System and method

The system addresses the issue of unauthorized remote repairs by implementing consent code verification, ensuring only authorized operators can perform remote repairs, thus enhancing the reliability of maintenance operations.

JP2026075979APending Publication Date: 2026-05-11CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2024-10-23
Publication Date
2026-05-11

AI Technical Summary

Technical Problem

Existing systems for remote repair of image forming apparatuses lack proper authority management, allowing unauthorized operators to perform settings changes, which can lead to unresolved issues or new problems.

Method used

A system that includes a network device and a device management system with features for generating a consent code, managing notification information, and verifying administrator consent before granting remote repair authority to authorized operators.

Benefits of technology

Ensures that only authorized operators can perform remote repairs, improving the effectiveness and reliability of remote maintenance operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026075979000001_ABST
    Figure 2026075979000001_ABST
Patent Text Reader

Abstract

The aim is to improve the implementation of remote repairs for devices. [Solution] The system is characterized by having means for receiving a request from a user to initiate remote repair of an error that occurred on a network device; means for generating a consent code to confirm consent to the remote repair in response to the request to initiate the remote repair, and adding notification information including the generated consent code to a notification information data table that manages notification information regarding the error; means for notifying the administrator of the network device of the generated consent code; means for obtaining a consent code from the administrator; means for verifying the consent code obtained from the administrator; and, if the verification is successful, means for granting the user who requested the initiation of the remote repair the authority to perform remote repair limited to the network device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a system and a method.

Background Art

[0002] Generally, in an image forming apparatus under a maintenance contract, it is known that a customer administrator of the image forming apparatus contacts a call center for trouble shooting, and a remote operator at the call center responds to the report. At this time, when the remote operator determines that a setting change of the image forming apparatus is necessary to resolve the trouble, it is necessary to dispatch a service technician to the trouble site. On the other hand, due to reasons such as suppression of dispatch costs and early resolution of troubles, there is a need for a remote operator to respond to troubles occurring in an image forming apparatus from a management apparatus at a remote location without going to the site.

[0003] As an approach to such a need, an information processing system is known that permits remote operation from a management apparatus to an image forming apparatus by pressing a connection permission button on the screen of the image forming apparatus (Patent Document 1). Hereinafter, the remote operator at the call center remotely operates information collection of the image forming apparatus, setting change of the image forming apparatus, etc. to resolve trouble reports of the image forming apparatus, which is defined as "remote repair".

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Patent Document 1 describes a system in which the customer administrator of an image forming apparatus who reports a problem authorizes remote repair of the image forming apparatus, but it does not limit the authority of the remote operator handling the call. Therefore, if remote repairs such as changing the settings of the image forming apparatus are performed separately by another remote operator, there is a possibility that the expected problem will not be resolved, or that other problems may be induced.

[0006] Therefore, there has traditionally been room for improvement in implementing remote repairs for devices such as image forming machines.

[0007] This invention has been made in view of the above-mentioned problems, and aims to improve the implementation of remote repairs for devices. [Means for solving the problem]

[0008] A system according to one embodiment of the present invention is a system including a network device and a device management system, characterized by having means for receiving a request from a user to initiate remote repair of an error occurring in the network device; means for generating a consent code to confirm consent to the remote repair in response to the request to initiate the remote repair, and adding notification information including the generated consent code to a notification information data table that manages notification information regarding the error; means for notifying the administrator of the network device of the generated consent code; means for obtaining a consent code from the administrator; means for verifying the consent code obtained from the administrator; and, if the verification is successful, means for granting the user who made the request to initiate the remote repair the authority to perform remote repair limited to the network device. [Effects of the Invention]

[0009] According to the present invention, improvements can be made to the implementation of remote repairs on devices. [Brief explanation of the drawing]

[0010] [Figure 1] This is a block diagram showing the overall configuration of the system according to Embodiment 1 of the present invention. [Figure 2] This is a block diagram showing the hardware configuration of a system according to Embodiment 1 of the present invention. [Figure 3] This is a block diagram showing the software configuration of the system according to Embodiment 1 of the present invention. [Figure 4] This figure shows the overall processing sequence of the system according to Embodiment 1 of the present invention. [Figure 5] This figure shows the overall processing sequence of the system according to Embodiment 1 of the present invention. [Figure 6] This figure shows a flowchart of the notification information creation process according to Embodiment 1 of the present invention. [Figure 7] This figure shows the notification information list confirmation screen according to Embodiment 1 of the present invention. [Figure 8] This figure shows the remote repair consent screen according to Embodiment 1 of the present invention. [Figure 9] This figure shows a flowchart of the consent code verification process according to Embodiment 1 of the present invention. [Figure 10] This figure shows a flowchart of the remote repair job creation request control process according to Embodiment 1 of the present invention. [Figure 11] This figure shows a screen related to remote repair job creation according to Embodiment 1 of the present invention. [Figure 12] This figure shows the notification information operation related screen according to Embodiment 2 of the present invention. [Figure 13] This figure shows the notification information operation related screen according to Embodiment 2 of the present invention. [Figure 14] This diagram shows a flowchart of the notification response transfer process according to Embodiment 2 of the present invention. [Figure 15] This figure shows a flowchart of the notification information creation process according to Embodiment 3 of the present invention. [Figure 16] This figure shows the input screen of the target device according to Embodiment 3 of the present invention. [Figure 17] It is a diagram showing a flowchart of consent code verification processing according to Embodiment 3 of the present invention. [Figure 18] It is a diagram showing a flowchart of consent code verification processing according to Embodiment 4 of the present invention. [Figure 19] It is a diagram showing a processing sequence of the entire system according to Embodiment 5 of the present invention. [Figure 20] It is a diagram showing a processing sequence of the entire system according to Embodiment 5 of the present invention. [Figure 21] It is a diagram showing a screen related to remote repair request according to Embodiment 5 of the present invention. [Figure 22] It is a diagram showing a flowchart of notification information creation processing according to Embodiment 5 of the present invention. [Figure 23] It is a diagram showing a screen for confirming a list of notification information according to Embodiment 5 of the present invention.

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the present invention according to the claims, and not all combinations of the features described in the present embodiment are essential for the solution of the present invention. Also, the same reference numerals are assigned to the same components, and the description thereof will be omitted.

[0012] For the implementation of remote repair, proper authority management is required such that only a remote operator who has been permitted by the customer administrator of a device such as an image forming apparatus to perform reporting response can perform remote repair only on the device permitted by the customer administrator. The customer administrator of a device such as an image forming apparatus is an example of a device administrator. For example, a system can be considered in which user management is performed including a remote operator and a call center to which the remote operator belongs, and the administrator of the image forming apparatus can issue browsing authority to specific users.

[0013] However, in remote repairs, remote operators are required to respond as quickly as possible by the customer administrator of the image forming apparatus, so it is desirable that authorization for remote repairs be issued quickly and appropriately. In an embodiment of the present invention, a system is provided that enables appropriate authorization management so that only the remote operator responding to the notification can perform remote repairs on the device targeted by the notification, even within the limited time available for responding to a notification.

[0014] <Embodiment 1> [Overall System Configuration] Figure 1 is a block diagram showing the overall configuration of a system according to Embodiment 1 of the present invention. As shown in Figure 1, the system 10 includes an image forming apparatus 100, a remote repair service server 101, a remote control service server 102, a PC 103, and a network 104. PC is an abbreviation for Personal Computer. The image forming apparatus 100, the remote repair service server 101, the remote control service server 102, and the PC 103 are connected via the network 104. The image forming apparatus 100 is an example of a device. The image forming apparatus 100 is also an example of a network device. The remote repair service server 101, the remote control service server 102, the PC 103, and the network 104 are an example of a device management system that manages the image forming apparatus 100, which is a device.

[0015] The image forming apparatus 100 is an example of an image processing device such as an MFP (Multi-Function Peripheral) or printer, and is equipped with functions such as printing, faxing, and image transmission. The image forming apparatus 100 also executes these functions on a job-by-job basis. Hereafter, jobs performed by the image forming apparatus 100 that perform functions such as printing, faxing, and image transmission will be defined as "device jobs." The image forming apparatus 100 is subject to remote repair.

[0016] A device job consists of a device job ID that uniquely identifies the device job itself, a device job type, the time of execution, an exit code that uniquely indicates the execution result, and information on the execution conditions. This information is stored as history information. The device job type is information that indicates the function of the executed job, such as a fax job, print job, or transmit job. The execution conditions are information about the conditions under which the device job was executed, such as the print size and number of pages when executing a print job. By using these execution conditions, it is possible to re-execute the executed device job.

[0017] The remote repair service server 101 is an information processing device that provides services for managing trouble notification information and remote repair information for the image forming apparatus 100. Trouble that occurs in the image forming apparatus 100 is also referred to as an error. The remote repair service server 101 receives a remote repair request for the image forming apparatus 100 from the PC 103 and performs remote repair by issuing control instructions to the remote control service server 102 for the image forming apparatus 100. In this embodiment, a job that issues such control instructions for performing remote repair will be defined as a "remote repair job." The remote repair service server 101 manages trouble notifications that occur in the image forming apparatus 100 as notification information, issues a remote repair job linked to the notification information, and then transmits the notification information and remote repair job information to the PC 103.

[0018] The remote control service server 102 provides services for remotely controlling the image forming apparatus 100, such as changing its configuration information and collecting the history of executed device jobs. The remote control service server 102 receives control instruction requests for the image forming apparatus 100 from the remote repair service server 101 and remotely controls the image forming apparatus 100 according to the requests. The remote control service server 102 also receives control instruction results from the image forming apparatus 100 and transmits the execution results to the remote repair service server 101.

[0019] PC103 is an example of an information processing device with a specified OS (not shown) installed. OS stands for Operating System.

[0020] Network 104 refers to communication networks such as LANs (Local Area Networks), WANs (Wide Area Networks), telephone lines, and dedicated digital lines, as well as combinations thereof. LAN stands for Local Area Network. WAN stands for Wide Area Network.

[0021] In this embodiment, it is assumed that the customer administrator of the image forming apparatus 100 notices an error in the device job of the image forming apparatus 100 and notifies the call center. At that time, it is assumed that the call center's remote operator communicates with the remote repair service server 101 using PC 103 and responds to the notification via remote repair. Based on the above, the customer administrator who notified the image forming apparatus 100 will be defined as the "customer administrator," and the remote operator who performs the remote repair at the call center will be defined as the "remote operator."

[0022] [Hardware configuration] Figure 2 is a block diagram showing the hardware configuration of system 10 according to Embodiment 1 of the present invention. Figure 2(A) shows the hardware configurations of the remote repair service server 101, the remote control service server 102, and the PC 103.

[0023] 201 is a CPU that directly or indirectly controls each device (ROM, RAM, etc., described later) connected via the internal bus and executes a program according to an embodiment of the present invention. ROM is an abbreviation for Read Only Memory. RAM is an abbreviation for Random Access Memory. CPU is an abbreviation for Central Processing Unit. 202 is a ROM in which the BIOS is stored. BIOS is an abbreviation for Basic Input Output System. 203 is RAM (direct memory) that is used as a work area for CPU 201 or as temporary storage for loading software modules according to an embodiment of the present invention.

[0024] 204 refers to an indirect storage device such as an HDD (hard disk drive) or SSD (solid state drive) that stores the basic software, including the operating system and software modules.

[0025] 205 is an input device, such as a keyboard or pointing device (not shown). 206 is an output device to which a display is connected. 207 is an interface (I / F) for connecting to network 104. I / F is an abbreviation for interface.

[0026] In the remote repair service server 101, remote control service server 102, and PC 103, after startup, the CPU 201 executes the BIOS and loads the OS from the HDD 204 into RAM 203 in an executable state. The CPU 201 loads various software modules, described later, from the HDD 204 into RAM 203 in an executable state as needed, according to the operation of the OS. The various software modules are executed and operated by the CPU 201 in cooperation with the above devices. In addition, the I / F 207 is connected to the network 104 and is controlled by the CPU 201 according to the operation of the OS, enabling communication using the communication means described above.

[0027] Figure 2(B) shows the hardware configuration of the image forming apparatus 100. The image forming apparatus 100 has a controller unit 211, which controls the scanner 221, printer 222, and operation unit 217.

[0028] When a user uses the copy function, the controller unit 211 controls the scanner 221 to acquire image data of the original document and controls the printer 222 to print the image onto paper. When a user uses the scan function, the controller unit 211 controls the scanner 221 to acquire image data of the original document, converts it into code data, and transmits it to an external device (not shown) via the network interface 218.

[0029] The controller unit 211 consists of a CPU 212, RAM 213, ROM 214, HDD 215, control interface 216, network interface 218, and device interface 219, which are connected by a system bus 220.

[0030] The CPU 212 controls the entire system of the image forming apparatus 100. The RAM 213 is the system work memory for the operation of the CPU 212 and is an image memory for temporarily storing image data. The RAM 213 also stores programs and data such as the operating system, system software, and application software. Furthermore, the RAM 213 stores scanned image data read by the scanner 221 and print data received via the network 104. The ROM 214 stores the system's boot program.

[0031] HDD215 stores the operating system, system software, application software, print data, configuration data, etc. The image forming apparatus 100 is assigned a serial number that uniquely identifies the image forming apparatus 100 itself, and this serial number is permanently stored in HDD215 in a unique ID format. Hereafter, the unique serial number of the image forming apparatus 100 will be defined as the "device ID".

[0032] The control unit I / F 216 is the interface unit with the control unit 217 and outputs information to be displayed on the control unit 217. It also receives information input by the user from the control unit 217. The network I / F 218 controls various communications with external devices via the network 104. The device I / F 219 connects the scanner 221 and printer 222, which perform image data reading and printing, to the controller unit 211 and performs image data input and output.

[0033] The scanner 221 has a document glass that detects the paper size of the document placed on the document glass and reads the document placed on the document glass to generate image data. The printer 222 prints the instructed print data on paper.

[0034] [Software configuration and network connection configuration] Figure 3 is a block diagram showing the software configuration of system 10 according to Embodiment 1 of the present invention.

[0035] The remote repair service server 101 has a remote repair application 300. The remote repair application 300 is a web service application stored on the HDD 204 and executed by the CPU 201. The remote repair application 300 consists of a communication unit 301, a display information generation unit 302, a user authentication unit 303, a notification information management unit 304, a consent code generation unit 305, a remote repair job information management unit 306, and a control instruction information generation unit 307.

[0036] The communication unit 301 communicates with the image forming apparatus 100, the remote control instruction server 102, and the PC 103. The display information generation unit 302 generates screen display information for sending and receiving information related to remote repair. The screen display information is generated in a language that can be parsed by a web browser, such as HTML, and is transmitted via the communication unit 301. HTML is an abbreviation for HyperText Markup Language. is an abbreviation for World Wide Web.

[0037] The user authentication unit 303 manages user information for the remote repair application 300 and verifies through authentication operations whether user information exists that matches the user ID and authentication information transmitted from the communication unit 301. The authentication operations performed by the user authentication unit 303 are not limited to specific authentication methods such as matching user ID and password or biometric authentication.

[0038] The notification information management unit 304 receives a request from the communication unit 301 to initiate remote repair, creates notification information, and manages it as a notification information data table on the HDD 204. An example of a notification information data table according to this embodiment is shown in Table 1. [Table 1]

[0039] The report information data table contains a "Report Information ID." The "Report Information ID" is an attribute that indicates a value used to uniquely identify the report information.

[0040] The notification information data table has a "Status" attribute. "Status" is an attribute that indicates the status of the notification information. When notification information is created, "Awaiting Agreement" is stored in "Status". When the customer administrator agrees to remote repair in response to the notification, "Agreement" is stored in "Status". When the notification response via remote repair is completed, "Response Completed" is stored in "Status".

[0041] The notification information data table contains a "consent code." The "consent code" is an attribute that indicates a value used to consent to remote repair in response to the notification information. The consent code is generated by the consent code generation unit 305. When the consent code is transmitted from the image forming apparatus 100, it is considered that the customer administrator has given consent to the notification, and the "status" is updated from "awaiting consent" to "consented."

[0042] The notification information data table contains a "Responding User ID". The "Responding User ID" is an attribute that indicates the user ID of the remote repair application 300 that created the notification information, and is used to identify the user who is authorized to perform remote repair operations on the notification information. In the case of Table 1, only "UserA" can perform remote repair operations on notification information where the "Notification Information ID" is "Notice_000".

[0043] The notification information data table contains a "Remote Repair Authorized Device ID." The "Remote Repair Authorized Device ID" is an attribute indicating the device ID of the image forming apparatus 100 that agreed to remote repair in response to the notification information, and is described in JSON format. JSON is an abbreviation for JavaScript Object Notation.

[0044] Remote repair operations using the "Corresponding User ID" are permitted only for the image forming apparatus 100 corresponding to the device ID listed in the "Remote Repair Authorized Device ID". In the case of Table 1, the remote repair operation for the notification information with "Notice_000" as the "Notification Information ID" is only permitted for "DeviceA".

[0045] Note that it is possible to set multiple device IDs for the "Remote Repair Authorized Device ID". For example, in Table 1, the targets of the remote repair operation for the notification information with "Notice_002" as the "Notification Information ID" are "DeviceB" and "DeviceC" as listed in the "Remote Repair Authorized Device ID".

[0046] The consent code generation unit 305 receives an instruction from the notification information management unit 304 to generate a consent code and generates the "consent code" value in the notification information data table shown in Table 1. The generated consent code is always a unique value that does not overlap with any other value in the notification information data table shown in Table 1.

[0047] The remote repair job information management unit 306 receives a request from the communication unit 301 to create a remote repair job, creates the remote repair job information, and manages it as a remote repair job information data table on the HDD 204. An example of the remote repair job information data table according to this embodiment is shown in Table 2. [Table 2]

[0048] The remote repair job information data table contains a "Remote Repair Job ID". The "Remote Repair Job ID" is an attribute that indicates a value used to uniquely identify remote repair job information.

[0049] The remote repair job information data table has a "Remote Repair Job Type" attribute. "Remote Repair Job Type" is an attribute that indicates the type of control request made to the image forming apparatus 100 by the remote repair job. If the request is to collect device job history information of the image forming apparatus 100, "Collection" is stored in "Remote Repair Job Type". If the request is to diagnose the device jobs of the image forming apparatus 100, "Diagnosis" is stored in "Remote Repair Job Type". If the request is to change the settings of the image forming apparatus 100, "Action" is stored in "Remote Repair Job Type". If the request is to re-execute the device jobs of the image forming apparatus 100, "Verification" is stored in "Remote Repair Job Type".

[0050] The remote repair job information data table has a "Status" attribute. "Status" is an attribute that indicates the status of the remote repair job information. In this embodiment, when a remote repair job is created, "Running" is stored in "Status". Also, when the execution of the remote repair job is completed, "Completed" is stored in "Status".

[0051] The remote repair job information data table has a "Related Notification Information ID". The "Related Notification Information ID" is an attribute that indicates the notification information ID of the notification information corresponding to the remote repair job. In the case of Table 2, the related notification information ID of the remote repair job information for which the "Remote Repair Job ID" is "Job_000" corresponds to the notification information for which the "Notification Information ID" is "Notice_000" in Table 1.

[0052] The remote repair job information data table contains "control instruction information." "Control instruction information" is an attribute that indicates an instruction that the image forming apparatus 100 can interpret in order to execute a remote repair job, and is written in JSON format. The "id" in the "script" element is an element that indicates a value for uniquely identifying the control information. "deviceId" is an element that indicates the device ID of the image forming apparatus 100 that is to be controlled. The "name" in the "command" element is the command that indicates the control instruction. The "parameter" element contains elements that show the details of the control instruction described in "name."

[0053] In Table 2, the "Control Instruction Information" for "Remote Repair Job ID" "Job_000" states that "DeviceA" is instructed to collect "2" device jobs of "Image Transmission Type". The "Control Instruction Information" for "Remote Repair Job ID" "Job_001" states that "DeviceB" is instructed to diagnose the device job corresponding to "DeviceJob_100". The "Control Instruction Information" for "Remote Repair Job ID" "Job_002" states that "DeviceB" is instructed to change the setting value of "Destination Domain Restriction" to OFF. The "Control Instruction Information" for "Remote Repair Job ID" "Job_003" states that "DeviceB" is instructed to re-execute the device job corresponding to "DeviceJob_100".

[0054] The remote repair job information data table contains "control instruction execution result information." "Control instruction execution result information" is an attribute that indicates the result of the image forming apparatus 100 executing the control instruction, and is described in JSON format.

[0055] In Table 2, the "Control Instruction Execution Result Information" for "Remote Repair Job ID" "Job_000" contains the execution history information of the device job as the result of collecting the device job history. The "Control Instruction Execution Result Information" for "Remote Repair Job ID" "Job_001" contains the code indicating the diagnostic result and the recommended action as the result of diagnosing the device job. The "Control Instruction Execution Result Information" for "Remote Repair Job ID" "Job_002" contains the details of the successful configuration change as the result of changing the configuration. The "Control Instruction Execution Result Information" for "Remote Repair Job ID" "Job_003" contains the execution result information of the re-executed device job as the result of re-executing the device job.

[0056] The control instruction information generation unit 307 receives an instruction from the remote repair job information management unit 306 to generate control instruction information and generates the value of "control instruction information" in the remote repair job information data table shown in Table 2.

[0057] The remote control service server 102 has a remote control application 310. The remote control application 310 is a web service application stored in the HDD 204 and executed by the CPU 201. The remote control application 310 consists of a communication unit 311, a control instruction information management unit 312, and a control instruction execution result management unit 313.

[0058] The communication unit 311 communicates with the image forming apparatus 100 and the remote repair service server 101. The control instruction information management unit 312 stores the control instruction information received from the communication unit 311 in the HDD 204. In addition, when the control instruction information management unit 312 receives a request to acquire control instruction information from the image forming apparatus 100 via the communication unit 311, it acquires the control instruction information corresponding to the device ID of the image forming apparatus 100 and transmits it to the communication unit 311.

[0059] The control instruction execution result management unit 313 saves the control instruction execution results received via the communication unit 311 to the HDD 204. The control instruction execution result management unit 313 also transmits the control instruction execution results to the remote repair application 300 via the communication unit 311.

[0060] The image forming apparatus 100 has a repair client application 320 and a control client application 330. The repair client application 320 is an application stored in the HDD 215 and executed by the CPU 212. The repair client application 320 consists of a communication unit 321, a display information generation unit 322, and a transmission information generation unit 323.

[0061] The communication unit 321 communicates with the remote repair service server 101. In response to notifications from the remote repair service server 101, the communication unit 321 also changes the setting value of the control instruction confirmation cycle, which is the period during which the control instructions stored in the HDD 215 are checked.

[0062] The display information generation unit 322 generates screen information to be displayed on the operation unit 217 and displays it on the screen via the operation unit I / F 216. In this embodiment, the display information generation unit 322 generates information for the remote repair consent screen for the customer administrator to enter a consent code.

[0063] The transmission information generation unit 323 generates transmission information, which is information to be sent to the remote repair service server 101 via the communication unit 321. In this embodiment, the transmission information generation unit 323 generates transmission information that includes the consent code entered by the customer administrator in the operation unit 202 and the device ID of the image forming apparatus 100.

[0064] The control client application 330 is an application stored in the HDD 215 and executed by the CPU 212. The control client application 330 consists of a communication unit 331, an instruction information analysis unit 332, an information collection instruction unit 333, a diagnostic instruction unit 334, a setting change instruction unit 335, and an execution instruction unit 336.

[0065] The communication unit 331 communicates with the remote control service server 102. The communication unit 331 also periodically retrieves control instructions from the remote control service server 102 at timings according to the control instruction confirmation cycle setting configured in the HDD 215. If the communication unit 331 successfully retrieves a control instruction during the control instruction confirmation cycle, it sends the control instruction to the instruction information analysis unit 332.

[0066] Furthermore, the instruction information analysis unit 332 analyzes the control instruction received from the communication unit 331 and issues instructions to the collection instruction unit 333, the diagnostic instruction unit 334, the setting change instruction unit 335, and the execution instruction unit 336. In addition, the instruction information analysis unit 332 receives the control instruction execution result, which is the result of executing the control instruction, and transmits the control instruction execution result to the remote control service server 102 via the communication unit 331.

[0067] The collection instruction unit 333 receives a device job history collection instruction from the instruction information analysis unit 332 and collects device job history information stored in the HDD 215. When collecting, the collection instruction unit 333 collects device job history information that matches the collection conditions received from the instruction information analysis unit 332. The collection instruction unit 333 also transmits the collected device job history information to the instruction information analysis unit 332 as the result of executing a control instruction.

[0068] The diagnostic instruction unit 334 receives a device job diagnostic instruction from the instruction information analysis unit 332 and performs a diagnosis of the device job. In performing the diagnosis, the diagnostic instruction unit 334 obtains device job information corresponding to the device job ID received from the instruction information analysis unit 332 from the HDD 215 and performs the diagnosis based on the exit code and device job type. The diagnostic instruction unit 334 also derives information on the expected error cause and candidate countermeasures as a result of the diagnosis. The diagnostic instruction unit 334 then transmits the diagnosis result to the instruction information analysis unit 332 as the control instruction execution result.

[0069] The setting change instruction unit 335 receives a device setting change instruction from the instruction information analysis unit 332 and changes the setting information of the image forming apparatus 100 stored in the HDD 215. The setting information of the image forming apparatus 100 refers to settings related to the operation of the image forming apparatus 100, such as network restriction settings and destination restrictions when sending faxes. The setting change instruction unit 335 also transmits the result of the setting change execution as a control instruction execution result to the instruction information analysis unit 332.

[0070] The execution instruction unit 336 receives a device job execution instruction from the instruction information analysis unit 332 and re-executes the specified device job. For re-execution, it obtains device job information corresponding to the device job ID received from the instruction information analysis unit 332 from the HDD 215 and re-executes the device job based on the execution conditions. The execution instruction unit 336 also transmits information about the re-executed device job to the instruction information analysis unit 332 as the control instruction execution result.

[0071] PC103 has a browser 340. Browser 340 is a web browser stored on HDD204 and run by CPU201, and is intended to be operated by a remote operator. Browser 340 communicates with the remote repair service server 101 to request the start of remote repairs and the creation of remote repair jobs.

[0072] [Processing Sequence] Figure 4 is a diagram showing the overall processing sequence of system 10 according to Embodiment 1 of the present invention. Figure 5 is a diagram showing the overall processing sequence of system 10 according to Embodiment 1 of the present invention, and is a follow-up to Figure 4. In this embodiment, it is assumed that the notification information data table is in the state shown in Table 1 and the remote repair job information data table is in the state shown in Table 2 when the sequences in Figures 4 and 5 are started. Furthermore, in the processing sequences in Figures 4 and 5, the device ID of the image forming apparatus 100 is "DeviceD", and the user ID of the remote operator performing the remote repair is "UserD".

[0073] In step S401, a device job execution error occurs in the image forming apparatus 100, and the customer administrator of the image forming apparatus 100 contacts a remote operator at the call center by telephone to report the problem. In step S402, the remote operator receives the trouble report from the customer administrator and confirms the details of the problem that occurred in the image forming apparatus 100 through a phone call with the customer administrator.

[0074] In step S403, the remote operator operates the browser 340 and sends a login request to the remote repair application 300 by entering the user ID and authentication information on the login screen (not shown) generated by the display information generation unit 302. The remote operator is an example of a user.

[0075] In step S404, the remote repair application 300 performs an authentication operation using the user ID and authentication information transmitted in step S403, and if authentication is successful, provides authorization information to the remote operator. The remote operator receives the authorization token as authorization information via the browser 340. In this embodiment, it is assumed that the authentication of the remote operator's user ID, "UserD", has been successfully verified in step S404.

[0076] In step S405, the remote operator operates the browser 340 and sends a request to initiate remote repair to the remote repair service application 300, along with the authorization token received in step S404. The process in step S405 is an example of a means of receiving a request from a user to initiate remote repair of an error that occurred in the network device.

[0077] From step S406 to step S407, a notification information creation process is performed to create notification information including consent code information for obtaining permission for remote repair from the customer administrator of the image forming apparatus 100. The notification information creation process will be explained using Figure 6. The notification information creation process is an example of a means for generating a consent code in response to a request to start the remote repair and adding the notification information including the generated consent code to a notification information data table that manages notification information regarding the error. The consent code is an example of a code for confirming consent to the remote repair.

[0078] Figure 6 is a flowchart showing the notification information creation process according to Embodiment 1 of the present invention. In step S501, the communication unit 301 determines whether a remote repair start request has been made from the PC 103 operated by the remote operator. If the communication unit 301 determines that a remote repair request has been made, the process in step S502 is executed. If the communication unit 301 determines that no remote repair request has been made, the process in the flowchart of Figure 6 ends. In this embodiment, since a remote repair start request was made in step S405, the process in step S406 is executed and notification information is created.

[0079] The process in step S502 is executed when it is determined in step S501 that a remote repair start request has been made. In step S502, the user authentication unit 303 obtains the user information of the user who requested the remote repair start from the authorization information transmitted from the communication unit 301. In this embodiment, it is assumed that in step S502, the information of "UserD", which is the user ID of the remote operator, has been obtained.

[0080] In step S503, the consent code generation unit 305 generates a consent code. In this embodiment, it is assumed that the consent code "67891234" is generated in step S503.

[0081] In step S504, the notification information management unit 304 creates notification information using the user information obtained in step S502 and the consent code generated in step S503, and adds it to the notification information data table. Table 3 shows the notification information data table in Table 1 with the notification information created in step S504 added. [Table 3]

[0082] In the notification information data table in Table 3, notification information with notification information ID "Notice_003" is added to the notification information data table in Table 1. In Table 3, the "Status" of the notification information with notification information ID "Notice_003" stores "Awaiting Consent," indicating that the customer has not yet given consent for remote repair. The "Consent Code" of the notification information with notification information ID "Notice_003" stores "67891234," the value generated in step S503. The "Responding User ID" of the notification information with notification information ID "Notice_003" stores "UserD," the user ID obtained in step S502. The "Remote Repair Authorized Device ID" of the notification information with notification information ID "Notice_003" stores a value indicating that there is no authorized device ID yet.

[0083] In step S505, the notification information management unit 304 retrieves all of the notification information data table in Table 3. In step S506, the notification information management unit 304 identifies the notification information for which the user ID obtained in step S502 corresponds to the user ID. In this embodiment, in step S502, only the notification information with notification information ID "Notice_003" is identified.

[0084] In step S507, the display information generation unit 302 generates a notification information list confirmation screen and transmits it to the PC 103 via the communication unit 301, displaying the screen to the remote operator. The display information generation unit 302 generates the notification information list confirmation screen with the consent code masked for notification information other than the user response notification information identified in step S506. The notification information list confirmation screen will now be explained using Figure 7.

[0085] Figure 7 shows a notification information list confirmation screen according to Embodiment 1 of the present invention. The notification information list confirmation screen 600 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340.

[0086] The notification information list display area 601 is an area that displays the notification information data table. In this embodiment, the information in Table 3 is displayed in the notification information list display area 601. The remote repair job creation buttons 610, 611, 612, and 613 are buttons that request the creation of a remote repair job related to the notification information. Note that the remote repair job creation buttons 610, 611, 612, and 613 can only be pressed when the "status" of the notification information is "agreement". Therefore, in the example in Figure 7, the remote repair job creation buttons 611, 612, and 613 cannot be pressed.

[0087] The notification response end buttons 620, 621, 622, and 623 are buttons that request the end of the notification information response. These buttons can only be pressed when the "status" of the notification information is "agreemented" or "awaiting agreement." Therefore, in the example in Figure 7, the notification response end button 623 cannot be pressed.

[0088] Now, let's return to the explanation of Figure 6. As described above, the notification information creation process in Figure 6 creates the notification information, and the consent code information for obtaining permission for remote repair is provided to the remote operator on the notification information list confirmation screen 600. In addition, on the notification information list confirmation screen 600, all consent codes other than those of the notification information created by the operator are masked, thus preventing the remote consent codes of notification information created by other remote operators from being revealed.

[0089] Now, let's return to the explanation of Figure 4. In step S408, the remote operator contacts the customer administrator by phone to request their consent for remote repair by inputting the notification information consent code into the image forming apparatus 100. In this embodiment, the remote operator requests the customer administrator to input "67891234" displayed in the notification information list display area 601. The notification of the consent code to the customer administrator is not limited to a phone call; it may also be notified by email, direct message, etc. The process in step S408 is one example of a means of notifying the administrator of the network device of the generated consent code.

[0090] In step S409, the customer administrator consents to the remote repair by entering the consent code provided by the remote operator in step S408 into the remote repair consent screen generated by the display information generation unit 322. The remote repair consent screen will be explained using Figure 8.

[0091] Figure 8 shows a remote repair consent screen according to Embodiment 1 of the present invention. The remote repair consent screen 700 is a screen generated by the display information generation unit 323 and is provided to the customer administrator by being displayed on the operation unit 217.

[0092] The consent code input area 701 is where the customer administrator enters the remote repair code, and the consent code entered via the operation unit 217 is displayed. The remote repair consent button 702 is a button that notifies consent to remote repair.

[0093] Now, let's return to the explanation of Figure 4. In this embodiment, in step S409, the customer administrator enters "67891234" into the consent code input area 701 and then presses the remote repair consent button 702.

[0094] In step S410, the repair client application 320 requests the remote repair application 300 to verify the consent code. In the verification request, the repair client application 320 sends the consent code entered in step S409 and the device ID that uniquely identifies the image forming apparatus 100 to the remote repair application 300. In this embodiment, it is assumed that the consent code entered in step S409, "67891234," and the device ID of the image forming apparatus 100, "DeviceD," are sent to the remote repair application 300. The processing in steps S409 and S410 is an example of a means to obtain the consent code from the administrator. The processing in steps S409 and S410 is an example of a means to obtain the device ID of the network device that is the target of the remote repair, along with the consent code from the administrator.

[0095] In step S411, the remote repair service application 300 performs a consent code verification process to verify the consent code entered in step S409. The consent code verification process will be explained using Figure 9. The consent code verification process is one example of a means for verifying the consent code obtained from the administrator.

[0096] Figure 9 is a flowchart showing the consent code verification process in Embodiment 1 of the present invention. In step S801, the communication unit 301 determines whether a consent code verification request has been made from the image forming apparatus 100. If the communication unit 301 determines that a consent code verification request has been made, the process in step S802 is executed. If the communication unit 301 determines that no consent code verification request has been made, the process in the flowchart of Figure 9 is terminated. In this embodiment, a consent code verification request was made in step S410, so the process in step S802 is executed.

[0097] The process in step S802 is executed when it is determined in step S801 that a consent code verification request has been made. In step S802, the notification information management unit 304 determines whether the consent code verification request made in step S801 includes a consent code and a device ID. If the notification information management unit 304 determines that the consent code verification request includes a consent code and a device ID, the process in step S803 is executed. If the notification information management unit 304 determines that the consent code verification request does not include a consent code and a device ID, the process in step S806 is executed. In this embodiment, since the consent code "67891234" and the device ID "DeviceD" have been transmitted in step S410, the process in step S803 is executed.

[0098] The process in step S803 is executed when it is determined in step S802 that the consent code verification request includes a consent code and a device ID. In step S803, the notification information management unit 304 refers to the notification information data table and determines whether there is notification information that includes a "consent code" attribute that exactly matches the consent code included in the consent code verification request. If the notification information management unit 304 determines that there is notification information that exactly matches the consent code, the process in step S804 is executed. If the notification information management unit 304 determines that there is no notification information that exactly matches the consent code, the process in step S806 is executed. In this embodiment, in the notification information data table in Table 3, there is notification information with notification information ID "Notice_003" that exactly matches the consent code, so the process in step S804 is executed. The process in step S803 is an example of a verification method that determines verification to be successful if there is notification information in the notification information data table that includes a consent code that matches the consent code obtained from the administrator.

[0099] The process in step S804 is executed when it is determined in step S803 that there is notification information that exactly matches the consent code. In step S804, the notification information management unit 304 updates the "Remote Repair Authorized Device ID" of the notification information that was determined in step S803 to exactly match the consent code by adding the device ID obtained in step S802. In addition, the notification information management unit 304 updates the "Status" attribute of the notification information to "Consent" as if the verification of the consent code was successful. Table 4 shows the notification information data table at the completion of the process in step S804 in this embodiment. [Table 4]

[0100] The notification information for "Notice_003" is updated with "DeviceD," the device ID included in the consent code verification request, added as a repair-authorized device to the "Remote Repair Authorized Device ID." In addition, the "Status" of the notification information for "Notice_003" is updated from "Waiting for consent" to "Consent." As a result, the Remote Repair Job Creation button 613 on the notification information list confirmation screen 600 in Figure 7 becomes pressable. The process in step S804 is an example of a means of granting the user who requested the start of the remote repair permission, limited to the network device, if the verification is successful.

[0101] In step S805, the notification information management unit 304 generates response information indicating that the remote repair consent verification was successful, and the processing of the flowchart in Figure 9 is completed.

[0102] The process in step S806 is executed when it is determined in step S802 that the consent code verification request does not include the consent code and device ID. Furthermore, the process in step S806 is executed when it is determined in step S803 that there is no notification information that exactly matches the consent code. In step S806, the notification information management unit 304 generates response information indicating that the remote repair consent verification failed, and the process in the flowchart of Figure 9 ends.

[0103] As described above, through the consent code verification process shown in Figure 9, in response to a remote repair consent request from the image forming apparatus 100, the device ID of the image forming apparatus 100 for which remote repair consent has been granted is imprinted on the notification information where the consent code matches.

[0104] Now, let's return to the explanation of Figure 4. In step S412, the remote repair application 300 notifies the repair client application 320 of the response information generated in the consent code verification process shown in Figure 9. In this embodiment, the remote repair application 300 notifies the repair client application 320 of the response information generated in step S805 indicating that the remote repair consent verification was successful.

[0105] In step S413, the remote repair application 300 notifies the remote operator of the response information generated by the consent code verification process shown in Figure 9. The notification to the remote operator is not limited to a specific method, such as sending an email to the remote operator's email address or sending information to the browser 340. In this embodiment, the remote repair application 300 notifies the remote operator of the response information generated in step S805 indicating that the remote repair consent verification was successful.

[0106] In step S414, upon receiving the remote repair consent completion notification in step S412, the repair client application 320 updates the control instruction confirmation cycle setting stored in the HDD 215 to an extremely short value of about 10 seconds. As a result, the control client application 330 will make control instruction confirmation requests to the remote control application 310 at extremely short intervals.

[0107] In step S415 of Figure 5, following step S414, the remote operator receives the remote repair consent completion notification in step S413 and performs a remote repair job creation operation for the image forming apparatus 100 associated with the notification information. The remote repair application 300's remote repair job creation request control process at this time will be explained with reference to Figure 10.

[0108] Figure 10 is a flowchart showing the remote repair job creation request control process according to Embodiment 1 of the present invention. In step S901, the communication unit 301 determines whether a remote repair job creation request has been made from the PC 103 operated by the remote operator in response to the notification information. If the communication unit 301 determines that a remote repair job creation request has been made, the process in step S902 is executed. If the communication unit 301 determines that no remote repair job creation request has been made, the process in the flowchart of Figure 10 is terminated. In this embodiment, it is assumed that a remote repair job creation request has been made when the remote repair job creation button 613 of the notification information "Notice_003" in Figure 7 is pressed. Therefore, the process in step S902 is executed.

[0109] The process in step S902 is executed when it is determined in step S901 that a request for remote repair job creation has been made. In step S902, the user authentication unit 303 obtains user information that requested the remote repair job creation from the authorization information transmitted from the communication unit 301. In this embodiment, the user authentication unit 303 obtains information on "UserD", which is the user ID of the remote operator.

[0110] In step S903, the notification information management unit 304 determines whether the corresponding user ID of the remote repair job notification information requested in step S901 matches the user ID that requested the remote repair job, which was obtained in step S902. If the notification information management unit 304 determines that the corresponding user ID and the requested user ID do not match, the process in step S904 is executed. If the notification information management unit 304 determines that the corresponding user ID and the requested user ID match, the process in step S905 is executed. In this embodiment, since the user ID obtained in step S902 is "UserD", it is determined that the corresponding user ID and the requested user ID match, and the process in step S905 is executed.

[0111] Step S904 is executed when it is determined in step S903 that the corresponding user ID and the requested user ID do not match. In step S904, the display information generation unit 302 generates an insufficient permission error screen, sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator. Here, the screens related to remote repair job creation will be explained using Figure 11. The screens related to remote repair job creation include the insufficient permission error screen displayed in step S904 and the target device selection screen displayed in step S905.

[0112] Figure 11 shows a screen related to remote repair job creation according to Embodiment 1 of the present invention. Figure 11(A) shows a permission shortage error screen according to Embodiment 1 of the present invention. Figure 11(B) shows a target device selection screen according to Embodiment 1 of the present invention.

[0113] The insufficient authorization error screen 1000 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340. The error content display area 1001 is an area that displays the content of the error, and it shows that the error occurred because an operation was performed on a report information that was not the operator's responsibility.

[0114] The target device selection screen 1010 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340. The remote repair target device display area 1011 is an area for the remote operator to display devices that can be remotely repaired. The remote repair target device display area 1011 displays all device IDs registered in the "Remote Repair Authorized Device ID" of the corresponding notification information in the notification information data table. In this embodiment, only "DeviceD", which is the "Remote Repair Authorized Device ID" of "Notice_003" in Table 4, is displayed.

[0115] The collection request button 1012 is pressed when requesting the image forming apparatus 100 corresponding to the device ID to collect device job history information. The diagnosis request button 1013 is pressed when requesting the image forming apparatus 100 corresponding to the device ID to diagnose a device job. The treatment request button 1014 is pressed when requesting a setting change from the image forming apparatus 100 corresponding to the device ID. The verification request button 1015 is pressed when requesting the image forming apparatus 100 corresponding to the device ID to re-execute a device job.

[0116] Now, let's return to the explanation of Figure 10. In step S904, for example, if user "UserD" presses the remote repair job creation button 610 for the notification information "Notice_000" in Figure 7, the permission deficiency error screen 1000 in Figure 11(A) will be displayed. This prevents other remote operators from performing remote repairs. After displaying the permission deficiency error screen 1000 in step S904, the flowchart in Figure 10 is completed.

[0117] Step S905 is executed when it is determined in step S903 that the corresponding user ID and the requested user ID do not match. In step S905, the display information generation unit 302 generates the target device selection screen 1010 shown in Figure 11(B), transmits it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0118] In step S906, the remote repair job information management unit 306 determines the type of remote repair job requested by the remote operator. The remote repair job information management unit 306 determines that the remote repair job type is collection if the collection request button 1012 is pressed on the target device selection screen 1010. If the remote repair job information management unit 306 determines that the remote repair job type is collection, the process in step S907 is executed. The remote repair job information management unit 306 determines that the remote repair job type is diagnosis if the diagnosis request button 1013 is pressed on the target device selection screen 1010. If the remote repair job information management unit 306 determines that the remote repair job type is diagnosis, the process in step S908 is executed. The remote repair job information management unit 306 determines that the remote repair job type is action if the action request button 1014 is pressed on the target device selection screen 1010. If the remote repair job information management unit 306 determines that the remote repair job type is "action", the process in step S909 is executed. If the verification request button 1015 is pressed on the target device selection screen 1010, the remote repair job information management unit 306 determines that the remote repair job type is "verification". If the remote repair job information management unit 306 determines that the remote repair job type is "verification", the process in step S910 is executed.

[0119] Step S907 is a process that is executed when a collection request is sent in step S906. In step S907, the display information generation unit 302 generates a remote repair job creation screen (not shown) for collection, sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0120] Step S908 is a process that is executed when a diagnostic request is sent in step S906. In step S908, the display information generation unit 302 generates a diagnostic remote repair job creation screen (not shown), sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0121] Step S909 is a process that is executed when a treatment request is sent in step S906. In step S909, the display information generation unit 302 generates a remote repair job creation screen (not shown) for treatment, sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0122] Step S910 is a process that is executed when a verification request is sent in step S906. In step S910, the display information generation unit 302 generates a verification remote repair job creation screen (not shown), sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0123] In the remote repair job creation screen displayed during steps S907, S908, S909, and S910, the remote operator requests job creation.

[0124] As described above, the remote repair job creation request control process shown in Figure 10 prevents remote repairs from being performed by other remote operators and provides proper authority management so that remote repairs can only be performed on image forming apparatus 100 for which remote repair permission has been granted.

[0125] Now, let's return to the explanation of Figure 5. In step S416, the remote repair management service 300 creates remote repair job information in accordance with the remote repair job creation request made in step S415 and adds it to the remote repair job information data table. When creating a remote repair job, the control instruction information generation unit 307 creates control instruction information in accordance with the creation request made in step S415.

[0126] In step S417, the remote repair application 300 sends the control instruction information included in the remote repair job information created in step S416 to the remote control application 310.

[0127] In step S418, the remote control application 310 analyzes the control instruction information transmitted in step S417 and stores the control instruction information in the HDD 204 for each corresponding device ID type.

[0128] Step S419 is a process that the control client application 330 periodically performs according to the set value of the control instruction confirmation cycle stored in the HDD 215. In step S419, the control client application 330 requests the remote control application 310 to confirm the control instruction corresponding to the device ID of the image forming apparatus 100.

[0129] In step S420, the remote control application 310 checks if it holds a control instruction corresponding to the device ID requested in step S419, and if it does, it sends the control instruction to the control client application 330.

[0130] In step S421, the control client application 330 executes the control instruction sent in step S420. In step S422, the control client application 330 sends the result of executing the control instruction performed in step S421 to the remote control application 310.

[0131] In step S423, the remote control application 310 notifies the remote repair application 300 of the execution result sent in step S422. The remote control application 310 also analyzes the execution result of the control instruction and, if it determines that the execution was successful, deletes the control instruction that was held in HDD204.

[0132] In step S424, the remote repair application 300 receives the execution result of the control instruction notified in step S423 and notifies the remote operator of the execution result. The remote repair application 300 also stores the execution result of the control instruction in the "Control Instruction Execution Result" column of the remote repair job information data table and updates the "Status" to "Completed".

[0133] Furthermore, the remote repair work performed by executing remote repair jobs in the process from step S415 to step S424 shall be repeatedly performed by the remote operator until it is determined that the problem with the image forming apparatus 100 has been resolved. In this process, the remote operator shall appropriately execute remote repair jobs for collection, diagnosis, treatment, and verification, depending on the nature of the problem.

[0134] Step S425 is a process performed when the remote operator determines that the problem with the image forming apparatus 100 has been resolved. In step S425, the remote operator requests the remote repair application 300 to terminate the notification response by pressing the notification response termination button shown in Figure 7. In this embodiment, it is assumed that the notification response termination button 623 has been pressed.

[0135] In step S426, the remote repair application 300 receives the notification response completion request in step S425 and updates the "Status" in the notification information data table to "Response Completed". Also in step S426, the remote repair application 300 notifies the repair client application 320 that the notification response has been completed. Table 5 shows the notification information data table at the completion of processing in step S426 in this embodiment. [Table 5]

[0136] As a result of the processing in step S426, the "Status" of the notification information for "Notice_003" is updated from "Agreed" to "Response Completed," as shown in Table 5. Consequently, the remote repair job creation button 613 on the notification information list confirmation screen 600 in Figure 7 becomes unclickable.

[0137] In step S427, upon receiving the notification of completion of the response in step S426, the repair client application 320 updates the control instruction confirmation cycle setting stored in the HDD 215 to a long period of approximately 8 hours. As a result, the control client application 330's request for control instruction confirmation from the remote control application 310 is executed at a long time interval rather than a very short interval.

[0138] As described above, the sequence shown in Figures 4 and 5 enables proper access control, allowing only remote operators authorized by the administrator of the image forming apparatus 100 to perform remote repairs on image forming apparatus 100, and only those authorized by the customer administrator. Furthermore, authorization by the customer administrator of the image forming apparatus 100 can be achieved simply by entering a consent code into the image forming apparatus 100, making it possible even within the limited time available for responding to notifications. Moreover, by having the customer administrator enter a consent code on another image forming apparatus, it is possible to dynamically respond to notifications from multiple image forming apparatuses.

[0139] In summary, this embodiment makes it possible to provide a system that enables proper authority management, allowing only the remote operator handling the notification to perform remote repairs specifically on the image forming apparatus that is the subject of the notification, even within the limited time available for responding to notifications.

[0140] <Embodiment 2> As a second embodiment of the present invention, a configuration is provided that enables proper management of authority while handing over remote repair response to another remote operator.

[0141] In Embodiment 1, a system was provided that limits the remote operators who can perform remote repairs in response to a notification by associating the information of the remote operator handling the call with the customer administrator of the image forming apparatus. However, one possible use case for such notification handling is when the remote operator handling the notification takes over to another remote operator with higher skills. In this case, in Embodiment 1, the operator taking over the notification cannot perform remote repairs for the existing notification information, so it is necessary to issue new notification information and have the customer administrator enter the consent code again. In this case, redundant work occurs for the customer of the image forming apparatus and the remote operators, which presents a challenge in achieving regular authority management within the limited time available for notification handling.

[0142] Embodiment 2 of the present invention aims to provide a configuration that enables proper management of authority while transferring remote repair response to another remote operator, in view of these issues. In this embodiment, the remote repair job information data table is assumed to be in the state shown in Table 5. Furthermore, in this embodiment, it is assumed that "UserA," the user responsible for the notification information with "Notification Information ID" "Notice_000" in Table 5, transfers the notification response via remote repair to "UserD."

[0143] Figures 12 and 13 show the notification information operation related screens according to Embodiment 2 of the present invention. The notification information operation related screens include a notification information list confirmation screen and a transfer user selection screen. Figure 12 shows the notification information list confirmation screen 1100.

[0144] The notification information list confirmation screen 1100 is the same screen as the notification information list confirmation screen 600 in Figure 7. The notification information list confirmation screen 1100 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340.

[0145] The notification information list display area 1101 is an area that displays the notification information data table, similar to the notification information list display area 601 in Figure 7. The remote repair job creation buttons 1110, 1111, 1112, and 1113 are buttons that request the creation of a remote repair job related to the notification information, similar to the remote repair job creation buttons 610, 611, 612, and 613 in Figure 7. The notification response end buttons 1120, 1121, 1122, and 1123 are buttons that request the end of the notification information response, similar to the notification response end buttons 620, 621, 622, and 623 in Figure 7.

[0146] The notification transfer buttons 1130, 1131, 1132, and 1133 are buttons that request the transfer of notification information. These buttons can only be pressed when the "Status" of the notification information is "Agreed" or "Awaiting Agreement." Therefore, notification transfer button 1132, which is for notification information with a "Status" of "Response Completed," cannot be pressed.

[0147] Figure 13 shows the user transfer selection screen 1140. The user transfer selection screen 1140 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340. The transfer destination user candidate list display area 1141 is an area that displays a list of candidate user IDs to which the notification information will be transferred. The transfer buttons 1150, 1151, and 1152 are buttons that request the transfer of the selected user (the user corresponding to each button) as the user to whom the notification information will be handled.

[0148] Figure 14 is a flowchart showing the notification response transfer process according to Embodiment 2 of the present invention. In step S1201, the communication unit 301 determines whether a notification response transfer request has been made for the notification information from the PC 103 operated by the remote operator. The communication unit 301 determines that a notification response transfer request has been made if the notification response transfer buttons 1130, 1131, 1132, or 1133 are pressed. If the communication unit 301 determines that a notification response transfer request has been made, the process in step S1202 is executed. If the communication unit 301 determines that no notification response transfer request has been made, the process in the flowchart of Figure 14 ends. Here, it is assumed that a notification response transfer request has been made because the notification response transfer button 1130 for the notification information "Notice_000" in Figure 12 is pressed. Therefore, the process in step S1202 is executed.

[0149] Step S1202 is a process that is executed when it is determined in step S1201 that a request for transfer of notification response has been made. In step S1202, the user authentication unit 303 obtains the user information that requested the request for transfer of notification response from the authorization information transmitted from the communication unit 301. Here, it is assumed that the information of "UserA", which is the user ID of the remote operator, has been obtained.

[0150] In step S1203, the notification information management unit 304 determines whether the corresponding user ID of the notification information requested for transfer in step S1201 matches the user ID of the user who made the transfer request, which was obtained in step S1202. If the notification information management unit 304 determines that the corresponding user ID and the requested user ID do not match, the process in step S1204 is executed. If the notification information management unit 304 determines that the corresponding user ID and the requested user ID do match, the process in step S1205 is executed. In this case, since the user ID obtained in step S1202 is "UserA", it is determined that the corresponding user ID and the requested user ID match, and the process in step S1205 is executed.

[0151] Step S1204 is executed when it is determined in step S1203 that the corresponding user ID and the requested user ID do not match. In step S904, the display information generation unit 302 generates the insufficient authority error screen 1000 shown in Figure 11(A), sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0152] Step S1205 is executed when it is determined in step S1203 that the corresponding user ID and the requested user ID match. In step S1205, the display information generation unit 302 generates the transfer user selection screen 1140 shown in Figure 13, transmits it to the PC 103 via the communication unit 301, and displays the screen to the remote operator.

[0153] In step S1206, the communication unit 301 determines whether a request for selection of a transfer user has been made from the PC 103 operated by the remote operator. The communication unit 301 determines that a request for selection of a transfer user has been made if the transfer buttons 1150, 1151, or 1152 are pressed. If the communication unit 301 determines that a request for selection of a transfer user has been made, the process in step S1207 is executed. If the communication unit 301 determines that no request for selection of a transfer user has been made, the process in the flowchart of Figure 14 ends. Here, it is assumed that the transfer button 1152 in Figure 13 was pressed, resulting in a request to select "UserD" as the transfer user. Therefore, the process in step S1207 is executed.

[0154] Step S1207 is a process that is executed when it is determined in step S1206 that a request for selection of a transfer user has been made. In step S1207, the remote repair application 300 updates the notification information data table, changing the "corresponding user ID" of the notification information requested for transfer in step S1201 to the user ID selected in step S1206. Table 6 shows the notification information data table at the completion of processing in step S804 in this embodiment. [Table 6]

[0155] Table 6 shows that, compared to Table 5, the "Responding User ID" for the "Notice_000" notification information has been updated from "UserA" to "UserD". As a result, "UserD" can now perform remote repairs for the "Notice_000" notification information, while "UserA" will no longer be able to perform remote repairs.

[0156] As described above, the notification response transfer process shown in Figure 14 allows for the transfer of notification information to another remote operator without redundant operations such as issuing new notification information or requiring the customer administrator to re-enter the consent code. Furthermore, it prevents the original remote operator from performing remote repair operations on the transferred notification information, thus enabling a transfer without compromising proper access control.

[0157] In summary, this embodiment makes it possible to provide a system that enables proper management of authority while handing over remote repair tasks to another remote operator.

[0158] <Embodiment 3> As a third embodiment of the present invention, a configuration is provided that can prevent consent for remote repair by an image forming apparatus that is not subject to remote repair authorization.

[0159] In Embodiment 1, a system was provided that limits the image forming machines that can be remotely repaired by generating an empty list of remote repair-authorized devices when notification information is issued, and then adding the information of the image forming machine into which the consent code was entered to the remote repair-authorized devices. However, it is possible that a customer administrator might mistakenly enter the consent code for an image forming machine other than the one experiencing the problem. In this case, Embodiment 1 presents the problem that a remote operator may unintentionally perform remote repair on an image forming machine that is not experiencing the problem.

[0160] Embodiment 3 aims to provide a configuration that can prevent remote repair consent from being granted by an image forming apparatus that is not subject to remote repair authorization, in light of these issues. In this embodiment, the remote repair job information data table is assumed to be in the state shown in Table 5. Furthermore, in this embodiment, the user ID of the remote operator performing the remote repair is "UserE", and it is assumed that the notification was received from the customer administrator of the image forming apparatus corresponding to the device ID "DeviceE".

[0161] Figure 15 is a flowchart showing the notification information creation process according to Embodiment 3 of the present invention. Step S1301 is the same as step S501, so its explanation is omitted.

[0162] The process in step S1302 is executed when it is determined in step S1301 that a remote repair start request has been made. In step S1302, the display information generation unit 302 generates a target device input screen, transmits it to the PC 103 via the communication unit 301, and displays the screen to the remote operator. The target device input screen will be explained using Figure 16.

[0163] Figure 16 shows a target device input screen according to Embodiment 3 of the present invention. The target device input screen 1400 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340.

[0164] The target device input field 1401 is an area where the remote operator enters the device ID of the image processing device 100 to be remotely repaired, and the entered device ID is displayed. Here, the remote operator enters "DeviceE," which is the device ID of the image processing device 100 obtained through a call with the customer manager.

[0165] The Add Target Device button 1402 is a button that requests the remote operator to add the device ID entered in the Target Device Input Field 1401 as a remote repair target device in the notification. The process in step S1302 is an example of a means of receiving input of the device ID of the network device that is the target of the remote repair from the user who made the request to start the remote repair.

[0166] Now, let's return to the explanation of Figure 15. In step S1303, the communication unit 301 determines whether a request for transmission of notification information to the target device has been made from the PC 103 operated by the remote operator. The communication unit 301 determines that a request for transmission to the target device has been made if the target device addition button 1402 is pressed. If the communication unit 301 determines that a request for transmission to the target device has been made, the process in step S1304 is executed. If the communication unit 301 determines that no request for transmission to the target device has been made, the process in the flowchart of Figure 15 ends. Here, we assume that a request for transmission to the target device "DeviceE" entered in the target device input field 1401 has been made by pressing the target device addition button 1402 in Figure 16. Therefore, the process in step S1304 is executed.

[0167] The processing from step S1304 to step S1305 is the same as the processing from step S502 to step S503, so the explanation is omitted.

[0168] In step S1306, the notification information management unit 304 creates notification information using the user information obtained in step S1302, the consent code generated in step S1305, and the target device ID transmitted in step S1303, and adds it to the notification information data table. Step S1306 is an example of a means for adding the notification information, including the generated consent code and the input device ID, to the notification information data table that manages the notification information related to the error. In this embodiment, Table 7 shows the notification information data table to which the created notification information has been added. [Table 7]

[0169] Table 7 shows that, compared to Table 5, notification information with notification information ID "Notice_004" has been added. The "Status" of the notification information for "Notice_004" contains "Awaiting Consent," indicating that the customer has not yet given consent for remote repair. The "Consent Code" of the notification information for "Notice_004" contains "12349876," the value generated in step S1305. The "Responding User ID" of the notification information for "Notice_004" contains "UserE," the user ID obtained in step S1302. The "Remote Repair Authorized Device ID" of the notification information for "Notice_004" contains "DeviceE," the device ID sent in step S1303.

[0170] The processing from step S1307 to step S1309 is the same as the processing from step S505 to step S507, so the explanation is omitted.

[0171] As described above, the notification information creation process in Figure 15 creates notification information containing the device IDs eligible for remote repair before consent to remote repair is given.

[0172] Figure 17 is a flowchart showing the consent code verification process according to Embodiment 3 of the present invention. The processes from steps S1501 to S1503 are the same as those from steps S801 to S803, so their explanation is omitted.

[0173] Step S1504 is executed when it is determined in step S1503 that there is notification information that exactly matches the consent code. In step S1504, the notification information management unit 304 determines whether the device ID obtained in step S1502 is included in the "remote repair authorized device ID" of the notification information that was determined to be an exact match in step S1503. If the notification information management unit 304 determines that the device ID is included in the "remote repair authorized device ID", the process in step S1505 is executed. If the notification information management unit 304 determines that the device ID is not included in the "remote repair authorized device ID", the process in step S1507 is executed. Here, it is assumed that "DeviceE", which is the device ID of the image processing device 100, was obtained in step S1502. Also, since "DeviceE" is included in the "remote repair authorized device ID" of the notification information "Novice_004" in the notification information data table, the process in step S1505 is executed. The processes in steps S1503 and S1504 are examples of verification methods. This verification method determines that the verification is successful if the notification information data table contains notification information that includes a consent code that matches the consent code obtained from the administrator, and a device ID that matches the device ID obtained together with the consent code.

[0174] The processing from steps S1505 to S1507 is the same as the processing from steps S804 to S806, so the explanation is omitted.

[0175] As described above, the consent code verification process shown in Figure 17 prevents consent for remote repairs by image processing devices other than those previously registered as authorized remote repair devices.

[0176] As described above, this embodiment makes it possible to provide a configuration that can prevent consent for remote repair by an image forming apparatus that is not subject to remote repair authorization.

[0177] <Embodiment 4> As a fourth embodiment of the present invention, a configuration is provided that can prevent remote repairs from being performed on image forming apparatus that are outside the scope of service of the call center to which the remote operator belongs.

[0178] Embodiment 1 provided a system in which a remote operator at a call center performs remote repairs upon receiving a notification from the customer manager of an image forming machine. However, there may be cases where a notification is received from an image forming machine that is not covered by the call center's support. For example, if call centers are located in different regions of a country, a notification may be received from an image forming machine in another region, or from another country. In this case, Embodiment 1 presents the problem that a remote operator may perform remote repairs on an image forming machine that is not covered by the call center's support.

[0179] Embodiment 2 aims to provide a configuration that can prevent remote repairs from being performed on image forming machines that are not covered by the call center to which the remote operator belongs, in light of these issues. In this embodiment, the notification information management unit 304 manages information about the call center to which the remote operator belongs and customer information managing the image forming machine 100 as an organizational information data table on the HDD 204. The organizational information data table in this embodiment is shown in Table 8. [Table 8]

[0180] In the organizational information data table in Table 8, "Organizational Information ID" is an attribute that indicates a value for uniquely identifying organizational information. "Regional Information" is an attribute that indicates a value for identifying the region of the organization. "Affiliated User ID" is an attribute that indicates the user ID of the remote repair application 300 belonging to the organization, and is written in JSON format. "Owned Device ID" is an attribute that indicates the device ID of the image forming apparatus 100 owned by the organization, and is written in JSON format.

[0181] In Table 8, for example, the organization information with "Organization Information ID" "Tenant_000" indicates that it is a regional organization in "France," to which "UserA" belongs, and that it does not own any image forming equipment. Also, the organization information with "Organization Information ID" "Tenant_001" indicates that it is a regional organization in "Germany," to which it has no users, and that it owns an image processing device with device ID "DeviceA."

[0182] Figure 18 is a flowchart showing the consent code verification process according to Embodiment 4 of the present invention. The processes from steps S1601 to S1603 are the same as those from steps S801 to S803, so their explanation is omitted.

[0183] Step S1604 is executed when it is determined in step S1603 that there is a report that exactly matches the consent code. In step S1604, the report information management unit 304 obtains the "corresponding user ID" of the report that was determined in step S1603 to be an exact match with the consent code. Furthermore, the report information management unit 304 refers to the organization information table to identify the organization information that includes the corresponding user in the "affiliated user ID" and obtains the value of "region information". For example, if the "corresponding user ID" of the report that was determined to be an exact match with the consent code is "UserA", then the region information "France" is obtained in the organization information data table in Table 8.

[0184] In step S1605, the information management unit 304 refers to the organization information table, identifies the organization information in which the device ID obtained in step S1602 is included in the "Owning Device ID", and obtains the value of "Regional Information". For example, if the device ID obtained in step S1602 is "DeviceA", then in the organization information data table in Table 8, the regional information "Germany" is obtained.

[0185] In step S1606, the notification information management unit 304 determines whether the regional information of the organization to which the user belongs, obtained in step S1604, matches the regional information of the organization that owns the image processing device, obtained in step S1605. If the notification information management unit 304 determines that the regional information matches, the process in step S1607 is executed. If the notification information management unit 304 determines that the regional information does not match, the process in step S1609 is executed.

[0186] The processing from steps S1607 to S1609 is the same as the processing from steps S804 to S806, so the explanation is omitted.

[0187] As described above, the consent code verification process in Figure 18 makes it possible to detect remote repair consent requests from image processing devices located outside the region of the call center to which the remote operator belongs.

[0188] In summary, this embodiment makes it possible to provide a configuration that prevents remote repairs from being performed on image forming machines that are outside the scope of service of the call center to which the remote operator belongs.

[0189] <Embodiment 5> As a fifth embodiment of the present invention, a configuration is provided that enables proper authority management so that only remote operators who respond to notifications can perform remote repairs limited to the image forming apparatus that is the subject of the notification, without requiring the input of a consent code on the image forming apparatus screen.

[0190] In Embodiment 1, a customer administrator of the image forming apparatus was provided who authorized remote repair of the image forming apparatus by entering a consent code and then pressing a remote repair consent button. However, the operation of entering the consent code by operating the image forming apparatus is more cumbersome than the operation of pressing a specific button, which leads to stress for the customer where the problem occurred.

[0191] Embodiment 5 aims to provide a configuration that, in light of these issues, enables proper authority management so that only remote operators who respond to notifications can perform remote repairs limited to the image forming apparatus that is the subject of the notification, without requiring the input of a consent code on the image forming apparatus screen.

[0192] Figure 19 is a diagram showing the overall processing sequence of system 10 according to Embodiment 5 of the present invention. Figure 20 is a diagram showing the overall processing sequence of system 10 according to Embodiment 5 of the present invention, and follows Figure 19. In this embodiment, the notification information data table at the start of the sequences in Figures 19 and 20 is assumed to be in the state of Table 1, and the remote repair job information data table is assumed to be in the state of Table 2. Furthermore, in the processing sequences of Figures 19 and 20, the device ID of the image forming apparatus 100 is assumed to be "DeviceD", and the user ID of the remote operator performing the remote repair is assumed to be "UserD".

[0193] In step S1701, the customer administrator requests a remote repair request screen for the trouble from the repair client application 320 via the operation unit 217 of the image forming apparatus 100.

[0194] In step S1702, the repair client application 320 generates a remote repair request screen and provides it to the customer administrator by displaying it on the screen. The screens related to the remote repair request will be explained using Figure 21. The screens related to the remote repair request include the remote repair request screen and the consent code confirmation screen.

[0195] Figure 21 shows a screen related to remote repair requests according to Embodiment 5 of the present invention. Figure 21(A) shows the remote repair request screen according to Embodiment 5 of the present invention. Figure 21(B) shows the consent code confirmation screen according to Embodiment 5 of the present invention.

[0196] The remote repair request screen 1800 is a screen generated by the display information generation unit 323 and is provided to the customer administrator by being displayed on the operation unit 217. The remote repair request button 1801 is a button for the customer administrator to request remote repair, and when pressed, a request for notification information is issued.

[0197] The consent code confirmation screen 1810 is a screen generated by the display information generation unit 323 and is provided to the customer administrator by being displayed on the operation unit 217. The consent code display area 1811 is the area where the consent code of the issued notification information is displayed. In the example in Figure 21(B), the consent code "67891234" is displayed.

[0198] Now, let's return to the explanation of Figure 19. In step S1703, the customer administrator requests a remote repair by pressing the remote repair request button 1801 on the remote repair request screen 1800 in Figure 21(A).

[0199] In step S1704, the repair client application 320 transmits equipment information to the remote repair application 300 and requests the creation of notification information. In addition, in the request for the creation of notification information, the repair client application 320 transmits a device ID that uniquely identifies the image forming apparatus 100 to the remote repair application 300. In this embodiment, it is assumed that "DeviceD", which is the device ID of the image forming apparatus 100, is transmitted.

[0200] In step S1705, the remote repair application 300 executes the notification information creation process. The notification information creation process will be explained using Figure 22.

[0201] Figure 22 is a flowchart showing the notification information creation process according to Embodiment 5 of the present invention. In step S1901, the communication unit 301 determines whether a request for notification information creation has been made from the image forming apparatus 100. If the communication unit 301 determines that a request for notification information creation has been made, the process in step S1902 is executed. If the communication unit 301 determines that no request for notification information creation has been made, the process in the flowchart of Figure 22 is terminated. In this case, since a request for notification information creation was made in step S1704, the process in step S1902 is executed.

[0202] Step S1902 is executed when it is determined in step S1901 that a request for the creation of notification information has been made. In step S1902, the communication unit 301 determines whether the notification information creation request made in step S1901 includes a device ID. If the communication unit 301 determines that the notification information creation request includes a device ID, the process in step S1903 is executed. If the communication unit 301 determines that the notification information creation request does not include a device ID, the process in the flowchart in Figure 22 is terminated.

[0203] Step S1903 is executed when it is determined in step S1902 that the notification information creation request includes a device ID. The process in step S1903 is the same as the process in step S503, so the explanation is omitted.

[0204] In step S1904, the notification information management unit 304 creates notification information using the device ID information obtained in step S1902 and the consent code generated in step S503, and adds it to the notification information data table. In this embodiment, Table 9 shows the notification information data table to which the created notification information has been added. [Table 9]

[0205] Table 9 shows the notification information with notification information ID "Notice_003" added to Table 1. The "Status" of the notification information for "Notice_003" contains "Unassigned," indicating that no remote operator has been assigned to handle the issue. The "Consent Code" of the notification information for "Notice_003" contains "67891234," the value generated in step S1903. The "Responding User ID" of the notification information for "Notice_003" contains a value indicating that no corresponding user exists. The "Remote Repair Authorized Device ID" of the notification information for "Notice_003" contains "DeviceD," the device ID obtained in step S1902.

[0206] As described above, the notification information is created through the notification information creation process shown in Figure 22.

[0207] Now, let's return to the explanation of Figure 19. In step S1706, the remote repair application 300 sends the consent code information of the notification information created in step S1705 to the repair client application 320. Here, let's assume that "67891234" is sent.

[0208] In step S1707, the repair client application 320 displays the consent code confirmation screen 1810 shown in Figure 21(B) on the operation unit 217 of the image forming apparatus 100. In step S1708, the customer manager makes a telephone call to the remote operator of the call center to report a problem. At that time, the customer manager tells the remote operator the consent code displayed in the consent code display area 1811 of the consent code confirmation screen 1810 shown in Figure 21(B). Here, it is assumed that "67891234" is told.

[0209] The processing from steps S1709 to S1711 is the same as the processing from steps S402 to S404, so the explanation is omitted.

[0210] In step S1712, the remote operator sends a request to the remote repair service application 300 to display the notification information list confirmation screen. In step S1713, the display information generation unit 302 of the remote repair application 300 generates the notification information list confirmation screen, sends it to the PC 103 via the communication unit 301, and displays the screen to the remote operator. The notification information list confirmation screen will now be explained using Figure 23.

[0211] Figure 23 shows a notification information list confirmation screen according to Embodiment 5 of the present invention. The notification information list confirmation screen 2000 is the same screen as the notification information list confirmation screen 600 in Figure 7. The notification information list confirmation screen 2000 is a screen generated by the display information generation unit 302 and is provided to the remote operator by the browser 340.

[0212] The notification information list display area 2001 is an area that displays the notification information data table, similar to the notification information list display area 601 in Figure 7. Here, the information in Table 8 is displayed in the notification information list display area 2001. The remote repair job creation buttons 2010, 2011, 2012, and 2013 are buttons that request the creation of a remote repair job related to the notification information, similar to the remote repair job creation buttons 610, 611, 612, and 613. The notification response end buttons 2020, 2021, 2022, and 2023 are buttons that request the end of the notification information response, similar to the notification response end buttons 620, 621, 622, and 623 in Figure 7.

[0213] The Assign button 2002 is displayed when there is no user to handle the notification information. When pressed, it sends an assignment request to the corresponding notification information. Note that the Remote Repair Job Creation buttons 2010, 2011, 2012, and 2013 cannot be pressed if the "Status" of the notification information is "Unassigned". Therefore, the Remote Repair Job Creation button 2013 cannot be pressed.

[0214] Please note that the "End Report Response" buttons 2020, 2021, 2022, and 2023 cannot be pressed if the "Status" of the report information is "Unassigned." Therefore, the "End Report Response" button 2023 cannot be pressed.

[0215] Now, let's return to the explanation of Figure 19. In step S1714, the remote operator requests the assignment of a notification from the remote repair application 300 by pressing the assignment button 2002 for a notification that has not been assigned to a user on the notification information list screen 2000 in Figure 23. In the assignment request, the notification information ID to be assigned and authorization information are transmitted. Here, we assume that the remote operator with user ID "UserD" pressed the assignment button 2002 for notification information with notification ID "Notice_003".

[0216] In step S1715, the remote repair service application 300 receives the notification information assignment request in step S1714, obtains user information from the transmitted notification information ID and authorization information, and updates the notification information data table. Table 10 shows the notification information data table at the completion of processing in step S804 in this embodiment. [Table 10]

[0217] As shown in Table 10, the "Responding User ID" of the notification information for "Notice_003" is updated to "UserD," which is the user ID of the remote operator who pressed the assign button 2002 in step S1714. In addition, the "Status" of the notification information for "Notice_003" is updated from "Unassigned" to "Agreed." As a result, the remote repair job creation button 2013 and the notification response completion button 2023 on the notification information list confirmation screen 2000 in Figure 23 become pressable.

[0218] The process from step S1716 in Figure 19 to step S1731 in Figure 20 is the same as that of steps S412 to S427, so the explanation is omitted.

[0219] As described above, the sequence shown in Figures 19 and 20 enables remote repair without the customer administrator having to enter a consent code into the image forming machine. Furthermore, it provides proper access control, allowing only remote operators who have been given a consent code by the customer administrator to perform remote repairs on image forming machines for which the customer administrator has requested remote repairs.

[0220] In summary, this embodiment provides a configuration that enables proper authority management, allowing only remote operators who respond to reports to perform remote repairs on the reported image forming apparatus, without requiring the input of a consent code on the screen for the image forming apparatus.

[0221] (Other embodiments) The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.

[0222] Although preferred embodiments of the present invention have been described above, the present invention is not limited to these embodiments, and various modifications and changes are possible within the scope of its essence.

[0223] This embodiment includes the following configurations and methods. (Composition 1) A system including network devices and a device management system, A means for receiving a request from a user to initiate remote repair of an error that occurred in the network device, In response to a request to initiate the remote repair, means for generating a consent code to confirm consent to the remote repair, and adding notification information including the generated consent code to a notification information data table that manages notification information regarding the error, A means for notifying the administrator of the network device of the generated consent code, A means of obtaining a consent code from the aforementioned administrator, A means for verifying the consent code obtained from the aforementioned administrator, If the verification is successful, the means of granting the user who requested the start of the remote repair the authority to perform remote repairs limited to the network device, A system characterized by having the following features. (Configuration 2) The verification means is considered successful if the notification information data table contains notification information that includes a consent code that matches the consent code obtained from the administrator. The system according to configuration 1, characterized by the features described above. (Composition 3) The system has a means to transfer the remote repair authority granted to the user who initiated the remote repair request to another user. The system according to configuration 1 or configuration 2, characterized by the above. (Composition 4) The system has means for receiving input of the device ID of the network device that is the target of the remote repair from the user who requested the commencement of the remote repair, The means for adding the above-mentioned means adds the notification information, including the generated consent code and the entered device ID, to the notification information data table that manages the notification information regarding the error. The means for obtaining the above-mentioned means obtains the device ID of the network device that is the target of the remote repair, along with the consent code from the administrator. The verification means is considered successful if the notification information data table contains notification information that includes a consent code that matches the consent code obtained from the administrator, and a device ID that matches the device ID obtained together with the consent code. A system according to any one of configurations 1 to 3, characterized by the features described herein. (Method 1) A method for controlling a system including a network device and a device management system, A process of receiving a request from a user to initiate remote repair of an error that occurred in the network device, In response to the request to initiate the remote repair, the process involves generating a consent code to confirm consent to the remote repair, and adding the notification information containing the generated consent code to a notification information data table that manages notification information regarding the error. The steps include notifying the administrator of the network device of the generated consent code, The process of obtaining a consent code from the aforementioned administrator, The process involves verifying the consent code obtained from the aforementioned administrator, If the verification is successful, the user who requested the start of the remote repair is granted remote repair privileges limited to the network device. A method characterized by having the following: [Explanation of symbols]

[0224] 10 Systems 100 Image forming apparatus 101 Remote Repair Service Server 102 Remote Control Service Server 103 PC 104 Network

Claims

1. A system including network devices and a device management system, A means for receiving a request from a user to initiate remote repair of an error that occurred in the network device, In response to a request to initiate the remote repair, means for generating a consent code to confirm consent to the remote repair, and adding notification information including the generated consent code to a notification information data table that manages notification information regarding the error, A means for notifying the administrator of the network device of the generated consent code, A means of obtaining a consent code from the aforementioned administrator, A means for verifying the consent code obtained from the aforementioned administrator, If the verification is successful, the means of granting the user who requested the start of the remote repair the authority to perform remote repairs limited to the network device, A system characterized by having the following features.

2. The verification means is considered successful if the notification information data table contains notification information that includes a consent code that matches the consent code obtained from the administrator. The system according to feature 1.

3. The system has a means to transfer the remote repair authority granted to the user who initiated the remote repair request to another user. The system according to feature 1.

4. The system has means for receiving input of the device ID of the network device that is the target of the remote repair from the user who requested the commencement of the remote repair, The means for adding the above-mentioned means adds the notification information, including the generated consent code and the entered device ID, to the notification information data table that manages the notification information regarding the error. The means for obtaining the above-mentioned means obtains the device ID of the network device that is the target of the remote repair, along with the consent code from the administrator. The verification means is considered successful if the notification information data table contains notification information that includes a consent code that matches the consent code obtained from the administrator, and a device ID that matches the device ID obtained together with the consent code. The system according to feature 1.

5. A method for controlling a system including a network device and a device management system, A process of receiving a request from a user to initiate remote repair of an error that occurred in the network device, In response to the request to initiate the remote repair, the process involves generating a consent code to confirm consent to the remote repair, and adding the notification information containing the generated consent code to a notification information data table that manages notification information regarding the error. The steps include notifying the administrator of the network device of the generated consent code, The process of obtaining a consent code from the aforementioned administrator, The process involves verifying the consent code obtained from the aforementioned administrator, If the verification is successful, the user who requested the start of the remote repair is granted remote repair privileges limited to the network device. A method characterized by having the following: