Information processing device and control method for information processing device

The information processing device manages token-based authentication by allowing users to control refresh token storage and verify credentials, enhancing security and simplifying management.

JP2026079383APending Publication Date: 2026-05-15SHARP KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
SHARP KK
Filing Date
2024-10-30
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing information processing devices face challenges in managing token-based authentication, particularly in handling refresh tokens and user authentication information, which can lead to security risks and complex management due to inconsistent account information storage.

Method used

An information processing apparatus and method that allows users to control the storage of refresh tokens based on settings, associating account names and device passwords, and enabling secure authentication by comparing entered credentials with server-verified information.

Benefits of technology

Enhances security and simplifies authentication management by allowing users to choose token storage, reducing the risk of password leakage and ensuring accurate credential verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026079383000001_ABST
    Figure 2026079383000001_ABST
Patent Text Reader

Abstract

This invention aims to simplify the management of authentication in information processing devices that use network services through token-based authentication. [Solution] An information processing device comprising a communication unit that can communicate via a network with a server that performs a first authentication based on first authentication information including an account name, and a storage unit. The device receives a refresh token sent by the server according to the result of the first authentication. Based on a setting regarding whether or not to store the refresh token in the storage unit, the device controls the storage of the refresh token in the storage unit.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0006] ,

[0001] The present disclosure relates to an information processing apparatus and the like.

Background Art

[0002] Some information processing apparatuses such as MFPs (Multi-Function Printers / Peripherals, multifunction devices) use access tokens and refresh tokens issued by an authentication server to utilize web services.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] The problem to be solved by the present disclosure is to facilitate management related to authentication in an information processing apparatus that uses token-based authentication to utilize services on a network.

Means for Solving the Problems

[0005] The present disclosure provides an information processing apparatus including a control unit, a communication unit communicable via a network with a server that executes a first authentication based on first authentication information including an account name, and a storage unit, wherein the control unit receives a refresh token transmitted by the server according to the result of the first authentication, and controls storage of the refresh token in the storage unit based on a setting regarding whether to store the refresh token in the storage unit.

[0006] Furthermore, this disclosure provides a control method for an information processing device comprising a communication unit that can communicate via a network with a server that performs a first authentication based on first authentication information including an account name, and a storage unit, the method including receiving a refresh token transmitted by the server in accordance with the result of the first authentication, and controlling the storage of the refresh token in the storage unit based on a setting regarding whether or not to store the refresh token in the storage unit. [Effects of the Invention]

[0007] According to this disclosure, in an information processing device that uses token-based authentication to access network services, the management of authentication can be made easier. [Brief explanation of the drawing]

[0008] [Figure 1] This is a schematic diagram of the authentication system according to the first embodiment of this disclosure. [Figure 2] This is a block diagram of an MFP (Multi-Function Printer / Peripheral) according to the first embodiment of this disclosure. [Figure 3] Figure 3(A) is a block diagram illustrating the configuration of the control unit of the MFP according to the first embodiment of this disclosure, and Figure 3(B) is a block diagram illustrating the configuration of the storage unit of the MFP according to the first embodiment of this disclosure. [Figure 4] This is a flowchart illustrating the operation of the MFP according to the first embodiment of this disclosure. [Figure 5] This is a flowchart illustrating the operation of the MFP according to the first embodiment of this disclosure. [Figure 6] This is a flowchart illustrating the operation of the MFP according to the first embodiment of this disclosure. [Figure 7] This is a schematic diagram illustrating the operation of the authentication system according to the first embodiment of this disclosure. [Figure 8]This is an example of a screen displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 9] This is a diagram illustrating the screen transitions displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 10] This is a diagram illustrating the screen transitions displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 11] This is an example of a screen displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 12] This is an example of a screen displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 13] This is an example of a screen displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 14] This is an example of a screen displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Figure 15] This is an example of a screen displayed on the display unit of the MFP according to the first embodiment of this disclosure. [Modes for carrying out the invention]

[0009] The embodiments of this disclosure will be described below with reference to the drawings. In this disclosure, for example, an MFP (Multi-Function Printer / Peripheral) 10 will be described as one form of information processing device. The MFP 10 in this disclosure is not limited in its configuration as long as it is capable of communicating with an authentication server 30 via a network NW. The following embodiments are examples for illustrating this disclosure and illustrate an example of the disclosure described in the claims, and the technical scope of this disclosure is not limited to the following description. There is a technology that stores a refresh token issued by the authentication server 30 in the MFP10 when a user uses the MFP10 to authenticate with the authentication server 30 and access network services on the MFP10, linking it to the user authentication information in the MFP10. However, if the account information of the authentication server 30 is used for user authentication in the MFP10, both the refresh token and the account information of the authentication server 30 will be stored in the MFP10. Some users may not want the refresh token to be stored in the MFP10 because this is undesirable from a security standpoint, but the above technology does not take such users into consideration. Furthermore, if the account information of the authentication server 30 stored in the MFP10 differs from the account information entered on the authentication screen of the authentication server 30, the MFP10 will store different information as user authentication information, making the management of user authentication information complicated. This disclosure aims to facilitate the management of authentication in an information processing device that uses token-based authentication to access network services, and this is achieved in the following embodiments.

[0010] [1. First Embodiment] [1.1 System Configuration] Figure 1 is a schematic diagram of an authentication system 1 according to the first embodiment of this disclosure. The authentication system 1 comprises an MFP (Multi-Function Printer / Peripheral) 10 and an authentication server 30. The MFP 10 and the authentication server 30 are connected to each other via a network NW. The MFP 10 is an example of an information processing device according to the first embodiment of this disclosure. The authentication server 30 is a server for authenticating users of network services, and a user U uses the MFP 10 to be authenticated by the authentication server 30 and uses the network services on the MFP 10. The authentication server 30 is also referred to as the network service 30.

[0011] [1.2 Configuration of MFP10] FIG. 2 is a block diagram of the MFP 10 according to the first embodiment of the present disclosure. The MFP 10 is an image forming apparatus (image processing apparatus) also called a multi-functional printer, and typically includes a copying function, an image scanner function, a facsimile function, and a printer function. The MFP 10 may further include other functions, for example, an email transmission / reception function, a file server function, etc.

[0012] The control unit 100 controls the entire MFP 10. The control unit 100 is composed of one or more control devices and one or more control circuits, and is, for example, a CPU (Central Processing Unit), which is a processor that executes various arithmetic processes, or is composed of a SoC (System on a Chip), etc.

[0013] FIG. 3(A) is a block diagram for explaining the configuration of the control unit of the MFP 10 according to the first embodiment of the present disclosure. The control unit 100 realizes various functions including a device authentication processing unit 101, a service authentication processing unit 103, a user information acquisition unit 105, and a setting processing unit 107 by reading out the programs stored in the storage unit 110 and executing the processing.

[0014] The device authentication processing unit 101 executes processing related to device authentication described later. Device authentication is also called the second authentication. The service authentication processing unit 103 executes processing related to service authentication executed by the authentication server 30. Service authentication is also called the first authentication. The user information acquisition unit 105 executes processing for acquiring user information from the authentication server 30. The setting processing unit 107 executes processing related to various settings of the MFP 10, including setting whether to store a refresh token in the MFP 10.

[0015] The memory unit 110 stores various programs and data necessary for the operation of the image forming apparatus. The memory unit 110 includes one or more temporary storage devices such as DRAM (Dynamic Random Access Memory) or non-temporary storage devices such as SSDs (Solid State Drives) made of semiconductor memory or HDDs (Hard Disk Drives) made of magnetic disks. Although the memory unit 110 is shown as a single configuration for the purposes of this explanation, it may also be configured as separate devices for each purpose, such as an area used for program execution (main memory area), an area for storing programs and data (auxiliary memory area), and an area used for caching.

[0016] Figure 3(B) is a block diagram illustrating the configuration of the storage unit 110 of the MFP 10 according to the first embodiment of this disclosure. The storage unit 110 has a user information storage unit 111 and a setting storage unit 113. The user information storage unit 111 stores user information acquired by the user information acquisition unit 105. The user information acquisition unit 105 acquires the account name, service password, etc., as user information. The account name and service password are the account name and password registered by the user to use the network service 30 (authentication server 30), respectively. The service password is also called the first password, and the device password, which will be described later, is also called the second password. Authentication information including the account name and service password is also called the first authentication information, and authentication information including the account name and device password is also called the second authentication information. It is assumed that the strings indicating the account name in the first authentication information and the second authentication information for the same user are exactly the same. Furthermore, the user information acquisition unit 105 acquires a refresh token issued by the authentication server 30 as user information. The user information storage unit 111 associates the account name, device password, and refresh token with each other and stores them as user information. The settings storage unit 113 stores information related to the settings set by the settings processing unit 107.

[0017] The display unit 120 displays images and text. For example, it is composed of a liquid crystal display (LCD) or an organic EL (Electro-Luminescence) panel. The display unit 120 may be a standalone display device or it may include an externally connected display device.

[0018] The control unit 130 accepts user input. For example, the control unit 130 consists of hardware keys and / or software keys. The control unit 130 also includes operation keys such as task keys for instructing the execution of tasks such as sending a fax or scanning an image, and a cancel key for instructing the user to stop an operation.

[0019] The operation unit 130 can be configured as a touch panel that allows input via the display unit 120. When the operation unit 130 is configured as a touch panel, it can detect user touch, tap, swipe operations on objects displayed via the display unit 120 and acquire coordinate position and pressure information of the touch panel. In this case, common input methods such as resistive touch, infrared touch, electromagnetic induction touch, and capacitive touch can be used as the input method for the touch panel.

[0020] The communication unit 140 connects to a network. For example, it is configured with an interface that can connect to a wired LAN (Local Area Network), wireless LAN, or LTE (Long Term Evolution) network. By connecting the communication unit 140 to a network, it becomes connected to other devices and external networks. In addition, the communication unit 140 may also have an interface that performs short-range wireless communication, such as NFC (Near Field Communication) or Bluetooth (registered trademark).

[0021] The connection section 150 connects the MFP 10 to other devices (external devices). For example, the connection section 150 is a USB interface, and a USB memory stick or the like is connected to it. In addition to a USB interface, the connection section 150 may also be an interface such as HDMI (registered trademark).

[0022] The image input unit 160 reads an image (document) and outputs it as image data. The image input unit 160 is composed of a general scanner (image input device). The image input unit 160 may also input image data from an external storage medium such as a USB memory stick, or it may receive images via a network.

[0023] The image forming unit 170 forms (prints) an image on a medium such as copy paper based on the image data. The printing method of the image forming unit 170 is arbitrary and may be any of the following: an inkjet printer, a laser printer, a thermal transfer printer, etc. The image forming unit 170 may be a monochrome printer or a color printer. The image forming unit 170 may also include a paper feeding mechanism for supplying the medium, a transport mechanism for transporting the medium, a sorter mechanism for sorting the medium after the image has been formed, etc.

[0024] [1.3 Operation of MFP10] Figures 4, 5, and 6 are flowcharts illustrating the operation of the MFP10 according to the first embodiment of this disclosure. While it is preferable that the following processes be performed by any of the configurations described in Figure 3(A), for the sake of explanation, these processes will be described as being performed by the control unit 100.

[0025] Prior to the operations described below, it is assumed that user U has already registered their account name and service password with the network service 30, and that user U knows their account name and service password. Furthermore, it is assumed that the control unit 100 functions as a setting processing unit 107, displaying a setting screen on the display unit 120, and accepting input for various settings, including whether or not to store a refresh token, according to the operation of a user such as user U (for example, a user with administrator privileges) via the operation unit 130, and storing the setting information in the setting storage unit 113. The setting screen will be described in more detail later.

[0026] When the control unit 100 displays the user authentication screen, it determines whether the setting to store a refresh token is enabled based on the setting information stored in the setting storage unit 113 (step 101). If the setting to store a refresh token is enabled (step 101, yes), the control unit 100 proceeds to step 103. If the setting not to store a refresh token is disabled (step 101, no), the control unit 100 proceeds to step 161 in Figure 6.

[0027] In step 103, the control unit 100 displays the first login screen on the display unit 120 (step 103). The first login screen is used for authentication using an account name and a device password (described later), or for new registration related to this authentication. The first login screen will be described in more detail later.

[0028] When the first login screen is displayed, if the operation unit 130 receives a request to register a new account (step 105, yes), the control unit 100 displays the account registration screen on the display unit 120 (step 107). The account registration screen is a screen for user U to register a device password to be associated with user U's network service 30 account name (sometimes simply called the account name). The device password is a password that can be registered independently of the network service 30 service password and is a password that is only valid for the MFP 10. More details about the account registration screen will be described later. Once the device password is determined, the control unit 100 may temporarily store the account name and device password in the user information storage unit 111, associating them with each other.

[0029] When the account name and device password are entered on the account registration screen, the control unit 100 accesses the authentication server 30 via the network NW using the communication unit 140 (step 109). In response to this access, the authentication server 30 sends service authentication screen data for authenticating the network service user to the MFP 10. When the communication unit 140 in the MFP 10 receives the service authentication screen data, the control unit 100 displays the service authentication screen on the display unit 120 (step 111).

[0030] The control unit 100 receives the account name and service password entered by user U using the operation unit 130 on the displayed service authentication screen (step 113). The control unit 100 transmits the entered account name and service password to the authentication server 30 via the network NW using the communication unit 140. Alternatively, instead of user U entering the account name using the operation unit 130 on the service authentication screen, the control unit 100 may reflect the account name entered on the first login screen as the account name on the service authentication screen.

[0031] The authentication server 30 performs the authentication process based on the received account name and service password. If authentication is successful (step 115, yes), the authentication server 30 sends the access token and refresh token to the MFP 10. If authentication fails (step 115, no), the authentication server 30 sends the data from the service authentication screen to the MFP 10 again, prompting user U to re-enter their account name and / or service password.

[0032] When authentication at the authentication server 30 is successful and the communication unit 140 receives the access token and refresh token (step 117), it sends a user information request to the authentication server 30 along with the access token received from the authentication server 30 (step 119). The user information request is a request to obtain various information about user U registered with the network service 30, and in particular, includes a request to obtain user U's account name.

[0033] Upon receiving the access token and the user information request, the authentication server 30 responds to the user information request based on the access token and sends the user information of user U to the MFP 10.

[0034] When the control unit 100 receives user information sent from the authentication server 30 (step 121), it compares the account name of user U registered with the network service 30 included in the received user information with the account name of user U entered on the account registration screen (step 123). If these account names match (step 125, yes), the control unit 100 stores the refresh token received in step 117 in the user information storage unit 111, associating it with the account name of user U (step 127), displays the home screen on the display unit 120 (step 129), and processes the login to the network service 30 as successful. If the account names compared in step 123 do not match (step 125, no), the control unit 100 displays an error on the display unit 120 (step 131), then returns to step 103 and displays the first login screen.

[0035] If the user does not select "New Registration" on the first login screen displayed in step 103 (step 105, No), the process proceeds to step 141 in Figure 5. The control unit 100 receives input of user U's account name and device password from the operation unit 130 (step 141) and authenticates user U based on the user U's account name and device password stored in the user information storage unit 111 (step 143). Hereinafter, authentication performed by the control unit 100 based on the account name and device password, as in this case, is referred to as device authentication. Device authentication is also referred to as second authentication.

[0036] If device authentication fails (step 145, no), the control unit 100 displays an error message indicating that device authentication failed on the display unit 120 (step 147), and then returns to step 103 to display the first login screen. If device authentication is successful (step 145, yes), the control unit 100 reads the refresh token associated with user U's account name from the user information storage unit 111 (step 149) and sends it to the authentication server 30 via the network NW using the communication unit 140 (step 151). If the refresh token sent in step 151 is within its validity period (step 153, yes), the authentication server 30 sends the access token and the refresh token to the MFP 10 via the network NW and proceeds to step 117 described above. On the other hand, if the refresh token sent in step 151 has expired (step 153, no), the authentication server 30 proceeds to step 111 described above.

[0037] Returning to step 101, if the setting to not remember the refresh token is selected (step 101, no), the control unit 100 proceeds to step 161 in Figure 6, and the control unit 100 displays the second login screen on the display unit 120 (step 161). The second login screen accepts the input of an account name via the operation unit 130. The second login screen will be described in more detail later.

[0038] When an account name is entered on the second login screen, the control unit 100 accesses the authentication server 30 (step 163). In response to the access, the authentication server 30 sends the service authentication screen data to the MFP 10, and when the communication unit 140 receives this data, the control unit 100 displays the service authentication screen on the display unit 120 (step 165).

[0039] When user U enters an account name and service password using the operation unit 130 on the displayed service authentication screen (step 167), the control unit 100 transmits the entered account name and service password to the authentication server 30 via the network NW using the communication unit 140. Alternatively, instead of transmitting the account name entered by user U using the operation unit 130 to the authentication server 30, the control unit 100 may store the account name entered on the second login screen and transmit that stored account name to the authentication server 30.

[0040] Upon receiving the account name and service password, the authentication server 30 performs authentication and sends the authentication result to the MFP 10 via the network NW. If authentication is successful, the authentication server 30 sends an access token and a refresh token to the MFP 10.

[0041] If the authentication result received by the communication unit 140 is an authentication failure (step 169, no), the control unit 100 returns to step 165 and prompts user U to re-enter their account name and service password. In other words, unless the operation unit 130 receives an operation to interrupt communication with the authentication server 30 (for example, an operation to close the browser running to access the authentication server 30), the control unit 100 will continue to display the service authentication screen, accept input of authentication information, and send authentication information to the authentication server 30 until authentication is successful at the authentication server 30.

[0042] If the authentication result received by the communication unit 140 indicates successful authentication (step 169, yes), the control unit 100 receives an access token and a refresh token (step 171). The control unit 100 transmits the received access token and a user information request to the authentication server 30 via the communication unit 140 and the network NW (step 173). Upon receiving this, the authentication server 30 responds to the user information request based on the access token and transmits the user information to the MFP 10.

[0043] When the communication unit 140 receives user information (step 175), the control unit 100 compares the account name entered on the second login screen (step 161) with the account name included in the user information received in step 175 to determine whether they match (step 177).

[0044] If the two account names match (step 179, yes), the control unit 100 updates the user information stored in the user information storage unit 111 using the user information received in step 175 (step 181), displays the home screen on the display unit 120 (step 183), and processes the login to the network service 30 as successful. If the two account names do not match (step 179, no), the control unit 100 displays an error on the display unit 120 (step 185) and returns to step 161.

[0045] In the above description, it was explained that in step 117, the MFP 10 receives an access token and a refresh token from the authentication server 30. Also, it was explained that in step 121, the MFP 10 receives user information from the authentication server 30. However, in steps 117 and 121, if an error response is received from the authentication server 30, or if reception fails due to a network failure or other reason, the control unit 100 may display an error on the display unit 120, similar to how "No" is selected in step 125 and the process proceeds to step 131 where an error is displayed.

[0046] Furthermore, in the above explanation, it was stated that in step 175, the MFP 10 receives user information from the authentication server 30. However, if, for example, an error response is received from the authentication server 30 in step 175, or if reception fails due to a network failure or other reason, the control unit 100 may display an error on the display unit 120, similar to how "No" is selected in step 179 and an error is displayed in step 185.

[0047] [1.4 Example of Authentication System Operation] Figure 7 is a schematic diagram illustrating an example of the operation of the authentication system 1. In this example, the account name and device password for the network service 30 are linked and stored in the user information storage unit 111, and the MFP 10 is configured to store a refresh token. First, when user U enters the account name and device password (PW) into the MFP 10 (1), the MFP 10 performs device authentication based on the entered account name and device password. If device authentication is successful, the MFP 10 accesses the authentication server 30 and displays the service authentication screen. When user U enters the account name and service password (PW) on the service authentication screen (2), the MFP 10 sends the entered account name and service password to the authentication server 30. Based on the received account name and service password, the authentication server 30 authenticates user U and sends an access token and a refresh token to the MFP 10 (3). The MFP 10 sends a user information request to the authentication server 30 along with the received access token (4). The authentication server 30 responds to the user information request based on the access token sent from the MFP 10 and sends the user information corresponding to the access token to the MFP 10 (5). Upon receiving the user information, the MFP 10 stores the user U's account name, device password, and refresh token in the user information storage unit 111, linking them together (6), and displays the home screen (7).

[0048] [1.5 MFP Screen Transitions] Screen D10 in Figure 8 is an example of a settings screen. Screen D10 is displayed on the display unit 120 by the settings processing unit 107. Screen D10 has a register button D101, a checkbox D105, an update button D107, and pull-down menus D109 and D111.

[0049] The registration button D101 is used to register settings while they are displayed on screen D10 and to move from screen D10 to another screen (for example, the home screen). The checkbox D105 is used to set whether or not to remember the refresh token. In the example in Figure 8, checkbox D105 is set to remember the refresh token. The update button D107 is used to update settings while they are displayed on screen D10. The pull-down menu D109 is used to set whether or not to enable user authentication. In the example in Figure 8, pull-down menu D109 is set to enable user authentication. The pull-down menu D111 is used to set the authentication destination when a user logs in to MFP10. In the example in Figure 8, pull-down menu D111 is set to set network service 30 as the authentication destination.

[0050] It may be possible to configure whether or not to store user information in the MFP10. To enable this setting, for example, a checkbox for setting whether or not to store user information could be provided on screen D10 in Figure 8. In an MFP10 where it is possible to configure whether or not to store refresh tokens, if the setting to store user information in the user information storage unit 111 is enabled, the control unit 100 may enable the setting to store refresh tokens. On the other hand, in this MFP10, if the setting to store refresh tokens is enabled, the setting may be restricted so that the setting to store user information in the user information storage unit 111 cannot be disabled.

[0051] Figure 9 is a diagram illustrating the screen transitions when the refresh token is set to be remembered. When the refresh token is set to be remembered, the first login screen D20 is displayed first (step 103). If new registration is selected on the first login screen D20 (step 105, yes), the account registration screen D40 is displayed (step 107), and then the service authentication screen D50 is displayed (step 111). At this time, the login name entered on the account registration screen D40 may be reflected in the account name on the service authentication screen D50 when the service authentication screen D50 is displayed. If the account name and service password for network service 30 are entered on the service authentication screen D50 and the sign-in button is operated (step 112) and authentication is successful, the home screen D70 is displayed.

[0052] On the other hand, if new registration is not selected on the first login screen D20 (step 105, no), and the account name and device password are entered on the first login screen D20 (step 141), a refresh token is read from the storage unit 110 and sent to the authentication server 30. If the refresh token is within its validity period, an access token and a refresh token are issued by the authentication server 30. If authentication is successful by sending the issued access token to the authentication server 30, the home screen D70 is displayed without the service authentication screen D50 being displayed.

[0053] Thus, according to authentication system 1, if the setting to store refresh tokens is enabled, the account name (login name, username) and device password of network service 30 are registered in association with each other. Within the validity period of the refresh token, authentication to the authentication server 30 and login to the MFP 10 can be performed simply by entering the account name and device password.

[0054] Figure 10 is a diagram illustrating the screen transitions when the refresh token is not remembered. When the refresh token is not remembered, the second login screen D60 is displayed first (step 161). As will be described later, there is no need to enter a device password on the second login screen D60, and entering the account name for the network service 30 will transition to the service authentication screen D50 (step 165). If authentication to the network service 30 is successful after entering the account name and service password on the service authentication screen D50 (step 167), an access token and a refresh token will be issued from the authentication server 30, and if authentication is successful after sending the issued access token to the authentication server 30, the screen will transition to the home screen D70 (step 183).

[0055] [1.6 Example of MFP screen] Figure 11 shows an example of the first login screen D20. The first login screen D20 has an authentication destination button D201, text input fields D203 and D205, a new registration button D207, and an OK button D209. The authentication destination button D201 is a button for changing the authentication server (network service) 30, which is the authentication destination, in response to operations via the operation unit 130. In this figure, "yyy" is displayed as the name of the network service 30. Alternatively, instead of displaying the name of the network service 30 as the authentication destination, the domain name of the network service 30 may be displayed. When the authentication destination button D201 is operated via the operation unit 130, the authentication destination specification screen D30, which will be described later, is displayed overlaid on the first login screen D20. The text input field D203 is a field for entering the login name (account name) via the operation unit 130. The text input field D205 is a field for entering the device password via the operation unit 130. The New Registration button D207 is used to register a new device password corresponding to the login name (account name) entered in input field D203. When this button is operated via the operation unit 130, the control unit 100 determines "Yes" in step 105 of Figure 4 and proceeds to step 107, "Display of Account Registration Screen". When the OK button D209 is operated via the operation unit 130, the control unit 100 performs device authentication in steps 141-145 of Figure 5 based on the login name (account name) entered in text input field D203 and the device password entered in text input field D205.

[0056] Figure 12 shows an example where the authentication destination selection screen D30 is displayed in response to the operation of the authentication destination button D201 on the first login screen D20. The authentication destination selection screen D30 is a screen for selecting an authentication destination. The authentication destination selection screen D30 has, but is not limited to, buttons D301 and D303, a text input field D305, and button D307. Button D301 is a button for selecting a machine (MFP10 in this embodiment) as the authentication destination. Button D303 is a button for selecting "yyy", which is a specification item for specifying network service 30 as the authentication destination in the example of Figure 12. Since "yyy" is selected as the authentication destination on the first login screen D20, button D303 may be displayed in a different display form (different display color, etc.) than the other unselected buttons. The text input field D305 is a field for adding other authentication destinations as options via the operation unit 130, and functions as button D305 after the additional authentication destinations have been entered. In the example in Figure 12, button D305 is displayed for selecting the authentication service specified as "zzz" as the authentication destination. Button D307 is a button for confirming the selection of the authentication destination; when button D307 is operated, the authentication destination selected by the user is confirmed as the new authentication destination.

[0057] Figure 13 shows an example of the account registration screen D40. The account registration screen D40 has text input fields D401, D403, D405, and a button D407. Text input field D401 is a field for entering the login name (account name) to be registered via the operation unit 130. Text input field D403 is a field for entering the device password via the operation unit 130. Text input field D405 is a field for re-entering the device password via the operation unit 130. Button D407 accepts an operation to register the login name (account name) and device password, based on the input in text input fields D401, D403, and D405, in response to an operation via the operation unit 130. When button D407 is operated via the operation unit 130, the control unit 100 compares the strings entered in text input fields D403 and D405. If they match, it accepts an operation to register an account where the string entered in text input field D401 is used as the login name (account name) and the strings entered in text input fields D403 and D405 are used as the device password. If the strings entered in text input fields D403 and D405 do not match, the control unit 100 prompts the user to re-enter the device password by displaying an error message on the display unit 120. Note that the account name of user U registered with the network service 30 must be entered in text input field D401, and this may be indicated to the user on the account registration screen D40.

[0058] Figure 14 shows an example of the service authentication screen D50. The screen data for the service authentication screen D50 is transmitted from the authentication server 30 to the MFP 10 via the network NW. When the communication unit 140 in the MFP 10 receives the screen data for the service authentication screen D50, the control unit 100 displays the service authentication screen D50 on the display unit 120 based on that screen data.

[0059] The service authentication screen D50 has text input fields D501 and D503, and a button D505. Text input field D501 is for entering the account name for the network service via the operation unit 130. Text input field D503 is for entering the service password via the operation unit 130. Button D505 is for requesting the authentication server 30 to perform service authentication. When button D505 is operated, the authentication server 30 performs service authentication using the string entered in text input field D501 as the account name and the string entered in text input field D503 as the service password. The service authentication screen D50 may also include buttons for changing the service password and for changing the account name used for signing in.

[0060] Figure 15 shows an example of the second login screen D60. The second login screen D60 has a button D601, a text input field D603, and a button D609. Button D601 is a button for changing the authentication server (network service) 30, which is the authentication destination, in response to an operation via the operation unit 130. In this figure, "yyy" is written as the name of the network service 30. When button D601 is operated via the operation unit 130, the authentication destination specification screen D30 is displayed overlaid on the second login screen D60. The text input field D603 is a field for entering the login name (account name) via the operation unit 130. Button D609 is an OK button, and when operated via the operation unit 130, the control unit 100 performs the service authentication shown in Figure 6, steps 163 to 169, based on the login name (account name) entered in the text input field D603.

[0061] [1.7 Effects] As described above, if the refresh token is set to be remembered (Step 101, Yes) and this is not a new registration (Step 105, No), then as long as the refresh token is within its validity period, user U can receive an access token from the authentication server 30 simply by entering the account name and device password for the network service 30. In this case, user U does not need to enter the service password, thus reducing the risk of the service password being leaked. The device password is a password used only for authentication within the MFP10, and even if a third party illegally obtains the device password, it is invalid on devices other than the MFP10. Therefore, even if the MFP10's device password is used on a device other than the MFP10, an access token cannot be received from the authentication server 30. Thus, the risk is reduced compared to the case where the service password is leaked. Even if the refresh token is set to be remembered (Step 101, Yes) and it is a new registration (Step 105, Yes), the account name entered on the account registration screen (Step 107) is compared with the account name included in the user information received from the authentication server 30 (Step 125), and an error is displayed if there is a mismatch (Step 131). This verifies whether the account name entered when registering an account with the MFP10 matches the account name authenticated by the authentication server 30, and if there is a mismatch, operations by the person currently operating the MFP10 can be restricted.

[0062] Furthermore, if the refresh token is not remembered (step 101, no), the account name entered on the second login screen (step 161) is compared with the account name included in the user information received from the authentication server 30 (step 177), and an error is displayed if there is a mismatch (step 185). This verifies whether the account name entered when logging into the MFP10 matches the account name authenticated by the authentication server 30, and if there is a mismatch, operations by the person currently operating the MFP10 can be restricted.

[0063] Thus, the MFP10 allows users to choose whether or not to store the refresh token. Therefore, when operating the MFP10, administrators can choose not to store the refresh token if security policies set by the administrator or network service restrict the storage of the refresh token in the MFP10, or they can choose to store the refresh token if there are no such restrictions.

[0064] [2. Variant] This disclosure is not limited to the embodiments described above, and various modifications are possible. That is, embodiments obtained by combining technical means that are appropriately modified without departing from the gist of this disclosure are also included in the technical scope of this disclosure.

[0065] In step 113, the authentication server 30 authenticated user U based on the account name and service password entered by user U via the operation unit 130, but the authentication server 30 may authenticate user U using other authentication methods. For example, the authentication server 30 may authenticate user U based on the results of biometric authentication (e.g., fingerprint authentication, facial recognition, etc.) or PIN (Personal Identification Number) code authentication performed on a terminal other than the MFP 10 owned by user U, such as user U's mobile phone, smartphone, or personal computer. In this disclosure, the information used by the authentication server 30 to authenticate user U is collectively referred to as authentication information (or first authentication information). The first authentication information includes information necessary for so-called password authentication, such as the account name and service password, as well as information relating to the results of authentication performed on other terminals.

[0066] In the embodiments, the programs that run in each device are programs that control the CPU and other components (programs that make the computer function) in order to realize the functions of the embodiments described above. The information handled by these devices is temporarily stored in a temporary storage device (e.g., RAM) during processing, and then stored in various storage devices such as ROMs (Read Only Memory), HDDs, and SSDs (Solid State Drives), and read, modified, and written by the CPU as needed.

[0067] Here, the recording medium for storing the program may be any of the following: semiconductor media (e.g., ROM, non-volatile memory cards, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray® Disc), etc.), magnetic recording media (e.g., magnetic tape, flexible disk, etc.). Furthermore, in addition to realizing the functions of the embodiments described above by executing the loaded program, the functions of this disclosure may also be realized by processing in cooperation with the operating system or other application programs, etc., based on the instructions of the program.

[0068] Furthermore, when distributing the program to the market, it can be stored on a portable storage medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is, of course, also included in this disclosure. [Explanation of Symbols]

[0069] 1. Authentication System 10 MFP (Multi-Function Printer / Peripheral) 30 Network Services (Authentication Server) 100 Control Unit 101 Device Authentication Processing Unit 103 Service Authentication Processing Unit 105 User Information Acquisition Unit 107 Setting Processing Unit 110 Storage section 110A ROM (Read Only Memory) 110B RAM (Random Access Memory) 110C Storage 111 User Information Storage Unit 113 Setting memory unit 120 Display section 130 Operation section 140 Communications Department 150 connection part 160 Image Input Section 170 Image forming unit NW Network U users

Claims

1. The system comprises a control unit, a communication unit that can communicate via a network with a server that performs first authentication based on first authentication information including an account name, and a storage unit. The control unit, The server receives the refresh token sent in response to the result of the first authentication, Based on the setting regarding whether or not to store the refresh token in the storage unit, the storage of the refresh token in the storage unit is controlled. Information processing device.

2. The first authentication information includes the account name and the first password, The storage unit stores a second password, which is different from the first password, and the account name in association with each other. The control unit performs a second authentication based on the account name and the second password. The information processing apparatus according to claim 1.

3. If the setting is configured to store the refresh token in the storage unit, the control unit shall The refresh token is stored in the storage unit, linked to the account name and the second password. The information processing apparatus according to claim 2.

4. If the setting is configured to store the refresh token in the storage unit, the control unit shall The system accepts input of the aforementioned account name and the aforementioned second password, The refresh token, stored in the storage unit and associated with the entered account name and the second password, is transmitted to the server using the communication unit. The information processing apparatus according to claim 3.

5. Furthermore, it is equipped with an operating unit, If the setting is configured so that the refresh token is not stored in the storage unit, the control unit shall The account and the first password are entered using the operation unit. The received account and the first password are transmitted to the server using the communication unit. The information processing apparatus according to claim 3.

6. A control method for an information processing device comprising a communication unit that can communicate via a network with a server that performs a first authentication based on first authentication information including an account name, and a storage unit, The steps include receiving a refresh token sent by the server in accordance with the result of the first authentication, A step of controlling the storage of the refresh token in the storage unit based on a setting regarding whether or not to store the refresh token in the storage unit. A control method for an information processing device, including the device itself.