Information processing system, information processing method, image processing device, and program
The information processing system automates user registration and permission management in image processing devices by using temporary registration and authentication keys, reducing administrative effort and enhancing security.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2026-04-08
AI Technical Summary
Existing image processing devices require administrators to manually register user IDs and passwords for each user, making the user registration process cumbersome.
An information processing system that facilitates user identification information registration through a communication network involving user terminals and an administrator terminal, utilizing temporary registration and authentication keys to streamline the process.
Reduces the administrative effort required for user registration by allowing automated user identification and permission management, enhancing security and efficiency in setting user permissions.
Smart Images

Figure 2026060047000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an image processing apparatus capable of restricting functions executable for each user.
Background Art
[0002] Patent Document 1 describes an image forming apparatus that sets a user ID for each user and can restrict functions available for each user ID. The image forming apparatus includes a controller, a printer engine, a scanner, an operation unit, and a storage device. To register a user ID by an administrator, the administrator operates the operation unit to display an operation screen for user ID management on the UI screen. The administrator presses a button on which "ID registration" is displayed on the operation screen for user ID management to display an operation screen for registering the user ID on the UI screen. The administrator inputs a user ID to be registered and a password by operating the numeric keypad of the operation unit and presses the OK button. The image forming apparatus stores the user ID and the password in the storage device. Thus, the registration of the user ID and the password is completed. The administrator presses a button on which "Change setting content" is displayed while selecting the registered user ID on the operation screen for user ID management to display an operation screen for changing the setting content on the UI screen. The administrator can set restrictions on the use of paper types and restrictions on the use of each function such as a copy function, a scan function, and a print function on the operation screen for changing the setting content.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When an administrator installs a multifunction printer in a company department, they may need to configure settings to restrict the functions that each user can perform on the printer. In the technology described in Patent Document 1, the administrator needs to register a user ID and password for each of the many users by using a numeric keypad, which makes user registration a cumbersome process for the administrator.
[0005] This invention was made to solve the above-mentioned problems, and aims to reduce the effort required for administrators to register user identification information for each user when setting restrictions on the functions that can be executed by the image processing device for each of many users. [Means for solving the problem]
[0006] To achieve the above objective, the information processing system described in claim 1 is an information processing system in which a plurality of user terminals, an administrator terminal, and an image processing device are communicated together, wherein the image processing device has a first storage unit that stores user identification information for identifying a user, and stores either permission information that permits a user to execute the functions of the image processing device, or disallowance information that does not permit a user to execute the functions of the image processing device, associated with the stored user identification information, a first receiving unit that receives the first user identification information, which is the user identification information for identifying a first user, from the user terminal of the first user, a second storage unit that stores the first user identification information received by the first receiving unit, and the first user identification information received by the first receiving unit The image processing device includes: a temporary registration unit that, if, at that time, user identification information identifying the same user as the first user identification information is not stored in the first storage unit, registers the first user identification information in the second storage unit; a temporary registration notification unit that notifies the administrator terminal in response to the temporary registration unit registering the first user identification information in the second storage unit; the administrator terminal, after receiving a notification from the temporary registration notification unit, transmits a permission notification to the image processing device that permits the first user to execute the functions of the image processing device; and the image processing device, when the permission notification unit transmits the permission notification, registers the first user identification information registered in the second storage unit by the temporary registration unit and the permission information in association with each other in the first storage unit.
[0007] Furthermore, the information processing system according to claim 2 is the information processing system according to claim 1, wherein the image processing device further comprises an authentication key generation unit that generates an authentication key and transmits it to the administrator terminal, the administrator terminal further comprises an authentication key transmission unit that transmits the authentication key transmitted by the authentication key generation unit as a first authentication key to the user terminal of the first user, the first receiving unit receives the first user identification information along with the first authentication key, and the provisional registration unit registers the first user identification information in the second storage unit at the time the first receiving unit receives the first user identification information and the first authentication key, if the user identification information identifying the same user as the first user identification information is not stored in the first storage unit and the first authentication key matches the authentication key generated by the authentication key generation unit.
[0008] Furthermore, the information processing system according to claim 3 is the information processing system according to claim 2, wherein the authentication key is a one-time key that is valid only for a predetermined period of time, and the provisional registration unit registers the first user identification information in the second storage unit when the first receiving unit receives the first user identification information and the first authentication key, and the predetermined period of time has not elapsed since the one-time key was generated by the authentication key generation unit.
[0009] Furthermore, the information processing system described in claim 4 is the information processing system described in claim 3, wherein the provisional registration notification unit includes a process of notifying the administrator terminal that a predetermined time has elapsed since the one-time key was generated by the authentication key generation unit.
[0010] Furthermore, the information processing system according to claim 5 is the information processing system according to any one of claims 1 to 4, wherein the image processing device further comprises a screen data transmission unit that transmits screen data containing the first user identification information stored in the second storage unit to the administrator terminal, the administrator terminal further comprises a display unit that displays a registration screen indicated by the screen data received from the image processing device, and the permission notification unit transmits the permission notification to the image processing device by receiving a predetermined operation for transmitting the permission notification on the registration screen displayed by the display unit.
[0011] Furthermore, the information processing system according to claim 6 is the information processing system according to any one of claims 1 to 4, wherein the image processing device is capable of executing a first function and a second function, the first storage unit stores either permission information that permits a user to execute the first function and disallowance information that does not permit a user to execute the first function, in association with the user identification information, the first storage unit stores either permission information that permits a user to execute the second function and disallowance information that does not permit a user to execute the second function, in association with the user identification information, the permission notification includes function identification information that identifies the function among the first function and the second function that the first user is permitted to execute, and the main registration unit registers the first user identification information registered in the second storage unit by the provisional registration unit and the permission information in association with the function identified by the function identification information among the first function and the second function.
[0012] Furthermore, the information processing system described in claim 7 is the information processing system described in any one of claims 1 to 4, wherein the image processing device further includes a deletion unit that deletes the first user identification information from the second storage unit after the registration unit has registered the first user identification information and the permission information in association with each other in the first storage unit.
[0013] Furthermore, the information processing system according to claim 8 is the information processing system according to any one of claims 1 to 4, wherein the image processing device further includes a second receiving unit that receives second user identification information, which is user identification information that identifies a second user, from the user terminal of the second user; and a permission addition request notification unit that, at the time the second receiving unit receives the second user identification information, sends a permission addition request notification to the administrator terminal requesting the administrator to change the denied information to the permitted information in association with the user identification information that identifies the same user as the second user identification information; the administrator terminal further includes a permission addition notification unit that sends a permission addition notification to the image processing device that permits the second user to perform the functions of the image processing device; and the image processing device further includes a registration change unit that, when the permission addition notification unit sends the permission addition notification, changes the denied information stored in the first storage unit in association with the user identification information that identifies the same user as the second user identification information to the permitted information.
[0014] To achieve the above objective, the information processing method described in claim 9 is an information processing system in which a plurality of user terminals, an administrator terminal, and an image processing device are communicated together, wherein the image processing device comprises a first storage unit and a second storage unit that store user identification information for identifying a user, and which store either permission information for a user to execute the functions of the image processing device or disallowance information for a user not to execute the functions of the image processing device in association with the stored user identification information, and the information processing method to be performed in the information processing system, comprising a first receiving step of receiving the first user identification information, which is the user identification information for identifying a first user, from the user terminal of the first user, and the first user identification information received in the first receiving step The system includes: a provisional registration step in which, if, at that time, user identification information identifying the same user as the first user identification information is not stored in the first storage unit, the first user identification information is registered in the second storage unit; a provisional registration notification step in which, in response to the first user identification information being registered in the second storage unit by the provisional registration step, a notification is sent to the administrator or administrator terminal; a permission notification step in which, after the notification is sent by the provisional registration notification step, a permission notification is sent to the image processing unit granting the first user the permission to execute the functions of the image processing unit; and a final registration step in which, if the permission notification is sent by the permission notification step, the first user identification information registered in the second storage unit by the provisional registration step and the permission information are registered in the first storage unit in association with each other.
[0015] To achieve the above objective, the image processing apparatus described in claim 10 is an image processing apparatus to which a plurality of user terminals and an administrator terminal are communicated together, comprising: a first storage unit that stores user identification information for identifying a user and stores either permission information that permits a user to perform the functions of the image processing apparatus, or disallowance information that does not permit a user to perform the functions of the image processing apparatus, associated with the stored user identification information; a first receiving unit that receives the first user identification information, which is the user identification information for identifying a first user, from the user terminal of the first user; a second storage unit that stores the first user identification information received by the first receiving unit; and the first receiving unit The system includes: a temporary registration unit that, when the first user identification information is received, registers the first user identification information in the second storage unit if the first user identification information identifying the same user as the first user identification information is not stored in the first storage unit; a permission notification receiving unit that receives a permission notification from the administrator terminal granting the first user permission to execute the functions of the image processing device in response to the temporary registration unit registering the first user identification information in the second storage unit; and a final registration unit that, when the permission notification receiving unit receives the permission notification, registers the first user identification information registered in the second storage unit by the temporary registration unit and the permission notification in association with each other in the first storage unit.
[0016] To achieve the above objective, the program described in claim 11 is an image processing apparatus to which a plurality of user terminals and an administrator terminal are communicated together, and is a program executed by a control unit of the image processing apparatus which includes a first storage unit and a second storage unit that store user identification information for identifying a user and store either permission information for allowing a user to execute the functions of the image processing apparatus or disallowance information for not allowing a user to execute the functions of the image processing apparatus in association with the stored user identification information, and the control unit is configured to receive first user identification information, which is the user identification information for identifying a first user, from the user terminal of the first user, and in the first receiving process If, at the time the first user identification information is received, user identification information identifying the same user as the first user identification information is not stored in the first storage unit, the following are performed: a provisional registration process to register the first user identification information in the second storage unit; a permission notification reception process to receive a permission notification from the administrator terminal in response to the first user identification information being registered in the second storage unit by the provisional registration process, granting the first user the right to perform the functions of the image processing device; and, if the permission notification is received by the permission notification reception process, a final registration process to register the first user identification information registered in the second storage unit by the provisional registration process and the permission information in association with each other in the first storage unit. [Effects of the Invention]
[0017] According to the invention of claim 1, the first user identification information transmitted from the first user's user terminal is registered in the second storage unit. When the image processing device receives a permission notification from the administrator terminal granting the first user permission to execute the functions of the image processing device, it registers the first user identification information registered in the second storage unit back into the first storage unit, thereby performing a setting that allows the first user to execute the functions of the image processing device. Therefore, the administrator can reduce the effort required to input the first user identification information into the administrator terminal when setting up permission for the first user to execute the functions of the image processing device. Furthermore, according to claim 1, in response to the first user identification information being registered in the second storage unit by the temporary registration unit, the temporary registration notification unit sends a notification to the administrator terminal. Therefore, the administrator can recognize that the first user has requested permission to execute the functions of the image processing device.
[0018] According to the invention of claim 2, if the first authentication key transmitted from the user terminal of the first user matches the authentication key generated by the authentication key generation unit, the first user identification information is registered in the second storage unit. Therefore, the administrator can prevent the user identification information of users they do not want to allow to use the image processing device from being registered in the second storage unit.
[0019] According to the invention of claim 3, if the first authentication key transmitted from the user terminal of the first user matches the one-time key generated by the authentication key generation unit, and a predetermined amount of time has not elapsed since the one-time key was generated, the first user identification information transmitted from the user terminal of the first user along with the first authentication key is registered in the second storage unit. Therefore, if a user illegally obtains a leaked one-time key, the risk of the user identification information of the illegally obtained user being registered in the second storage unit can be reduced.
[0020] According to the invention of claim 4, after a predetermined period of time has elapsed since the one-time key was generated and the one-time key was valid, the image processing device notifies the administrator terminal that the predetermined time has elapsed. Therefore, the administrator can recognize that it is time to register the user identification information of multiple users in bulk.
[0021] According to the invention of claim 5, the administrator can send a permission notification from the administrator terminal to the image processing device without accepting input of the first user identification information by performing a predetermined operation on the registration screen shown on the screen data containing the first user identification information. Therefore, when the administrator sets up the system to allow the first user to execute the functions of the image processing device, the administrator can reduce the effort required to input the first user identification information into the administrator terminal.
[0022] When introducing an image processing device to a department within a company, it is conceivable to restrict the execution of specific functions from among the multiple functions of the image processing device depending on the employee's position. According to the invention of claim 6, the image processing device is capable of executing a first function and a second function, and it is possible to permit or restrict a user from executing the first function, as well as permit or restrict a user from executing the second function.
[0023] According to the invention of claim 7, the image processing device deletes the first user identification information from the second storage unit after the registration unit has registered the first user identification information in the first storage unit. Therefore, the administrator can reduce the effort required to find user identification information that has not been registered during subsequent registrations.
[0024] The setting to permit or restrict the execution of the functions of the image processing apparatus can be made only by the administrator of the image processing apparatus. Therefore, a user of the image processing apparatus may not know that he / she is not permitted to execute the functions of the image processing apparatus until he / she tries to execute the functions. According to the invention of claim 8, when a second user whose user identification information is registered in the first storage unit tries to execute the functions of the image processing apparatus, he / she can request the administrator to permit him / her to execute the functions of the image processing apparatus.
[0025] According to the invention of claim 9, the first user identification information transmitted from the user terminal of the first user is registered in the second storage unit. When a permission notification for permitting the first user to execute the functions of the image processing apparatus is transmitted in the permission notification step, in this registration step, by registering the first user identification information registered in the second storage unit in the first storage unit, a setting for permitting the first user to execute the functions of the image processing apparatus is executed. Therefore, when the administrator makes a setting for permitting the first user to execute the functions of the image processing apparatus, the administrator can reduce the trouble of inputting the first user identification information into the administrator terminal. Further, according to claim 9, in the provisional registration notification step, when the first user identification information is registered in the second storage unit, a notification is executed to the administrator or the administrator terminal. Therefore, the administrator can recognize that a request has been made by the first user to permit the first user to execute the functions of the image processing apparatus.
[0026] According to the invention of claim 10, the first user identification information transmitted from the user terminal of the first user is registered in the second storage unit. When the image processing apparatus receives a permission notification for permitting the first user to execute the functions of the image processing apparatus from the administrator terminal, by registering the first user identification information registered in the second storage unit in the first storage unit, a setting for permitting the first user to execute the functions of the image processing apparatus is executed. Therefore, when the administrator makes a setting for permitting the first user to execute the functions of the image processing apparatus, the administrator can reduce the trouble of inputting the first user identification information into the administrator terminal.
[0027] According to the invention of claim 11, the first user identification information transmitted from the user terminal of the first user is registered in the second storage unit. When the image processing apparatus receives a permission notification permitting the first user to execute the functions of the image processing apparatus from the administrator terminal, the image processing apparatus registers the first user identification information registered in the second storage unit in the first storage unit, thereby executing a setting for permitting the first user to execute the functions of the image processing apparatus. Therefore, when the administrator performs a setting for permitting the first user to execute the functions of the image processing apparatus, the administrator can reduce the trouble of inputting the first user identification information into the administrator terminal.
Brief Description of the Drawings
[0028] [Figure 1] It is a block diagram showing the configuration of an information processing system 1 according to a first embodiment that performs one-time key authentication. [Figure 2] It is a diagram showing changes in the stored contents of the main registration list 312. [Figure 3] It is a diagram showing changes in the stored contents of the temporary registration list 313. [Figure 4] It is a diagram showing the stored contents of the Job table 314. [Figure 5] It is a sequence diagram explaining the procedure for the administrator to perform batch registration settings. [Figure 6] It is a diagram showing the administrator screen 500. [Figure 7] It is a diagram showing the batch registration setting screen 600. [Figure 8] It is a flowchart explaining the procedure of the authentication determination process S100. [Figure 9] It is a sequence diagram explaining the procedure for a registered user to succeed in authentication and execute the scan function. [Figure 10] It is a sequence diagram explaining the procedure when a registered user fails in authentication and cannot execute the scan function. [Figure 11] It is a sequence diagram explaining the procedure for a registered user to request the administrator to add the permission of the printing function. [Figure 12] This sequence diagram illustrates the first part of the procedure when an unregistered user's user ID and password are provisionally registered, and then administrators add permissions to that user. [Figure 13] This sequence diagram illustrates the latter part of the procedure when an unregistered user's user ID and password are provisionally registered, and then privileges are added by the administrator. [Figure 14] This is a diagram showing the batch registration screen 700. [Figure 15] This is a sequence diagram illustrating the procedure to follow when the provisional registration of an unregistered user's user ID and password fails. [Figure 16] This flowchart illustrates the procedure for the authentication decision process S200 in the second embodiment, which does not perform one-time key authentication. [Figure 17] This sequence diagram illustrates the procedure for when an unregistered user's user ID and password are provisionally registered without one-time key authentication, and then privileges are added by the administrator. [Modes for carrying out the invention]
[0029] <First Example> This document describes an information processing system according to a first embodiment that performs one-time key authentication. The information processing system 1 shown in Figure 1 comprises an administrator terminal 100, a plurality of user terminals 200A to 200C, and a multifunction printer 300. The administrator terminal 100, the user terminals 200A to 200C, and the multifunction printer 300 communicate with each other via a network NT. The network NT is, for example, a Local Area Network (LAN). When referring to the plurality of user terminals 200A to 200C collectively, they are referred to as user terminal 200.
[0030] <Administrator terminal configuration> The administrator terminal 100 is managed by the administrator of the multifunction printer 300. The administrator terminal 100 is, for example, a smartphone. The administrator terminal 100 includes non-volatile memory 110, volatile memory 120, CPU 130, touch panel 140, display 150, and communication interface 160. Hereafter, the interface will be abbreviated as "IF".
[0031] The non-volatile memory 110 is, for example, ROM. The non-volatile memory 110 stores the browser 111 and the operating system 112. The browser 111 is software for viewing web pages provided by the multifunction printer 300. The operating system 112 is a program that controls the administrator terminal 100. Hereafter, the operating system will be abbreviated as "OS".
[0032] The volatile memory 120 is, for example, RAM. The volatile memory 120 temporarily stores the user ID and password entered by the administrator.
[0033] CPU130 performs various processes according to OS112.
[0034] The touch panel 140 is, for example, an LCD panel. The touch panel 140 receives touch operations from the administrator and sends a signal corresponding to the touch operation to the CPU 130.
[0035] Display 150 displays the administrator screen 500, the batch registration settings screen 600, and the batch registration screen 700, which will be described later.
[0036] The communication IF160 connects wirelessly to the NT network and communicates with each other, including the user terminal 200 and the multifunction printer 300.
[0037] <User terminal configuration> The user terminal 200 is owned by a user who uses the multifunction printer 300, or a user who wishes to use the multifunction printer 300. The user terminal 200 includes non-volatile memory 210, volatile memory 220, CPU 230, touch panel 240, display 250, and communication IF 260. The volatile memory 220, CPU 230, and touch panel 240 have the same functions as the volatile memory 120, CPU 130, and touch panel 140, respectively.
[0038] The non-volatile memory 210 stores the general-purpose application 211 and the OS 212. The general-purpose application is an application program that instructs the multifunction printer 300 to execute the scan or print function. The general-purpose application 211 is an application that corresponds to each scanner from each manufacturer, and the user can execute the scan function without installing the manufacturer's proprietary scanner driver. The general-purpose application 211 is, for example, the Mopria Scan application from the Mopria® Alliance. The OS 212 is a program that controls the user terminal 200.
[0039] Display 250 displays the authentication screen and the scanning screen, which will be described later.
[0040] <Configuration of the multifunction printer> The multifunction printer 300 includes a scanning function, a printing function, and a web server function. The multifunction printer 300 also includes a non-volatile memory 310, a volatile memory 320, a CPU 330, a communication interface 340, a scanner unit 350, a printing unit 360, and a timer 370.
[0041] The non-volatile memory 310 stores firmware 311, a permanent registration list 312, a temporary registration list 313, a Job table 314, administrator information 315, EWS 316, and an application program 317. Firmware 311 is a program for controlling scanning by the scanner unit 350 and printing by the printer unit 360. The application program 317 includes various programs that execute the sequence procedures and authentication decision processes described later.
[0042] The registration list 312 shown in Figure 2 displays a list of users authorized by the administrator to execute the scanning or printing functions of the multifunction printer 300. The registration list 312 stores the username, password, user ID, scanning privileges, and printing privileges in association with each username. The username is a string that identifies the user. The password is a string that represents the key required to log in. The username and password are set by the user. The user ID is a string that identifies the combination of the username and password. The user ID is issued by the multifunction printer 300 when the username and password are registered in the registration list 312. Either the string "UNLOCK" or the string "LOCK" is stored for scanning privileges and printing privileges. The string "UNLOCK" indicates that the administrator has authorized the user identified by the username to execute the functions of the multifunction printer 300. The string "LOCK" indicates that the administrator has not authorized the user identified by the username to execute the functions of the multifunction printer 300.
[0043] In this embodiment, the data sets associated in a list are called records. In Figure 2, the data set consisting of username "User1", password "Pw1", user ID "10000", scan permission "UNLOCK", and print permission "LOCK" constitutes a single record.
[0044] In the provisional registration list 313 shown in Figure 3, the user ID and password are registered in steps S138 and S155 of the authentication decision process (S100) described later. The user identified by the user ID registered in the provisional registration list 313 is a user who has not yet been authorized to execute at least one of the scanning and printing functions of the multifunction printer 300.
[0045] The Job table 314 shown in Figure 4 stores JobIDs linked to User IDs. The User ID is the same string as the User ID stored in the main registration list 312. The JobID is a unique ID assigned to each scan and print job.
[0046] EWS316 is a program that provides web server functionality. The web server functionality transmits screen data indicating the screens displayed on each external device, depending on whether the administrator terminal 100 or user terminal 200 is accessed by these external devices. For example, the web server functionality causes the multifunction printer 300 to send administrator screen data indicating the administrator screen 500, batch registration setting screen data indicating the batch registration setting screen 600, and batch registration screen data indicating the batch registration screen 700 to the administrator terminal 100. EWS is an abbreviation for Embedded Web Server.
[0047] Administrator information 315 includes the administrator ID, which is the ID used to log in to the web server function, and the password. In this embodiment, the administrator ID is "Admin" and the password is "Pw".
[0048] The volatile memory 320 temporarily stores scan data indicating images scanned by the scanner unit 350. The volatile memory 320 also temporarily stores a one-time key generated when the administrator performs batch registration settings.
[0049] The CPU 330 executes the firmware 311, controls scanning by the scanner unit 350 and printing by the printer unit 360, and performs processing such as the sequence procedures and authentication decision processing described later, according to the application program 317.
[0050] The scanner unit 350 scans the document to be scanned and forms image data. The scanner unit 350 includes at least a light source that illuminates the document from below and an image sensor that reads the light reflected by the document.
[0051] The printing unit 360 performs printing using an electrophotographic method, which transfers a toner image representing the image to be printed onto the printing paper. The printing unit 360 comprises at least a photosensitive drum on which the toner image is formed, and a toner cartridge filled with toner.
[0052] <Bulk Registration Settings> Refer to Figure 5 to explain the procedure for administrators to perform bulk registration settings.
[0053] The administrator terminal 100 accepts input from the administrator for the IP address assigned to the multifunction printer 300 (T100). The administrator terminal 100 requests the multifunction printer 300 to send administrator login screen data (T105).
[0054] The multifunction printer 300 transmits administrator login screen data (T110).
[0055] The administrator terminal 100 receives administrator login screen data from the multifunction printer 300. The administrator terminal 100 displays the administrator login screen on the display 150 (T115). The administrator login screen includes an administrator ID input box for entering the administrator ID and a password input box for entering the password. The administrator terminal 100 accepts the administrator ID "Admin" and password "Pw" from the administrator (T120). The administrator terminal 100 temporarily stores the administrator ID "Admin" and password "Pw" in the volatile memory 120 (T125). The administrator terminal 100 sends an authentication request including the administrator ID "Admin" and password "Pw" to the multifunction printer 300 (T130).
[0056] The multifunction printer 300 receives an authentication request from the administrator terminal 100. The multifunction printer 300 determines that authentication is successful because the administrator ID and password stored in the non-volatile memory 310 match the administrator ID "Admin" and password "Pw" included in the authentication request (T135). The multifunction printer 300 sends the administrator screen data to the administrator terminal 100 (T140).
[0057] The administrator terminal 100 receives administrator screen data from the multifunction printer 300. The administrator terminal 100 displays the administrator screen 500 on the display 150 (T145). The administrator screen 500 shown in Figure 6 includes a batch registration setting button 510, a batch registration button 520, and a registration content change button 530. The administrator terminal 100 accepts input from the administrator via the batch registration setting button 510 (T150). The administrator terminal 100 requests the multifunction printer 300 to send the batch registration setting screen data (T155).
[0058] When the multifunction printer 300 is requested to send batch registration settings screen data, the multifunction printer 300 generates a one-time key "ADLKH" and temporarily stores it in the volatile memory 320 (T160). The multifunction printer 300 then sends the batch registration settings screen data to the administrator terminal 100 (T165).
[0059] The administrator terminal 100 receives batch registration settings screen data from the multifunction printer 300. The administrator terminal 100 displays the batch registration settings screen 600 on the display 150 (T170). The batch registration settings screen 600 shown in Figure 7 includes a one-time key input box 610, an expiration date input box 620, and a registration start button 630. The batch registration settings screen 600 displays an example of how a regular user would enter a username and password. Initially, the one-time key input box 610 is populated with the one-time key "ADLKH" generated by the multifunction printer 300 in T160. Initially, the expiration date input box 620 is populated with "60" to indicate that the one-time key has an expiration date of 60 minutes.
[0060] The administrator terminal 100 receives a press of the registration start button 630 from the administrator (T180). The administrator terminal 100 sends a batch registration setting, including the one-time key "ADLKH" and the expiration date "60", to the multifunction printer 300 (T185).
[0061] The multifunction printer 300 receives the batch registration settings from the administrator terminal 100. The multifunction printer 300 activates timer 370 (T190). In other words, the one-time key is activated.
[0062] The administrator terminal 100 may accept editing of the one-time key input box 610 and the expiration date input box 620 before accepting the press of the registration start button 630 on T180. If the one-time key and expiration date are edited, T185 sends a batch registration setting including the edited one-time key and the edited expiration date. The multifunction printer 300 temporarily stores the edited one-time key in the volatile memory 320 in place of the one-time key generated on T160. The multifunction printer 300 temporarily stores the edited expiration date in the volatile memory 320 and starts the timer 370.
[0063] <Authentication Decision Processing> The authentication decision process (S100) will be explained with reference to Figure 8. The authentication decision process S100 is executed by the CPU 330 according to the application program 317. The authentication decision process S100 is started when the user terminal 200 receives one of the following requests: a status request, a job creation request, or an image request.
[0064] In S103, it is determined whether the header information of the received request is empty or not. Specifically, if the header information does not contain the input string or the password (S103: YES), a 401 error indicating authentication failure is sent to the user terminal 200 (S140).
[0065] If the header information includes both the input string and the password (S103:NO), S105 reads both the input string and the password. In S110, the input string is separated into the username and the one-time key. Specifically, if the input string contains an underscore, CPU330 determines the string from the beginning up to the underscore as the one-time key, and the string from the end after the underscore as the username. If the input string does not contain an underscore, CPU330 determines the one-time key as an empty string and the entire input string as the username.
[0066] In S115, records matching the username are searched for in the main registration list 312. In S120, it is determined whether or not a record matching the username exists.
[0067] If a record exists (S120:YES), it is determined whether the received password matches the password contained in the record (S125). If the received password does not match the password contained in the record (S125:NO), a 401 error indicating authentication failure is sent to the user terminal 200 (S140).
[0068] If the received password matches the password contained in the record (S125:YES), it is determined whether the user has the authority to perform the function (S130). Specifically, if a signal requesting the execution of a scan is received, it is determined whether "UNLOCK" is stored in the record's scan authority. If "UNLOCK" is not stored in the record's scan authority, that is, if "LOCK" is stored (S130:NO), the username and password are registered in the temporary registration list 313 (S138). In S138, the contents of the scan authority and print authority are also registered in the temporary registration list 313. Once S138 is complete, a 401 error indicating authentication failure is sent to the user terminal 200 (S140). If a signal requesting the execution of a print is received, the determination in S130 is performed depending on whether "UNLOCK" is stored in the record's print authority.
[0069] If it is determined that the user has the authority to execute the function (S130: YES), the function execution preparation process is executed (S135). In the function execution preparation process, the necessary processing to execute the function is performed depending on whether the signal received from the user terminal 200 is a status request (T240) in Figure 9, a job creation request (T265), or an image request (T285).
[0070] If no record exists that matches the username (S120:NO), it is determined whether a one-time key exists (S145). Specifically, it is determined whether the one-time key separated in S110 is an empty column. If it is determined that the one-time key is an empty column (S145:NO), a 401 error indicating authentication failure is sent to the user terminal 200 (S140).
[0071] If it is determined that the one-time key is not an empty string (S145:YES), it is determined whether the one-time key is valid or not (S150). Specifically, it is determined whether the one-time key matches the one-time key generated in T160 and whether the time indicated by the expiration date has not elapsed since timer 370 was started in T190. If the one-time key does not match the one-time key generated in T160, or if the time indicated by the expiration date has elapsed (S150:NO), a 401 error indicating authentication failure is sent to the user terminal 200 (S140).
[0072] If the one-time key matches the one-time key generated in T160 and the time indicated by the expiration date has not elapsed (S150: YES), the username and password are registered in the temporary registration list 313 (S155). Once S155 is complete, a 401 error indicating authentication failure is sent to the user terminal 200 (S140). Once either S135 or S140 is executed, the CPU 330 terminates the authentication determination process (S100).
[0073] <Case CA1: Registered users perform the function> Refer to Figure 9 to explain the procedure for a registered user to perform the scan function. The user with username "User1" has completed registration, and this registration list 312 is in the state shown in Figure 2(a).
[0074] The user terminal 200 receives an operation from the user named "User1" to select the multifunction printer 300 as the scanner to perform the scanning function in the general-purpose application 211 (T200). The user terminal 200 requests the multifunction printer 300 to send capability information (T205). Capability information includes, for example, whether or not it has an automatic document feeder and the resolutions that the multifunction printer 300 can scan.
[0075] When the multifunction printer 300 receives a request from the user terminal 200, the multifunction printer 300 transmits capability information to the user terminal 200 (T210).
[0076] The user terminal 200 receives capability information from the multifunction printer 300. The user terminal 200 sends a status request (T215) to the multifunction printer 300 that does not include header information.
[0077] The multifunction printer 300 receives a status request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S100) (T218). Since the status request does not contain header information, the multifunction printer 300 sends a 401 error to the user terminal 200 (T220).
[0078] The user terminal 200 receives a 401 error from the multifunction printer 300. The user terminal 200 displays an authentication screen on the display 150 according to image data pre-stored in the general-purpose application 211 (T225). The authentication screen includes a username input box and a password input box. The user terminal 200 accepts the input of username "User1" and password "Pw1" from the user with username "User1" (T230). The user terminal 200 temporarily stores username "User1" and password "Pw1" in the volatile memory 120 (T235). The user terminal 200 sends a status request to the multifunction printer 300, which includes username "User1" and password "Pw1" in its header information (T240).
[0079] The multifunction printer 300 receives a status request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S100) (T245). The registration list 312 contains a record with the username "User1" and password "Pw1", and the scan permission "UNLOCK" is stored in it. Therefore, as part of the function execution preparation processing (S135), the multifunction printer 300 sends status information to the user terminal 200 indicating that the multifunction printer 300 is in standby mode (T250).
[0080] The status of the multifunction printer 300 is either "running" or "standby." "Running" means that another user has instructed the printer to perform a scan, and the printer 300 is executing the processes described in T265 to T305. "Standby" means that the printer is not running.
[0081] The user terminal 200 receives status information from the multifunction printer 300. The user terminal 200 displays a scan screen on the display 150 according to the image data pre-stored in the general-purpose application 211 (T255). The scan screen is a screen that accepts scan settings based on the capability information transmitted in T210. The scan screen includes a scan execution button that instructs the multifunction printer 300 to perform a scan. On the scan screen, the user terminal 200 accepts scan settings from the user with username "User1". When the user terminal 200 accepts the operation of the scan execution button from the user with username "User1" (T260), the user terminal 200 sends a Job creation request to the multifunction printer 300 (T265). The Job creation request includes the username "User1" and password "Pw1", which were temporarily stored in the volatile memory 120 in T235, and information regarding the scan settings set on the scan screen in its header information.
[0082] The multifunction printer 300 receives a Job creation request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S100) (T270). The registration list 312 contains a record with username "User1" and password "Pw1", and the scan permission "UNLOCK" is stored. Therefore, as a function execution preparation process (S135), the multifunction printer 300 performs processing to send a user-specific URI (Uniform Resource Identifier) for username "User1" to the user terminal 200. Specifically, the multifunction printer 300 obtains user ID "10000", which is stored in association with username "User1" and password "Pw1". The multifunction printer 300 generates JobID "Job1" and stores it in the Job table 314 in association with user ID "10000" (T275). The multifunction printer 300 generates a URI "http: / / server.com / Job1" that includes the JobID "Job1" and sends it to the user terminal 200 (T280).
[0083] User terminal 200 receives the URI "http: / / server.com / Job1" from the multifunction printer 300. User terminal 200 sends an image request to the multifunction printer 300 with the URI "http: / / server.com / Job1" as the destination (T285). The image request includes the username "User1" and password "Pw1" in the header information.
[0084] The multifunction printer 300 receives an image request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S100) (T290). The registration list 312 contains a record with the username "User1" and password "Pw1", and the scan permission "UNLOCK" is stored there. Therefore, as a function execution preparation process (S135), the multifunction printer 300 performs processing to send scan data to the user terminal 200. Specifically, the multifunction printer 300 obtains the user ID "10000", which is stored in association with the username "User1" and password "Pw1". The user ID "10000" obtained by the multifunction printer 300 matches the user ID stored in the Job table 314 in association with JobID "Job1" (T295), so the multifunction printer 300 performs a scan using the scanner unit 350 and temporarily stores the scan data in the volatile memory 320 (T300). The multifunction printer 300 sends the scanned data to the user terminal 200 (T305). As a result, the user with username "User1" can view the scanned data on the user terminal 200.
[0085] <Effects of Case CA1> According to Case CA1, as shown in Figure 2(a), if a user name with scanning privileges is already registered in the main registration list 312, the user can perform the normal scanning function. Since the user name is not registered in the temporary registration list 313, there is no risk of the administrator misidentifying users who need to be registered when performing bulk registration.
[0086] <Case CA2: Registered user enters password incorrectly> Refer to Figure 10 to explain the case where a registered user enters the wrong password. The user with username "User1" has completed registration, and this registration list 312 is in the state shown in Figure 2(a).
[0087] For T400 to T425, the same processing as for T200 to T225 in case CA1 is performed. In T430, the user terminal 200 receives input of the username "User1" and password "Pw0" from the user with the username "User1". The user terminal 200 temporarily stores the username "User1" and password "Pw0" in the volatile memory 120 (T435). The user terminal 200 sends a status request containing the username "User1" and password "Pw0" in the header information to the multifunction printer 300 (T440).
[0088] The multifunction printer 300 receives a status request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S100) (T445). The registration list 312 contains a record with the username "User1" and the password "Pw1" stored in it. Since the password "Pw0" included in the authentication request does not match the password "Pw1" stored in the record (S125: NO), in T450, the multifunction printer 300 sends a 401 error to the terminal 200 (S140).
[0089] <Effects of Case CA2> According to Case CA2, if a username is already registered in the main registration list 312, the username will not be registered in the temporary registration list 313 even if the user enters the password incorrectly. Therefore, when the administrator performs bulk registration, there is no risk of registering a username that has already been registered twice in the main registration list 312.
[0090] <Case CA3: A registered user requests additional permission to execute a function> Refer to Figure 11 to explain the procedure for a registered user to request additional print permissions. The user with username "User1" has completed registration, and this registration list 312 is in the state shown in Figure 2(a).
[0091] The user terminal 200 receives an operation from the user named "User1" to select the multifunction printer 300 as the printer to execute the printing function in the general-purpose application 211 (T500). Subsequently, in T505 to T540, the same processing as in T205 to T240 of case CA1 is performed.
[0092] At T545, the multifunction printer 300 performs an authentication determination process (S100). The main registration list 312 contains a record with the username "User1" and password "Pw1", and the print permission "LOCK" is stored in it. Therefore, the multifunction printer 300 registers the contents of the record in the temporary registration list 313 (S138), and at T550, sends a 401 error to the user terminal 200 (S140). The multifunction printer 300 sends a permission addition request notification containing the username "User1" to the administrator terminal 100 (T555). The permission addition request notification is a notification requesting the addition of permission for a function that the user is not permitted to perform. In this case, the permission addition request notification includes the text message "A user with username "User1" has requested the addition of print permission." The permission addition request notification is sent, for example, by email. The contents of the permission addition request notification are confirmed by the administrator who owns the administrator terminal 100.
[0093] The administrator terminal 100 accepts the administrator login using the same process as T100 to T145 and displays the administrator screen 500 on the display 150. The administrator terminal 100 accepts operation of the registration change button 530 (T560). The administrator terminal 100 requests the multifunction printer 300 to send the registration change screen data (T565).
[0094] The multifunction printer 300 sends the registration change screen data to the administrator terminal 100 (T570). The registration change screen data includes the stored contents of the temporary registration list 313.
[0095] The administrator terminal 100 receives registration change screen data from the multifunction printer 300. The administrator terminal 100 displays the registration change screen shown in Figure 14 on the display 150 (T575). The registration change screen includes a list of usernames and passwords of users registered in the temporary registration list 313, and a confirmation button. The list includes a scan permission checkbox indicating whether the user has permission to perform the scan function, and a print permission checkbox indicating whether the user has permission to perform the print function. In Figure 2(a), the user with username "User1" is a user whose username is already registered in the main registration list 312, and "UNLOCK" is stored for scan permission. Therefore, in Figure 14, the checkbox for the scan permission "Scanner" of the user with username "User1" is displayed in a checked state by default. The administrator terminal 100 accepts the operation of the print permission checkbox of the user with username "User1" (T580). When the administrator terminal 100 receives a confirmation button press (T585), the administrator terminal 100 sends a permission request to the multifunction printer 300 (T590). The permission request includes the username "User1", the password "Pw1", and the function identifier string "Printer".
[0096] The multifunction printer 300 receives a request to add permissions from the administrator terminal 100. The multifunction printer 300 changes the print permission status "LOCK" stored in the record for the username "User1" in the main registration list 312 to "UNLOCK" (T595). From this point onward, the user with username "User1" can perform print operations.
[0097] <Effects of Case CA3> According to Case CA3, a user whose username is registered in this registration list 312 but who is not permitted to execute the print function can request the administrator to add print permissions when they attempt to execute the print function and fail authentication.
[0098] <Case CA4: An unregistered user performs a provisional registration> Referring to Figures 12 and 13, the procedure for a user who owns user terminal 200A to provisionally register the username "User2" is described. The username "User2" is not stored in the main registration list 312, and the main registration list 312 is in the state shown in Figure 2(a). The administrator has executed the sequence shown in Figure 5, and 30 minutes have passed since the bulk registration settings were completed.
[0099] The administrator terminal 100 notifies each of the user terminals 200A to 200C of the one-time key "ADLKH" generated in T160 (T690). The one-time key is notified, for example, by email. The one-time key is verified by the user who owns user terminal 200.
[0100] In steps T700 to T725, the same processing as in steps T200 to T225 of case CA1 is performed. In step T730, user terminal 200A receives the username "ADLKH_User2" and password "Pw2" from the user who owns user terminal 200A. User terminal 200A temporarily stores the username "ADLKH_User2" and password "Pw2" in volatile memory 220 (T735). User terminal 200A sends a status request to the multifunction printer 300, which includes the username "ADLKH_User2" and password "Pw2" in its header information (T740).
[0101] The multifunction printer 300 receives a status request from the user terminal 200A. The multifunction printer 300 performs authentication determination processing (S100) (T745). The main registration list 312 does not contain any records containing the username "User2". The status request includes the one-time key "ADLKH", and 60 minutes have not elapsed since the one-time key was generated. Therefore, the multifunction printer 300 registers the username "User2" and the password "Pw2" in the temporary registration list 313 (S155). The multifunction printer 300 performs processing to send a 401 error to the user terminal 200A (S140) (T748). The multifunction printer 300 notifies the administrator terminal 100, for example by email, that the temporary registration is complete (T750).
[0102] Furthermore, processes T700 to T750 are also executed for the user who owns user terminal 200B and the user who owns user terminal 200C. The user who owns user terminal 200B is assumed to have registered the username "User3" and password "Pw3", and the user who owns user terminal 200C is assumed to have registered the username "User4" and password "Pw4". In other words, the provisional registration list 313 is in the state shown in Figure 3(a).
[0103] After 60 minutes have passed since the one-time key "ADLKH" was generated, the multifunction printer 300 notifies the administrator terminal 100 via email that the one-time key has expired (T755).
[0104] The administrator terminal 100 accepts the administrator login using the same process as T100 to T145 and displays the administrator screen 500 on the display 150. The administrator terminal 100 accepts the operation of the batch registration button 520 (T760). The administrator terminal 100 requests the multifunction printer 300 to send the batch registration screen data (T765).
[0105] The multifunction printer 300 sends the batch registration screen data to the administrator terminal 100 (T770). The batch registration screen data includes the contents of the temporary registration list 313.
[0106] The administrator terminal 100 receives batch registration screen data from the multifunction printer 300. The administrator terminal 100 displays the batch registration screen 700 on the display 150 (T775). The batch registration screen 700 shown in Figure 14 includes a list of usernames and passwords registered in the temporary registration list 313, and an OK button. The list includes a scan permission checkbox indicating whether the user has permission to execute the scan function "Scanner" and a print permission checkbox indicating whether the user has permission to execute the print function "Printer". The administrator terminal 100 accepts the operation of the scan permission checkbox and the print permission checkbox for the user with username "User2" (T780). When the administrator terminal 100 accepts the operation of the OK button (T785), the administrator terminal 100 sends a permission addition request to the multifunction printer 300 (T790). The permission request includes the username "User2", the password "Pw2", and the function-identifying strings "Scanner" and "Printer".
[0107] The multifunction printer 300 receives a request to add permissions from the administrator terminal 100. The multifunction printer 300 registers the username "User2" and password "Pw2" in the permanent registration list 312 by generating a new record containing the username "User2" and password "Pw2" stored in the temporary registration list 313 (T795). "UNLOCK" is registered for the scan and print permissions of the generated record. At the same time, a user ID "20000" is generated for the user with username "User2" and registered in the generated record. The multifunction printer 300 deletes the record containing the username "User2" from the temporary registration list 313 (T800).
[0108] Figure 2(b) shows that the username "User2" and password "Pw2" are registered in the main registration list 312, and both scanning and printing permissions are granted. Figure 2(b) also shows that the username "User3" and password "Pw3" are registered in the main registration list 312, and only scanning permission is granted.
[0109] Figure 3(b) shows that the record containing the username "User2" and password "Pw2" was deleted from the provisional registration list 313. Figure 3(b) also shows that the record containing the username "User3" and password "Pw3" was deleted from the provisional registration list 313, but the record containing the username "User4" and password "Pw4" was not deleted. In other words, the administrator did not allow the user with username "User4" to use the multifunction printer 300.
[0110] <Effects of Case CA4> According to Case CA4, users whose usernames are not stored in the main registration list 312 will fail authentication when attempting to use the multifunction printer 300, but their username and password will be registered in the temporary registration list 313. On the batch registration screen 700, which displays the contents of the temporary registration list 313, the administrator can set restrictions on the functions that the multifunction printer 300 can perform by operating the scan permission checkbox and the print permission checkbox, without having to manually enter the username.
[0111] <Case CA5: Unregistered user fails to complete pre-registration> Referring to Figure 15, we will explain the case in which a user who has not been notified of a one-time key fails to complete the provisional registration. The username "User5" is not stored in the main registration list 312, and the main registration list 312 is in the state shown in Figure 2(a).
[0112] In T900~T925, the same processing as in T200~T225 of case CA1 is performed. In T930, user terminal 200 receives the username "User5" and password "Pw5" from the user who owns user terminal 200. User terminal 200 temporarily stores the username "User5" and password "Pw5" in volatile memory 220 (T935). User terminal 200 sends a status request containing the username "User5" and password "Pw5" in the header information to the multifunction printer 300 (T940).
[0113] The multifunction printer 300 receives a status request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S100) (T945). The main registration list 312 does not contain any records containing the username "User5". Since the status request does not include the one-time key "ADLKH", the multifunction printer 300 does not register the username "User5" and password "Pw5" in the temporary registration list 313, and instead performs processing to send a 401 error to the user terminal 200 (S140) (T950).
[0114] Case CA5 also applies when an incorrect or expired one-time key is entered. Specifically, in T930, if an incorrect or expired one-time key is entered, the multifunction printer 300 does not register the username "User5" and password "Pw5" in the temporary registration list 313 (T945), and instead executes the process of sending a 401 error to the user terminal 200 (S140) (T950).
[0115] <Effects of Case CA5> According to Case CA5, if a one-time key is not entered on the authentication screen, the username and password will not be registered in the temporary registration list 313. Similarly, if an incorrect or expired one-time key is entered, the username and password will not be registered in the temporary registration list 313. Therefore, it is possible to prevent the usernames of users who should not be allowed to use the multifunction printer 300 from being registered in the temporary registration list 313.
[0116] <Effects of the First Example> (1) According to the first embodiment, the username "User2" transmitted from the user terminal 200 is registered in the temporary registration list 313 (S155). When the multifunction printer 300 receives a request from the administrator terminal 100 to add permission to allow the user with username "User2" to execute the scanning or printing function of the multifunction printer 300 (T790), it registers the username "User2" registered in the temporary registration list 313 in the main registration list 312 (T795), thereby executing the setting that allows the user with username "User2" to execute the scanning or printing function of the multifunction printer 300. Therefore, when the administrator sets up the setting that allows the user with username "User2" to execute the scanning or printing function of the multifunction printer 300, the effort required to enter the username "User2" into the administrator terminal 100 is reduced. Furthermore, the multifunction printer 300 notifies the administrator terminal 100 (T750, T755) when the username "User2" sent from the user terminal 200 is registered in the temporary registration list 313. Therefore, the administrator can recognize that the user "User2" has requested permission to use the scanning or printing function of the multifunction printer 300.
[0117] (2) According to the first embodiment, if the one-time key transmitted from the user terminal 200 matches the one-time key "ADLKH" generated in T160 (S150: YES), the username "User2" transmitted from the user terminal 200 is registered in the provisional registration list 313 (S155). Therefore, the administrator can prevent the usernames of users they do not want to allow to use the multifunction printer 300 from being registered in both the official registration list 312 and the provisional registration list 313.
[0118] (3) According to the first embodiment, if the one-time key transmitted from the user terminal 200 matches the one-time key "ADLKH" generated in T160, and 60 minutes, which is the expiration time of the one-time key, has not elapsed since the one-time key was generated (S150: YES), the username "User2" transmitted from the user terminal 200 is registered in the provisional registration list 313 (S155). Therefore, if a user illegally obtains a leaked one-time key, the risk that the username of the user who illegally obtained it will be registered in both the main registration list 312 and the provisional registration list 313 can be reduced.
[0119] (4) According to the first embodiment, after 60 minutes have elapsed since the one-time key was generated, the multifunction printer 300 notifies the administrator terminal 100 of the expiration of the one-time key (T755). Therefore, the administrator can recognize that it is time to register the usernames of multiple users at once.
[0120] (5) According to the first embodiment, the administrator can send a permission request to the multifunction printer 300 from the administrator terminal 100 without accepting input of the username "User2" by operating the scan permission checkbox or the print permission checkbox on the batch registration screen 700 (T780) (T790). Therefore, when the administrator sets up the system to allow the user with username "User2" to perform the scan function or print function of the multifunction printer 300, the administrator can reduce the effort required to enter the username "User2" into the administrator terminal 100.
[0121] (6) When introducing an image processing device to a department of a company, it is conceivable to restrict the execution of specific functions of the image processing device from among its multiple functions depending on the employee's position. According to the first embodiment, the multifunction device 300 is capable of performing scanning and printing functions, and it is possible to allow or restrict the user from performing scanning functions, as well as allowing or restricting the user from performing printing functions.
[0122] (7) The multifunction printer 300 registers the username "User2" in the main registration list 312, and then deletes the record for username "User2" from the temporary registration list 313 (T800). Therefore, the administrator can reduce the effort required to find usernames that have not yet been registered when performing main registration in the future.
[0123] (8) Settings that allow or restrict the execution of functions of the multifunction printer 300 can only be made by the administrator of the multifunction printer 300. Therefore, a user of the multifunction printer 300 may only find out that they are not authorized to execute a function when they try to execute a function of the multifunction printer 300. According to the first embodiment, when a user named "User1", whose username is registered in this registration list 312, tries to execute a function of the multifunction printer 300 (T500~T550), the multifunction printer 300 can request the administrator terminal 100 to allow the user named "User1" to execute a function of the multifunction printer 300 (T555).
[0124] <Second Example> This document describes an information processing system according to a second embodiment that does not perform one-time key authentication. In the second embodiment, components corresponding to the components of the first embodiment are numbered the same as in the first embodiment. The information processing system 1 of the second embodiment comprises an administrator terminal 100, a plurality of user terminals 200A to 200C, and a multifunction printer 300. The configurations of the administrator terminal 100 and the plurality of user terminals 200A to 200C are the same as those in the first embodiment. The multifunction printer 300 of the second embodiment differs from the multifunction printer 300 of the first embodiment in that it does not have a timer 370. The volatile memory 320 of the second embodiment differs from the volatile memory 320 of the first embodiment in that it does not have an area for storing one-time keys.
[0125] <Authentication Decision Processing> Referring to Figure 16, the authentication decision process (S200) in the second embodiment, which does not perform one-time key authentication, will be described. The authentication decision process (S200) is executed by the CPU 330 according to the application program 317. The authentication decision process (S200) is started when one of the following requests is received from the user terminal 200: a status request, a job creation request, or an image request.
[0126] In S203, it is determined whether the header information of the received request is empty or not. Specifically, if the header information does not contain the username and password (S203: YES), a 401 error indicating authentication failure is sent to the user terminal 200 (S235).
[0127] If the header information includes both the username and password (S203:NO), in S205, the username and password are read from the volatile memory 320. In S210, a record with a matching username is searched for in the main registration list 312. In S215, it is determined whether or not a record with a matching username exists.
[0128] If a record exists (S215:YES), steps S220-S235 will execute the same process as steps S125-S140.
[0129] If no record exists (S215: NO), it is determined whether the system has received two requests with mismatched usernames in the header information (S238). Specifically, it is determined whether the username and password in the header information match those of a previous request. If it is determined that two requests with the same information in the header information have been received (S238: YES), the username and password are registered in the temporary registration list 313 (S240). Once registered in the temporary registration list 313, a 401 error is sent to the user terminal 200 (S235). If it is not determined that two requests with the same information in the header information have been received (S238: NO), the username and password are not registered in the temporary registration list 313, and a 401 error is sent to the user terminal 200 (S235). Once either S230 or S235 is executed, the CPU 330 terminates the authentication determination process (S200).
[0130] <Specific Cases> A specific case in the second embodiment will be described. In the second embodiment, when a registered user performs the scan function, in T218, T245, T270, and T290 of case CA1 in the first embodiment, an authentication decision process that does not perform one-time key authentication (S200) is executed instead of an authentication decision process that performs one-time key authentication (S100). In the second embodiment, when a registered user enters the wrong password, in T418 and T445 of case CA2 in the first embodiment, an authentication decision process that does not perform one-time key authentication (S200) is executed instead of an authentication decision process that performs one-time key authentication (S100). In the second embodiment, when a registered user requests the addition of print privileges, in T518 and T545 of case CA3 in the first embodiment, an authentication decision process that does not perform one-time key authentication (S200) is executed instead of an authentication decision process that performs one-time key authentication (S100).
[0131] <Case CB: An unregistered user attempts to register without one-time key authentication> Referring to Figure 17, the procedure for a user who owns the user terminal 200 to provisionally register the username "User2" in the second embodiment will be explained. The username "User2" is not stored in the main registration list 312, and the main registration list 312 is in the state shown in Figure 2(a).
[0132] In T1000~T1025, the same processing as in T200~T225 of case CA1 is performed. In T1030, user terminal 200 receives the username "User2" and password "Pw2" from the user who owns user terminal 200. User terminal 200 temporarily stores the username "User2" and password "Pw2" in volatile memory 220 (T1035). User terminal 200 sends a status request containing the username "User2" and password "Pw2" in the header information to the multifunction printer 300 (T1040).
[0133] The multifunction printer 300 receives a status request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S200) (T1045). At the time of execution of T1045, only one status request containing the username "User2" and password "Pw2" in the header information has been received. Therefore, the multifunction printer 300 sends a 401 error to the user terminal 200 (T1050).
[0134] The user terminal 200 receives a 401 error from the multifunction printer 300 and displays the authentication screen on the display 150 again (T1055). The user terminal 200 again accepts the username "User2" and password "Pw2" from the user who owns the user terminal 200 (T1060). The user terminal 200 temporarily stores the username "User2" and password "Pw2" in the volatile memory 220 (T1065). The user terminal 200 sends a status request to the multifunction printer 300, which includes the username "User2" and password "Pw2" in its header information (T1070).
[0135] The multifunction printer 300 receives a status request from the user terminal 200. The multifunction printer 300 performs authentication determination processing (S200) (T1075). Since the main registration list 312 does not contain a record containing the username "User2", the determination processing in S238 is executed. In S238, it is determined that two requests with the same content in the header information have been received (S238: YES). Therefore, the multifunction printer 300 registers the username "User2" and password "Pw2" in the temporary registration list 313 (S240). The multifunction printer 300 performs processing to send a 401 error to the user terminal 200 (S245) (T1080). The multifunction printer 300 sends an email to the administrator terminal 100 containing the username "User2" and password "Pw2" registered in the temporary registration list 313 (T1085).
[0136] The administrator terminal 100 receives an email from the multifunction printer 300. This allows the administrator to recognize the username and password of the user who needs to be registered on the administrator terminal 100. The procedure for registering the username and password registered in the temporary registration list 313 to the final registration list 312 is the same as in T760~T800 of case CA4. This allows the administrator to register the username "User2" and password "Pw2" contained in the email to the final registration list 312.
[0137] <Effects of Case CB> According to Case CB, users whose usernames are not stored in the main registration list 312 will fail authentication when attempting to use the multifunction printer 300, but their username and password will be registered in the temporary registration list 313. On the batch registration screen 700, which displays the contents of the temporary registration list 313, the administrator can set restrictions on the functions that the multifunction printer 300 can perform by operating the scan permission checkbox and the print permission checkbox, without having to manually enter the username.
[0138] <Effects of the second example> (1) According to the second embodiment, the username "User2" transmitted from the user terminal 200 is registered in the temporary registration list 313 (S240). When the multifunction printer 300 receives a request from the administrator terminal 100 to add permission to allow the user "User2" to perform the scanning or printing function of the multifunction printer 300, it registers the username "User2" registered in the temporary registration list 313 to the main registration list 312, thereby configuring the multifunction printer 300 to allow the user "User2" to perform the scanning or printing function. Therefore, the administrator can reduce the effort required to input the username "User2" into the administrator terminal 100 when configuring the multifunction printer 300 to allow the user "User2" to perform the scanning or printing function. Furthermore, the multifunction printer 300 sends a notification to the administrator terminal 100 in response to the registration of the username "User2" transmitted from the user terminal 200 in the temporary registration list 313 (T1085). Therefore, the administrator can recognize that the user with the username "User2" has requested permission to use the scanning or printing functions of the multifunction printer 300.
[0139] (2) According to the second embodiment, if the multifunction printer 300 receives two requests from the user terminal 200 with the same content in the header information (S238:YES), it registers the username and password in the temporary registration list 313 (S240). Therefore, if it is determined that the first request received had a mismatched username in the header information (S238:NO), this request is likely to have an incorrect username, thus reducing the registration of usernames from requests that are likely to have incorrect usernames in the temporary registration list 313.
[0140] <Variation> (1) The main registration list 312 and the temporary registration list 313 may be configured as a single list. Specifically, the main registration list 313 stores the username, password, user ID, scanner permission, print permission, and registered flag in association with each other. The registered flag is either "OFF" (main registration is not complete) or "ON" (main registration is complete). In this case, S155 registers the registered flag as "OFF", and T790 changes the registered flag to "ON". In this modified example, a single list functions as both the main registration list and the temporary registration list, depending on the status of the registered flag.
[0141] (2) The functions provided by the multifunction printer 300 may be either a scanning function or a printing function, or they may have other functions such as a copying function in addition to these functions.
[0142] (3) The contents of the provisional registration list 313 may remain and not be deleted.
[0143] (4) If the processes of T750 and T755 are performed in connection with registration to the provisional registration list 313, they may be performed before S155. Similarly, T1085 may be performed before S240.
[0144] (5) The one-time key generated in T165 does not need to have an expiration date.
[0145] (6) Instead of T690, a one-time key may be verbally notified and shared with the user by the administrator.
[0146] (7) In the T780, the operation of the scan permission checkbox and the print permission checkbox may be performed by touch operation on the touch panel or by clicking operation.
[0147] (8) Instead of the processes of T750 and T1085, the user may verbally notify the administrator. That is, the user name to be provisionally registered may be notified verbally.
[0148] <Correspondence> User terminals 200A to 200C are examples of "multiple user terminals". Administrator terminal 100 is an example of an "administrator terminal". Multifunction device 300 is an example of an "image processing device". Information processing system 1 is an example of an "information processing system". User name is an example of "user identification information". Scanning function and printing function are examples of "functions of the image processing device". In particular, the scanning function is an example of a "first function", and the printing function is an example of a "second function". The string "UNLOCK" is an example of "permission information". The string "LOCK" is an example of "denial information". This registration list 312 is an example of a "first storage unit". The user with username "User2" is an example of a "first user". User name "User2" is an example of "first user identification information". T740, T1040, and T1070 are examples of processes executed by the "first receiving unit", "first receiving step", and "first receiving process". The provisional registration list 313 is an example of the "second storage unit". S155 and S240 are examples of processes executed by the "provisional registration unit", "provisional registration step", and "provisional registration processing". T750, T755, and T1085 are examples of processes executed by the "provisional registration notification unit" and "provisional registration notification step". The authorization addition request is an example of an "authorization notification". T790 is an example of a process executed by the "authorization notification unit" and "authorization notification step". The receiving process of the multifunction device 300 in T590 and T790 is an example of a process executed by the "authorization notification receiving unit" and "authorization notification receiving processing". T795 is an example of a process executed by the "final registration unit", "final registration step", and "final registration processing". T160 and T165 are examples of processes executed by the "authentication key generation unit", and the one-time key "ADLKH" generated in T160 is an example of an "authentication key" and a "one-time key". T690 is an example of a process executed by the "authentication key transmission unit". "60 minutes" is an example of a "specified time." The batch registration screen data is an example of "screen data," and batch registration screen 700 is an example of a "registration screen." T770 is an example of a process executed by the "screen data transmission unit." T775 is an example of a process executed by the "display unit."The operations on the scan permission checkbox and the print permission checkbox are examples of "prescribed operations for sending permission notifications." The string "Printer" included in the permission addition request is an example of "function identification information." T800 is an example of processing performed by the "deletion unit." The user with username "User1" is an example of a "second user," and username "User1" is an example of "second user identification information." T540 is an example of processing performed by the "second receiving unit." T555 is an example of the "permission addition request notification unit." T590 is an example of the "permission addition request notification unit." T595 is an example of the "registration change unit." [Explanation of Symbols]
[0149] 1 Information processing system, 100 administrator terminals, 200A user terminals, 200B user terminals, 200C user terminals, 300 multifunction printers, NT network
Claims
1. An information processing system in which multiple user terminals, an administrator terminal, and an image processing device are connected in a communicative manner, The aforementioned image processing device is A first storage unit that stores user identification information to identify a user, and stores either permission information that permits the user to execute the functions of the image processing device, or denial information that does not permit the user to execute the functions of the image processing device, in association with the stored user identification information. A first receiving unit receives the first user identification information, which is the user identification information that identifies the first user, from the user terminal of the first user. A second storage unit that stores the first user identification information received by the first receiving unit, If, at the time the first receiving unit receives the first user identification information, no user identification information identifying the same user as the first user identification information is stored in the first storage unit, the first user identification information is registered in the second storage unit by a provisional registration unit. A temporary registration notification unit notifies the administrator terminal when the first user identification information is registered in the second storage unit by the temporary registration unit, Equipped with, The aforementioned administrator terminal is The system includes a permission notification unit that, after receiving a notification from the provisional registration notification unit, transmits a permission notification to the image processing unit granting the first user permission to perform the functions of the image processing unit, The aforementioned image processing device is When the permission notification is transmitted by the permission notification unit, the main registration unit registers the first user identification information registered in the second storage unit by the provisional registration unit and the permission information in association with each other in the first storage unit. An information processing system equipped with the following features.
2. The information processing system according to claim 1, The aforementioned image processing device further, It includes an authentication key generation unit that generates an authentication key and transmits it to the administrator terminal, The aforementioned administrator terminal further, The system includes an authentication key transmission unit that transmits the authentication key transmitted by the authentication key generation unit as the first authentication key to the user terminal of the first user, The first receiving unit receives the first authentication key along with the first user identification information. The aforementioned provisional registration section is, When the first receiving unit receives the first user identification information and the first authentication key, if the first user identification information identifying the same user as the first user identification information is not stored in the first storage unit, and the first authentication key matches the authentication key generated by the authentication key generation unit, the first user identification information is registered in the second storage unit. Information processing system.
3. The information processing system according to claim 2, The aforementioned authentication key is a one-time key that is valid only for a predetermined period of time. The provisional registration unit registers the first user identification information in the second storage unit if, at the time the first receiving unit receives the first user identification information and the first authentication key, the predetermined time has not elapsed since the one-time key was generated by the authentication key generation unit. Information processing system.
4. The information processing system according to claim 3, The provisional registration notification unit includes a process for notifying the administrator terminal that a predetermined time has elapsed since the one-time key was generated by the authentication key generation unit. Information processing system.
5. An information processing system according to any one of claims 1 to 4, The image processing device further, The system includes a screen data transmission unit that transmits screen data containing the first user identification information stored in the second storage unit to the administrator terminal. The aforementioned administrator terminal further, The system includes a display unit that displays the registration screen shown by the screen data received from the image processing device, The permission notification unit, upon receiving a predetermined operation for transmitting the permission notification on the registration screen displayed by the display unit, transmits the permission notification to the image processing device. Information processing system.
6. An information processing system according to any one of claims 1 to 4, The image processing device is capable of performing a first function and a second function, The first storage unit stores either the permission information that permits the user to perform the first function, or the disallowance information that does not permit the user to perform the first function, in association with the user identification information. The first storage unit stores either the permission information that permits the user to perform the second function, or the disallowance information that does not permit the user to perform the second function, in association with the user identification information. The permission notification includes function identification information that identifies the function among the first function and the second function that the first user is permitted to execute. The main registration unit registers in the first storage unit, in association with the first user identification information registered in the second storage unit by the provisional registration unit, and the permission information, for the function identified by the function identification information among the first function and the second function. Information processing system.
7. An information processing system according to any one of claims 1 to 4, The aforementioned image processing device further, The registration unit registers the first user identification information and the permission information in association with each other in the first storage unit, and then includes a deletion unit that deletes the first user identification information from the second storage unit. Information processing system.
8. An information processing system according to any one of claims 1 to 4, The aforementioned image processing device further, A second receiving unit receives the second user identification information, which is the user identification information used to identify the second user, from the user terminal of the second user. The system includes a permission addition request notification unit that, when the second receiving unit receives the second user identification information, and the disallowed information is stored in the first storage unit in association with the user identification information that identifies the same user as the second user identification information, sends a permission addition request notification to the administrator terminal requesting the administrator to change the disallowed information to the permitted information. The aforementioned administrator terminal further, The system includes a permission addition notification unit that sends a permission addition notification to the image processing device granting the second user permission to perform the functions of the image processing device, The aforementioned image processing device further, When the authorization addition notification unit transmits the authorization addition notification, the registration change unit changes the denied information stored in the first storage unit to the authorized information, in association with the user identification information that identifies the same user as the second user identification information. Information processing system.
9. An information processing system in which multiple user terminals, an administrator terminal, and an image processing device are connected in a communicative manner, wherein the image processing device comprises a first storage unit and a second storage unit that store user identification information for identifying a user, and which store either permission information that permits a user to perform the functions of the image processing device, or disallowance information that does not permit a user to perform the functions of the image processing device, in association with the stored user identification information, and an information processing method executed in the information processing system, A first receiving step of receiving the first user identification information, which is the user identification information that identifies the first user, from the user terminal of the first user, If, at the time the first user identification information is received in the first receiving step, no user identification information identifying the same user as the first user identification information is stored in the first storage unit, a provisional registration step is performed to register the first user identification information in the second storage unit. In response to the registration of the first user identification information in the second storage unit through the provisional registration step, a provisional registration notification step is performed to notify the administrator or administrator terminal. After notification is given in the provisional registration notification step, a permission notification step is performed to send a permission notification to the image processing device that permits the first user to perform the functions of the image processing device, If the permission notification is transmitted in the permission notification step, the main registration step involves registering the first user identification information registered in the second storage unit in the provisional registration step and the permission information in association with each other in the first storage unit. An information processing method comprising:
10. An image processing device in which multiple user terminals and an administrator terminal are connected in a manner that enables communication between them, A first storage unit that stores user identification information to identify a user, and stores either permission information that permits the user to execute the functions of the image processing device, or denial information that does not permit the user to execute the functions of the image processing device, in association with the stored user identification information. A first receiving unit receives the first user identification information, which is the user identification information that identifies the first user, from the user terminal of the first user. A second storage unit that stores the first user identification information received by the first receiving unit, If, at the time the first receiving unit receives the first user identification information, no user identification information identifying the same user as the first user identification information is stored in the first storage unit, the first user identification information is registered in the second storage unit by a provisional registration unit. In response to the registration of the first user identification information in the second storage unit by the provisional registration unit, the permission notification receiving unit receives a permission notification from the administrator terminal that authorizes the first user to execute the functions of the image processing device, When the permission notification is received by the permission notification receiving unit, the main registration unit registers the first user identification information registered in the second storage unit by the temporary registration unit and the permission information in association with each other in the first storage unit. An image processing device equipped with the following features.
11. A program executed by a control unit of an image processing device, wherein multiple user terminals and an administrator terminal are connected in a communicative manner, the control unit of the image processing device comprises: a first storage unit that stores user identification information for identifying a user, and a second storage unit that stores either permission information that permits a user to execute the functions of the image processing device, or disallowance information that does not permit a user to execute the functions of the image processing device, associated with the stored user identification information, The control unit, A first receiving process that receives the first user identification information, which is the user identification information that identifies the first user, from the user terminal of the first user, If, at the time the first user identification information is received by the first receiving process, no user identification information identifying the same user as the first user identification information is stored in the first storage unit, a provisional registration process is performed to register the first user identification information in the second storage unit. In response to the registration of the first user identification information in the second storage unit through the provisional registration process, a permission notification reception process is performed to receive a permission notification from the administrator terminal that authorizes the first user to execute the functions of the image processing device. When the permission notification is received by the permission notification receiving process, the main registration process registers the first user identification information registered in the second storage unit by the provisional registration process and the permission information in association with each other in the first storage unit. A program that executes something.
Citation Information
Patent Citations
Image formation apparatus
JP2018058300A