Mobile device, its control method, and program
The system enables convenient user authentication and service access by using short-range wireless communication between a mobile terminal and an information processing device, addressing the inefficiencies of traditional IC card-based methods.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- CANON KK
- Filing Date
- 2026-02-27
- Publication Date
- 2026-06-02
AI Technical Summary
Conventional IC card-based user authentication for multifunction devices requires physical proximity and can be time-consuming, leading to inconvenience.
A communication system utilizing short-range wireless communication between a mobile terminal and an information processing device, enabling user authentication and service access by simply approaching the device with the mobile terminal, reducing authentication time.
Allows users to receive services from an information processing device conveniently by using their mobile device, eliminating the need for physical contact and reducing authentication wait times.
Smart Images

Figure 2026090545000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a communication system, an information processing apparatus, a mobile terminal and a control method thereof, and a program.
Background Art
[0002] When logging in to a conventional multifunction device, the user has been authenticated and logged in by causing the multifunction device to read the user's IC card into a card reader connected to the multifunction device (for example, Patent Document 1).
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] When logging in using an IC card as in the prior art, it is necessary to hold the IC card over the card reader. Also, after holding the IC card over the card reader, it may take time until the user authentication is completed, which means it takes time for the user to log in.
[0005] An object of the present invention is to solve the problems of the above prior art.
[0006] A feature of the present invention is to provide a technique that enables a user to receive services of an information processing apparatus simply by the user carrying a mobile terminal and approaching the information processing apparatus, and that reduces the waiting time required for user authentication to improve user convenience.
Means for Solving the Problems
[0007] To achieve the above objective, a communication system according to one aspect of the present invention has the following configuration. That is, A communication system having a mobile terminal and an information processing device, The aforementioned mobile terminal is An acquisition means for acquiring the distance between the information processing device and the information processing device based on the signal of short-range wireless communication between the information processing device and the information processing device, An establishment means for establishing short-range wireless communication with the information processing device when the distance acquired by the acquisition means is shorter than a first predetermined value, A first transmission means that transmits a service request to the information processing device while the short-range wireless communication is established, It includes a first receiving means for receiving a response to a request for the service from the information processing device, The aforementioned information processing device is A second receiving means for receiving service requests from the aforementioned mobile terminal, The system is characterized by having a second transmission means for transmitting a response to a request for the service to the mobile terminal via short-range wireless communication. [Effects of the Invention]
[0008] According to the present invention, a user can receive services provided by an information processing device simply by approaching the information processing device using a mobile device owned by the user.
[0009] Other features and advantages of the present invention will become apparent from the following description with reference to the accompanying drawings. In the accompanying drawings, the same or similar components are given the same reference numeral. [Brief explanation of the drawing]
[0010] The attached drawings are included in the specification and constitute part thereof, illustrating embodiments of the present invention and are used together with the description to explain the principles of the present invention. [Figure 1] A diagram showing an example configuration of a communication system according to Embodiment 1 of the present invention. [Figure 2]Block diagram for explaining the hardware configurations of the MFP and the mobile terminal according to Embodiment 1. [Figure 3] Block diagram (A) for explaining the software configuration of the MFP according to Embodiment 1 and block diagram (B) for explaining the software configuration of the mobile terminal according to Embodiment 1. [Figure 4] Diagram for explaining an example of the screen displayed on the operation unit of the MFP according to Embodiment 1 and the screen transition related to login and logout. [Figure 5] Diagram showing an example of the Bluetooth service provided by the MFP according to Embodiment 1. [Figure 6] Flowchart showing the basic operations of the mobile terminal according to Embodiment 1. [Figure 7] Flowchart showing the details of the usage process of the MFP in S608 of FIG. 6. [Figure 8] Diagram showing the UI for presenting alternative functions to the user on the mobile terminal [Figure 9] Flowchart for explaining the details of the usage process of the alternative function in S710 of FIG. 7. [Figure 10] Flowchart showing the details of the end-of-usage process of the MFP in S611 of FIG. 6. [Figure 11] Flowchart for explaining the operation of the local login process in the MFP according to Embodiment 1. [Figure 12] Flowchart showing the operation of the logout process in the MFP according to Embodiment 1. [Figure 13] Flowchart showing the operation when the MFP receives a login request from the mobile terminal. [Figure 14] Diagram for explaining an example of the states of the MFP and the mobile terminal according to Embodiment 1 of the present invention. [Figure 15] Diagram for explaining the user authentication service and characteristics by Bluetooth provided by the MFP according to Embodiment 2 of the present invention. [Figure 16] Diagram showing the sequence when the mobile terminal according to Embodiment 2 makes a login request to the MFP. [Figure 17]Flowchart for explaining the manual logout process by the MFP according to Embodiment 3. [Figure 18] Diagram for explaining the characteristics of the user authentication service of the MFP according to Embodiment 4 of the present invention. [Figure 19] Flowchart showing the details of the process of S608 in FIG. 6 in Embodiment 4. [Figure 20] Flowchart for explaining the operation of the local login process in the MFP according to Embodiment 4. [Figure 21] Block diagram for explaining the hardware configuration of the MFP according to Embodiment 5 of the present invention. [Figure 22] Flowchart for explaining the process until the MFP according to Embodiment 5 logs in and logs out the user of the mobile terminal by a signal from the mobile terminal. [Figure 23] Flowchart for explaining the process by which the mobile terminal 102 according to Embodiment 5 logs in to the MFP101.
Modes for Carrying Out the Invention
[0011] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the present invention according to the claims, and not all combinations of the features described in this embodiment are essential for the solution means of the present invention. In the embodiments described below, a multi-functional peripheral (MFP) will be described as an example of an information processing apparatus according to the present invention. However, the information processing apparatus according to the present invention is not limited to such a multi-functional peripheral, and can also be applied to communication devices such as printers, scanner, facsimile, and information devices such as PCs.
[0012] [Embodiment 1] FIG. 1 is a diagram showing a configuration example of a communication system according to Embodiment 1 of the present invention.
[0013] This communication system involves multiple MFPs (Multifunction Printers) and multiple mobile terminals, assuming an office environment where, for example, each user possesses and always carries their own mobile terminal. Each MFP has functions such as copying, sending and receiving faxes, scanning, boxing, sending, and printing, and is installed according to the office environment. In the system shown in Figure 1, MFP 101 and mobile terminals 102 and 103 are shown, but the number of these devices is not limited to these.
[0014] Mobile terminals 101 and 102 are each owned by different users. MFP 101 is connected to the network (LAN) 104 and can communicate with other terminals connected to LAN 104 via LAN 104. Similarly, mobile terminals 102 and 103 can connect to LAN 104 via wireless router 105 and can communicate wirelessly with other terminals connected to LAN 104. In addition, MFP 101 and mobile terminals 102 and 103 are equipped with Bluetooth® communication functionality as a short-range wireless communication function and can connect and communicate with each other within the range of Bluetooth radio waves.
[0015] Figure 2 is a block diagram illustrating the hardware configuration of the MFP 101 and the mobile terminal 102 according to Embodiment 1. Note that the hardware configuration of the mobile terminal 103 is the same as that of the mobile terminal 102, so its explanation is omitted.
[0016] First, let's explain the hardware configuration of the MFP101.
[0017] The CPU 201 controls the overall operation of the MFP 101. The CPU 201 reads control programs stored in the ROM 202 and performs various controls such as read control, print control, and transmit control. The RAM 203 is a volatile memory used as a work area when the CPU 201 executes various programs. The HDD 204 stores image data and various programs. The operation unit 205 is equipped with a display unit that operates as a touch panel that can be operated with the user's finger, as well as hard keys. The printer 206 prints images onto a sheet according to image data transferred via the internal bus 221. The scanner 207 reads an image on a document and generates image data. The IC card reader 208 reads the IC card owned by the user for user authentication. The Bluetooth I / F 209 is an interface that performs wireless communication using the Bluetooth standard and communicates wirelessly with other devices that have a Bluetooth I / F. In Embodiment 1, the MFP 101 can communicate with mobile terminals 102 and 103 using the Bluetooth standard. The network interface 210 has a NIC (Network Interface Card) for connecting to the LAN 104. The timer 223 measures a predetermined time according to the instructions of the CPU 201, and notifies the CPU 201 by interrupt or other means when the specified time has elapsed. The internal bus 221 connects the CPU 201 to the above-mentioned parts and transmits data, control signals, etc. The program executed by the CPU 201 may be installed on the HDD 204 and loaded into RAM 203 and executed at runtime.
[0018] Next, we will explain the hardware configuration of the mobile terminal 102.
[0019] The CPU 211 controls the overall operation of the mobile terminal 102. The RAM 212 is a volatile memory used as a work area when the CPU 211 executes various programs. The flash memory 213 is a non-volatile memory that stores various programs and data. The operation unit 214 has a display unit that operates as a touch panel that can be operated with the user's finger. The Bluetooth I / F 215 is an interface for communication via Bluetooth and communicates with other devices that have a Bluetooth interface. In Embodiment 1, the mobile terminal 102 communicates with the MFP 101 via Bluetooth. The wireless network interface 216 is a wireless-enabled NIC that can connect to and communicate with the wireless router 105. The speaker 217 converts electrical signals into sound. The microphone 218 detects sound and converts it into an electrical signal. The camera 219 takes still images and videos and converts them into electronic data. The GPS 220 is a receiver for the Global Positioning System. The internal bus 222 connects the CPU 211 to the aforementioned components and transmits data, control signals, and the like.
[0020] Figure 3 shows block diagram (A) illustrating the software configuration of the MFP 101 according to Embodiment 1, and block diagram (B) illustrating the software configuration of the mobile terminal 102 according to Embodiment 1. Note that the software configuration of the mobile terminal 103 is the same as that of the mobile terminal 102, so its explanation is omitted.
[0021] Figure 3(A) is a block diagram showing the software configuration of the MFP101 and the data areas managed by the software. Documents 304, print jobs 305, counters 306, and user accounts 313 represent the data areas that the software stores and manages in RAM 203 and HDD 204. Platform 301 can be configured to include an operating system such as Linux®, a JAVA® virtual machine, an OSGi® framework, and a group of device drivers. JAVA is a registered trademark of Oracle Corporation. The OSGi framework is a JAVA-based service platform defined by the OSGi Alliance (standardization organization). Platform 301 includes a group of device drivers for controlling various hardware and provides APIs for applications running on Platform 301 to utilize the hardware. For example, the Bluetooth control unit 302 is a device driver for controlling the Bluetooth I / F 209, and the network control unit 303 is a device driver for controlling the network I / F 210. Although not shown in the diagram, a printer module for controlling printer 206 and a scanner module for controlling scanner 207 are also present on this platform 301. Furthermore, platform 301 provides applications with APIs for reading and writing data from document 304, print job 305, and counter 306.
[0022] Menu 307, Copy 308, Print 309, and Send 310 are applications that run on platform 301 and display a user interface that provides various functions to the operation unit 205. For example, Copy 308 controls the scanner 207 and printer 206 via platform 301 to perform copying. Print 309 provides the function to print document data stored in document 304 or print jobs stored in print job 305. Copying and printing output are performed via the API of platform 301, and platform 301 records the number of printed pages in counter 306. Send 310 provides the function to send document data acquired from scanner 207 to an external source. Menu 307 is a module that displays a menu screen for selecting applications (e.g., copy, print, send) from the operation unit 205. Remote UI 311 is a module that provides an HTML-written user interface when MFP 101 is accessed via the HTTP protocol from a web browser of a mobile terminal 102 or 103. The remote UI 311 provides a user interface for managing the settings of the MFP 101 and a user interface for printing document data stored in document 304. The login service 312 is a module that provides login functionality for users to use the MFP 101.
[0023] Next, we will describe the user account management functions, local login functions, remote login functions, and Bluetooth service access login functions provided by the login service 312. • User account management function A user interface is provided to users for registering and managing user accounts. Information registered through the user interface is recorded and managed in user account 313. This managed information includes, for example, username, password, IC card number, and role, as shown in Table 1 (User Information List).
[0024] [Table 1]
[0025] • Local login function The control unit 205 provides login / logout functionality to users. A login screen is displayed on the control unit 205 to prevent users who are not logged in from using it. Here, the number of users who can log in locally simultaneously is set to "1". Therefore, multiple users cannot log in locally at the same time. If a user logs in successfully, the display screen of the control unit 205 transitions from the login screen to the menu screen, making the MFP101 available for use by the user. Multiple login methods are provided as means of performing local login. For example, the following login methods are provided: (1) Login via keyboard The system retrieves the username and password entered by the user through the login screen displayed on the control unit 205, authenticates the user, and then performs the login process. (2) Login using an IC card The IC card reader 208 retrieves the IC card number from the user's IC card held over it to identify the user, and if the user is authenticated, the login process is performed. (3) Login via mobile When a login request is received from a mobile device via Bluetooth communication along with user authentication information, the system authenticates the user and performs the login process. Here, levels are set for mobile login requests, and the system is implemented to reject requests of a predetermined level depending on the state of the MFP101. The MFP101 stores and manages the StatusID shown in Table 2 (List of Login Availability Statuses) in RAM203. As shown in Table 2, if the StatusID is "1", login is possible, but if the StatusID is "2" or "3", the login request may not be accepted depending on the login request level and the state of the MFP101. If the StatusID is "3", after the user logs out, the system will not accept login requests from that user until the user moves out of a predetermined distance range (e.g., 10cm to 2m) from the MFP101.
[0026] [Table 2]
[0027] Next, the system offers several methods for logging out after local login. (1) A logout button (410 in Figure 4) is displayed on the operation unit 205, and when the logout button is pressed, the logout process is performed. (2) If the user does not operate the control unit 205 for a certain period of time, the system will perform a logout process. (3) When a logout request is received from a mobile device, the system performs the logout process.
[0028] After the logout process is complete, the login screen will be displayed.
[0029] Next, we will explain remote login. • Remote login function This system provides login / logout functionality for using the remote UI 311. For example, when access to the remote UI 311 is detected from a mobile device 102, an HTML login screen is sent to the mobile device 102. The system then retrieves the username and password entered on the login screen to authenticate the user and grants permission to log in to the remote UI 311. The system is configured to allow multiple users to log in remotely simultaneously. (2) Login function for Bluetooth service access This service provides login / logout functionality for accessing services exposed via Bluetooth.
[0030] Next, with reference to Figure 3(B), the software configuration of the mobile terminal 102 according to this embodiment will be described. Note that although the following description uses mobile terminal 102 as an example, the same procedures can be followed for mobile terminal 103.
[0031] Document 320 and authentication information 319 indicate the area of data that the software stores and manages in flash memory 213. Platform 314 can be configured with a platform such as Google's Android® or Apple's iOS®. Platform 314 is equipped with a group of device drivers for controlling various hardware and provides APIs for applications running on platform 314 to utilize various hardware. In Embodiment 1, the group of device drivers includes a Bluetooth control unit 315 and a wireless network control unit 316. The Bluetooth control unit 315 is a device driver for controlling the Bluetooth I / F 215, and the wireless network control unit 316 is a device driver for controlling the wireless network I / F 216. Various applications can be installed on the mobile terminal 102 and run on platform 314. In Embodiment 1, it is assumed that the MFP connection application 317 is pre-installed. The MFP connection application 317 has the following functions, for example. (1) Connect to the MFP101 via Bluetooth and send login and logout requests. (2) User authentication information (username and password) used when requesting login can be pre-recorded by the user in the authentication information 319. For example, the username and password pair shown in Table 3 (Authentication Information) below can be recorded.
[0032] [Table 3]
[0033] (3) Connect to the MFP101 via wireless LAN and issue a print request for the photo data and document data recorded in document 320. (4) Launch the web browser 318 and connect to the MFP101's remote UI 311.
[0034] The MFP connection application 317 is assumed to maintain the following configuration values, for example, as shown in Table 4 (Connection Settings List). Table 4 below indicates that a login request will be made when the mobile terminal 102 is within 2m of the MFP 101, and a logout request will be made when it is more than 5m away. It also means that the level of login request will be used differently depending on the distance between the mobile terminal 102 and the MFP 101. As will be described later, the distance at which this request is made may be set to a different value depending on the user. For example, for a user who always works near the MFP 101, the distance at which this request is made will be set to be shorter than for other users.
[0035] [Table 4]
[0036] The above distance may be configured to be changeable by the user of the mobile terminal 102, or it may be configured to obtain the setting from the MFP 101. The Bluetooth RSSI (Received Signal Strength Indication) transmitted by the MFP 101 is used to measure the distance from the MFP 101. It is desirable to make the logout distance longer than the login distance. This is because the RSSI can weaken if there is an obstacle between the mobile terminal 102 and the MFP 101, so this prevents false detections that may cause users to log out due to obstacles. For example, by utilizing the property that the RSSI attenuates as the distance between the MFP 101 and the mobile terminal 102 increases, it is possible to create data showing the relationship between RSSI (dBm) and the distance from the MFP 101, as shown in Table 5 (List of RSSI and Estimated Distances) below.
[0037] [Table 5]
[0038] If the strength of the Bluetooth transmission signal emitted by MFP101 is known in advance, the mobile terminal 102 may be configured to have the relationship data between RSSI and the distance from MFP101 in advance. Alternatively, the mobile terminal 102 may dynamically obtain information regarding the strength of the Bluetooth transmission signal emitted by MFP101 from MFP101 and compare it with the RSSI to calculate the distance from MFP101.
[0039] Figure 4 is a diagram illustrating an example of a screen displayed on the operation unit 205 of the MFP101 according to Embodiment 1, and the screen transitions related to login and logout.
[0040] For example, when a user is not yet logged in, the operation unit 205 displays the login screen 401 and waits for detection of an IC card or reception of a login request via Bluetooth from the mobile terminal 102. When the IC card is detected or a login request is received via Bluetooth, the login process is executed. If the login is successful, the system transitions to the menu screen 403; if the login fails, the original login screen 401 is displayed. If the button 404 for switching to keyboard authentication is pressed on the login screen 401, the system transitions to the login screen 402 for entering an account and password using a soft keyboard. The login screen 402 has a button 405 to return to the login screen 401. If the login button 406 is pressed on the login screen 402, the system retrieves the entered account and password and performs the login process, including user authentication. If the login is successful, the system transitions to the menu screen 403; if the login fails, the original login screen 402 is displayed.
[0041] The menu screen 403 includes buttons 407-409 for calling various applications and a logout button 410. When the logout button 410 is detected to be pressed, the logout process is executed and the login screen 401 is displayed.
[0042] Next, the Bluetooth functions and services provided by the MFP101 according to Embodiment 1 will be described.
[0043] In Embodiment 1, when the MFP101 is powered on, the platform 301 activates Bluetooth via the Bluetooth control unit 302 and sends Bluetooth advertising packets at predetermined intervals. These advertising packets include the following data. • Local Name This is the name of the device, for example, "(Company Name) MFP CXXX". Manufacturer Specific Data This section stores the manufacturer's identifier for the MFP and any other data. It can include information such as the RSSI (Received Signal Strength Indication, e.g., -59 dBm) when a Bluetooth packet is received at a distance of 1 meter from the device. • TX Power Level Transmitted radio wave strength. For example, "-38 dBm". Service UUIDs A UUID that represents the function of the device.
[0044] Figure 5 shows an example of the Bluetooth services provided by the MFP101 according to Embodiment 1.
[0045] This MFP 101 exposes a user authentication service 501, an MFP information service 502, a print service 503, and a maintenance service 504, defined in a GATT (Generic Attribute) profile, to a mobile terminal 102 connected via Bluetooth. The user authentication service 501 includes the following characteristics defined in the GATT profile. The login service 312 reads and writes the values of each characteristic via APIs provided by the platform 301 and the Bluetooth control unit 302. • StatusID505 This characteristic indicates the login status of MFP101. The mobile terminal 102 reads this characteristic to obtain the login status of MFP101. Similar to the login status list, the values shown in Table 6 (StatusID list) below are stored as this value.
[0046] [Table 6]
[0047] The login service 312 changes the value (StatusID) according to the change in status. When the value changes, the Bluetooth control unit 302 notifies the connected mobile terminal 102 of the change in value using Attribute Protocol (ATT) Notification. ·UserName506 This is a characteristic used to write the username when mobile device 102 requests login. Password 507 This is a characteristic for writing the password when the mobile device 102 requests login. It may also be configured as a characteristic that requires encryption of the password to be written. RequestID508 This is a characteristic for mobile terminal 102 to write a request to the authentication service. For example, it writes RequestID 508 as shown in Table 7 (List of RequestIDs) below. Note that the login request levels shown in Table 7 correspond to the login request levels shown in Table 4 above.
[0048] [Table 7]
[0049] ResultID509 This characteristic stores the authentication result (success or failure of user authentication) when MFP101 receives a login request from the mobile terminal 102 and performs user authentication. For example, it stores values such as those shown in Table 8 (List of ResultIDs) below.
[0050] [Table 8]
[0051] When storing the authentication result, the Bluetooth control unit 302 notifies the connected mobile terminal 102 of the authentication result using Attribute Protocol (ATT) Notification.
[0052] The MFP information service 502 includes a URL 510 that characteristically stores the URL of the remote UI 311. The value of URL 510 is set by the platform 301 when the MFP 101 is started.
[0053] The print service 503 is configured as a service that can be searched from the mobile terminal 102 after a successful login for Bluetooth service access. The print service 503 has the following characteristics. The print 309 reads and writes the values of each characteristic via APIs provided by the platform 301 and the Bluetooth control unit 302. • MyJobList511 Print job 305 stores the identifier of the print job associated with the user who logged in for Bluetooth service access, from among the print jobs temporarily stored. If there are multiple print jobs associated with that user, the identifiers of all print jobs are stored. RequestID512 This is a characteristic that the mobile terminal 102 uses to request operations on the print job 305. For example, it is possible to write to the IDs shown in Table 9 (List of Request IDs for Print Services) below. The value written by the mobile terminal 102 is notified to the print 309, and the print 309 performs operations on the print job as requested. In this case, the print job can be instructed to be printed or deleted.
[0054] [Table 9]
[0055] • RequestParameter513 This characteristic stores the identifier of the print job 305 that is the target of the operation when the mobile terminal 102 requests an operation on the print job 305. The mobile terminal 102 writes the print job identifier obtained from MyJobList511.
[0056] Maintenance service 504 is configured as a searchable service from the mobile terminal 102 when the user successfully logs in for Bluetooth service access and the logged-in user's role is administrator. Maintenance service 504 includes Count 514, which stores the count of counter 306 characteristically. The value of Count 514 is set by platform 301 when it detects a change in the value of counter 306.
[0057] Although not shown in the diagram, each service and characteristic includes information such as a handle, UUID, data type information, and text information.
[0058] Next, the basic operation of the mobile terminal 102 according to Embodiment 1 will be described.
[0059] Figure 6 is a flowchart showing the basic operation of the mobile terminal 102 according to Embodiment 1. The following describes the basic operation when a user with the mobile terminal 102 approaches the MFP 101 and begins using the MFP 101, referring to Figure 6. Unless otherwise specified, the CPU 211 is the primary driver of the mobile terminal 102's operation. Unless otherwise specified, the MFP connection application 317 is the primary driver of the software, or the MFP connection application 317 calls APIs provided by the platform 314, which then handles the processing. Here, the CPU 211 is described as the primary driver.
[0060] When processing for the mobile terminal 102 begins, in S601, the CPU 211 starts scanning for Bluetooth advertising packets transmitted from the MFP 101. Then, in S602, when the CPU 211 receives an advertising packet, it proceeds to S603, where the CPU 211 determines whether the source of the advertising packet is a predetermined MFP. Here, it is assumed that the mobile terminal 102 has pre-registered MFPs that the user of the mobile terminal 102 normally uses. Therefore, in S603, the CPU 211 determines whether the source of the received advertising packet is this registered MFP. Specifically, the CPU 211 analyzes the received advertising packet and refers to the values of LocalName, Manufacturer Specific Data, and Service UUIDs, and determines that it is a predetermined MFP if known values are stored. If it is determined in S603 that it is not a predetermined MFP, the advertising packet is ignored and the process proceeds to S602. The reason for performing this S603 check is to prevent users from logging into an MFP simply by approaching or passing by it if they do not intend to use that MFP.
[0061] If S603 determines that the advertising packet is from a designated MFP101, the process proceeds to S604, where the CPU211 calculates the distance between the MFP101 and the mobile terminal 102 from the RSSI. Here, for example, the distance is calculated from the difference between the RSSI and the information on the transmitted radio wave strength emitted by the MFP101 contained in the TX Power Level and Manufacturer Specific Data of the advertising packet. Note that since there is an error in the RSSI, the distance calculation may be performed by sampling multiple advertising packets.
[0062] Next, in S605, the CPU 211 refers to the distance calculated in S604 and the settings shown in the connection settings list table (Table 4) to determine whether or not the MFP 101 is within a predetermined distance for use. In Embodiment 1, the predetermined distance is, for example, within 2m. Note that different distances may be set depending on the user. For example, if user A is working almost always near the MFP 101, setting the distance at which user A can log in to within 2m would result in user A always logging in. In this case, the distance corresponding to user A should be set to, for example, 30cm. If the CPU 211 determines in S605 that the MFP 101 is within the predetermined distance, the process proceeds to S606 to determine whether or not the MFP 101 is in use. As a method of this determination, for example, an MFP usage status flag indicating whether or not it is in use, as shown in Table 10 (MFP usage status flag) below, is recorded in the RAM 212 and used. If MFP101 is in use, its usage flag is set to TRUE, and when use is finished, the flag is set to FALSE, allowing the mobile terminal 102 to manage the usage status of MFP101.
[0063] [Table 10]
[0064] The purpose of managing the usage status of MFP101 here is to prevent submitting another job while MFP101 is running another job. If the MFP usage status flag indicates that it is not in use, the process proceeds to S607, where CPU211 changes the flag to "on" (in use) and proceeds to S608 to execute the process using MFP101. On the other hand, if the MFP usage status flag indicates "in use" in S606, the process terminates immediately.
[0065] On the other hand, if the CPU 211 determines in S605 that the distance to the MFP 101 is not within a predetermined distance, the process proceeds to S609, where it refers to the settings shown in Table 4 of the connection settings list to determine whether the distance to the MFP 101 is greater than or equal to a predetermined distance in order to terminate the use of the MFP 101. In Embodiment 1, this predetermined distance is, for example, 5m or more. If the CPU 211 determines in S609 that the distance is greater than or equal to the predetermined distance, the process proceeds to S610, where the CPU 211 refers to the aforementioned flag to determine whether the MFP 101 is in use. If the CPU 211 determines that the MFP 101 is in use, the process proceeds to S611, where the CPU 211 performs the process to terminate the use of the MFP 101. Then, the process proceeds to S612, where the CPU 211 changes the aforementioned flag to FALSE and terminates this process. If the CPU 211 determines in S609 that the distance to the MFP 101 is not greater than or equal to a predetermined distance, the process proceeds to S602. If the CPU 211 determines in S610 that the MFP 101 is not in use, the process terminates.
[0066] Furthermore, in S601, the MFP connection application 317 does not necessarily need to be running. For example, the MFP connection application 317 can request the platform 314 to monitor whether it has received advertising packets from a designated MFP. The platform 314, upon receiving advertising packets from the designated MFP, can then start the stopped MFP connection application 317.
[0067] In this way, simply by bringing the mobile terminal 102 close to a designated MFP, the MFP can be put into a usable state. Furthermore, the mobile terminal 102 is something that the user always carries with them, so unlike an IC card, the user will not forget to have it with them.
[0068] Figure 7 is a flowchart showing the details of the MFP usage process for S608 in Figure 6.
[0069] When the mobile terminal 102 starts using the MFP 101, the CPU 211 first establishes a Bluetooth communication connection with the MFP 101 in S701. Unless otherwise specified, all subsequent data communication between the mobile terminal 102 and the MFP 101 is via Bluetooth. Next, in S702, the CPU 211 obtains Bluetooth service information from the MFP 101. In Embodiment 1, it is assumed that information on the user authentication service 501 and the MFP 101's services can be obtained at this point. Next, in S703, the CPU 211 reads the StatusID 505 provided by the user authentication service 501. Then, in S704, the CPU 211 determines whether or not a login request can be made to the MFP 101 based on the distance calculated in S604 and the value obtained by reading the StatusID 505. For example, if the calculated distance is between 2m and 30cm, the CPU 211 determines whether or not a login request at login request level 1 can be made to the MFP 101 based on the value obtained from the StatusID 505. As shown in Table 6 above, if StatusID505 is "1", a login request is possible, but if it is any other value, a login request is deemed impossible. Similarly, for example, if the calculated distance is between 30cm and 10cm, the feasibility of a login request at login request level 2 is determined based on the value obtained from StatusID505. In this case, if StatusID505 is "1" or "2", a login request is possible, and if StatusID505 is "3", a login request is deemed impossible. Also, if the calculated distance is 10cm or less, the login request level is 3, so a login request is deemed possible regardless of the value of StatusID505.
[0070] If CPU211 determines in S704 that a login request is possible, it proceeds to S705 and requests login to MFP101. Specifically, it writes values to UserName506, Password507, and RequestID508 in the user authentication service 501. For UserName506 and Password507, it writes information such as that shown in Table 3's authentication information, and for RequestID508, it writes one of the values "1", "2", or "3" shown in the RequestID list in Table 7 above, depending on the calculated distance. Next, it proceeds to S706 and CPU211 receives a notification from MFP101 updating ResultID509 and StatusID505 as a response. Then it proceeds to S707 and CPU211 disconnects the Bluetooth connection with MFP101 and terminates this process.
[0071] On the other hand, if S704 determines that the login request is not possible, the process proceeds to S708, where the CPU 211 displays a screen on the operation unit 214, for example, as shown in Figure 8, and presents available functions as alternatives to local login.
[0072] Figure 8 is a diagram showing an example screen displaying an alternative function when logging into the MFP is not possible, as shown on the operation panel of the mobile terminal 102 according to Embodiment 1.
[0073] Here, a message is displayed indicating that the MFP101 is unavailable because another user is using it, along with a list of alternative functions. The buttons for the alternative functions are displayed as follows: "Connect to Remote UI" button 801, "Print" button 802, "View Maintenance Information" button 803, and "Cancel" button 804.
[0074] Next, the process proceeds to S709, where the CPU 211 determines, on the screen shown in Figure 8, whether the user has selected an alternative function. If the user does not select an alternative function and presses the cancel button 804, the process proceeds to S707, disconnects the Bluetooth connection with the MFP 101, and terminates. On the other hand, if the user has selected an alternative function, the process proceeds to S710, where the user is provided with the selected alternative function. After providing the alternative function and completing the processing performed by that function, the process proceeds to S707, disconnects the Bluetooth connection with the MFP 101, and terminates.
[0075] Figure 9 is a flowchart illustrating the details of the process for using the alternative function of S710 in Figure 7.
[0076] First, in S901, the CPU211 determines the alternative function selected by the user via the screen shown in Figure 8 and performs processing according to the selected alternative function. For example, if the user selects the "Connect to Remote UI" button 801, the process proceeds to S902. In S902, the CPU211 reads the URL 510 of the MFP information service 502 and obtains the URL of the MFP101's remote UI 311. Next, in S903, the CPU211 launches the web browser 318 and connects to the MFP101's remote UI 311 via the wireless network I / F 216. Finally, in S904, the CPU211 performs remote login using the HTTP protocol.
[0077] On the other hand, if the user selects the "Print" button 802 in S901, the process proceeds to S905, where the CPU 211 requests a login for Bluetooth service access from the MFP 101. Specifically, it writes values to UserName 506, Password 507, and RequestID 508 in the user authentication service 501. Here, UserName 506 and Password 507 are written with the authentication information of the mobile terminal 102 user as shown in Table 3. Also, the value "5" indicating a login request for Bluetooth service access as shown in Table 7 is written to RequestID 508. Next, the process proceeds to S906, where the CPU 211 receives a notification from the MFP 101 indicating the update of ResultID 509 as the authentication result. If the Bluetooth login is successful, the CPU 211 obtains service information in S906 and proceeds to S907.
[0078] In Embodiment 1, after Bluetooth login, the MFP 101 grants access to the print service, and information about the print service becomes available. The CPU 211 of the mobile terminal 102, having obtained the print service information, can then use the print service via S907. For example, it can also obtain information about jobs associated with the authenticated user from the print service. For example, it can also display the user's jobs on the operation unit 214 and accept print commands from the user. When a user commands a print, the print request is written to RequestID 508, and the MFP 101 is instructed to print.
[0079] Furthermore, if, for example, the user selects the "View Maintenance Information" button 803 in S901, the process proceeds to S908, where the CPU 211 requests a login for Bluetooth service access from the MFP 101. Next, the process proceeds to S909, where the CPU 211 retrieves the service information. In Embodiment 1, if the Bluetooth login is successful and the authenticated user's role is administrator, the MFP 101 grants permission to access the maintenance service, making it possible to retrieve the maintenance service information. Once access to the maintenance service is successful, the process proceeds to S910, where the CPU 211 utilizes the maintenance service. Here, for example, information from the maintenance service can be retrieved from the counter 306, and the counter value can be displayed on the operation unit 214.
[0080] Figure 10 is a flowchart detailing the termination process for the MFP101 in step S611 of Figure 6.
[0081] First, at S1001, the CPU 211 initiates the logout process and establishes a Bluetooth connection with the MFP 101. Next, at S1002, the CPU 211 obtains service information and retrieves information about the user authentication service 501. Then, at S1003, the CPU 211 reads the value of StatusID 505. Next, at S1004, the CPU 211 determines whether or not the user is locally logged into the MFP 101 based on the value of StatusID 505. In Embodiment 1, a StatusID of "2" in the list of StatusID 505 in Table 6 indicates that the user is locally logged in. If the CPU determines that the user is locally logged in, it proceeds to S1005 and requests the MFP 101 to log out. Specifically, it writes the username to UserName 506 and the value "4" (Table 7), which indicates a logout request, to RequestID 508. Finally, it proceeds to S1006 to disconnect the Bluetooth connection with the MFP 101 and terminate this process. On the other hand, if S1004 determines that the user is not currently logged in locally, the process proceeds to S1006 without requesting a logout, disconnects the Bluetooth connection with MFP101, and terminates the process.
[0082] According to the process described above, the user can log in to and use the MFP 101 simply by bringing the mobile terminal 102 close to the pre-configured MFP 101. If the MFP 101 is being used by another user, the user who owns the mobile terminal 102 will be presented with selectable alternative functions, and the user can choose and execute one of these alternative functions. Furthermore, after logging in to the MFP 101, the user who owns the mobile terminal 102 will be automatically logged out of the MFP 101 when they move a predetermined distance away from the MFP 101, thus preventing the user from forgetting to log out after logging in.
[0083] Figure 11 is a flowchart illustrating the operation of the local login process in the MFP101 according to Embodiment 1. Unless otherwise specified, the CPU201 is the primary driver of the MFP101's operation. Unless otherwise specified, the primary driver of the software is the login service 312, or the login service 312 calls an API provided by the platform 301, which then handles the processing.
[0084] When CPU201 begins accepting local login requests, it enables login using the keyboard, login using an IC card, and login from a mobile device. Specifically, in S1101, CPU201 enables login using the keyboard and displays the login screen on the operation unit 205, making it possible to detect user login operations. For login using an IC card, in S1102, CPU201 makes it possible to detect the IC card using the IC card reader 208. For login from a mobile device, in S1103, CPU201 exposes the user authentication service defined in the Bluetooth GATT profile, making it possible to detect local login requests via Bluetooth.
[0085] The process then proceeds to S1104, and when CPU201 detects a login request from any source, it proceeds to S1105. In S1105, CPU201 identifies the source of the login request and performs authentication processing according to the source of the login request.
[0086] If the CPU 201 determines in S1105 that the login was performed using the keyboard of the control unit 205, it proceeds to S1106, where the CPU 201 detects the operation on the login screen of the control unit 205 and obtains the username and password entered on that login screen. Next, in S1107, the CPU 201 authenticates the user by comparing and verifying the obtained values with information already registered in the MFP 101, for example, in the user information list shown in Table 1 above, and then proceeds to S1116.
[0087] On the other hand, if CPU201 determines in S1105 that the login is via IC card, it proceeds to S1108. CPU201 detects that an IC card has been placed over the IC card reader 208 and obtains the IC card number. Then, in S1109, CPU201 compares and verifies the obtained IC card number with the IC card numbers registered in the user information list already registered in MFP101 (see Table 1), authenticates the user who possesses that IC card, and proceeds to S1116.
[0088] Furthermore, if CPU201 determines in S1105 that it is a mobile login, it proceeds to S1110, where CPU201 detects that an ID indicating a login request has been written to RequestID508 of the user authentication service 501. CPU201 then obtains the level of the login request (Table 7) from the value written to RequestID508 and compares it with the login availability status in Table 2 to determine whether the login request level is acceptable. For example, if the login availability status for a level 1 login request is not "login possible" (StatusID=1) but rather "StatusID=2" or "3", the login process is canceled. Similarly, if the login availability status for a level 2 login request indicates that level 2 login requests are not accepted (StatusID=3), the login process is also canceled. If the login process is canceled, it proceeds to S1115, where CPU201 sets the value "3" (Table 8) to ResultID509 to indicate that it has been canceled, and notifies the mobile terminal 102 that made the login request of the cancellation via Notification. In S1110, if the login request is level 3, the login request is accepted unconditionally. Once CPU201 determines in S1110 that the login request level is acceptable, it proceeds to S1111, where it determines whether another user is currently logged in locally. If it determines that another user is logged in, it proceeds to S1112, where CPU201 forcibly logs out the logged-in user and proceeds to S1113. If no other user is logged in at S1111, it also proceeds to S1113. In S1113, CPU201 retrieves the username and password by referring to UserName506 and Password507 written from the mobile terminal 102. Then, in S1114, CPU201 authenticates the user by comparing and verifying the retrieved values with the information recorded in the user information list previously registered in MFP101. Next, proceeding to S1115, CPU201 sets the user authentication result to ResultID509, sends the login result to the mobile terminal 102 that made the login request via Notificattion, and proceeds to S1116.
[0089] In S1116, the CPU 201 determines whether user authentication was successful. If authentication fails, it returns to the beginning of the flowchart in Figure 11 and waits for the next login request to be detected. On the other hand, if the CPU 201 determines in S1116 that user authentication was successful, it proceeds to S1117. In S1117, the CPU 201 updates the StatusID 505 of the login status to the value "2," which indicates that "login request level 1 is not accepted because another user is logged in." Then, in S1118, the CPU 201 transitions the display on the operation unit 205 from the login screen to the menu screen, and terminates this login process.
[0090] Furthermore, if the mobile terminal 102 is configured to reliably check in advance whether it is possible to log in to the MFP 101, and to prevent it from mistakenly making a login request to the MFP 101, then the process of determining the level of the login request in S1110 is not necessarily required.
[0091] Next, we will explain the logout process on the MFP101.
[0092] Figure 12 is a flowchart showing the operation of the logout process in the MFP101 according to Embodiment 1. Unless otherwise specified, the CPU201 is the main driver of the MFP101's operation. Unless otherwise specified, the main driver of the software is the login service 312, or the login service 312 calls an API provided by the platform 301, and the platform 301 then performs the processing on its behalf.
[0093] When a user logs in locally, the MFP101 begins accepting logout requests. Here, the following logout methods are enabled: manual logout, timer 223-based logout, and mobile logout. Specifically, for manual logout, in S1201, the CPU 201 displays a logout button 410 (Figure 4) on the operation unit 205, making it possible to detect when the user presses the logout button 401. For timer 223-based logout, in S1202, the CPU 201 detects that there has been no user activity for a certain period of time through timer processing. For mobile logout, in S1203, the CPU 201 detects when a logout request is written to RequestID 508 via Bluetooth from a mobile device.
[0094] Then, proceeding to S1204, CPU201 detects a logout request and proceeds to S1205. In S1205, CPU201 determines whether the logout request is manual, timer-based, or mobile, and performs processing according to the logout request.
[0095] If the CPU 201 detects that the logout button 410 has been pressed in S1205, it proceeds to S1206 and performs the logout process. Next, in S1207, the CPU 201 updates the login status tatusID 505 to the value "3", which indicates that "login requests level 1 and level 2 will not be accepted because the user has just logged out". Further on, in S1208, the CPU 201 starts the timer 223 to check the passage of time. Then, in S1209, the CPU 201 transitions the display on the operation unit 205 to the login screen. At this point, login via keyboard, login via IC card, and login using a level 3 request via Bluetooth become possible. After this, in S1210, if there are no login requests for a certain period of time and the timer 223 detects that a certain period (for example, 10 seconds) has elapsed, the CPU 201 proceeds to S1211. In S1211, CPU201 updates StatusID505, which indicates the login status, to the value "1," which means "login possible." This returns all login methods to a valid state.
[0096] Meanwhile, in S1205, if the CPU 201 detects, based on the timer 223, that there has been no user operation for a certain period of time, it proceeds to S1212, where the CPU 201 performs the logout process. Next, in S1213, the CPU 201 updates the StatusID 505, which indicates the login status, to the value "1," indicating "login possible." Then, in S1214, the CPU 201 displays the login screen on the operation unit 205 and terminates this process.
[0097] In S1205, the CPU 201 detects that a username has been written to UserName 506 via Bluetooth from the mobile terminal 102, and that a logout request has been written to RequestID 508, and proceeds to S1215. In S1215, the CPU 201 detects the mobile logout and determines whether the logged-in username and the username written to UserName 506 are the same. If it determines that the usernames do not match, it cancels the logout request and returns to the beginning of this flowchart to wait for the next logout request. If it determines in S1215 that the usernames match, it proceeds to S1216 and the CPU 201 performs the logout process. Next, in S1217, the CPU 201 updates StatusID 505, which indicates the login status, to the value "1", indicating "login possible". Finally, in S1218, the CPU 201 displays the login screen on the operation unit 205 and terminates this process.
[0098] Figure 13 is a flowchart showing the operation of the MFP 101 according to Embodiment 1 when it receives a login request for Bluetooth service access from a mobile terminal 102. Unless otherwise specified, the main operator of the MFP 101 is the CPU 201. Unless otherwise specified, the main operator of the software is the login service 312, or the login service 312 calls an API provided by the platform 301, and the platform 301 handles the processing.
[0099] This process begins in S1301 when the CPU 201 detects that a "login request for Bluetooth service access" has been written to RequestID 508 of the user authentication service 501. Next, in S1302, the CPU 201 refers to UserName 506 and Password 507 written from the mobile terminal 102 to obtain the user's authentication information, name and password. Then, in S1303, the CPU 201 performs user authentication by comparing and verifying the values obtained in S1302 with the information recorded in the user information list (Table 1) that has been registered in the MFP 101 in advance. Then, in S1304, the CPU 201 determines whether the user authentication was successful. If the user authentication was successful, the process proceeds to S1305, and the CPU 201 makes the print service available for Find from the mobile terminal 102 on the same Bluetooth connection. On the other hand, if the CPU 201 determines in S1304 that user authentication failed, the process proceeds to S1308. Following S1305, the process proceeds to S1306, where CPU201 checks the role of the authenticated user. If the user's role is administrator, the process proceeds to S1307, where the maintenance service is made available for Find from the mobile terminal 102 during the same Bluetooth connection period, and then proceeds to S1308. On the other hand, if CPU201 determines in S1306 that the user's role is not administrator, the process proceeds to S1308.
[0100] In S1308, CPU201 sets the user authentication result to ResultID509 and sends the login result to the mobile terminal 102 that made the login request via Notification. Then, proceeding to S1309, CPU201 detects a Bluetooth disconnection and proceeds to S1310, where CPU201 resets the service exposure status. Specifically, it returns to a state where it cannot find the print service and maintenance service via Bluetooth.
[0101] According to this process, a mobile device user issues a login request for Bluetooth service access to the MFP from their mobile device. Once the login is approved, they can use the printing and other services provided by the MFP.
[0102] Figure 14 is a diagram illustrating an example of the state of the MFP101 and the mobile terminal according to Embodiment 1 of the present invention. The effects of Embodiment 1 will be described below with reference to Figure 14.
[0103] Figure 14(A) shows a state where no one is logged into the MFP101 and a user (Alice) approaches the MFP101 with a mobile device 102. In this case, when the system detects that Alice's mobile device 102 is within 2m of the MFP101, it sends a login request to the MFP101. Therefore, by the time Alice reaches the operation unit 205 of the MFP101, the login is complete, and Alice can use the MFP101 immediately without having to wait in front of the operation unit 205 to log in. Furthermore, if Alice, who is holding the mobile device 102, moves away from the MFP101, she will be automatically logged out if she is more than 5m away from the MFP101, thus preventing her from forgetting to log out.
[0104] Figure 14(B) shows a situation where user (Bob), who owns mobile terminal 103, is using MFP 101, and user (Alice) is approaching MFP 101 with mobile terminal 102. In this case, Alice's mobile terminal 102 does not send a login request to MFP 101 because MFP 101 is in use. Therefore, mobile terminal 102 does not interfere with Bob's use of MFP 101. On the other hand, Alice's mobile terminal 102 is presented with an alternative means, so Alice can also use the functions of MFP 101 to the extent of the functions provided by the alternative means.
[0105] Figure 14(C) shows a scenario where user Carol has finished using the MFP101 but has forgotten to log out, leaving her logged in, and Alice approaches the MFP101 with her mobile device 102. In this case, if the distance between the MFP101 and the mobile device 102 is between 30cm and 2m, Alice's mobile device 102 will not initiate a login request. However, once Alice reaches the operation panel 205 of the MFP101 and the distance between the MFP101 and the mobile device 102 is within 30cm, Alice's mobile device 102 will initiate a login request to the MFP101. This forces the MFP101 to log out Carol and log Alice in. This prevents Alice from mistakenly using the MFP101 while Carol is still logged in. Furthermore, Alice does not need to press the logout button 410 displayed on the operation panel 205 on behalf of Carol.
[0106] Figure 14(D) shows the state immediately after the logout button 410 displayed on the operation panel 205 of the MFP101 is pressed. In this case, even if Bob's mobile terminal 103 is nearby, Bob's mobile terminal 103 will not initiate a login request. Therefore, it is safe because Bob's mobile terminal 103 will not attempt to log in while Alice is in front of the operation panel 205 of the MFP101. Furthermore, if the user who pressed the logout button 410 is Alice, and Alice wants to log in to the MFP101 again immediately after logging out, Alice moves her mobile terminal 102 within 10 cm of the MFP101. This causes Alice's mobile terminal 102 to initiate a login request to the MFP101. In this way, Alice can log in to the MFP101 again, even immediately after logging out.
[0107] [Embodiment 2] Next, Embodiment 2 of the present invention will be described. Embodiment 2 shows an example in which a more secure communication method is implemented than the communication shown in the detailed login flow of Embodiment 1. Note that the configuration of the MFP 101 and mobile terminals 102 and 103, and their system configuration in Embodiment 2 are the same as those of Embodiment 1 described above, so their explanation will be omitted.
[0108] Figure 15 illustrates the Bluetooth-based user authentication service and characteristics of the MFP101 according to Embodiment 2 of the present invention. Parts common to Figure 5 are indicated by the same numbers. In Embodiment 2, the user authentication service of the MFP101 includes the following two characteristics instead of the Password 507 of Embodiment 1 described above. Everything else is the same as in Embodiment 1 described above. Challenge 1501 The characteristic used to store the challenge. This value stores the random number issued by the MFP101 each time. Hash1502 A characteristic used to store hash values.
[0109] In Embodiment 2, in order to prevent unauthorized acquisition of passwords through packet eavesdropping or MFP impersonation, challenge-response user authentication is implemented using Bluetooth characteristics.
[0110] Figure 16 shows the sequence of events when the mobile terminal 102 according to Embodiment 2 makes a login request to the MFP 101. Referring to Figure 16, the method of using the characteristics of the user authentication service according to Embodiment 2 will be explained. Note that the basic operation of the mobile terminal 102 here is the same as in Figure 7 in Embodiment 1.
[0111] When the mobile terminal 102 starts processing the login request in S705, it issues a Read request for Challenge1501 in S1601 and obtains the challenge value in S1602. Next, in S1603, the mobile terminal 102 calculates a hash value using the obtained challenge and the user's password. The algorithm for generating the challenge and calculating the hash value here could be the Challenge-Response Authentication Mechanism (CRAM) described in RFC2195, but the present invention is not limited to this. Next, in S1604, the mobile terminal 102 writes the username to UserName506, the calculated hash value to Hash1502, and writes the login request to RequestID508. As a result, the MFP101 detects the login request and reads the username, hash value, and challenge from the characteristics. After reading these values, it clears them so that other terminals cannot access and refer to them. Then, in S1605, the MFP101 performs user authentication using the username, hash value, and challenge obtained from the characteristic. Specifically, it obtains the challenge set in the characteristic and the user's password registered in the user DB, and calculates a hash value using the same algorithm as the mobile terminal 102. Then, it compares the calculated hash value with the hash value obtained from the characteristic. Once the MFP101 has finished authenticating the user, it updates the challenge in the characteristic with a new value in preparation for the next authentication. The subsequent operation after user authentication is the same as in Embodiment 1.
[0112] As described above, Embodiment 2 enables challenge-response type user authentication using Bluetooth, which is more secure than Embodiment 1 and has the effect of preventing unauthorized acquisition of passwords through packet eavesdropping and MFP impersonation.
[0113] [Embodiment 3] In the aforementioned Embodiment 1, the manual logout process shown in S1206 to S1211 of Figure 12 was modified to not accept login requests other than level 3 immediately after manual logout, thereby resolving the problem that occurs immediately after logout.
[0114] Figure 17 shows the method according to Embodiment 3, which achieves the same effect. Note that the configuration of the MFP 101 and the mobile terminals 102 and 103, and their system configuration according to Embodiment 3 are the same as those of Embodiment 1 described above, so their explanation is omitted.
[0115] Figure 17 is a flowchart illustrating the manual logout process performed by the MFP101 according to Embodiment 3. Unless otherwise specified, the CPU201 is the primary driver of the MFP101's operation. Unless otherwise specified, the primary driver of the software is the login service 312, or the login service 312 calls an API provided by the platform 301, which then performs the processing on behalf of the platform 301.
[0116] First, in S1701, the CPU 201 detects that the logout button 410 has been pressed and performs the logout process. Next, in S1702, the CPU 201 stops sending Bluetooth advertising packets. Next, in S1703, the CPU 201 starts timer 223 to check the passage of time. Then, in S1704, the CPU 201 transitions the display of the operation unit 205 to the login screen. At this point, login is possible using the keyboard, IC card, and Bluetooth login request level 3. After this, in S1705, if there are no login requests for a certain period of time and timer 223 detects the passage of a certain period (for example, 10 seconds), the CPU 201 proceeds to S1706. In S1706, after manual logout, the CPU 201 resumes sending advertising packets after a certain period of time has elapsed.
[0117] As a result, the mobile terminal 102 is unable to detect the distance to the MFP 101 while the MFP 101 has stopped sending advertising packets. This prevents the mobile terminal 102 from making a login request to the MFP 101 when the MFP 101 is performing a manual logout process.
[0118] [Embodiment 4] In embodiments 1 to 3 described above, examples were shown in which the mobile terminal 102 checks the login status of the MFP 101 and decides whether to make a login request. For example, the determination at S704 in Figure 7 corresponds to this. In contrast, embodiment 4 shows an example in which the mobile terminal 102 does not make a determination of login status and leaves the determination of login status to the MFP 101. Note that the configuration of the MFP 101 and mobile terminals 102 and 103 in embodiment 4, and their system configuration are the same as in embodiment 1 described above, so their explanation will be omitted.
[0119] Figure 18 illustrates the characteristics of the user authentication service of the MFP101 according to Embodiment 4 of the present invention. Here, parts common to Figures 5 and 15 are indicated by the same numbers, and their explanations are omitted. In addition to the characteristics of Embodiments 1 and 2 described above, the user authentication service of the MFP101 according to Embodiment 4 includes Distance1801 and Distance1802 for writing the distance calculated by the mobile terminal 102. Furthermore, regarding login requests, levels from level 1 to level 3 as shown in Embodiment 1 are not necessary, and a single RequestID indicating a login request is used. Note that the MFP101 according to Embodiment 4 is assumed to have the login availability status list of Embodiment 4 shown in Table 11 below stored as a setting in advance.
[0120] [Table 11]
[0121] The operation of the mobile terminal 102 according to Embodiment 4 is the same as that described in the flowchart of Figure 6 of Embodiment 1 above, so its explanation will be omitted.
[0122] Figure 19 is a flowchart illustrating the details of the process in S608 of Figure 6 according to Embodiment 4. The detailed flow of S608 in Embodiment 4 will be explained with reference to Figure 19.
[0123] When the CPU 211 of the mobile terminal 102 starts processing the use of the MFP 101, it first establishes a Bluetooth connection with the MFP 101 in S1901. Next, in S1902, the CPU 211 obtains Bluetooth service information from the MFP 101. In this embodiment 4, it is assumed that information for the user authentication service 501 and the MFP information service 502 can be obtained at this point. Next, in S1903, the CPU 211 issues a login request to the MFP 101. In this embodiment 4, when issuing this login request, the distance to the MFP 101 calculated by the CPU 211 of the mobile terminal 102 is written to Distance(1801 or 1802). Next, in S1904, the CPU 211 receives a notification from the MFP 101 regarding the update of ResultID and StatusID as a result of the login process.
[0124] Then, in S1905, the CPU211 determines whether the login was successful based on the received result. If it determines that the login was successful, the process proceeds to S1906, where the CPU211 disconnects the Bluetooth connection with the MFP101 and terminates this process.
[0125] On the other hand, if the CPU 211 determines in S1905 that the login failed, it proceeds to S1907, where the CPU 211 presents the user with available functions as alternative functions instead of performing a local login to the MFP 101. This is the same as in Figure 8 mentioned above. Then, proceeding to S1908, the CPU 211 determines whether the user has selected an alternative function. If the user does not select an alternative function and presses the cancel button 804, it proceeds to S1906, where the CPU 211 disconnects the Bluetooth connection with the MFP 101 and terminates this process. On the other hand, if the CPU 211 determines in S1908 that the user has selected an alternative function, it proceeds to S1909, where it provides the user with the alternative function selected by the user, as explained with reference to the flowchart in Figure 9 mentioned above. After providing this alternative function, it proceeds to S1906, where the CPU 211 disconnects the Bluetooth connection with the MFP 101, which is no longer needed, and terminates this process.
[0126] Figure 20 is a flowchart illustrating the operation of the local login process in the MFP101 according to Embodiment 4. In Figure 20, processes that are the same as those in Figure 11 are given the same number and their explanations are omitted. In Embodiment 1 described above, when the MFP101 receives a login request, at S1110 in Figure 11, it compares the login request level with the login availability status to determine whether the login request level is an acceptable level.
[0127] In contrast, the CPU 201 of the MFP 101 according to Embodiment 4, upon detecting a login request from the mobile terminal 102, proceeds to S2001 and obtains the distance information written to Distance(1801,1802). Next, proceeding to S2002, the CPU 201 refers to the login availability status list (Table 11) of Embodiment 4 and determines whether the distance between the mobile terminal 102 and the MFP 101 is within a distance that allows the login request to be accepted. For example, if the obtained distance is between 2m and 30m, and the login availability status in Table 11 is not "1" (indicating login is possible), but rather "2" or "3", then the system determines that login is not possible and cancels the login process. Also, for example, if the obtained distance is between 30cm and 10cm, and the login availability status is "3", then the system determines that login is not possible and cancels the login process. If the login process is canceled, the value "3" indicating that the login has been canceled is set to ResultID, and the result is notified to the mobile terminal 102 in S2003.
[0128] As explained above, according to Embodiment 4, the mobile terminal 102 does not need to perform any determination or processing based on the distance to the MFP 101, which has the effect of simplifying the processing of the mobile terminal 102.
[0129] [Embodiment 5] Next, Embodiment 5 of the present invention will be described. In Embodiments 1 to 4 described above, the MFP 101 transmitted an advertisement packet, and the mobile terminal 102 received it and determined the distance between the MFP 101 and the mobile terminal 102. In contrast, Embodiment 5 describes an example in which the mobile terminal 102 transmits an advertisement packet, the MFP 101 receives it, and the MFP 101 determines the distance between the MFP 101 and the mobile terminal 102. Although this is described as a process between the mobile terminal 102 and the MFP 101, it can of course be done similarly with the mobile terminal 103, as in the embodiments described above.
[0130] Figure 21 is a block diagram illustrating the hardware configuration of the MFP101 according to Embodiment 5 of the present invention. Note that the hardware configuration of the mobile terminal 102 and the system configuration including the MFP101 and mobile terminal 102 are the same as those of Embodiment 1 described above, so their descriptions are omitted. The MFP101 according to this Embodiment 5 is also basically the same as the MFP101 according to the previously described embodiment, so parts common to Figure 2 are indicated by the same symbols, and their descriptions are omitted.
[0131] The configuration of the MFP101's control unit 2100 is as follows: The CPU 201, RAM 203, ROM 202, SRAM 2101, network interface 210, RIP 2103, scanner image processing unit 2104, printer image processing unit 2105, and storage controller 2108 are connected via the system bus 2114. The CPU 201 is also connected to the operation unit 205 via the UART interface 2101, and to the Bluetooth module 2113 of the operation unit 205 via the USB interface 2109 and USB connector 2110. The scanner image processing unit 2104 receives image data obtained by scanning a document with the scanner 207 via the scanner I / F 2106, performs image processing, and outputs it to the system bus 2114. The printer image processing unit 2105 receives the image data received via the system bus 2114, performs color conversion etc. according to the characteristics of the printer 206, and then outputs it to the printer 206 via the printer I / F 2107 for printing. The storage controller 2108 controls access to the HDD 204. The CPU 201 executes the boot program stored in the ROM 202, then loads the OS and programs installed on the HDD 204 into the RAM 203 and executes them, thereby performing the processes described later.
[0132] Next, the configuration of the control unit 205 will be explained.
[0133] The sub-CPU 2111 controls the operation of the control unit 205. The key display panel 2112 is a display panel with touch panel functionality that receives user input and notifies the sub-CPU 2111. The ROM 2115 stores programs and various data executed by the sub-CPU 2111. The RAM 2116 provides a work area for storing various data when processing is performed by the sub-CPU 2111. The Bluetooth module 2113 communicates with the Bluetooth I / F 215 of the mobile terminal 205 according to the Bluetooth standard.
[0134] The operation of the MFP101 based on the above configuration will be briefly explained. Print data, which is PDL data, is received via LAN104 through the network interface 210. The CPU201 writes the received PDL data to RAM203, and then stores it in HDD204 via storage controller2108. The PDL data stored in HDD204 is converted into a display list by the CPU201 and written back to HDD204 via RAM203. Next, the display list in HDD204 is read by the CPU201, sent to RIP2103 to be converted into raster data, and written back to HDD204. In this way, print jobs submitted to the MFP101 are printed by printer206 when a user logs into the MFP101 using the login method described later. During this printing, raster data is read from HDD204 via system bus2114, and after density, screen processing, etc., are performed by printer image processing unit2105, it is output to printer206 via printer I / F2107.
[0135] Next, we will explain the procedure for users to log in to the MFP101.
[0136] The CPU 201 controls the Bluetooth module 2113 via the USB connector 2110. Specifically, it receives advertising packets of Bluetooth Low Energy communication transmitted from the mobile terminal 102 and performs services such as login requests or print job submissions from the mobile terminal 102. By authenticating with the MFP 101 using the mobile terminal 102 owned by the user, the user can not only execute print jobs but also transition to the operation menu screen of the MFP 101 and obtain the authority to use the MFP 101.
[0137] Next, the communication process between the MFP101 and the mobile terminal 102 according to Embodiment 5 will be described.
[0138] Figure 22 is a flowchart illustrating the process by which the MFP 101 according to Embodiment 5 logs in the user of the mobile terminal 102 via a signal from the mobile terminal 102 and logs them out. The program that executes this process is stored in the HDD 204, loaded into the RAM 203 at runtime, and executed by the CPU 201.
[0139] In Embodiment 5, the MFP 101 and the mobile terminal 102 communicate with each other using the Bluetooth Low Energy communication standard. The services requested by the mobile terminal 102 from the MFP 101 include control that automatically logs in according to a user ID transmitted from the mobile terminal 102 within a predetermined distance from the MFP 101, and automatically logs out when the mobile terminal moves beyond that predetermined distance.
[0140] First, at S2201, CPU201 transitions to the Bluetooth Low Energy standby state. Next, at S2202, CPU201 determines whether user authentication is possible. If user authentication is possible, it proceeds to S2203; otherwise, it waits for user authentication to become possible before proceeding to S2203. At S2203, CPU201 determines whether the service that can receive requests from the mobile terminal 102, in this case authentication processing, is configured. If it is not configured, it proceeds to S2204, prompts the administrator to configure it to enable authentication, and then proceeds to S2203. At S2203, if CPU201 determines that the service that can receive requests from the mobile terminal 102 is configured, it proceeds to S2205, where it determines whether the distance used as the basis for login has been set. If it is determined that it has not been set, it proceeds to S2206, prompts the MFP101 administrator to set the distance. Once the distance required to connect with the source of the received Bluetooth advertising packet is set in MFP101, the process proceeds to S2207. In S2207, CPU201 transitions to a scanning state and waits for the receipt of an advertising packet. In S2208, CPU201 receives an advertising packet and proceeds to S2209 to analyze the received advertising packet. Here, CPU201 obtains the distance from the source, the service UUID, and the user ID. Then, in S2210, CPU201 determines whether the distance from the source of the received advertising packet is within the value set in S2205. If it is determined to be within the set value, the process proceeds to S2211; otherwise, it proceeds to S2208. Here, the distance to be set may also be changed according to the user ID. That is, as explained in Embodiment 1, the distance for user A, who is always working near the MFP101, may be set to, for example, 30 cm, while the distance set for other users may be, for example, 2 m. In this case, S2210 determines whether the connection distance is within the range corresponding to the user ID.In S2211, CPU201 determines whether the service UUID listed in the received advertising packet is for a service that can be configured on MFP101, and in this case, whether it is a request for an authentication service. If so, it proceeds to S2212; otherwise, it proceeds to S2208.
[0141] In S2212, CPU201 transitions to the int state and proceeds to S2213, where it sends a Connect Req packet to the mobile terminal 102 that sent the advertising packet. Then, in S2214, upon receiving the Connect Req packet from the mobile terminal 102, it proceeds to S2215. In S2215, CPU201 executes the login process using the user ID requested by the mobile terminal 102. Here, it refers to the user information list in Table 1 mentioned above to determine whether to allow the user to log in. Then, in S2216, CPU201 notifies the mobile terminal 102 of the result of the login process, whether authentication was successful or not. Next, in S2217, CPU201 transitions to the scanning state, similar to S2207, and in S2218 waits for the receipt of an advertising packet. Upon receiving the advertising packet, it proceeds to S2219. In S2219, CPU201 analyzes the received advertising packet, similar to S2209, to obtain the distance from the source, the service UUID, and the user ID. Next, proceeding to S2220, CPU201 determines whether the distance is sufficient for logging out. In S2220, if CPU201 determines that the source of the advertising packet received in S2218 is the same as the logged-in user ID and the distance is greater than a predetermined distance, proceed to S2221. In S2221, CPU201 logs out the user of the mobile terminal 102 and returns to S2201.
[0142] In this way, the user of the mobile terminal 102 can log in to the MFP 101 simply by approaching the MFP 101 within a predetermined distance while holding the mobile terminal 102. At this time, the MFP 101 is assumed to have pre-registered information such as the distance to the source from which login is possible, the service UUIDs that can be accepted, and the user information to be authenticated.
[0143] Next, the operation of the mobile terminal 102 according to Embodiment 5 will be described.
[0144] Figure 23 is a flowchart illustrating the process by which the mobile terminal 102 according to Embodiment 5 logs into the MFP 101. The program that executes this process is stored in the flash memory 213, and is loaded into the RAM 211 and executed by the CPU 211 at runtime.
[0145] First, in S2301, the CPU 211 launches an application stored in the mobile terminal 102. This application is launched by the user operating the mobile terminal 102. Next, in S2302, the CPU 211 determines whether a user ID for logging into the MFP 101 has been set. If it is determined that no user ID has been set, the process proceeds to S2303, where the CPU 211 prompts the mobile terminal 102 to set the user ID that it wants the user to authenticate with, and then proceeds to S2302. Once the user ID has been set, the process proceeds to S2304, where the CPU 211 determines whether a service UUID to request from the MFP 101 has been set, or in this case, whether a request for authentication services to the MFP 101 has been set. If it is determined that no service UUID has been set, the CPU 211 proceeds to S2305, prompting the user of the mobile terminal 102 to set the service UUID, and then proceeds to S2304. Once the service ID is set in S2304, the process proceeds to S2306, and CPU211 transitions to the state of sending advertising packets.
[0146] Next, the process proceeds to S2307, where the CPU 211 waits for a Connect Req packet from the MFP 101. Upon receiving the Connect Req packet, the process proceeds to S2308, where the CPU 211 transitions to a connected state with the MFP 101. Then, the process proceeds to S2309, where the CPU 211 sends a Connect Res packet to the MFP 101 and proceeds to S2310, where it waits for the authentication result to be received, indicating whether the login process was successful or not. Upon receiving the authentication result in S2310, the process proceeds to S2311, where the result is displayed on the operation panel 214 of the mobile terminal 102. Here, if authentication is successful, for example, "Logged in" is displayed, and if authentication fails, "Login failed" is displayed, etc. Then, the process proceeds to S2312, where the CPU 211 transitions to the advertising state and proceeds to S2307.
[0147] In this way, the user of the mobile terminal 102 can log in to the MFP 101 using the user ID set on the mobile terminal 102 simply by bringing the mobile terminal 102 close to the MFP 101.
[0148] (Other embodiments) The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.
[0149] The present invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, the following claims are attached to make the scope of the invention public. [Explanation of symbols]
[0150] 101…MFP, 102, 103…Mobile terminal, 104…LAN, 105…Wireless router, 201…CPU of MFP101, 211…CPU of mobile terminal, 205, 214…Operation unit, 302, 315…Bluetooth control unit
Claims
1. A communication system having a mobile terminal and an information processing device, The aforementioned mobile terminal is An acquisition means for acquiring the distance between the information processing device and the information processing device based on the signal of short-range wireless communication between the information processing device and the information processing device, An establishment means for establishing short-range wireless communication with the information processing device when the distance acquired by the acquisition means is shorter than a first predetermined value, A first transmission means that transmits a service request to the information processing device while the short-range wireless communication is established, It includes a first receiving means for receiving a response to a request for the service from the information processing device, The aforementioned information processing device is A second receiving means for receiving service requests from the aforementioned mobile terminal, A second transmission means for transmitting a response to the service request to the mobile terminal via short-range wireless communication, A communication system characterized by having the following features.
2. The aforementioned mobile terminal is The system further includes a first determination means that determines whether to transmit a request for the service based on the service information held by the information processing device and the state of the information processing device. The communication system according to claim 1, characterized in that the first transmitting means transmits the service request to the information processing device when the first determination means determines that it should transmit the service request.
3. The communication system according to claim 2, wherein if the first determination means determines not to transmit a request for the service to the information processing device, the mobile terminal further has a presentation means for presenting the user with a function that is an alternative to the service.
4. The communication system according to any one of claims 1 to 3, characterized in that the request for the service is a request for the mobile terminal to log in to the information processing device, and if the distance acquired by the acquisition means is greater than or equal to a second predetermined value which is longer than the first predetermined value, and the mobile terminal is logged in, the mobile terminal requests the information processing device to log out.
5. The mobile terminal transmits a request for the service at a level corresponding to the distance acquired by the acquisition means using the first transmission means. The communication system according to any one of claims 1 to 4, characterized in that the information processing device determines a response to a service request based on the state of the information processing device and the level.
6. The communication system according to claim 1, characterized in that the acquisition means estimates and acquires the distance based on the signal strength of short-range wireless communication between the information processing device and the acquisition means.
7. The aforementioned short-range wireless communication is wireless communication based on the Bluetooth standard, The communication system according to any one of claims 1 to 6, characterized in that the acquisition means acquires the distance based on the signal strength of the advertising packet transmitted by the information processing device.
8. The communication system according to claim 7, characterized in that the information processing device stops transmitting the advertising packets for a predetermined period after the user logs out by manual operation of the user.
9. The request for the aforementioned service is a login request. The information processing device further includes authentication means for authenticating the user of the mobile terminal based on user authentication information from the mobile terminal and user information that has been registered in advance. The communication system according to any one of claims 1 to 8, characterized in that the second transmission means transmits the authentication result by the authentication means.
10. The communication system according to any one of claims 1 to 9, wherein the information processing device further comprises a second determination means that obtains the distance obtained by the acquisition means from the mobile terminal and determines whether or not to accept the request for the service based on the distance and the state of the information processing device.
11. The communication system according to claim 10, characterized in that the information processing device sets the distance at which the second determination means determines that it can accept a request for the service for a predetermined period after the user logs out by manual operation of the user to a shorter distance.
12. The state of the information processing device includes the case where another user other than the user of the mobile terminal is logged in to the information processing device, and if the other user is logged in, the distance over which the service request can be received is set to a shorter distance. The communication system according to any one of paragraphs 2, 5, or 10, characterized in that, if the request for the service is a login request, the system logs out any other users who are currently logged in, and then logs in the user who made the login request.
13. The aforementioned short-range wireless communication is wireless communication based on the Bluetooth standard, The aforementioned information processing device is The system further includes a means for exposing a characteristic that stores a challenge used for user authentication to the mobile terminal, The aforementioned mobile terminal is Means for reading the challenge from the characteristic, A calculation means for calculating a hash value using the challenge and the user's password, The system comprises means for writing the hash value calculated by the calculation means and the user identifier to the characteristic of the information processing device, The communication system according to claim 9, characterized in that the authentication means performs user authentication by comparing the hash value written by the mobile terminal with the hash value obtained from user information pre-registered by the information processing device.
14. A communication system having a mobile terminal and an information processing device, The aforementioned information processing device is An acquisition means for acquiring the distance between the mobile terminal and the mobile terminal based on the short-range wireless communication signal received from the mobile terminal, An establishment means for establishing short-range wireless communication with the mobile terminal when the distance acquired by the acquisition means is shorter than a predetermined value, A first receiving means that receives a service request from the mobile terminal while the aforementioned short-range wireless communication is established, It includes a first transmission means for transmitting a response to the request for the service to the mobile terminal, The aforementioned mobile terminal is A second transmission means that transmits a service request to the information processing device while the short-range wireless communication is established, A second receiving means that receives a response to the request for the aforementioned service from the information processing device, A communication system characterized by having the following features.
15. An information processing device capable of communicating with a mobile terminal, A receiving means that receives a login request from the mobile terminal via short-range wireless communication while the login function using the mobile terminal is enabled, A determination means for determining whether or not to accept the login request according to the level of the login request received by the receiving means and the state of the information processing device, If the determination means determines that the login request is accepted, the authentication means performs authentication of the user of the mobile device. A control means that, upon successful authentication of the user by the authentication means, controls the system to allow the user to log in in response to a login request from the mobile device. An information processing device characterized by having the following features.
16. The information processing apparatus according to claim 15, characterized in that the level of the login request is determined based on the distance between the mobile terminal and the information processing apparatus, which is estimated by the strength of the signal of the short-range wireless communication.
17. An information processing device capable of communicating with a mobile terminal, A receiving means that receives a login request from the mobile terminal via short-range wireless communication while the login function using the mobile terminal is enabled, An acquisition means for acquiring the distance between the mobile terminal and the aforementioned mobile terminal, A determination means for determining whether or not to accept the login request according to the distance acquired by the acquisition means and the state of the information processing device, If the determination means determines that the login request is accepted, the authentication means performs authentication of the user of the mobile device. A control means that, upon successful authentication of the user by the authentication means, controls the system to allow the user to log in in response to a login request from the mobile device. An information processing device characterized by having the following features.
18. A portable terminal capable of communicating with an information processing device, An acquisition means for acquiring the distance to the information processing device, An establishment means for establishing short-range wireless communication with the information processing device when the distance acquired by the acquisition means is shorter than a first predetermined value, A determination means for determining whether it is possible to log in to the information processing device based on the distance and the state of the information processing device when the short-range wireless communication is established, A transmission means that, when the determination means determines that login is possible, transmits a login request to the information processing device. Receiving means for receiving a response to the login request from the information processing device, A mobile terminal characterized by having the following features.
19. The mobile terminal according to claim 18, further comprising a presentation means for presenting the user with a function that serves as an alternative to the login request when the determination means determines that it is not possible to log in to the information processing device.
20. The mobile terminal according to claim 18 or 19, further comprising a request means for requesting the information processing device to log out if the distance acquired by the acquisition means is greater than or equal to a second predetermined value which is longer than the first predetermined value, and the mobile terminal is logged into the information processing device.
21. A control method for controlling an information processing device capable of communicating with a mobile terminal, A receiving step in which a login request is received from the mobile terminal via short-range wireless communication while the login function using the mobile terminal is enabled, A determination step which determines whether or not to accept the login request according to the level of the login request received in the receiving step and the state of the information processing device, If the determination step determines that the login request is accepted, the authentication step performs authentication of the user of the mobile device. If the authentication process successfully authenticates the user, a control process is performed to allow the user to log in in response to a login request from the mobile device. A control method for an information processing device, characterized by having the following features.
22. A method for controlling a mobile terminal capable of communicating with an information processing device, A step of obtaining the distance between the information processing device and the information processing device, If the distance acquired in the acquisition step is shorter than a first predetermined value, the establishment step establishes short-range wireless communication with the information processing device, A determination step in which, with the short-range wireless communication established, a determination is made to determine whether it is possible to log in to the information processing device based on the distance and the state of the information processing device, If the determination step determines that login is possible, a transmission step is performed to send a login request to the information processing device. A receiving step of receiving a response to the login request from the information processing device, A method for controlling a mobile terminal, characterized by having the following features.
23. A program for causing a computer to function as an information processing device according to any one of claims 15 to 17.
24. A program for causing a computer to function as a portable terminal according to any one of claims 18 to 20.