User authentication system and information processing apparatus

The user authentication system uses a three-dimensional code to securely register a new device without sensitive information input, addressing the challenge of registering a new mobile device after the previous one is lost, ensuring efficient and secure registration.

JP2025176561APending Publication Date: 2025-12-04KYOCERA DOCUMENT SOLUTIONS INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024082800
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-21
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Existing user authentication systems do not provide a simple and secure method for registering a new mobile device after the previous device is lost, requiring cumbersome input of sensitive information and posing a risk of leakage.

Method used

A user authentication system that uses a three-dimensional code, such as a QR code, to facilitate the registration of a new terminal device by generating a code indicating user identification information and a service usage request, allowing the new device to be registered without sensitive information input, and ensuring secure communication with a server.

Benefits of technology

Enables secure and efficient registration of a new terminal device by eliminating the need for cumbersome sensitive information input and reducing the risk of leakage, while maintaining system security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025176561000001_ABST
    Figure 2025176561000001_ABST
Patent Text Reader

Abstract

To eliminate the need of complicated operations, reduce the possibility of leakage of sensitive information, and allow additional registration of a terminal device to a server, when log-in to an information processing apparatus is authenticated on the basis of a user's identification information.SOLUTION: In a user authentication system Sy, an image forming apparatus 10, when authenticating log-in on the basis of a user's identification information, generates and outputs a QR code indicating an instruction to execute an access to a FIDO server 30 and a request for using a service from the FIDO server 30. A second portable terminal device 52, upon reading the QR code, accesses the FIDO server 30 and requests using the service from the FIDO server 30. The FIDO server 30 additionally registers the second portable terminal device 52 to the FIDO server 30.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a user authentication system, and more particularly to a technique for registering a new terminal device of a user to a server. [Background technology]

[0002] In online services that use data communication via the Internet, user authentication using safer and simpler methods such as FIDO (Fast Identity Online) is becoming more common, and various proposals have been made to further improve convenience.

[0003] For example, in the information processing system described in Patent Document 1, when FIDO using biometric authentication is successful, the user terminal receives identification information (e.g., a token) from the authentication server and transmits the token received from the authentication server to the information processing device. The information processing device inquires of the authentication server whether the token received from the user terminal is the token transmitted to the user terminal by the authentication server. If the token received by the information processing device from the user terminal is the token transmitted to the user terminal by the authentication server, the information processing device permits the user to use the information processing device (e.g., allows the user to log in to the information processing device). The user terminal retains the token received from the authentication server therein and transmits the retained token to the information processing device to receive permission to use the information processing device. Therefore, the user does not need to perform authentication on the user terminal, such as biometric authentication, every time the user uses the information processing device.

[0004] Furthermore, the information processing device described in Patent Document 2 performs registration processing for each service for each user, thereby storing a combination of a user ID, service ID, service name, authenticator ID, and authenticator name (preferably also an authentication method) as authenticator correspondence information in the memory of the image processing device. The image processing device acquires the user ID of the user to be notified. A notification processing unit of the image processing device references the authenticator correspondence information stored in the memory and identifies the service ID and authenticator ID associated with the acquired user ID. The notification processing unit then notifies the user of the service indicated by the identified service ID and the authenticator indicated by the identified authenticator ID (i.e., the authenticator corresponding to the service). This allows the user to know the authenticator required for authentication processing for services available to the user when different authenticators need to be used for authentication processing for multiple services. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Publication No. 2022-53955 [Patent Document 2] Japanese Patent Publication No. 2022-46024 Summary of the Invention [Problem to be solved by the invention]

[0006] When a user's device used with FIDO is a mobile device such as a smartphone or tablet, the user may want to register a new mobile device and continue using the same service if the previous mobile device is lost. In this case, to prove that the new mobile device is used by the same user as the lost mobile device, the user must enter sensitive information about the user into the new mobile device and transmit the sensitive information from the new mobile device, which is a cumbersome process and poses a risk of leaking the sensitive information.

[0007] Neither Patent Document 1 nor Patent Document 2 provides any technical description or suggestion for simplifying the process for registering a new mobile terminal when the previous mobile terminal is lost or for other reasons.

[0008] The present invention has been developed in consideration of the above circumstances, and aims to enable additional registration of terminal devices by a server when login to an information processing device is authenticated based on a user's identification information, while eliminating the need for cumbersome work and reducing the risk of leakage of sensitive information. [Means for solving the problem]

[0009] a first control unit that executes user login authentication processing for the information processing device based on whether the user identification information input to the operation unit matches the user identification information of the user stored in the storage unit, and the information processing device includes a first communication unit that performs data communication with the server, a three-dimensional code output unit that displays or prints a three-dimensional code, an operation unit into which user identification information and instructions from the user are input, and a first control unit that executes user login authentication processing for the information processing device based on whether the user identification information input to the operation unit matches the user identification information of the user stored in the storage unit, and the first control unit executes user login authentication processing for the information processing device based on whether the user identification information input to the operation unit matches the user identification information of the user stored in the storage unit, and and generates a three-dimensional code indicating user identification information, an instruction to access the server, and a service utilization request from the server, and causes the three-dimensional code output unit to output the three-dimensional code. The terminal device comprises a second communication unit that performs data communication with the server, a three-dimensional code reading unit that reads the three-dimensional code, and a second control unit that accesses the server through the second communication unit in accordance with the access utilization instruction indicated by the three-dimensional code read by the three-dimensional code reading unit, and transmits the terminal identification information of the terminal device, the user identification information, and the service utilization request indicated by the three-dimensional code from the second communication unit to the server. The server comprises a third communication unit that communicates with the terminal device, and a third control unit that, when the terminal identification information, the user identification information, and the service utilization request transmitted from the terminal device are received by the third communication unit, additionally registers the terminal device indicated by the terminal identification information in the server in association with the user identified by the user identification information.

[0010] According to one aspect of the present invention, there is provided a user authentication system comprising: a server; and an information processing device that performs data communication with the server via a network, the information processing device comprising: a first communication unit that performs data communication with the server; a three-dimensional code output unit that displays or prints a three-dimensional code; an operation unit into which a user's identification information and an instruction from the user are input; a storage unit that stores identification information of each user required for authentication processing of a user's login to the information processing device; and a first control unit that executes user login authentication processing for the information processing device based on whether the user's identification information input to the operation unit matches the user's identification information stored in the storage unit, When an instruction to execute authentication processing for additional registration of the terminal device to the server is input to the operation unit while the user's login is being approved by the authentication processing based on the above, a three-dimensional code indicating the user identification information of the user who approved the login, an instruction to execute access to the server, and a service usage request from the server is generated, and the three-dimensional code output unit outputs the three-dimensional code. The server comprises a third communication unit that communicates with the terminal device, and a third control unit that, when the terminal identification information of the terminal device transmitted from the terminal device, the user identification information indicated by the three-dimensional code, and the service usage request are received by the third communication unit, additionally registers the terminal device indicated by the terminal identification information to the server. An information processing device according to one aspect of the present invention is an information processing device that performs data communication with a server over a network, and includes: a first communication unit that performs data communication with the server; a three-dimensional code output unit that displays or prints a three-dimensional code; an operation unit to which user identification information and instructions from the user are input; a storage unit that stores identification information of each user required for authentication processing of user login to the information processing device; and a first control unit that executes user login authentication processing for the information processing device based on whether the user identification information input to the operation unit matches the user identification information stored in the storage unit, and the first control unit executes user login authentication processing for the information processing device based on the user identification information input to the operation unit When an instruction to execute authentication processing for additional registration of the terminal device to the server is input to the operation unit while approving the login of the user, the first control unit generates a three-dimensional code indicating the user identification information of the user who approved the login, an instruction to execute access to the server, and a service usage request from the server, and causes the three-dimensional code output unit to output the three-dimensional code. After the three-dimensional code is output, and after the first communication unit receives confirmation information from the server requesting an instruction to allow the addition of the terminal device to the server, when an instruction to allow the addition of the terminal device is input to the operation unit, the first control unit transmits permission information from the first communication unit to the server, indicating that the addition of the terminal device is allowed. [Effects of the Invention]

[0011] According to the present invention, when login to an information processing device is authenticated based on a user's identification information, it is possible to eliminate the need for cumbersome work, reduce the risk of leakage of sensitive information, and enable the server to additionally register a terminal device. [Brief explanation of the drawings]

[0012] [Figure 1]FIG. 1 is a block diagram showing a user authentication system according to one embodiment of the present invention, and the configuration of an image forming device, a FIDO server, a first mobile terminal device, and a second mobile terminal device in the user authentication system. [Figure 2] 10 is a flowchart showing processing executed by the image forming device, the FIDO server, and the second mobile terminal device when permitting additional authentication registration of the second mobile terminal device based on authentication of login to the image forming device using user identification information. [Figure 3] FIG. 10 is a sequence diagram illustrating a communication protocol implemented between an image forming apparatus, a FIDO server, and a second portable terminal device when permitting additional authentication and registration of a second portable terminal device based on authentication of a user's login to the image forming apparatus using the user's identification information. DETAILED DESCRIPTION OF THE INVENTION

[0013] A user authentication system and an information processing device according to an embodiment of the present invention will be described below with reference to the drawings. Fig. 1 is a block diagram showing the configuration of a user authentication system according to an embodiment of the present invention, and the configuration of an image forming device, a FIDO server, and a mobile terminal device in the user authentication system.

[0014] A user authentication system Sy according to this embodiment includes an image forming device 10, a FIDO server 30, a first mobile terminal device 51, and a second mobile terminal device 52. In the user authentication system Sy, data communication is performed between the image forming device 10 and the FIDO server 30 via a network (such as an intranet) N. Data communication is also performed between the FIDO server 30 and the first and second mobile terminal devices 51 and 52 via the network N. The image forming device 10 is one embodiment of an information processing device according to the present invention.

[0015] Note that a user authentication system that does not include the first mobile terminal device 51 and the second mobile terminal device 52, but includes the image forming device 10 and the FIDO server 30, is also an embodiment of the present invention. FIDO is an abbreviation for Fast Identity Online.

[0016] Here, the image forming device 10 is an example of an image forming device in the claims. The FIDO server 30 is an example of a server in the claims. The second mobile terminal device 52 is an example of a terminal device in the claims.

[0017] It is also assumed that the first mobile terminal device 51 and the second mobile terminal device 52 are owned by the same user. The user loses the first mobile terminal device 51 and starts using the new second mobile terminal device 52 in place of the first mobile terminal device 51.

[0018] In the user authentication system Sy, the image forming device 10 is an MFP (multi-function peripheral) that combines multiple functions such as a copy function and a scanner function. The image forming device 10 includes a display unit 11, an operation unit 12, a touch panel 13, a communication unit 14, an image reading unit 15, an image forming unit 16, a storage unit 18, and a control unit 19. These components transmit and receive data or signals to and from each other via a bus.

[0019] The display unit 11 is configured by a liquid crystal display (LCD) or an organic light-emitting diode (OLED) display.

[0020] A touch panel 13 is superimposed on the screen of the display unit 11. The touch panel 13 detects contact (touch) with the user's finger or the like on the touch panel 13 together with the contact position, and outputs a detection signal indicating the coordinates of the contact position to the control unit 21 of the control unit 19. This makes it possible to operate a GUI (Graphical User Interface) or the like displayed on the screen of the display unit 11 through the touch panel 13. Therefore, the touch panel 13 functions as an operation unit into which user operations are input to the screen of the display unit 11.

[0021] The operation unit 12 includes hardware keys such as a numeric keypad, a decision key, a start key, etc. The operation unit 12 receives various instructions from the user.

[0022] The image reading unit 15 has a scanner that optically reads an image of a document, and generates image data that represents the image of the document.

[0023] The image forming unit 16 includes a photosensitive drum, a charging device that uniformly charges the surface of the photosensitive drum, an exposure device that exposes the surface of the photosensitive drum to light to form an electrostatic latent image on the surface of the photosensitive drum, a developing device that develops the electrostatic latent image on the surface of the photosensitive drum into a toner image, and a transfer device that transfers the toner image (image) on the surface of the photosensitive drum to recording paper, and prints an image represented by the image data on the recording paper.

[0024] The communication unit 14 is a communication interface equipped with a communication module such as a LAN chip. The communication unit 14 is connected to the FIDO server 30 via a network (such as an intranet) N, and performs data communication with the FIDO server 30.

[0025] The storage unit 18 is a large-capacity storage device such as an SSD (Solid State Drive) or an HDD (Hard Disk Drive), and stores various application programs and various data.

[0026] The control unit 19 is composed of a processor, a RAM (Random Access Memory), a ROM (Read Only Memory), etc. The processor is, for example, a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), or an MPU (Micro Processing Unit). The control unit 19 functions as a control unit 21 when a control program stored in the ROM or the storage unit 18 is executed by the processor.

[0027] The control unit 19 is responsible for overall control of the image forming apparatus 10. The control unit 19 is also connected to the display unit 11, the operation unit 12, the touch panel 13, the communication unit 14, the image reading unit 15, the image forming unit 16, and the storage unit 18, and controls each of the above components and transmits and receives signals or data to and from each of the components.

[0028] The control unit 21 functions as a processing unit that executes various processes, and also has the function of controlling the display unit 11 and the communication unit 14.

[0029] In addition, the communication unit 14 corresponds to the first communication unit in the claims, the display unit 11 and the image forming unit 16 correspond to the QR code (registered trademark) output unit in the claims, and the control unit 21 corresponds to the first control unit in the claims.

[0030] In the user authentication system Sy, the FIDO server 30 includes a communication unit 34, a storage unit 38, and a control unit 39. These components transmit and receive data or signals to and from each other via a bus.

[0031] The communication unit 34 is a communication interface, and is connected to the image forming device 10, the first portable terminal device 51, or the second portable terminal device 52 via the network N, and performs data communication between the image forming device 10, the first portable terminal device 51, or the second portable terminal device 52.

[0032] The storage unit 38 is a storage device such as an SSD or HDD, and stores programs and various data.

[0033] The control unit 39 is composed of a processor, RAM, ROM, etc. The control unit 39 functions as a control unit 41 when a program stored in the ROM or the storage unit 38 is executed by the processor.

[0034] The control unit 39 is responsible for overall control of the FIDO server 30. The control unit 39 is also connected to the communication unit 34, the storage unit 38, and the like, and controls each of the above components and transmits and receives signals or data to and from each of the components.

[0035] The communication unit 34 corresponds to a third communication unit in the claims, and the control unit 41 corresponds to a third control unit in the claims.

[0036] In the user authentication system Sy, the first mobile terminal device 51 is, for example, a smartphone, and includes a display unit 61, a touch panel 63, a communication unit 64, an imaging camera 65, an authentication unit 67, a storage unit 68, and a control unit 69. These components transmit and receive data or signals to and from each other via a bus.

[0037] The display unit 61 is configured with a liquid crystal display, etc. The touch panel 63 is placed on the screen of the display unit 61 and detects touch operations by the user's finger, etc.

[0038] The communication unit 64 is a communication interface that is connected to the FIDO server 30 via the network N and transmits and receives data to and from the FIDO server 30.

[0039] The authentication unit 67 is a known sensor that detects a user's fingerprint or the like and is used for biometric authentication.

[0040] The storage unit 68 is a large-capacity storage device such as an SSD or HDD, and stores various application programs and various data.

[0041] The control unit 69 is composed of a processor, RAM, ROM, etc. The control unit 69 functions as a control unit 71 when a control program stored in the ROM or the storage unit 68 is executed by the processor.

[0042] The control unit 69 is responsible for overall control of the first mobile terminal device 51. The control unit 69 is also connected to the display unit 61, the touch panel 63, the communication unit 64, the imaging camera 65, the authentication unit 67, and the storage unit 68, and controls each of the above components and transmits and receives signals or data to and from each of the components.

[0043] In the user authentication system Sy, the second mobile terminal device 52 is, like the first mobile terminal device 51, for example, a smartphone, and has the same configuration as the first mobile terminal device 51.

[0044] The communication unit 64 corresponds to a second communication unit in the claims, the imaging camera 65 corresponds to a QR code input unit in the claims, and the control unit 71 corresponds to a second control unit in the claims.

[0045] In the user authentication system Sy configured as described above, the first mobile terminal device 51 has been authenticated by the FIDO server 30 and is already registered as a terminal device that receives services from the FIDO server 30. Here, the user has lost the first mobile terminal device 51 and is using a new second mobile terminal device 52. The user would like to continue using the same services by having the second mobile terminal device 52 authenticated and registered by the FIDO server 30. In this case, if the user were to input sensitive information about the user into the new second mobile terminal device 52 and transmit the sensitive information from the second mobile terminal device 52 to prove that the user is the same user as the lost mobile terminal device, inputting the sensitive information into the second mobile terminal device 52 would require cumbersome work and pose a risk of leaking the sensitive information.

[0046] In this embodiment, the control unit 21 of the image forming device 10 determines whether the user identification information ID entered into the operation unit 12 matches the identification information ID of each user who is authorized to log in, stored in the memory unit, and if they match, performs authentication processing to approve the login of the user who entered the identification information ID into the operation unit 12 to the image forming device 10.

[0047] When an instruction to execute an authentication process for additional registration of the second mobile terminal device 52 to the FIDO server 30 is input to the operation unit 12 while the control unit 21 is approving the login of the user through the above authentication process based on the user's identification information ID input to the operation unit 12, the control unit 21 generates an instruction to execute access to the FIDO server 30, the identification information ID (an example of user identification information) of the user who approved the login, and a QR code (an example of a three-dimensional code) indicating a service usage request from the FIDO server 30, and displays the QR code on the display unit 11 or forms the QR code on recording paper using the image forming unit 16.

[0048] The user operates the second mobile terminal device 52 to cause the imaging camera 65 to capture an image of the QR code displayed on the display unit 11 or the QR code formed on the recording paper. The control unit 71 of the second mobile terminal device 52 accesses the FIDO server 30 via the communication unit 64 in accordance with the access execution instruction indicated by the captured QR code, and transmits the terminal identification information of the second mobile terminal device 52, the user's identification information ID, and the service usage request indicated by the QR code from the communication unit 64 to the FIDO server 30.

[0049] In the FIDO server 30, when the communication unit 34 receives the terminal identification information and service usage request transmitted from the second mobile terminal device 52, the control unit 41 additionally registers the second mobile terminal device 52, which is the terminal device indicated by the terminal identification information, in the FIDO server 30 in association with the user indicated by the identification information ID.

[0050] In other words, in this case, upon receiving the service usage request, the control unit 41 of the FIDO server 30 determines that the second mobile terminal device 52 indicated by the terminal identification information is a trusted terminal device, and approves the additional registration of the second mobile terminal device 52 to the FIDO server 30, corresponding to the user indicated by the identification information ID.

[0051] In a further embodiment, the control unit 21 of the image forming device 10 may create a QR code that further indicates the device identification information of the image forming device 10 in addition to the access execution instruction, the identification information ID, and the service usage request.

[0052] In this case, when the control unit 71 of the second mobile terminal device 52 accesses the FIDO server 30 through the communication unit 64 in accordance with the access execution instruction, the control unit 71 transmits the device identification information indicated by the QR code from the communication unit 64 to the FIDO server 30 in addition to the terminal identification information of the second mobile terminal device 52, the identification information ID, and the service usage request.

[0053] Then, when the communication unit 34 receives the device identification information from the second mobile terminal device 52 in addition to the terminal identification information, the identification information ID, and the service usage request, the control unit 41 of the FIDO server 30 causes the communication unit 34 to send confirmation information to the image forming device 10 indicated by the device identification information, requesting an instruction as to whether to allow the addition associated with the user indicated by the identification information ID of the second mobile terminal device 52 indicated by the terminal identification information.

[0054] After the communication unit 14 receives the confirmation information, when an instruction to allow the addition of the second mobile terminal device 52 indicated by the terminal identification information associated with the user indicated by the identification information ID is input to the operation unit 12, the control unit 21 of the image forming device 10 transmits permission information from the communication unit 14 to the FIDO server 30 indicating that the addition of the second mobile terminal device 52 is allowed.

[0055] Furthermore, when the communication unit 34 receives the permission information, the control unit 41 of the FIDO server 30 additionally registers the second mobile terminal device 52 indicated by the terminal identification information in the FIDO server 30 in association with the user indicated by the identification information ID.

[0056] Next, with reference to the flowchart shown in Fig. 2, a description will be given of processes executed by the image forming device 10, the FIDO server 30, and the second mobile terminal device 52 when additionally registering the second mobile terminal device 52 in the FIDO server 30 based on login authentication to the image forming device 10 using the user's identification information ID according to the further embodiment. Fig. 3 is a sequence diagram schematically illustrating a communication protocol implemented between the image forming device 10, the FIDO server 30, and the second mobile terminal device 52 when additionally registering the second mobile terminal device 52 based on login authentication in this manner.

[0057] The user of the second portable terminal device 52 inputs the user's identification information ID into the operation unit 12 of the image forming device 10. When the identification information ID is input into the operation unit 12 of the image forming device 10, the control unit 21 of the image forming device 10 executes a login authentication process based on the identification information ID (S101). For example, the user inputs the user's identification information ID registered on their own ID card into the operation unit 12 by having the card reader (part of the operation unit 12) of the image forming device 10 read the user's identification information ID, or by operating the operation unit 12 or soft keys displayed on the display unit 11 via the touch panel 13 to input the user's identification information ID.

[0058] When a user's identification information ID is input to the operation unit 12, if the identification information ID matches any of the identification information IDs of multiple users who are permitted to log in and are stored in advance in the storage unit 18, the control unit 21 approves the login to the image forming device 10 for the input user's identification information ID. In other words, at the time of this approval, the image forming device 10 has completed identity verification of the user.

[0059] After the login is approved, the control unit 21 causes the display unit 11 to display, for example, a message prompting whether to request the user to start a process of additionally registering a new mobile terminal device in the FIDO server 30 and a button for accepting the request. When the user operates the button to input the request into the operation unit 12 (S102), the control unit 21 generates a QR code indicating the device identification information of the image forming device 10, an instruction to access the FIDO server 30, the identification information ID of the user who approved the login, and a service usage request from the FIDO server 30, and causes the display unit 11 to display the QR code or causes the image forming unit 16 to form the QR code on recording paper (S103).

[0060] The instruction to access the FIDO server 30 includes a URL (an example of access destination information) for accessing the FIDO server 30, device identification information for the image forming device 10, and preferably a private key corresponding to the public key of the FIDO server 30.

[0061] The user operates the second mobile terminal device 52 that the user wishes to add to the FIDO server 30, and causes the imaging camera 65 (three-dimensional code reader) to capture an image of a QR code displayed on the display unit 11 or formed on recording paper. The control unit 71 of the second mobile terminal device 52 analyzes the QR code read by the imaging camera 65 and detects the device identification information, the identification information ID, the access execution instruction, and the service usage request indicated by the QR code (S301). In accordance with the access execution instruction, the control unit 71 accesses the FIDO server 30 via the communication unit 64 and transmits the device identification information, the identification information ID, and the service usage request, as well as the terminal identification information of the second mobile terminal device 52, from the communication unit 64 to the FIDO server 30 (S302). At this time, if the QR code includes the private key, the control unit 71 also transmits the private key from the communication unit 64 to the FIDO server 30.

[0062] The FIDO server 30 accepts access from the second mobile terminal device 52 via the communication unit 34. When the communication unit 34 receives the device identification information, the identification information ID, the service usage request, and the terminal identification information (S201), the control unit 41 causes the communication unit 64 to transmit confirmation information to the image forming device 10 indicated by the device identification information, requesting an instruction on whether to permit the second mobile terminal device 52 indicated by the terminal identification information to be added in association with the user indicated by the identification information ID (S202). That is, the device identification information includes access information (e.g., a URL or an IP address) for accessing the image forming device 10. In addition, in an embodiment in which the private key is included in a QR code, the control unit 41 transmits confirmation information to the image forming device 10 and performs additional registration of the second mobile terminal device 52, as described below, on the condition that the control unit 41 receives the device identification information, the identification information ID, the service usage request, and the terminal identification information, as well as the private key corresponding to the stored public key.

[0063] When the communication unit 14 of the image forming device 10 receives the confirmation information (S104), the control unit 21 of the image forming device 10 causes the display unit 11 to display a message prompting the user to input an instruction as to whether to allow additional registration of the second mobile terminal device 52 indicated by the confirmation information to the FIDO server 30 associated with the user indicated by the identification information ID, and a button for accepting the input of the instruction (S105).

[0064] After this display, i.e., after the communication unit 14 receives the above confirmation information, when an instruction to permit additional registration of the second mobile terminal device 52 associated with the user indicated by the above identification information ID to the FIDO server 30 is input to the operation unit 12 based on operation of the button (S106), the control unit 21 transmits permission information from the communication unit 14 to the FIDO server 30 indicating that the addition of the second mobile terminal device 52 indicated by the above confirmation information is permitted (S107).

[0065] When the communication unit 34 of the FIDO server 30 receives the permission information from the image forming device 10 (S203), the control unit 41 of the FIDO server 30 additionally registers the second mobile terminal device 52 indicated by the identification information in the FIDO server 30 in association with the user indicated by the identification information ID (S204).

[0066] As described above, in this embodiment, the second mobile terminal device 52 is additionally registered with the FIDO server 30 based on the trust of the user authentication (login authentication) by the image forming apparatus 10, without transmitting sensitive information such as personal information about the user from the second mobile terminal device 52. As shown in FIG. 3 , the second mobile terminal device 52 uses the user's identification information ID, but only performs QR code reading and analysis processes and accesses the FIDO server 30, and does not transmit sensitive information about the user. Furthermore, the image forming apparatus 10 does not transmit sensitive information to either the second mobile terminal device 52 or the FIDO server 30. Therefore, while ensuring the reliability of the terminal device additionally registered with the FIDO server 30, the cumbersome task of inputting sensitive information into the second mobile terminal device 52 is not required, and the risk of sensitive information leakage can be eliminated. The user's identification information ID is simply a string of characters and symbols, and is not sensitive information.

[0067] Furthermore, in the above embodiment, after the second mobile terminal device 52 accesses the FIDO server 30, if an instruction to allow the second mobile terminal device 52 to be additionally registered on the FIDO server 30 is input into the image forming device 10, the FIDO server 30 additionally registers the second mobile terminal device 52. Therefore, even if a third party unrelated to the user misuses the QR code to access the FIDO server 30 after the QR code is output by the image forming device 10, unless the user inputs an instruction to the image forming device 10 to allow the terminal device to be additionally registered on the FIDO server 30, it is possible to prevent the misused terminal device from being additionally registered in association with the user on the FIDO server 30.

[0068] The present invention is not limited to the configuration of the above embodiment, and various modifications are possible. In addition, in the above embodiment, the image forming apparatus 10, which is a multifunction peripheral, is exemplified as one embodiment of the information processing apparatus according to the present invention, but instead, a personal computer or a device that combines a scanner, a camera, etc. and has the same functions as the image forming apparatus 10 may be applied.

[0069] Furthermore, the configurations and processes of the above-described embodiment explained using FIGS. 1 to 3 are merely examples of the present invention, and the present invention is not limited to these configurations and processes. [Explanation of symbols]

[0070] Sy User Authentication System 10 Image forming device 11 Display section 12 Control section 13 Touch Panel 14 Communications Department 15 Image reading unit 16 Image forming unit 18 Memory section 19 Control Unit 21 Control section 30 FIDO servers 34 Communications Department 38 Memory section 39 Control Unit 41 Control Unit 51 First mobile terminal device 52 Second mobile terminal device 61 Display section 63 Touch Panel 64 Communications Department 65 Imaging camera 67 Authentication Section 68 Memory section 69 Control Unit 71 Control Unit

Claims

1. The server and an information processing device that performs data communication with the server through a network; a terminal device that communicates with the server, The information processing device includes: a first communication unit that performs data communication with the server; a three-dimensional code output unit that displays or prints a three-dimensional code; an operation unit into which user identification information and instructions from the user are input; a storage unit for storing identification information of each user required for authentication processing of user login to the information processing device; a first control unit that executes a login authentication process for a user to the information processing device based on whether the user identification information input to the operation unit matches the user identification information of the user stored in the storage unit; when an instruction to request execution of authentication processing for additional registration of the terminal device to the server is input to the operation unit while the login of the user is being approved by the authentication processing based on the identification information of the user input to the operation unit, the first control unit generates a three-dimensional code indicating the user identification information of the user who approved the login, an instruction to access the server, and a service utilization request from the server, and causes the three-dimensional code output unit to output the three-dimensional code; The terminal device a second communication unit that performs data communication with the server; a three-dimensional code reading unit that reads the three-dimensional code; a second control unit that accesses the server through the second communication unit in accordance with the access execution instruction indicated by the three-dimensional code read by the three-dimensional code reading unit, and transmits terminal identification information of the terminal device, the user identification information, and the service use request indicated by the three-dimensional code from the second communication unit to the server; The server a third communication unit that communicates with the terminal device; a third control unit that, when the terminal identification information, the user identification information, and the service usage request sent from the terminal device are received by the third communication unit, additionally registers the terminal device indicated by the terminal identification information in the server in association with the user identified by the user identification information.

2. the first control unit of the information processing device creates the three-dimensional code that further indicates device identification information of the information processing device, When the second control unit of the terminal device accesses the server through the second communication unit in accordance with the access execution instruction, the second control unit transmits the device identification information indicated by the three-dimensional code from the second communication unit to the server in addition to the terminal identification information of the terminal device, the user identification information, and the service use request; a third control unit of the server, when the third communication unit receives the device identification information from the terminal device in addition to the terminal identification information and the service use request, causes the third communication unit to transmit, to the information processing device indicated by the device identification information, confirmation information requesting an instruction as to whether to permit addition of the terminal device indicated by the terminal identification information; When an instruction to permit addition of the terminal device indicated by the identification information is input to the operation unit after the first communication unit receives the confirmation information, the first control unit of the information processing device transmits permission information indicating that addition of the terminal device is permitted from the first communication unit to the server; 2. The user authentication system of claim 1, wherein when the third communication unit receives the permission information, the third control unit of the server additionally registers the terminal device indicated by the identification information in the server in association with the user identified by the user identification information.

3. A server and an information processing device that performs data communication with the server through a network, The information processing device includes: a first communication unit that performs data communication with the server; a three-dimensional code output unit that displays or prints a three-dimensional code; an operation unit into which user identification information and instructions from the user are input; a storage unit that stores identification information of each user required for authentication processing of a user's login to the information processing device; a first control unit that executes a login authentication process for a user to the information processing device based on whether the user identification information input to the operation unit matches the user identification information stored in the storage unit; when an instruction to request execution of authentication processing for additional registration of the terminal device to the server is input to the operation unit while the login of the user is being approved by the authentication processing based on the identification information of the user input to the operation unit, the first control unit generates a three-dimensional code indicating the user identification information of the user who approved the login, an instruction to access the server, and a service utilization request from the server, and causes the three-dimensional code output unit to output the three-dimensional code; The server a third communication unit that communicates with the terminal device; A user authentication system comprising: a third control unit that additionally registers the terminal device indicated by the terminal identification information on the server when the third communication unit receives the terminal identification information of the terminal device, the user identification information indicated by the three-dimensional code, and the service usage request transmitted from the terminal device.

4. the first control unit of the information processing device creates the three-dimensional code that further indicates device identification information of the information processing device, When the second control unit of the terminal device accesses the server through the second communication unit in accordance with the access execution instruction, the second control unit transmits the device identification information indicated by the three-dimensional code from the second communication unit to the server in addition to the identification information of the terminal device, the user identification information, and the service use request; when the third communication unit receives the device identification information from the terminal device in addition to the terminal identification information, the user identification information, and the service usage request, the third control unit of the server causes the third communication unit to transmit, to the information processing device indicated by the device identification information, confirmation information requesting an instruction as to whether to permit addition of the terminal device indicated by the identification information; When an instruction to permit addition of the terminal device indicated by the terminal identification information is input to the operation unit after the first communication unit receives the confirmation information, the first control unit of the information processing device transmits permission information indicating that addition of the terminal device is permitted from the first communication unit to the server; 4. The user authentication system of claim 3, wherein when the third communication unit receives the permission information, the third control unit of the server additionally registers the terminal device indicated by the terminal identification information in the server in association with the user indicated by the user identification information.

5. An information processing device that performs data communication with a server through a network, a first communication unit that performs data communication with the server; a three-dimensional code output unit that displays or prints a three-dimensional code; an operation unit into which user identification information and instructions from the user are input; a storage unit that stores identification information of each user required for authentication processing of a user's login to the information processing device; a first control unit that executes a login authentication process for a user to the information processing device based on whether the user identification information input to the operation unit matches the user identification information stored in the storage unit; when an instruction to request execution of authentication processing for additional registration of the terminal device to the server is input to the operation unit while the login of the user is being approved by the authentication processing based on the identification information of the user input to the operation unit, the first control unit generates a three-dimensional code indicating the user identification information of the user who approved the login, an instruction to access the server, and a service utilization request from the server, and causes the three-dimensional code output unit to output the three-dimensional code; The information processing device, after outputting the three-dimensional code and after the first communication unit receives confirmation information from the server requesting an instruction as to whether to allow the addition of the terminal device to the server, when an instruction to allow the addition of the terminal device is input to the operation unit, the first control unit transmits permission information from the first communication unit to the server indicating that the addition of the terminal device is allowed.

Citation Information

Patent Citations

  • Information processor and information processing program

    JP2022046024A

  • Method, program, information processing apparatus, authentication server, and information processing system

    JP2022053955A