Image forming apparatus
The image processing apparatus addresses authorization method limitations by determining server support and prompting alternative methods, ensuring seamless authorization processes despite service provider or device limitations, thus enhancing operational reliability and user experience.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- SHARP KK
- Filing Date
- 2025-12-26
- Publication Date
- 2026-04-20
AI Technical Summary
Existing authorization methods for image processing devices, such as multifunction peripherals, face challenges with service providers that do not support the device flow method, leading to potential hindrances in authorization processes due to browser limitations or service provider restrictions, causing user confusion and process failures.
The image processing apparatus is equipped with a control unit that determines the support for selected authorization methods on an authorization server, restricting unauthorized methods and prompting users to choose alternative methods if unsupported, thereby ensuring seamless authorization processes through multiple authorization methods.
This approach reduces the risk of authorization process hindrances by enabling flexible method selection, ensuring uninterrupted authorization processes even when service providers or device capabilities change, enhancing user experience and operational reliability.
Smart Images

Figure 2026067410000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an image processing apparatus and the like.
Background Art
[0002] As an authorization method for resource utilization, a more secure authorization method using the OAuth protocol or the like has become mainstream (for example, Patent Document 1).
[0003] As an authorization method based on the OAuth protocol, a device flow method is known in which authorization for an image processing apparatus such as a multifunction peripheral is performed via the Web through an external terminal device such as a PC (Personal Computer) or a smartphone.
[0004] In the device flow method, authorization of the image processing apparatus can be performed without being restricted by the presence or absence of a browser installed in the image processing apparatus or input means for inputting authorization / authentication information.
[0005] However, depending on the service provider that provides the OAuth authorization service, it may not support the device flow method, and the authorization process by the device flow method may not be executable.
Prior Art Documents
Patent Documents
[0006]
Patent Document 1
Summary of the Invention
[0007] An object of the present disclosure is to provide an image processing apparatus and the like capable of reducing the risk that the realization of an authorization process is hindered due to the authorization method to be applied.
Means for Solving the Problems
[0008] To solve the above problems, the image processing apparatus according to this disclosure comprises a control unit capable of performing authorization processing using multiple authorization methods on an authorization server, a storage unit for storing connection information to the authorization server, and an output unit for outputting screen information related to the authorization processing. The control unit determines whether the authorization server supports an authorization method when the user selects an authorization method based on the connection information, and if the authorization server determines that it does not support the authorization method, it restricts the execution of the authorization processing using the authorization method. The output unit outputs a notification prompting the user to select an authorization method different from the authorization method.
[0009] Furthermore, the authorization method in the image processing device relating to this disclosure is an authorization method in an image processing device capable of performing authorization processing using multiple authorization methods, characterized in that, when the user selects the authorization processing based on one authorization method, the authorization server determines whether or not it supports the said authorization method, and if the authorization server determines that it does not support the said authorization method, it restricts the execution of the authorization processing using the said authorization method and outputs a notification prompting the user to select an authorization method different from the said authorization method. [Effects of the Invention]
[0010] According to this disclosure, it is possible to provide an image processing device, etc., that can reduce the risk that the implementation of the authorization process will be hindered due to the applicable authorization method. [Brief explanation of the drawing]
[0011] [Figure 1] This diagram illustrates the connection configuration between a service server and an external terminal device for a multifunction printer according to the first embodiment. [Figure 2] This diagram illustrates the functional configuration of a multifunction device according to the first embodiment. [Figure 3] This diagram illustrates the configuration information table. [Figure 4]This is a flowchart illustrating the processing flow according to the first embodiment. [Figure 5] This diagram illustrates the authorization flow method and the device flow method. [Figure 6] This is a diagram illustrating an example of operation according to the first embodiment. [Figure 7] This is a diagram illustrating an example of operation according to the first embodiment. [Figure 8] This is a flowchart illustrating the processing flow according to the second embodiment. [Figure 9] This figure illustrates an example of operation according to the second embodiment. [Figure 10] This figure illustrates an example of operation according to the third embodiment. [Figure 11] This figure illustrates an example of operation according to the third embodiment. [Modes for carrying out the invention]
[0012] The embodiments relating to this disclosure will be described below with reference to the drawings. In this disclosure, for example, a multifunction device capable of performing jobs related to copying, faxing, emailing, etc., in a single housing will be described as one form of the image processing device relating to this disclosure. Note that the following embodiments are examples for illustrating this disclosure, and the technical content of the description in the claims is not limited to the following description.
[0013] In addition to the device flow method described above, an authorization flow method based on the OAuth protocol is known that utilizes a browser built into the image processing device itself to perform authorization. If it is difficult to implement authorization processing using the device flow method, performing authorization processing using the authorization flow method on the image processing device itself allows for the continuation of the authorization process, which is considered beneficial for the user.
[0014] Therefore, for example, when executing an authorization process from the main body of an image processing apparatus, an authorization flow method is applied, and when executing an authorization process using settings via the Web, a device flow method is applied. By enabling an image processing apparatus to implement authorization processes corresponding to a plurality of different authorization methods in this way, a dramatic increase in the throughput related to the authorization process can be expected.
[0015] However, with the above configuration, differences may occur in the service providers that can be used depending on which method is used to execute the authorization process. Also, due to the state of the main body of the image processing apparatus and considerations such as the support expiration date by the service provider, when the browser equipped in the main body of the image processing apparatus becomes unusable, there is also a possibility that the authorization process cannot be executed by the authorization flow method. Thus, the inability to execute the authorization process depending on the state, setting method, or setting content of the image processing apparatus may cause confusion for the user.
[0016] The present disclosure realizes an image processing apparatus and the like capable of reducing the risk that the realization of an authorization process is hindered due to the authorization method to be applied in the following embodiments.
[0017] [1 First Embodiment] In the first embodiment, the form of a multifunction machine 10 is described as one form of an image processing apparatus. However, the image processing apparatus may be a printer, a copying machine, a FAX device, etc. that limit various job functions in addition to the multifunction machine 10.
[0018] [1.1 Connection Form] Figure 1 illustrates an example of a connection configuration between a service server 30 (30a, 30b, ...) and an external terminal device 50 to a multifunction printer 10. The multifunction printer 10 is connected via a network NW to enable mutual communication between the service server 30 (30a, 30b, ...) and the external terminal device 50. The multifunction printer 10 according to this disclosure can also function as a server device capable of outputting screen information related to job execution, various settings, authorization processes, etc., as a Web-UI (User Interface) to the external terminal device 50 or its own browser via a web application using a communication protocol such as HTTP (HyperText Transfer Protocol), or a native application not shown.
[0019] A service server 30 (30a, 30b, ...) is an authorization server capable of performing authorization processing based on the OAuth protocol using at least one of the authorization flow method or the device flow method, or both. Here, lowercase letters ("a", "b") represent service servers 30 with different service specifications (e.g., corresponding authorization method, browser requirement, settings, etc.). Furthermore, service servers 30 are not limited to two service servers 30a and 30b, but may include two or more service servers 30. In this disclosure, when service servers 30a and 30b are not distinguished, they may simply be referred to as service server 30.
[0020] The external terminal device 50 is an information processing device that can control the multifunction printer 10 via the Web (application). Based on screen information output from the multifunction printer 10, which functions as a server device, the external terminal device 50 can perform operations on the multifunction printer 10 such as job execution, various settings, and authorization processing. In particular, in the authorization process using the device flow method, the external terminal device 50 can accept authentication information input from the user and perform authentication processing with the service server 30.
[0021] [1.2 Functional Configuration] [1.2.1 About the Multifunction Printer 10] The functional configuration of the multifunction device 10 will be explained using Figure 2. The multifunction device 10 comprises a control unit 11, a display unit 13, an operation input unit 15, a communication unit 17, an image processing unit 19, and a storage unit 21.
[0022] The control unit 11 controls the multifunction printer 10 as a whole. The control unit 11 can be composed of one or more processing units (e.g., a CPU (Central Processing Unit), a SoC (System On Chip), etc.). The control unit 11 realizes its functions by reading various programs stored in the memory unit 21.
[0023] The display unit 13 is a display device that displays various information to the user. The display unit 13 can be configured as, for example, an LCD (Liquid Crystal Display), an organic EL (Electro-Luminescence) display, etc. Based on control by the control unit 11, the display unit 13 displays screen information such as a home screen (not shown), settings screens for the execution of each job and authorization processing, etc., via a browser screen which will be described later.
[0024] The operation input unit 15 is an input device that accepts information input from users, etc. The operation input unit 15 can be composed of various input devices such as operation keys and buttons, such as hardware keys and software keys. The operation input unit 15 can also be configured as a touch panel that allows input via a display device such as an LCD (Liquid Crystal Display) or an organic EL (Electro-Luminescence) display. When the operation input unit 15 is configured as a touch panel (hereinafter sometimes referred to as the operation panel), coordinate information and pressure information on the operation panel can be acquired. In this case, common methods such as resistive touch, infrared touch, electromagnetic induction touch, and capacitive touch can be used as input methods for the touch panel.
[0025] The communication unit 17 includes a wired, wireless, or both interface for communicating with the service server 30 and external terminal devices 50 via a network NW such as a LAN (Local Area Network), WAN (Wide Area Network), the Internet, a telephone line, or a fax line. Furthermore, the communication unit 17 may also include interfaces related to wireless communication technologies such as Bluetooth®, NFC (Near Field Communication), Wi-Fi®, IrDA (Infrared Data Association), and Wireless USB (Universal Serial Bus).
[0026] The image processing unit 19 includes an image forming unit 191 and an image input unit 193. The image forming unit 191 feeds paper from a paper feeding unit (not shown), forms an image on the paper based on image data, and then discharges the paper from a paper output unit (not shown). The image forming unit 191 can be configured, for example, by a laser printer employing an electrophotographic method. In this case, the image forming unit 191 performs image formation using toner supplied from a toner cartridge (not shown) corresponding to a toner color (e.g., cyan, magenta, yellow, black).
[0027] The image input unit 193 generates image data by scanning a document. The image input unit 193 can be configured as a scanner device equipped with an image sensor such as a CCD (Charge Coupled Device) or CIS (Contact Image Sensor), as well as an automatic document feeder (ADF) and a flatbed for placing and scanning documents. The image input unit 193 is not particularly limited in its configuration as long as it is capable of reading reflected light from the document image with the image sensor. The image input unit 193 can also be configured as an interface capable of acquiring image data stored on a storage medium such as a USB memory or image data transmitted from an external terminal device 50. The image processing unit 19 may generate image data for image transmission by applying, for example, shading correction or density correction to the image data input from the image input unit 193.
[0028] The memory unit 21 is one or more storage devices that store various programs and data necessary for the operation of the multifunction printer 10. The memory unit 21 can be composed of storage devices such as RAM (Random Access Memory), SSD (Solid State Device), HDD (Hard Disk Drive), and ROM (Read Only Memory).
[0029] In the first embodiment, the storage unit 21 stores the control program 211, the authorization program 213, the browser program 215, and the server program 217, and reserves a configuration information storage area 219.
[0030] The control program 211 is a program that the control unit 11 reads when controlling the entire multifunction device 10. After reading the control program 211, the control unit 11 functions as an OS (Operating System) and controls the operation of hardware such as the display unit 13, operation input unit 15, communication unit 17, and image processing unit 19.
[0031] The authorization program 213 is a program that the control unit 11 reads when performing authorization processing with the service server 30. After reading the authorization program 213, the control unit 11 can request the acquisition of an authorization code or access token issued by the service server 30, and request resources by presenting the acquired access token.
[0032] The authorization program 213 includes an authorization method determination program 2131, an authorization information acquisition restriction program 2133, and a notification output program 2135. The control unit 11, upon reading the authorization method determination program 2131, determines whether authorization processing using the authorization method selected by the user is possible. The control unit 11, upon reading the authorization method determination program 2131, can, for example, determine whether authorization processing using the authorization method is possible based on whether the authorized service server 30 supports the authorization method selected by the user.
[0033] If the control unit 11 determines that the authorization process using the authorization method selected by the user cannot be executed, it reads the authorization information acquisition restriction program 2133. Upon reading the authorization information acquisition restriction program 2133, the control unit 11 restricts the execution of the authorization process using that authorization method. In this case, for example, the control unit 11 restricts the acquisition (request) of authorization information by hiding the selection button that accepts requests to acquire authorization information such as authorization codes and access tokens from the service server 30, or by graying out the selection button and making it unselectable.
[0034] Furthermore, if the control unit 11 determines that the authorization process using the authorization method selected by the user is unexecutable, it reads the notification output program 2135. After reading the notification output program 2135, the control unit 11 functions as an output unit and outputs a notification that restricts the execution of the authorization process using the said authorization method and prompts the user to select an authorization method different from the said authorization method. Alternatively, if the control unit 11 determines that the authorization process using the authorization method selected by the user is unexecutable, it may first read the notification output program 2135, output a notification prompting the user to select an authorization method different from the said authorization method, and then restrict the acquisition of authorization information by reading the authorization information acquisition restriction program 2133.
[0035] The browser program 215 is a program that the control unit 11 reads when rendering screen information and displaying a screen for viewing on the display unit 13. In the following description, the functions implemented by the control unit 11 after reading the browser program 215 may be simply referred to as the browser. The browser can display notifications and other information output by the notification output program 2135 via the browser screen displayed on the display unit 13.
[0036] The server program 217 is a program that the control unit 11 reads when providing screen information in response to a request from a browser. Upon reading the server program 217, the control unit 11 can implement a server function that outputs screen information in response to requests from its own browser or a browser on an external terminal device 50.
[0037] The configuration information storage area 219 is a storage area that stores configuration information related to the device settings of the multifunction printer 10. Here, an example of configuration information stored in the configuration information storage area 219 will be explained using Figure 3. Figure 3 is an example of a configuration information table that manages the configuration information stored in the configuration information storage area 219 on a per-configuration-item basis. Note that the configuration information stored in the configuration information storage area 219 may be managed in a database format in addition to the table format.
[0038] The configuration information table illustrated in Figure 3 is an example that extracts connection settings, browser settings, and provided services (service settings) as configuration items. The configuration information table can, of course, also manage configuration information related to hardware settings, system settings, and other settings in addition to these.
[0039] Connection settings are configuration items related to connection information for connecting to terminal devices or services located on a network NW, such as a service server 30. Here, ID is an identifier for uniquely identifying connection information. For example, connection information identified by ID "001" includes settings such as protocol "OAuth", provider "provider aaa", response type "Code", client ID "aabbcc", and redirect URL "https: / / aabbcc.com". Note that connection information identified by ID "001" is an example of request parameters included in an authorization request using the authorization flow method. When the authorization method is the authorization flow method, the control unit 11 sends an authorization request based on these request parameters to the authorization endpoint of the service server 30.
[0040] Furthermore, the connection information identified by ID "002" includes settings such as the protocol "OAuth", provider "provider aaa", and client ID "aabbcc". Note that the connection information identified by ID "002" is an example of the request parameters included in a device flow authorization request. When the authorization method is the device flow method, the control unit 11 sends an authorization request based on these request parameters to the authorization endpoint of the service server 30.
[0041] Note that the connection settings may include connection information related to protocols other than the OAuth protocol. For example, the connection information identified by ID "00N" is an example of connection information related to the SMTP protocol.
[0042] Browser settings are configuration information that defines whether the browser function of the multifunction printer 10 is enabled or disabled. In the first embodiment, if the value of the browser setting is "Yes", it indicates that the browser function is enabled, and if the value of the browser setting is "No", it indicates that the browser function is disabled.
[0043] The services provided (service settings) are configuration items that define the authorization services that the service server 30, which is the provider, can provide. For example, service server 30a, which functions as provider aaa, can provide authorization services using both authorization flow method and device flow method (authorization flow_Yes, device flow_Yes). On the other hand, service server 30b, which functions as provider bbb, can provide authorization services using the authorization flow method (authorization flow_Yes), but cannot provide authorization services using the device flow method (device flow_No).
[0044] The control unit 11, having read the authorization method determination program 2131, can determine whether authorization processing can be performed using the authorization method selected by the user by referring to the setting items (service settings) stored in the setting information storage area 219.
[0045] [1.2.2 About Service Server 30 (30a, 30b, ...)] The service server 30 can use any known configuration as long as it is capable of executing authorization processing based on the OAuth protocol using at least one of the authorization flow method, the device flow method, or both. Therefore, a description of the functional configuration of the service server 30 is omitted. In Figure 1, the configuration of the service server 30 (30a, 30b, ...) is shown as a standalone device configuration capable of providing authorization services, but it is also possible to configure it as a cloud service that includes a hardware configuration that provides resources based on the authorization results, in addition to the device configuration related to providing authorization services.
[0046] [1.2.3 Regarding the external terminal device 50] The external terminal device 50 can be, for example, an information processing device with a known configuration such as a PC, smartphone, tablet, or mobile phone. The external terminal device 50 is not particularly limited in its configuration as long as it has a browser program that generates a Web-UI (User Interface) by rendering screen information acquired via the server function provided by the multifunction printer 10. In the device flow type authorization method, if user code information is provided from the multifunction printer 10, the external terminal device 50 can access the authorization page via a hyperlink on the browser. Incidentally, if the user code information provided from the multifunction printer 10 is provided as encoded information, the external terminal device 50 may be equipped with decoding means to acquire this encoded information from imaging means such as a camera (not shown) and decode the acquired encoded information. Here, the encoded information may be a one-dimensional code such as a barcode (e.g., EAN code, JAN code, Codbar, CODE128, etc.), a two-dimensional code (a stacked two-dimensional code (e.g., PDF417, CODE49, etc.)), or a matrix-type two-dimensional code (e.g., Quick Response Code (QR Code®), DataMatrix, VeriCode, Aztec, etc.).
[0047] [1.3 Processing Flow] Next, the processing flow according to the first embodiment will be described. Figure 4 is a flowchart illustrating the processing related to the acceptance of authorization according to the first embodiment. The processing described in Figure 4 is executed by the control unit 11 by reading the control program 211, authorization program 213 (authorization method determination program 2131, authorization information acquisition restriction program 2133, notification output program 2135), browser program 215, server program 217, etc.
[0048] The control unit 11 accepts the selection of an authorization method depending on whether or not input is received via the service setting screen displayed on either the browser screen of its own device or the browser screen of the external terminal device 50 (step S10).
[0049] The control unit 11 determines whether the accepted authorization method is the device flow method (step S13). The control unit 11 can determine that the authorization flow method has been selected as the authorization method if the provider selection is accepted via the browser screen of its own device. On the other hand, the control unit 11 can determine that the device flow method has been selected as the authorization method if the provider selection is accepted via the browser screen of the external terminal device 50.
[0050] If the control unit 11 determines that the accepted authorization method is the device flow method, it determines whether the provider selected as the authorization server supports the device flow method (step S13; Yes → step S15). In this case, the control unit 11 can determine whether the provider selected by the user supports the device flow method by referring to the setting items of the provided services (service settings) in the configuration information table illustrated in Figure 3.
[0051] On the other hand, if the control unit 11 determines that the accepted authorization method is not the device flow method, it proceeds to step S17 (step S13; No → step S17).
[0052] If the control unit 11 determines that the provider selected by the user supports the device flow method, it accepts a request to obtain authorization information (step S15; Yes → step S17).
[0053] Upon receiving a request to obtain authorization information, the control unit 11 refers to the connection settings item in the settings information table shown in Figure 3, sends the authorization request to the provider (service server 30) selected in step S10, and terminates the process (steps S17 → S19).
[0054] On the other hand, if it is determined that the provider selected by the user does not support the device flow method, the request for obtaining authorization information is restricted (step S15; No → step S21).
[0055] Next, the control unit 11 notifies the external terminal device 50 via its browser screen or the like, prompting it to select an authorization method other than the device flow method (authorization flow method) as the authorization method, and then terminates the process (step S23).
[0056] [1.4 Example of Operation] Prior to describing an example of operation according to the first embodiment, the authorization flow method and the device flow method as authorization methods relating to this disclosure will be explained with reference to Figure 5.
[0057] Figure 5 illustrates the exchange of commands, etc., between the multifunction device 10 and the service servers 30 (30a, 30b, ...) acting as authorization servers in either the authorization flow method (left side of the figure) or the device flow method (right side of the figure). In the following explanation, the service servers 30 (30a, 30b, ...) that perform authorization processing will be referred to as the authorization server 30.
[0058] First, let's explain the authorization flow method. In the authorization flow, authorization (authentication) processing takes place between the multifunction device 10 (a browser screen displayed on the operation panel, which is an example of the display unit 13) and the authorization server 30.
[0059] When authorization processing is initiated, the control unit 11 sends an authorization request to an authorization endpoint (not shown) of the authorization server 30 (1).
[0060] The authorization endpoint of the authorization server 30 returns the authorization screen as an authorization response to the redirect URL of the multifunction printer 10 (see Figure 3). Upon receiving the authorization screen, the multifunction printer 10 displays the authorization screen on the browser screen of its control panel (2).
[0061] The user of the multifunction printer 10 enters their authentication information, such as their login ID and password, on the authorization server 30 via the authorization screen displayed on the browser screen, and approves the authorization request for the multifunction printer 10 (3).
[0062] Upon accepting approval of the authorization request, the authorization decision endpoint (not shown) of the authorization server 30 issues an authorization code (4).
[0063] The multifunction printer 10 presents the issued authorization code to the token endpoint (not shown) of the authorization server 30 and requests an access token (5).
[0064] The token endpoint of the authorization server 30 verifies the validity of the presented authorization code and issues an access token to the multifunction printer 10 as a token response (6).
[0065] Next, the device flow method will be explained. In the device flow method, authorization (authentication) processing is performed between the external terminal device 50 (Web-UI not shown) and the authorization server 30.
[0066] When authorization processing is performed by the external terminal device 50, the control unit 11 of the multifunction printer 10 sends an authorization request to an unillustrated device authorization endpoint of the authorization server 30 (1).
[0067] The device authorization endpoint of the authorization server 30 returns an authorization response to the multifunction printer 10, which includes a device code (not shown), a user code, an end-user verification URL, etc. (2).
[0068] Upon receiving the authorization response, the multifunction printer 10 displays the user code and end-user verification URL included in the authorization response to the external terminal device 50 (3). If the displayed user code and end-user verification URL are, for example, QR codes (registered trademarks), the external terminal device 50 decrypts the user code and end-user verification URL by decrypting the QR code.
[0069] The external terminal device 50, having obtained the user code and the end-user verification URL, accesses the end-user verification endpoint specified by the end-user verification URL via a browser and enters its own authentication information such as login ID and password, as well as the obtained user code (4)'.
[0070] The authorization server 30 verifies the entered authentication information against the user code. If the authorization server 30 successfully verifies the authentication information against the user code, it returns an authorization screen to the external terminal device 50 to confirm whether or not to approve the authorization request for the multifunction printer 10.
[0071] At this time, after receiving the authorization response, the multifunction printer 10 repeatedly requests to obtain an access token by polling or other means until the final result is obtained (4).
[0072] When an authorization request is approved via the authorization screen displayed on the Web-UI of the external terminal device 50, the token endpoint of the authorization server 30 returns an access token to the multifunction device 10 as a token response (5).
[0073] Next, a specific example of operation according to the first embodiment will be described. Figure 6(a) is a diagram illustrating one example of the configuration of a service setting screen W10 corresponding to an authorization flow as the authorization method, displayed on the operation panel (browser screen) of the multifunction printer 10. Figure 6(b) is a diagram illustrating one example of the configuration of a service setting screen W20 corresponding to a device flow method as the authorization method, displayed on the Web-UI of an external terminal device 50. Note that the service setting screen W10 shown in Figure 6(a) and the service setting screen W20 shown in Figure 6(b) can have the same configuration, and will be described using common reference numerals.
[0074] The service settings screens W10 and W20 include the provider settings area R10. The provider settings area R10 includes an authentication method selection dropdown menu P10, a provider selection dropdown menu P12, an account name input box Bx10, and a token acquisition button B10 as a means of requesting authorization information.
[0075] The authentication method selection dropdown menu P10 is a dropdown menu that accepts the selection of a protocol related to authorization (authentication) processing. Figure 6 is an example where OAuth2.0 is selected as the protocol. The provider selection dropdown menu P12 is a dropdown menu that accepts the selection of a service server 30 (30a, 30b, ...) as the provider (authorization server). Figure 6 is an example where "Provider aaa" is selected as the provider (see Figure 3). The account name input box Bx10 is an input box that accepts the input of an account name for the provider ("Provider aaa") selected in the provider selection dropdown menu P12.
[0076] The token acquisition button B10 is a selection button that accepts a command to acquire an access token as authorization information. When the token acquisition button B10 receives a selection command, the control unit 11 starts the authorization process for the provider selected in the provider selection pull-down menu P12 ("Provider aaa").
[0077] Note that the service settings screen W20 illustrated in Figure 6(b) is a settings screen that supports the device flow method as an authorization method. Since the selected “provider aaa” is a provider that supports the device flow method (see Figure 3), there are no notifications prompting the user to select another authorization method, no restrictions on the display of the token acquisition button B10, and no changes to the display of the token acquisition button B10.
[0078] Figures 7(a) and 7(b) illustrate the case where "Provider bbb," which does not support the device flow method, is selected as the authorization method in the service setting screens W10 and W20, as illustrated in Figures 6(a) and 6(b).
[0079] As illustrated in Figure 7(a), the service settings screen W10 displayed on the operation panel (browser screen) of the multifunction printer 10 uses the authorization flow method. Therefore, even if "Provider bbb" is selected as the provider, there are no restrictions on the display of the token acquisition button B10, nor are there any changes to the display format.
[0080] On the other hand, the service settings screen W20 displayed on the Web-UI of the external terminal device 50, as exemplified in Figure 7(b), uses the device flow authorization method. Therefore, if "Provider bbb" is selected as the provider, notifications prompting the selection of another authorization method, restrictions on the display of the token acquisition button B10, and changes to the display pattern of the token acquisition button B10 are performed.
[0081] Figure 7(b) is an example of restricting the display of the token acquisition button B10 by superimposing a message M10 prompting the user to select an alternative authorization method onto the token acquisition button B10. Message M10 is an example of a message screen that prompts the user to select an alternative authorization method and states, "To enable OAuth authentication, you need to acquire a token. The selected provider cannot acquire a token from the device's web page, so please acquire a token by pressing the [Acquire] button in the same setting on the main unit's control panel."
[0082] As described above, according to the first embodiment, when a user selects an authorization process based on a device flow method as one authorization method using connection information, the authorization server determines whether or not it supports the device flow method. If the authorization server determines that it does not support the device flow method, it restricts the execution of authorization processing using the device flow method and outputs a notification prompting the user to select an authorization flow method other than the device flow method. This provides an image processing device that can reduce the risk of the authorization process being hindered due to the applicable authorization method.
[0083] [2 Second Embodiment] The second embodiment is a configuration in which, based on the capabilities or device settings of the multifunction printer 10, such as when the browser function is restricted, such as when the browser screen displayed on the operation panel of the multifunction printer 10 cannot be used, or when authorization processing by authorization flow on the multifunction printer 10 is not permitted, either the authorization flow method or the device flow method is set as the authorization method to the authorization server.
[0084] The functional configuration of the multifunction printer 10, service server 30 (30a, 30b, ...), and external terminal device 50 according to the second embodiment can be the same as in the first embodiment, so a detailed explanation is omitted here.
[0085] [2.1 Processing Flow] The processing flow according to the second embodiment is a replacement of the flowchart in Figure 4 of the first embodiment with the flowchart in Figure 8. Therefore, for processes identical to those described in Figure 4, the same step numbers are used and their descriptions are omitted.
[0086] The control unit 11 determines whether the received authorization method is an authorization flow method (step S30). If the control unit 11 determines that the received authentication method is an authorization flow, it determines whether the authorization flow is set to be active (step S30; Yes → step S32). If the control unit 11 determines that the received authentication method is not an authorization flow, it proceeds to step S15 in Figure 4 (step S30; No → “Go to step S15 in Figure 4”).
[0087] If the control unit 11 determines that the authorization flow method is enabled as the authorization method, it accepts an authorization information acquisition request (step S32; Yes → step S17). Upon receiving the authorization information acquisition request, the control unit 11 sends the authorization request to the provider (service server 30) selected in step S10 and terminates the process (step S17 → step S19).
[0088] On the other hand, if the control unit 11 determines that the authorization flow method is not enabled as an authorization method, for reasons such as restrictions on browser functionality or settings that do not allow authorization processing by authorization flow on the multifunction device 10, it restricts the request to obtain authorization information (step S32; No → step S21).
[0089] Next, the control unit 11 notifies the user via the operation panel (browser screen, etc.) of the multifunction printer 10 of a message prompting the user to select an authorization method other than the authorization flow method (device flow method) as the authorization method, and then terminates the process (step S23).
[0090] [2.2 Example of Operation] Next, an example of operation according to the second embodiment will be described. Figure 9(a) is a diagram illustrating an example configuration of the service setting screen W10 when it is determined that the authorization flow method is enabled as the authorization method in step S32 of Figure 8. Note that the service setting screen W10 illustrated in Figure 9(a) has the same configuration as the service setting screen W10 described in Figure 7(a), so its explanation is omitted here.
[0091] On the other hand, the service settings screen W10' illustrated in Figure 9(b) is a diagram illustrating one example of the configuration of the service settings screen W10' when it is determined in step S32 of Figure 8 that the authorization flow method is not set as the authorization method.
[0092] In the service settings screen W10' illustrated in Figure 9(b), since the authorization flow method is not enabled as the authorization method, if "Provider aaa" is selected as the provider, a notification prompting the user to select another authorization method will be displayed, the display of the token acquisition button B10 will be restricted, and the display of the token acquisition button B10 will be changed.
[0093] Figure 9(b) is an example of restricting the display of the token acquisition button B10 by superimposing a message M12 prompting the user to select an alternative authorization method onto the token acquisition button B10. Message M12 is an example of a message screen that prompts the user to select an alternative authorization method and states, "To enable OAuth authentication, you need to acquire a token. Please acquire a token from the device web page."
[0094] As described above, according to the second embodiment, if the authorization flow method is not enabled as the authorization method, a notification is output prompting the user to select a device flow method as an authorization method other than the authorization flow method. This reduces the risk that the authorization process may be hindered due to the applicable authorization method.
[0095] [3 Third Embodiment] The third embodiment is a configuration in which the user can select either an authorization flow method or a device flow method as the authorization method via the operation panel (browser screen) provided by the multifunction printer 10.
[0096] The functional configuration and processing flow of the multifunction printer 10, service server 30 (30a, 30b, ...), and external terminal device 50 according to the third embodiment can be the same as those of the first or second embodiment, so a detailed explanation is omitted here.
[0097] [3.1 Example of Operation] Figure 10 is a diagram illustrating an example configuration of the service setting screen W30 according to the third embodiment. Components identical to those in the service setting screen W10 described in Figure 6, etc., are denoted by the same reference numerals and their descriptions are omitted.
[0098] The service settings screen W30 includes the same configuration as the service settings screen W10, plus an authorization method selection dropdown menu P14 and a settings button B12.
[0099] The authorization method selection dropdown menu P14 is a dropdown menu that accepts the selection of an authorization method. Figure 10 shows an example where the "device flow" method is selected as the authorization method. The setting button B12 is a selection button that accepts confirmation instructions for the selection (input) operation in the provider setting area R10.
[0100] Figure 11 shows an example configuration of the authorization information display screen W40 displayed on the operation panel (browser screen) of the multifunction printer 10 when the device flow method is selected as the authorization method via the operation panel. The authorization information display screen W40 includes an authorization information display area R12.
[0101] Users can access the end-user verification endpoint specified by the end-user verification URL displayed in the authorization information display area R12 using an information processing device such as a smartphone or tablet. This allows them to input their login ID, password, and other authentication information, as well as the acquired user code. The user code and end-user verification URL may also be obtained by scanning the QR code (registered trademark) displayed in the authorization information display area R12.
[0102] As described above, according to the third embodiment, in addition to the effects of the first and second embodiments, it is possible to select either the authorization flow method or the device flow method as the authorization method via the operation panel (browser screen) provided by the multifunction device 10, thereby providing an image processing device with superior operability.
[0103] This disclosure is not limited to the embodiments described above, and various modifications are possible. That is, embodiments obtained by combining technical means that are appropriately modified without departing from the gist of this disclosure are also included in the technical scope of this disclosure.
[0104] Furthermore, although the embodiments described above are explained separately for the sake of explanation, it goes without saying that they may be combined and implemented to the extent that is technically possible.
[0105] Furthermore, in the embodiments, the programs that run in each device are programs that control the CPU and the like (programs that make the computer function) in order to realize the functions of the embodiments described above. The information handled by these devices is temporarily stored in a temporary storage device (for example, RAM) during processing, and then stored in storage devices such as various ROMs (Read Only Memory) and HDDs, and read, modified, and written by the CPU as needed.
[0106] Here, the computer-readable non-transient recording medium on which the program in the information processing device is recorded may be any of the following: semiconductor media (e.g., ROM, non-volatile memory card, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray® Disc, etc.)), magnetic recording media (e.g., magnetic tape, flexible disk, etc.). In this case, the program recorded on the recording medium is read by the computer of the information processing device and executed by the computer, thereby realizing the functions of the embodiments described above. Furthermore, the functions of this disclosure are realized by processing in cooperation with the operating system or other application programs, etc., based on the instructions of the program.
[0107] Furthermore, when distributing the program to the market, it can be stored on a portable storage medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is, of course, also included in this disclosure.
[0108] Furthermore, each functional block or feature of the apparatus used in the embodiments described above can also be implemented and executed by an electrical circuit, such as an integrated circuit or a plurality of integrated circuits. An electrical circuit designed to realize the functions described herein may include a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or tronograph logic, discrete hardware components, or a combination thereof. The general-purpose processor may be a microprocessor, a conventional processor, controller, microcontroller, or state machine. The aforementioned electrical circuit may consist of digital circuits or analog circuits. Also, if advances in semiconductor technology lead to the emergence of integrated circuit technologies that replace current integrated circuits, one or more aspects of this disclosure may use new integrated circuits based on such technologies. [Explanation of symbols]
[0109] 11 Control Unit 13 Display section 15 Operation Input Section 17 Communications Department 19 Image Processing Unit 191 Image forming unit 193 Image Input Section 21 Memory section 211 Control Program 213 Authorization Programs 2131 Approval Method Determination Program 2133 Authorization Information Acquisition Restriction Program 2135 Notification Output Program 215 Browser Programs 217 Server Programs 219 Configuration Information Storage Area
Claims
1. An image forming apparatus that executes instructions related to authorization processing received on a settings screen displayed on an external device based on screen information provided to the external device, The image forming apparatus is The external device receives and executes instructions to send connection information to the authorization server, which consists of one or more servers selected on the settings screen, based on the HTTPS protocol, to the authorization server. The URL received from the authorization server is displayed on the external device. If the authorization process based on the code related to the user of the external device to the authorization server indicated by the URL is successful, information indicating that the authorization process was successful is received from the authorization server selected on the settings screen. An image forming apparatus characterized by displaying information indicating that the authorization process was successful on the external device.
2. The image forming apparatus is The image forming apparatus according to claim 1, characterized in that the URL is displayed on the external device together with a display prompting the authorization process.
3. The image forming apparatus is The image forming apparatus according to claim 1, characterized in that the aforementioned URL is displayed on the external device as encoded information.
4. The image forming apparatus is The image forming apparatus according to claim 1, characterized in that the status of token acquisition before the authorization process is performed is displayed on the external device.
5. The image forming apparatus is The image forming apparatus according to claim 1, characterized in that the authentication method selected on the settings screen and information related to the authorization server are displayed on the same screen of the external device.
Citation Information
Patent Citations
Information processing system, control method, and service providing device
JP2017010266A
Information processing system, control method thereof, and program
JP2019139520A
Authorization server device, processing method of authorization server device, and program
JP2022054025A
Enhanced security for device authorization for browserless or input-constrained devices
US20230291723A1
Information processing device and information processing device control method
JP2021152835A