Authentication processing system, information processing device, and image forming apparatus
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2026-04-07
Smart Images

Figure 2026059133000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication processing system, an information processing apparatus, and an image forming apparatus.
Background Art
[0002] Conventionally, as shown in Patent Document 1, a system that uses a server to provide services related to an image forming apparatus is known.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, the convenience when using a plurality of servers was low.
Means for Solving the Problems
[0005] An authentication processing system comprising: an image forming apparatus; a terminal device; a first management server capable of issuing first authentication information to the terminal device and providing first services related to the image forming apparatus; a second management server capable of issuing second authentication information to the terminal device and providing second services related to the image forming apparatus; and an information processing device capable of authenticating the first authentication information and the second authentication information, wherein if the information processing device has received and stored the first authentication information from the first management server, it transmits first access information related to the information processing device to the image forming apparatus for printing; the terminal device obtains the first access information printed by the image forming apparatus and accesses the information processing device, transmits the first authentication information issued by the first management server; if the information processing device determines that the received first authentication information matches the first authentication information it has stored, it authenticates the first authentication information and transitions the terminal device's access destination to the first service of the first management server; and if it has received and stored second authentication information from the second management server, it transmits second access information related to the information processing device to the image forming apparatus for printing.
[0006] An information processing device provided in an authentication processing system including a processor, an image forming apparatus, a terminal device, a first management server capable of issuing first authentication information to the terminal device and providing first services related to the image forming apparatus, and a second management server capable of issuing second authentication information to the terminal device and providing second services related to the image forming apparatus, wherein the processor, when it has received and stored the first authentication information from the first management server, transmits first access information to the image forming apparatus for printing; when the terminal device obtains the first access information printed by the image forming apparatus and accesses the information processing device, the processor receives the first authentication information issued by the first management server, and if it determines that the received first authentication information matches the stored first authentication information, it authenticates the first authentication information and transitions the access destination of the terminal device to the first service of the first management server; and when it has received and stored second authentication information from the second management server, it transmits second access information to the image forming apparatus for printing.
[0007] An image forming apparatus provided in an authentication processing system comprising a processor and a head, a terminal device, a first management server capable of issuing first authentication information to the terminal device and providing a first service, a second management server capable of issuing second authentication information to the terminal device and providing a second service, and an information processing device capable of authenticating the first authentication information and the second authentication information, wherein the first service and the second service relate to the image forming apparatus, and the processor, when the information processing device has received and stored the first authentication information from the first management server, provides first access information related to the information processing device. The first access information is received and printed by the head, the terminal device obtains the printed first access information and accesses the information processing device, and transmits the first authentication information issued by the first management server, and further, the information processing device determines that the received first authentication information matches the first authentication information it stores, authenticates the first authentication information, and transitions the terminal device's access destination to the first service of the first management server, and further, if the second authentication information has been received and stored from the second management server, the second access information relating to the information processing device is received and printed by the head. [Brief explanation of the drawing]
[0008] [Figure 1] A schematic diagram showing the configuration of the authentication processing system. [Figure 2] A state transition diagram showing the process when the first and second management servers register each service of the image forming apparatus based on a request from a terminal device, and the servers store the registration information. [Figure 3] A state transition diagram showing the process when the server authenticates a terminal device for the first service of the first management server. [Figure 4] The state transition diagram follows Figure 3. [Figure 5] Following Figure 4, this is a state transition diagram when the server authenticates the terminal device regarding the second service of the second management server. [Figure 6] The state transition diagram follows Figure 5. [Modes for carrying out the invention]
[0009] 1. Configuration of the authentication processing system As shown in Figure 1, the authentication processing system 1 is composed of a first management server 10, a second management server 20, an information processing server 30, an image forming apparatus 40, and a terminal device 50. The image forming apparatus 40 and terminal device 50 are located in a designated premises 2, such as a company, factory, or store. Users use the image forming apparatus 40 and terminal device 50 within premises 2 to perform tasks such as printing. If premises 2 is a store, the image forming apparatus 40 and terminal device 50 are configured, for example, to form a POS (Point of Sale) system. In this case, the image forming apparatus 40 prints receipts. The first management server 10, the second management server 20, and the server 30 are located in a data center, for example.
[0010] The devices included in the authentication processing system 1 can communicate with each other via the Internet, which is a Wide Area Network (WAN) 60. Furthermore, the image forming apparatus 40 and the terminal device 50 may be connected to a local area network (LAN) (not shown), which is a communication network within a limited area such as a premises 2, and configured to communicate with each other. In this case, the image forming apparatus 40 and the terminal device 50 can communicate with the WAN 60 via the LAN. The LAN also includes functions such as a router and a firewall.
[0011] Each of the aforementioned devices connected to WAN60 is assigned a unique IP address (Internet Protocol Address). These devices can communicate with a destination by specifying the IP address assigned to that destination. Furthermore, these devices can communicate using protocols such as HTTP (Hypertext Transfer Protocol) and HTTPS (Hypertext Transfer Protocol Secure).
[0012] The first management server 10, the second management server 20, and the server 30 can provide various services to the image forming apparatus 40 and terminal device 50 via the WAN 60, thus forming a form of so-called cloud computing. As described later, the terminal device 50 stores a web browser in its memory and can read and execute the web browser. Such a terminal device 50 is a so-called web client.
[0013] On the other hand, the first management server 10, the second management server 20, and the server 30, as described later, store URLs (Uniform Resource Locators) and the websites corresponding to those URLs in their respective memory units. These memory units also store web pages and APIs (Application Programming Interfaces) corresponding to the URLs. These servers can retrieve web pages, APIs, and websites specified by URLs from their respective storage units and provide various services from the image forming apparatus 40 and terminal device 50. In this way, these servers are so-called web servers. APIs used in a web environment, such as authentication processing system 1, are also known as Web APIs.
[0014] The image forming apparatus 40 is configured to include a fourth control unit 41, a fourth communication unit 42, and a fourth storage unit 43. The fourth control unit 41 comprehensively controls each part of the image forming apparatus 40. The fourth control unit 41 is configured to include a CPU (Central Processing Unit), a UART (Universal Asynchronous Receiver Transmitter) for managing input / output, an FPGA (Field Programmable Gate Array) which is a logic circuit, a PLD (Programmable Logic Device), and the like. A control unit such as the fourth control unit 41 is also referred to as a processor. In addition, the CPU of the fourth control unit 41 may be particularly referred to as a processor.
[0015] The fourth storage unit 43 is configured to include memories such as a flash ROM (Read Only Memory) which is a rewritable non-volatile memory, an HDD (Hard Disk Drive), and a RAM (Random Access Memory) which is a volatile memory. Note that the non-volatile memory of the fourth storage unit 43 may include an SSD (Solid State Drive). The CPU of the fourth control unit 41 reads out a program stored in the non-volatile memory of the fourth storage unit 43 and executes it using the RAM of the fourth storage unit 43 as a working area.
[0016] The fourth communication unit 42 is configured to include a circuit capable of communicating wirelessly or wired. Note that the fourth communication unit 42 has an antenna in the case of wireless communication and has a connector in the case of wired communication. The fourth communication unit 42 is capable of communicating via the WAN 60. Note that when the image forming apparatus 40 transmits and receives data to and from a communication destination, it is performed by the fourth communication unit 42. However, in the following, for the sake of simplicity of explanation, the transmission and reception by the fourth communication unit 42 are omitted. The same applies to the first communication unit 12 of the first management server 10, the second communication unit 22 of the second management server 20, the third communication unit 32 of the server 30, and the fifth communication unit 52 of the terminal device 50, which will be described later.
[0017] Furthermore, the image forming apparatus 40 includes a printing unit 45. The printing unit 45 is configured to include printing mechanisms such as a head, a conveyance roller, and a cutter (all not shown). Examples of the medium to be printed include plain paper, synthetic paper, photographic paper, film, and the like. The medium is, for example, in a long shape and wound in a roll. The medium may also be in a sheet form. The printing unit 45 can pull out the medium from the roll by the conveyance roller, convey it, print it by the head, and then cut it by the cutter to obtain a printed matter of a predetermined size. The head is, for example, an inkjet type and can print on the medium by ejecting a plurality of colors of ink such as CMYK (Cyan, Magenta, Yellow, Black). Note that the head may also be a thermal type or an electrophotographic type.
[0018] Furthermore, the image forming apparatus 40 includes a fourth input / output unit 44. The fourth input / output unit 44 is a user interface for the user. The fourth input / output unit 44 is, for example, a touch panel display. The fourth input / output unit 44 includes a display panel that is an output unit for displaying various information and a detection panel that is an input unit. The detection panel is configured to be overlaid on the display panel. The detection panel can detect operations such as a user's finger by methods such as a capacitance method, a resistive film method, an optical method, etc. Note that in the fourth input / output unit 44, the input unit may be a keyboard, a mouse, buttons, etc., and the output unit may be a stand-alone liquid crystal display, etc. Furthermore, the image forming apparatus 40 may be configured to include a scanner (not shown). The image forming apparatus 40 can acquire an image of an original by the scanner.
[0019] The terminal device 50 is, for example, a smartphone, a tablet terminal, a computer, etc. The terminal device 50 includes a fifth control unit 51, a fifth communication unit 52, a fifth storage unit 53, and a fifth input / output unit 54. The fifth control unit 51, or the CPU included in the fifth control unit 51, is also referred to as a processor. The configurations of the terminal device 50 are almost the same as those of the image forming apparatus 40, so a detailed explanation will be omitted. As mentioned above, a web browser is stored in the fifth storage unit 53, which can be read and executed by the CPU of the fifth control unit 51. The fifth input / output unit 54 is also equipped with a camera. The terminal device 50 can send print data to the image forming apparatus 40 and have it print. Furthermore, if the image forming apparatus 40 is equipped with a scanner, the terminal device 50 can acquire an image of the original document from the image forming apparatus 40.
[0020] The information processing device, server 30, is installed, for example, by the manufacturer of the image forming apparatus 40. Server 30 consists of a third control unit 31, a third communication unit 32, and a third storage unit 33. The third control unit 31, or the CPU included in the third control unit 31, is also called a processor. Since the configuration of server 30 is almost the same as that of image forming apparatus 40, a detailed explanation will be omitted. As described above, the third storage unit 33 stores web pages, APIs, and websites related to the third service provided by the manufacturer of the image forming apparatus 40. These are stored so as to correspond to the URLs of the server 30.
[0021] Management servers such as the first management server 10 and the second management server 20 are installed, for example, by an ISV (Independent Software Vendor) other than the aforementioned manufacturer that provides the first service related to the image forming apparatus 40. The first management server 10 is installed, for example, by the first ISV. The first management server 10 is comprised of a first control unit 11, a first communication unit 12, and a first storage unit 13. The first control unit 11, or the CPU included in the first control unit 11, is also called a processor. Since the configuration of the first management server 10 is almost the same as that of the image forming apparatus 40, a detailed explanation will be omitted.
[0022] As described above, the first storage unit 13 stores web pages, APIs, and websites related to the first service provided by the first ISV. These are stored so as to correspond to URLs related to the first management server 10. For example, the first ISV is a vendor that performs maintenance and management of the image forming apparatus 40. The first management server 10 provides a web page, API, and website that perform first services such as monitoring the status of the image forming apparatus 40 and reporting maintenance and management of the terminal device 50. In this case, as a third service, the server 30 may monitor the status of the target image forming apparatus 40 and transmit the acquired information to the first management server 10.
[0023] The second management server 20 is a separate device from the first management server 10 and is installed by a second ISV different from the first ISV. The second management server 20 consists of a second control unit 21, a second communication unit 22, and a second storage unit 23. The second control unit 21, or the CPU included in the second control unit 21, is also called a processor. Since the configuration of the second management server 20 is almost the same as that of the image forming apparatus 40, a detailed explanation will be omitted.
[0024] As described above, the second storage unit 23 stores web pages, APIs, and websites related to the second service provided by the second ISV. These are stored so as to correspond to the URLs related to the second management server 20. For example, the second ISV is a vendor that analyzes the print data of the image forming apparatus 40. The second management server 20 provides a web page, API, and website that perform second services, such as acquiring print data from the image forming apparatus 40, analyzing sales trends in the case of a store, and reporting the results to the terminal device 50. In this case, as a third service, the server 30 may acquire print data from the target image forming apparatus 40 and send it to the second management server 20.
[0025] The first management server 10, the second management server 20, and the server 30 may also be equipped with input / output units having the same configuration as the fourth input / output unit 44 of the image forming apparatus 40.
[0026] 2. Registration by the management server and storage by the server. Each of the processes described below is executed by the first control unit 11 of the first management server 10, the second control unit 21 of the second management server 20, the third control unit 31 of the server 30, the fourth control unit 41 of the image forming apparatus 40, and the fifth control unit 51 of the terminal device 50, respectively. For the sake of brevity, the execution of these processes by these control units will be omitted from the explanation.
[0027] First, the user shall apply for the first service provided by the first management server 10. The first management server 10 stores the website related to the application, and the corresponding web pages, etc., in the first storage unit 13, and enables external access to the website. The website related to the application may also be the portal site of the first management server 10.
[0028] The user operates the fifth input / output unit 54 of the terminal device 50 to access the application-related website on the first management server 10. The terminal device 50 and the first management server 10 can send and receive various types of information via the web page corresponding to the application-related website. Furthermore, the terminal device 50 can display the web page using the fifth input / output unit 54, and the user can input information into the web page.
[0029] The user applies to use the first service provided by the first management server 10 using the terminal device 50. Specifically, the user applies by operating the fifth input / output unit 54 of the terminal device 50. The terminal device 50 detects the operation on the fifth input / output unit 54 and requests the first authentication information, the first CD (Confirm Code), from the first management server 10, as shown in Figure 2 (S101).
[0030] The first management server 10 issues a first CD, which is a unique identification code related to the first service, and transmits it to the terminal device 50 (S102). At this time, the first management server 10 also requests from the terminal device 50 the serial number (SN), which is a unique identification information of the image forming apparatus 40. The SN is, for example, the manufacturing number of the image forming apparatus 40. The terminal device 50 performs various processes based on the detection of user operations on the fifth input / output unit 54, but in the following explanation, user operations and detection by the fifth input / output unit 54 will be omitted.
[0031] The user records the first CD, which is transmitted to the terminal device 50 and displayed by the fifth input / output unit 54. The user can also input the SN assigned to the image forming apparatus 40 into the terminal device 50. The terminal device 50 transmits the input SN of the image forming apparatus 40 to the first management server 10 (S103). The first management server 10 registers the issued first CD and the received SN in association with each other in the first storage unit 13 (S104), and accepts applications from users via the terminal device 50. Note that registration by the first management server 10 means that the information is stored in the first storage unit 13 until it is discarded with the agreement of the user and the first ISV.
[0032] The first CD and SN registered in the first management server 10 are referred to as the first registration information. Furthermore, the first management server 10 can also register the first URL and first message of the first website related to the first service as the first registration information. The first URL and the first message are pre-stored in the first storage unit 13. The first message is information related to the first service. For example, the first message is information related to the maintenance and management of the image forming apparatus 40 provided by the first ISV.
[0033] In this case, the registration of the first management server 10 may be processed as a provisional agreement or a first agreement. As described later, the granting of End-User License Agreement information by the user related to the first CD to the server 30 may be processed as a main agreement or a second agreement. In the following, the End-User License Agreement information will be referred to as the EULA.
[0034] The first management server 10 sends the first registration information to the server 30. Specifically, the first management server 10 sends the first CD and SN (S105). At this time, the first management server 10 may also send the first URL and the first message. Server 30 stores the received first registration information. Specifically, Server 30 associates the received first CD and SN with each other and stores them in the third storage unit 33 (S106). At this time, Server 30 can also store the received first URL and first message, associating them with the first CD and SN. Server 30 also stores the order in which the applications were received, and in the above case, stores the application related to the first management server 10 as the first. In this way, the first management server 10 can issue a first CD to the terminal device 50 and provide the first service related to the image forming apparatus 40.
[0035] Next, the user shall use terminal device 50 to apply for the second service provided by the second management server 20. The process for applying to the second management server 20 is the same as the process for applying to the first management server 10 described above, so it will be explained briefly. The terminal device 50 requests the second authentication information, the second CD, from the second management server 20 (S111) and applies for the second service. The second management server 20 issues the second CD, which is a unique identification code related to the second service, and transmits it to the terminal device 50 (S112). The terminal device 50 transmits the SN of the image forming apparatus 40 to the second management server 20 (S113), and the second management server 20 associates the issued second CD and the received SN and registers them as second registration information in the second storage unit 23 (S114), and transmits it to the server 30 (S115).
[0036] As a result, the second management server 20 can accept applications from users. Server 30 stores the second CD and SN as second registration information (S116). Server 30 also stores the application related to the second management server 20 as the second item. In this way, the second management server 20 can issue a second CD to the terminal device 50 and provide the second service related to the image forming apparatus 40. In this case, the user will apply for the same image forming apparatus 40, and the SN will be the same as in the case of the first management server 10 described above.
[0037] The second management server 20 can also register the second URL and second message of the second website related to the second service, including them in the second registration information. The second management server 20 can also send these to the server 30. The second message contains information related to the second service provided by the second management server 20. For example, the second message contains information related to the analysis of sales trends of the second ISV.
[0038] Server 30 can also store the second URL and second message in the second registration information. The relationship between the provisional contract and the formal contract can be the same as in the case of the first management server 10 described above.
[0039] 3. Authentication by the server The image forming apparatus 40 can store the URL of the image forming apparatus website for the server 30, as well as its own serial number (SN), in the fourth storage unit 43 at the time of factory shipment. When the image forming apparatus 40 determines that a predetermined condition has been met, it reads the URL of the image forming apparatus website of the server 30 from the fourth storage unit 43 and can access the image forming apparatus website of the server 30.
[0040] In the authentication process for the first and second services, the image forming apparatus 40 and the server 30 can send and receive various types of information via a website for the image forming apparatus or a web page corresponding to the website. The image forming apparatus 40 may also have a flag set in its fourth storage unit 43 to allow access to the server 30. The image forming apparatus 40 may check the flag in the fourth storage unit 43 when a predetermined condition is met, and if the flag is set, it may access the server 30. On the other hand, the image forming apparatus 40 may not access the server 30 when the flag is not set.
[0041] The aforementioned predetermined conditions include, for example, when power is turned on to the image forming apparatus 40 and it starts up, when the image forming apparatus 40 is rebooted, when the fourth communication unit 42 of the image forming apparatus 40 is connected to the WAN 60, or when a predetermined operation is performed on the cover or sensors (not shown) of the image forming apparatus 40. Note that when the fourth communication unit 42 of the image forming apparatus 40 is connected to the WAN 60, it may also mean when a communication cable is connected to the connector of the fourth communication unit 42, or when the image forming apparatus 40 is connected to the internet.
[0042] When the image forming apparatus 40 determines that the above-mentioned predetermined conditions have been met, it may print the assigned IP address and the URL of the website for the image forming apparatus, which are stored in the fourth storage unit 43. Users can view these settings, access the server 30 via the terminal device 50, and configure the image forming apparatus 40 via a Web API for configuring the image forming apparatus 40. This is convenient when a user unpacks the image forming apparatus 40 purchased from the manufacturer and sets it up for the first time.
[0043] 3-1. Authentication of the first service related to the first management server Server 30 processes applications in the order they are received, and by referring to the third storage unit 33, it can process the authentication of the first service related to the first management server 10 as the first, as shown in Figure 3. When the image forming apparatus 40 determines that the above-mentioned predetermined conditions have been met, it can automatically access the image forming apparatus website on the server 30, read the SN from the fourth storage unit 43, and transmit it (S201). Furthermore, the transmission of the SN also serves as an inquiry to the server 30 regarding whether the image forming apparatus 40 is subject to the first service.
[0044] The server 30 refers to the third storage unit 33 and checks whether the first registration information corresponding to the SN received from the image forming apparatus 40 is stored there. Specifically, the server 30 checks whether the SN received from the image forming apparatus 40 matches the SN included in the first registration information stored in the third storage unit 33 (S202). When server 30 determines that the SNs of both parties match and that the first registration information is stored, it transmits the first access information related to server 30 stored in the third storage unit 33 to the image forming apparatus 40 (S203). The first access information includes the URL of the authentication website of server 30. At this time, server 30 may also transmit the first URL and first message included in the first registration information along with the first access information.
[0045] The receipt of the first access information, or the receipt of the first registration information, is also a response from the server 30 indicating that the image forming apparatus 40 is subject to the first service. The image forming apparatus 40 can be determined to be subject to the said first service. On the other hand, if server 30 determines that the SNs of both parties do not match and that the first registration information is not stored, it does not send the first access information to image forming apparatus 40. In this case, server 30 may also send error information to image forming apparatus 40. The image forming apparatus 40 can determine that it is not subject to the first service if there is no transmission from the server 30 or if it receives error information.
[0046] The image forming apparatus 40 prints the first access information received from the server 30 onto the medium using the printing unit 45 (S204). At this time, the image forming apparatus 40 may encode the first access information into a two-dimensional code to form a first code which is a first symbol image, and print it onto the medium using the printing unit 45. The first code may also be a barcode. Furthermore, the image forming apparatus 40 may print first registration information, such as the first message received from the server 30. Users can view this information and learn about the first service.
[0047] The image forming apparatus 40 can prompt the terminal device 50 to access the server and proceed to the authentication process for the first service, as described later, by printing the first code, which is the first access information, or by printing the first registration information. The terminal device 50 reads the first code printed on the medium using the camera of the fifth input / output unit 54 (S205). The terminal device 50 can decode the read first code and obtain the first access information.
[0048] As described above, the terminal device 50 can run a web browser. The terminal device 50 can display acquired web pages and input / output various information via the web pages via the fifth input / output unit 54. The terminal device 50 can receive web pages and send and receive various information that is input / output to and from the web pages via the fifth communication unit 52. In the following explanation, we will omit the fact that the terminal device 50 runs a web browser to perform these processes.
[0049] The terminal device 50 accesses the authentication website of server 30 using the URL of the authentication website of server 30, which is the first access information obtained (S206). When terminal device 50 accesses server 30, server 30 sends the EULA, which is the End User License Agreement information, to terminal device 50 along with a web page that displays the licensing screen (S207). At this time, server 30 may also send the first URL and the first message included in the first registration information. The EULA is stored in the third storage unit 33 of server 30. The EULA may include, for example, a provision allowing the user of terminal device 50 to permit server 30 to monitor the status of image forming apparatus 40 and obtain information. Based on the monitoring information received from the server, the first management server 10 can provide the first service to the user of terminal device 50.
[0050] The terminal device 50 displays the EULA and licensing screen on the fifth input / output unit 54 based on the web page received from the server 30. At this time, the terminal device 50 may also display the first URL and first message received from the server 30. The user can view these and learn about the information related to the first service. The user confirms the EULA displayed by the fifth input / output unit 54 of the terminal device 50. If the user decides to accept the EULA, they operate the acceptance screen displayed on the fifth input / output unit 54 of the terminal device 50 and input that they have accepted the EULA (S208). The terminal device 50 sends information to the server 30 indicating that it has accepted the entered EULA (S209).
[0051] When server 30 receives information from terminal device 50 that it has accepted the EULA, it sends a web page to terminal device 50 that displays the screen for inputting the first CD and requests the first CD (S210). The terminal device 50 displays the first CD input screen to the fifth input / output unit 54 based on the web page received from the server 30.
[0052] The user operates the screen for inputting the first CD displayed on the fifth input / output unit 54 of the terminal device 50 and inputs the first CD that they have noted down. The terminal device 50 transmits the input first CD to the server 30 (S211). When server 30 receives the first CD from terminal device 50, it checks whether it matches the first CD received from the first management server 10 and stored in the third storage unit 33 (S212).
[0053] Here, as shown in Figure 4, the image forming apparatus 40 separately sends an SN to the server 30 to request an Agent Key (AK), which is an agent key to allow connection with the server 30 (S213), and attempts to poll with the server 30. The server 30 checks whether the received SN matches an SN stored in the third storage unit 33. Hereafter, the polling between the image forming apparatus 40 and the server 30 using this AK will be referred to as the first polling. Furthermore, if the server 30 determines that the SNs of both parties match, and if it authenticates the first CD as described later (S214), it issues and transmits an AK (S215). Until the first CD is authenticated, the server 30 sends error information to the image forming apparatus 40 indicating that it cannot transmit the AK in response to the AK request. The AK is a unique identification piece of information.
[0054] If, after checking (S212), server 30 determines that both first CDs match, it authenticates the first CD (S214). In other words, server 30 can officially register the first CD. Furthermore, formally registering the first CD means that the server 30 stores in the first storage unit 13 a record indicating that the user of the first CD has accepted the EULA.
[0055] If the server 30 determines that both first CDs match, it may determine that at least one of the users or terminal devices 50 corresponds to the first CD, and then formally register them in the third storage unit 33 by associating their names and identification information with the SN of the image forming apparatus 40. Server 30 can authenticate the first CD and register the target user or terminal device 50.
[0056] Thus, while referring to the third storage unit 33, if the server 30 determines that the SN received from the image forming apparatus 40 matches as described above, that the EULA has been approved, and that the first CD received from the terminal device 50 also matches, it authenticates the first CD (S214). The server 30 can then issue an AK and send it to the image forming apparatus 40 (S215).
[0057] When the image forming apparatus 40 receives an AK from the server 30 (S215), it determines that the first polling is complete and prints a message to that effect (S216). The user can visually confirm the printout and understand that a connection has been established between the image forming apparatus 40 and the server 30. When the image forming apparatus 40 determines that the first polling is complete, it can determine that a connection with the server 30 has been established (S219). After this, for example, the server 30 can monitor the status of the image forming apparatus 40 as a third service, acquire information, and send it to the first management server 10. Based on the received monitoring information, the first management server 10 can provide the first service. Then, once the image forming apparatus 40 establishes a connection with the server 30, it performs a reboot (S220).
[0058] Furthermore, once the server 30 authenticates the first CD (S214), it sends the authentication result to the terminal device 50 (S217). Here, the server 30 sends a message indicating that the first CD has been authenticated as the authentication result. On the other hand, if the server 30 determines that the first CDs of both devices do not match, it may send error information to the terminal device 50 indicating that it was unable to authenticate the first CD. If the first CDs of both devices are still not authenticated after a certain period of time has elapsed, the server 30 may send error information to the image forming apparatus 40 indicating that it was unable to authenticate the first CD. When the image forming apparatus 40 receives error information from the server 30, it prints a message indicating that an error has occurred based on the error information.
[0059] The terminal device 50 displays the received authentication result on the fifth input / output unit 54 (S218). At this time, the server 30 also sends a web page containing information about the first URL of the first website of the first management server 10 to the terminal device 50, and can display it on the terminal device 50. The first website is a website related to the first service that the first management server 10 provides to users. The user can see the display on the terminal device 50 and understand that the first CD has been authenticated by the server 30 and that the first service provided by the first management server 10 is now available.
[0060] The user views the authentication result displayed by the terminal device 50 and attempts to use the first service. Specifically, the terminal device 50 can obtain the first URL from a web page and access the first website of the first management server 10 (S221). The terminal device 50 can receive the first service provided by the first management server 10 via the web page of the first website. Thus, once the first CD is authenticated by the server 30, the terminal device 50 can transition from the web page provided by the server 30 to the web page of the first website related to the first service provided by the first management server 10. In the following, the transition of the terminal device 50 to the web page of the first website related to the first service provided by the first management server 10 will also be simply referred to as the terminal device 50 transitioning to the first service of the first management server 10.
[0061] As mentioned above, after server 30 authenticates the first CD (S214), the following two processes are performed asynchronously. In other words, in one process, when the image forming apparatus 40 receives an AK from the server 30 (S215), it determines that the first polling is complete and prints a statement to that effect (S216). In the other process, the server 30 sends the authentication result to the terminal device 50 (S217) and also sends the web page of the first management server 10, allowing the terminal device 50 to transition to the web page related to the first service of the first management server 10.
[0062] In other words, the timing at which server 30 redirects the access destination of terminal device 50 to the first service of first management server 10 and the timing at which image forming apparatus 40 prints a message indicating that the first polling has been completed are not synchronized. Therefore, the timing at which the server 30 redirects the access destination of the terminal device 50 to the first service of the first management server 10 and the timing at which the image forming apparatus 40 prints a message indicating that the first polling has been completed may overlap, at least partially.
[0063] 3-2. Authentication of the second service related to the second management server Server 30, in order of successful application, then processes authentication for the second service related to the second management server 20, as shown in Figures 5 and 6. The following explanation of the authentication process for the second service related to the second management server 20 will focus on the differences from the authentication process for the first service of the first management server 10 described above with reference to Figures 3 and 4, and will be explained concisely, with some similar content omitted.
[0064] As described above with reference to Figure 4, the image forming apparatus 40 reboots (S220) once the first polling is completed and a connection with the server 30 is established. Upon rebooting, the image forming apparatus 40 can determine that the predetermined conditions described above have been met. As shown in Figure 5, the image forming apparatus 40 automatically accesses the server 30 and transmits the SN (S301). The transmission of the SN also serves as an inquiry to the server 30 regarding whether the image forming apparatus 40 is eligible for the second service provided by the second management server 20.
[0065] The server 30 refers to the third storage unit 33 and checks whether the second registration information, which corresponds to the SN received from the image forming apparatus 40 and follows the first registration information, is stored there. Specifically, the server 30 checks whether the received SN and the SN included in the stored second registration information match (S302). When server 30 determines that the SNs of both parties match and that the second registration information is stored, it transmits the second access information related to server 30 stored in the third storage unit 33 to the image forming apparatus 40 (S303). The second access information includes the URL of the authentication website of server 30. Note that the second access information may be the same as the first access information. At this time, server 30 may send the second URL and second message included in the second registration information along with the second access information.
[0066] The receipt of the second access information, or the receipt of the second registration information, is also a response from the server 30 indicating that the image forming apparatus 40 is subject to the second service. The image forming apparatus 40 can be determined to be subject to the said second service. On the other hand, if server 30 determines that the SNs of both parties do not match and that the second registration information is not stored, it will not send the second access information to image forming apparatus 40. In this case, server 30 may also send error information to image forming apparatus 40. The image forming apparatus 40 can determine that it is not subject to the second service if there is no transmission from the server 30 or if it receives error information.
[0067] The image forming apparatus 40 prints the second access information received from the server 30 onto the medium using the printing unit 45 (S304). At this time, the image forming apparatus 40 may encode the second access information into a two-dimensional code to form a second symbol image, which is a second code, and print it onto the medium using the printing unit 45. The second code may also be a barcode. The image forming apparatus 40 may also print second registration information, such as a second message, that has been received. Users can view this information and learn about the second service.
[0068] The image forming apparatus 40 can prompt the terminal device 50 to access the server 30 and proceed to the authentication process for the second service, as described later, by printing a second code, which is second access information, or by printing second registration information. The terminal device 50 reads the second code printed on the medium using the camera of the fifth input / output unit 54 (S305). The terminal device 50 can decode the read second code and obtain the second access information. The terminal device 50 accesses the authentication website of server 30 using the URL of the authentication website of server 30, which is the second access information obtained (S306). When terminal device 50 accesses server 30, server 30 sends the EULA, which is the End User License Agreement information, to terminal device 50 along with a web page that displays the licensing screen (S307). The EULA may have the same content as described above. At this time, server 30 may also send the second URL and second message included in the second registration information.
[0069] The terminal device 50 displays the EULA and licensing screen based on the web page received from the server 30. At this time, the terminal device 50 may also display the received second URL and second message. The user can view these and learn about the information related to the second service. The user checks the EULA displayed on the terminal device 50. If the user decides to accept the EULA, they input a message to the terminal device 50 indicating that they accept the EULA (S308). The terminal device 50 sends information to the server 30 indicating that it has accepted the entered EULA (S309). The EULA may include, for example, a provision allowing the user of terminal device 50 to obtain print data from the image forming apparatus 40. Based on the print data received from server 30, the first management server 10 can provide a second service to the user of terminal device 50.
[0070] When server 30 receives information from terminal device 50 that it has accepted the EULA, it sends a web page to terminal device 50 that displays a screen for inputting the second CD and requests the second CD (S310). The terminal device 50 displays a screen for inputting the second CD based on the received web page. The user operates the second CD input screen displayed on the terminal device 50 and inputs the second CD. The terminal device 50 transmits the input second CD to the server 30 (S311). When server 30 receives the second CD from terminal device 50, it checks whether it matches the second CD received from second management server 20 and stored in third storage unit 33 (S312).
[0071] Here, as shown in Figure 6, the image forming apparatus 40 separately sends a second CD to the server 30 and requests information from the server 30 indicating that it has received and confirmed the second CD (S313), and attempts polling with the server 30. Hereafter, the information indicating that the second CD has been received and confirmed will be referred to as the second CD confirmation information. Furthermore, the polling between the image forming apparatus 40 and the server 30 using this second CD will be referred to as the second polling. Unlike the authentication process related to the first management server 10 described above, the image forming apparatus 40 requests second CD confirmation information instead of an AK request. By using the second CD, which is unique identification information, the server 30 does not need to issue a new AK.
[0072] The server 30 checks whether the second CD received from the image forming apparatus 40 matches the second CD stored in the third storage unit 33. Furthermore, when the server 30 determines that the second CD received from the image forming apparatus 40 matches the second CD it has stored, and if it authenticates the second CD received from the terminal device 50 as described later (S314), it sends second CD verification information to the image forming apparatus 40 (S315). Until the second CD is authenticated, the server 30 will send error information indicating that it cannot verify the second CD in response to the image forming apparatus 40's request for verification information.
[0073] The server 30 checks whether the second CD received from the terminal device 50 matches the second CD stored in its memory (S312). If it determines that they match, it can authenticate the second CD (S314). In other words, the server 30 can officially register the second CD. Officially registering the second CD means that the server 30 stores in the third storage unit 33 that it has authenticated the user associated with the second CD as having accepted the EULA.
[0074] If the server 30 determines that both second CDs match, it may determine that at least one of the users or terminal devices 50 corresponds to the second CD, and register their names and identification information in the third storage unit 33, associating them with the SN of the image forming apparatus 40. Server 30 can authenticate the second CD and register the target user or terminal device 50.
[0075] Thus, while referring to the third storage unit 33, if the server 30 determines that the SN received from the image forming apparatus 40 matches as described above, that the EULA has been approved, and that the second CD received from the terminal device 50 also matches, it authenticates the second CD (S314). The server 30 can then transmit the second CD confirmation information to the image forming apparatus 40 (S315).
[0076] When the image forming apparatus 40 receives the second CD confirmation information from the server 30 (S315), it determines that the second polling is complete and prints a message to that effect (S316). After this, for example, the server 30 can acquire print data from the image forming apparatus 40 and send it to the second management server 20. The second management server 20 can then provide the second service based on the received print data.
[0077] Here, the server 30 refers to the third storage unit 33 and checks whether the next registration information after the second registration information is stored. If the next registration information is not available, the server 30 does not send the URL of the authentication website to the image forming apparatus 40. In other words, if server 30 refers to the third storage unit 33 and there is no registration information relating to management servers other than the first management server 10 and the second management server 20, it does not send the URL of the authentication website to image forming apparatus 40 even if it receives an SN from image forming apparatus 40.
[0078] In this case, server 30 may send a message to image forming apparatus 40 indicating that there is no next management server for which the application has been accepted and that processing will be terminated. That is, even if an inquiry is made by sending the SN to image forming apparatus 40 regarding whether it is subject to other services provided by other management servers, it will respond that it is not subject to other services. Server 30 terminates the series of authentication processes (S318).
[0079] The image forming apparatus 40 determines that the authentication process is complete (S319) because it has not received any data from the server 30, or because it has received a message indicating that the process has been completed, and terminates the series of processes. Furthermore, the server 30 refers to the third storage unit 33, and if there is registration information for the next management server for which the application has been accepted, it refers to Figure 5 and, as described above, receives the SN from the image forming apparatus 40 (S301), checks the SN (S302), and continues the series of processes starting with sending the URL of the authentication website to the image forming apparatus 40 (S303).
[0080] Furthermore, once the server 30 authenticates the second CD (S314), it sends the authentication result to the terminal device 50 (S317). Here, the server 30 sends a message indicating that the second CD has been authenticated as the authentication result. On the other hand, if the server 30 determines that the second CDs of both devices do not match, it may send error information to the terminal device 50 indicating that it was unable to authenticate the second CD. If the second CDs of both devices are still not authenticated after a certain period of time has elapsed, the server 30 may send error information to the image forming apparatus 40 indicating that it was unable to authenticate the second CD. When the image forming apparatus 40 receives error information from the server 30, it prints a message indicating that an error has occurred based on the error information.
[0081] The terminal device 50 displays the received authentication result (S320). At this time, the server 30 also sends a web page containing information about the second URL of the second website of the second management server 20 to the terminal device 50, and the terminal device 50 can display it. The second website is a website related to the second service that the second management server 20 provides to users.
[0082] The user views the authentication result displayed by the terminal device 50 and attempts to use the second service. Specifically, the terminal device 50 can obtain the second URL from the web page and access the second website related to the second service provided by the second management server 20 (S321). The terminal device 50 can receive the second service provided by the second management server 20 via the web page of the second website. Thus, once the second CD is authenticated by the server 30, the terminal device 50 can transition from the web page provided by the server 30 to the web page of the second website related to the second service provided by the second management server 20. This transition of the terminal device 50 to the web page of the second website related to the second service provided by the second management server 20 is also simply referred to as the terminal device 50 transitioning to the second service of the second management server 20.
[0083] As mentioned above, after server 30 authenticates the second CD (S314), the following two processes are performed asynchronously. In other words, in one process, when the image forming apparatus 40 receives the second CD confirmation information from the server 30 (S315), it determines that the second polling is complete and prints a statement to that effect (S316). In the other process, the server 30 sends the authentication result to the terminal device 50 (S317) and also sends the web page of the second management server 20, allowing the terminal device 50 to transition to the web page related to the second service of the second management server 20.
[0084] In other words, the timing at which server 30 redirects the access destination of terminal device 50 to the second service of second management server 20 and the timing at which image forming apparatus 40 prints a message indicating that the second polling has been completed are not synchronized. Therefore, the timing at which server 30 transitions the access destination of terminal device 50 to the second service of second management server 20 and the timing at which image forming apparatus 40 prints a message indicating that the second polling has been completed may overlap, at least partially.
[0085] As described above, the authentication processing system 1 is comprised of a first management server 10, a second management server 20, a server 30, an image forming apparatus 40, and a terminal device 50. The first management server 10 can issue a first CD to the terminal device 50 to provide a first service related to the image forming apparatus 40. The second management server 20 can issue a second CD to the terminal device 50 to provide a second service related to the image forming apparatus 40. Server 30 can authenticate the first CD and the second CD.
[0086] If server 30 has received and stored the first CD from the first management server 10, it sends the first access information relating to server 30 to the image forming apparatus 40 to print. The terminal device 50 obtains the first access information printed by the image forming apparatus 40, accesses the server 30, and transmits the first CD issued by the first management server 10. If server 30 determines that the received first CD matches the first CD it has stored, it authenticates the first CD and redirects the access destination of terminal device 50 to the first service of first management server 10. If the second CD is received and stored from the second management server 20, the second access information relating to the server 30 is sent to the image forming apparatus 40 for printing.
[0087] As a result, this authentication processing system 1 can improve convenience by enabling users to access various services from multiple servers, such as the first management server 10 and the second management server 20, using a terminal device 50 with simple procedures. Furthermore, the authentication processing system 1 can print or display an appropriate message for each service provided, guiding users to easily access each service. Furthermore, the authentication processing system 1 can utilize multiple services for a single image forming apparatus 40, such as a first service provided by the first management server 10 and a second service provided by the second management server 20.
[0088] Although embodiments have been described in detail above with reference to the drawings, the specific configuration is not limited to these embodiments and may be modified, substituted, deleted, etc., as long as it does not depart from the spirit of this invention. In the above description, the authentication processing system 1 was explained using an example that includes a first management server 10 and a second management server 20, but it may also include other management servers equivalent to the second management server 20. Other management servers can be processed in the same way as the second management server 20 described above. [Explanation of Symbols]
[0089] 1…Authentication processing system, 10…First management server, 11…First control unit, 12…First communication unit, 13…First storage unit, 20…Second management server, 21…Second control unit, 22…Second communication unit, 23…Second storage unit, 30…Server, 31…Third control unit, 32…Third communication unit, 33…Third storage unit, 40…Image forming apparatus, 41…Fourth control unit, 42…Fourth communication unit, 43…Fourth storage unit, 44…Fourth input / output unit, 45…Printing unit, 50…Terminal device, 51…Fifth control unit, 52…Fifth communication unit, 53…Fifth storage unit, 54…Fifth input / output unit, 60…WAN.
Claims
1. An authentication processing system comprising: an image forming apparatus; a terminal device; a first management server capable of issuing first authentication information to the terminal device and providing first services related to the image forming apparatus; a second management server capable of issuing second authentication information to the terminal device and providing second services related to the image forming apparatus; and an information processing device capable of authenticating the first authentication information and the second authentication information, The aforementioned information processing device is If the first authentication information is received and stored from the first management server, the first access information relating to the information processing device is transmitted to the image forming apparatus for printing. The aforementioned terminal device is The first access information printed by the image forming apparatus is acquired and accessed by the information processing device, and the first authentication information issued by the first management server is transmitted. The aforementioned information processing device is If it is determined that the received first authentication information matches the stored first authentication information, the first authentication information is authenticated, and the access destination of the terminal device is redirected to the first service of the first management server. An authentication processing system that, when it has received and stored the second authentication information from the second management server, transmits the second access information relating to the information processing device to the image forming apparatus for printing.
2. The image forming apparatus stores identification information, The aforementioned first management server is When issuing the first authentication information, the terminal device receives the identification information, transmits the identification information to the information processing device, and stores it in association with the first authentication information. The aforementioned second management server is When issuing the second authentication information, the terminal device receives the identification information, transmits the identification information to the information processing device, and stores it in association with the second authentication information. The image forming apparatus is When the predetermined conditions are determined, the identification information is transmitted to the information processing device. The aforementioned information processing device is If the first authentication information corresponding to the received identification information is stored, the first access information can be transmitted to the image forming apparatus for printing. The authentication processing system according to claim 1, wherein, after authenticating the first authentication information, if the system has stored the second authentication information corresponding to the received identification information, it is possible to transmit the second access information to the image forming apparatus for printing.
3. The aforementioned predetermined conditions include connecting the image forming apparatus to the internet and rebooting, The image forming apparatus is Upon determining the connection to the Internet, the system transmits the identification information to the information processing device, prints the first access information, and then performs a first poll with the first management server. The authentication processing system according to claim 2, wherein after the information processing device authenticates the first authentication information, it completes the first polling with the first management server and determines that it needs to reboot, and then transmits the identification information to the information processing device.
4. The image forming apparatus is The first polling with the first management server is performed using an agent key. The authentication processing system according to claim 3, wherein after printing the second access information, a second polling is performed with the second management server using the second authentication information.
5. When the image forming apparatus completes the first polling with the first management server, it prints a message indicating that it has been completed. After the information processing device has authenticated the first authentication information, The authentication processing system according to claim 3, wherein at least part of the timing at which the information processing device transitions the access destination of the terminal device to the first service of the first management server and the timing at which the image forming apparatus prints the completion statement overlap.
6. The authentication processing system according to claim 5, wherein the timing at which the information processing device transitions the access destination of the terminal device to the first service of the first management server and the timing at which the image forming apparatus prints the completion status are not synchronized.
7. The aforementioned information processing device is If the first management server has received and stored the first message relating to the first service along with the first authentication information, it sends the first message along with the first access information to the image forming apparatus. The image forming apparatus is The authentication processing system according to claim 1, wherein when printing the first message together with the first access information, the first access information is printed as a first symbol image.
8. When the terminal device accesses the information processing device, The aforementioned information processing device is The authentication processing system according to claim 1, which transmits license agreement information and a first message relating to the first service to the terminal device, and requests the first authentication information upon receiving confirmation that the license has been granted.
9. The aforementioned information processing device is The authentication processing system according to claim 1, wherein if the second authentication information is not stored, the second access information is not transmitted to the image forming apparatus.
10. It has a processor, An information processing device provided in an authentication processing system including an image forming apparatus, a terminal device, a first management server capable of issuing first authentication information to the terminal device and providing first services related to the image forming apparatus, and a second management server capable of issuing second authentication information to the terminal device and providing second services related to the image forming apparatus, The aforementioned processor, If the system has received and stored the first authentication information from the first management server, it will send the first access information to the image forming apparatus to print. When the terminal device obtains the first access information printed by the image forming apparatus and accesses the information processing device, it receives the first authentication information issued by the first management server, If it is determined that the received first authentication information matches the first authentication information stored, the first authentication information is authenticated, and the access destination of the terminal device is redirected to the first service of the first management server. An information processing device that, when it has received and stored the second authentication information from the second management server, transmits the second access information to the image forming apparatus to cause printing.
11. It has a processor and a head, An image forming apparatus provided in an authentication processing system including a terminal device, a first management server capable of issuing first authentication information to the terminal device and providing a first service, a second management server capable of issuing second authentication information to the terminal device and providing a second service, and an information processing device capable of authenticating the first authentication information and the second authentication information, The first service and the second service relate to the image forming apparatus, The aforementioned processor, If the information processing device has received and stored the first authentication information from the first management server, it receives the first access information related to the information processing device and prints it using the head. When the terminal device obtains the printed first access information and accesses the information processing device, and transmits the first authentication information issued by the first management server, Furthermore, when the information processing device determines that the received first authentication information matches the first authentication information stored in it, authenticates the first authentication information, and transitions the access destination of the terminal device to the first service of the first management server, Furthermore, if the second authentication information has been received and stored from the second management server, the image forming apparatus receives the second access information relating to the information processing device and prints using the head.
Citation Information
Patent Citations
Printing system, server system, and printer
JP2022025667A