must be performed in a state that satisfies an appropriate security level.
[0023] However, if the authentication method for the multi-factor authentication used by user A is statically determined based on the installation location of the image processing device 40 or the time of use by the user, there is a risk that the user authentication information used by user A for the multi-factor authentication may be misused from the image processing device 40 if it is stolen.
[0024] Therefore, in the image processing system 1 of this embodiment, the image processing device 40 acquires information about people who have stopped in the vicinity of the image processing device 40 for a predetermined time or longer using the human presence sensor 49, and transmits this acquired information to the cloud server 20. The cloud server 20 then dynamically switches the authentication method of the multi-factor authentication used by user A to an authentication method with a security level corresponding to the acquired information, thereby preventing damage caused by theft. It is assumed that the authentication method and its selection conditions are set in advance by user A. In addition, the cloud server 20 determines a default authentication method in advance, and switches to an authentication method with a high security level in high-risk situations, and switches to an authentication method with a low security level in low-risk situations, thereby maintaining an appropriate security level.
[0025] In the present embodiment, the image processing device 40 detects the surrounding situation using, for example, the human presence sensor 49 described below and transmits the information to the cloud server 20, and the cloud server 20 dynamically switches the authentication method depending on the surrounding situation of the image processing device 40. However, since the information that can be detected and the content that can be determined by each human presence sensor 49 alone are limited, it is desirable to improve the detection accuracy of the surrounding situation of the image processing device 40 by using a combination of multiple human presence sensors 49. Note that the information that can be detected by the human presence sensor 49 listed below is merely an example and is not limited to this.
[0026] The first type of human presence sensor 49 is a reflective sensor 49a. The reflective sensor 49a detects a human body or object in front based on the state of light blocking in the front. It is conceivable that the security level is increased when multiple users are detected, and decreased when only one user is detected.
[0027] A second type of human presence sensor 49 is a pyroelectric infrared sensor 49b. Pyroelectric infrared sensor 49b detects whether an object in front of it is a human or non-human body based on the temperature difference of the object. It is conceivable that the security level will be increased if multiple users are detected, and decreased if only one user is detected.
[0028] A third type of human presence sensor 49 is a camera sensor 49c. The camera sensor 49c visually captures a human body or object in front and detects the orientation of the human body or object. For example, the camera sensor 49c detects the direction of a person's gaze and feet. If the gazes of multiple users are detected, the security level may be increased, and if the gaze of only one user is detected, the security level may be decreased. Furthermore, if the user's feet are directed in multiple directions toward the image processing device 40, the security level may be increased, and if the user's feet are directed in another direction, the security level may be decreased.
[0029] A fourth type of human presence sensor 49 is a vibration sensor 49d. Vibration sensor 49d detects any vibrations in the surrounding area to detect the surrounding congestion, etc. It is conceivable that the security level be increased if the number of vibrations is high, and decreased if the number of vibrations is low.
[0030] A fifth type of human presence sensor 49 is a sound detection sensor 49e. Sound detection sensor 49e detects any sound in the surrounding area to detect the surrounding congestion, etc. It is conceivable that the security level will be increased if multiple sounds are detected, and decreased if no sound is detected.
[0031] [Image processing system overview] (First aspect) In the image processing system 1 of the first embodiment, the cloud server 20 selects an authentication method based on information detected by the reflection sensor 49a.
[0032] It should be noted that a pyroelectric infrared sensor 49b or a camera sensor 49c may be used in place of or in combination with the reflection sensor 49a, but the following description will be given assuming that the reflection sensor 49a is used.
[0033] FIG. 4 is a diagram showing an example of a user's operation on the image processing system 1 of the first embodiment. As shown in the figure, it is assumed that user A has already set authentication methods 1 to 3 and their selection conditions in accordance with the security level. Specifically, "ID / password / fingerprint authentication," an authentication method with a "high" security level, is set as authentication method 1. Here, "ID / password / fingerprint authentication" is an authentication method in which a user ID is entered, authentication is performed using a password, and authentication is performed using a fingerprint. It is also set that authentication method 1 will be selected when the number of people staying is five or more. Additionally, "ID / password / email notification," an authentication method with a "medium" security level, is set as authentication method 2. Here, "ID / password / email notification" is an authentication method in which a user ID is entered, authentication is performed using a password, and authentication is performed using a passcode sent by e-mail. It is also set that authentication method 2 is selected when the number of users staying is between 2 and 4. Furthermore, "ID / fingerprint authentication," an authentication method with a "low" security level, is set as authentication method 3. Here, "ID / fingerprint authentication" is an authentication method in which a user ID is entered and authentication is performed using a fingerprint. It is also set that authentication method 3 is selected when the number of remaining users is one.
[0034] In this state, a case will be considered in which two people, a user A who has proper authority and a non-passerby B who does not have proper authority, are standing still near the image processing device 40. In this case, assume that user A stands in front of image processing device 40 and performs multi-factor authentication to print document X stored in cloud server 20. At this time, cloud server 20 selects an authentication method that suits the situation around image processing device 40. In this example, the number of people detected by reflection sensor 49a is two, so cloud server 20 selects authentication method 2. As a result, user A performs authentication using "ID / password / email notification," and if authentication is successful, document X can be printed. Furthermore, suppose that after user A leaves, non-passer B performs multi-factor authentication. At that time, the cloud server 20 dynamically switches the authentication method. In this example, the number of people detected by the reflection sensor 49a decreases from two to one, so the cloud server 20 switches from authentication method 2 used by user A to authentication method 3. As a result, non-passer B can no longer be authenticated using "ID / password / email notification," and unauthorized use of the image processing device 40 by others is prevented.
[0035] A specific flow of user operations will be described below. First, user A logs in to cloud server 20 and registers document X and a user ID in cloud server 20 (S11). Note that although a print instruction for document X may be registered in cloud server 20, the following description will be given assuming that document X is registered. Next, in the image processing device 40, the reflection sensor 49a detects "two people", namely, the user A and the non-passerby B, as the number of people who have been standing still for a predetermined time (for example, five seconds) or more (S12). Then, the image processing device 40 makes an access request to the cloud server 20 and transmits "two people" obtained from the reflection sensor 49a (S13). As a result, cloud server 20 selects authentication method 2 from authentication methods 1 to 3 based on the information that there are "two people" obtained from image processing device 40 (S14). Then, cloud server 20 presents authentication method 2 to image processing device 40 (S15). As a result, user A is authenticated by the image processing device 40 using "ID / password / email notification" (S16). If the authentication is successful, user A obtains document X from cloud server 20 and prints document X (S17).
[0036] In the above, the number of people standing still around the image processing device 40 is used as information that affects the risk of theft of user authentication information of a legitimate user of the image processing device 40, but this is not limiting. The state of the people standing still around the image processing device 40, such as the direction of the people, may also be used as such information.
[0037] (Second aspect) In the image processing system 1 of the second embodiment, the cloud server 20 switches the authentication method from the default authentication method based on the information detected by the reflection sensor 49a.
[0038] It should be noted that a pyroelectric infrared sensor 49b or a camera sensor 49c may be used in place of or in combination with the reflection sensor 49a, but the following description will be given assuming that the reflection sensor 49a is used.
[0039] FIG. 5 is a diagram showing an example of a user's operation on the image processing system 1 of the second embodiment. As shown in the figure, it is assumed that user A has previously set authentication methods 1 to 3 that match the security level and their selection conditions. Also, as underlined, user A has set authentication method 2 as the default authentication method. Note that the details of authentication methods 1 to 3 are the same as those in the first aspect, so a description thereof will be omitted.
[0040] In this state, it is assumed that only user A, who has proper authority, is standing around the image processing device 40. In this case, assume that user A stands in front of image processing device 40 and performs multi-factor authentication to print document X stored in cloud server 20. At this time, cloud server 20 switches the default authentication method to an authentication method suited to the situation around image processing device 40. In this example, the number of people detected by reflection sensor 49a is one, and there are no non-passersby who may be malicious users around image processing device 40. Therefore, since the risk of the user ID, password, etc. being stolen is low, cloud server 20 switches the authentication method from default authentication method 2 to authentication method 3, which requires fewer operations, thereby simplifying the operation procedure.
[0041] A specific flow of user operations will be described below. First, user A logs in to cloud server 20 and registers document X and a user ID in cloud server 20 (S21). Note that although a print instruction for document X may be registered in cloud server 20, the following description will be given assuming that document X is registered. Next, in the image processing device 40, the reflection sensor 49a detects "one" user A as the number of people who have been standing still for a predetermined time (for example, five seconds) or more (S22). Then, the image processing device 40 makes an access request to the cloud server 20 and transmits "one person" obtained from the reflection sensor 49a (S23). As a result, the cloud server 20 selects authentication method 3 from authentication methods 1 to 3 based on the information that "1 person" is obtained from the image processing device 40, and changes the default authentication method 2 to the selected authentication method 3 (S24). Then, cloud server 20 presents authentication method 3 to image processing device 40 (S25). As a result, user A will be authenticated by "ID / fingerprint authentication" at image processing device 40 (S26). If the authentication is successful, user A obtains document X from cloud server 20 and prints document X (S27).
[0042] In the above, the number of people standing still around the image processing device 40 is used as information that affects the risk of theft of user authentication information of a legitimate user of the image processing device 40, but this is not limiting. The state of the people standing still around the image processing device 40, such as the direction of the people, may also be used as such information.
[0043] (Third aspect) If the image processing device 40 is installed in a place where the population density is always high, such as a store or office, there is a possibility that passersby will always be present around the image processing device 40. In such a case, in S12 of the first embodiment or S22 of the second embodiment, the reflection sensor 49a continuously detects passersby within the detection range when acquiring the number of people standing still around the image processing device 40. This can lead to false detection of the number of people standing still around the image processing device 40, which can result in, for example, a complicated authentication method being mistakenly selected, resulting in an increase in the number of steps.
[0044] Therefore, in the image processing system 1 of the third embodiment, the cloud server 20 selects an authentication method based on the information detected by the reflection sensor 49a and the information detected by the vibration sensor 49d.
[0045] Specifically, the cloud server 20 acquires information about a person or object standing still in front of the image processing device 40 detected by the reflection sensor 49a, as well as information about passersby around the image processing device 40 detected by the vibration sensor 49d. That is, the cloud server 20 acquires information about a person or object standing still in front of the image processing device 40 in combination with information about the number of people passing by, thereby detecting the situation around the image processing device 40 in more detail and reducing false detections. This allows the cloud server 20 to select and dynamically switch an appropriate authentication method, thereby enabling the selection of an operation procedure appropriate for the user that is suited to the installation situation of the image processing device 40.
[0046] It should be noted that a pyroelectric infrared sensor 49b or a camera sensor 49c may be used in place of or in combination with the reflection sensor 49a, but the following description will be given assuming that the reflection sensor 49a is used. Furthermore, sound detection sensor 49e may be used in place of vibration sensor 49d or in combination with vibration sensor 49d, but the following description will be given assuming that vibration sensor 49d is used.
[0047] FIG. 6 is a diagram showing an example of a user's operation on the image processing system 1 of the third embodiment. As shown in the figure, it is assumed that user A has already set authentication methods 1 to 3 and their selection conditions in accordance with the security level. Specifically, "ID / password / fingerprint authentication," an authentication method with a "high" security level, is set as authentication method 1. It is also set to be selected when the number of people staying is five or more and there are few passersby. Additionally, "ID / password / email notification," an authentication method with a "medium" security level, is set as authentication method 2. It is also set to be selected when the number of people staying is five or more and there are many passersby. Furthermore, "ID / fingerprint authentication," an authentication method with a "low" security level, is set as authentication method 3. It is also set that authentication method 3 will be selected when there is only one person staying and many people passing by.
[0048] In the third aspect, the expressions "many" and "few" are used to indicate the number of passersby, but the number of passersby may be defined as "many" when it is greater than a predetermined value, and as "few" when it is less than a predetermined value. Also, instead of "many" and "few," the number of passersby may be stored. Also, the figure does not show the authentication method that is selected when there are 2 to 4 people staying, or when there is only one person staying and few passersby, but these authentication methods may also be set.
[0049] A specific flow of user operations will be described below. First, user A logs in to cloud server 20 and registers document X and a user ID in cloud server 20 (S31). Note that although a print instruction for document X may be registered in cloud server 20, the following description will be given assuming that document X is registered. Next, in the image processing device 40, the reflection sensor 49a acquires "five people" as the number of people who have stopped for a predetermined time (e.g., five seconds) or more (S32). Here, the "five people" refers to user A and non-passers B and C who were correctly recognized by the reflection sensor 49a, passerby D who was mistakenly recognized as passersby D1, D2, ... by the reflection sensor 49a, and passerby E who was mistakenly recognized as passersby E1, E2, ... by the reflection sensor 49a. Furthermore, in the image processing device 40, the vibration sensor 49d detects that there are many passersby based on vibrations caused by passersby D1, D2, . . . and passersby E1, E2, . Then, the image processing device 40 makes an access request to the cloud server 20 and transmits "five people" obtained from the reflection sensor 49a and "many passersby" obtained from the vibration sensor 49d (S34). As a result, the cloud server 20 selects authentication method 2 from authentication methods 1 to 3 based on the information of "five people" and the information of "many passersby" obtained from the image processing device 40 (S35). In other words, although reflection sensor 49a detected five or more people, vibration sensor 49d determined that there were many passersby, and therefore it was determined that there was no need to increase the security level to authentication method 1, and authentication method 2 was selected. Then, cloud server 20 presents authentication method 2 to image processing device 40 (S36). As a result, user A is authenticated by the image processing device 40 using "ID / password / email notification" (S37). If the authentication is successful, user A obtains document X from cloud server 20 and prints document X (S38).
[0050] In the above, the number of people standing still around the image processing device 40 is used as information that affects the risk of theft of user authentication information of a legitimate user of the image processing device 40, but this is not limiting. The state of the people standing still around the image processing device 40, such as the direction of the people, may also be used as such information.
[0051] (Fourth aspect) To address the same issues as those described in the third aspect, in the image processing system 1 of this embodiment, the cloud server 20 selects an authentication method based on the information detected by the reflection sensor 49a and the information obtained by the map application.
[0052] Specifically, the cloud server 20 works in conjunction with the map application to acquire the density, which is the number of people per unit area for each time period in surrounding buildings, stored in the map application, based on the location information of the image processing device 40. Then, the cloud server 20 dynamically determines the authentication method based on the information acquired from the reflection sensor 49a and the information obtained from the map application, thereby correcting false detections when five or more passersby are detected at any one time, selecting an appropriate authentication method, and preventing an increase in the number of procedures.
[0053] It should be noted that a pyroelectric infrared sensor 49b or a camera sensor 49c may be used in place of or in combination with the reflection sensor 49a, but the following description will be given assuming that the reflection sensor 49a is used. Also, instead of or in combination with the map application, another application capable of accumulating the density may be used, but the following description will be given assuming that the map application is used.
[0054] FIG. 7 is a diagram showing an example of a user's operation on the image processing system 1 of the fourth embodiment. As shown in the figure, it is assumed that user A has already set authentication methods 1 to 3 and their selection conditions in accordance with the security level. Specifically, "ID / password / fingerprint authentication," an authentication method with a "high" security level, is set as authentication method 1. It is also set that authentication method 1 will be selected when the number of people staying is five or more and the density is low. Additionally, "ID / password / email notification," an authentication method with a "medium" security level, is set as authentication method 2. It is also set that authentication method 2 will be selected when the number of people staying is five or more and the density is high. Furthermore, "ID / fingerprint authentication," an authentication method with a "low" security level, is set as authentication method 3. It is also set that authentication method 3 will be selected when there is only one person staying and the density is high.
[0055] In the fourth aspect, the density is expressed as "high" or "low", but the density value may be defined as "high" when it is greater than a predetermined value, and as "low" when it is less than a predetermined value. Also, instead of the density being "high" or "low", the density value may be stored. Also, the figure does not show the authentication method that is selected when the number of people staying is 2 to 4, or when the number of people staying is 1 and the density is low, but these authentication methods may also be set.
[0056] A specific flow of user operations will be described below. First, user A logs in to cloud server 20 and registers document X and a user ID in cloud server 20 (S41). Note that although a print instruction for document X may be registered in cloud server 20, the following description will be given assuming that document X is registered. Next, in the image processing device 40, the reflection sensor 49a acquires "five people" as the number of people who have stopped for a predetermined time (e.g., five seconds) or more (S42). Here, the "five people" refers to user A and non-passers B and C who were correctly recognized by the reflection sensor 49a, passerby D who was mistakenly recognized as passersby D1, D2, ... by the reflection sensor 49a, and passerby E who was mistakenly recognized as passersby E1, E2, ... by the reflection sensor 49a. Furthermore, the image processing device 40 acquires from the map application 50 information that the density of people in the area where the image processing device 40 is installed is high (S43). Then, the image processing device 40 makes an access request to the cloud server 20 and transmits "5 people" obtained from the reflection sensor 49a and "high density" obtained from the map application 50 (S44). As a result, the cloud server 20 selects authentication method 2 from authentication methods 1 to 3 based on the information of "five people" and the information of "high density" obtained from the image processing device 40 (S45). In other words, although the reflection sensor 49a detected five or more people, the map application 50 determined that the density was high, so it was determined that there was no need to increase the security level to authentication method 1, and authentication method 2 was selected. Then, cloud server 20 presents authentication method 2 to image processing device 40 (S46). As a result, user A is authenticated by the image processing device 40 using "ID / password / email notification" (S47). If the authentication is successful, user A obtains document X from cloud server 20 and prints document X (S48).
[0057] In the above, the number of people standing still around the image processing device 40 is used as information that affects the risk of theft of user authentication information of a legitimate user of the image processing device 40, but this is not limiting. The state of the people standing still around the image processing device 40, such as the direction of the people, may also be used as such information.
[0058] [Cloud server functional configuration] 8 is a block diagram showing an example of the functional configuration of cloud server 20 according to the present embodiment. As shown in the figure, cloud server 20 includes a receiving unit 31, a document data storage unit 32, a document data management unit 33, an authentication method information storage unit 34, an authentication method selection unit 35, a user authentication information storage unit 36, an authentication execution unit 37, and a transmission unit 38.
[0059] When a user uses the terminal device 10 to perform an operation to register document data in the cloud server 20, the receiving unit 31 receives a document registration request including a user ID, a document ID, and the document data from the terminal device 10.
[0060] Furthermore, when the user performs an operation to access the cloud server 20 in order to retrieve document data using the image processing device 40, the receiving unit 31 performs the following operation.
[0061] That is, in any of the first to fourth aspects, the receiving unit 31 receives from the image processing device 40 an access request including a user ID and a document ID, and information on the staying person detected by the reflection sensor 49a. Here, the information on stayers may be any information related to stayers. For example, the information on stayers may be the number of stayers or the status of the stayers. Furthermore, when the information on stayers is the status of the stayers, the status of the stayers may be, for example, the orientation of the stayers. In this embodiment, this processing by the receiving unit 31 is an example of acquiring stayer information related to stayers who have stopped near the device. Furthermore, in this embodiment, this processing by the receiving unit 31 is an example of acquiring the number of stayers as stayer information. Furthermore, in this embodiment, this processing by the receiving unit 31 is an example of acquiring the status of the stayers as stayer information. Furthermore, in this embodiment, this processing by the receiving unit 31 is an example of acquiring the orientation of the stayers as the status of the stayers.
[0062] Furthermore, particularly in the third and fourth aspects, the receiving unit 31 receives from the image processing device 40 information on people present in the vicinity of the image processing device 40 (hereinafter referred to as "present people") in addition to the access request and information on people staying nearby detected by the reflection sensor 49a. Here, the present people include people who are standing still near the image processing device 40, as well as passersby passing by the vicinity of the image processing device 40. In this embodiment, this processing by the receiving unit 31 is performed as an example of further obtaining present person information on people present in the vicinity of the device.
[0063] In the third aspect, the receiving unit 31 receives, from the image processing device 40, information on passersby in the vicinity of the image processing device 40 detected by the vibration sensor 49d as information on present persons, in addition to the access request and information on stayers detected by the reflection sensor 49a. In this embodiment, the reflection sensor 49a is used as an example of a first type of sensor, and the information on stayers detected by the reflection sensor 49a is used as an example of information on stayers detected by the first type of sensor. In addition, in this embodiment, the vibration sensor 49d is used as an example of a second type of sensor different from the first type, and the information on passersby detected by the vibration sensor 49d is used as an example of information on present persons detected by the second type of sensor.
[0064] In a fourth aspect, the receiving unit 31 receives from the image processing device 40, in addition to the access request and the information on the stayer detected by the reflection sensor 49a, the density of people around the image processing device 40 obtained from the map application 50 as information on the presenter. In this embodiment, the reflection sensor 49a is used as an example of a sensor, and the information on the stayer detected by the reflection sensor 49a is used as an example of the information on the stayer detected by the sensor. In this embodiment, the density obtained from the map application 50 is used as an example of the information on the presenter stored in advance in the device.
[0065] Furthermore, when a user performs an operation to authenticate using the image processing device 40, the receiving unit 31 receives from the image processing device 40 user authentication information that is selected by the authentication method selection unit 35 described later and entered in accordance with the authentication method presented by the image processing device 40.
[0066] When the user uses the terminal device 10 to perform an operation to register document data in the cloud server 20, the document data storage unit 32 stores the document data included in the document registration request received by the receiving unit 31.
[0067] When a user uses terminal device 10 to perform an operation to register document data in cloud server 20, document data management unit 33 writes the document data included in the document registration request received by receiving unit 31 into document data storage unit 32. At that time, document data management unit 33 manages the document data written to document data storage unit 32 by linking the user ID and document ID included in the document registration request received by receiving unit 31.
[0068] In addition, when a user performs an authentication operation to retrieve document data using the image processing device 40, if the authentication is successful, the document data management unit 33 reads the document data from the document data storage unit 32 based on the document ID linked to the user ID.
[0069] The authentication method information storage unit 34 stores, for each user, authentication method information that associates multiple authentication methods that may be used in user authentication with selection conditions for selecting each of the multiple authentication methods. For example, in the examples of Figures 4 and 5, the selection condition for authentication method 1 is that there are five or more stayers, the selection condition for authentication method 2 is that there are two to four stayers, and the selection condition for authentication method 3 is that there is one stayer. In the example of Figure 6, the selection condition for authentication method 1 is that there are five or more stayers and few passersby, the selection condition for authentication method 2 is that there are five or more stayers and many passersby, and the selection condition for authentication method 3 is that there is one stayer and many passersby. Furthermore, in the example of Figure 7, the selection condition for authentication method 1 is that there are five or more stayers and a low density, the selection condition for authentication method 2 is that there are five or more stayers and a high density, and the selection condition for authentication method 3 is that there is one stayer and a high density. In particular, in the second aspect, the authentication method information storage unit 34 also stores information indicating which authentication method is the default authentication method. In this embodiment, the multiple authentication methods stored in the authentication method information storage unit 34 are used as an example of multiple authentication methods predetermined for the user.
[0070] When a user accesses the cloud server 20 to retrieve document data using the image processing device 40, the authentication method selection unit 35 reads, from the authentication method information storage unit 34, authentication method information for the user ID included in the access request received by the receiving unit 31. Then, the authentication method selection unit 35 performs the following operation.
[0071] That is, in any of the first to fourth aspects, the authentication method selection unit 35 selects an authentication method to be used by the image processing device 40 from the authentication method information read from the authentication method information storage unit 34, based on the stayer information received by the receiving unit 31. Furthermore, particularly in the second aspect, the authentication method selection unit 35 determines whether the selected authentication method is the default authentication method. In this embodiment, this processing by the authentication method selection unit 35 is performed as an example of selecting a specific authentication method to be used by the device when authenticating a user from among multiple authentication methods in accordance with the stayer information. Furthermore, in this embodiment, when the stayer information about a stayer who is standing still near the device is first information, the authentication method selection unit 35 selects a first authentication method from among multiple authentication methods as the specific authentication method to be used by the device when authenticating a user, and when the stayer information is second information, the authentication method selection unit 35 performs this processing as an example of selecting a second authentication method from among multiple authentication methods as the specific authentication method.
[0072] Here, the information about the stayer may be any information related to the stayer. For example, suppose the information about staying persons is the number of staying persons. In this case, the authentication method selection unit 35 selects a certain authentication method if the number of staying persons is a certain number, and selects another authentication method with a higher security level than the first authentication method if the number of staying persons is another number greater than the first number. In this embodiment, this processing by the authentication method selection unit 35 is an example of selecting a first authentication method as the specific authentication method when the number of staying persons is a first number, and selecting a second authentication method with a higher security level than the first authentication method as the specific authentication method when the number of staying persons is a second number greater than the first number.
[0073] Furthermore, it is assumed that the information about the stayer is the state of the stayer. In this case, the authentication method selection unit 35 selects a certain authentication method if the state of the stayer is a certain state, and selects another authentication method with a higher security level than the certain authentication method if the state of the stayer is another state in which the threat to authentication is higher than the certain state. Here, "high threat to authentication" means that the state of the stayer is such that there is a high risk that the user authentication information of the user currently operating the device will be stolen. In this embodiment, this processing by the authentication method selection unit 35 is an example of selecting a first authentication method as the specific authentication method when the state of the stayer is a first state, and selecting a second authentication method with a higher security level than the first authentication method as the specific authentication method when the state of the stayer is a second state in which the threat to authentication is higher than the first state.
[0074] Furthermore, when the information about the staying person is the state of the staying person, the state of the staying person is assumed to be the orientation of the staying person. In this case, the authentication method selection unit 35 selects a certain authentication method if the staying person is not facing the image processing device 40, and selects another authentication method with a higher security level than the authentication method if the staying person is facing the image processing device 40. In this embodiment, the processing of the authentication method selection unit 35 is an example of selecting a first authentication method when the state of the staying person, which is the orientation of the staying person, is a state where the staying person is not facing the device, and selecting a second authentication method with a higher security level than the first authentication method when the state of the staying person, which is the orientation of the staying person, is a state where the staying person is facing the device.
[0075] In particular, in the third and fourth aspects, the authentication method selection unit 35 selects an authentication method to be used in the image processing device 40 from the authentication method information read from the authentication method information storage unit 34, based on the information on presenters received by the receiving unit 31 in addition to the information on presenters received by the receiving unit 31. In this embodiment, the processing of the authentication method selection unit 35 is performed as an example of selecting a specific authentication method from a plurality of authentication methods further depending on the information on presenters.
[0076] In the third aspect, the authentication method selection unit 35 selects the authentication method to be used by the image processing device 40 based on information about passersby around the image processing device 40 received by the receiving unit 31 as information about presenters, in addition to information about presenters received by the receiving unit 31. As described above, the information about presenters is information detected by the reflection sensor 49a, and the information about passersby is information detected by the vibration sensor 49d. In this embodiment, the reflection sensor 49a is used as an example of a first type of sensor, and the information about presenters detected by the reflection sensor 49a is used as an example of information about presenters detected by the first type of sensor. In addition, in this embodiment, the vibration sensor 49d is used as an example of a second type of sensor different from the first type, and the information about passersby detected by the vibration sensor 49d is used as an example of information about presenters detected by the second type of sensor.
[0077] In a fourth aspect, the authentication method selection unit 35 selects an authentication method to be used by the image processing device 40 based on the density of people around the image processing device 40 received by the receiving unit 31 as information on present persons, in addition to the information on stayers received by the receiving unit 31. Here, as described above, the information on stayers is information detected by the reflection sensor 49a, and the density is information obtained from the map application 50. In this embodiment, the reflection sensor 49a is used as an example of a sensor, and the information on stayers detected by the reflection sensor 49a is used as an example of information on stayers detected by the sensor. In addition, in this embodiment, the density obtained from the map application 50 is used as an example of information stored in advance in the device.
[0078] The user authentication information storage unit 36 stores, for each user, user authentication information used to authenticate the user. For example, in the examples of Figures 4 to 7, the user authentication information is a password, an email address, and a fingerprint. However, the user authentication information is not limited to these, and other information may also be used.
[0079] When a user performs an operation to be authenticated using the image processing device 40, the authentication execution unit 37 performs authentication of the user by determining whether or not the user authentication information received by the receiving unit 31 is stored for the user ID received by the receiving unit 31.
[0080] When a user performs an operation to access the cloud server 20 to retrieve document data using the image processing device 40, the transmission unit 38 transmits the authentication method selected by the authentication method selection unit 35 to the image processing device 40. However, in the second mode, if the authentication method selected by the authentication method selection unit 35 is not the default authentication method, the transmission unit 38 transmits an instruction to change from the default authentication method to the selected authentication method to the image processing device 40. Furthermore, if the authentication method selected by the authentication method selection unit 35 is the default authentication method, the transmission unit 38 transmits an instruction to maintain the default authentication method to the image processing device 40.
[0081] In addition, when a user performs an authentication operation to retrieve document data using the image processing device 40, if the authentication execution unit 37 successfully authenticates the user, the transmission unit 38 transmits the document data read by the document data management unit 33 to the image processing device 40. Furthermore, when a user performs an authentication operation to retrieve document data using the image processing device 40, if the authentication of the user by the authentication execution unit 37 fails, the transmission unit 38 transmits a message to that effect to the image processing device 40.
[0082] In the present embodiment, the cloud server 20 has all of the main functions of the image processing system 1, but this is not limiting. The cloud server 20 may have some of the main functions of the image processing system 1, and the image processing device 40 may have the remaining part of the main functions of the image processing system 1. For example, the image processing device 40 may have a user authentication information storage unit 36 and an authentication execution unit 37, and user authentication after receiving the authentication method from the cloud server 20 may be performed in the image processing device 40.
[0083] [Image processing system operation] (First aspect) 9 is a sequence diagram showing an example of operation of the image processing system 1 of the first aspect. Prior to this example of operation, a user uses the terminal device 10 to create document data and transmits a document registration request including a user ID, a document ID, and the document data to the cloud server 20. In response to this, the receiving unit 31 of the cloud server 20 receives the document registration request. Then, the document data management unit 33 stores the document data included in this document registration request in the document data storage unit 32, and associates and holds the user ID and document ID also included in this document registration request.
[0084] Thereafter, as shown in the figure, the image processing device 40 determines whether a user has approached (step 411). For example, the image processing device 40 may determine whether a user has approached based on whether the operation panel 45 has been pressed. Note that the user here includes not only the user who registered the document data, but also other users who have approached the image processing device 40 to operate it.
[0085] If it is determined in step 411 that the user is not approaching, the image processing device 40 ends the process. On the other hand, if it is determined in step 411 that a user has approached, image processing device 40 activates reflection sensor 49a (step 412). Then, image processing device 40 acquires the number of staying people detected by reflection sensor 49a (step 413). Now, suppose that the user uses image processing device 40 to log in to cloud server 20 and perform an operation to select document data. Then, image processing device 40 transmits to cloud server 20 an access request to cloud server 20 including the user ID and document ID acquired by this operation, and the number of staying people acquired in step 413 (step 414).
[0086] As a result, in the cloud server 20, the receiving unit 31 receives the access request and the number of staying users from the image processing device 40 (step 311). Then, the authentication method selection unit 35 reads out authentication method information for the user ID included in the access request received in step 311 from the authentication method information storage unit 34 (step 312). Then, the authentication method selection unit 35 selects an authentication method to be used for authenticating the user in the image processing device 40 from the authentication method information read out in step 312, based on the number of users received in step 311 (step 313).
[0087] Thereafter, the transmitting unit 38 transmits an instruction to present the authentication method selected in step 313 to the image processing device 40 (step 314).
[0088] As a result, the image processing device 40 receives an instruction to present the authentication method from the cloud server 20 (step 415). Then, based on the instruction to present received in step 415, the image processing device 40 presents the authentication method selected in step 313 on, for example, the operation panel 45 (step 416).
[0089] Thereafter, the user performs multi-factor authentication using the authentication method presented in step 416. Then, the image processing device 40 transmits an authentication request including the user authentication information to the cloud server 20.
[0090] As a result, in the cloud server 20, the receiving unit 31 receives the authentication request. Next, the authentication executing unit 37 executes user authentication by determining whether or not a combination of the user ID included in the access request received in step 414 and the user authentication information included in this authentication request is stored in the user authentication information storage unit 36. As a result, if the user authentication fails, the transmitting unit 38 transmits a message to that effect to the image processing device 40. On the other hand, if the user authentication is successful, the document data managing unit 33 reads document data from the document data storage unit 32 based on the document ID linked to the user ID, and the transmitting unit 38 transmits this document data to the image processing device 40.
[0091] As a result, the image processing device 40 receives the document data from the cloud server 20 and prints the document data.
[0092] (Second aspect) 10 is a sequence diagram showing an example of the operation of the second aspect of the image processing system 1. The operation for registering document data that is performed prior to this example of the operation is the same as that described in the first aspect, and therefore a description thereof will be omitted.
[0093] Thereafter, as shown in the figure, the image processing device 40 determines whether a user has approached (step 421). For example, the image processing device 40 may determine whether a user has approached based on whether the operation panel 45 has been pressed. Note that the user here includes not only the user who registered the document data, but also other users who have approached the image processing device 40 to operate it.
[0094] If it is determined in step 421 that the user is not approaching, the image processing device 40 ends the process. On the other hand, if it is determined in step 421 that a user has approached, image processing device 40 activates reflection sensor 49a (step 422). Then, image processing device 40 acquires the number of people staying detected by reflection sensor 49a (step 423). Now, suppose that the user uses image processing device 40 to log in to cloud server 20 and perform an operation to select document data. Then, image processing device 40 transmits to cloud server 20 an access request to cloud server 20 including the user ID and document ID acquired by this operation, and the number of people staying acquired in step 423 (step 424).
[0095] As a result, in the cloud server 20, the receiving unit 31 receives the access request and the number of staying users from the image processing device 40 (step 321). Then, the authentication method selection unit 35 reads out authentication method information for the user ID included in the access request received in step 321 from the authentication method information storage unit 34 (step 322). Then, the authentication method selection unit 35 selects an authentication method to be used for authenticating the user in the image processing device 40 from the authentication method information read out in step 322, based on the number of users received in step 321 (step 323). Furthermore, the authentication method selection unit 35 refers to the authentication method information read out in step 322 and checks whether the authentication method selected in step 323 is the default authentication method (step 324).
[0096] Thereafter, the transmitting unit 38 transmits an instruction to change or maintain the authentication method depending on whether the authentication method selected in step 323 is the default authentication method (step 325). Specifically, if it is determined that the authentication method selected in step 323 is not the default authentication method, the transmitting unit 38 transmits an instruction to change the authentication method from the default authentication method to the selected authentication method to the image processing device 40. On the other hand, if it is determined that the authentication method selected in step 323 is the default authentication method, the transmitting unit 38 transmits an instruction to maintain the default authentication method to the image processing device 40.
[0097] As a result, the image processing device 40 receives an instruction to change or maintain the authentication method from the cloud server 20 (step 425). Then, the image processing device 40 determines whether or not an instruction to change the authentication method has been received in step 425 (step 426). Assume that an instruction to change the authentication method is received in step 426. In this case, image processing device 40 changes the default authentication method to the authentication method selected in step 323, and displays the selected authentication method on, for example, operation panel 45 (step 427). On the other hand, suppose that an instruction to change the authentication method is not received in step 426. In other words, suppose that an instruction to maintain the authentication method is received in step 426. In this case, image processing device 40 does not change the default authentication method to the authentication method selected in step 323, and presents the default authentication method on, for example, operation panel 45 (step 428).
[0098] The subsequent operation for printing the document data is the same as that described in the first embodiment, and therefore a description thereof will be omitted.
[0099] (Third aspect) 11 is a sequence diagram showing an example of the operation of the third embodiment of the image processing system 1. The operation for registering document data that is performed prior to this example of operation is the same as that described in the first embodiment, and therefore a description thereof will be omitted.
[0100] Thereafter, as shown in the figure, the image processing device 40 determines whether a user has approached (step 431). For example, the image processing device 40 may determine whether a user has approached based on whether the operation panel 45 has been pressed. Note that the user here includes not only the user who registered the document data, but also other users who have approached the image processing device 40 to operate it.
[0101] If it is determined in step 431 that the user is not approaching, the image processing device 40 ends the process. On the other hand, if it is determined in step 431 that a user has approached, the image processing device 40 activates the reflection sensor 49a and the vibration sensor 49d (step 432). Then, the image processing device 40 acquires the number of people staying there detected by the reflection sensor 49a (step 433) and the number of people passing by detected by the vibration sensor 49d (step 434). Now, suppose that the user logs in to the cloud server 20 using the image processing device 40 and performs an operation to select document data. Then, the image processing device 40 transmits to the cloud server 20 an access request to the cloud server 20 including the user ID and document ID obtained by this operation, the number of people staying there acquired in step 433, and the number of people passing by acquired in step 434 (step 435).
[0102] As a result, in the cloud server 20, the receiving unit 31 receives the access request, the number of staying people, and the number of passersby from the image processing device 40 (step 331). Then, the authentication method selection unit 35 reads out authentication method information for the user ID included in the access request received in step 331 from the authentication method information storage unit 34 (step 332). Then, the authentication method selection unit 35 selects an authentication method to be used for authenticating the user in the image processing device 40 from the authentication method information read out in step 332, based on the number of stayers and the number of passersby received in step 331 (step 333).
[0103] Thereafter, the transmitting unit 38 transmits an instruction to present the authentication method selected in step 333 to the image processing device 40 (step 334).
[0104] As a result, the image processing device 40 receives an instruction to present the authentication method from the cloud server 20 (step 436). Then, based on the instruction to present received in step 436, the image processing device 40 presents the authentication method selected in step 333 on, for example, the operation panel 45 (step 437).
[0105] The subsequent operation for printing the document data is the same as that described in the first embodiment, and therefore a description thereof will be omitted.
[0106] (Fourth aspect) 12 is a sequence diagram showing an example of the operation of the fourth embodiment of the image processing system 1. The operation for registering document data that is performed prior to this example of operation is the same as that described in the first embodiment, and therefore a description thereof will be omitted.
[0107] Thereafter, as shown in the figure, the image processing device 40 determines whether a user has approached (step 441). For example, the image processing device 40 may determine whether a user has approached based on whether the operation panel 45 has been pressed. Note that the user here includes not only the user who registered the document data, but also other users who have approached the image processing device 40 to operate it.
[0108] If it is determined in step 441 that the user is not approaching, the image processing device 40 ends the process. On the other hand, if it is determined in step 441 that a user has approached, the image processing device 40 activates the reflection sensor 49a (step 442). Then, the image processing device 40 acquires the number of people detected by the reflection sensor 49a (step 443) and acquires the density from the map application 50 (step 444). Now, suppose that the user logs in to the cloud server 20 using the image processing device 40 and performs an operation to select document data. Then, the image processing device 40 transmits to the cloud server 20 an access request to the cloud server 20 including the user ID and document ID obtained by this operation, the number of people acquired in step 443, and the density acquired in step 444 (step 445).
[0109] As a result, in the cloud server 20, the receiving unit 31 receives the access request, the number of people staying, and the density from the image processing device 40 (step 341). Then, the authentication method selection unit 35 reads out authentication method information for the user ID included in the access request received in step 341 from the authentication method information storage unit 34 (step 342). Then, the authentication method selection unit 35 selects an authentication method to be used for authenticating the user in the image processing device 40 from the authentication method information read out in step 342, based on the number of users and the congestion level received in step 341 (step 343).
[0110] Thereafter, the transmitting unit 38 transmits an instruction to present the authentication method selected in step 343 to the image processing device 40 (step 344).
[0111] As a result, the image processing device 40 receives an instruction to present the authentication method from the cloud server 20 (step 446). Then, based on the instruction to present received in step 446, the image processing device 40 presents the authentication method selected in step 343 on, for example, the operation panel 45 (step 447).
[0112] The subsequent operation for printing the document data is the same as that described in the first embodiment, and therefore a description thereof will be omitted.
[0113] [Processor] In this embodiment, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.). Furthermore, the operations of the processor in this embodiment may not only be performed by one processor, but may also be performed by multiple processors located at physically separate locations working together. Furthermore, the order of the operations of the processor is not limited to the order described in this embodiment, and may be changed.
[0114] [program] The processes performed by cloud server 20 in this embodiment are prepared as programs such as application software, for example. In this case, the program that realizes this embodiment can be seen as a program that enables a computer to obtain stayer information about stayers who are standing still near the device, and to select a specific authentication method from multiple authentication methods that the device will use to authenticate the user, depending on the stayer information. The program for realizing this embodiment can be provided not only by communication means but also by being stored on a recording medium such as a CD-ROM.
[0115] [Note] (((1))) one or more processors; the one or more processors: Acquire information about people standing still around the device, selecting a specific authentication method to be used by the device when authenticating a user from among a plurality of authentication methods according to the stayer information; Information processing system. (((2))) The information processing system according to (((1))), wherein the plurality of authentication methods are predetermined for the user. (((3))) the one or more processors: The number of the staying people is acquired as the staying person information, An information processing system described in (((1))) or (((2))), wherein when the number of stayers is a first number, a first authentication method is selected as the specific authentication method, and when the number of stayers is a second number greater than the first number, a second authentication method having a higher security level than the first authentication method is selected as the specific authentication method. (((4))) the one or more processors: As the staying person information, the status of the staying person is acquired; An information processing system described in any of (((1))) to (((3))), wherein when the state of the stayer is a first state, a first authentication method is selected as the specific authentication method, and when the state of the stayer is a second state which poses a higher threat to authentication than the first state, a second authentication method which has a higher security level than the first authentication method is selected as the specific authentication method. (((5))) the state of the person staying is the orientation of the person staying, the first state is a state in which the person is not facing the device, The information processing system according to (((4))), wherein the second state is a state in which the person is facing the device. (((6))) the one or more processors: Further acquiring presence information regarding presences present in the vicinity of the device; The information processing system according to any one of ((1))) to ((5))), further selecting the specific authentication method from among the plurality of authentication methods according to the entity information. (((7))) the stayer information is information detected by a first type of sensor, The information processing system according to (((6))), wherein the person information is information detected by a second type of sensor different from the first type. (((8))) the stayer information is information detected by a sensor, The information processing system according to (((6))), wherein the entity information is information stored in advance for the device. (((9))) one or more processors; the one or more processors: selecting a first authentication method from among a plurality of authentication methods as a specific authentication method to be used by the device when authenticating a user, when stayer information regarding a stayer who is standing still near the device is first information; If the stayer information is second information, select a second authentication method as the specific authentication method from among a plurality of authentication methods. Information processing system. (((10))) On the computer, A function for acquiring information about people standing still around the device; a function of selecting a specific authentication method to be used when the device authenticates a user from among a plurality of authentication methods according to the stayer information; A program to achieve this.
[0116] According to the invention (((1))), the device can authenticate the user using an appropriate authentication method according to information on a person standing still around the device. According to the invention (((2))), an appropriate authentication method according to information on a person standing around the device can be selected from a plurality of authentication methods predetermined for the user. According to the invention (((3))), the device can authenticate users using an appropriate authentication method according to the number of people standing around the device. According to the invention (((4))), the device can authenticate the user using an appropriate authentication method according to the state of the person standing still around the device. According to the invention (((5))), the device can authenticate the user using an appropriate authentication method according to the orientation of the person standing still around the device. According to the invention of (((6))), it is possible to reduce the possibility that an inappropriate authentication method will be selected due to the erroneous recognition of a person standing still near the device. According to the invention of (((7))), even if information is not stored in advance, it is possible to reduce the possibility that an inappropriate authentication method will be selected due to the erroneous recognition of a person standing still near the device. According to the invention of (((8))), it is possible to reduce the possibility of selecting an inappropriate authentication method due to the false recognition of a person standing still near the device, without using two different types of sensors. According to the invention (((9))), the device can authenticate the user using an appropriate authentication method according to information on the person standing still around the device. According to the invention (((10))), the device can authenticate the user using an appropriate authentication method according to information on the person standing still around the device. [Explanation of symbols]
[0117] 1...image processing system, 10...terminal device, 20...cloud server, 31...receiving unit, 32...document data storage unit, 33...document data management unit, 34...authentication method information storage unit, 35...authentication method selection unit, 36...user authentication information storage unit, 37...authentication execution unit, 38...transmission unit, 40...image processing device
Claims
1. one or more processors; the one or more processors: Acquire information about people standing still around the device, selecting a specific authentication method to be used by the device when authenticating a user from among a plurality of authentication methods according to the stayer information; Information processing system.
2. The information processing system according to claim 1 , wherein the plurality of authentication methods are predetermined for the user.
3. the one or more processors: The number of the staying people is acquired as the staying person information, 2. The information processing system of claim 1, wherein when the number of stayers is a first number, a first authentication method is selected as the specific authentication method, and when the number of stayers is a second number greater than the first number, a second authentication method having a higher security level than the first authentication method is selected as the specific authentication method.
4. the one or more processors: As the staying person information, the status of the staying person is acquired; 2. The information processing system of claim 1, wherein when the state of the resident is a first state, a first authentication method is selected as the specific authentication method, and when the state of the resident is a second state which poses a higher threat to authentication than the first state, a second authentication method which has a higher security level than the first authentication method is selected as the specific authentication method.
5. the state of the person staying is the orientation of the person staying, the first state is a state in which the person is not facing the device, The information processing system according to claim 4 , wherein the second state is a state in which the person is facing the device.
6. the one or more processors: Further acquiring presence information regarding presences present in the vicinity of the device; 2. The information processing system according to claim 1, wherein the specific authentication method is selected from the plurality of authentication methods further depending on the person information.
7. the stayer information is information detected by a first type of sensor, The information processing system according to claim 6 , wherein the person information is information detected by a second type of sensor different from the first type.
8. the stayer information is information detected by a sensor, 7. The information processing system according to claim 6, wherein the person information is information stored in advance for the device.
9. one or more processors; the one or more processors: selecting a first authentication method from among a plurality of authentication methods as a specific authentication method to be used by the device when authenticating a user, when stayer information relating to a stayer who is standing still around the device is first information; selecting a second authentication method as the specific authentication method from among a plurality of authentication methods when the stayer information is second information; Information processing system.
10. On the computer, A function for acquiring information about people standing still around the device; a function of selecting a specific authentication method to be used when the device authenticates a user from among a plurality of authentication methods according to the stayer information; A program to achieve this.
Citation Information
Patent Citations
Image processor and image processing method
JP2004102708A
Authentication method, authentication device, and authentication system
JP2019160058A