Image forming apparatus, information processing apparatus, method for controlling these, and program

The image forming apparatus synchronizes user names by receiving authentication information, requesting server authentication, and setting usernames based on rules, addressing the mismatch issue and enhancing user association accuracy.

JP2025177029APending Publication Date: 2025-12-05CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024083508
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-05-22
Publication Date
2025-12-05

AI Technical Summary

Technical Problem

When an information processing device and an image forming device each perform user authentication using an authentication server, the usernames representing the currently logged-in users may not match, leading to incorrect association of users and inconvenience.

Method used

An image forming apparatus that includes a receiving means for receiving authentication information from an information processing device, requesting user authentication from an authentication server, acquiring attribute values, and setting a username based on selected setting rules to synchronize user names across devices.

Benefits of technology

This approach suppresses mismatches in user names between the image forming apparatus and the information processing apparatus, ensuring correct user association and reducing user inconvenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025177029000001_ABST
    Figure 2025177029000001_ABST
Patent Text Reader

Abstract

To prevent mismatch in user names between an image forming apparatus and an information processing apparatus.SOLUTION: An image forming apparatus comprises: a receiving unit that receives, from an information processing apparatus, authentication information of a user of the information processing apparatus; a request unit that requests an authentication server to authenticate the user; an acquisition unit that, when the authentication server successfully authenticates the user, acquires an attribute value of the user from the authentication server; and a setting unit that sets a user name of the user on the basis of the attribute value according to a setting rule selected from a plurality of setting rules.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an image forming apparatus, an information processing apparatus, and a control method and program therefor. [Background technology]

[0002] In recent years, authentication services have been provided that centrally manage user accounts for organizations such as companies and schools and have user authentication functions. Some authentication services also have the function of registering and managing personal computers within a company on a tenant or domain basis. For example, a user registered with Microsoft's "Microsoft Entra ID" can log in to a personal computer running Windows using a user account managed by "Microsoft Entra ID." Patent Document 1 describes an image forming apparatus that performs user authentication using an authentication service. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Japanese Patent Application Publication No. 2024-7209 Summary of the Invention [Problem to be solved by the invention]

[0004] When an information processing device and an image forming device each perform user authentication using an authentication server, the username representing the user currently logged in to the information processing device may not match the username representing the user currently logged in to the image forming device. In such cases, the image forming device may not be able to correctly associate the user currently logged in to the image forming device with the user who submitted a print job to the image forming device, which may cause inconvenience to the user. Some aspects of the present invention aim to provide a technology for suppressing username mismatches between the image forming device and the information processing device. [Means for solving the problem]

[0005] According to some embodiments, an image forming apparatus is provided, comprising: a receiving means for receiving authentication information of a user of an information processing device from the information processing device; a requesting means for requesting authentication of the user from an authentication server; an acquiring means for acquiring attribute values ​​of the user from the authentication server if authentication of the user by the authentication server is successful; and a setting means for setting a username of the user based on the attribute values ​​in accordance with a setting rule selected from a plurality of setting rules. [Effects of the Invention]

[0006] According to the above embodiment, mismatches in user names between the image forming apparatus and the information processing apparatus are suppressed. [Brief explanation of the drawings]

[0007] [Figure 1] FIG. 1 is a block diagram illustrating an example of the configuration of a system according to a first embodiment. [Figure 2] FIG. 2 is a block diagram illustrating an example of hardware of components of the system according to the first embodiment. [Figure 3] FIG. 2 is a block diagram illustrating an example of software for components of the system according to the first embodiment. [Figure 4] FIG. 3 is a schematic diagram illustrating an example of a setting page according to the first embodiment. [Figure 5] FIG. 3 is a schematic diagram illustrating an example of a setting page according to the first embodiment. [Figure 6] FIG. 3 is a schematic diagram illustrating an example of a setting page according to the first embodiment. [Figure 7] FIG. 3 is a schematic diagram illustrating an example of a setting page according to the first embodiment. [Figure 8] FIG. 3 is a schematic diagram illustrating an example of a property screen according to the first embodiment. [Figure 9] FIG. 4 is a flowchart illustrating an example of a method for setting a user name of a PC according to the first embodiment. [Figure 10] FIG. 4 is a flowchart illustrating an example of the operation of the printer driver according to the first embodiment. [Figure 11]FIG. 3 is a flow diagram illustrating an example of a login method for the MFP according to the first embodiment. [Figure 12] FIG. 4 is a sequence diagram illustrating an example of a method for synchronizing setting rules according to the first embodiment. [Figure 13] FIG. 10 is a schematic diagram illustrating an example of a setting screen according to the second embodiment. [Figure 14] FIG. 10 is a flowchart illustrating an example of an operation of authenticated printing according to the second embodiment. [Figure 15] FIG. 10 is a flowchart illustrating an example of an operation of authenticated printing according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0008] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the scope of the invention claimed. Although multiple features are described in the embodiments, not all of these multiple features are necessarily essential to the invention, and multiple features may be combined arbitrarily. Furthermore, in the accompanying drawings, the same reference numerals are used to designate the same or similar components, and redundant explanations will be omitted.

[0009] First Embodiment [System Configuration] An example configuration of a system 100 according to the first embodiment will be described with reference to Fig. 1. The system 100 includes an MFP (Multifunction Peripheral) 101, an authentication server 102, and a PC (Personal Computer) 103. Although Fig. 1 shows one MFP 101, one authentication server 102, and one PC 103, the system 100 may include a plurality of MFPs 101, a plurality of authentication servers 102, and a plurality of PCs 103. The multiple MFPs 101 included in the system 100 may have the same configuration or different configurations. The same applies to the multiple authentication servers 102 and the multiple PCs 103.

[0010] The MFP 101 is an image forming device that has multiple main functions, such as copying, printing, and scanning. The MFP 101 is an example of an image forming device. The system 100 may include other image forming devices, such as dedicated printers, instead of the MFP 101. The following description of the MFP 101 also applies to other image forming devices.

[0011] The authentication server 102 is a device that provides an authentication service for authenticating a user. The authentication server 102 may be located in a cloud environment. In this case, the authentication server 102 may be called a cloud authentication server, and the authentication service may be called a cloud authentication service.

[0012] The PC 103 is an example of an information processing device. The system 100 may include other information processing devices, such as a smartphone or a tablet computer, instead of the PC 103. The following description of the PC 103 also applies to other information processing devices. The PC 103 is used by a user to submit a print job to the MFP 101. The information processing device may also be called an information processing terminal, a user device, or a user terminal.

[0013] The MFP 101, authentication server 102, and PC 103 can communicate with each other via a network 104. The network 104 may be the Internet, a local area network, a cellular network, a private network, another network, or any combination thereof.

[0014] [MFP101 hardware configuration] With reference to Fig. 2(a), a description will be given of the hardware configuration of the MFP 101. The MFP 101 may not include some of the components shown in Fig. 2(a), or may include components not shown in Fig. 2(a).

[0015] The CPU (Central Processing Unit) 201 is a processor that controls the overall operation of the MFP 101. The MFP 101 may include another processor, such as a microprocessor, instead of or in addition to the CPU 201. The ROM (Read Only Memory) 202 is a non-volatile memory. The ROM 202 stores a boot program for the MFP 101 and the like. The RAM (Random Access Memory) 203 is a volatile memory. The RAM 203 is used as a temporary storage area (work area) for expanding various control programs stored in the ROM 202 and the HDD (Hard Disk Drive) 204. The HDD 204 is a non-volatile storage device with a larger capacity than the RAM 203. The HDD 204 stores a control program for the MFP 101, an operating system (OS), application programs, and the like.

[0016] When the MFP 101 starts up, the CPU 201 executes a boot program stored in the ROM 202. This boot program defines the process of reading out the OS stored in the HDD 204 and loading it onto the RAM 203. After executing the boot program, the CPU 201 executes the OS loaded onto the RAM 203 and controls the MFP 101. The CPU 201 also loads data used by the control program into the RAM 203.

[0017] Operations by the MFP 101 may be performed by the CPU 201 executing a program read into the RAM 203. The CPU 201 may execute the program in cooperation with another processor. At least some of the operations by the MFP 101 may be performed by a dedicated circuit (for example, a hardware circuit) such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).

[0018] The operation panel 205 is a touch-operable display (i.e., a touch screen). The printer 206 is a device that prints print data received from an external device via a communication unit 208 and digital data acquired from a scanner 207. The scanner 207 is a device that reads a paper document and generates digital data.

[0019] A communication unit 208 is a network interface for connecting to the network 104. An IC (Integrated Circuit) card reader 209 is a device for reading information used for authentication from an IC card.

[0020] [Hardware configuration of computer 200] The hardware configuration of the computer 200 will be described with reference to FIG. 2(b). The computer 200 may not include some of the components shown in FIG. 2(b), or may include components not shown in FIG. 2(b). The computer 200 may be used as the authentication server 102 or as the PC 103. In the following description, the components of the computer 200 used as the authentication server 102 will be simply referred to as the components of the authentication server 102 (for example, the CPU 211 of the authentication server 102). The same applies to the PC 103.

[0021] The CPU 211, ROM 212, RAM 213, HDD 214, and communication unit 217 may be similar to the CPU 201, ROM 202, RAM 203, HDD 204, and communication unit 208, and therefore a duplicated description will be omitted.

[0022] The input control unit 215 is an input interface that controls input devices of the computer 200, such as a mouse, keyboard, and touchpad. The input control unit 215 acquires inputs made by a user to the input devices. The input devices may be external devices of the computer 200, or may be built into the computer 200.

[0023] The output control unit 216 is an output interface that controls output devices of the computer 200, such as a display and a speaker. The output control unit 216 controls the output devices to output information to the user. The output devices may be external devices to the computer 200, or may be built into the computer 200.

[0024] [Software configuration of authentication server 102] With reference to Fig. 3(a), the software configuration of the authentication server 102 will be described. The authentication server 102 may not include some of the components shown in Fig. 3(a), or may include components not shown in Fig. 3(a).

[0025] The authentication server 102 centrally manages user accounts (authentication information and user information) of contracted tenants (organizations such as companies and schools). The authentication server 102 has a function for authenticating users. The authentication server 102 is a server that provides authentication services such as Microsoft Entra ID (formerly known as Azure Active Directory) from Microsoft, Google Workspace (registered trademark) from Google, and Okta from Okta. The authentication server 102 is also called an IdP (identity provider). The authentication server 102 identifies tenants by tenant IDs and tenant names. The tenant names are also called domain names or directory names. For example, Microsoft Entra ID uses tenant IDs and tenant names such as those shown in Table 1.

[0026] [Table 1]

[0027] The authentication server 102 has the functionality of a web service 301 for communicating with clients using the Hypertext Transfer Protocol (HTTP). The web service 301 supports authentication protocols such as OAuth 2.0, OpenID Connect, WS-Federation, SAML 2.0, and the Representational State Transfer (REST) ​​API. One REST API provided by Microsoft Entra ID from Microsoft Corporation is called the Graph API.

[0028] Furthermore, the web service 301 provides a web page written in HTML (HyperText Markup Language). A user of the PC 103 can access this web page using a web browser 312 of the PC 103. For example, a tenant administrator can use the web page provided by the web service 301 to register and manage accounts of users who belong to his or her tenant.

[0029] User management 303 is a software module that manages the account information of multiple users registered using a web page. For example, with Microsoft Entra ID, the information shown in Table 2 below can be registered as information associated with one account.

[0030] [Table 2]

[0031] The user principal name is an identifier that uniquely identifies a user. For example, Microsoft Entra ID uses a string that combines a user's name and tenant name with an @, such as "alice@tenant.example.com." A user registered in User Management 303 by a tenant administrator can access web pages or use REST APIs after authenticating themselves using the registered user principal name and password.

[0032] Information about a user, especially information about a user's characteristics or properties, is called a user attribute. A user attribute may be represented by a pair of a name and a value. The name of a user attribute may be referred to as an attribute name or a user attribute name. The value of a user attribute may be referred to as an attribute value or a user attribute value. "Attribute name" in Table 2 is the name of the user attribute. The attribute name indicates the type of attribute value.

[0033] A tenant administrator can create and manage user groups using a web page. User group management 304 is a software module that manages information about registered user groups. In addition, a tenant administrator can register and manage information about applications using a web page. An application is a client that accesses the authentication server 102. An application may be a cloud service provided by another server, an application installed on a mobile terminal, or a service or application that runs on the MFP 101. Application management 305 manages registered application information using a web page. Table 3 shows an example of application information.

[0034] [Table 3]

[0035] The application ID is an identifier that uniquely identifies the application. The secret is a password used to authenticate that the client is a valid client. The application ID and secret may be used as the client_id and client_secret described in "2.3.1. Client Password" of RFC6749, "The OAuth 2.0 Authorization Framework."

[0036] It may be possible to register REST APIs that can be used by applications that have been successfully authenticated as the application's access permissions. For example, User.ReadAll indicates that all user information can be read. User.ReadWriteAll indicates that all user information can be read and written. Group.ReadAll indicates that all user group information can be read.

[0037] The authentication and authorization service 302 refers to data registered in user management 303, user group management 304, and application management 305, and authenticates users and clients accessing the web service 301. If the authentication is successful, the authentication and authorization service 302 grants access permission to the users and clients.

[0038] [PC103 software configuration] With reference to Fig. 3(b), a description will be given of the software configuration of the PC 103. The PC 103 may not include some of the components shown in Fig. 3(b), or may include components not shown in Fig. 3(b).

[0039] The PC 103 has an OS 311, a web browser 312, and a printer driver 313. In this embodiment, the case where the OS 311 is Windows will be described. This embodiment can also be implemented with other OSs. The web browser 312 accesses a web page provided by the web service 301 of the authentication server 102.

[0040] The printer driver 303 includes a user management module 314 and a print management module 315. The user management module 314 is a software module that manages user information. The print management module 315 is a software module that manages print jobs. The printer driver 303 may be a driver that is additionally installed in the OS 311, or may be a driver that the OS 311 includes as standard.

[0041] [MFP101 software configuration] With reference to Fig. 3(c), a description will be given of the software configuration of the MFP 101. The MFP 101 may not include some of the components shown in Fig. 3(c), or may include components not shown in Fig. 3(c).

[0042] A local UI (User Interface) 321 provides a user interface to be displayed on the operation panel 205. The local UI 321 includes a menu for the user to select a function, an application, a UI platform that controls screen transitions, etc. For example, the MFP 101 has a copy application that controls the printer 206 and scanner 207 to provide the user with a copy function, and an application that controls the scanner 207 and communication unit 208 to provide a function for transmitting scanned documents.

[0043] The remote UI 323 has an HTTP server function. The remote UI 323 provides the user with a web page written in HTML as a user interface. A user of the MFP 101 (for example, an administrator) can access the remote UI 323 using a web browser 312 on the PC 103 to change the settings and use the functions of the MFP 101.

[0044] The login service 324 is a software module that authenticates a user who uses the local UI 321 or the remote UI 323. The login service 324 has a web browser function 325. The web browser function 325 can render a web page written in HTML and display it on the operation panel 205 as part of the login screen. The web browser function 325 may be WebKIT or the like. The function in which the application itself displays a web page may be called WebView.

[0045] The IC card reader driver 322 is a driver that controls the IC card reader 209. The IC card reader driver 322 acquires information from the IC card and provides this information to the login service 324. The print service 326 receives a print job sent from the PC 103 and executes printing in accordance with this print job.

[0046] [Login Service] Settings related to the login function of MFP 101 and functions provided by login service 324 will be described with reference to FIGS.

[0047] 4 shows an example of a setting page 400 for configuring settings related to the login function provided by the login service 324. The setting page 400 is a web page provided by the remote UI 323. The setting page 400 is displayed on a display device of a computer that remotely accesses the MFP 101. Values ​​configured using the setting page 400 are stored in the HDD 204 of the MFP 101. The login service 324 reads settings related to the login function from the HDD 204 and determines the behavior of the login service 324 in accordance with the configured values.

[0048] Area 401 contains objects for setting a login method for the local UI 321. In the following description of the screen, the object refers to a graphic object. Area 401 allows selection of "keyboard authentication" or "IC card authentication" as the login method. Keyboard authentication is a login method that authenticates a user with a username and password. IC card authentication is a login method that authenticates a user using an IC card owned by the user. When keyboard authentication is enabled, the login service 324 displays a keyboard authentication screen 600 shown in FIG. 6 on the operation panel 205. When IC card authentication is enabled, the login service 324 displays an IC card authentication screen 610 shown in FIG. 6 on the operation panel 205. When both "keyboard authentication" and "IC card authentication" are enabled, the keyboard authentication screen 600 and the IC card authentication screen 610 are switchably displayed. For example, the keyboard authentication screen 600 includes a button 602 for transitioning to the IC card authentication screen 610. The IC card authentication screen 610 includes a button 611 for transitioning to the keyboard authentication screen 600.

[0049] Area 402 contains an object for setting the authentication execution entity (authentication destination). In area 402, "local" or "server" can be selected as the authentication execution entity. If "local" is selected, authentication is performed using a user account stored in HDD 204. For example, login service 324 stores and manages user accounts in a user count table such as that shown in Table 4. The user count table is a database stored in HDD 204. The user count table includes user names, passwords, card IDs used for IC card authentication, roles, email addresses, etc.

[0050] [Table 4]

[0051] "Role" is information indicating a user's usage rights for the MFP 101. Examples of roles and usage rights are shown in Table 5 below. In addition to the role definitions that the MFP 101 has when shipped from the factory, a user may be able to set detailed usage rights and create new roles.

[0052] [Table 5]

[0053] When "Server" is selected in area 402, authentication is performed by the authentication server 102. In area 402, the type of server that will perform authentication can also be selected. In the example of FIG. 4, the server can be selected from "LDAP Server," "Active Directory," "Google Workspace," and "Microsoft Entra ID." Furthermore, detailed server information can be set by pressing the setting button for each server.

[0054] For example, when button 403 for setting "Microsoft Entra ID" is pressed, setting page 500 of FIG. 5 is displayed. Setting page 500 is a web page for setting information used for linking with Microsoft Entra ID. Input field 501 ("Display name of authentication target") is an object for acquiring from the user a character string for identifying the authenticating entity. The character string designated by the user is displayed in "Authentication target" on keyboard authentication screen 600. Input field 502 ("Tenant name") is an object for acquiring from the user a tenant name. For example, the same value as the tenant name in Table 1 is set in input field 502. Input field 503 ("Application ID") is an object for acquiring from the user a designation of an application ID. For example, the same value as the "Application ID" in Table 3 is set in input field 503. Input field 504 ("Secret") is an object for acquiring from the user a secret designation. For example, the same value as the "Secret" in Table 3 is set in input field 504.

[0055] Input field 505 is an object for acquiring from the user the specification of the user attribute of the Microsoft Entra ID that stores the ID of the IC card. The attribute names in Table 2 are used to specify the user attribute of the Microsoft Entra ID. For example, if the employee ID stored in the IC card is used for authentication, "employeeId" is set in object 505. "employeeId" may also be used as an area for storing the ID (serial number) of the IC card.

[0056] Pull-down list 506 is an object for acquiring from the user the specification of a user attribute to be used for the login user name after login. In the example of FIG. 5, pull-down list 506 is a pull-down list including four candidates. Instead of pull-down list 506, an input field into which the user can input any character string may be used. The options in pull-down list 506 include "WindowsLogonName", "displayName", "userPrincipalName", and "userPrincipalName-Prefix".

[0057] Each of the multiple options in pull-down list 506 represents a setting rule for setting a login user name for a user of MFP 101. Each setting rule includes a type of user attribute value used to set the login user name and a setting regarding whether to process the user attribute value. If it is set that the user attribute value is to be processed, the setting rule further includes a method for processing the user attribute value. The user attribute value used to set the login user name is acquired from authentication server 102.

[0058] Table 6 below shows the relationship between the setting rules selectable in the pull-down list 506, the types of user attributes used, and the methods of processing attribute values.

[0059] [Table 6]

[0060] Among the options in the pull-down list 506, "displayName" and "userPrincipalName" are setting rules that set the user attribute value stored in the authentication server 102 (for example, Microsoft Entra ID) as the login user name without modification. Among the options in the pull-down list 506, "WindowsLogonName" and "userPrincipalName-Prefix" are setting rules that set the value obtained by processing the user attribute value stored in the authentication server 102 (for example, Microsoft Entra ID) as the login user name. Setting rules that process user attribute values ​​in this way are referred to as custom setting rules.

[0061] "WindowsLogonName" and "userPrincipalName-Prefix" are built-in setting rules pre-implemented in the MFP 101. In the example of Table 7, when the custom setting rule "WindowsLogonName" is selected, the MFP 101 acquires the value of the user attribute "displayName" from the Microsoft Entra ID, processes this value according to the processing method in Table 7, and uses the resulting value as the login user name. The processing method may include at least one of deleting a specific type of character from the user attribute value, extracting a portion before the specific type of character from the user attribute value, and deleting a portion of the user attribute value that exceeds a threshold number of characters.

[0062] For example, assume that the user attributes shown in Table 7 below are set for one user account on Microsoft Entra ID.

[0063] [Table 7]

[0064] Table 8 below shows the login user names used in MFP 101 when each of the options in pull-down list 506 is selected.

[0065] [Table 8]

[0066] If "userPrincialName" is selected, the value of the Microsoft Entra ID user attribute "userPrincialName" is used as is. If "displayName" is selected, the value of the Microsoft Entra ID user attribute "displayName" is used as is. If "windowsLogonName" is selected, the value obtained by removing spaces from the value of the Microsoft Entra ID user attribute "displayName" is used. If "userPrincialName-Prefix" is selected, the part before the @ character in the value of the Microsoft Entra ID user attribute "userPrincialName" is used.

[0067] A user of the MFP 101 may be able to edit an existing custom setting rule or create a new custom setting rule. For example, the MFP 101 displays an edit screen 510 on the operation panel 205 in response to pressing a button 507 on the setting page 500.

[0068] Input field 511 is an object for acquiring from the user the name of a custom setting rule. When creating a new custom setting rule, the user (e.g., an administrator of MFP 101) can specify any character string that does not overlap with existing user attributes. Input field 512 is an object for acquiring from the user the name of a user attribute to be acquired from authentication server 102 (e.g., Microsoft Entra ID). Area 513 is arranged with objects for acquiring from the user the specification of a method for processing attribute values ​​acquired from authentication server 102. In the example of FIG. 5, the user can specify whether to delete half-width spaces, whether to delete characters following @, and the type of symbols to delete. The example of FIG. 5 is not limited to this, and MFP 101 may also be able to acquire the specification of the processing method using, for example, regular expressions. MFP 101 creates a new setting rule based on the user's input to edit screen 510 and adds this new setting rule to the existing setting rules. As a result, this selection rule is displayed as a choice in pull-down list 506.

[0069] [Print service] 7, the settings related to the print function of the MFP 101 and the functions provided by the print service 326 will be described. The print service 326 controls print jobs sent from the printer driver 303.

[0070] 7 shows an example of a setting page 700 for configuring settings related to the print function provided by the print service 326. The setting page 700 is a web page provided by the remote UI 323. The setting page 700 is displayed on a display device of a computer that remotely accesses the MFP 101. Values ​​configured using the setting page 700 are stored in the HDD 204 of the MFP 101. The print service 326 reads the settings related to the print function from the HDD 204 and determines the behavior of the print service 326 in accordance with the configured values.

[0071] The print service 326 has a function to temporarily store and reserve a print job sent from the printer driver 303 in the HDD 204 or RAM 203. This function is called a forced reservation function. An object 701 acquires a designation from the user as to whether to enable or disable the forced reservation function. Instead of being reserved in the MFP 101, the print job may be reserved in an external device such as a print server.

[0072] When the forced reservation function is enabled, the MFP 101 does not immediately execute a print job received from the PC 103, but instead stores the print job in the HDD 204 or RAM 203. When a user logs in to the MFP 101 and issues an instruction to display a list of print jobs, the MFP 101 displays a list of print jobs having a job owner name that matches the login user name of the user currently logged in to the MFP 101, as shown on screen 630 in FIG. 6. When a displayed print job is selected and the print button is pressed, the MFP 101 executes printing in accordance with the selected print job. When the forced reservation function is disabled, the MFP 101 immediately executes printing in accordance with the acquired print job.

[0073] Object 702 acquires from the user a designation as to whether the authentication printing function is enabled or disabled. If the authentication printing function is enabled, MFP 101 rejects printing according to a print job that does not include authentication information or a print ticket. If the authentication printing function is disabled, MFP 101 executes printing regardless of whether the print job includes authentication information or a print ticket.

[0074] [Printer driver operation] The operation of the printer driver 313 of the PC 103 will be described with reference to FIGS. 8 to 10. FIG. 8 shows an example of a property screen 800 for configuring settings related to the print function provided by the printer driver 313. The property screen 800 is displayed on the display device of the PC 103. Values ​​configured using the property screen 800 are stored in the HDD 214 of the PC 103. The printer driver 313 reads settings related to the print function from the HDD 214 and determines the behavior of the printer driver 313 in accordance with the configured values. In order to display the property screen 800, the user of the PC 103 may be required to log on to the PC 103. Logging on to the PC 103 may be performed using a user account stored in the PC 103, or may be performed using the authentication server 102.

[0075] In response to a button 802 on the property screen 800 being pressed, the user management 314 displays a setting screen 810 for setting user information. A display field 811 shows the currently set user name. An area 812 contains an object for acquiring from the user the setting rule designation for setting the user name. The user can select one of three setting rules: "Logon Name," "Computer Name," and "Name Setting."

[0076] When "Logon Name" is selected, the user can select a setting rule for setting a user name from multiple setting rules. In the example of FIG. 8, the pull-down list 813 allows the user to select a setting rule from four setting rules. When "Computer Name" is selected, the computer name of PC 103 is specified as the user name. When "Name Setting" is selected, the character string entered by the user in input field 814 is specified as the user name.

[0077] Each of the multiple setting rules selectable in pull-down list 813 includes a setting for the type of user attribute value used to set a user name and whether to process the user attribute value. If it is set that the user attribute value is to be processed, the setting rule further includes a method for processing the user attribute value. The user attribute value used to set a user name is acquired from OS 311. As with the setting rules of MFP 101 described above, setting rules for processing user attribute values ​​of PC 103 are referred to as custom setting rules.

[0078] The relationship between the setting rules selectable in the pull-down list 813, the types of user attributes used, and the method of processing attribute values ​​is shown in Table 9 below. The explanation of Table 9 is the same as that of Table 6, so duplicate explanations will be omitted.

[0079] [Table 9]

[0080] FIG. 9 illustrates the operation of printer driver 313, which is executed when button 815 is pressed after a setting rule for setting a user name has been specified in area 812 of setting screen 810. Using the method of FIG. 9, printer driver 313 sets a user name according to the user's specification. The method of FIG. 9 is defined in the software programs of printer driver 313 and OS 311. The software programs are stored in non-volatile storage, such as ROM 212 or HDD 214 of PC 103, loaded into RAM 213, and executed by CPU 211. Furthermore, printer driver 313 and OS 311 mutually provide APIs (Application Programming Interfaces) and cooperate by mutually using the APIs. In the description of FIG. 9, the calling of APIs will be omitted.

[0081] In S901, the user management 314 identifies the setting rule specified in the area 812. If a "logon name" is specified, the user management 314 transitions the process to S904, if a "computer name" is specified, the process to S903, and if a "name specification" is specified, the process to S902.

[0082] In S902, the user management 314 sets the character string entered in the input field 814 as the user name and displays this user name in the display field 811. In S903, the user management 314 acquires the computer name of the PC 103, sets this computer name as the user name, and displays this user name in the display field 811.

[0083] In S904, the user management 314 determines whether a custom setting rule has been selected as the setting rule for the logon name in the pull-down list 813. If it is determined that a custom setting rule has been selected ("YES" in S904), the user management 314 transitions the process to S906, and otherwise ("NO" in S904), the user management 314 transitions the process to S905.

[0084] The options in the pull-down list 813 include a setting rule that sets the user attribute value as the username as is, and a setting rule that sets a value obtained by processing the user attribute value as the username (i.e., a custom setting rule). In the example of Fig. 8, "the left side of @ in the user principal name" is a custom setting rule, and the other options are not custom setting rules.

[0085] In S905, the user management 314 uses the API of the OS 311 to obtain the attribute value of the logged-in user ("Windows logon name," "display name," or "user principal name") from the OS 311 in accordance with the logon name obtaining method selected in the pull-down list 813.

[0086] When a user logs in to OS 311 using a user account on authentication server 102, OS 311 sets a logon name based on a user attribute value obtained from authentication server 102. For example, assume that authentication server 102 is "Microsoft Entra ID" and OS 311 is "Windows." In this case, the user attribute "userPrincipalName" is used to log in to OS 311. This user attribute is a unique identifier on the Internet and is formed in a format similar to an email address, such as username@tenant.example.com. After the user logs in to OS 311, OS 311 uses a Windows logon name to identify the user. OS 311 obtains the value of the user attribute "displayName" from authentication server 102 and sets the resulting value as the Windows logon name by processing this value. The type of processing depends on the type of OS. For example, in Windows, "half-width spaces," "certain symbols," and "character strings following the @ character" are deleted.

[0087] When "Windows logon name" is selected, the user management 314 obtains the Windows logon name generated as described above from the OS 311 and sets this value as the user name as is. The "Windows logon name" can be obtained using the GetUserName function provided by Windows. When "display name" is selected, the user management 314 obtains the display name from the OS 311 and sets this value as the user name as is. The "display name" can be obtained using the GetUserNameEx function provided by Windows. When "user principal name" is selected, the user management 314 obtains the user principal from the OS 311 and sets this value as the user name as is. The user management 314 sets the obtained attribute value as the user name and displays this user name in the display field 811. Whether the PC 103 is linked to a Microsoft Entra ID can be confirmed using the NetGetAadJoinInformation function provided by Windows. The printer driver 313 may make it impossible to select "display name," "user principal name," and "left side of @ in user principal name" in the pull-down list 813 if Windows is not configured to work with Microsoft Entra ID.

[0088] In S906, the user management 314 acquires the attribute value ("user principal name") of the currently logged-in user from the OS 311 using the API of the OS 311 according to the logon name acquisition method selected in the pull-down list 813. In S907, the user management 314 processes the acquired attribute value according to the processing method, stores the value obtained as the user name, and displays this user name in the display field 811. For example, "the left side of the @ in the user principal name" specifies that processing should be performed to extract the part before the @ in the user principal name.

[0089] In this way, the user name is set according to the setting rules specified by the user and stored for subsequent processing.

[0090] 10 illustrates the operation of the printer driver 313, which is executed in response to receiving a print execution instruction from a user of the PC 103 (hereinafter simply referred to as the user in the method of FIG. 10). In S1001, the print manager 315 generates a print job in accordance with the instruction from the user. The print job can include print data for a print mode and settings for printing the print data.

[0091] In S1002, the print management 315 determines whether the user information settings are valid. The print management 315 determines that the user information settings are valid when the check box 801 on the property screen 800 is checked. If the print management 315 determines that the user information settings are valid ("YES" in S1002), it transitions the process to S1003, and otherwise ("NO" in S1002), it transitions the process to S1004.

[0092] In S1003, the print management 315 assigns the user name set by the method of Fig. 9 to the print job generated in S1001. For example, the print management 315 sets the user name set by the method of Fig. 9 as the owner name of the print job generated in S1001. As a result, a print job having the user name set by the method of Fig. 9 is generated. If S1003 is not executed, the owner name of the print job does not need to be set, or the "Windows logon name" may be set. In S1004, the print management 315 sends the generated print job to the MFP 101. Alternatively, the print management 315 may send the print job to a print server, and the MFP 101 may obtain the print job from the print server.

[0093] [Login service operation] The operation of the login service 324 of the MFP 101 will be described with reference to FIG. 11. The method of FIG. 11 is defined in the software programs of the local UI 321, remote UI 323, login service 324, and IC card reader driver 322. The software programs are stored in non-volatile storage, such as the ROM 202 or HDD 2p4 of the MFP 101, loaded into the RAM 203, and executed by the CPU 201. The software programs, such as the local UI 321, remote UI 323, login service 324, and IC card reader driver 322, mutually provide APIs and cooperate by using the APIs. In the description of FIG. 11, the calling of APIs will be omitted. The method of FIG. 11 may be started in response to the power-on of the MFP 101 or in response to a user instruction to display the keyboard authentication screen 600 of FIG. 6. In the method of FIG. 11, a user logs in to the MFP 101 using an account on the authentication server 102 (e.g., Microsoft Entra ID).

[0094] In S1101, the login service 324 displays the keyboard authentication screen 600 on the operation panel 205. In S1102, the login service 324 determines whether an instruction to start the login process has been received from the user of the MFP 101 (hereinafter simply referred to as the user in the description of FIG. 11). If it is determined that an instruction to start the login process has been received (YES in S1102), the login service 324 transitions the process to S1103; otherwise (NO in S1102), the login service 324 repeats S1102. The login service 324 may determine that an instruction to start the login process has been received based on the pressing of a button 603 on the keyboard authentication screen 600. In the following description, it is assumed that Microsoft Entra ID is selected as the "authentication destination" in the pull-down list 601 on the keyboard authentication screen 600. The same description applies when another type of authentication server 102 is selected as the "authentication destination."

[0095] In S1103, the login service 324 requests the authentication server 102 (Microsoft Entra ID) to authenticate the user based on the information entered by the user on the keyboard authentication screen 600. Specifically, the login service 324 sends an authentication request including the username and password entered on the keyboard authentication screen 600 to the authentication server 102. For example, the value of the user attribute "userPrincialName" is entered as the username.

[0096] The authentication request may be made using the Access Token Request described in "4.3. Resource Owner Password Credentials Grant" in RFC 6749, "The OAuth 2.0 Authorization Framework." For example, the information in Table 10 below may be sent to a predetermined URL of the authentication server 102 by HTTP POST.

[0097] [Table 10]

[0098] "Scope" indicates the range of resources that can be accessed using the access token generated upon successful authentication. The login service 324 specifies the scope required to obtain a user profile (user attributes) such as an email address using the REST API.

[0099] In S1104, the login service 324 determines whether the authentication was successful based on the response from the authentication server 102. If the login service 324 determines that the authentication was successful ("YES" in S1104), the process proceeds to S1106, and otherwise ("NO" in S1104), the process proceeds to S1105. For example, the login service 324 determines that the authentication was successful when it receives an access token from the authentication server 102 in response to the request sent in S1103. The login service 324 determines that the authentication was unsuccessful when it receives an error from the authentication server 102 in response to the request sent in S1103, indicating that matching of the username or password failed.

[0100] If it is determined that the authentication has failed, in S1105 the login service 324 notifies the user that the authentication has failed. For example, the login service 324 displays an error message on the operation panel 205 indicating that the user name or password entered on the keyboard authentication screen 600 is invalid.

[0101] The processing from S1106 onwards is executed when it is determined that the authentication of the user by the authentication server 102 has been successful. In S1106, the login service 324 determines the type of user attribute value to be acquired from the authentication server 102, and acquires that type of user attribute value from the authentication server 102. Specifically, the login service 324 determines the type of user attribute value to be acquired from the authentication server 102 based on the setting rule specified in the pull-down list 506 on the setting page 500. The type of user attribute value to be acquired from the authentication server 102 for each setting rule specified in the pull-down list 506 is as described above with reference to Table 6.

[0102] The login service 324 requests the user attribute values ​​of the type determined in this manner from the authentication server 102. Specifically, the login service 324 uses the access token acquired in S1104 to access the REST API of the authentication server 102 and requests the user attribute values. The login service 324 may acquire only user attribute values ​​of a specific type, or may acquire all user attribute values ​​that can be acquired. For example, the login service 324 may be able to acquire the user attribute values ​​shown in Table 2 above from the authentication server 102. For example, the login service 324 can store the access token in an HTTP Authorization header and send a GET request to a URL for a specific REST API, thereby receiving the user attribute values ​​of Table 2 in response.

[0103] In S1107, the login service 324 determines whether the setting rule specified in the pull-down list 506 of the setting page 500 is a custom setting rule. If it is determined to be a custom setting rule ("YES" in S1107), the login service 324 transitions the process to S1108, and otherwise ("NO" in S1107), the login service 324 transitions the process to S1109. In S1108, the login service 324 processes the user attribute value acquired in S1106 in accordance with the processing method. The method of processing the user attribute value is as described above with reference to Table 6.

[0104] In S1109, the login service 324 instantiates a structure (hereinafter referred to as a login context) that stores information about the currently logged-in user. Table 11 below shows an example of user information included in the login context.

[0105] [Table 11]

[0106] The login user name is the value obtained by processing in S1108 if S1108 is executed, and is the user attribute value acquired in S1106 if S1108 is not executed. The example in Table 11 shows a case where the setting rule "windowsLogonName" is specified in the pull-down list 506. In this case, "John Smith", which is the value of the user attribute "displayName", is acquired from the authentication server 102 according to Table 6. After that, "JohnSmith", which is obtained by removing half-width spaces included in "John Smith" according to the processing method, becomes the login user name.

[0107] The "role" of the user information may be determined based on, for example, the job title (jobTitle) of the user attributes acquired from the authentication server 102, or may be determined based on user group information to which the user belongs acquired from the authentication server 102. The MFP 101 may have a function for setting the relationship between the user information that can be acquired from the authentication server 102 and the role of the MFP 101.

[0108] In S1110, the login service 324 uses the login context generated in S1109 to execute login processing for the MFP 101, thereby logging the user in to the MFP 101. Specifically, the login service 324 notifies the local UI 321 of the login context via the API. In response to the notification of the login context, the local UI 321 detects that the user has logged in to the MFP 101, closes the keyboard authentication screen 600 on the operation panel 205, and displays the menu screen 620. The menu screen 620 and screens that can be transitioned from it (for example, a list screen 630 and a status and history screen 640) are displayed while the user is logged in to the MFP 101.

[0109] In response to the user pressing button 621 on menu screen 620, local UI 321 displays list screen 630. List screen 630 includes a list of print jobs that have a job owner name that matches the login user name included in the login context and that are reserved in MFP 101. Local UI 321 identifies print jobs that have the login user name of MFP 101 as print jobs of the user currently logged in to MFP 101, and includes them in the list of print jobs.

[0110] For example, as in the example above, assume that the login user name included in the login context is "JohnSmith." When "Windows logon name" is specified in the pull-down list 813 of the printer driver 313 of the PC 103, the owner name of the print job also becomes "JohnSmith." Therefore, the MFP 101 can correctly associate the user currently logged in to the MFP 101 with the user who submitted the print job to the MFP 101, using the login user name of the user of the MFP 101. Specifically, the list screen 630 displays print jobs to which the PC 103 has assigned the same user name as the login user name of the MFP 101. When a print job is selected from the list screen 630 and a button 631 is pressed, the print service 326 of the MFP 101 executes printing in accordance with the print job.

[0111] In response to the user pressing button 622 on menu screen 620, local UI 321 displays status / history screen 640. The owner name of each print job included in status / history screen 640 is displayed as the user name for each print job. Meanwhile, the login user name of MFP 101 is displayed as the user name for each copy job included in status / history screen 640. By matching the owner name of the print job (i.e., the user name of PC 103) with the login user name of MFP 101, it becomes possible to correctly tally jobs executed by MFP 101 for each user.

[0112] In the above-described method, at least one of the setting rules for MFP 101 and PC 103 is specified so that the login user name of MFP 101 is the same as the user name of PC 103. The setting rule for MFP 101 is specified by a user (e.g., an administrator) of MFP 101. The setting rule for PC 103 is specified by a user of PC 103. However, specifying the setting rule can be cumbersome, and there is a possibility that an error in specifying the setting rule may occur. Therefore, the setting rule for MFP 101 and the setting rule for PC 103 may be synchronized using the method of FIG. 12. The method of FIG. 12 may be started, for example, when a user of PC 103 presses button 803 on property screen 800. Alternatively, the method of FIG. 12 may be executed when an installer for printer driver 313 installs printer driver 313 for MFP 101. The installer for printer driver 313 can access a setting file or registry of printer driver 313 to change the initial setting values.

[0113] In S1201, the print management 315 of the PC 103 requests the MFP 101 for the setting rule set in the MFP 101. In S1202, in response to this request, the MFP 101 transmits the setting rule set in the MFP 101 to the PC 103. The communications in S1201 and S1202 may be performed using HTTP such as SOAP or REST, SNMP, or a protocol unique to the vendor of the MFP 101. In this manner, the print management 315 of the PC 103 acquires the setting rule used by the MFP 101 to set the login user name of the user of the MFP 101. In S1201, the entire configuration information of the MFP 101 may be requested, and in S1202, the setting rule may be transmitted as part of the configuration information of the MFP 101 (including, for example, information such as the setting values ​​of the MFP 101 and the installation status of options).

[0114] As described above, the setting rule includes the type of user attribute value used to set the login user name and a setting regarding whether to process the user attribute value. If it is set that the user attribute value is to be processed, the setting rule further includes a method for processing the user attribute value. If the type of user attribute value used to set the login user name differs depending on the type of authentication server 102, MFP 101 may also transmit the type of authentication server 102 to PC 103.

[0115] In step S1203, the print management 315 of the PC 103 selects a setting rule to be used to set the user name of the PC 103 from the multiple setting rules of the PC 103, based on the setting rule acquired from the MFP 101. For example, if Microsoft Entra ID is used as the authentication server 102 and a setting rule that uses the user attribute "userPrincipalName" as is is acquired, the PC 103 selects "User Principal Name" in the pull-down list 813 from the multiple setting rules selectable in the area 812. In this way, the PC 103 selects a setting rule so that the user name set on the PC 103 matches the login user name set on the MFP 101. If it is notified that server authentication will not be performed or if the type of user attribute included in the acquired setting rule is unknown, the PC 103 may select the default "Windows logon name."

[0116] 9 using the setting rule selected in step S1203, the PC 103 sets the user name of the PC 103. The user name set in this manner matches the login user name set by the MFP 101.

[0117] 12 may be executed for each MFP 101. Specifically, PC 103 may select an individual setting rule for each of the multiple MFPs 101 from the multiple setting rules selectable in area 812.

[0118] In the above-described embodiment, information about MFP 101 is acquired by PC 103 without going through the print server. Alternatively, information about MFP 101 may be acquired by PC 103 via the print server. For example, the print server may store information about MFP 101, and PC 103 may acquire the information about MFP 101 stored in the print server. Also, in the above-described embodiment, a print job generated by PC 103 is sent to MFP 101 without going through the print server. Alternatively, a print job generated by PC 103 may be sent to MFP 101 via the print server. For example, PC 103 submits a print job to a logical printer managed by the print server. MFP 101 may acquire a print job associated with a logical printer associated with itself.

[0119] [Effects of the first embodiment] In the above-described embodiment, in an environment in which the MFP 101 and the PC 103 can each authenticate a user using the authentication server 102, the login user name of the MFP 101 can be made to match the user name of the PC 103. This improves user convenience. Specifically, when Microsoft Entra ID is used as the authentication server 102, the MFP 101 can obtain the attribute value of the displayName from the authentication server 102 and process it to set the same user name as the Windows logon name as the login user name of the MFP 101. This allows the MFP 101 to associate this print job generated by the PC 103 with the user currently logged in to the MFP 101, even if the owner name of the print job is the Windows logon name.

[0120] The MFP 101 can also set a login user name according to setting rules that the user creates himself / herself. This allows the MFP 101 to flexibly accommodate changes on the PC 103 side by changing the setting rules of the MFP 101, even if the rules for generating print job owner names change due to changes in the OS 311 or printer driver 313 used by the PC 103.

[0121] A "Windows logon name" and a "display name" are not unique on the Internet and may overlap with the values ​​of other users. On the other hand, a "user principal name" is unique on the Internet. In the above-described embodiment, a "user principal name" can be set for each of the MFP 101 and the PC 103, thereby preventing duplication of user names. Since a "user principal name" has more characters than a "Windows logon name" or a "display name," users may find it difficult to use. In the above-described embodiment, a setting rule for extracting the part to the left of the @ in the user principal name can also be selected. This allows a user name that is not too long and easy to use to be set while ensuring the uniqueness of the user name when operating within the same tenant (same domain).

[0122] Furthermore, in the above-described embodiment, the PC 103 has a function for automatically associating the setting rules of the MFP 101 with the setting rules of the PC 103. This makes it possible to prevent mismatches in user names between the MFP 101 and the PC 103 due to setting errors in the setting rules.

[0123] <Second embodiment> A second embodiment will be described. The following description focuses on differences from the first embodiment. Contents not described in the second embodiment may be the same as those in the first embodiment. In the second embodiment, the PC 103 assigns to the print job a user name specified by the MFP 101 when executing authenticated printing. Authenticated printing is a printing method that requires user authentication in order to submit a print job from the PC 103 to the MFP 101.

[0124] Referring to FIG. 13, an example of a setting screen 1300 for using authenticated printing is shown. The setting screen 1300 is displayed on the display device of the PC 103 by the printer driver 313. A check box 1301 is an object for acquiring from the user a designation as to whether or not to use authenticated printing. The printer driver 313 may acquire the setting of the object 702 of the MFP 101 and automatically set the check box 1301 based on this setting. An input field 1302 is an object for acquiring a user identifier from the user. For example, the user inputs a user principal name. An input field 1303 is an object for acquiring a password from the user. A pull-down list 1304 is an object for acquiring from the user a designation of the entity that will perform authentication (one of the authentication servers 102). The printer driver 313 may set the options in the pull-down list 1304 based on the "authentication destination" set in the MFP 101 using the area 402 of the setting page 400.

[0125] When a specific type of authentication server 102 (for example, Microsoft Entra ID) is selected in the pull-down list 1304, the printer driver 313 may obtain a user identifier (for example, a user principal name) used by this authentication server 102 for authentication from the OS 311 and set it in the input field 1302. The user identifier obtained by the printer driver 313 is the user identifier of the user currently logged in to the PC 103.

[0126] An example of the operation of system 100 when performing authenticated printing will be described with reference to Fig. 14. Before the method of Fig. 14 starts, a user of PC 103 (hereinafter simply referred to as a user in the description of Fig. 14) may be logged in to PC 103 locally, or may be logged in to PC 103 using authentication server 102. The method of Fig. 14 may be started in response to the user pressing button 1305 on setting screen 1300.

[0127] In S1401, the printer driver 313 acquires information specified by the user in the input field 1302, the input field 1303, and the pull-down list 1304. This information is referred to as authentication information because it is used to authenticate the user. The authentication information includes a user identifier, a password, and the designation of the authentication server 102 that will perform the authentication. In S1402, the printer driver 313 transmits the authentication information acquired in S1401 to the login service 324 of the MFP 101.

[0128] In S1403, the login service 324 of the MFP 101 requests the authentication server 102 specified in the authentication information acquired in S1402 to authenticate the user of the PC 103. This request includes the user identifier and password included in the authentication information acquired in S1402. In S1404, the login service 324 determines whether the authentication has been successful based on the response from the authentication server 102. For example, the login service 324 determines that the authentication has been successful if it receives an access token from the authentication server 102 in response to the request sent in S1103. The login service 324 determines that the authentication has been unsuccessful if it receives an error from the authentication server 102 in response to the request sent in S1103, indicating that matching of the user name or password has failed. The following describes the case where the authentication has been successful. If the authentication has been unsuccessful, the login service 324 may notify the PC 103 that the authentication has been unsuccessful.

[0129] In S1405, the login service 324 requests user attribute values ​​from the authentication server 102, similar to S1106 in Fig. 11. In S1406, the authentication server 102 responds with the requested user attribute values. In S1407, the login service 324 sets the login user name, similar to S1107 to S1109 in Fig. 11.

[0130] In S1407, the login service 324 may further determine the role of the user. The login service 324 may determine the role based on the job title (jobTitle) of the user attributes acquired from the authentication server 102. The login service 324 may acquire information about the user group to which the user belongs from the authentication server 102 and determine the role based on the user group to which the user belongs.

[0131] In S1408, the login service 324 determines the user's printing privileges based on the role determined in S1407, and generates data indicating the printing privileges. This data is referred to as a print ticket. As shown in Table 5 above, if the user is a GeneralUser, a print ticket is generated indicating that color printing, single-sided printing, and 1-in-1 printing are possible. If the user is a LimitedUser, a print ticket is generated indicating that color printing is prohibited, double-sided printing, and 2-in-1 printing are possible.

[0132] In S1409, the login service 324 transmits the login user name set in S1407 and the print ticket generated in S1408 to the printer driver 313 of the PC 103. The printer driver 313 of the PC 103 stores the login user name and print ticket received from the MFP 101 in the RAM 213 or HDD 214 of the PC 103 for subsequent processing.

[0133] In S1410, printer driver 313 of PC 103 displays to the user the login user name and the contents of the print ticket received from MFP 101 in S1409. For example, printer driver 313 displays the login user name in area 1306 of setting screen 1300, and displays the contents of the print ticket in area 1307 of setting screen 1300. Printer driver 313 may change the print settings of printer driver 313 depending on the print authority. Communication by printer driver 313 to send authentication information to MFP 101 and receive the login user name and print ticket may be performed in one round trip or multiple round trips.

[0134] In S1411, upon receiving a print execution instruction from the user to the MFP 101, the printer driver 313 of the PC 103 generates a print job in accordance with the instruction from the user. This print job is specified to be executed by the MFP 101. The print job may include print data of a print mode and settings for printing the print data. Furthermore, the printer driver 313 assigns the login user name and print ticket received from the MFP 101 in S1409 to the print job. For example, the login user name is set as the owner name of the print job. In S1412, the printer driver 313 sends this print job to the MFP 101.

[0135] In S1403, the print service 326 of the MFP 101 determines whether the print job received in S1412 includes a print ticket. If the print job does not include a print ticket, the print service 326 may cancel printing. If the print job includes a print ticket, the print service 326 determines that the user has been authenticated and executes printing in accordance with the print job. If the reservation function is enabled, the print service 326 executes printing in accordance with instructions from the user on the MFP 101. The processes of S1401 to S1409 in FIG. 14 described above may be executed every time a user print request is detected in order to update to the latest information.

[0136] Another example of the operation of system 100 when performing authenticated printing will be described with reference to Fig. 15. In the method of Fig. 15, PC 103 does not acquire a print ticket, but includes authentication information in the print job. Before the method of Fig. 15 begins, the user of PC 103 (hereinafter simply referred to as the user in the description of Fig. 15) may be logged in to PC 103 locally, or may be logged in to PC 103 using authentication server 102. It is assumed that authentication information is set by the user on setting screen 1300 before the method of Fig. 15 begins. The method of Fig. 15 is executed in response to receiving a print execution instruction from the user.

[0137] In S1501, the printer driver 313 of the PC 103 generates a print job in accordance with instructions from the user. This print job is specified to be executed by the MFP 101. The print job may include print data of a print mode and settings for printing the print data. Furthermore, the printer driver 313 assigns to the print job authentication information set on the setting screen 1300. As described above, the authentication information includes a user identifier, a password, and a designation of the authentication server 102 that will perform authentication. In S1502, the printer driver 313 sends this print job to the print service 326 of the MFP 101.

[0138] In S1503, the print service 326 of the MFP 101 confirms that authentication information has been assigned to the print job received in S1502. The print service 326 notifies the login service 324 of the assigned authentication information and requests a login user name and printing authority. In S1504 to S1508, the login service 324 sets the user's login user name and determines the user's printing authority by performing the same processing as in S1403 to S1407 of FIG. 14. In S1509, the login service 324 responds to the print service 326 with the determined login user name and printing authority.

[0139] In S1510, the print service 326 assigns the login service name acquired in S1509 to the print job received in S1502. For example, the print service 326 sets the login service name as the owner name of the print job. Alternatively, the print service 326 may manage the print job in association with the login service name. In S1511, the print service 326 executes printing in accordance with the print job in S1403. If the reservation function is enabled, the print service 326 executes printing in accordance with an instruction from the user of the MFP 101.

[0140] In the method of FIG. 15, if the print job received in S1502 does not include authentication information, or if the authentication requested in S1504 fails, the print service 326 cancels the print job.

[0141] [Effects of the second embodiment] In the above-described embodiment, the MFP 101 sets the user name of the user of the PC 103 based on the authentication information sent by the PC 103 to the MFP 101. This reduces the possibility of a mismatch in the user names between the MFP 101 and the PC 103. Also, in the above-described embodiment, the print service 326 acquires the user identifier used by the authentication server 102 from the OS 311. This saves the user the trouble of manually inputting the user identifier.

[0142] <Other embodiments> The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or device via a network or a storage medium, and having one or more processors in the computer of the system or device read and execute the program.The present invention can also be realized by a circuit (e.g., ASIC) that realizes one or more functions.

[0143] <Summary of the embodiment> (Item 1) An image forming apparatus, a receiving means for receiving authentication information of a user of an information processing device from the information processing device; a requesting means for requesting authentication of the user from an authentication server; an acquisition means for acquiring an attribute value of the user from the authentication server when the authentication of the user by the authentication server is successful; and a setting unit that sets a user name of the user based on the attribute value in accordance with a setting rule selected from a plurality of setting rules. (Item 2) the image forming apparatus, a transmitting means for transmitting the user name to the information processing device; Item 10. The image forming apparatus according to item 1, further comprising: a second acquisition unit that acquires a print job having the user name. (Item 3) the receiving means receives a print job including the authentication information from the information processing device; 3. The image forming apparatus according to item 1 or 2, further comprising an assigning unit that assigns the user name to the print job. (Item 4) Each of the plurality of setting rules includes: The type of attribute value used to set the user name; A setting as to whether to process the attribute value; 4. The image forming apparatus according to any one of items 1 to 3, further comprising: a method for processing the attribute value when it is set that the attribute value is to be processed. (Item 5) The image forming apparatus described in item 4, wherein the processing method includes at least one of deleting a specific type of character from the attribute value, extracting a portion of the attribute value before the specific type of character, and deleting a portion of the attribute value that exceeds a threshold number of characters. (Item 6) The plurality of setting rules include: a first setting rule for setting a value obtained by processing a first attribute value acquired from the authentication server as the user name; and a second setting rule for setting the first attribute value acquired from the authentication server as the user name. (Item 7) The plurality of setting rules include: a first setting rule for setting a value obtained by processing a first attribute value acquired from the authentication server as the user name; and a third setting rule for setting the user name to a value obtained by processing the second attribute value acquired from the authentication server. (Item 8) 8. The image forming apparatus according to any one of items 1 to 7, further comprising an adding unit that adds a setting rule created by a user of the image forming apparatus to the plurality of setting rules. (Item 9) 1. A method for controlling an image forming apparatus, comprising: a receiving step in which a receiving means receives authentication information of a user of the information processing device from the information processing device; a request step in which a request means requests authentication of the user from an authentication server; an acquisition step of acquiring an attribute value of the user from the authentication server when the authentication of the user by the authentication server is successful; a setting step in which a setting means sets a username of the user based on the attribute value in accordance with a setting rule selected from a plurality of setting rules. (Item 10) An information processing device, a transmitting unit for transmitting authentication information of a user of the information processing device to an image forming device; a receiving means for receiving a user name of the user from the image forming device; and assigning means for assigning the user name to a print job executed by the image forming apparatus. (Item 11) Item 11. The information processing device according to item 10, wherein the authentication information includes a user identifier of the user and a designation of an authentication server that performs authentication. (Item 12) Item 12. The information processing device according to item 11, further comprising an acquisition means for acquiring a user identifier of the user from an operating system of the information processing device. (Item 13) A program for causing a computer to function as each means of the information processing device according to any one of items 10 to 12. (Item 14) A method for controlling an information processing device, comprising: a transmitting step in which a transmitting unit transmits authentication information of a user of the information processing device to an image forming device; a receiving step in which a receiving means receives the user name of the user from the image forming device; an assigning step in which an assigning unit assigns the user name to a print job executed by the image forming device.

[0144] The invention is not limited to the above-described embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Accordingly, the following claims are appended to apprise the public of the scope of the invention. [Explanation of symbols]

[0145] 101 MFP, 102 authentication server, 103 PC

Claims

1. An image forming apparatus, a receiving means for receiving authentication information of a user of an information processing device from the information processing device; a requesting means for requesting authentication of the user from an authentication server; an acquisition means for acquiring an attribute value of the user from the authentication server when the authentication of the user by the authentication server is successful; and a setting unit that sets a user name of the user based on the attribute value in accordance with a setting rule selected from a plurality of setting rules.

2. the image forming apparatus, a transmitting means for transmitting the user name to the information processing device; The image forming apparatus according to claim 1 , further comprising: a second acquisition unit that acquires a print job having the user name.

3. the receiving means receives a print job including the authentication information from the information processing device; 2. The image forming apparatus according to claim 1, further comprising an assigning unit that assigns the user name to the print job.

4. Each of the plurality of setting rules includes: The type of attribute value used to set the user name; A setting as to whether to process the attribute value; The image forming apparatus according to claim 1 , further comprising: a method for processing the attribute value when the attribute value is set to be processed.

5. 5. The image forming apparatus according to claim 4, wherein the processing method includes at least one of deleting a specific type of character from the attribute value, extracting a portion of the attribute value before the specific type of character, and deleting a portion of the attribute value that exceeds a threshold number of characters.

6. The plurality of setting rules include: a first setting rule for setting a value obtained by processing a first attribute value acquired from the authentication server as the username; and a second setting rule for setting the first attribute value acquired from the authentication server as the user name.

7. The plurality of setting rules include: a first setting rule for setting a value obtained by processing a first attribute value acquired from the authentication server as the username; and a third setting rule for setting, as the user name, a value obtained by processing the second attribute value acquired from the authentication server.

8. 2. The image forming apparatus according to claim 1, further comprising an adding unit that adds a setting rule created by a user of the image forming apparatus to the plurality of setting rules.

9. 1. A method for controlling an image forming apparatus, comprising: a receiving step in which a receiving means receives authentication information of a user of the information processing device from the information processing device; a request step in which a request means requests authentication of the user from an authentication server; an acquisition step of acquiring an attribute value of the user from the authentication server when the authentication of the user by the authentication server is successful; a setting step in which a setting means sets a username of the user based on the attribute value in accordance with a setting rule selected from a plurality of setting rules.

10. An information processing device, a transmitting unit for transmitting authentication information of a user of the information processing device to an image forming device; a receiving means for receiving a user name of the user from the image forming device; and assigning means for assigning the user name to a print job executed by the image forming apparatus.

11. The information processing apparatus according to claim 10 , wherein the authentication information includes a user identifier of the user and a designation of an authentication server that performs authentication.

12. The information processing apparatus according to claim 11 , further comprising an acquisition unit that acquires a user identifier of the user from an operating system of the information processing apparatus.

13. A program for causing a computer to function as each of the means of the information processing device according to any one of claims 10 to 12.

14. A method for controlling an information processing device, comprising: a transmitting step in which a transmitting unit transmits authentication information of a user of the information processing device to an image forming device; a receiving step in which a receiving means receives the user name of the user from the image forming device; an assigning step in which an assigning unit assigns the user name to a print job executed by the image forming device.

Citation Information

Patent Citations

  • Information processing apparatus, method for controlling the same, program, and image forming apparatus

    JP2024007209A