Execution Server
The execution server addresses the incomplete deletion of customer data by scheduling the removal of applications, firmware, and personal information from image forming apparatuses and servers upon contract termination, ensuring secure data cleanup.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2024-10-08
- Publication Date
- 2026-04-20
AI Technical Summary
Existing systems fail to completely delete customer personal information from servers and applications after the termination of service contracts for image forming apparatuses, leaving a risk of misuse.
An execution server that includes mechanisms to acquire expired service usage contract information, instruct image forming apparatuses to delete applications and firmware components, and delete predetermined information from service servers, while scheduling deletion instructions to avoid overloading the system.
Ensures complete deletion of applications, firmware components, and personal information from image forming apparatuses and servers, reducing the risk of unauthorized use of customer data.
Smart Images

Figure 2026067203000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an execution server, an information processing system, a processing method of the execution server, and a program.
Background Art
[0002] Currently, contract services that enable more convenient use of multifunctional devices are provided. For example, many contract services that integrate multifunctional devices and cloud technologies, such as backup services for managing the setting information of multifunctional devices online, have been deployed.
[0003] To use such contract services, it is necessary to register customers' personal information online. In addition, customers may also be required to input their personal information into the applications used when the multifunctional device communicates with cloud-side services.
[0004] However, even after the service usage contract ends and the customer is not using the service, it is possible that the customer's personal information is left undeleted in the applications installed on the cloud or the multifunctional device.
[0005] There are means to delete applications from the multifunctional device according to the status of the service usage contract.
[0006] Patent Document 1 discloses identifying applications to be installed, deleted, or updated on a device used by a user according to the user's service usage status, and instructing the device to install, delete, or update the applications.
[0007] In addition, it is generally practiced to delete a user's personal information when the user withdraws from the service, which has merits in terms of protecting the user's personal information.
Prior Art Documents
Patent Documents
[0008] [Patent Document 1] Japanese Patent Publication No. 2022-165208 [Overview of the project] [Problems that the invention aims to solve]
[0009] Even after the termination of the service contract for the image forming apparatus, if personal information registered on the server used by the image forming apparatus remains on the server, it could lead to the misuse of customers' personal information. This is also true if the applications installed on the image forming apparatus, or the firmware components necessary to run those applications, remain on the server even after the termination of the service contract.
[0010] However, in Patent Document 1, while the application installed on the image forming apparatus is deleted upon termination of the usage contract for the image forming apparatus, the personal information of service users is not deleted from the services on the server associated with the image forming apparatus. Therefore, the risk of customers' personal information being misused cannot be completely eliminated.
[0011] The purpose of this disclosure is to enable the deletion of applications or firmware components operating in an image forming apparatus, as well as predetermined information on a service server. [Means for solving the problem]
[0012] The execution server includes a first acquisition means for acquiring service usage contract information whose contract period has expired, a first transmission means for sending instructions to one or more image forming apparatuses to delete applications or firmware components operating on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, and a second transmission means for sending instructions to one or more service servers to delete predetermined information on one or more service servers corresponding to the service usage contract information whose contract period has expired. [Effects of the Invention]
[0013] According to the present disclosure, in addition to applications or firmware components operating in an image forming apparatus, predetermined information on a service server can also be deleted.
Brief Description of the Drawings
[0014] [Figure 1] It is a diagram showing a configuration example of an information processing system. [Figure 2] It is a diagram showing a hardware configuration example of a contract management server, a contract-linked processing execution server, and a service server. [Figure 3] It is a diagram showing a hardware configuration example of an image forming apparatus. [Figure 4] It is a block diagram showing a functional configuration example of a contract management server. [Figure 5] It is a block diagram showing a functional configuration example of a contract-linked processing execution server. [Figure 6] It is a block diagram showing a functional configuration example of an image forming apparatus. [Figure 7] It is a block diagram showing a functional configuration example of a service server. [Figure 8] It is a sequence diagram of an information processing system. [Figure 9] It is a flowchart of creating a deletion instruction in a contract-linked processing execution server. [Figure 10] It is a flowchart of creating client deletion instruction information in a contract-linked processing execution server. [Figure 11] It is a flowchart of creating server data deletion instruction information in a contract-linked processing execution server. [Figure 12] It is a flowchart of creating an execution time of a deletion instruction in a contract-linked processing execution server. [Figure 13] It is a sequence diagram of an information processing system. [Figure 14] It is a diagram showing an example of display of an icon of an application in an image forming apparatus. [Figure 15]It is a flowchart of notifications to service users. [Figure 16] It is a diagram showing an example of an email sent to service users. [Figure 17] It is a sequence diagram at the time of data deletion. [Figure 18] It is a sequence diagram of restoring set values. [Figure 19] It is a diagram showing various information. [Figure 20] It is a diagram showing various information. [Figure 21] It is a diagram showing various information. <When the contract-linked processing execution server 102 detects the termination of the service usage contract for the image forming apparatus 103, it issues an instruction to the image forming apparatus 103 to delete the application and firmware components installed on it. Similarly, the contract-linked processing execution server 102 issues an instruction to the service server 104 to delete specified information, such as the user's personal information. Furthermore, when issuing deletion instructions to the image forming apparatus 103 or the service server 104, the contract-linked processing execution server 102 schedules the deletion instructions to prevent a concentration of deletion processes at any given time.
[0018] When the image forming apparatus 103 receives a deletion instruction from the contract-linked processing execution server 102, it deletes the application specified in the deletion instruction and the firmware components necessary to run the application.
[0019] When the service server 104 receives a deletion instruction from the contract-linked processing execution server 102, it deletes the information specified in the deletion instruction.
[0020] The contract management server 101, the contract-linked processing execution server 102, the image forming apparatus 103, and the service server 104 are each connected via the network 105.
[0021] [Server hardware configuration] Figure 2 shows an example of the hardware configuration for the contract management server 101, the contract-linked processing execution server 102, and the service server 104.
[0022] Random Access Memory (RAM) 201 is a temporary memory area.
[0023] Storage 202 records predetermined information, such as embedded programs and customer personal information.
[0024] The network interface 203 communicates with other computers, network devices, and the image forming apparatus 103, and supports both wired and wireless communication methods.
[0025] The input / output interface 205 receives signals and information from devices such as displays, keyboards, mice, and touch panels. It can also accept connections and operations from other computers via remote desktop or remote shell.
[0026] Secondary storage devices 206 include hard disk drives (HDDs) and flash memory.
[0027] CPU200 executes programs read from RAM201, storage202, and secondary storage206.
[0028] The above components are connected by a system bus 204, and control commands from the CPU 200 are propagated to each piece of hardware.
[0029] [Hardware configuration of image forming apparatus] Figure 3 shows an example of the hardware configuration of the image forming apparatus 103.
[0030] RAM301 is a temporary memory area.
[0031] Storage 302 stores embedded programs, applications developed for the image forming apparatus 103, and firmware components necessary to run those applications.
[0032] The network interface 303 communicates with other computers and network devices and supports both wired and wireless communication methods.
[0033] The input / output interface 305 performs input and output of information and signals via hard keys, touch panels, etc.
[0034] Secondary storage devices 306 include hard disk drives (HDDs) and flash memory.
[0035] The CPU 300 executes programs read from RAM 301, storage 302, secondary storage device 306, etc.
[0036] Printer 308 performs jobs such as printing.
[0037] The device controller 307 controls the printer 308 based on control commands received from the CPU 300.
[0038] The various components are connected to each other by the system bus 304, which propagates control commands from the CPU 300 to other hardware.
[0039] [Functional Configuration of the Contract Management Server] Figure 4 is a block diagram showing an example of the functional configuration of the contract management server 101. The contract management server 101 includes an external communication unit 400, an input reception unit 401, and a contract management unit 402.
[0040] The program for the contract management server 101 is read from RAM 201, storage 202, and secondary storage device 206, and executed by the CPU 200. This realizes each of the functional components shown in Figure 4.
[0041] External access to the contract-linked processing execution server 102 and other external systems is performed via the network interface 203. The contract management server 101 receives service usage contract information for the image forming apparatus 103 registered by users such as service technicians and customers via the external communication unit 400 and records it in the storage 202. Service usage contract information can be registered using the Application Programming Interface (API), message sending, or remote desktop. The received service usage contract information is checked by the input reception unit 401 to determine if the input content is correct and then stored in the contract management unit 402.
[0042] Figure 19(a) shows an example of service usage contract information.
[0043] The "Contract ID" column stores a unique ID issued for each service usage contract.
[0044] The "Customer ID" column is a column that stores a unique ID that identifies the service user.
[0045] The "Customer Contact Information" column stores the contact information (email address, etc.) of the service user.
[0046] The "Device Serial Number" column stores the serial number of the image forming apparatus 103 to which the service agreement applies.
[0047] The "Device Location" column is a column that stores the location of the image forming apparatus 103 described in the "Device Serial Number" column.
[0048] The "Contracted Service" column stores the name of the service stipulated in the service usage agreement. If a unique ID that identifies the service name exists, that ID may be applied as a parameter to the "Contracted Service" column.
[0049] The "Contract Start Date" column stores the start date of the service usage contract.
[0050] The "Contract End Date" column stores the end date of the service usage contract, and service usage contract information whose value is a contract end date that has passed the current time is subject to processing in this embodiment.
[0051] [Functional Configuration of the Contract-Linked Processing Execution Server] Figure 5 is a block diagram showing an example of the functional configuration of the contract-linked processing execution server 102. The contract-linked processing execution server 102 includes an external communication unit 500, a contract period detection unit 501, a deletion instruction creation unit 502, a service termination information management unit 503, a deletion schedule creation unit 504, a deletion instruction management unit 505, and a setting value transmission unit 506.
[0052] The program for the contract-linked processing execution server is read from RAM 201, storage 202, and secondary storage device 206, and executed by the CPU 200. This realizes each functional component shown in Figure 5.
[0053] Furthermore, the contract-linked processing execution server 102 communicates with the contract management server 101, the image forming apparatus 103, and the service server 104 via the network interface 203.
[0054] The contract period detection unit 501 obtains the service usage contract information shown in Figure 19(a) from the contract management server 101 via the external communication unit 500 and detects service usage contract information whose contract period has expired.
[0055] The deletion instruction creation unit 502 is executed when, as a result of processing by the contract period detection unit 501, service usage contract information whose contract period has ended is detected. First, the deletion instruction creation unit 502 receives the service usage contract information shown in Figure 19(a) whose contract period has ended from the contract period detection unit 501. Then, for each service listed in the service usage contract information, the deletion instruction creation unit 502 queries the service termination information management unit 503 for information that should be deleted at the time of termination. For example, key-value pairs to identify data to be deleted from the service server, or application uninstaller file names, etc., are the targets of the query to the service termination information management unit 503.
[0056] The service termination information management unit 503 comprises a service setting value management unit 503-1, an application management unit 503-2, and a firmware component management unit 503-3.
[0057] The service setting management unit 503-1 is contained within the service termination information management unit 503. The service setting management unit 503-1 has the function of managing information that needs to be deleted when the service usage contract is terminated, from the information recorded on the server on which the service described in the service usage contract information is running (hereinafter referred to as server deletion information).
[0058] Figure 19(b) shows an example of server deletion information.
[0059] The "Service ID" column is a column that stores a unique ID that identifies the service associated with the image forming apparatus 103.
[0060] The "Service Name" column stores the name of the service related to the image forming apparatus.
[0061] The "ApiURL" column stores the URL of an API that can delete specified data from the database of the service listed in the "Service Name" column.
[0062] The "Key-Value to Delete" column stores the column and value combinations of data to be deleted from the service's database.
[0063] The Application Management Unit 503-2 is contained within the Service Termination Information Management Unit 503. The Application Management Unit 503-2 has the function of managing the deletion information (application deletion information) of applications installed in the image forming apparatus 103 that need to be deleted when the service usage contract is terminated.
[0064] Figure 19(c) shows an example of application deletion information.
[0065] The "Service ID" and "Service Name" columns are equivalent to the columns shown in the server deletion information in Figure 19(b), so we will omit their explanation.
[0066] The "To be deleted" column is a column that stores information to identify the application to be deleted.
[0067] The firmware component management unit 503-3 is contained within the service termination information management unit 503. The firmware component management unit 503-3 has the function of managing deletion information (firmware component deletion information) for firmware components necessary for the operation of the application that need to be deleted when the service usage contract is terminated.
[0068] Figure 19(d) shows an example of firmware component deletion information.
[0069] The "Service ID" and "Service Name" columns are equivalent to the columns shown in the server deletion information in Figure 19(b), so we will omit their explanation.
[0070] The "Delete Target" column stores the filenames of the firmware components to be deleted.
[0071] The deletion instruction creation unit 502 receives server deletion information shown in Figure 19(b), application deletion information shown in Figure 19(c), and firmware component deletion information shown in Figure 19(d) as responses to inquiries made to the service termination information management unit 503. Subsequently, the deletion instruction creation unit 502 queries the deletion schedule creation unit 504 to obtain the transmission time of the deletion instruction in order to create a deletion instruction that corresponds one-to-one with the various deletion information.
[0072] The deletion schedule creation unit 504 issues corrected deletion instruction transmission time information to the deletion instruction creation unit 502 and returns it to the deletion instruction creation unit 502, so as not to place an excessive load on the contract-linked processing execution server 102 due to a concentration of deletion instruction transmissions during a specific time period. In order to determine the transmission time of the deletion instruction, the deletion schedule creation unit 504 queries the deletion instruction management unit 505.
[0073] Figure 19(e) shows an example of deletion instruction transmission time information.
[0074] The "Deletion Instruction Sent Time" column stores the time the deletion instruction was sent.
[0075] The deletion instruction creation unit 502 obtains the transmission time information of the deletion instruction from the deletion schedule creation unit 504, and then creates client deletion instruction information to delete the application and firmware components from the image forming apparatus 103. The deletion instruction creation unit 502 also creates server data deletion instruction information to delete predetermined information from the service server 104. The created client deletion instruction information and server data deletion instruction information are transmitted to the deletion instruction management unit 505.
[0076] Figure 20(a) shows an example of client deletion instruction information.
[0077] The "Service ID" column is equivalent to the column shown in the server deletion information in Figure 19(b), so its explanation is omitted.
[0078] The "Contract ID" and "Customer Contact Information" columns are equivalent to the columns shown in the service usage contract information in Figure 19(a), so we will omit their explanation.
[0079] The "Device Serial Number" column stores the serial number of the image forming apparatus 103, which is obtained from the service usage contract information in Figure 19(a).
[0080] The "Deletion Instruction Transmission Time" column stores the time information obtained from the deletion instruction transmission time information shown in Figure 19(e) when the client deletion instruction information is transmitted to the image forming apparatus 103.
[0081] The "Delete Application" column is a column that stores a value to identify the application to be deleted.
[0082] The "Firmware to Delete" column stores the filenames of the firmware components necessary for deleting the firmware components required to run the application being deleted.
[0083] Figure 20(b) shows an example of server data deletion instruction information.
[0084] The "Service ID" and "Contract ID" columns are equivalent to the columns shown in the server deletion information in Figure 19(b), so we will omit their explanation.
[0085] The "Deletion Target" column is a column for storing a key-value combination as a value to identify data that needs to be deleted from the service server 104. For example, in the case of the server deletion information shown in Figure 19(b), the deletion instruction creation unit 502 obtains the value "userId":"${customer ID}"" from the "Deletion Target Key-Value" column of the deletion server information. Then, the deletion instruction creation unit 502 obtains the value "CST00001" set in the "customer ID" column from the service usage contract information shown in Figure 19(a). Finally, the deletion instruction creation unit 502 replaces the "${customer ID}" part of the value "userId":"${customer ID}"" obtained from the deletion server information with the value "CST00001" obtained from the service usage contract information. As a result of the replacement, the value "userId":"CST00001" is obtained and stored as the value of the "Deletion Target" column.
[0086] The "Deletion API" column stores the value of the "ApiURL" column obtained from the server deletion information shown in Figure 19(b).
[0087] The "Deletion Instruction Transmission Time" column stores the time information obtained from the deletion instruction transmission time information shown in Figure 19(e) when the server data deletion instruction information is sent to the service server 104.
[0088] The deletion instruction management unit 505 records the client deletion instruction information shown in Figure 20(a) and the server data deletion instruction information shown in Figure 20(b) received from the deletion instruction creation unit 502.
[0089] Furthermore, the deletion instruction management unit 505 is periodically executed by a timer to determine whether it holds client deletion instruction information or server data deletion instruction information that matches the current time. If the deletion instruction management unit 505 determines that it holds the aforementioned information, it sends the client deletion instruction information to the image forming apparatus 103 and the server data deletion information to the service server 104.
[0090] Assuming the current time is "January 1, 2024, 0:10:00 AM" and the deletion instruction management unit 505 holds the client deletion instruction information in Figure 20(c) and the server data deletion instruction information in Figure 20(d), an example of a deletion instruction to be sent is shown below.
[0091] Since the time stored in the "Deletion Instruction Transmission Time" column of the client deletion instruction information in Figure 20(c) matches the current time, the client deletion instruction information in Figure 20(c) is transmitted to the image forming apparatus 103. On the other hand, since the time stored in the "Deletion Instruction Transmission Time" column of the server data deletion instruction information in Figure 20(d) does not match the current time, the server data deletion instruction information in Figure 20(d) is not transmitted to the service server 104 and remains in the deletion instruction management unit 505.
[0092] The setting value transmission unit 506 is used in the fourth embodiment and is a function that acquires setting values from the secondary storage device 206 of the contract-linked processing execution server 102 and transmits them to the image forming apparatus 103 and the service server 104. Details will be explained in the section on the fourth embodiment.
[0093] [Functional configuration of an image forming apparatus] Figure 6 is a block diagram showing an example of the functional configuration of the image forming apparatus 103. The image forming apparatus 103 includes an external communication unit 600, an application deletion unit 601, a firmware component deletion unit 602, a scanning unit 603, a printing unit 604, a copying unit 605, and a box unit 606.
[0094] The image forming apparatus 103 operates when the program necessary for its operation is stored in RAM 201, storage 202, and secondary storage device 206, and executed by the CPU 200. This realizes each functional component shown in Figure 6. Communication with the contract-linked processing execution server 102 and the service server 104 is performed via the network interface 303.
[0095] The image forming apparatus 103 receives the client deletion instruction information shown in Figure 20(a) from the contract-linked processing execution server 102 via the external communication unit 600 and transmits it to the application deletion unit 601 and the firmware component deletion unit 602.
[0096] The application deletion unit 601 can delete the application specified in the client deletion instruction information from the image forming apparatus 103 using the client deletion instruction information.
[0097] The firmware component deletion unit 602 can delete the firmware components described in the client deletion instruction information from the image forming apparatus 103 using the client deletion instruction information.
[0098] Furthermore, the image forming apparatus 103 can utilize various functions of the image forming apparatus 103 using the scanning unit 603, printing unit 604, copying unit 605, and box unit 606. These functions can be used by sending jobs via the UI provided in the image forming apparatus 103 or via the external communication unit 600.
[0099] [Functional Configuration of Server Services] Figure 7 is a block diagram showing an example of the functional configuration of the service server 104. The service server 104 includes an external communication unit 700, a service provision unit 701, and an information management unit 702.
[0100] The external communication unit 700 serves as a network interface for the service provision unit 701 and the information management unit 702 to communicate with the contract-linked processing execution server 102, the image forming apparatus 103, and the like.
[0101] The service provision unit 701 provides services related to the image forming apparatus 103 by recording programs in the RAM 201, storage 202, and secondary storage device 206, and executing the programs using the CPU 200.
[0102] The Information Management Unit 702 manages customer information necessary for the Service Provision Unit 701 to provide services related to the image forming apparatus 103. Furthermore, when a service usage contract is terminated, the Information Management Unit 702 receives the server data deletion instruction information shown in Figure 20(a) from the contract-linked processing execution server 102 and deletes data that matches the value stored in the "Deletion Target" column of the server data deletion instruction information.
[0103] Figure 21(a) shows an example of customer information managed by the Information Management Department 702.
[0104] The "userId" column is a column that stores a unique ID to identify the customer.
[0105] The "userName," "address," "phoneNumber," and "email" columns are columns that store customer personal information such as customer name, customer address, phone number, and email address, respectively.
[0106] For example, if the Information Management Unit 702 receives the server data deletion instruction information shown in Figure 20(b), the record with the value "CST00001" in the "userId" column will be deleted.
[0107] [Overall sequence of contract-linked processing] Figure 8 shows the overall sequence in the first embodiment. The processing method of the information processing system 100 will be described below.
[0108] In step S800, the contract period detection unit 501 of the contract-linked processing execution server 102, which is periodically activated by a timer, requests the contract management server 101 via the external communication unit 500 to send the service usage contract information shown in Figure 19(a) whose contract period has ended. Specifically, the contract period detection unit 501 requests the transmission of all service usage contract information where the value of the "Contract End Date" column of the service usage contract information is set to a date earlier than the current date and time.
[0109] In step S801, the contract management server 101 transmits the service usage contract information shown in Figure 19(a) to the contract linkage processing execution server 102 via the external communication unit 400.
[0110] The contract period detection unit 501 of the contract linkage processing execution server 102 obtains (receives) service usage contract information whose contract period has expired from the contract management server 101.
[0111] The following steps are executed if the contract period detection unit 501 finds that there is any service usage contract information whose contract period has expired among the service usage contract information shown in Figure 19(a) acquired in S801.
[0112] In step S802, the deletion instruction creation unit 502 of the contract linkage processing execution server 102 creates the client deletion instruction information shown in Figure 20(a) for each service listed in the contract service column of the service usage contract information shown in Figure 19(a) obtained in S801.
[0113] In step S803, the deletion instruction creation unit 502 of the contract linkage processing execution server 102 creates server data deletion instruction information as shown in Figure 20(b) for each service listed in the contract service column of the service usage contract information shown in Figure 19(a) obtained in S801.
[0114] In step S804, the deletion instruction creation unit 502 of the contract-linked processing execution server 102 transmits the client deletion instruction information described in Figure 20(a) created in S802 and the server data deletion instruction information described in Figure 20(b) created in S803 to the deletion instruction management unit 505. As a result, the client deletion instruction information described in Figure 20(a) is transmitted to the image forming apparatus 103, and the server data deletion instruction information described in Figure 20(b) is transmitted to the service server 104, both via the external communication unit 500.
[0115] Steps S802, S803, and S804 are processed in a loop for each service included in all the service usage contract information shown in Figure 19(a) obtained in S801.
[0116] In step S805, if the deletion instruction management unit 505 holds client deletion instruction information shown in Figure 20(a) that matches the current time, it transmits the client deletion instruction information to the image forming apparatus 103.
[0117] In other words, when the current time reaches the deletion instruction transmission time in the client deletion instruction information, the deletion instruction management unit 505 sends an instruction to one or more image forming apparatuses 103 to delete the applications and / or firmware components operating on one or more image forming apparatuses 103 corresponding to the service usage contract information whose contract period has expired. One or more image forming apparatuses 103 receive the instruction.
[0118] In step S806, one or more image forming apparatuses 103 execute the uninstaller of the application recorded in the client deletion instruction information shown in Figure 20(a) received in S805. This allows the image forming apparatuses 103 to delete applications whose service usage contract period has expired.
[0119] In step S807, one or more image forming apparatuses 103 delete the firmware component files recorded in the client deletion instruction information shown in Figure 20(a) received in S805.
[0120] In step S808, if the deletion instruction management unit 505 of the contract-linked processing execution server 102 holds server data deletion instruction information shown in Figure 20(b) that matches the current time, it transmits the server data deletion instruction information to the service server 104.
[0121] In other words, when the current time reaches the deletion instruction transmission time in the server data deletion instruction information, the deletion instruction management unit 505 sends an instruction to one or more service servers 104 to delete the specified information on one or more service servers 104 corresponding to the service usage contract information whose contract period has expired. One or more service servers 104 receive the instruction.
[0122] In step S809, the service server 104 deletes data (predetermined information) from the information management unit 702 that has the columns and values recorded in the server data deletion instruction information shown in Figure 20(b) received in S808.
[0123] [Overall processing flow for creating deletion instructions on the contract-linked processing execution server] Figure 9 shows the overall processing flow for creating a deletion instruction in the contract-linked processing execution server 102.
[0124] In step S900, the contract period detection unit 501, which is activated by a timer, obtains all service usage contract information listed in Figure 19(a) whose contract period has expired from the contract management server 101.
[0125] In step S901, the contract period detection unit 501 determines whether it was able to obtain service usage contract information whose contract period has expired. If it was able to obtain service usage contract information whose contract period has expired, it sends the service usage contract information to the deletion instruction creation unit 502 and proceeds to S902. If it was not possible to obtain the information, the processing flow in Figure 9 ends.
[0126] The processing from step S902 onward is performed in a loop for each instance of the service usage contract information obtained in S900.
[0127] In step S902, the deletion instruction creation unit 502 retrieves one or more contract service names from the "Contract Service" column of the service usage contract information obtained in S900.
[0128] The processing from step S903 onward is performed in a loop for each contracted service name obtained in S902.
[0129] In step S903, the deletion instruction creation unit 502 queries the application management unit 503-2 to obtain the application deletion information shown in Figure 19(c) that corresponds to the contract service name.
[0130] In step S904, the deletion instruction creation unit 502 queries the firmware component management unit 503-3 to obtain the firmware component deletion information shown in Figure 19(d) that corresponds to the contract service name.
[0131] In step S905, the deletion instruction creation unit 502 determines whether it was able to obtain application deletion information or firmware component deletion information. If it was able to obtain application deletion information or firmware component information, the process proceeds to S906. If it was not possible to obtain the information, the process in S906 is not executed.
[0132] In step S906, the deletion instruction creation unit 502 creates client deletion instruction information using the application deletion information obtained in S903 and the firmware component deletion information obtained in S904. A detailed processing flow for creating client deletion instruction information is explained in Figure 10.
[0133] In step S907, the deletion instruction creation unit 502 queries the service setting value management unit 503-1 to obtain the server deletion information shown in Figure 20(b) that corresponds to the contracted service name.
[0134] In step S908, the deletion instruction creation unit 502 determines whether it was able to obtain the server deletion information in S907. If the server deletion information was obtained, the process proceeds to S909. If it was not obtained, the process in S909 is not executed.
[0135] In step S909, the deletion instruction creation unit 502 creates server data deletion instruction information using the server deletion information obtained in S907. The detailed processing flow for creating server data deletion instruction information is explained in Figure 11.
[0136] In step S910, the deletion instruction creation unit 502 sends the client deletion instruction information created in S906 and the server data deletion instruction information created in S909 to the deletion instruction management unit 505.
[0137] The flow shown in Figure 9 ends when processing of service usage contract information for which all contract periods have expired is complete.
[0138] [Process flow for creating client deletion instruction information] Figure 10 is a flowchart of the creation of client deletion instruction information described in Figure 20(a) in S906 of the deletion instruction creation unit 502 of the contract-linked processing execution server 102. The processing flow in Figure 10 is started when the application deletion information described in Figure 19(c) or the firmware component deletion information described in Figure 19(d) can be obtained in Figure 9.
[0139] In step S1000, the deletion instruction creation unit 502 obtains an identification number of the image forming apparatus 103, such as the device serial number, from the service usage contract information shown in Figure 19(a) received from the contract period detection unit 501.
[0140] In step S1001, the deletion instruction creation unit 502 obtains the uninstaller file name for deleting the application from the application deletion information obtained from the application management unit 503-2. The uninstaller file name may also be the identification information of the application to be deleted (such as the application ID).
[0141] In step S1002, the deletion instruction creation unit 502 obtains identification information (such as file name and file path) of the firmware component to be deleted from the firmware component deletion information obtained from the firmware component management unit 503-3.
[0142] In step S1200, the deletion instruction creation unit 502 acquires time information for transmitting the client deletion instruction information to the image forming apparatus 103. A detailed flow is explained in Figure 12.
[0143] In step S1003, the deletion instruction creation unit 502 integrates the information acquired in S1000, S1001, S1002, and S1200 to create client deletion instruction information.
[0144] The processing flow in Figure 10 terminates when client deletion instruction information is generated.
[0145] [Processing flow for creating server deletion instruction information] Figure 11 shows the processing flow for creating the server data deletion instruction information described in Figure 20(b) in S909 of the deletion instruction creation unit 502 of the contract-linked processing execution server 102. The processing flow in Figure 11 is started when the server deletion information described in Figure 19(e) in Figure 9 can be obtained.
[0146] In step S1100, the deletion instruction creation unit 502 obtains a key-value combination to identify the customer information to be deleted and the URL of the API to delete the data from the service server 104 from the server deletion information shown in Figure 19(b).
[0147] In step S1101, the deletion instruction creation unit 502 obtains the value corresponding to the value portion of the key-value combination obtained in S1100 from the service usage contract information shown in Figure 19(a) received from the contract period detection unit 501. This determines the combination of column name and value of the customer information to be deleted from the service server 104.
[0148] In step S1200, the deletion instruction creation unit 502 acquires time information for transmitting server data deletion instruction information to the image forming apparatus 103. A detailed flow is explained in Figure 12.
[0149] In step S1102, the deletion instruction creation unit 502 integrates the URL of the deletion API obtained in S1100, the combination of column names and values of the customer information obtained in S1101, and the transmission time of the server data deletion instruction information obtained in S1200 to create server data deletion instruction information.
[0150] The processing flow shown in Figure 11 terminates when the server data deletion instruction information is created.
[0151] [Processing flow for the deletion schedule creation function] Figure 12 shows the processing flow for generating deletion processing transmission time information in S1200 of the deletion schedule creation unit 504 of the contract-linked processing execution server 102. The processing flow in Figure 12 is started during the execution of S906 and S909.
[0152] In step S1201, the deletion schedule creation unit 504 specifies the initial value (desired deletion instruction transmission time) for the transmission time of the client deletion instruction information or server data deletion instruction information. For example, by adding 5 minutes to the current time, that time is set as the desired deletion instruction transmission time.
[0153] In step S1202, the deletion schedule creation unit 504 queries the deletion instruction management unit 505 to obtain the number of client deletion instruction information and server data deletion instruction information that have the same transmission time as the desired deletion instruction transmission time generated in S1201.
[0154] In step S1203, the deletion schedule creation unit 504 determines whether the number of deletion instructions obtained in S1202 exceeds a certain threshold. If it exceeds the threshold, the process proceeds to S1204. If it does not exceed the threshold, i.e., if no correction is needed for the desired deletion instruction transmission time, the process proceeds to S1205. The aforementioned threshold is set to the number of client deletion instruction information and server data deletion instruction information that can be sent within a certain period of time, within a range that does not place an excessive load on the contract-linked processing execution server 102. For example, if the upper limit of the number of deletion instructions that can be sent per unit time by the contract-linked processing execution server 102 is 10, the threshold is set to 10.
[0155] In step S1204, the deletion schedule creation unit 504 corrects the desired deletion instruction transmission time by adding a certain amount of time to the desired deletion instruction transmission time used in the comparison in S1202. For example, if the desired deletion instruction transmission time was set to "January 1, 2024, 0:10:00" in S1202, 5 minutes is added as a certain amount of time, and "January 1, 2024, 0:15:00" becomes the corrected desired deletion instruction transmission time.
[0156] In step S1205, the deletion schedule creation unit 504 sets the desired deletion instruction transmission time as the value of the "deletion instruction transmission time" column in the deletion instruction transmission time information shown in Figure 19(e), and transmits the deletion instruction transmission time information to the deletion instruction creation unit 502.
[0157] As described above, the deletion schedule creation unit 504 sets the deletion instruction transmission time so that the number of instructions transmitted at the same time does not exceed a threshold.
[0158] As described above, in the sequence shown in Figure 8, when a service usage agreement is terminated, the application and its firmware components related to the terminated service are deleted from the image forming apparatus 103. At the same time, the personal information of the service user is deleted from the service server 104, eliminating the risk of unauthorized use of the service user's personal information.
[0159] (Second embodiment) As a second embodiment, when deleting data from multiple image forming apparatuses 103 and multiple service servers 104, a configuration is provided in which the timing of starting data deletion and the timing of ending data deletion are synchronized.
[0160] In the first embodiment, if multiple image forming apparatuses 103 are listed in a single service usage agreement, the deletion process may be performed sequentially, potentially resulting in differences in the timing of application deletion from each image forming apparatus 103. This could confuse service users.
[0161] Furthermore, if the timing of the deletion of specific information from the service server 104 differs, it is possible that service users may become confused.
[0162] In the second embodiment, in view of the above-mentioned problems, the objective is to synchronize the timing of the start and completion of data deletion when the contract-linked processing execution server 102 performs data deletion on multiple image forming apparatuses 103 or multiple services included in a single service usage contract.
[0163] Figure 13 shows the overall sequence in the second embodiment.
[0164] Steps S1300 to S1304 are the same as S800 to S804 in Figure 8, so their explanation will be omitted.
[0165] In step S1305, the deletion instruction management unit 505 sends an operation restriction instruction for the application to be deleted to one or more image forming apparatuses 103 listed in the client deletion instruction information.
[0166] In other words, the deletion instruction management unit 505 sends instructions to one or more image forming apparatuses 103 to restrict the operation of an application running on one or more image forming apparatuses 103 that corresponds to service usage contract information whose contract period has expired.
[0167] In step S1306, one or more image forming apparatuses 103 notify the deletion instruction management unit 505 that it has restricted the operation of the application to be deleted.
[0168] In step S1307, the deletion instruction management unit 505 sends a restriction instruction to prevent customers whose customer ID is listed in the server data deletion instruction information from accessing the service server 104 that is subject to data deletion.
[0169] In other words, the deletion instruction management unit 505 sends an instruction to one or more service servers 104 to restrict a customer corresponding to service usage contract information whose contract period has expired from accessing one or more service servers 104 corresponding to that service usage contract information whose contract period has expired.
[0170] In step S1308, the service server 104 notifies the deletion instruction management unit 505 that it has restricted access to the service server 104 so that the customer with the customer ID in question cannot access it.
[0171] Steps S1309 to S1312 are executed if the deletion instruction management unit 505 holds client deletion instruction information that matches the current time.
[0172] Steps S1309 to S1311 are the same as steps S805 to S807 in Figure 8, so their explanation will be omitted.
[0173] In step S1312, each of the one or more image forming apparatuses 103 that received the client deletion instruction information in S1309 notifies the deletion instruction management unit 505 that the deletion process has been completed.
[0174] Steps S1313 to S1315 are executed when the deletion instruction management unit 505 has server data deletion information that is set to be sent at the current time.
[0175] Steps S1313 to S1314 are the same as steps S808 to S809 in Figure 8, so their explanation will be omitted.
[0176] In step S1315, the service server 104, which received the server data deletion instruction information, notifies the deletion instruction management unit 505 that it has deleted the specified information.
[0177] Step S1316 is executed if a deletion completion notification is received in both S1312 and S1315. In S1316, the deletion instruction management unit 505 sends an instruction to delete the icon of the application to be deleted from the UI of one or more image forming apparatuses 103.
[0178] Step S1316 is executed when one or more image forming apparatuses 103 have received a deletion completion notification corresponding to the transmission of S1309, and one or more service servers 104 have received a deletion completion notification corresponding to the transmission of S1313. In step S1316, the deletion instruction management unit 505 sends an instruction to one or more image forming apparatuses 103 to delete the application icons running on one or more image forming apparatuses 103 that correspond to the service usage contract information whose contract period has expired.
[0179] In step S1317, the image forming apparatus 103 removes the icon of the application to be deleted from the UI of the image forming apparatus 103.
[0180] Figure 14 shows how applications targeted for deletion are displayed on the UI of the image forming apparatus 103. At S1305 in Figure 13, when the image forming apparatus 103 receives an application operation restriction from the contract-linked processing execution server 102, it grays out the icon of the application targeted for deletion, as shown at 1400 in Figure 14. Applications that are grayed out cannot be operated from the UI of the image forming apparatus 103. When S1316 is executed, the grayed-out icon at 1400 in Figure 14 is removed from the UI of the image forming apparatus 103.
[0181] As described above, the sequence diagram in Figure 13 and the UI display in Figure 14 allow the icons of applications to be deleted from multiple image forming apparatuses 103 to be deleted at the same time, thus preventing user confusion during the deletion process. Similarly, the timing of customer information deletion can be synchronized from the service server 104, eliminating the risk of user confusion during the deletion process.
[0182] (Third embodiment) As a third embodiment, a method is provided for notifying the service user when, during the execution of the application deletion process, a deletion completion notification cannot be received from the image forming apparatus 103 due to a communication failure or the like.
[0183] In the second embodiment, if the deletion instruction management unit 505 fails to receive a deletion completion notification from the image forming apparatus 103 at S1312 in Figure 13, the application icon remains on the image forming apparatus 103 without being deleted, which presents a problem.
[0184] In the third embodiment, in view of the above-mentioned problems, the objective is to provide a configuration in which the deletion instruction management unit 505 can notify the service user of an image forming apparatus 103 that did not send a deletion completion notification.
[0185] Figure 15 shows the processing flow when the deletion instruction management unit 505 fails to receive a deletion completion notification from the image forming apparatus 103 after executing a client deletion instruction. This flow starts at step S1312 in Figure 13.
[0186] In step S1500, the deletion instruction management unit 505 determines whether it has received deletion completion notifications for the application and firmware components from all image forming apparatuses 103 specified in the client deletion instruction. If the deletion instruction management unit 505 has received deletion completion notifications from all image forming apparatuses 103, it terminates the processing flow shown in Figure 15. If the deletion instruction management unit 505 has not received deletion completion notifications from one or more image forming apparatuses 103, it proceeds to S1501.
[0187] In other words, the deletion instruction management unit 505 determines whether it was able to receive a deletion completion notification from the image forming apparatus 103 that sent the notification in S805 or S1309. If there is an image forming apparatus 103 from which a deletion completion notification could not be received, the unit proceeds to S1501.
[0188] In step S1501, the deletion instruction management unit 505 creates an email containing the contract ID, application name, and identification information of the image forming apparatus 103 that failed to delete the application, as specified in the client deletion instruction. The email is sent to the customer contact information specified in the client deletion instruction.
[0189] In step S1502, the deletion instruction management unit 505 sends the email created in S1501 to the email notification recipient. This email is, for example, an email stating that the deletion failed.
[0190] Figure 16 shows an example of email 1600 sent to the service user in S1502 of Figure 15.
[0191] The email recipient will be set to the customer contact value listed in the client deletion instructions.
[0192] The email body will contain the name of the application that failed to be uninstalled.
[0193] As shown in the flowchart in Figure 15, if the deletion instruction management unit 505 fails to delete the application, it can notify the service user, thereby preventing the application from remaining on the system without being deleted.
[0194] (Fourth embodiment) As a fourth embodiment, we provide a method for backing up data in the event that a service user forgets to renew their service contract and the data is deleted due to the termination of the contract.
[0195] In the first embodiment, when the service usage agreement expires, the application is automatically deleted from the image forming apparatus 103, and specified information, such as the customer's personal information, is deleted from the service server 104. If the service user forgets to renew the service usage agreement, the service user will need to re-enter their personal information into the image forming apparatus 103 and the service server 104. This is problematic in terms of service convenience for the service user.
[0196] In the fourth embodiment, in view of the above issues, the deletion instruction management unit 505 of the contract-linked processing execution server 102 aims to back up the application settings on the image forming apparatus 103 and predetermined information on the service server 104 for a certain period of time. It also aims to transmit the application settings to the image forming apparatus 103 and the predetermined information to the service server 104 when the service usage contract is resumed.
[0197] Figure 17 shows the overall sequence at the termination of the service usage agreement in the fourth embodiment. The contents of the service usage agreement information at the start of the sequence are as shown in Figure 21(b).
[0198] The columns from "Contract ID" to "Contract End Date" are the same as the service usage contract information shown in Figure 19(a), so we will omit the explanation.
[0199] The "Resumption Flag" is a column that stores a flag indicating whether a service agreement was temporarily suspended but subsequently resumed. A value of False indicates that the service agreement has not been resumed. A value of True indicates that the service agreement has been resumed.
[0200] Steps S1700 to S1704 are the same as steps S800 to S804 in the sequence diagram of Figure 8, so their explanation will be omitted.
[0201] Steps S1705 to S1710 are executed if a client deletion instruction exists in the deletion instruction management unit 505 that has a transmission time matching the current time.
[0202] In step S1705, the deletion instruction management unit 505 requests the image forming apparatus 103 to send the setting values of the application to be deleted.
[0203] In step S1706, the image forming apparatus 103 returns the setting values of the application to be deleted to the deletion instruction management unit 505. An example of the application setting information to be returned is shown in Figure 21(c).
[0204] The "Contract ID" column is where the deletion instruction management unit 505 stores the contract ID listed in the service usage contract information, which was the source from which the application settings were backed up.
[0205] The "Device Serial Number" column stores identification information of the image forming apparatus 103 from which the application settings were obtained.
[0206] The "Settings" column is a column that stores the attribute and value combinations of each setting for the application that is to be deleted.
[0207] In step S1707, the deletion instruction management unit 505 saves the application setting information shown in Figure 21(c), which was acquired in S1706, to the secondary storage device 206 of the contract-linked processing execution server 102.
[0208] In other words, the deletion instruction management unit 505 acquires and stores the settings of an application running on one or more image forming apparatuses 103 that corresponds to service usage contract information whose contract period has expired.
[0209] Steps S1708 to S1710 are the same as S805 to S807 in Figure 8, so their explanation will be omitted.
[0210] Steps S1711 to S1715 are executed if a server data deletion instruction exists in the deletion instruction management unit 505 that has a transmission time matching the current time.
[0211] In step S1711, the deletion instruction management unit 505 requests the image forming apparatus 103 to transmit predetermined information of the service server 104 to be deleted.
[0212] In step S1712, the image forming apparatus 103 transmits the setting values of predetermined information of the service server 104 to be deleted to the deletion instruction management unit 505. An example of predetermined information (server data setting value information) is shown in Figure 21(d).
[0213] The "Contract ID" column is the same as the application settings information shown in Figure 21(c), so no explanation is provided.
[0214] The "Service ID" column is a column that stores the identification information of the service server 104 that obtained the setting values of the predetermined information.
[0215] The "Setting Value" column stores records of the data in the service server 104 that was targeted for deletion.
[0216] In step S1713, the deletion instruction management unit 505 saves the predetermined information (server data setting value information) described in Figure 21(d) obtained in S1712 to the secondary storage device 206 of the contract-linked processing execution server 102.
[0217] In other words, the deletion instruction management unit 505 retrieves and stores predetermined information from one or more service servers 104 that corresponds to service usage contract information whose contract period has expired.
[0218] Steps S1714 to S1715 are the same as steps S808 to S809 in Figure 8, so their explanation will be omitted.
[0219] Figure 18 shows the overall sequence in this embodiment when the backed-up settings are transmitted to the image forming apparatus 103 and the service server 104 when the service usage contract is resumed.
[0220] Steps S1800 to S1805 are executed if there is a service usage contract information in which the value of the "restart flag" column in the service usage contract information shown in Figure 21(b) is True.
[0221] In step S1800, the contract linkage processing execution server 102 queries the contract management server 101 for service usage contract information for which the contract has been resumed.
[0222] In step S1801, the contract management server 101 returns the service usage contract information for which the contract has been resumed to the contract linkage processing execution server 102.
[0223] The contract-linked processing execution server 102 obtains (receives) service usage contract information for which the contract has been resumed from the contract management server 101.
[0224] Steps S1802 through S1805 are looped through a number of times equal to the number of service usage contract information entries obtained in S1801, and the number of services in each service usage contract information entry.
[0225] In step S1802, the setting value transmission unit 506 obtains application setting value information from the secondary storage device 206 that matches the value of the "Customer ID" column of the service usage contract information obtained in S1801.
[0226] In step S1803, the setting value transmission unit 506 transmits the application setting value information to the image forming apparatus 103 that has the device serial number listed in the "device serial number" column of the application setting value information.
[0227] In other words, the setting value transmission unit 506 transmits the stored application setting values corresponding to the service usage contract information for which the contract has been resumed to one or more image forming apparatuses 103.
[0228] In step S1804, the setting value transmission unit 506 obtains server data setting value information from the secondary storage device 206 that matches the value of the "Customer ID" column of the service usage contract information obtained in S1801.
[0229] In step S1805, the setting value transmission unit 506 transmits the server data setting value information to the service server 104 that has the service ID listed in the "Service ID" column of the server data setting value information.
[0230] In other words, the setting value transmission unit 506 transmits the stored predetermined information (server data setting value information) corresponding to the service usage contract information for which the contract has been resumed to one or more service servers 104.
[0231] As described above, the sequence shown in Figure 18 allows for the rapid restoration of the application installed on the image forming apparatus 103 and the settings configured on the service server 104 when reactivating the service agreement. This contributes to improving customer convenience.
[0232] In the first to fourth embodiments, upon termination of the service usage agreement, predetermined information such as the application and firmware components installed in the image forming apparatus 103, as well as the customer's personal information handled by the service on the service server 104 associated with the image forming apparatus 103, are deleted together.
[0233] Furthermore, when performing deletion in a configuration where multiple image forming apparatuses 103 are connected to the service server 104, there is concern about an increase in the load on the service server 104. When the load on the service server 104 increases, the responsiveness of the service deteriorates, leading to a decrease in usability.
[0234] In light of these challenges, the first to fourth embodiments aim to suppress the increase in load on the service server 104 and to appropriately delete customers' personal information after the termination of the service usage contract, even in an environment where multiple image forming apparatuses 103 are connected to the service server 104.
[0235] In the first to fourth embodiments, after the termination of the service usage contract for the image forming apparatus 103, both the application and customer-related information are deleted from the image forming apparatus 103 and the service server 104 used by the image forming apparatus 103, thereby appropriately eliminating the risk of unauthorized use of customer information. Furthermore, when performing the deletion, it is possible to reduce the load on the contract-linked processing execution server 102 that issues the deletion instruction.
[0236] (Other embodiments) This disclosure can also be implemented by supplying a program that implements one or more of the functions of the embodiments described above to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be implemented by a circuit (e.g., an ASIC) that implements one or more functions.
[0237] Furthermore, the embodiments described above are merely examples illustrating how to implement this disclosure, and they should not be interpreted as limiting the technical scope of this disclosure. In other words, this disclosure can be implemented in various ways without departing from its technical concept or its main features.
[0238] This embodiment includes the following configuration. (Item 1) A first means of obtaining service usage contract information whose contract period has expired, A first transmission means that transmits instructions to one or more image forming apparatuses to delete applications or firmware components operating on one or more image forming apparatuses corresponding to service usage contract information whose contract period has expired, A second transmission means that transmits to one or more service servers an instruction to delete predetermined information on one or more service servers corresponding to the service usage contract information whose contract period has expired. An execution server characterized by having the following features. (Item 2) Prior to transmission by the first transmission means, a third transmission means transmits to one or more image forming apparatuses an instruction to restrict the operation of an application running on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, The execution server according to item 1, further comprising a fourth transmission means for transmitting, before the transmission by the second transmission means, instructions to one or more service servers to restrict a customer corresponding to the expired service usage contract information from accessing one or more service servers corresponding to the expired service usage contract information. (Item 3) The execution server according to item 2, further comprising a fifth transmission means that, upon receiving a deletion completion notification from one or more image forming apparatuses corresponding to a transmission by the first transmission means, and upon receiving a deletion completion notification from one or more service servers corresponding to a transmission by the second transmission means, transmits an instruction to one or more image forming apparatuses to delete the icon of an application running on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired. (Item 4) An execution server according to any one of items 1 to 3, further comprising a sixth transmission means that determines whether it was able to receive a deletion completion notification from an image forming apparatus to which the first transmission means transmitted, and if there is an image forming apparatus that was unable to receive a deletion completion notification, sends an email to the notification recipient stating that the deletion failed. (Item 5) Prior to transmission by the first transmission means, the first storage means obtains and stores the settings of an application operating on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, from the one or more image forming apparatuses. Prior to transmission by the second transmission means, a second storage means obtains and stores predetermined information on one or more service servers corresponding to the service usage contract information whose contract period has expired from the one or more service servers, A second acquisition means for acquiring service usage contract information for which the contract has been resumed, after the transmission by the first transmission means and the transmission by the second transmission means, A seventh transmission means for transmitting the stored application settings corresponding to the service usage contract information for which the contract has been resumed to one or more image forming apparatuses, An execution server according to any one of items 1 to 4, further comprising an eighth transmission means for transmitting the stored predetermined information corresponding to the service usage contract information for which the contract has been resumed to one or more service servers. (Item 6) The execution server according to any one of items 1 to 5, characterized in that the first transmission means transmits instructions to one or more image forming apparatuses to delete applications and firmware components operating on one or more image forming apparatuses corresponding to service usage contract information whose contract period has expired. (Item 7) The first transmitting means transmits the instruction when the current time reaches the first transmission time. The execution server according to any one of items 1 to 6, characterized in that the second transmission means transmits the instruction when the current time reaches the second transmission time. (Item 8) The execution server according to item 7, characterized in that the first transmission means and the second transmission means each set the first transmission time and the second transmission time such that the number of instructions transmitted at the same time does not exceed a threshold. (Item 9) The execution server described in any one of items 1 to 8 is characterized in that the first acquisition means acquires service usage contract information whose contract period has expired from the contract management server. (Item 10) The execution server described in any one of items 1 to 9, Upon receiving the aforementioned instruction, one or more image forming apparatuses delete the application or firmware component, Upon receiving the aforementioned instruction, one or more service servers delete the predetermined information. An information processing system characterized by having the following features. (Item 11) The first acquisition step is to obtain service usage contract information whose contract period has expired, A first transmission step of sending instructions to one or more image forming apparatuses to delete an application or firmware component operating on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, A second transmission step of sending an instruction to one or more service servers to delete specified information on one or more service servers corresponding to the service usage contract information whose contract period has expired. A processing method for an execution server, characterized by having the following features. (Item 12) A program that causes a computer to function as an execution server as described in any one of items 1 through 9. [Explanation of symbols]
[0239] 500 External Communications Department 501 Contract Period Detection Unit 502 Deletion Instruction Creation Department 503 Service Termination Information Management Department 504 Deletion Schedule Creation Department 505 Deletion Instruction Management Department 506 Setting value transmission unit
Claims
1. A first means of obtaining service usage contract information whose contract period has expired, A first transmission means that transmits instructions to one or more image forming apparatuses to delete applications or firmware components operating on one or more image forming apparatuses corresponding to service usage contract information whose contract period has expired, A second transmission means that transmits an instruction to one or more service servers to delete predetermined information on one or more service servers corresponding to the service usage contract information whose contract period has expired. An execution server characterized by having the following features.
2. Prior to transmission by the first transmission means, a third transmission means transmits to the one or more image forming apparatus an instruction to restrict the operation of an application running on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, The execution server according to claim 1, further comprising a fourth transmission means for transmitting, before the transmission by the second transmission means, instructions to one or more service servers to restrict a customer corresponding to the expired service usage contract information from accessing one or more service servers corresponding to the expired service usage contract information.
3. The execution server according to claim 2, further comprising a fifth transmission means for receiving a deletion completion notification from one or more image forming apparatuses corresponding to a transmission by the first transmission means, and receiving a deletion completion notification from one or more service servers corresponding to a transmission by the second transmission means, and transmitting an instruction to one or more image forming apparatuses to delete the icon of an application running on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired.
4. The execution server according to claim 1, further comprising a sixth transmission means for determining whether the first transmission means was able to receive a deletion completion notification from an image forming apparatus, and if there is an image forming apparatus from which the deletion completion notification could not be received, sending an email to the notification recipient stating that the deletion failed.
5. Prior to transmission by the first transmission means, the first storage means obtains and stores the settings of an application operating on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, from the one or more image forming apparatuses. Prior to transmission by the second transmission means, a second storage means obtains and stores predetermined information on one or more service servers corresponding to the service usage contract information whose contract period has expired from the one or more service servers, A second acquisition means for acquiring service usage contract information for which the contract has been resumed, after the transmission by the first transmission means and the transmission by the second transmission means, A seventh transmission means for transmitting the stored application settings corresponding to the service usage contract information for which the contract has been resumed to one or more image forming apparatuses, The execution server according to claim 1, further comprising an eighth transmission means for transmitting the stored predetermined information corresponding to the service usage contract information for which the contract has been resumed to one or more service servers.
6. The execution server according to claim 1, characterized in that the first transmission means transmits instructions to one or more image forming apparatuses to delete applications and firmware components operating on one or more image forming apparatuses corresponding to service usage contract information whose contract period has expired.
7. The first transmitting means transmits the instruction when the current time reaches the first transmission time. The execution server according to claim 1, characterized in that the second transmission means transmits the instruction when the current time reaches the second transmission time.
8. The execution server according to claim 7, characterized in that the first transmission means and the second transmission means each set the first transmission time and the second transmission time such that the number of instructions transmitted at the same time does not exceed a threshold.
9. The execution server according to claim 1, characterized in that the first acquisition means acquires service usage contract information whose contract period has expired from the contract management server.
10. An execution server according to any one of claims 1 to 9, Upon receiving the aforementioned instruction, one or more image forming apparatuses delete the application or firmware component, Upon receiving the aforementioned instruction, one or more service servers delete the predetermined information. An information processing system characterized by having the following features.
11. The first acquisition step is to obtain service usage contract information whose contract period has expired, A first transmission step of sending instructions to one or more image forming apparatuses to delete an application or firmware component operating on one or more image forming apparatuses corresponding to the service usage contract information whose contract period has expired, A second transmission step of sending an instruction to one or more service servers to delete specified information on one or more service servers corresponding to the service usage contract information whose contract period has expired. A processing method for an execution server, characterized by having the following features.
12. A program for causing a computer to function as an execution server according to any one of claims 1 to 9.
Citation Information
Patent Citations
Information processing system and program
JP2022165208A