Communication system, management server, and device

The communication system and management server configuration addresses service cancellation inconsistencies by using coordinated reset processes to ensure synchronized data deletion, enhancing service cancellation reliability and device usability.

JP2026019275APending Publication Date: 2026-02-05BROTHER KOGYO KK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024120734
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-26
Publication Date
2026-02-05

AI Technical Summary

Technical Problem

When a user cancels a service, inconsistencies in information between a device and a server can occur due to incomplete deletion of information during the cancellation process, leading to potential malfunctions and hindered device usage.

Method used

A communication system and management server configuration that utilizes start, progress, and progress response notifications to coordinate a controlled reset process, ensuring synchronized deletion of device and server information through a series of timed and acknowledged steps.

Benefits of technology

This approach reduces the likelihood of information inconsistencies between devices and servers, ensuring complete data deletion and enabling seamless service cancellation without device malfunctions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026019275000001_ABST
    Figure 2026019275000001_ABST
Patent Text Reader

Abstract

To reduce the possibility that information inconsistency occurs between a device and a server.SOLUTION: The device control unit of the device transmits a start notification to the server system in response to the reset instruction. A server controller of the server system sends a start response to the device. In a specific case where the start response is received by the device, the device control unit starts a reset process including a process of deleting the setting information from the storage device of the device. The device controller transmits the progress notification to the server system. The server control unit executes a process for deleting the device information from the first storage area of the server system and a process for transmitting a progress response to the device in a specific case where the progress notification is received by the server system. The device control unit executes the remaining processing of the reset processing in a specific case where the progress response is received by the device.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present specification relates to a communication system, a management server, and a device. [Background technology]

[0002] A user may subscribe to various services. A user may also cancel a service. Patent Document 1 discloses a configuration for canceling a service to be canceled using the functions of RPA (Robotic Process Automation). A cancellation processing unit realized by RPA launches a web browser at a predetermined timing and executes cancellation processing on the web browser. The cancellation processing unit also launches an application for the service to be canceled at a predetermined timing and executes cancellation processing on the application. [Prior art documents] [Patent documents]

[0003] [Patent Document 1] Patent Publication No. 2021-124782 Summary of the Invention [Problem to be solved by the invention]

[0004] Various services, such as print subscriptions, are provided using a server and a device. Each of the server and the device stores various pieces of information used for the service. When a user cancels a service, the user may delete the information on the device. This may result in inconsistencies in information between the device and the server.

[0005] This specification discloses a technique for reducing the possibility of information inconsistency occurring between a device and a server. [Means for solving the problem]

[0006] The techniques disclosed in this specification can be implemented in the following application examples.

[0007] [Application Example 1] A communication system including a server system and a device used for a service, wherein the server system includes a server control unit and a first storage area configured to store device information indicating the device and user information indicating a user associated with the service, in association with each other; the device includes a device control unit and a storage device configured to store the device information and setting information indicating settings used for the service; the device control unit transmits a start notification to the server system in response to a reset instruction from a user of the device, the start notification being a notification including the device information; and when the start notification is received by the server system, the server control unit transmits a start response to the start notification to the device; a device control unit that, in a first specific case when the start response is received by the device, initiates a reset process including a process of deleting the setting information from the storage device of the device, and, in response to the reset process having progressed to a specific stage, sends a progress notification to the server system indicating the progress of the reset process up to the specific stage; a server control unit that, in a second specific case when the progress notification is received by the server system, executes a process for deleting the device information from the first storage area of ​​the server system and a process for sending a progress response to the progress notification to the device; and a device control unit that, in a third specific case when the progress response is received by the device, executes the remaining processes of the reset process.

[0008] According to this configuration, the device control unit and the server control unit use the start notification, start response, progress notification, and progress response to proceed with the reset process, which includes deleting device information from the first storage area of ​​the server system and deleting setting information from the device's storage device, thereby reducing the possibility of information inconsistency occurring between the device and the server system.

[0009] [Application Example 2] A management server configured to communicate with each of a service server and a device used for a service, the management server comprising a server control unit, the service server comprising a first storage area configured to store, in association with each other, device information indicating a device and user information indicating a user associated with the service, the device comprising a storage device configured to store the device information and setting information indicating settings used for the service, the server control unit transmitting, to the service server, an instruction to delete the device information from the first storage area of ​​the service server in a specific case in which a progress notification from the device is received by the management server, the progress notification being a notification transmitted by the device in response to a reset process having progressed to a specific stage, the reset process including a process of deleting the setting information from the storage device of the device.

[0010] According to this configuration, in certain cases when a progress notification from the device is received by the management server, the server control unit sends an instruction to the service server to delete the device information from the first storage area of ​​the service server, thereby reducing the possibility of information inconsistency occurring between the device and the service server.

[0011] [Application Example 3] A device configured to communicate with a server system and used for a service, the device comprising: a device control unit; and a storage device configured to store device information that identifies the device and setting information that indicates settings to be used for the service, wherein the device control unit sends a start notification to the server system in response to a reset instruction from a user of the device, the start notification being a notification including the device information; if the device does not receive a start response that is a response to the start notification from the server system before a first waiting time has elapsed since the sending of the start notification, the device control unit does not start a reset process including a process of deleting the setting information from the storage device of the device; and starts the reset process in a first specific case in which the start response is received by the device before the first waiting time has elapsed since the sending of the start notification; sends a progress notification to the server system in response to the reset process having progressed to a specific stage, the progress notification indicating the progress of the reset process up to the specific stage; and performs the remaining processes of the reset process in a specific case in which the device receives a progress response that is a response from the server system to the progress notification.

[0012] According to this configuration, the device control unit proceeds with the reset process by using the start notification, start response, progress notification, and progress response, thereby reducing the possibility that the information in the device will become inconsistent with the information in the server system.

[0013] The technology disclosed in this specification can be realized in various forms, such as an information processing method, a communication system, a server system, a device, a management server, a service server, a computer program for realizing the functions of these methods, systems, devices, and servers, a recording medium on which the computer program is recorded (e.g., a non-temporary recording medium), and the like. [Brief explanation of the drawings]

[0014] [Figure 1] FIG. 1 is an explanatory diagram illustrating a communication system according to an embodiment; [Figure 2] 1A is a diagram showing an example of a service database D3, and FIG. 1B is a diagram showing an example of a management database D4. [Figure 3] FIG. 10 is a sequence diagram illustrating an example of a reset process and a server process. [Figure 4] FIG. 10 is a sequence diagram illustrating an example of a reset process and a server process. [Figure 5] FIG. 10 is a sequence diagram illustrating an example of a reset process and a server process. [Figure 6] FIG. 10 is a sequence diagram illustrating an example of a reset process and a server process. DETAILED DESCRIPTION OF THE INVENTION

[0015] A. First Example: A1. System configuration: 1 is an explanatory diagram showing a communication system according to one embodiment. The communication system 1000 includes a multifunction peripheral 100 and a server system 200. The server system 200 includes a service server 300 and a management server 400. These devices 100, 300, and 400 are connected to a network IT. The network IT may include the so-called Internet. The network IT may also include a so-called local area network.

[0016] The multifunction device 100 has a processor 110, a storage device 115, a display unit 140, an operation unit 150, a print execution unit 160, a read execution unit 170, and a communication interface 180. These elements are connected to each other via a bus. The storage device 115 includes a volatile storage device 120 and a non-volatile storage device 130.

[0017] The processor 110 is a device configured to perform data processing, and is, for example, a central processing unit (CPU) or a system on a chip (SoC). The volatile storage device 120 is, for example, a dynamic random access memory (DRAM), and the non-volatile storage device 130 is, for example, a flash memory. The non-volatile storage device 130 stores data for a program PG1, device information DVp, communication information SSp, service information SVp, and user setting information UIp. The program PG1 is stored in the non-volatile storage device 130 by the manufacturer of the multifunction device 100 when the multifunction device 100 is manufactured. Alternatively, the program PG1 may be downloaded from a server (not shown). Details of the information DVp, SSp, SVp, and UIp will be described later.

[0018] The display unit 140 is a device configured to display images, such as a liquid crystal display or an organic EL display. The operation unit 150 is a device configured to receive operations by a user, such as buttons, levers, or a touch panel overlaid on the display unit 140. The display unit 140 and the operation unit 150 may form a so-called touch screen. The user can input various requests and instructions to the multifunction peripheral 100 by operating the operation unit 150. The display unit 140 may display operation elements (e.g., buttons, sliders, etc.), and the displayed elements may be operated through operation of the operation unit 150.

[0019] The print execution unit 160 is a device that prints images. In this embodiment, the print execution unit 160 is a so-called inkjet printer. The print execution unit 160 is configured to print images using one or more types of printing material (for example, four colors of ink: cyan, magenta, yellow, and black). Note that the print execution unit 160 may be a device that prints images using another method (for example, a laser printer).

[0020] The reading execution unit 170 is a device that optically reads an object such as a document. In this embodiment, the reading execution unit 170 includes an optical sensor (not shown). The reading execution unit 170 optically reads the object and generates scan data representing the read object.

[0021] The communication interface 180 is an interface for communicating with other devices (for example, it includes one or more of a USB interface, a wired LAN interface, and an IEEE802.11 wireless interface). In this embodiment, the communication interface 180 is connected to a network IT.

[0022] Next, a description will be given of the hardware configuration of the servers 300 and 400. In this embodiment, the servers 300 and 400 have similar hardware configurations. Below, the configuration of the service server 300 and the configuration of the management server 400 will be described together.

[0023] The servers 300 and 400 each have a processor 310 or 410, a storage device 315 or 415, and a communication interface 380 or 480. In each server 300 or 400, these elements are connected to each other via a bus (not shown). The storage device 315 or 415 includes a volatile storage device 320 or 420 and a non-volatile storage device 330 or 430.

[0024] The processors 310, 410 are devices configured to perform data processing, such as a CPU or an SoC. The volatile storage devices 320, 420 are, for example, DRAM, and the nonvolatile storage devices 330, 430 are, for example, flash memory. The communication interfaces 380, 480 are interfaces for communicating with other devices (e.g., including one or more of a USB interface, a wired LAN interface, and an IEEE802.11 wireless interface). The communication interfaces 380, 480 are connected to a network IT. In this embodiment, the communication interface 380 of the service server 300 and the communication interface 480 of the management server 400 are connected by a network SN internal to the server system 200, not via a network IT external to the server system 200. Communication between the service server 300 and the management server 400 is performed via the internal network SN.

[0025] The service server 300 executes processing for providing a service that uses a device. The multifunction peripheral 100 is an example of a device used for the service. The service may be various services. In this embodiment, the service server 300 provides a remote printing service. Specifically, the service server 300 receives a print request including data of a target image from a terminal device (not shown) (e.g., a smartphone, a personal computer, etc.) via the network IT. The service server 300 causes a device (e.g., the multifunction peripheral 100) to print the target image via the network IT. A user can receive the service by registering a device with the service server 300 in advance.

[0026] Non-volatile storage device 330 of service server 300 stores data for program PG3 and service database D3. Program PG3 is uploaded to service server 300 by a service provider. Hereinafter, the portion of the storage area formed by non-volatile storage device 330 that stores service database D3 will be referred to as first storage area SA1.

[0027] FIG. 2(A) is a diagram showing an example of the service database D3. In this embodiment, the service database D3 shows the correspondence between user information US, device information DV, and status ST. The user information US is information about a user associated with a service. The user information US includes, for example, a user identifier. The device information DV is information about a device used for a service. The device information DV includes, for example, a device identifier. In this embodiment, data representing the device identifier is stored in advance in the device's storage device (for example, the non-volatile storage device 130 of the multifunction peripheral 100) when each device is manufactured. The status ST indicates the status of the service. In this embodiment, the status ST is selected from a plurality of statuses including "in service," which indicates that the service is being provided, and "cancelling," which indicates that the service is being canceled.

[0028] Although not shown in the figures, a user registers a device such as the multifunction peripheral 100 with the service server 300 in advance to receive a service. In the registration process, the server system 200 (e.g., the service server 300 or the management server 400) assigns a user identifier to the user. The service server 300 then registers in the service database D3 the correspondence between user information US including the user identifier, device information DV including the device identifier, and a status ST indicating that the service is being provided. The user information US may further include various information related to the user, such as a payment method for the service fee. The device information DV may further include various information related to the device, such as the model name of the device.

[0029] Furthermore, in the registration process, the multifunction peripheral 100 (FIG. 1) stores various information used for the service in the nonvolatile storage device 130. In this embodiment, the multifunction peripheral 100 stores communication information SSp and service information SVp in the nonvolatile storage device 130.

[0030] The communication information SSp is information used for communication for a service. In this embodiment, the communication information SSp includes access information for accessing the service server 300 and access information for accessing the management server 400. The access information may include, for example, a uniform resource locator (URL). Hereinafter, the URL of the management server 400 will be referred to as the management URL. The management URL is used to transmit various information related to the service to the management server 400. The scheme of the management URL may be, for example, http. The communication information SSp may be notified to the multifunction peripheral 100 by the server system 200 (e.g., the service server 300 or the management server 400) during the registration process. Note that the management URL may be different for each device used for the service. For example, the management URL may include a different path for each device. Alternatively, the management URL may be common to multiple devices.

[0031] The service information SVp is information related to the service, and may include, for example, user information US associated with the multifunction peripheral 100.

[0032] The communication information SSp and the service information SVp are examples of setting information that indicates the settings used for the service. Hereinafter, the information SSp and SVp as a whole will be referred to as service setting information SI, or simply as setting information SI.

[0033] The device information DVp is device information DV associated with the multifunction peripheral 100. In this embodiment, the device information DVp is stored in the nonvolatile storage device 130 when the multifunction peripheral 100 is manufactured.

[0034] The user setting information UIp represents the settings of the multifunction peripheral 100 determined by the user. The user setting information UIp may include, for example, shortcuts. A shortcut is a function that calls and applies a set of frequently used settings, such as multiple copy settings (quality, contrast, etc.) or multiple scan settings (resolution, scan size, etc.).

[0035] In the example of FIG. 2(A), two pieces of device information DVp and DVq are associated with user information USi. The status ST of these two pieces of device information DVp and DVq is "in service." One piece of device information DVr is associated with user information USj. The status ST of device information DVr is "canceled." The service server 300 provides a service using a device associated with a status ST indicating "in service." For a device associated with a status ST indicating "canceled," the service server 300 may perform a process other than providing the service. For example, the service server 300 may stop providing the service. The service server 300 may return an error in response to a service request.

[0036] The management server 400 executes various processes related to the service. In this embodiment, the processes executed by the management server 400 include a process for resetting a device associated with the service. As will be described later, a user can start the reset process by inputting a reset instruction to the device. As the reset process in the device progresses, the device information DV is deleted from the service database D3 (FIG. 2(A)). This removes the device from the scope of the service. In other words, the service is canceled.

[0037] The nonvolatile storage device 430 of the management server 400 stores data for a program PG4 and a management database D4. The program PG4 is uploaded to the management server 400 by a service provider. Hereinafter, the portion of the storage area formed by the nonvolatile storage device 430 that stores the management database D4 will be referred to as the second storage area SA2.

[0038] FIG. 2(B) is a diagram showing an example of the management database D4. In this embodiment, the management database D4 shows the correspondence between device information DV and device setting information DS. The device information DV is the same as the device information DV in FIG. 2(A). The device setting information DS is information that indicates the settings of a device and includes service setting information used for services. In the example of FIG. 2(B), three pieces of device information DVp, DVq, and DVr are registered. The device setting information DS that is associated with the device information DVp indicating the multifunction peripheral 100 includes setting information SI (i.e., communication information SSp and service information SVp) and user setting information UIp.

[0039] In this embodiment, the reset process in the multifunction peripheral 100 (FIG. 1) deletes the information SSp, SVp, and UIp stored in the nonvolatile storage device 130 of the multifunction peripheral 100. If a malfunction occurs during the reset process, some of the information that should be deleted may not be deleted and may remain on the device. Incomplete deletion of information may hinder new use of the device. In this embodiment, the device information is backed up in the management database D4. Then, if a malfunction occurs during the reset process, the device information is restored using the information in the management database D4 (details will be described later).

[0040] A2. Reset process and server process: 3-6 are sequence diagrams showing examples of reset processing by the multifunction peripheral 100 and server processing by the server system 200. FIG. 4 shows a continuation of FIG. 3, FIG. 5 shows a continuation of FIG. 4, and FIG. 6 shows a continuation of FIG. 5. The processors 110, 310, and 410 of the multifunction peripheral 100, service server 300, and management server 400 execute corresponding processing in accordance with programs PG1, PG3, and PG4, respectively. Hereinafter, the processor 110 of the multifunction peripheral 100 will be referred to as the device processor 110, the processor 310 of the service server 300 will be referred to as the service processor 310, and the processor 410 of the management server 400 will be referred to as the management processor 410.

[0041] In S110, the device processor 110 confirms that it is able to communicate with the management server 400. For example, the device processor 110 refers to the communication information SSp (FIG. 1) to acquire an administration URL, accesses the administration URL, and acquires a response (e.g., an affirmative response) from the management server 400. This allows the multifunction peripheral 100 to confirm that it is able to communicate with the management server 400. Hereinafter, it is assumed that the device processor 110 transmits information to the management server 400 via the administration URL. It should be noted that the device processor 110 may execute S110 at various times. In this embodiment, it is assumed that S110 is included in the registration process.

[0042] In S115, the device processor 110 transmits information stored in the multifunction peripheral 100 to the management server 400. The transmitted information includes information to be deleted by the reset process. In this embodiment, the device processor 110 transmits the information DVp, SSp, SVp, and UIp data to the management server 400. In S120, the management processor 410 registers the received information DVp, SSp, SVp, and UIp in the management database D4 (FIG. 2(B)). The device processor 110 may execute S115 at various times. In this embodiment, S115 is included in the registration process.

[0043] In S125, the user logs in to the multifunction peripheral 100 as an administrator. In S130, the device processor 110 performs login authentication. Various authentication methods may be used. In this embodiment, the administrator of the multifunction peripheral 100 registers an administrator password in the multifunction peripheral 100 in advance. The device processor 110 stores authentication data (e.g., a hash value of the password) of the password determined by the administrator in the non-volatile storage device 130 (not shown). In S125, the user inputs the administrator password by operating the operation unit 150. In S130, the device processor 110 authenticates the input password by referring to the authentication data. If the authentication fails (S135: No), the device processor 110 ends the process without starting the reset process (the device processor 110 then waits for the input of a new instruction, such as a login). In this way, if the authentication fails, the device processor 110 does not accept an instruction to start the reset process.

[0044] If the authentication is successful (S135: Yes), the device processor 110 accepts an instruction to perform the reset process. Here, in S140, the user operates the operation unit 150 to input an instruction to start the reset process. In S145, the device processor 110 transmits a reset process start notification to the management server 400. The start notification includes information data identifying the device that is the target of the reset process (in this embodiment, device information DVp). The device processor 110 also starts a timer. The device processor 110 accepts a start response, which will be described later, until a first waiting time T1 has elapsed since the start notification was transmitted.

[0045] In response to the start notification, the management processor 410 executes S150 and S155. In S150, the management processor 410 sets on a processing flag indicating that the reset process associated with the device information DV (here, device information DVp) included in the start notification is in progress. In S155, the management processor 410 transmits a start response, which is a response to the start notification, to the device that sent the start notification (here, the multifunction peripheral 100). In this embodiment, the start response includes data of a one-time secret key OTK that is used when interrupting the reset process. For each start response, the management processor 410 generates a one-time secret key OTK using a random number. In addition, the management processor 410 starts a timer. The management processor 410 accepts progress notifications, which will be described later, until a second waiting time T2 has elapsed since the start response was sent.

[0046] In S160, the device processor 110 determines whether the start response is received by the multifunction peripheral 100 before the first waiting time T1 has elapsed. The start response may not be received before the first waiting time T1 has elapsed due to various causes, such as a malfunction in the communication path between the multifunction peripheral 100 and the management server 400 or a malfunction in the server system 200. The first waiting time T1 is experimentally determined in advance so that the start response is received before the first waiting time T1 has elapsed since the start notification (S145) was sent if there is no malfunction, and so that a longer time than the first waiting time T1 may elapse since the start notification was sent without the start response being received if there is a malfunction. The first waiting time T1 may be, for example, 30 seconds or more and 2 minutes or less (more specifically, for example, 1 minute).

[0047] If the start response is not received before the first waiting time T1 has elapsed (S160: No), in S165 the device processor 110 displays a first error on the display unit 140, indicating that the start response was not received before the first waiting time T1 had elapsed. The first error may include, for example, a message indicating that the start response was not received before the first waiting time T1 had elapsed. By observing the displayed first error, the user can recognize that the start response was not received before the first waiting time T1 had elapsed. The user can proceed with processing to resolve the communication problem, such as reviewing the communication settings of the multifunction peripheral 100 or the communication settings of a relay device (e.g., a router) to which the multifunction peripheral 100 is connected. After S165, the device processor 110 ends the processing without starting the reset processing (the device processor 110 then waits for input of a new instruction, such as logging in).

[0048] If the start response is received before the first waiting time T1 has elapsed (S160: Yes), the device processor 110 starts the reset process in S210 (FIG. 4). In this embodiment, the reset process includes deleting the information SSp, SVp, and UIp stored in the nonvolatile memory device 130 in a predetermined order. It is preferable that the information used for communication with the management server 400 (here, communication information SSp) be set last. Hereinafter, the deletion order will be user setting information UIp, service information SVp, and communication information SSp.

[0049] In S215, the device processor 110 proceeds with the reset process. In this embodiment, the device processor 110 proceeds with the deletion of information based on the deletion order.

[0050] In S220, the device processor 110 branches the process depending on the status of the reset process. If a malfunction occurs during the reset process, the device processor 110 proceeds to S305 (FIG. 5). Various malfunctions can occur during the reset process. For example, the multifunction device 100 may restart during the reset process (for example, the multifunction device 100 is powered off and then powered on again). Also, the reset process may be interrupted by a user operating the operation unit 150 during the reset process. The process to be performed when a malfunction occurs during the reset process will be described later.

[0051] When the reset process has progressed to a specific stage, the device processor 110 proceeds to S225 (details will be described later). In this embodiment, the specific stage is the stage where the user setting information UIp and the service information SVp have been deleted.

[0052] If the status of the reset process is different from the above two statuses, i.e., if no malfunction occurs in the reset process and the reset process has not progressed to a specific stage, the device processor 110 proceeds to S215 and continues the reset process. In this way, if no malfunction occurs in the reset process, the device processor 110 repeats S215 to progress the reset process to a specific stage. In this embodiment, the device processor 110 deletes the user setting information UIp and the service information SVp from the non-volatile storage device 130.

[0053] When the reset process has progressed to a specific stage, in S225, the device processor 110 transmits a progress notification, which is a notification indicating that the reset process has progressed to the specific stage, to the management server 400. The progress notification includes information data identifying the device that is the target of the reset process (for example, a one-time private key OTK or device information DVp).

[0054] In S230, the management processor 410 determines whether a progress notification is received by the management server 400 before the second waiting time T2 has elapsed since the start response (S155 in FIG. 3) was transmitted. The progress notification used for this determination is a progress notification that includes information identifying the device associated with the start response (S155), i.e., the device associated with the start notification (S145). The progress notification may not be received before the second waiting time T2 has elapsed due to various causes, such as a malfunction in the reset process of the multifunction peripheral 100 or a malfunction in the communication path between the multifunction peripheral 100 and the management server 400. The second waiting time T2 is experimentally determined in advance so that, if there is no malfunction, the progress notification is received before the second waiting time T2 has elapsed since the start response (S155) was transmitted, and, if there is a malfunction, a time longer than the second waiting time T2 may elapse without the progress notification being received. The second waiting time T2 may be, for example, 30 seconds or more and 2 minutes or less (more specifically, for example, 1 minute).

[0055] If the progress notification is received before the second waiting time T2 has elapsed (S230: Yes), in S235 the management processor 410 transmits a deletion instruction to the service server 300. This instruction includes data of device information DV (here, device information DVp) indicating the device associated with the progress notification. In S240, the management processor 410 sets the processing flag associated with the device associated with the progress notification to OFF.

[0056] In S245, service processor 310, in response to the deletion instruction (S235), deletes the device information DV and the state ST of the device associated with the deletion instruction from service database D3 (FIG. 2(A)). In S245 of FIG. 4, service processor 310 deletes device information DVp associated with the deletion instruction (S235) and the state ST associated with device information DVp from service database D3.

[0057] Note that there are cases where the user information US associated with the device information DV to be deleted is associated with device information DV of another device. In this case, the service processor 310 maintains the information of the other device without deleting it. For example, in the example of FIG. 2(A), the user information USi associated with the device information DVp to be deleted is associated with device information DVq of another device. The device information DVq is maintained without being deleted. Furthermore, the user information US is maintained without being deleted. The user information US may be reused in a future registration process. There are cases where the user information US associated with the device information DV to be deleted is not associated with device information DV of another device. In this case, the service processor 310 may delete the user information US associated with the device information DV to be deleted.

[0058] In S250, the service processor 310 transmits a deletion completion notification to the management server 400. In S255, the management processor 410 transmits a progress response, which is a response to the progress notification (S225), to the device that transmitted the progress notification (here, the multifunction peripheral 100).

[0059] In S260, the device processor 110 determines whether a progress response has been received by the multifunction peripheral 100. The progress response may not be received due to various reasons, such as a malfunction in the communication path between the multifunction peripheral 100 and the management server 400 or a malfunction in the server system 200. The device processor 110 may limit the waiting time from the transmission of the progress notification (S225) to the reception of the progress response. In this embodiment, the device processor 110 determines that a progress response has been received if a progress response is received before the third waiting time T3 has elapsed since the transmission of the progress notification. If a progress response is not received before the third waiting time T3 has elapsed, the device processor 110 determines that a progress notification has not been received. The third waiting time T3 may be determined experimentally in advance so that, in the absence of a malfunction, a progress response is received before the third waiting time T3 has elapsed since the transmission of the progress notification (S225), and, in the presence of a malfunction, a time longer than the third waiting time T3 may elapse since the transmission of the progress notification without receiving a progress response. The third waiting time T3 may be, for example, 30 seconds or more and 2 minutes or less (more specifically, for example, 1 minute).

[0060] If a progress response is received before the third waiting time T3 elapses (S260: Yes), in S265, the device processor 110 proceeds with the remaining processes of the reset process. In S265 of FIG. 4, the remaining processes include deleting the communication information SSp from the non-volatile storage device 130. Completion of S265 marks the end of the reset process.

[0061] If the progress response is not received before the third waiting time T3 elapses (S260: No), in S270, the device processor 110 displays a second error on the display unit 140, indicating that the reset process has not been completed and that the progress response has not been received. The second error may include, for example, a message indicating that the reset process has not been completed and that the progress response has not been received. By observing the displayed second error, the user can recognize that the reset process has not been completed and that the device information DVp may not have been deleted from the service database D3. The user can proceed with the process to resolve the problem with the reset process, such as by inquiring about the second error with the service provider. After S270, the reset process ends.

[0062] If it is determined in S220 (FIG. 4) that a malfunction has occurred in the reset process, the device processor 110 proceeds to S305 (FIG. 5). In S305, the device processor 110 interrupts the reset process. In S310, the device processor 110 transmits an interruption notice indicating the interruption of the reset process to the management server 400. The interruption notice includes data of the one-time secret key OTK (FIG. 3: S155).

[0063] In S312, the management processor 410 determines whether the interruption notification is appropriate. Various methods may be used for the determination in S312. In this embodiment, the management processor 410 determines that the interruption notification is appropriate if the interruption notification includes the same one-time private key OTK as the one-time private key OTK included in the start response (FIG. 3: S155). If the interruption notification is not appropriate (S312: No), in S313 the management processor 410 discards the interruption notification. Then, the management processor 410 returns to the process of waiting for a notification from the device, such as a progress notification (FIG. 4: S225) or an interruption notification (FIG. 5: S310).

[0064] If the interruption notification is appropriate (S312: Yes), in S315 the management processor 410 sets the processing flag associated with the device associated with the interruption notification to off. As described above, the one-time secret key OTK included in the interruption notification is associated with the start response (FIG. 3: S155), and the start response is associated with the start notification (FIG. 3: S145). The device associated with the interruption notification is the device indicated by the device information (here, device information DVp) included in the start notification associated with the interruption notification.

[0065] In S320, the management processor 410 transmits a response to the interruption notification (S310) to the device that sent the interruption notification. This response includes data on the device associated with the interruption notification. In this embodiment, the management processor 410 references the management database D4 (FIG. 2(B)) and acquires device setting information DS associated with the device information DV of the device associated with the interruption notification. In S320 of FIG. 5, the management processor 410 acquires information SSp, SVp, and UIp associated with the device information DVp (including setting information SI). The management processor 410 transmits data representing the device information DVp and the acquired information SSp, SVp, and UIp to the device that sent the interruption notification (here, the multifunction peripheral 100). Note that, upon completion of information reception, the communication interface 180 or device processor 110 of the multifunction peripheral 100 transmits a reception response RP indicating completion of information reception to the management server 400.

[0066] Here, the processing by the multifunction peripheral 100 after S320 will be described. The processing by the server system 200 will be described later. In S325, the device processor 110 determines whether the setting information SI has been received by the multifunction peripheral 100. The setting information SI may not be received due to various reasons, such as a malfunction in the communication path between the multifunction peripheral 100 and the management server 400 or a malfunction in the server system 200. The device processor 110 may limit the waiting time from the transmission of the interruption notice (S310) to the reception of the setting information SI. In this embodiment, the device processor 110 determines that the setting information SI has been received if the setting information SI is received before the fourth waiting time T4 has elapsed since the transmission of the interruption notice. If the setting information SI is not received before the fourth waiting time T4 has elapsed, the device processor 110 determines that the setting information SI has not been received. The fourth waiting time T4 may be experimentally determined in advance so that, if there is no malfunction, the setting information SI is received before the fourth waiting time T4 has elapsed since the transmission of the interruption notice (S310), and, if there is a malfunction, a time longer than the fourth waiting time T4 may elapse without the setting information SI being received since the transmission of the interruption notice. The fourth waiting time T4 may be, for example, 30 seconds or more and 2 minutes or less (more specifically, for example, 1 minute).

[0067] If the setting information SI is not received before the fourth waiting time T4 elapses (S325: No), in S330, the device processor 110 displays a third error on the display unit 140. The third error may include, for example, a message indicating that the setting information SI has not been received. By observing the displayed third error, the user can recognize that a malfunction in the reset process may have occurred. The user can proceed with the process to resolve the malfunction in the reset process, such as by inquiring about the third error with the service provider. After S330, the reset process ends.

[0068] If the setting information SI is received before the fourth waiting time T4 has elapsed (S325: Yes), then in S350 the device processor 110 stores the received information SSp, SVp, and UIp (including the setting information SI) in the non-volatile storage device 130. This restores the settings of the multifunction peripheral 100 to the settings before the start of the reset process.

[0069] In S355, the device processor 110 displays a fourth error on the display unit 140. The fourth error may include, for example, a message indicating that the settings of the multifunction peripheral 100 have been restored to the settings before the start of the reset process. By observing the displayed fourth error, the user can recognize that the settings of the multifunction peripheral 100 have been restored. The user can proceed with processing to resolve the problem with the reset process, such as entering a reset command again or inquiring about the fourth error with the service provider. After S355, the reset process ends.

[0070] Next, the processing by the server system 200 after S320 (FIG. 5) will be described. In S360, the management processor 410 determines whether the transmission of the setting information was successful. Various methods may be used for the determination in S360. In this embodiment, the management processor 410 determines that the transmission of the setting information was successful if the management server 400 receives a reception response RP from the multifunction peripheral 100 in S320.

[0071] If the sending of the setting information was successful (S360: Yes), in S365 the management processor 410 sends a first reset notification to the service server 300. The first reset notification indicates that the reset process has started, that the reset process may have a problem, and that the device settings have been restored. The first reset notification includes data on the device information DV (here, device information DVp) of the target of the interrupted reset process.

[0072] In S370, the service processor 310 executes a first process in response to the first reset notification. After S370, the server process ends. The first process may be any process suitable for service when the reset process is initiated and the reset process has a malfunction. The first reset notification indicates that the device settings have been restored. Therefore, the service processor 310 may provide the service associated with the device information DVp that is the target of the reset process, just as it was before the reset process began. For example, the first process may include a process of setting the status ST associated with the device information DVp in the service database D3 (FIG. 2(A)) to "providing." Thereafter, the reset process may be executed again when the user inputs a reset instruction into the multifunction peripheral 100.

[0073] The first reset notification also indicates that the device administrator requests a reset process. If the reset process is completed successfully, a new registration process for the device may then be performed. Therefore, the first process may include a process for allowing a new registration of the device information DVp that is the target of the reset process. For example, the service processor 310 may set the status ST associated with the device information DVp in the service database D3 to "available and re-registration possible." If the status ST indicates "re-registration possible," in the new registration process for the device information DVp, the service processor 310 may delete the old information associated with the device information DVp from the service database D3 and register the new information associated with the device information DVp in the service database D3. If the status ST does not indicate "re-registration possible," the service processor 310 may reject the new registration process for the device information DVp.

[0074] If the transmission of the setting information is not successful (S360: No), in S410 (FIG. 6), the management processor 410 sends a second reset notification to the service server 300. The second reset notification indicates that the reset process has started, that the reset process may have a problem, and that the information stored in the device has been partially deleted. The second reset notification includes data on the device information DV (here, device information DVp) of the target of the interrupted reset process.

[0075] In S415, the service processor 310 executes a second process in response to the second reset notification. After S415, the server process ends. The second process may be various processes suitable for a service when the reset process is initiated and the reset process has a malfunction. The second reset notification indicates that some of the device settings have been deleted. That is, the device may not have some of the information used for the service. Therefore, the second process may include a process for stopping the provision of a service associated with the device information DVp that is the target of the reset process. For example, the service processor 310 may set the status ST associated with the device information DVp in the service database D3 (FIG. 2(A)) to "canceled." This causes the service server 300 to stop providing the service associated with the device information DVp.

[0076] The second reset notification also indicates that the device administrator desires a reset process. Therefore, the second process may include a process of allowing new registration of the device information DVp that is the target of the reset process. For example, the service processor 310 may set the status ST associated with the device information DVp in the service database D3 to "cancelled and re-registration allowed." Alternatively, the second process may include a process of deleting information associated with the device information DVp from the service database D3. In this case, the device information DVp may be registered in the service database D3 by a new registration process. In the new registration process, the device associated with the device information DVp (here, the multifunction peripheral 100) may delete from the non-volatile storage device 130 any information that was not deleted during the interrupted reset process.

[0077] Next, a case will be described where, in S230 of FIG. 4, a progress notification is not received before the second waiting time T2 has elapsed. In this case (S230: No), the management processor 410 proceeds to S315 of FIG. 5. As described above, if a progress notification is not received before the second waiting time T2 has elapsed, a malfunction in the reset process may have occurred in the multifunction device 100. The management processor 410 executes the same process as when the management server 400 receives an interruption notification from the multifunction device 100 (S310). For example, the management processor 410 sets the processing flag to OFF (S315) and transmits information data including the setting information SI to the multifunction device 100 (S320).

[0078] Let us assume that the transmission of the progress notification (S225 in FIG. 4) is delayed due to a malfunction of the multifunction device 100. In this case, the multifunction device 100 receives the setting information SI (S320) even though it has not transmitted the interruption notification (S310 in FIG. 5). In this case, in S325, the device processor 110 determines that the setting information SI will be received regardless of the interruption notification (S310) (S325: Yes). The device processor 110 then prioritizes processing the received setting information SI over deleting information from the nonvolatile storage device 130. Specifically, the device processor 110 executes S350 and S355. After S355, the reset process ends.

[0079] Let us assume that there is no problem with the multifunction device 100, but that there is a problem with the communication path between the multifunction device 100 and the management server 400. In this case, the multifunction device 100 cannot receive the start response (FIG. 3: S155) or the progress response (FIG. 4: S255). Therefore, the device processor 110 displays a first error (FIG. 3: S165) or a second error (FIG. 4: S270). Then, the reset process ends.

[0080] As described above, in this embodiment, the communication system 1000 (FIG. 1) includes the server system 200 and the multifunction peripheral 100. The multifunction peripheral 100 is an example of a device used for a service. The server system 200 includes a management processor 410 and a first storage area SA1. The management processor 410 is an example of a server control unit that controls the server system 200 (hereinafter, the management processor 410 will also be referred to as the server control unit 410). As shown in FIG. 2(A), the first storage area SA1 is configured to store device information DV (e.g., device information DVp) indicating a device and user information US (e.g., user information USi) indicating a user associated with a service, in association with each other.

[0081] The multifunction peripheral 100 includes a device processor 110 and a nonvolatile storage device 130. The device processor 110 is an example of a device control unit that controls the multifunction peripheral 100 (hereinafter, the device processor 110 will also be referred to as the device control unit 110). The nonvolatile storage device 130 is configured to store information including device information DVp and setting information SI. The setting information SI includes communication information SSp and service information SVp. The communication information SSp and service information SVp are examples of setting information that indicate settings used for a service.

[0082] The device control unit 110 and the server control unit 410 execute the following processes. In S145 (FIG. 3), the device control unit 110 transmits a start notification, which is a notification including device information DVp, to the server system 200 (in this embodiment, the management server 400), in response to a reset instruction (S140) from the user of the multifunction peripheral 100. In S155, when the start notification is received by the server system 200 (in this embodiment, the management server 400), the server control unit 410 transmits a start response, which is a response to the start notification, to the multifunction peripheral 100.

[0083] As explained in S160 (FIG. 3), the device control unit 110 determines whether a start response is received by the multifunction peripheral 100 before the first waiting time T1 has elapsed. If the determination result in S160 is Yes (C1), the device control unit 110 starts the reset process in S210 (FIG. 4). The reset process includes processes (S215, S265) for deleting the setting information SI (information SSp, SVp in this embodiment) from the non-volatile storage device 130 of the multifunction peripheral 100. In this way, if the determination result in S160 is Yes (C1), this is an example of a first specific case in which the start response is received by the multifunction peripheral 100 and the reset process is started. Hereinafter, this case C1 will also be referred to as the first specific case C1.

[0084] As explained in S220 and S225 (FIG. 4), the device control unit 110 transmits a progress notification to the server system 200 (in this embodiment, the management server 400) in response to the reset process having progressed to a specific stage. The progress notification indicates the progress of the reset process up to the specific stage.

[0085] As described in S230 (FIG. 4), the server control unit 410 determines whether the progress notification is received by the management server 400 before the second waiting time T2 has elapsed. If the determination result in S230 is Yes (C2), the server control unit 410 executes S235 and S255. In S235, the server control unit 410 transmits a deletion instruction to the service server 300. In response to the deletion instruction, the service processor 310 deletes the device information DVp from the service database D3 (i.e., the first storage area SA1). Thus, transmitting the deletion instruction (S235) is an example of processing for deleting the device information DVp from the service database D3 (i.e., from the first storage area SA1). In S255, the server control unit 410 transmits a progress response, which is a response to the progress notification (S225), to the multifunction peripheral 100. Thus, when the determination result of S230 is Yes, C2 is an example of a second specific case in which the progress notification is received by the server system 200 (in this embodiment, the management server 400), and a process (S235) for deleting the device information DVp from the first storage area SA1 and a process (S255) for sending a progress response to the multifunction peripheral 100 are executed. Hereinafter, this case C2 will also be referred to as the second specific case C2.

[0086] As described in S260 (FIG. 4), the device control unit 110 determines whether or not a progress response is received before the third waiting time T3 has elapsed. If the determination result in S260 is Yes (C3), the device control unit 110 executes the remaining processes of the reset process in S265. Thus, if the determination result in S260 is Yes (C3), this is an example of a third specific case in which the progress response is received by the multifunction peripheral 100 and the remaining processes of the reset process are executed. Hereinafter, this case C3 will also be referred to as the third specific case C3.

[0087] According to the above configuration, the device control unit 110 and the server control unit 410 use the start notification, start response, progress notification, and progress response to proceed with the reset process, which includes deleting the device information DVp from the first storage area SA1 of the server system 200 and deleting the setting information SI from the non-volatile storage device 130 of the multifunction device 100, thereby reducing the possibility of information inconsistency occurring between the multifunction device 100 and the server system 200.

[0088] In this embodiment, in S125 and S130 (FIG. 3), the device control unit 110 authenticates the user of the multifunction peripheral 100. In S135 and S140, if the authentication is successful (S135: Yes), the device control unit 110 accepts a reset instruction. Therefore, the device control unit 110 can reduce the possibility that the reset process will be executed by mistake.

[0089] Furthermore, in this embodiment, if a start response (S155) is not received by the multifunction peripheral 100 (S160: No) before the first waiting time T1 has elapsed since the start notification was sent (S145 in FIG. 3), the device control unit 110 does not start the reset process. In a first specific case C1 (S160: Yes) in which the start response (S155) is received by the multifunction peripheral 100 before the first waiting time T1 has elapsed since the start notification was sent (S145), the device control unit 110 starts the reset process (S210 in FIG. 4). Therefore, if there is a problem with the communication path between the multifunction peripheral 100 and the server system 200 or with the server system 200, the device control unit 110 can reduce the possibility of proceeding with the reset process without cooperating with the server system 200.

[0090] In this embodiment, the multifunction peripheral 100 (FIG. 1) also includes a display unit 140. As described in S260 and S270 (FIG. 4), if a progress response is not received by the device (S260: No), the device control unit 110 displays a second error on the display unit 140 (S270). The second error indicates that the reset process has not been completed. By observing the second error, the user can recognize that the reset process has not been completed (and thus the possibility of an information inconsistency between the multifunction peripheral 100 and the server system 200).

[0091] In this embodiment, the server system 200 (FIG. 1) includes a management server 400 having a server control unit 410, and a service server 300 having a first storage area SA1. The device control unit 110 transmits a start notification (FIG. 3: S145) and a progress notification (FIG. 4: S225) to the management server 400. In a second specific case C2 in which the progress notification is received by the management server 400 (FIG. 4: S230: Yes), the server control unit 410 transmits to the service server 300 an instruction to delete the device information DVp from the first storage area SA1 of the service server 300 (S235). If the progress notification is not received by the management server 400 (FIG. 4: S230: No) after transmitting the start response (FIG. 3: S155), the server control unit 410 transmits a first reset notification (FIG. 5: S365) or a second reset notification (FIG. 6: S410) to the service server 300. As described above, the first reset notification and the second reset notification indicate the start of the reset process.

[0092] According to this configuration, in the second specific case C2, the server control unit 410 can cause the service server 300 to delete the device information DVp. Furthermore, if a progress notification is not received by the management server 400 after the start response is transmitted (S230: No), the server control unit 410 transmits a notification indicating the start of the reset process to the service server (S365 or S410), and the server control unit 410 can cause the service server 300 to perform a process other than deleting the device information DVp. For example, in response to the notification indicating the start of the reset process, the service server 300 may perform a process that allows new registration of the device information DVp (i.e., new storage of the device information DVp in the first storage area SA1).

[0093] In this embodiment, the server system 200 (FIG. 1) further includes a second storage area SA2 (FIG. 2B) configured to store the device information DVp and the setting information SI in association with each other. If a malfunction occurs in the reset process after the start of the reset process (FIG. 4: S220), the device control unit 110 interrupts the reset process (FIG. 5: S305) and transmits an interruption notice indicating the interruption of the reset process to the server system 200 (S310). If the interruption notice is received by the server system 200, the server control unit 410 transmits the setting information SI to the device (S320). In S325, the device control unit 110 determines whether the setting information SI is received by the multifunction peripheral 100 before the fourth waiting time T4 has elapsed. If the determination result in S325 (FIG. 5) is Yes (C4), the device control unit 110 stores the setting information SI in the storage device 115 of the multifunction peripheral 100 (S350). This configuration reduces the possibility that the setting information SI in the multifunction device 100 will be partially lost due to an interruption of the reset process. Note that the case C4 where the determination result in S325 is Yes is an example of a fourth specific case in which the setting information SI is received by the multifunction device 100 and stored in the non-volatile storage device 130 of the multifunction device 100. Hereinafter, this case C4 will be referred to as the fourth specific case C4.

[0094] In this embodiment, the server system 200 (FIG. 1) further includes a second storage area SA2 (FIG. 2(B)) configured to store the device information DVp and the setting information SI in association with each other. If the server system 200 does not receive a progress notification (FIG. 4: S225) after transmitting the start response (FIG. 3: S155) (S230: No), the server control unit 410 transmits the setting information SI to the device (FIG. 5: S320). As described above, if the setting information SI is received by the multifunction peripheral 100 (S325: Yes), the device control unit 110 stores the setting information SI in the non-volatile storage device 130 of the multifunction peripheral 100 (S350). This configuration reduces the possibility that the setting information SI in the multifunction peripheral 100 will be partially lost.

[0095] 4, the second specific case C2 is a case where the progress notification is received by the server system 200 before the second waiting time T2 has elapsed since the transmission of the start response. Therefore, the server control unit 410 can execute processing to delete the device information DVp from the first storage area SA1 in the second specific case C2 where the progress notification is properly received.

[0096] 4, the third specific case C3 is a case where a progress response is received by the multifunction peripheral 100 before the third waiting time T3 has elapsed since the transmission of the progress notification. Therefore, the device control unit 110 can execute the remaining processes of the reset process in the third specific case C3 where the progress response is properly received.

[0097] Furthermore, in this embodiment, as described in S312 and S320 (FIG. 5), if the interruption notification is appropriate, the server control unit 410 transmits device information to the device that sent the interruption notification. This reduces the possibility that the device information will be erroneously transmitted to another device. Note that the method for determining whether the interruption notification is appropriate is not limited to the method using the one-time private key OTK included in the start response (FIG. 3: S155), and various other methods may be used. For example, the one-time private key OTK may be omitted, and a private key previously associated with the device information DVp may be used.

[0098] In this embodiment, the management server 400 (FIG. 1) has the following configuration. The management server 400 is configured to communicate with each of the service server 300 and the multifunction peripheral 100. The multifunction peripheral 100 is an example of a device used for a service. The management server 400 includes a server control unit 410. The service server 300 includes a first storage area SA1 (FIG. 2(A)). The first storage area SA1 is configured to store device information DV (e.g., device information DVp) indicating a device and user information US (e.g., user information USi) indicating a user associated with a service, in association with each other. The multifunction peripheral 100 includes a non-volatile storage device 130 configured to store the device information DVp and setting information SI indicating settings used for the service. In the specific case C2 (FIG. 4: S230: Yes) in which the management server 400 receives a progress notification from the multifunction peripheral 100, the server control unit 410 transmits to the service server 300 an instruction to delete the device information DVp from the first storage area SA1 of the service server 300 (S235). As described in S220 of FIG. 4, the progress notification (S225) is a notification transmitted by the multifunction peripheral 100 in response to the reset process having progressed to a specific stage. The reset process includes processes (S215, S265) in which the setting information SI (information SSp, SVp in this embodiment) is deleted from the non-volatile storage device 130 of the multifunction peripheral 100. In this way, in the specific case C2 in which the management server 400 receives a progress notification from the multifunction peripheral 100, the server control unit 410 transmits to the service server 300 an instruction to delete the device information DVp. Therefore, the possibility of an information inconsistency occurring between the multifunction peripheral 100 and the service server 300 is reduced compared to when an instruction to delete the device information DVp is sent in response to a start notification (FIG. 3: S145).

[0099] In this embodiment, the multifunction peripheral 100 (FIG. 1) has the following configuration. The multifunction peripheral 100 is an example of a device used for a service, and is configured to communicate with the server system 200. The multifunction peripheral 100 includes a device control unit 110 and a nonvolatile storage device 130. The nonvolatile storage device 130 is configured to store device information DVp indicating the device and setting information SI indicating the settings used for the service. In S145 (FIG. 3), the device control unit 110 transmits a start notification, which is a notification including the device information DVp, to the server system 200 (in this embodiment, the management server 400), in response to a reset instruction (S140) from the user of the multifunction peripheral 100.

[0100] As explained in S160 (FIG. 3), the device control unit 110 does not start the reset process if the determination result in S160 is No, but starts the reset process in the first specific case C1 where the determination result in S160 is Yes (FIG. 4: S210). In S160, the device control unit 110 determines whether a start response (S155) is received by the multifunction peripheral 100 before the first waiting time T1 has elapsed since the start notification was sent (FIG. 3: S145). The start response is a response from the server system 200 to the start notification (S145). The reset process includes processes (S215, S265) for deleting the setting information SI from the nonvolatile storage device 130 of the multifunction peripheral 100.

[0101] As described in S220 and S225 (FIG. 4), the device control unit 110 transmits a progress notification to the server system 200 (to the management server 400 in this embodiment) in response to the reset process having progressed to a specific stage. The progress notification indicates the progress of the reset process to a specific stage. As described in S260 (FIG. 4), if the determination result in S260 is Yes (C3), the device control unit 110 executes S265. In S260, the device control unit 110 determines whether or not a progress response is received within the third waiting time T3 from the transmission of the progress notification. In S265, the device control unit 110 executes the remaining processes of the reset process. Thus, if the determination result in S260 is Yes (C3), the MFP 100 receives a progress response, which is a response from the server system 200 to the progress notification, and executes the remaining processes of the reset process.

[0102] According to the above configuration, the device control unit 110 proceeds with the reset process by using the start notification, start response, progress notification, and progress response, thereby reducing the possibility that the information in the multifunction device 100 will become inconsistent with the information in the server system 200.

[0103] B. Variations: (1) The authentication method in S130 (FIG. 3) may be various methods. For example, the device control unit 110 may perform user authentication by communicating with an authentication server (not shown). The user authentication may be authentication of a user associated with a service that uses the multifunction peripheral 100. The user authentication may be performed by the service server 300. Note that the user authentication for accepting a reset instruction may be omitted.

[0104] (2) The order in which multiple pieces of information are deleted by the reset process may be various. For example, instead of the order of information UIp, SVp, SSp, the order of deletion may be information SVp, UIp, SSp. Note that it is preferable that information used for communication with the server system 200 (e.g., communication information SSp) be deleted last. Also, the information deleted by the reset process may be various information including setting information indicating settings used for a service. For example, user setting information UIp does not need to be deleted by the reset process. Also, device information DVp may be deleted by the reset process. In this case, the server system 200 (e.g., service server 300 or management server 400) may assign a device identifier (and therefore device information DV) to the device in the device registration process.

[0105] In either case, the device control unit 110 may send a progress notification (FIG. 4: S225) to the server system 200 in response to the reset process having progressed to a specific stage. The specific stage may be any stage of the reset process. For example, the specific stage may be a stage at which one or more pieces of information that are a predetermined part of the plurality of pieces of information to be deleted have been deleted.

[0106] (3) The first specific case in which the reset process is initiated is not limited to the case C1 in which the determination result in S160 (FIG. 3) is Yes, but may also be the case in which a first specific condition is satisfied. The first specific condition may be various conditions, including the start response (S155) being received by the multifunction peripheral 100. For example, as described in S160, the first specific condition may include a first waiting time condition indicating that the start response (S155) is received by the multifunction peripheral 100 before the first waiting time T1 has elapsed since the start notification (S145) was transmitted. The first specific condition may also include other conditions, such as obtaining a user instruction indicating the progress of the reset process. In either case, if the first specific condition includes the first waiting time condition, the case in which the first specific condition is satisfied (i.e., the first specific case) is the specific case in which the start response is received by the multifunction peripheral 100 before the first waiting time T1 has elapsed since the start notification was transmitted.

[0107] (4) The second specific case in which S235 and S255 in FIG. 4 are executed is not limited to the case C2 in which the determination result in S230 is Yes, but may also be a case in which a second specific condition is satisfied. The second specific condition may be various conditions, including a progress notification being received by the server system 200. For example, as described in S230, the second specific condition may include a second waiting time condition indicating that a progress notification (S225 in FIG. 4) is received by the server system 200 before the second waiting time T2 has elapsed since the transmission of the start response (S155 in FIG. 3). The second specific condition may also include other conditions, such as obtaining a user instruction indicating the progress of the reset process (the device control unit 110 may provide the management server 400 with the user instruction input to the multifunction peripheral 100). In either case, if the second specific condition includes a second waiting time condition, the case in which the second specific condition is satisfied (i.e., the second specific case) is the specific case in which a progress notification is received by the server system 200 before the second waiting time T2 has elapsed since the sending of the start response.

[0108] The server control unit 410 may start a timer in response to receiving the start notification (S145). That is, in S230 (FIG. 4), the server control unit 410 may determine whether a progress notification will be received before a predetermined waiting time has elapsed since receiving the start notification. Here, the server control unit 410 may transmit the start response after the processing time has elapsed since receiving the start notification. In this case, it can be said that in S230, the server control unit 410 determines whether a progress notification will be received before the second waiting time T2, which is the time remaining after subtracting the processing time from the specific waiting time, has elapsed since transmitting the start response. Note that if the server control unit 410 does not communicate with a device other than the management server 400 between receiving the start notification (S145) and transmitting the start response (S155), the processing time from receiving the start notification to transmitting the start response is approximately constant. That is, the second waiting time T2 is approximately constant.

[0109] (5) The third specific case in which the remaining process of the reset process (S265 in FIG. 4) is executed is not limited to the case C3 in which the determination result of S260 is Yes, but may also be the case in which a third specific condition is satisfied. The third specific condition may be various conditions, including the progress response (S255) being received by the multifunction peripheral 100. For example, as described in S260, the third specific condition may include a third waiting time condition indicating that the progress response (S255) is received by the multifunction peripheral 100 before the third waiting time T3 has elapsed since the transmission of the progress notification (S225). The third specific condition may also include other conditions, such as obtaining a user instruction indicating the progress of the reset process. In either case, if the third specific condition includes the third waiting time condition, the case in which the third specific condition is satisfied (i.e., the third specific case) is the specific case in which the progress response is received by the multifunction peripheral 100 before the third waiting time T3 has elapsed since the transmission of the progress notification.

[0110] (6) The fourth specific case in which the setting information SI is stored in the non-volatile storage device 130 of the multifunction peripheral 100 after the transmission of the interruption notice (S310 in FIG. 5) is not limited to the case C4 in which the determination result in S325 is Yes, but may also be the case in which a fourth specific condition is satisfied. The fourth specific condition may be various conditions including the setting information SI (S320) being received by the multifunction peripheral 100. For example, as described in S325, the fourth specific condition may include a fourth waiting time condition indicating that the setting information SI (S320) is received by the multifunction peripheral 100 before the fourth waiting time T4 has elapsed since the transmission of the interruption notice (S310). The fourth specific condition may include other conditions, such as obtaining a user instruction indicating storage of the setting information SI. In either case, if the fourth specific condition includes a fourth waiting time condition, the case in which the fourth specific condition is satisfied (i.e., the fourth specific case) is a specific case in which the setting information SI is received by the multifunction device 100 before the fourth waiting time T4 has elapsed since the transmission of the interruption notification.

[0111] (7) The process for deleting the device information DVp from the first storage area SA1 is not limited to sending a deletion instruction (S235 (FIG. 4)), and may be various processes for deleting the device information DVp from the first storage area SA1. For example, the first storage area SA1 may be provided in the non-volatile storage device 430 of the management server 400. Instead of S235, the server control unit 410 may delete the device information DVp from the first storage area SA1 by controlling the non-volatile storage device 430. The server control unit 410 may further delete information associated with the device information DVp (here, the status ST) from the first storage area SA1.

[0112] (8) In S270 (FIG. 4), which is executed when the progress response (S255 in FIG. 4) is not received by the multifunction peripheral 100 (for example, when the progress response is not received before the third waiting time T3 has elapsed since the transmission of the progress notification (S225)), the device control unit 110 may display various information indicating that the reset process is not complete, in addition to the message described above. For example, the display unit 140 of the multifunction peripheral 100 may include a lamp (for example, a light-emitting diode). The device control unit 110 may blink the lamp in a specific blinking pattern indicating that the reset process is not complete. The blinking pattern is a pattern that represents the change in the illumination state (on or off) of the lamp over time. Note that the display of the information (for example, S270) may be omitted. Instead, the device control unit 110 may transmit information indicating that the reset process is not complete to an external device other than the multifunction peripheral 100 and the server system 200. For example, the device control unit 110 may send an electronic message (for example, an email) indicating that the reset process is not complete. The destination of the electronic message may be specified by the user during the service registration process (e.g., the user's email address, etc.). The transmitted information is received by a device associated with the destination (e.g., a terminal device such as a smartphone). The destination of the electronic message may be included in the communication information SSp.

[0113] (9) If the progress notification (FIG. 4: S225) is not received by the management server 400 (for example, if the progress notification is not received before the second waiting time T2 has elapsed since the transmission of the start response (FIG. 3: S155)), the server control unit 410 sends a notification indicating the start of reset processing to the service server 300 in S365 (FIG. 5) or S410 (FIG. 6). In response to the notification indicating the start of reset processing, the service processor 310 may execute various processes appropriate for the service.

[0114] For example, the service may be a service that does not require a fee (e.g., a remote printing service). In this case, a new registration process for the multifunction peripheral 100 allows the service to be started easily using the multifunction peripheral 100. Therefore, the service processor 310 may execute a process to delete the device information DVp from the first storage area SA1. For example, one or both of the first process (S370 in FIG. 5) and the second process (S415 in FIG. 6) may include a process to delete the device information DVp from the first storage area SA1.

[0115] Furthermore, services may include processes involving changes in monetary values, such as charging for the number of printed pages or awarding points for replacing cartridges containing color materials (ink, toner, etc.). In this case, deleting the device information DVp from the first storage area SA1 may result in disadvantages to the user, such as the loss of points or double payment due to re-registration of the multifunction peripheral 100. Therefore, in such cases, it is preferable for the service processor 310 to maintain the device information DVp rather than deleting it from the first storage area SA1. Here, the service processor 310 may temporarily suspend provision of the service associated with the device information DVp. For example, one or both of the first process (S370 in FIG. 5) and the second process (S415 in FIG. 6) may include a process of temporarily suspending provision of the service associated with the device information DVp without deleting the device information DVp.

[0116] The first process may include a process that is not included in the second process. Similarly, the second process may include a process that is not included in the first process. The second process may be the same as the first process.

[0117] Also, S360 (FIG. 5) may be omitted. That is, if the management server 400 does not receive a progress notification (FIG. 4: S225) after transmitting the start response (FIG. 3: S155) (for example, if the progress notification is not received before the second waiting time T2 has elapsed since the transmission of the start response), the server control unit 410 may transmit a notification indicating the start of the reset process to the service server. Then, in response to this notification, the service processor 310 may execute various processes appropriate for the service.

[0118] Note that the transmission of a notification indicating the start of the reset process (e.g., S365, S410) may be omitted. Instead, the server control unit 410 may transmit information indicating the start of the reset process to an external device other than the multifunction peripheral 100 and the server system 200. For example, the server control unit 410 may transmit an electronic message (e.g., email) indicating the start of the reset process. The destination of the electronic message may be predetermined by the service provider (e.g., the email address of an administrator). The transmitted information is received by a device associated with the destination (e.g., a terminal device such as a smartphone).

[0119] (10) The process (e.g., S115 and S120 in FIG. 3) of associating the device information DVp with the setting information SI and storing them in the management database D4 (i.e., the second storage area SA2 (FIG. 2(B))) may be executed at various times, not just when the multifunction peripheral 100 is registered. For example, the device control unit 110 may periodically transmit the latest setting information SI to the management server 400. Alternatively, the device control unit 110 may transmit the setting information SI to the management server 400 in response to successful user authentication (S125, S130, S135). Alternatively, the device control unit 110 may transmit the setting information SI to the management server 400 in response to a reset instruction (FIG. 3: S140). For example, the device control unit 110 may transmit the setting information SI to the management server 400 together with a start notification (FIG. 3: S145).

[0120] In either case, the server control unit 410 may delete the setting information SI from the management database D4 (i.e., from the second storage area SA2) in response to transmission of the setting information SI to the multifunction peripheral 100. This reduces the possibility of unintended leakage of the setting information SI. Furthermore, the determination of whether the interruption notice is appropriate (FIG. 5: S312) may be omitted. Furthermore, transmission of the setting information SI (S320) when the interruption notice (FIG. 5: S310) is received by the server system 200 may be omitted. In this case, steps S325-S355 by the device control unit 110 after transmission of the interruption notice (S310) may be omitted. Alternatively, the device control unit 110 may display information indicating the interruption of the reset process on the display unit 140.

[0121] (11) If a progress notification (FIG. 4: S225) is not received by the server system 200 after the start response (FIG. 3: S155) is sent (for example, if a progress notification is not received before the second waiting time T2 has elapsed since the start response was sent), the sending of the setting information SI (FIG. 5: S320) may be omitted.

[0122] (12) If the server system 200 does not receive a progress notification (FIG. 4: S225) after transmitting the start response (FIG. 3: S155) (for example, if the progress notification is not received before the second waiting time T2 has elapsed since the transmission of the start response), the communication path between the multifunction peripheral 100 and the server system 200 may have a malfunction. Therefore, the transmission of the setting information SI to the multifunction peripheral 100 (FIG. 5: S320) may fail. If the server system 200 does not receive a progress notification after transmitting the start response, the server control unit 410 may transmit information indicating that the setting information SI in the multifunction peripheral 100 may have a malfunction (for example, partial loss) to an external device other than the multifunction peripheral 100 and the server system 200. For example, the server control unit 410 may send an electronic message such as an email. The destination of the electronic message may be predetermined by the service provider. The transmitted information is received by a device associated with the destination.

[0123] (13) The processes executed by the multifunction peripheral 100 and the server system 200 are not limited to those shown in Figures 3 to 6, and may be various other processes. For example, S312 (Figure 5) may be omitted.

[0124] (14) The method of communicating with the server system 200 may be various methods other than the method using a URL. For example, the multifunction peripheral 100 and the management server 400 may communicate via a constant connection. In this case, the communication information SSp may include information used for the constant connection (e.g., a token, a session ID, etc.). The constant connection may be established, for example, according to XMPP (eXtensible Messaging and Presence Protocol) or MQTT (Message Queuing Telemetry Transport). Similarly, the multifunction peripheral 100 and the service server 300 may communicate via a constant connection. Note that the multifunction peripheral 100 and the management server 400 may send and receive information using a management URL, and may communicate via the constant connection if a problem occurs in this communication (e.g., a timeout).

[0125] (15) The services provided by the server system 200 are not limited to remote printing services and may be various other services. For example, the server system 200 may provide a delivery service that acquires the remaining amount of consumables (ink, paper, etc.) via the network IT and delivers the consumables to the user according to the remaining amount. The server system 200 may also provide a service that acquires scan data generated by the reading execution unit 170 via the network IT and saves the scan data in a storage device of a server (not shown) designated by the user. In this way, the services may be services unrelated to printing.

[0126] The device used for the service is not limited to the multifunction peripheral 100 (FIG. 1), but may be any device suitable for the service. For example, if the service is related to printing, the device may be a variety of devices including a printer. If the service is related to optically reading an object, the device may be a variety of devices including a reader.

[0127] (16) The configuration of the server system is not limited to the configuration of server system 200 (FIG. 1), and various configurations are possible. For example, multiple processing modules may each share a portion of the processing of management server 400. In this case, the multiple processing modules as a whole correspond to management server 400. A processing module may be, for example, a physical computer or a virtualized computer. Similarly, multiple processing modules may each share a portion of the processing of service server 300. Furthermore, one processing module may execute both the processing of service server 300 and the processing of management server 400. Furthermore, first storage area SA1 may be provided in management server 400. Furthermore, S245 (FIG. 4), S370 (FIG. 5), and S415 (FIG. 6) may be executed by management server 400. In this case, service server 300 may be omitted from server system 200.

[0128] In each of the above embodiments, a part of the configuration realized by hardware may be replaced by software, and conversely, a part or all of the configuration realized by software may be replaced by hardware. For example, the reset process by the multifunction peripheral 100 may be executed by a dedicated hardware circuit such as an Application Specific Integrated Circuit (ASIC).

[0129] Furthermore, when some or all of the functions of the present disclosure are realized by a computer program, the program can be provided in a form stored on a computer-readable recording medium (e.g., a non-transitory recording medium). The program can be used in a state stored on the same or a different recording medium (computer-readable recording medium) from when it was provided. The "computer-readable recording medium" is not limited to portable recording media such as memory cards and CD-ROMs, but can also include internal storage devices within a computer, such as various ROMs, and external storage devices connected to a computer, such as a hard disk drive.

[0130] The above-described examples and modifications can be combined as appropriate. The above-described examples and modifications are provided to facilitate understanding of the present disclosure and are not intended to limit the present invention. The present invention may be modified or improved without departing from the spirit thereof, and the present invention includes equivalents thereof. [Explanation of symbols]

[0131] 100...multifunction device, 110...device processor (device control unit), 200...server system, 300...service server, 310...service processor, 400...management server, 410...management processor (server control unit), 115, 315, 415...storage device, 120, 320, 420...volatile storage device, 130, 330, 430...non-volatile storage device, 180, 380, 480...communication interface, 140...display unit, 150...operation unit, 160...print execution unit, 170...read execution unit, 1000...communication system, PG1, PG3, PG4...program, D3...service database, D4...management database

Claims

1. A communication system including a server system and a device used for a service, The server system includes: a server control unit; a first storage area configured to store device information indicating the device and user information indicating a user associated with a service in association with each other; Equipped with The device comprises: a device control unit; a storage device configured to store the device information and setting information indicating settings to be used for the service; Equipped with the device control unit transmits a start notification, which is a notification including the device information, to the server system in response to a reset instruction from a user of the device; the server control unit, when the start notification is received by the server system, transmits a start response to the start notification to the device; The device control unit Initiating a reset process, including deleting the configuration information from the storage device of the device, in a first specific case in which the initiation response is received by the device; In response to the reset process having progressed to a specific stage, transmitting a progress notification indicating the progress of the reset process to the specific stage to the server system; The server control unit, in a second specific case in which the progress notification is received by the server system, a process for deleting the device information from the first storage area of ​​the server system; sending a progress response to the progress notification to the device; Run the device control unit executes the remaining process of the reset process in a third specific case in which the progress response is received by the device. Communication system.

2. 2. The communication system of claim 1, The device control unit authenticating the user of the device; If the authentication is successful, the reset instruction is accepted. Communication system.

3. 3. A communication system according to claim 1 or 2, The device control unit If the start response is not received by the device before a first waiting time has elapsed since the transmission of the start notification, the reset process is not started, Initiating the reset process in the first specific case where the initiation response is received by the device before the first waiting time has elapsed since the transmission of the initiation notification. Communication system.

4. 3. A communication system according to claim 1 or 2, the device includes a display device; If the progress response is not received by the device, the device control unit displays information indicating that the reset process is not completed on the display device. Communication system.

5. 3. A communication system according to claim 1 or 2, The server system includes: a management server having the server control unit; a service server having the first storage area; Including, the device control unit transmits the start notification and the progress notification to the management server; The server control unit In the second specific case in which the progress notification is received by the management server, sending an instruction to the service server to delete the device information from the first storage area of ​​the service server; If the progress notification is not received by the management server after the start response is sent, sending a notification indicating the start of the reset process to the service server. Communication system.

6. 3. A communication system according to claim 1 or 2, the server system further includes a second storage area configured to store the device information and the setting information in association with each other; When a malfunction of the reset process occurs after the start of the reset process, the device control unit: The reset process is interrupted, Sending an interruption notice to the server system indicating an interruption of the reset process; the server control unit transmits the setting information to the device when the interruption notification is received by the server system; the device control unit stores the setting information in the storage device of the device in a fourth specific case in which the setting information is received by the device; Communication system.

7. 3. A communication system according to claim 1 or 2, the server system further includes a second storage area configured to store the device information and the setting information in association with each other; the server control unit transmits the setting information to the device when the progress notification is not received by the server system after the start response is transmitted; the device control unit stores the setting information in the storage device of the device when the setting information is received by the device; Communication system.

8. 3. A communication system according to claim 1 or 2, The second specific case is when the progress notification is received by the server system before a second waiting time has elapsed since the transmission of the start response. Communication system.

9. 3. A communication system according to claim 1 or 2, The third specific case is when the progress response is received by the device before a third waiting time has elapsed since the transmission of the progress notification. Communication system.

10. a management server configured to communicate with each of the service servers and the devices used for the service, A server control unit is provided, the service server includes a first storage area configured to store device information indicating a device and user information indicating a user associated with a service in association with each other; the device comprises a storage device configured to store the device information and setting information indicating settings to be used for the service; the server control unit transmits to the service server an instruction to delete the device information from the first storage area of ​​the service server in a specific case where a progress notification from the device is received by the management server, the progress notification being a notification transmitted by the device in response to a reset process having progressed to a specific stage, and the reset process includes a process of deleting the setting information from the storage device of the device; Management server.

11. 1. A device configured to communicate with a server system and used for a service, comprising: a device control unit; a storage device configured to store device information indicating the device and setting information indicating settings to be used for the service; Equipped with The device control unit In response to a reset instruction from a user of the device, a start notification is sent to the server system, the start notification being a notification including the device information; if a start response, which is a response to the start notification from the server system, is not received by the device before a first waiting time has elapsed since the transmission of the start notification, the reset process including a process of deleting the setting information from the storage device of the device is not started, and in a first specific case in which the start response is received by the device before the first waiting time has elapsed since the transmission of the start notification, the reset process is started; In response to the reset process having progressed to a specific stage, transmitting a progress notification indicating the progress of the reset process to the specific stage to the server system; In a specific case where a progress response, which is a response from the server system to the progress notification, is received by the device, the remaining processing of the reset processing is performed. device.

Citation Information

Patent Citations

  • Service cancellation method, computer program, and service cancellation system

    JP2021124782A