Authentication program and terminal device

The terminal device performs user authentication via a cloud server, ensuring secure access and operation logging for image forming devices, addressing the challenge of unauthorized access by impersonation.

JP2025182560APending Publication Date: 2025-12-15KONICA MINOLTA INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024090197
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-03
Publication Date
2025-12-15

AI Technical Summary

Technical Problem

Existing image forming devices face challenges in securely authenticating service personnel without generating authentication information on the device or connecting it to an external network, leading to potential impersonation and unauthorized access.

Method used

A terminal device accesses an authentication server to perform user authentication, receives success information, and transmits it to the image forming device, associating operation details with the authenticated user and storing them as a log, without generating authentication information on the device or connecting it to an external network.

Benefits of technology

This approach ensures high-security authentication, preventing impersonation and allowing legitimate users to access functions while maintaining operation logs, without the need for on-device authentication or network connection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025182560000001_ABST
    Figure 2025182560000001_ABST
Patent Text Reader

Abstract

To provide an authentication program and a terminal device capable of performing authentication with higher security without requiring generation of authentication information in an image generation device, and network connection of the image generation device with an external authentication device when a service personnel or the like uses a prescribed function of the image generation device.SOLUTION: In order to implement authentication for using a prescribed function of an image generation device 2, an authentication program causes a computer of a terminal device 1 to execute the steps for: accessing an authentication server 3 to request of user authentication; receiving success information that the user authentication has been successful from the authentication server 3; and when the success information has been received, transmitting the prescribed information indicating that the user authentication of the user has been successful to the image generation device 2.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication program that operates a computer of a terminal device to perform authentication for using a predetermined function of an image forming device, and to the terminal device. [Background technology]

[0002] When a service person or the like performs maintenance on an image forming device at a customer's site, it is common for the service person or the like to access a maintenance screen to check the status and settings of the image forming device. Since this maintenance screen is accessed by the service person or the like, not the customer, a fixed password is often used.

[0003] However, if multiple service personnel share the same password, they may be unable to log in if they forget it, which may affect maintenance of the image forming device. For this reason, image forming devices often have a fixed initial password, which can lead to the risk that a third party could leak or guess the password and log in illegally, impersonating the user and performing important operations without their permission.

[0004] Therefore, it is desirable to perform authentication of the individual serviceman rather than authentication linked to the image forming apparatus, and leave a trail of who logged in to the image forming apparatus and performed maintenance work.

[0005] However, since there are multiple service personnel outside the company, it is difficult to store the authentication information of each service personnel in the customer's image forming device. Although it would be possible to use external authentication for the authentication of service personnel, there are cases in which the customer does not agree to connecting the image forming device to an external network.

[0006] Patent Document 1 discloses an image forming system that can perform authentication without entering a password or using a network line connected to the image forming device, thereby improving security and convenience, and switching the image forming device into maintenance mode.

[0007] Specifically, this image forming system includes an image forming device, a mobile phone, and an authentication code management server that exchanges authentication codes with the mobile phone. The mobile phone acquires an inquiry code from the image forming device and sends it to the authentication code management server. If the server determines that the code is appropriate, it sends the corresponding authentication code to the mobile phone, which the image forming device acquires and enters maintenance mode.

[0008] Patent Document 2 discloses an image forming system that increases the security level of the maintenance mode.

[0009] Specifically, the terminal device identifies the input base code and generates and displays an individual password from it. The image forming device has a function to generate and display the base code and authenticate the input individual password. Authentication is performed based on the legitimate individual password, and if it is valid, the device switches to maintenance mode. [Prior art documents] [Patent documents]

[0010] [Patent Document 1] Japanese Patent Application Laid-Open No. 2012-155647 [Patent Document 2] Japanese Patent Application Laid-Open No. 2017-107461 Summary of the Invention [Problem to be solved by the invention]

[0011] In the above-mentioned Patent Documents 1 and 2, there is a problem that authentication information is generated on the image forming apparatus, and if the authentication code is known, spoofing can be performed (it is not possible to guarantee who has accessed).

[0012] The object of the present invention is to provide an authentication program and a terminal device that can perform highly secure authentication when a service person or the like uses a specified function of an image forming device, without the need to generate authentication information on the image forming device or to connect the image forming device to an external authentication device via a network. [Means for solving the problem]

[0013] The above object can be achieved by the following means. (1) In order to perform authentication to use a predetermined function of the image forming device, the computer of the terminal device accessing an authentication server to request user authentication; receiving success information from an authentication server indicating that the user authentication was successful; When the success information is received, transmitting predetermined information indicating that the user authentication of the user has been successful to the image forming device; An authentication program that runs (2) acquiring from the image forming device details of operations performed during maintenance of the image forming device; a step of associating the acquired operation details with the authenticated user and storing the details as an operation log; 2. The authentication program according to claim 1, further causing the computer to execute the following: (3) The authentication program according to the preceding paragraph 2, further causing the computer to execute a step of transmitting the work log to an external device. (4) The authentication program according to the preceding paragraph 1, wherein if the user authentication by the authentication server is unsuccessful, login to the image forming apparatus is not permitted. (5) A terminal device for performing authentication to use a predetermined function of an image forming apparatus, a requesting means for accessing an authentication server and requesting user authentication; a receiving means for receiving success information indicating that the user authentication has been successful from the authentication server; a transmitting unit configured to transmit, when the success information is received, predetermined information indicating that the user authentication of the user has been successful to the image forming apparatus; A terminal device comprising: (6) an acquisition unit that acquires from the image forming device details of operations performed during maintenance of the image forming device; a storage means for storing the acquired operation details as an operation log in association with the authenticated user; 6. The terminal device according to claim 5, further comprising: (7) The terminal device according to the preceding paragraph 6, further comprising a transmission means for transmitting the work log to an external device. (8) The terminal device according to the preceding paragraph 5, wherein if the user authentication by the authentication server is unsuccessful, login to the image forming device is not possible. [Effects of the Invention]

[0014] In the authentication program and terminal device according to the present invention, the terminal device accesses the authentication server to request user authentication, and receives success information from the authentication server indicating that the user authentication has been successful. Upon receiving the success information, the terminal device transmits predetermined information indicating that the user authentication of the user has been successful to the image forming apparatus.

[0015] Upon receiving the predetermined information indicating successful user authentication, the image forming device analyzes the predetermined information, evaluates the validity of the information, and performs authentication. If the authentication is successful, the image forming device allows the user to use functions such as maintenance.

[0016] Therefore, when authenticating a user such as a serviceman to use a predetermined function of the image forming apparatus, it is not necessary to generate authentication information on the image forming apparatus or to connect the image forming apparatus to an external authentication device via a network. Furthermore, since user authentication is performed by the authentication server, high-security user authentication is performed. This makes it possible to prevent third parties from impersonating others, and allows legitimate servicemen and others whose identities are guaranteed to use the predetermined function of the image forming apparatus. [Brief explanation of the drawings]

[0017] [Figure 1] 1 is a block diagram showing a functional configuration of an authentication system including a terminal device according to an embodiment of the present invention. [Figure 2] FIG. 2 is a sequence diagram for explaining the operation of the authentication system shown in FIG. [Figure 3] 10 is a login screen for an image forming apparatus maintenance application displayed on a terminal device. [Figure 4] 10 is a screen showing the contents of an image forming apparatus maintenance application displayed on a terminal device. [Figure 5] 10 is a table illustrating an example of a work log. [Figure 6] FIG. 6A is a login screen for the image forming apparatus login service application displayed on the terminal device, and FIG. 6B is a screen showing the contents of the image forming apparatus login service application. DETAILED DESCRIPTION OF THE INVENTION

[0018] Hereinafter, an embodiment of the present invention will be described with reference to the drawings.

[0019] FIG. 1 is a block diagram showing the functional configuration of an authentication system including a terminal device according to an embodiment of the present invention.

[0020] This authentication system includes a terminal device 1, an image forming device 2, an authentication server 3, and the like.

[0021] In this embodiment, the terminal device 1 is a mobile terminal such as a smartphone or tablet, but it may also be a personal computer, etc. However, it is preferable that the terminal device 1 is a terminal that can be carried by a user such as a serviceman of the manufacturer of the image forming device 2. In the following description, the terminal device is also referred to as a mobile terminal.

[0022] In this embodiment, the image forming apparatus 2 is a multi-function digital multifunction peripheral (MFP) that has functions such as copying, printing, scanning, and facsimile. Hereinafter, the image forming apparatus will also be referred to as a multifunction peripheral.

[0023] In this embodiment, the mobile terminal 1 is a company-owned mobile terminal loaned by the manufacturer of the multifunction peripheral 2 to a serviceman or the like belonging to the company. As shown in Fig. 1, the mobile terminal 1 includes a main processing unit 11, an authentication server communication unit 12, a multifunction peripheral communication unit 13, a work information storage unit 14, and a storage 15. Note that although the mobile terminal 1 is equipped with general functions of a mobile terminal, Fig. 1 mainly shows only functions related to user authentication.

[0024] The main processing unit 11 includes a computer system including a CPU, a ROM, a RAM, etc., and performs overall control and processing of the mobile terminal 1.

[0025] The authentication server communication unit 12 is an interface for connecting to the authentication server 3 via a network. The multifunction device communication unit 13 is an interface for communicating with the multifunction device 2.

[0026] The work information storage unit 14 stores in the storage 15 the work information created by the service person or transmitted from the multifunction device 2 after the service person or the like is permitted to log in to the multifunction device 2 and performs work such as maintenance of the multifunction device 2.

[0027] In addition to the above-mentioned work information, various other data are stored in the storage 15. For example, programs for the main processing unit 11 to perform control and processing, information about the service person who owns the mobile terminal 1, and success information indicating that user authentication received from the authentication server 3 was successful are stored. The success information will be described later.

[0028] 1, the multifunction device 2 includes a main processing unit 21, a mobile terminal communication unit 22, a request verification unit 23, etc. The multifunction device 2 is equipped with general functions of a multifunction device, such as a copy function, a printer function, a scan function, and a facsimile function, but FIG. 1 mainly shows only the functions related to user authentication.

[0029] The main processing unit 21 includes a CPU, a ROM, a RAM, etc., and performs overall control and processing of the multifunction device 2.

[0030] The mobile terminal communication unit 22 is an interface for communicating with the mobile terminal 1. The request verification unit 23 verifies the validity of predetermined information indicating successful user authentication transmitted from the mobile terminal 1. The verification of validity will be described later.

[0031] In this embodiment, the authentication server 3 is configured as a cloud system (cloud server). In the following description, the authentication server is also referred to as the cloud system.

[0032] In this embodiment, the cloud system 3 is managed and operated by the manufacturer of the multifunction peripheral 2, and is a maintenance server that centrally manages the multifunction peripherals 2 installed at customer companies. The cloud system 3 includes a main processing unit 31, a mobile terminal communication unit 32, a user authentication unit 33, a work information storage unit 34, and a database (DB) 35. The cloud system 3 is equipped with general functions of an authentication server, but FIG. 1 mainly shows functions related to user authentication.

[0033] The main processing unit 31 includes a CPU, a ROM, a RAM, etc., and performs overall control and processing of the cloud system 3 as a whole.

[0034] The mobile terminal communication unit 32 is an interface for communicating with the mobile terminal 1 .

[0035] The user authentication unit 33 performs user authentication for the serviceman who is the owner of the portable terminal 1. The user authentication is performed by comparing the authentication information sent from the portable terminal 1 with the authentication information held by the cloud system 3.

[0036] The work information storage unit 34 associates the work information transmitted from the mobile terminal 1 with the user and stores it in the database 35. In addition to the work information, the database 35 also stores authentication information for each of multiple users.

[0037] The operation of the authentication system shown in FIG. 1 will be described with reference to the sequence diagram of FIG.

[0038] The service technician launches an application (hereinafter, the application will be simply referred to as an app) running on the mobile terminal 1 (step S1). Next, the service technician operates the mobile terminal 1 to send identification information (ID) and password (Pass) to an authentication service on the cloud system 3, which is managed by the same manufacturer as the multifunction device 2, and requests login processing (step S2). Communication between the mobile terminal 1 and the cloud system 3 is carried out using a general mobile phone line, and the communication content is encrypted using HTTPS.

[0039] The cloud system 3 returns the authentication result to the mobile terminal 1 (step S3). If the authentication is successful, the service person can use the application functions on the mobile terminal 1. If the authentication is unsuccessful, the application functions cannot be used.

[0040] The service technician operates the app on the mobile terminal 1 (step S4) to request the acquisition of a digital certificate created by the manufacturer of the multifunction device (step S5). The cloud system 3 sends the digital certificate to the mobile terminal 1, which then receives the digital certificate (step S5). The digital certificate has been issued by a trusted certificate authority.

[0041] Next, the service technician displays a login screen (shown in FIG. 3) for the multifunction device maintenance app installed on the mobile terminal 1, and presses the "Login" button on the login screen (step S6). Then, the service technician enters identification information (ID) and a password (Password) that the service technician has set in advance.

[0042] This will display the MFP maintenance app screen, as shown in Figure 4. This screen displays the following buttons: "Notifications," "Messages," "Past Work History," and "Start Maintenance."

[0043] When the service technician presses the "maintenance start button," a function for starting the maintenance work is activated, and the mobile terminal 1 starts connecting with the multifunction device 2 (step S7). Possible communication methods include wireless communication using Bluetooth (registered trademark) and communication using a wired cable.

[0044] When the connection is completed, the multifunction device 2 transmits a connection completion notification to the portable terminal 1 (step S8), and the portable terminal 1 receives the connection completion notification.

[0045] After completing the connection with the multifunction device 2, the portable terminal 1 transmits and conveys user information about the service person to the multifunction device 2 (step S9). In order to prove the validity of the user information and the validity of the communication partner, the portable terminal 1 simultaneously transmits a digital signature (well-known technology) and a digital certificate (well-known technology) for the user information to the multifunction device 2.

[0046] The multifunction device 2 verifies the validity of the data sent from the mobile terminal 1 (step S10). By verifying the validity, the multifunction device 2 can detect tampering of the user information and can verify whether the data has been sent from a valid party.

[0047] The multifunction device 2 notifies the portable terminal 1 of the verification result. That is, if the multifunction device 2 determines that the data is valid, it notifies the portable terminal 1 of confirmation OK (authentication success) (step S11-1). Then, the multifunction device 2 transitions the display screen to a maintenance screen (step S12). A service person can perform maintenance on the multifunction device 2 using the maintenance screen displayed on the multifunction device 2.

[0048] If the multifunction device 2 determines that the data is not valid, it notifies the portable terminal 1 that the confirmation is NG (authentication failed) (step S11-2). In this case, it becomes impossible to log in to the multifunction device 2, and the maintenance screen is not displayed on the multifunction device 2. As a result, the service person cannot perform maintenance on the multifunction device 2. If the data sent from the portable terminal 1 to the multifunction device 2 is not valid, it means that the service person has not been authenticated. As a result, it is possible to prevent a third party impersonating a service person from accessing the multifunction device 2.

[0049] After the work is completed, the service technician may create a work log as work information on the mobile terminal 1 and store the created work log in the storage 15 via the work information storage unit 14. The work log may also be transmitted from the mobile terminal 1 to the cloud system 3 (step S13).

[0050] Furthermore, the mobile terminal 1 may acquire from the multifunction device 2 the details of the work actually performed on the multifunction device 1, and store the details as a work log in the storage 15 via the work information storage unit 14. In addition, the mobile terminal 1 may transmit this work log to the cloud system 3 (step S13).

[0051] The cloud system 3, which has received the work log from the mobile terminal 1, notifies the mobile terminal 1 that the work log has been accepted (step S14).

[0052] The work log stored in the storage 15 of the mobile terminal 1 can be viewed by pressing the "Past Work History" button on the screen of Fig. 4. Fig. 5 shows an example of a work log stored in the storage 15. In this example, the work log displays the execution user ID, operation details, and execution results in chronological order.

[0053] After the maintenance work is completed, the service technician operates the application on the mobile terminal 1 (step S15) and logs out from the cloud system 3 (step S16). When the technician logs out, the certificate obtained from the cloud system 3 may be deleted.

[0054] In this embodiment, after logging in to the cloud system 3, the user remains logged in to the cloud system 3 until the maintenance work on the multifunction device 2 is completed, but the user may also log out after obtaining the digital certificate from the cloud system 3 and before the start of the maintenance work. However, remaining logged in has the advantage that it is not necessary to log in again when sending a work log to the cloud system 3.

[0055] As described above, in this embodiment, when authenticating a service person or the like to use a predetermined function of the multifunction device 2, it is not necessary to generate authentication information on the multifunction device 2, and it is also not necessary to connect the multifunction device 2 to a network with an external authentication device. Furthermore, since user authentication of the service person or the like is performed by the cloud system 3, highly secure user authentication is performed. This makes it possible to prevent impersonation by a third party, and it is possible to permit legitimate service people or the like whose identities are guaranteed to use the predetermined function of the multifunction device 2.

[0056] If the service person's identification information (ID) or password is leaked, the cloud system 3 will disable the account, and the disabled account will be unable to log in to the cloud system 3. As a result, the mobile terminal 1 will be unable to obtain the electronic certificate issued by the cloud system 3, and will also be unable to log in to the multifunction device 2.

[0057] In the above embodiment, an example in which user authentication is performed by a serviceman has been shown, but an example in which user authentication is used by a client company will be described below.

[0058] As mentioned above, some customers have multifunction peripherals 2 that are not connected to a network such as the Internet due to security requirements, etc. For such multifunction peripherals 2, a customer user such as an employee can log in to the cloud system 3 on their behalf using a mobile terminal 1 and send the results to the multifunction peripheral 2, thereby enabling the user to log in to the multifunction peripheral 2.

[0059] Specifically, the customer user operates the mobile terminal 1 to send identification information (ID) and password (Pass) to the cloud system 3 and request login processing. The subsequent processing and operations are the same as the example shown in the sequence diagram in Figure 2, and if authentication is successful, the mobile terminal 1 receives and acquires a digital certificate from the cloud system 3.

[0060] The components that realize this system are the same as those in Figure 1, but the difference is that the mobile terminal 1 is owned and managed by the customer company, and the authentication server, cloud system 3, stores the customer user's authentication information.

[0061] When using the multifunction printer login service app installed on the mobile terminal 1, the customer user operates the mobile terminal 1 to display a login screen for the multifunction printer login service app. An example of this login screen is shown in FIG. 6A. The customer user presses the "Login" button on the login screen and enters their identification information (ID) and a password that they have set in advance.

[0062] 6B is then displayed. On this screen, information about the most recently used multifunction devices 2 is displayed. When the customer user selects the multifunction device 2 to which the customer user wants to connect, the mobile terminal 1 starts connecting to the selected multifunction device 2.

[0063] When the connection is complete, the multifunction device 2 sends a connection completion notification to the portable terminal 1, and the portable terminal 1 receives the connection completion notification. After the connection with the multifunction device 2 is complete, the portable terminal 1 sends user information about the customer user to the multifunction device 2. In order to prove the validity of the user information and the validity of the communication partner, the portable terminal 1 simultaneously sends a digital signature (well-known technology) and a digital certificate (well-known technology) for the user information to the multifunction device.

[0064] The multifunction device 2 verifies the validity of the data sent from the portable terminal 1 and notifies the portable terminal 1 of the verification result. In other words, if the multifunction device 2 determines that the data is valid, it notifies the portable terminal 1 of confirmation OK (authentication successful). Then, the multifunction device 2 changes the display screen to an operation screen. The customer user can use the operation screen displayed on the multifunction device 2 to use the multifunction device 2. In other words, it becomes possible to log in to the multifunction device 2.

[0065] If the multifunction device 2 determines that the data is not valid, it notifies the mobile terminal 1 that the confirmation is NG (authentication failed). In this case, logging into the multifunction device 2 is not possible, and the operation screen is not displayed on the multifunction device 2. As a result, the customer user cannot use the multifunction device 2. This makes it possible to prevent a third party impersonating the customer from logging into the multifunction device.

[0066] 2, a log (work log) of the contents of the maintenance work performed by the serviceman is acquired and stored in the storage 15 of the mobile terminal 1. In an embodiment in which the client company uses user authentication, the mobile terminal 1 may acquire a log of job operations performed by the user and store it in the storage 15. [Explanation of symbols]

[0067] 1. Mobile terminal (terminal device) 2 Multifunction device (image forming device) 3 Cloud system (authentication server) 11 Main processing section 12 Authentication Server Communication Unit 13 Image forming device communication unit 14 Work information storage section 15. Storage 21 Main processing section 22 Mobile terminal communication unit 23 Request Validation Unit 31 Main processing section 32 Mobile terminal communication unit 33 User authentication section 34 Work information storage section 35 databases

Claims

1. In order to perform authentication to use a predetermined function of the image forming device, the computer of the terminal device accessing an authentication server to request user authentication; receiving success information from an authentication server indicating that the user authentication was successful; When the success information is received, transmitting predetermined information indicating that the user authentication of the user has been successful to the image forming device; An authentication program that runs

2. acquiring from the image forming apparatus details of operations performed during maintenance of the image forming apparatus; a step of associating the acquired operation details with the authenticated user and storing the details as an operation log; The authentication program according to claim 1 , further comprising:

3. 3. The authentication program according to claim 2, further causing the computer to execute a step of transmitting the work log to an external device.

4. 2. The authentication program according to claim 1, wherein if the user authentication by the authentication server is unsuccessful, login to the image forming apparatus is not permitted.

5. A terminal device for performing authentication to use a predetermined function of an image forming apparatus, a requesting means for accessing an authentication server and requesting user authentication; a receiving means for receiving success information indicating that the user authentication has been successful from the authentication server; a transmitting unit configured to transmit, when the success information is received, predetermined information indicating that the user authentication of the user has been successful to the image forming apparatus; A terminal device comprising:

6. an acquisition unit that acquires from the image forming apparatus details of operations performed during maintenance of the image forming apparatus; a storage means for storing the acquired operation details as an operation log in association with the authenticated user; The terminal device according to claim 5 , further comprising:

7. 7. The terminal device according to claim 6, further comprising a transmission means for transmitting the work log to an external device.

8. 6. The terminal device according to claim 5, wherein if the user authentication by the authentication server is unsuccessful, login to the image forming device is not permitted.

Citation Information

Patent Citations

  • Image forming system and authentication program

    JP2012155647A

  • Image forming system, image forming apparatus, and maintenance mode password generation program

    JP2017107461A