Information processing apparatus, image forming apparatus, information processing method, and program

A cost-effective multi-factor authentication system for MFPs uses short-range wireless communication and card authentication with presence monitoring to enhance security by resetting authentication or operation screens when users move away, addressing the economic constraints of camera-based face authentication.

JP2025163963APending Publication Date: 2025-10-30RICOH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024067641
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-18
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing multifunction peripherals (MFPs) require additional costs for face authentication due to the need for a camera, which is not economically viable.

Method used

Implement a system that uses short-range wireless communication and card authentication to perform multi-factor authentication, where user presence is monitored to reset authentication or operation screens if the user moves beyond a specified range, enhancing security without additional costs.

Benefits of technology

Improves security strength in MFPs by preventing unauthorized use without incurring additional costs through the use of existing hardware for authentication and presence monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025163963000001_ABST
    Figure 2025163963000001_ABST
Patent Text Reader

Abstract

To strengthen security without requiring additional cost for user authentication.SOLUTION: An information processing apparatus includes: a storage unit which stores user information including identification information identifying a user who uses a predetermined system; a monitoring unit which monitors the presence of the user using the predetermined system; and an authentication processing unit which authenticates the user based on the user information. The authentication processing unit is configured to reset the authentication information of the user or an operation screen of the predetermined system when the monitor unit detects the user departing from the predetermined system exceeding a predetermined range after the user authentication before the user completes using the predetermined system.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing apparatus, an image forming apparatus, an information processing method, and a program. [Background technology]

[0002] In today's highly information-oriented society, there is an ever-increasing demand for enhanced security. For example, high security is required for systems that are expected to be used by many users, such as multifunction peripherals (MFPs), which are multifunction peripherals with multiple functions. Multifactor authentication is known in which, when a user of an MFP (hereinafter referred to as an "MFP user") logs in, a primary authentication step is performed by touching or swiping an integrated circuit (IC) card, followed by a secondary authentication step by entering a password on the screen of the MFP operation unit. In multifactor authentication, a technology has been proposed that adds facial recognition to prevent impersonation by a malicious third party who knows the password for secondary authentication after the primary authentication step is completed by the MFP user (see, for example, Patent Document 1). Summary of the Invention [Problem to be solved by the invention]

[0003] The technology disclosed in Patent Document 1 requires a camera for face authentication, which poses a problem of increased costs for introducing additional authentication.

[0004] An embodiment of the present invention has been made in consideration of the above problems, and one of its objects is to improve security strength without incurring additional costs for user authentication. [Means for solving the problem]

[0005] An information processing device according to one embodiment of the present invention has a memory unit that stores user information including identification information that identifies a user using a specified system, a monitor unit that monitors the presence of the user using the specified system, and an authentication processing unit that authenticates the user based on the user information, and if the monitor unit detects that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system, the authentication processing unit resets the user's authentication information or the operation screen of the specified system. [Effects of the Invention]

[0006] The security strength can be improved without incurring additional costs for user authentication. [Brief explanation of the drawings]

[0007] [Figure 1A] FIG. 1A is a diagram illustrating an example of an application scene of the information processing technology according to the embodiment. [Figure 1B] FIG. 1B is a functional block diagram of an information processing device that performs the processing of FIG. 1A. [Figure 1C] FIG. 1C is a flowchart showing the basic operation of the information processing device of FIG. 1B. [Figure 2] FIG. 2 is a block diagram showing an example of the hardware configuration of the image forming apparatus according to the first embodiment. [Figure 3] FIG. 3 is a block diagram showing an example of the software configuration of the image forming apparatus according to the first embodiment. [Figure 4] FIG. 4 is a functional block diagram of the image forming apparatus according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating an example of user information. [Figure 6] FIG. 6 is an example of a flowchart of the operation of the information processing device according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing a subroutine of step S101 (zero-order authentication) in FIG. [Figure 8]FIG. 8 is a diagram showing a subroutine of step S102 (primary authentication) in FIG. [Figure 9] FIG. 9 is a diagram showing an example of a display on the operation panel when the determination in step S103 of FIG. 6 is affirmative ("Yes"). [Figure 10] FIG. 10 is a diagram showing an example of a display on the operation panel when a negative determination ("No") is made in step S103 of FIG. [Figure 11] FIG. 11 is a diagram illustrating an example of a setting screen for zero-level authentication displayed by the information processing apparatus according to the second embodiment. [Figure 12] FIG. 12 is an example of a flowchart of the operation of the information processing device according to the second embodiment. [Figure 13] FIG. 13 is an example of a flowchart of the operation of the information processing device according to the third embodiment. [Figure 14] FIG. 14 is a diagram showing an example of a reset setting screen displayed by the information processing device. [Figure 15] FIG. 15 is an example of a flowchart of the operation of the information processing device according to the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings. In the following embodiments, an example in which information processing technology for improving security is applied to an image forming apparatus will be described, but the present invention is not limited to this example. For example, the information processing technology of the embodiment can also be applied to other systems, devices, or apparatuses that require user authentication, such as a data management system.

[0009] FIG. 1A illustrates an example of an application scenario of the information processing technology of the embodiment. First, a user 103 approaches the image forming apparatus 100 while carrying a card 102 that authorizes the use of the image forming apparatus 100, and user authentication is performed. The user 103 is authenticated by an information processing device incorporated in or connected to the image forming apparatus 100. The user authentication may include, for example, authentication by operating the card 102 and, if necessary, authentication of other factors. For example, if the user 103 carries a short-range wireless communication terminal 101, the user authentication may include automatic authentication using a short-range wireless communication function of the image forming apparatus 100 or the information processing device. Entering a password into a login screen displayed on the image forming apparatus 100 after user authentication by operating the card 102 may also be included in the user authentication. In this way, user authentication may be multi-factor authentication consisting of multiple factors. In the following embodiments, automatic authentication via short-range wireless communication may be referred to as zero-stage authentication, and authentication by user operation may be referred to as first-stage authentication. However, zero-stage authentication is not essential and may be omitted depending on the usage scenario. Authentication using card 102 is an example of primary authentication, and primary authentication may also be performed using biometric information such as a fingerprint or voiceprint. Card 102 and short-range wireless communication terminal 101 may be separate entities, or a short-range wireless communication function may be incorporated into card 102. Zero-level authentication using short-range wireless communication and user authentication using short-range wireless communication terminal 101 may be used synonymously. User authentication identifies user 103 who uses image forming apparatus 100. After user 103 is identified, a login screen or a menu screen may be displayed on the operation panel of image forming apparatus 100.

[0010] If user 103 moves beyond a predetermined range from image forming apparatus 100 after user authentication and before user 103 has completed using image forming apparatus 100, image forming apparatus 100 resets the authentication information of user 103 or the operation screen of image forming apparatus 100. Whether user 103 has moved beyond the predetermined range from image forming apparatus 100 is monitored by an information processing apparatus. For example, based on the strength of radio waves received by image forming apparatus 100 from short-range wireless communication terminal 101, the information processing apparatus determines that user 103 has moved beyond the predetermined range from image forming apparatus 100 when the radio wave strength becomes lower than a threshold. Alternatively, the information processing apparatus may calculate the distance between image forming apparatus 100 and user 103 based on location information transmitted from short-range wireless communication terminal 101, or may use a timer function of image forming apparatus 100 or the information processing apparatus to determine that user 103 has moved beyond the predetermined range if no operation is performed on image forming apparatus 100 within a predetermined time after user authentication.

[0011] The short-range wireless communication terminal 101 may be, for example, a portable information processing terminal such as a smartphone or a smart watch, or may be an RF tag incorporated in a card 102. The card 102 in this specification may be called an IC card.

[0012] When the user 103 carries the short-range wireless communication terminal 101, the user 103 is considered to carry the short-range wireless communication terminal 101 even when the user 103 moves away from the image forming apparatus 100 after user authentication.

[0013] As examples of when the user 103 leaves the image forming apparatus 100, there are three possible cases after the user 103 who uses the image forming apparatus 100 has been identified by primary authentication. (1) The state before entering the password on the login screen, (2) After entering the password on the login screen but before operating the menu screen, and (3) A state after input to the menu screen and before use of the image forming apparatus 100 is completed.

[0014] In the above states (1) to (3), the image forming apparatus 100 may be used by a malicious third party in the following ways.

[0015] (1): A third party who does not possess the card 102 required for primary authentication of the user 103 but knows the password of the user 103 can log in to the image forming device 100 and use the image forming device 100 by entering the password of the user 103 on the login screen.

[0016] (2) A third party who does not possess the card 102 required for primary authentication of the user 103 and does not know the password of the user 103 operates the menu screen after login without permission and uses the image forming apparatus 100.

[0017] (3) A third party who does not possess the card 102 required for primary authentication of the user 103 and does not know the password of the user 103 uses the image forming apparatus 100 while the image forming apparatus 100 is operating based on a user operation.

[0018] As shown in FIG. 1A, these unauthorized usage patterns can be suppressed by invalidating the primary authentication (first authentication) performed by user operation or resetting the operation screen when user 103 leaves the device beyond a predetermined range, thereby strengthening the security of image forming device 100.

[0019] Fig. 1B is a block diagram of information processing device 410 that performs the processing of Fig. 1A, and Fig. 1C is a flowchart of the basic operation executed by information processing device 410 of Fig. 1B. Information processing device 410 is mainly composed of a processor and a memory, and may be incorporated into image forming device 100 or may be connected to image forming device 100 via a network or the like.

[0020] As shown in FIG. 1B, the information processing device 410 that performs the processing of FIG. 1A includes a monitor unit 450 that monitors whether the user 103 has left the device beyond a predetermined range, an authentication processing unit 414 that performs user authentication based on user information including identification information that identifies the user 103, and a memory unit 415 that stores the user information.

[0021] As shown in FIG. 1C, the information processing device 410 of FIG. 1B performs primary authentication (first authentication) by user operation in step S11, and then performs authentication (second authentication) by password input in step S12. After the second authentication is completed, the information processing device 410 monitors whether the user who has completed the second authentication is within a predetermined range from the information processing device 410 in step S13. If the user is not within the predetermined range, the information processing device 410 resets the authentication information of the user (first authentication) or the operation screen of the information processing device 410. The above is an application example of the information processing technology of the embodiment.

[0022] Next, the configuration of the image forming apparatus 100 will be described.

[0023] <Configuration example of image forming device> (Hardware configuration) FIG. 2 is a block diagram showing an example of a hardware configuration of the image forming apparatus according to the embodiment.

[0024] Image forming apparatus 100 includes a main body 210 having an image forming engine that realizes various image forming functions such as a copy function, a scanner function, a fax (FAX) function, and a printer function, and an operation unit 220 that accepts user operations for each image forming engine and controller, etc. Here, accepting an operation by user 103 is a concept that includes accepting information (including signals indicating screen coordinate values, etc.) input in response to an operation by user 103.

[0025] (Main unit hardware configuration) As shown in FIG. 2, the main body 210 has a CPU (Central Processing Unit) 211, a ROM (Read Only Memory) 212, a RAM (Random Access Memory) 213, a storage 214, a communication I / F (Interface) 215, a connection I / F 216, an engine 217, and a system bus 218.

[0026] The CPU 211 performs overall control of the operation of the main body 210. The CPU 211 controls the operation of the entire main body 210 by executing programs stored in the ROM 212 or the storage 214, etc., using the RAM 213 as a work area. For example, the CPU 211 realizes various functions such as the copy function, scanner function, FAX function, and printer function described above.

[0027] The ROM 212 is a non-volatile memory that stores, for example, a basic input / output system (BIOS) that is executed when the main body 210 starts up, various settings, etc. The RAM 213 is a volatile memory that is used as a work area for the CPU 211, etc. The storage 214 is a non-volatile storage device that stores, for example, an operating system (OS), application programs, various data, etc. The storage 214 is configured, for example, by a hard disk drive (HDD) or a solid state drive (SSD).

[0028] The communication I / F 215 is a network interface that connects the main body 210 to a network 260 and communicates with external devices connected to the network 260. The connection I / F 216 is an interface that communicates with the operation unit 220 via a communication path 250.

[0029] The engine 217 is hardware that performs general-purpose information processing and processing other than communication in order to realize functions such as a copy function, a scanner function, a fax function, and a printer function. The engine 217 includes, for example, a scanner that scans and reads images of an original, a plotter that prints on sheet materials such as paper, and a fax unit that performs fax communication. Note that the engine 217 may also include specific options such as a finisher that sorts printed sheet materials or an ADF (Auto Document Feeder) that automatically feeds originals.

[0030] The system bus 218 is a transmission path that connects the above-mentioned components to each other and transmits address signals, data signals, various control signals, and the like.

[0031] (Hardware configuration of the control unit) As shown in FIG. 2, the operation unit 220 has a CPU 221, a ROM 222, a RAM 223, a flash memory 224, a communication I / F 225, an operation panel 226, a connection I / F 227, an external connection I / F 228, a short-range wireless communication device 229, a card reader 230, and a system bus 240.

[0032] The CPU 221 comprehensively controls the operation of the operation unit 220. The CPU 221 controls the operation of the entire operation unit 220 by executing programs stored in the ROM 222, the flash memory 224, or the like using the RAM 223 as a work area. For example, the CPU 221 realizes various functions such as displaying information (images) on the operation panel 226 in accordance with input received from the user 103.

[0033] The ROM 222 is a non-volatile memory that stores, for example, a BIOS that is executed when the operation unit 220 is started up, various settings, etc. The RAM 223 is a volatile memory that is used as a work area, etc. for the CPU 221. The flash memory 224 is a non-volatile storage device that stores, for example, an OS, application programs, various data, etc.

[0034] The communication I / F 225 is a network interface that connects the operation unit 220 to a network 260 and enables communication with external devices connected to the network 260 .

[0035] Operation panel 226 is a device with input and display functions that accepts various inputs in response to operations by user 103 and displays various information (e.g., information in response to the accepted operations, information indicating the operating status of image forming apparatus 100, setting information, etc.). Operation panel 226 is configured, for example, by a liquid crystal display (LCD) equipped with a touch panel function. Note that operation panel 226 is not limited to a liquid crystal display, and may be configured, for example, by an organic electroluminescence (EL) display device equipped with a touch panel function. Furthermore, operation panel 226 may be provided with an operation unit such as hardware keys or a display unit such as a lamp in addition to or instead of the touch panel function.

[0036] The connection I / F 227 is an interface for communicating with the main body 210 via the communication path 250. The external connection I / F 228 is an interface such as a USB (Universal Serial Bus) for connecting an external device.

[0037] The short-range wireless communication device 229 is a short-range wireless device for communicating with the short-range wireless communication terminal 101 within a predetermined range by short-range wireless communication. The short-range wireless communication device 229 measures the radio wave intensity from the short-range wireless communication terminal 101 to the short-range wireless communication device 229, and detects the short-range wireless communication terminal 101 whose radio wave intensity exceeds a predetermined threshold. Note that the short-range wireless communication device 229 may be a short-range wireless device that performs short-range wireless communication such as BLE (Bluetooth (registered trademark) Low Energy). Furthermore, the radio wave intensity may be expressed as a numerical value such as received signal strength indicator (RSSI).

[0038] The card reader 230 is a device for reading identification information from the card 102 by short-range wireless communication.

[0039] The system bus 240 is a transmission path that connects the above-mentioned components to each other and transmits address signals, data signals, various control signals, and the like.

[0040] (Software configuration) FIG. 3 is a block diagram showing an example of the software configuration of the image forming apparatus according to the embodiment.

[0041] 3, main body 210 of image forming apparatus 100 includes application layer 311, service layer 312, and OS layer 313. Application layer 311, service layer 312, and OS layer 313 are actually various software programs stored in ROM 212, storage 214, or the like. CPU 211 executes these software programs (programs) to provide various functions of main body 210.

[0042] The application layer 311 is application software (hereinafter, sometimes simply referred to as "application") for operating hardware resources to provide predetermined functions. Examples of applications include a copy application for providing a copy function, a scanner application for providing a scanner function, a fax application for providing a fax function, and a printer application for providing a printer function.

[0043] The service layer 312 is software that resides between the application layer 311 and the OS layer 313 and provides an interface for applications in the application layer 311 to use hardware resources of the main body 210. Specifically, the service layer 312 provides a function for accepting operation requests for hardware resources and arbitrating the operation requests. Examples of operation requests accepted by the service layer 312 include requests for scanning using a scanner and printing using a plotter. The interface function of the service layer 312 is provided not only to the application layer 311 of the main body 210 but also to the application layer 321 of the operation unit 220. The interface function of the WebAPI of the service layer 312 is provided by, for example, a WebAPI. That is, the application layer 321 of the operation unit 220 can also realize functions that use the hardware resources of the main body 210 (e.g., the engine 217) via the interface function of the WebAPI of the service layer 312 of the main body 210.

[0044] The OS layer 313 is basic software (operating system) for providing basic functions for controlling the hardware included in the main body 210. The service layer 312 converts requests for using hardware resources from various applications into commands that can be interpreted by the OS layer 313 and passes the commands to the OS layer 313. The OS layer 313 then executes the commands, causing the hardware resources to operate in accordance with the application requests.

[0045] 3, operation unit 220 of image forming apparatus 100 includes an application layer 321, a service layer 322, and an OS layer 323. The application layer 321, service layer 322, and OS layer 323 included in operation unit 220 also have the same hierarchical structure as those on main body 210. However, the functions provided by the applications on application layer 321 and the types of operation requests that service layer 322 can accept differ from those on main body 210.

[0046] The applications in application layer 321 may be software for operating hardware resources included in operation unit 220 to provide predetermined functions, but they mainly provide UI (User Interface) functions for operating and displaying functions included in main body 210. In addition, the applications in application layer 321 provide short-range wireless communication device 229 included in operation unit 220.

[0047] In the embodiment, in order to maintain functional independence, the software of OS layer 313 on the main body 210 side and the software of OS layer 323 on the operation unit 220 side are different from each other. In other words, main body 210 and operation unit 220 operate independently of each other using different operating systems. For example, it is possible to use Linux (registered trademark) as the software of OS layer 313 on the main body 210 side and Android (registered trademark) as the software of OS layer 323 on the operation unit 220 side.

[0048] As described above, in the image forming apparatus 100 of the embodiment, the main body 210 and the operation unit 220 operate on different operating systems. Therefore, communication between the main body 210 and the operation unit 220 is performed as communication between different devices, rather than as inter-process communication within a common device. This includes an operation (command communication) in which the operation unit 220 transmits information received by the operation unit 220 (contents of operation instructions from a user) to the main body 210, and an operation in which the main body 210 transmits information to the operation unit 220. Here, the operation unit 220 performs command communication with the main body 210, thereby enabling the use of functions of the main body 210. Furthermore, information transmitted from the main body 210 to the operation unit 220 includes, for example, the execution status of operations in the main body 210 and settings made on the main body 210 side. Furthermore, in the embodiment, power is supplied to the operation unit 220 from the main body 210 via the communication path 250. Therefore, power control of the operation unit 220 can be performed separately (independently) from power control of the main body 210.

[0049] (Functional configuration) FIG. 4 is a functional block diagram of the image forming apparatus according to the embodiment.

[0050] (Main unit functional configuration) As shown in FIG. 4, the main body 210 of the image forming apparatus 100 includes an authentication processing unit 401, a user information management unit 402, an image forming unit 403, a storage unit 404, and a communication unit 405.

[0051] The authentication processing unit 401 is a functional unit that controls the process of logging in to or logging out of the image forming apparatus 100. The authentication processing unit 401 is realized by, for example, a program that runs on the CPU 211 shown in FIG.

[0052] The user information management unit 402 is a functional unit that manages the user information 406 stored in the storage unit 404. The user information management unit 402 is realized, for example, by a program that runs on the CPU 211 shown in FIG.

[0053] Image forming unit 403 is a functional unit that executes various image forming functions (for example, a printer function, a copy function, a scanner function, a FAX function, etc.) provided in image forming apparatus 100. Image forming unit 403 is realized by, for example, engine 217 shown in FIG. 2 and a program that runs on CPU 211 shown in FIG. 2.

[0054] The storage unit 404 is a functional unit that stores various information such as user information 406 including information indicating pre-registered users of the image forming apparatus 100. The storage unit 404 is realized by, for example, programs that run on the CPU 211, RAM 213, and storage 214 shown in FIG.

[0055] The communication unit 405 is a functional unit that connects the main body 210 to the network 260 and communicates with external devices connected to the network 260. The communication unit 405 is realized by, for example, the CPU 211 shown in FIG. 2 and a program that runs on the communication I / F 215.

[0056] Note that the authentication processing unit 401, user information management unit 402, image forming unit 403, storage unit 404, and communication unit 405 of main body 210 shown in Fig. 4 are conceptual illustrations of functions, and are not limited to such configurations. For example, the multiple functional units illustrated as independent functional units in main body 210 shown in Fig. 4 may be configured as a single functional unit. On the other hand, the function of a single functional unit in main body 210 shown in Fig. 4 may be divided into multiple units and configured as multiple functional units.

[0057] Furthermore, the image forming unit 403 of the main body 210 may be realized by a hardware circuit such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application Specific Integrated Circuit) instead of a software program.

[0058] (Functional configuration of the operation section) As shown in FIG. 4, the operation unit 220 of the image forming apparatus 100 includes an information processing device 410 and a communication unit 416. The information processing device 410 includes a short-range wireless communication unit 412, a card detection unit 413, an authentication processing unit 414, and a storage unit 415. The authentication processing unit 414 includes a multi-factor authentication processing unit 411. The storage unit 415 includes user information 417. The information processing device 410 is implemented by the CPU 221, ROM 222, and RAM 223 shown in FIG. 2. In this example, the information processing device 410 is incorporated into the operation unit 220 of the image forming apparatus 100. However, the information processing device 410 may be external to the image forming apparatus 100 or may be connected to the image forming apparatus 100 via a network or the like. When the information processing device 410 is incorporated into the image forming apparatus 100 as shown in FIG. 4, the monitor unit 450 shown in FIG. 1B may be implemented by the short-range wireless communication unit 412.

[0059] The multi-factor authentication processing unit 411 is a functional unit that displays settings for executing multi-factor authentication and a screen for accepting login. The multi-factor authentication processing unit 411 is realized by, for example, the CPU 211 shown in FIG. 2 or a program executed by the CPU 211.

[0060] The short-range wireless communication unit 412 is a functional unit that detects radio waves of short-range wireless communication such as those of the short-range wireless communication terminal 101. The short-range wireless communication unit 412 is realized by, for example, the short-range wireless communication device 229 shown in FIG.

[0061] The card detection unit 413 detects information included in the card 102 possessed by the user 103, and notifies the detected card information to the multi-factor authentication processing unit 411. The card detection unit 413 is realized by, for example, the card reader 230 and the CPU 221 shown in FIG.

[0062] The authentication processing unit 414 including the multi-factor authentication processing unit 411 manages the user information 417 stored in the storage unit 415, and implements cooperation between the multi-factor authentication processing unit 411 and the authentication processing unit 401 of the main body 210. The authentication processing unit 414 is realized by, for example, the CPU 221 shown in FIG. 2 or a program executed by the CPU 221.

[0063] The storage unit 415 is a functional unit that stores the card linking information and the short-range wireless notification information as user information 417 of the operation unit 220 in addition to the user information 406 of the main body 210. The storage unit 415 is realized by, for example, the RAM 213 and the flash memory 224 shown in FIG. 2 and a program that runs on the CPU 211 shown in FIG. 2 .

[0064] The communication unit 416 is a functional unit that connects the operation unit 220 to the network 260 and communicates with external devices connected to the network 260. The communication unit 416 is realized by, for example, the communication I / F 225 shown in FIG. 2 and a program that runs on the CPU 211 shown in FIG. 2.

[0065] Note that the multi-factor authentication processing unit 411, short-range wireless communication unit 412, card detection unit 413, authentication processing unit 414, storage unit 415, and communication unit 416 of the operation unit 220 shown in Fig. 4 are conceptual illustrations of functions, and are not limited to such configurations. For example, the multiple function units illustrated as independent function units in the operation unit 220 shown in Fig. 4 may be configured as a single function unit. On the other hand, the function of a single function unit in the operation unit 220 shown in Fig. 4 may be divided into multiple parts and configured as multiple function units.

[0066] The authentication processing unit 414 including the multi-factor authentication processing unit 411 of the operation unit 220, the short-range wireless communication unit 412, and some or all of the card detection unit 413 may be realized by a hardware circuit such as an FPGA or ASIC, rather than a software program.

[0067] At least a part of the functions of the operation unit 220 may be executed within the main body 210 , and conversely, at least a part of the functions of the main body 210 may be executed within the operation unit 220 .

[0068] (User information configuration) FIG. 5 is a diagram illustrating an example of user information according to the embodiment.

[0069] User information 417 shown in Fig. 5 is an example of pre-registered user information. In the example of Fig. 5, the user information 417 includes information such as a "registration number," a "user name," a "login user name," a "login password," a "card ID (identity)," and a "wireless ID."

[0070] The "registration number" is, for example, a serial number assigned when the information of each user is registered in the user information 417, or an identification number unique to each user's data, and is an example of identification information unique to each user (identification information indicating the user). The "registration number" may also be identification information indicating the user, such as an employee ID.

[0071] The "user name" is the name of the user. The "login user name" and the "login password" are examples of authentication information for the user to log in to the image forming apparatus 100.

[0072] The "card ID" is identification information of the card 102 possessed by each user, and the "wireless ID" is identification information of the short-range wireless communication terminal 101 possessed by each user.

[0073] In addition to the above, the user information 417 may also include "email address," "fax number," and "authority information (to use the image forming apparatus 100)."

[0074] In the user information 417 shown in FIG. 5, for example, a user with registration number "0001" has a username "A," a login username "a," a login password "aaa," a card ID "1234567890," and a wireless ID "qwertyuiop," and each piece of information is stored in association with each other.

[0075] Furthermore, although the user information 417 shown in FIG. 5 is in table format, it is not limited to this and may be in any format as long as the values ​​of each field can be managed in association with each other.

[0076] <Authentication process flow> Next, the flow of authentication processing executed by information processing device 410 will be described.

[0077] First Embodiment 6 is a flowchart showing the operation of the first embodiment of the information processing device 410. In the first embodiment, the information processing device 410 performs multi-factor authentication that combines zero-level authentication, primary authentication, and authentication by password input.

[0078] First, the authentication processing unit 414 executes the zero-order authentication in step S101 and the primary authentication in step S102 in parallel or sequentially.

[0079] 7 is a flowchart showing the subroutine of the zero-order authentication in step S101. For the sake of explanation, a case where BLE is used for short-range wireless communication will be described here. Also, as a basic communication flow of BLE, a case where the image forming apparatus 100 is a central that is a parent station, and the short-range wireless communication terminal 101 is a peripheral that is a child station will be described. The device that serves as the peripheral in BLE communication is not limited to the short-range wireless communication terminal 101, and may be, for example, a wireless tag such as an RFID (Radio Frequency ID).

[0080] In step S201, the short-range wireless communication unit 412 in the operation unit 220 of the image forming device 100 polls using basic BLE communication to determine whether the short-range wireless communication unit 412 has detected the short-range wireless communication terminal 101 in order to detect the short-range wireless communication terminal 101.

[0081] Specifically, image forming apparatus 100, which is a central, waits for a connection from short-range wireless communication terminal 101, which is a peripheral (advertises). If short-range wireless communication unit 412 detects short-range wireless communication terminal 101 (step S201: Yes), the process proceeds to step S202. On the other hand, if short-range wireless communication unit 412 does not detect short-range wireless communication terminal 101 (step S201: No), the process performs detection again.

[0082] In step S202, the short-range wireless communication unit 412 outputs the wireless ID of the detected short-range wireless communication terminal 101 to the authentication processing unit 414, and performs authentication processing of the short-range wireless communication terminal 101.

[0083] Specifically, the authentication processing unit 414 acquires the user information 417 and verifies whether the user associated with the wireless ID of the detected short-range wireless communication terminal 101 is included in the user information 417. If the authentication processing unit 414 can verify that the user associated with the wireless ID of the detected short-range wireless communication terminal 101 is included in the user information 417, the authentication processing unit 414 permits authentication of the detected short-range wireless communication terminal 101. On the other hand, if the authentication processing unit 414 cannot verify that the user associated with the wireless ID of the detected short-range wireless communication terminal 101 is included in the user information 417, the authentication processing unit 414 does not permit authentication of the detected short-range wireless communication terminal 101.

[0084] In step S203, if the authentication of the detected short-range wireless communication terminal 101 is permitted (if there is user information linked to the wireless ID) (step S203: Yes) as a result of authentication by the authentication processing unit 414, the process proceeds to step S204. On the other hand, if the authentication of the detected short-range wireless communication terminal 101 is not permitted (if there is user information linked to the wireless ID) (step S203: No), the process returns to step S201 and repeats the same process.

[0085] In step S204, the authentication processing unit 414 stores the user information associated with the wireless ID of the detected short-range wireless communication terminal 101.

[0086] Through the operations of steps S201 to S204 described above, authentication processing by short-distance wireless communication is executed, which is zero-order authentication that does not require any operation by the user.

[0087] FIG. 8 is a flowchart showing the subroutine for primary authentication in step S102.

[0088] In step S301, card detection unit 413 in operation unit 220 of image forming apparatus 100 polls whether card 102 has touched or swiped card reader 230 in order to detect card 102. If card detection unit 413 detects card 102 (step S301: Yes), the process proceeds to step S302, and if card detection unit 413 does not detect card 102 (step S301: No), the process performs detection again.

[0089] In step S302, the card detection unit 413 outputs the card ID of the detected card 102 to the authentication processing unit 414, and performs authentication processing of the card 102.

[0090] Specifically, the authentication processing unit 414 acquires the user information 417 and verifies whether the user associated with the card ID of the detected card 102 is included in the user information 417. If the authentication processing unit 414 can verify that the user associated with the card ID of the detected card 102 is included in the user information 417, the authentication processing unit 414 permits authentication of the detected card 102. On the other hand, if the authentication processing unit 414 cannot verify that the user associated with the card ID of the detected card 102 is included in the user information 417, the authentication processing unit 414 does not permit authentication of the detected card 102.

[0091] In step S303, if the authentication processing unit 414 determines that authentication of the detected card 102 is permitted (if there is user information linked to the card ID) (step S303: Yes), the process proceeds to step S304. On the other hand, if authentication of the detected card 102 is not permitted (if there is user information linked to the card ID) (step S303: No), the process proceeds to step S305.

[0092] In step S304, authentication processing unit 414 stores user information linked to the card ID of the detected card 102. Meanwhile, in step S305, operation unit 220 displays an error screen, and when the user closes the error screen, the process returns to step S301.

[0093] Through the operations in steps S301 to S305 described above, authentication processing by card 102, which is the primary authentication that requires an operation by the user, is executed.

[0094] 6, in step S103, the authentication processing unit 414 determines whether the user 103 who succeeded in the zero-level authentication in step S101 and the user 103 who succeeded in the primary authentication in step S102 are the same user. In other words, the authentication processing unit 414 determines whether the user authentication, which is multi-factor authentication, has been successful. If the result of this determination is that the user authentication has been successful (step S103: Yes), the process proceeds to step S104.

[0095] 6, an example of a display on the operation panel 226 is shown. If the user authentication is successful, the authentication processing unit 414 executes authentication by password entry, and displays a password entry screen 502 on the operation panel 226 (step S104). When the user 103 presses the cancel button or when the user 103 leaves the device, the authentication processing unit 414 resets the user's authentication information or the operation screen.

[0096] On the other hand, if the user authentication is not successful (step S103: No), the process proceeds to step S105, where an error screen 503 is displayed. When the error screen 503 is closed, the process returns to steps S101 and S102.

[0097] 10 shows an example of a display on operation panel 226 when step S103 in Fig. 6 is No. Because user authentication has not been successful, authentication processing unit 414 displays error screen 503 on operation panel 226 (step S105). When user 103 presses the OK button to close error screen 503, authentication processing unit 414 resets the operation screen.

[0098] In step S106, while the password entry screen 502 is being displayed by short-range wireless communication by the short-range wireless communication unit 412, the radio wave intensity between the short-range wireless communication terminal 101 carried by the user 103 and the short-range wireless communication device 229 is measured. In other words, the short-range wireless communication unit 412 continues to detect whether the short-range wireless communication terminal 101 carried by the user 103 is within a predetermined distance. If the short-range wireless communication unit 412 has detected the short-range wireless communication terminal 101, the authentication processing unit 414 continues to display the password entry screen 502 on the operation panel 226.

[0099] Here, when the user 103 inputs a password, the authentication processing unit 414 compares the input password with the user who has been successfully authenticated. If the comparison is successful, the user can log in to the image forming apparatus 100. On the other hand, if the comparison is unsuccessful, an error screen 503 is displayed. Note that if the short-range wireless communication unit 412 detects the short-range wireless communication terminal 101, the password input screen 502 continues to be displayed on the operation panel 226.

[0100] In step S107, if the short-range wireless communication unit 412 cannot detect that the short-range wireless communication terminal 101 carried by the user 103 is within a predetermined distance, the authentication processing unit 414 discards the user information for which the user authentication was successful and returns to the state before the authentication processing in steps S101 and S102.

[0101] In step S108, the authentication processing unit 414 erases the password entry screen 502 displayed on the operation panel 226 and displays the initial login screen 501.

[0102] As described above, according to the information processing device 410 of the first embodiment, by using the short-range wireless communication terminal 101 that the user has, it is possible to improve the security strength and user convenience for a specific system (such as the image forming device 100) that has multi-factor authentication without incurring additional costs.

[0103] Second Embodiment In the second embodiment, authentication by short-range wireless communication is selectable. In the first embodiment, an example was shown in which authentication by the short-range wireless communication terminal 101 is performed for the zero-level authentication, authentication by the card 102 is performed for the primary authentication, and further authentication is performed by password input. In the second embodiment, however, a configuration is made in which settings related to the zero-level authentication by the short-range wireless communication terminal can be switched.

[0104] In the first embodiment, if a user 103 logging in to the image forming apparatus 100 touches or swipes the card 102 on the card reader to perform primary authentication without carrying the short-range wireless communication terminal 101, an error screen 503 is displayed on the operation screen, and the image forming apparatus 100 cannot be used. Therefore, in the second embodiment, the user can select whether or not to perform primary authentication using the short-range wireless communication terminal 101, thereby improving user convenience.

[0105] 11 is a diagram showing an example of a setting screen for zero-level authentication displayed on the operation panel 226. The setting screen in FIG. 11 is displayed on the operation panel 226 by the authentication processing unit 414 after or during the primary authentication using, for example, the card 102. The user 103 can select whether or not to perform the zero-level authentication on the setting screen. When the image forming apparatus 100 performs the zero-level authentication via short-range wireless communication, the user 103 selects "Authenticate." On the other hand, when the image forming apparatus 100 does not perform the zero-level authentication, the user 103 selects "Do not authenticate."

[0106] 12 is an example of a flowchart of the operation of the authentication processing unit 414 of the information processing device 410 according to the second embodiment. First, in step S401, the setting of whether or not to execute zero-order authentication in the image forming device 100 is confirmed. If zero-order authentication is to be executed (step S401: Yes), the process proceeds to step S403, where primary authentication using the card 102 and zero-order authentication via short-range wireless communication are executed. If zero-order authentication is not to be executed (step S401: No), the process proceeds to step S402, where primary authentication using the card 102 is executed.

[0107] In step S403, if zero-order authentication is performed by image forming apparatus 100, the steps from step S404 onwards are the same as steps S103 to S108 in Fig. 6. On the other hand, if zero-order authentication is not performed, in step S402, image forming apparatus 100 does not perform zero-order authentication, but performs only primary authentication using card 102, and then proceeds to step S404 to display a password entry screen.

[0108] Steps S404 and thereafter are the same as steps S104 and thereafter in FIG. 6. A password entry screen is displayed (S404), and simultaneously with or before or after S404, it is determined whether or not the short-range wireless communication terminal 101 of the user 103 is within a predetermined range from the image forming apparatus 100 (S405). If it is determined that the short-range wireless communication terminal 101 of the user 103 is not within the predetermined range from the image forming apparatus 100 (S405: No), the primary authentication using the card 102 is canceled (S406), and the password entry screen is reset (S407). In step S402, the zero-order authentication is not performed, but the short-range wireless communication unit 412 may measure the radio wave intensity between the short-range wireless communication terminal 101 held by the user who has successfully completed the first authentication. In other words, regardless of whether or not the zero-order authentication is performed, the short-range wireless communication unit 412 may continue to detect whether the short-range wireless communication terminal 101 held by the user 103 is within a predetermined distance. As a result, when the multi-factor authentication processing unit 411 detects that a user who has successfully passed the primary authentication has left the image forming device 100 (step S405: No), it discards the user information whose primary authentication has succeeded, as in step S406, and returns to the state before the processing of step S401.

[0109] In step S407, the authentication processing unit 414 erases the password entry screen 502 on the operation panel 226 and displays the initial login screen 501. If the user 103 does not carry the near-field wireless communication terminal 101, even if the setting without zero-level authentication is selected, the determination in S405 may result in the user 103 being unable to use the image forming apparatus 100. Therefore, if the setting without zero-level authentication is selected (S401: No), the authentication processing unit 414 may execute the determination in S405 using, for example, a timer function built into the CPU 221. For example, if there is no input operation on the password entry screen within a predetermined time from the display of the password entry screen in S404, it may be determined that the user 103 has moved beyond a predetermined range from the image forming apparatus 100.

[0110] As described above, the configuration and method of the second embodiment make it possible to switch the execution of zero-level authentication, thereby improving the flexibility of settings related to user authentication and increasing convenience for users. Furthermore, by using the short-range wireless communication terminal 101 that the user possesses, the security strength of the image forming apparatus having multi-factor authentication can be improved without incurring additional costs.

[0111] Third Embodiment In the first and second embodiments, when performing zero-level authentication using the short-range wireless communication terminal 101, it is necessary to associate the short-range wireless communication terminal 101 with the user 103 in advance (see FIG. 5). In the third embodiment, even if the short-range wireless communication terminal 101 and the user 103 are not associated in advance, a configuration is provided that improves the security strength of a predetermined system such as the image forming apparatus 100.

[0112] 13 is an example of a flowchart of the operation of the authentication processing unit 414 of the information processing device 410 according to the third embodiment. In the third embodiment, it is assumed that the user 103 who uses the image forming device 100 carries the short-range wireless communication terminal 101. First, in step S501, as in FIG. 12, the image forming device 100 checks the setting content as to whether or not to execute the zero-order authentication. If the zero-order authentication is to be executed (step S501: Yes), the process proceeds to step S503, and if the zero-order authentication is not to be executed (step S501: No), the process proceeds to step S502.

[0113] In step S503, image forming apparatus 100 performs zero-level authentication, and the subsequent steps are the same as steps S103 to S108 in Fig. 6. On the other hand, in step S502, image forming apparatus 100 does not perform zero-level authentication, but performs only primary authentication using card 102, and then proceeds to step S504.

[0114] In step S504, the authentication processing unit 414 stores the terminal device that is closest to the short-range wireless communication device 229 when the primary authentication is successful as the short-range wireless communication terminal 101 of the user currently performing user authentication, and proceeds to step S505. Note that the short-range wireless communication terminal 101 to be stored may be the short-range wireless communication terminal 101 whose radio wave strength received by the short-range wireless communication device 229 is the strongest.

[0115] Step S505 and subsequent steps are the same as step S104 and subsequent steps in Fig. 6, and therefore detailed description thereof will be omitted. Even if the user 103 and the short-range wireless communication terminal 101 are not associated in advance, the same processing as step S106 in Fig. 6 and step S405 in Fig. 12 is performed in step S506. That is, when the authentication processing unit 414 detects through short-range wireless communication by the short-range wireless communication unit 412 that the user 103, who has been successfully primary authenticated, has moved away from the image forming apparatus 100, the authentication processing unit 414 discards the user information for which the primary authentication has been successful, and returns to the state before the processing of step S501.

[0116] In step S508, the authentication processing unit 414 erases the password entry screen 502 displayed on the operation panel 226 and displays the initial login screen 501.

[0117] As described above, according to the configuration and method of the third embodiment, it is not necessary to associate the short-range wireless communication terminal 101 with the user 103 in advance, and the effort required for the association work can be saved. Furthermore, it is possible to improve the security strength of user authentication while saving the effort required for the association work.

[0118] <Fourth embodiment> In the first to third embodiments, when the short-range wireless communication unit 412 detects that a user who has successfully completed primary authentication has left the image forming apparatus 100, the authentication processing unit 414 resets the image forming apparatus 100 to the state before the zero-level authentication or primary authentication process, and the operation panel 226 is reset to the initial login screen 501. In consideration of users who find these reset operations bothersome, the fourth embodiment is configured to allow users to select whether to reset the authentication result and the operation screen.

[0119] 14 shows an example of a reset setting screen displayed on the operation panel 226 in the fourth embodiment. When the image forming apparatus 100 changes (resets) the login screen on the operation panel 226 of a user who has undergone zero-level authentication or primary authentication via short-range wireless communication terminal 101 to the initial login screen 501, the setting contents of the above means are set to "reset." On the other hand, when the image forming apparatus 100 does not change (does not reset) the login screen on the operation panel 226 of a user who has undergone zero-level authentication or primary authentication via short-range wireless communication to the initial login screen 501, the setting contents of the above means are set to "do not reset."

[0120] Fig. 15 is an example of a flowchart of the operation of the fourth embodiment by the authentication processing unit 414 of the information processing device 410. Steps S601 to S604 are similar to steps S401 to S404 in Fig. 12, and therefore description thereof will be omitted.

[0121] In step S605, image forming apparatus 100 checks whether the setting is set to reset the login screen on operation panel 226 to initial login screen 501. If operation panel 226 is set to be reset to initial login screen 501 (step S605: Yes), the process proceeds to step S607, and if operation panel 226 is set not to be reset to initial login screen 501 (step S605: No), the process proceeds to step S606.

[0122] In step S607, image forming apparatus 100 resets the login screen on operation panel 226 to initial login screen 501, and therefore performs operations similar to steps S106 to S108 in Fig. 6 and steps S405 to S407 in Fig. 12. On the other hand, in step S606, the login screen on operation panel 226 is not reset to initial login screen 501, and therefore operation panel 226 continues to output the password entry screen until user 103 enters a password.

[0123] In step S608, the user 103 logs in to the image forming apparatus 100 by inputting the correct password in step S606.

[0124] As described above, according to the configuration and method of the fourth embodiment, it is possible to switch whether to reset the login screen by short-range wireless communication, which improves the flexibility of settings related to user authentication and increases convenience for users.

[0125] Although the present invention has been described above based on each embodiment, the present invention is not limited to the requirements set forth in the above embodiments. These aspects can be modified without departing from the spirit of the present invention and can be appropriately determined depending on the application. The above-described embodiments can be combined with each other. For example, after selecting zero-level authentication via near-field wireless communication in the second embodiment, the terminal device with the strongest reception strength may be stored as the near-field wireless communication terminal of the user being authenticated, as in the third embodiment. Alternatively, the display of the reset screen of the fourth embodiment may be combined with each of the first to third embodiments, or a combination of these.

[0126] For example, aspects of the present invention are as follows. <1> a storage unit for storing user information including identification information for identifying a user who uses a predetermined system; a monitor unit that monitors the presence of the user using the predetermined system; an authentication processing unit that authenticates the user based on the user information, The authentication processing unit resets the user's authentication information or the operation screen of the specified system when the monitor unit detects that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system. <2> the storage unit stores card information of a card that authorizes the user to use the predetermined system or biometric information of the user as the identification information; the authentication processing unit, after the first authentication based on the identification information, causes an input screen for second authentication by inputting a password of the user to be displayed on the operation screen, and resets the first authentication and the input screen when the monitor unit detects that the user has left the predetermined system beyond the predetermined range after the display of the input screen. <1> The information processing device described in <3> the storage unit stores terminal information of the user's short-range wireless communication terminal as the user information; the monitor unit is a short-range wireless communication unit that communicates with the short-range wireless communication terminal by short-range wireless communication, the authentication processing unit resets the authentication information of the user and the operation screen when the strength of the radio waves received by the short-range wireless communication unit from the short-range wireless communication terminal becomes smaller than a threshold. <1> or <2> The information processing device described in <4> the storage unit stores the terminal information and card information that authorizes the user to use the predetermined system as the user information; the authentication processing unit displays an error screen on the operation screen when the first authentication based on the card information and the second authentication based on the terminal information do not match. <2> or <3> The information processing device described in <5> the authentication processing unit displays, on the operation screen, a setting screen for switching whether or not to perform the second authentication based on the terminal information. <2> or <4> The information processing device described in <6> When the second authentication is set not to be performed, the authentication processing unit associates the terminal receiving the strongest radio waves by the short-range wireless communication unit with the user as the short-range wireless communication terminal at the time when the first authentication is successful, and resets the first authentication and the operation screen when the strength of the radio waves from the terminal detected by the short-range wireless communication unit becomes smaller than the threshold. <3> or <5> The information processing device described in <7> When the monitor detects that the user has left the predetermined system beyond the predetermined range after user authentication based on the identification information, the authentication processing unit displays a setting screen on the operation screen for selecting whether or not to reset the operation screen. <1> from <6> 10. The information processing device according to claim 9, wherein: <8> the monitor unit includes a timer, and when there is no input operation on the operation screen for a predetermined time after user authentication based on the identification information, the authentication processing unit determines that the user has left the predetermined range and has left the predetermined system, and resets the user's authentication information or the operation screen of the predetermined system. <1> from <7> 10. The information processing device according to claim 9, wherein: <9> <1> from <8> an information processing device according to any one of the preceding claims; an image forming system; and The predetermined system is the image forming system. <10> storing user information including identification information that identifies a user who uses a predetermined system; monitoring the presence of said user using said predetermined system; authenticating the user based on the user information; and resetting the user's authentication information or the operation screen of the specified system when it is detected that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system. <11> storing user information including identification information that identifies a user who uses a predetermined system; monitoring the presence of said user using said predetermined system; authenticating the user based on the user information; and resetting the user's authentication information or the operation screen of the specified system when it is detected that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system. [Explanation of symbols]

[0127] 100 Image forming device 101 Near Field Communication Terminal 102 Cards 103 users 210 Main Unit 220 Operation section 226 Operation Panel 410 Information processing equipment 411 Multi-factor authentication processing unit 412 Near Field Wireless Communication Department 414 Authentication processing section 415 Storage section 417 User Information 450 Monitor unit [Prior art documents] [Patent documents]

[0128] [Patent Document 1] Patent Publication No. 2017-107473

Claims

1. a storage unit for storing user information including identification information for identifying a user who uses a predetermined system; a monitor unit that monitors the presence of the user using the predetermined system; an authentication processing unit that authenticates the user based on the user information, The authentication processing unit resets the user's authentication information or the operation screen of the specified system when the monitor unit detects that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system.

2. the storage unit stores card information of a card that authorizes the user to use the predetermined system or biometric information of the user as the identification information; 2. The information processing device according to claim 1, wherein the authentication processing unit, after a first authentication based on the identification information, displays an input screen on the operation screen for a second authentication by inputting the user's password, and if the monitor unit detects that the user has left the specified system beyond the specified range after the input screen is displayed, resets the first authentication and the input screen.

3. the storage unit stores terminal information of the user's short-range wireless communication terminal as the user information; the monitor unit is a short-range wireless communication unit that communicates with the short-range wireless communication terminal by short-range wireless communication, 2 . The information processing device according to claim 1 , wherein the authentication processing unit resets the authentication information of the user and the operation screen when the strength of the radio waves received by the short-range wireless communication unit from the short-range wireless communication terminal becomes smaller than a threshold.

4. the storage unit stores the terminal information and card information that authorizes the user to use the predetermined system as the user information; The information processing apparatus according to claim 3 , wherein the authentication processing unit displays an error screen on the operation screen when the first authentication based on the card information and the second authentication based on the terminal information do not match.

5. The information processing apparatus according to claim 4 , wherein the authentication processing unit displays, on the operation screen, a setting screen for switching whether or not to execute the second authentication based on the terminal information.

6. 6. The information processing device of claim 5, wherein when the second authentication is set not to be performed, the authentication processing unit associates the terminal receiving the strongest radio waves by the short-range wireless communication unit with the user as the short-range wireless communication terminal at the time the first authentication is successful, and resets the first authentication and the operation screen when the strength of the radio waves from the terminal detected by the short-range wireless communication unit becomes smaller than the threshold.

7. The information processing device according to claim 1, wherein the authentication processing unit, after user authentication based on the identification information, when the monitor unit detects that the user has left the specified system beyond the specified range, displays a setting screen on the operation screen that allows the user to select whether or not to reset the operation screen.

8. 2. The information processing device according to claim 1, wherein the monitor unit includes a timer, and the authentication processing unit determines that the user has left the specified system beyond the specified range when there is no input operation on the operation screen for a specified time after user authentication based on the identification information, and resets the user's authentication information or the operation screen of the specified system.

9. An information processing device according to any one of claims 1 to 8; an image forming system; and The predetermined system is the image forming system.

10. storing user information including identification information that identifies a user who uses a predetermined system; monitoring the presence of said user using said predetermined system; authenticating the user based on the user information; and resetting the user's authentication information or the operation screen of the specified system when it is detected that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system.

11. storing user information including identification information that identifies a user who uses a predetermined system; monitoring the presence of said user using said predetermined system; authenticating the user based on the user information; and resetting the user's authentication information or the operation screen of the specified system when it is detected that the user has left the specified system beyond a specified range after user authentication and before the user has completed using the specified system.

Citation Information

Patent Citations

  • Information processing system, information processing apparatus, server, and information processing method

    JP2017107473A