Information processing systems and programs

JP2026126612APending Publication Date: 2026-08-05FUJIFILM BUSINESS INNOVATION CORP
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
FUJIFILM BUSINESS INNOVATION CORP
Filing Date
2025-01-24
Publication Date
2026-08-05

AI Technical Summary

Benefits of technology

【0013】 本開示の第1態様の情報処理システムによれば、複数の情報処理装置のそれぞれにあるサービス機能が追加されていて、情報処理装置とそのサービスの両方でログイン操作が必要な場合に、複数の情報処理装置のうちのいずれかの情報処理装置でログイン操作してそのサービスにログイン操作を行えば、ログイン操作を行った情報処理装置とは別の情報処理装置にログイン操作した場合にそのサービスへのログイン操作を不要にすることができる。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026126612000001_ABST
    Figure 2026126612000001_ABST
Patent Text Reader

Abstract

If multiple information processing devices have added service functions, and login operations are required for both the information processing device and its service, then logging in to the service on any of the multiple information processing devices eliminates the need to log in to the service again when logging in to another information processing device. [Solution] In multiple information processing devices, when an authentication success is returned from an external server managing additional services, the authentication token information sent is transmitted to the management server along with user information that can identify the user. The management server associates the authentication token information sent from one of the multiple information processing devices with the user information and stores it in the synchronization data of that information processing device, as well as in the synchronization data of other information processing devices that perform authentication management in common with that information processing device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an information processing system and a program.

Background Art

[0002] Patent Document 1 discloses an authentication cooperation system including an authentication unit that performs user authentication based on internal user information input in a login operation for an information processing device, an authentication cooperation information holding unit that stores authentication cooperation information including the internal user information when external user information input for using a service provided via a network matches the internal user information, and an authentication cooperation control unit that performs control to permit use of the service for a user who has logged in to the information processing device using the internal user information when the authentication cooperation information is stored in the authentication cooperation information holding unit.

Prior Art Documents

Patent Documents

[0003]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0004] If an application program (hereinafter referred to as "app") providing a service is installed on multiple information processing devices, and login is required for both the information processing device and the app, then after logging in to the desired information processing device, the user must log in again to the app installed on that device. If the user logs in to the same information processing device again, and the login status to the app is maintained for a certain period, the user can use the services provided by the app without needing to log in to the app again. However, if the user logs in to another information processing device among the multiple information processing devices, they will also need to log in to that app again, which is inconvenient for the user.

[0005] The purpose of this disclosure is to provide an information processing system and program that, when multiple information processing devices have additional service functions and login operations are required for both the information processing device and its service, allows users to log in to the service using one of the multiple information processing devices, thereby eliminating the need to log in to the service again when logging in to a different information processing device. [Means for solving the problem]

[0006] An information processing system according to the first aspect of this disclosure is an information processing system comprising a plurality of information processing devices and a management server that manages the plurality of information processing devices, Each of the aforementioned plurality of information processing devices comprises a first processor, The aforementioned first processor, The system uses the first identification information and first password information entered by the user to perform the authentication process for that user, and if the authentication process is successful, it grants the user permission to use the device. When a user enters second identification information and second password information in order to use additional services available on their device, the second identification information and second password information are sent to an external server managing the service to request the execution of authentication processing. If the external server returns a message indicating successful authentication, the user is permitted to use the service, and the authentication token information sent from the external server when the message indicating successful authentication was returned is sent to the management server along with user information that can identify the user. The management server comprises a second processor and a memory unit, The second processor acquires data relating to the state of the plurality of information processing devices by performing synchronous communication with the plurality of information processing devices under management, and stores it in the storage unit as synchronous data. The authentication token information transmitted from the first processor is associated with user information and stored in the synchronization data of the information processing device that transmitted the authentication token information, as well as in the synchronization data of other information processing devices that perform authentication management in common with the said information processing device. When the first processor performs an authentication process using the first identification information and the first password information, it sends the user information of the logged-in user to the management server. If the authentication token information associated with the user information transmitted from the first processor is stored in the synchronization data of any of the multiple information processing devices that perform common authentication management, the second processor transmits the authentication token information to the information processing device that transmitted the user information. The first processor uses the authentication token information transmitted from the second processor to request the external server to perform authentication processing, and if the external server returns a response indicating successful authentication, it grants the user permission to use the service.

[0007] In the second aspect of this disclosure, the information processing system is the first identification information necessary for logging in to the information processing device, in the information processing system of the first aspect.

[0008] The information processing system in the third aspect of this disclosure, in the information processing system in the first aspect, when a user logs into the device using the first identification information and the first password information, the first processor obtains the user's user information from the registration information within the device. The acquired user information is sent to the management server along with the authentication token information.

[0009] The information processing system of the fourth aspect of this disclosure is the information processing system of the third aspect, wherein the user information is the email address information of a user who has logged into the information processing device.

[0010] The information processing system of the fifth aspect of this disclosure is an information processing system of the first aspect in which a plurality of information processing devices that perform common authentication management within the management server are composed of a plurality of information processing devices that can be used by the same user.

[0011] The information processing system of the sixth aspect of this disclosure is an information processing system of the fifth aspect in which multiple information processing devices that can be used by the same user are multiple information processing devices that are commonly used within the same company, the same department, or the same group.

[0012] A program according to a seventh aspect of this disclosure is a program that controls the operation of an information processing system comprising a plurality of information processing devices and a management server that manages the plurality of information processing devices, In the aforementioned plurality of information processing devices, the steps include: performing authentication processing for the user using first identification information and first password information entered by the user, and if the authentication process is successful, granting the user who has successfully been authenticated permission to use the device; In the aforementioned plurality of information processing devices, when a user enters second identification information and second password information in order to use additional services available on the device, the second identification information and second password information are sent to an external server managing the service to request the execution of authentication processing. In the aforementioned plurality of information processing devices, when a response indicating successful authentication is received from the external server, the user is permitted to use the service, and the authentication token information sent when the response indicating successful authentication was received from the external server is sent to the management server along with user information that can identify the user. The management server acquires data relating to the status of the multiple information processing devices by performing synchronous communication with the multiple information processing devices under management, and stores it as synchronous data. The steps include: associating authentication token information transmitted from one of the multiple information processing devices with user information, storing the authentication token information in the synchronization data of the information processing device that transmitted it, and also storing it in the synchronization data of other information processing devices that perform authentication management in common with that information processing device; In the aforementioned plurality of information processing devices, when a user performs authentication processing using the first identification information and the first password information, the user information of the logged-in user is transmitted to the management server. In the management server, if authentication token information associated with user information transmitted from one of the multiple information processing devices is stored in the synchronization data of one of the multiple information processing devices that perform common authentication management, the authentication token information is transmitted to the information processing device that transmitted the user information. The computer is instructed to perform the following steps in the aforementioned multiple information processing devices: request the external server to perform authentication processing using the authentication token information transmitted from the management server, and if the external server returns a reply indicating successful authentication, permit the user to use the service. [Effects of the Invention]

[0013] According to the information processing system of the first aspect of the present disclosure, when a service function is added to each of a plurality of information processing devices and a login operation is required for both the information processing device and its service, if a login operation is performed on any one of the plurality of information processing devices to perform a login operation on the service, when a login operation is performed on an information processing device different from the information processing device on which the login operation was performed, the login operation to the service can be made unnecessary.

[0014] According to the information processing system of the second aspect of the present disclosure, it is possible to eliminate the need to previously register user information that can identify a user in a plurality of information processing devices.

[0015] According to the information processing system of the third aspect of the present disclosure, even when the same user logs in to an information processing device using a plurality of different first identification information, or even when a login operation is performed on an information processing device different from the information processing device on which the user performed a login operation, the second and subsequent login operations to a certain service can be made unnecessary.

[0016] According to the information processing system of the fourth aspect of the present disclosure, even when the same user logs in to an information processing device using a plurality of different first identification information without deliberately setting user information that can identify the user, or even when a login operation is performed on an information processing device different from the information processing device on which the user performed a login operation, the second and subsequent login operations to a certain service can be made unnecessary.

[0017] According to the information processing system of the fifth aspect of the present disclosure, a user can log in to a certain service without performing a second and subsequent login operation on any of the plurality of information processing devices that the user can use.

[0018] According to the information processing system of the sixth aspect of the present disclosure, a user can log in to a certain service without performing a login operation for the second and subsequent times on any of a plurality of information processing devices that are commonly used within the same company, the same department, or the same group.

[0019] According to the program of the seventh aspect of the present disclosure, when a service function is added to each of a plurality of information processing devices and a login operation is required for both the information processing device and its service, if a login operation is performed on any one of the plurality of information processing devices to log in to the service, then when logging in to an information processing device different from the information processing device on which the login operation was performed, the login operation to the service can be made unnecessary.

Brief Description of the Drawings

[0020] [Figure 1] It is a diagram showing the system configuration of the information processing system according to an embodiment of the present disclosure. [Figure 2] It is a block diagram showing the hardware configuration of the image forming apparatus 10 according to an embodiment of the present disclosure. [Figure 3] It is a block diagram showing the functional configuration of the image forming apparatus 10 according to an embodiment of the present disclosure. [Figure 4] It is a diagram showing an example of a login screen in the image forming apparatus 10. [Figure 5] It is a diagram showing an example of a home screen of the image forming apparatus 10. [Figure 6] It is a diagram showing an example of a login screen of an application in the image forming apparatus 10. [Figure 7] It is a block diagram showing the hardware configuration of the management server 40 according to an embodiment of the present disclosure. [Figure 8] It is a block diagram showing the functional configuration of the management server 40 according to an embodiment of the present disclosure. [Figure 9] It is a diagram for explaining the operation at the first login when a certain user A logs in to an application from the image forming apparatus 10A at base A. [Figure 10]This figure shows an example of how authentication token information is stored in the synchronous data storage units 51, 52, and 53. [Figure 11] This diagram illustrates the operation during the second and subsequent logins when user A moves to location B and logs into the application from the image forming apparatus 10B1. [Figure 12] This diagram illustrates the behavior during the first login when permission to share authentication information is set on a group-by-group basis. [Figure 13] This diagram illustrates the operation during the first login when the user IDs for logging into the image forming apparatus 10 are different at locations A and B. [Figure 14] This diagram shows how authentication token information is stored in synchronization data storage units 51, 52, and 53 in association with user A's email address. [Figure 15] This diagram illustrates the operation during the second and subsequent logins when user A moves to site B and logs into the application from image forming apparatus 10B1, in cases where the user IDs for logging into the image forming apparatus 10 are different at sites A and B. [Modes for carrying out the invention]

[0021] Next, embodiments of the present disclosure will be described in detail with reference to the drawings.

[0022] Figure 1 shows the system configuration of an information processing system according to one embodiment of the present disclosure.

[0023] As shown in Figure 1, an information processing system according to one embodiment of the present disclosure consists of a plurality of image forming apparatuses 10A, 10B1, and 10B2, a management server 40 that manages the plurality of image forming apparatuses 10A, 10B1, and 10B2, and an application server 20 that provides functions by a certain application.

[0024] The multiple image forming machines 10A, 10B1, and 10B2 are connected to the management server 40 and the application server 20 via the Internet 30. Image forming machine 10A is installed at a certain company's location A, while image forming machines 10B1 and 10B2 are installed at a certain company's location B. When referring to the multiple image forming machines 10A, 10B1, and 10B2 without distinction, they will be referred to simply as image forming machine 10.

[0025] Furthermore, when using multiple image forming machines 10A, 10B1, and 10B2, it is necessary to perform a login operation and execute the authentication process.

[0026] Furthermore, each of the multiple image forming apparatuses 10A, 10B1, and 10B2 has an application installed that provides a specific service. When using the services provided by this application, it is necessary to perform a login operation and authentication. When the user logs in to the application in the image forming apparatus 10 and enters authentication information such as a user ID and password, the entered authentication information is sent to the application server 20 and the authentication process is executed. If this authentication process is successful, the user can use the functions of the application. The functions provided by the application include, for example, a web service that allows users to check the usage status of the image forming apparatus 10, request repairs, check the billing amount, and obtain support information.

[0027] Therefore, users who wish to use this app must first log in to one of the multiple image forming machines 10A, 10B1, or 10B2, and then log in again to the app installed in the image forming machine 10 they logged into. If the user logs in to the same image forming machine 10 again, and the login status to the app is maintained for a certain period, they can use the services provided by the app without having to log in to the app again. However, if the user logs in to another image forming machine 10 among the multiple image forming machines 10A, 10B1, or 10B2, they will also have to log in to that app again, which is inconvenient for the user.

[0028] Therefore, in the information processing system of this embodiment, if a user logs in to the service using one of the multiple image forming apparatuses 10A, 10B1, or 10B2, by the method described below, it becomes unnecessary to log in to the service again when logging in to a different image forming apparatus 10 than the one used for the initial login.

[0029] Next, Figure 2 shows the hardware configuration of the image forming apparatus 10 in the information processing system of this embodiment.

[0030] As shown in Figure 2, the image forming apparatus 10 includes a CPU 11, memory 12, storage device 13 such as a hard disk drive, a communication interface (IF) 14 for transmitting and receiving data to and from external devices via the Internet 30, a user interface (UI) device 15 including a touch panel or liquid crystal display and keyboard, a scan unit 16, and an image forming unit 17. These components are connected to each other via a control bus 18.

[0031] The image forming unit 17 prints an image onto a recording medium such as printing paper through processes such as charging, exposure, development, transfer, and fixing.

[0032] The CPU 11 is a processor that controls the operation of the image forming apparatus 10 by executing predetermined processes based on a control program stored in the memory 12 or storage device 13. In this embodiment, the CPU 11 is described as reading and executing a control program stored in the memory 12 or storage device 13, but it is not limited to this. This control program may be provided in the form of a computer-readable recording medium. For example, this program may be provided in the form of a CD (Compact Disc)-ROM and DVD (Digital Versatile Disc)-ROM recorded on an optical disc, or in the form of a USB (Universal Serial Bus) memory and memory card recorded on a semiconductor memory. Furthermore, this control program may be acquired from an external device via a communication line connected to the communication interface 14. In addition, this control program may be provided as a standalone application software, or it may be incorporated into the software of each device as a function of the image forming apparatus 10.

[0033] Figure 3 is a block diagram showing the functional configuration of the image forming apparatus 10 realized by the execution of the control program described above.

[0034] As shown in Figure 3, the image forming apparatus 10 of this embodiment includes an authentication unit 31, an operation input unit 32, a display unit 33, a data transmission / reception unit 34, a control unit 35, an image reading unit 36, a data storage unit 37, and an image output unit 38.

[0035] The data transmission / reception unit 34 transmits and receives data with external devices such as the application server 20 and the management server 40.

[0036] The control unit 35 controls the operation of the image forming apparatus 10. Specifically, the control unit 35 controls the image reading unit 36 ​​and the image output unit 38 to perform scanning or printing processes. Furthermore, the control unit 35 performs processes such as verifying the user ID and password entered from the operation input unit 32 and performing user authentication, and sending the entered application user ID and password to the application server 20. The data storage unit 37 stores various data, such as print data, generated by the control unit 35.

[0037] The display unit 33 is controlled by the control unit 35 and displays various information to the user. The operation input unit 32 receives various operation information performed by the user. In this embodiment of the image forming apparatus 10, the display unit 33 and the operation input unit 32 constitute a touch panel.

[0038] The image output unit 38 outputs an image onto a recording medium such as printing paper based on control by the control unit 35. The image reading unit 36 ​​reads an image from a set original document based on control by the control unit 35.

[0039] The process of a user logging into this image forming apparatus 10 and using the functions of the installed application will be explained with reference to Figures 4 to 6.

[0040] First, as shown in Figure 4, the user enters the user ID and password for the image forming apparatus 10 on the operation screen of the image forming apparatus 10. The user ID used here is identification information to identify the user, and for example, the user's employee number can be used. In Figure 4, it can be seen that the string "1234ABC" is entered as the user ID. Alternatively, instead of entering the user ID and password, authentication may be performed by touching an IC card, which has been provided to each user in advance, to the IC card reader of the image forming apparatus 10.

[0041] When the user ID and password are entered in this manner, the control unit 35 authenticates the user, and if authentication is successful, it displays a home screen on the display unit 33 as shown in Figure 5. An icon 61 named "XXX App" is placed on this home screen. When the user operates this icon 61, the app's login screen, as shown in Figure 6, is displayed on the display unit 33.

[0042] Then, on the app's login screen shown in Figure 6, when the user enters the app's user ID and password, this user ID and password are sent to the app server 20 for authentication. If this authentication process is successful, the user can use the functions provided by this app. Note that Figure 6 shows the case where the user's email address is set as the app's user ID. Therefore, in Figure 6, it can be seen that the string "ABCD@aaa.bbb.co.jp", which is the email address of user A, is entered as the user ID.

[0043] In this manner, the control unit 35 uses the user ID and password information entered by the user to perform authentication processing for that user, and if the authentication process is successful, it grants the user permission to use the image forming apparatus 10, which is the device itself.

[0044] Then, when a user enters the application's user ID and password information in order to use additional services available on their device, the control unit 35 sends the application's user ID and password information to the application server 20, which is an external server that manages the services of this application, and requests that it perform authentication processing.

[0045] Then, if the application server 20 returns a message indicating successful authentication, the application server 40 grants the user permission to use the application's services and sends the authentication token information received from the application server 20, along with user information that can identify the user, to the management server 40.

[0046] Here, authentication token information refers to authentication information with a set expiration date, which can be used multiple times as long as the expiration date has not expired. Furthermore, by using authentication token information, authentication can be obtained without presenting a user ID and password. In the following explanation, this authentication token information may be simply referred to as the authentication token.

[0047] In this embodiment, we will describe a case where the user ID required to log in to the image forming apparatus 10 is used as user information that can identify the user. However, it is also possible to use information other than the user ID as long as it can identify the user.

[0048] In this embodiment, the information processing system provides a service called digital shadow, which synchronizes and stores various data such as setting information, history information, status information, device information, and destination list of the physical device, the image forming apparatus 10, within the management server 40, which is a cloud server. By using this digital shadow, the management server 40 can manage the status of the image forming apparatus 10 even if the connection via the internet 30 is interrupted. When managing the status of multiple image forming apparatuses 10A, 10B1, and 10B2 using digital shadow, the data of each of the multiple image forming apparatuses 10A, 10B1, and 10B2 will be stored as synchronized data within the cloud server.

[0049] Next, Figure 7 shows the hardware configuration of the management server 40 in the information processing system of this embodiment.

[0050] As shown in Figure 7, the management server 40 includes a CPU 21, memory 22, storage devices 23 such as a hard disk drive, a communication interface (IF) 24 for sending and receiving data to and from the image forming apparatus 10 via the internet 30, and a user interface (UI) device 25. These components are connected to each other via a control bus 26.

[0051] The CPU 21 is a processor that controls the operation of the management server 40 by executing predetermined processes based on a control program stored in the memory 22 or storage device 23. In this embodiment, the CPU 21 is described as reading and executing a control program stored in the memory 22 or storage device 23, but it is not limited to this. This control program may be provided in the form of a computer-readable recording medium. For example, this program may be provided in the form of a CD (Compact Disc)-ROM and DVD (Digital Versatile Disc)-ROM recorded on an optical disc, or in the form of a USB (Universal Serial Bus) memory and memory card recorded on a semiconductor memory. Alternatively, this control program may be acquired from an external device via a communication line connected to the communication interface 24. Furthermore, this control program may be provided as a standalone application software, or it may be incorporated into the software of each device as a function of the management server 40.

[0052] Figure 8 is a block diagram showing the functional configuration of the management server 40 realized by the execution of the control program described above.

[0053] As shown in Figure 8, the management server 40 includes synchronization control units 41-43 and synchronization data storage units 51-53.

[0054] The synchronization control units 41 to 43 each acquire data regarding the status of the multiple image forming apparatuses 10A, 10B1, and 10B2 by performing synchronous communication with the multiple image forming apparatuses 10A, 10B1, and 10B2 under their management, and store this data as synchronization data in the synchronization data storage units 51 to 53.

[0055] Then, the synchronization control units 41 to 43 associate the authentication token information transmitted from the image forming apparatus 10 with the user information and store it in the synchronization data of the image forming apparatus 10 that transmitted the authentication token information, as well as in the synchronization data of other image forming apparatuses 10 that perform authentication management in common with the image forming apparatus 10.

[0056] In the following explanation, image forming apparatuses 10A, 10B1, and 10B2 are assumed to be image forming apparatuses 10 that perform common authentication management. Here, multiple image forming apparatuses 10 that perform common authentication management within the management server 40 consist of, for example, multiple image forming apparatuses 10 that can be used by the same user. Specifically, multiple image forming apparatuses 10 that can be used by the same user are multiple image forming apparatuses 10 that are commonly used within the same company, the same department, or the same group.

[0057] For example, when the synchronization control unit 41 receives authentication token information and user information from the image forming apparatus 10A under management, it associates the authentication token information and user information and stores them as synchronization data in the synchronization data storage unit 51. The synchronization control unit 41 then associates the authentication token information and user information and stores them as synchronization data in the synchronization data storage units 52 and 53.

[0058] Then, when a user logs into the app for the second time or later, the control unit 35 of the image forming apparatus 10 sends the user information of the logged-in user to the management server 40 if the user performs authentication using the user ID and password information of the image forming apparatus 10.

[0059] Then, if the authentication token information associated with the user information transmitted from the image forming apparatus 10 is stored in the synchronization data of any of the multiple image forming apparatuses 10A, 10B1, or 10B2 that perform common authentication management, the synchronization control units 41 to 43 of the management server 40 transmit that authentication token information to the image forming apparatus 10 that transmitted the user information.

[0060] Upon receiving the authentication token information, the image forming apparatus 10's control unit 35 requests the application server 20 to perform the authentication process using the authentication token information transmitted from the management server 40. If the application server 20 replies that authentication was successful, the control unit 35 grants the user permission to use the application's services.

[0061] Next, the operation of the information processing system of this embodiment will be described in detail with reference to the drawings.

[0062] First, we will explain the operation during the initial login when a user A logs into the application from the image forming apparatus 10A at site A, referring to Figure 9.

[0063] (1) User A operates the control panel of the image forming apparatus 10A and enters the user ID and password to log in.

[0064] (2) Next, User A operates the control panel of the image forming apparatus 10A and enters the user ID and password for the application to log in.

[0065] (3) The user ID and password for the application are then sent from the image forming apparatus 10A to the application server 20 to request authentication.

[0066] (4) The application server 20 then performs authentication using the user ID and password of the application that have been sent, and returns the authentication result and authentication token to the image forming apparatus 10A.

[0067] (5) The image forming apparatus 10A then grants user A permission to use the application and sends the received authentication token, along with the user ID of the image forming apparatus 10, to the management server 40.

[0068] (6) Then, the synchronization control unit 41 of the management server 40 associates the transmitted authentication token with the user ID of the image forming apparatus 10 and stores it in the synchronization data storage unit 51.

[0069] (7) Furthermore, the synchronization control unit 41 associates the transmitted authentication token with the user ID of the image forming apparatus 10 and stores it in the synchronization data storage units 52 and 53.

[0070] Figure 10 shows an example of how authentication token information is stored in the synchronous data storage units 51, 52, and 53. As shown in Figure 10, the authentication token information is stored in the synchronous data storage units 51, 52, and 53 in association with the user ID.

[0071] Next, we will explain the operation of the second and subsequent logins when user A moves to site B and logs into the application from the image forming apparatus 10B1, referring to Figure 11.

[0072] (1) User A operates the control panel of the image forming machine 10B1 at site B and enters the user ID and password to log in.

[0073] (2) Next, user A operates the control panel of the image forming apparatus 10B1 to launch the application.

[0074] (3) Then, the image forming apparatus 10B1 transmits the user ID "1234ABC" of the image forming apparatus 10 to the management server 40.

[0075] (4) Then, in the management server 40, the synchronization control unit 42 obtains the authentication token stored in association with the transmitted user ID "1234ABC" of the image forming apparatus 10 from the synchronization data storage unit 52.

[0076] (5) The synchronization control unit 42 then sends the acquired authentication token back to the image forming apparatus 10B1.

[0077] (6) The image forming apparatus 10B1 then uses the authentication token returned from the management server 40 to execute an application authentication request to the application server 20.

[0078] (7) As a result, the application server 20 performs authentication processing using the received authentication token, and the authentication result is returned to the image forming apparatus 10B1. If the authentication result is successful, user A can use the services provided by the application in the image forming apparatus 10B1.

[0079] As explained above, user A can use the services provided by the app on the image forming apparatus 10B1 without having to enter the app's user ID and password.

[0080] [Example 1] In the embodiment described above, regardless of the location where the image forming machines 10A, 10B1, and 10B2 of a given company were installed, users could log in to the application for the second time and beyond without having to enter their user ID and password. However, even within the same company, there are cases where it is desirable to set different levels of security for different groups, such as departments. For example, among the accounting, sales, and development departments, it may be desirable to configure the image forming machine installed in the accounting department to always require the user ID and password to be entered when logging in to the application, without sharing authentication information with other departments. In such cases, the company's machine administrator can configure whether or not to allow the sharing of authentication information for each group.

[0081] Figure 12 illustrates the behavior during the first login when permission to share authentication information is set for each group, as shown above.

[0082] Referring to Figure 12, it can be seen that an image forming apparatus 10C has been newly added to site C. The management server 40 now has a newly added synchronous control unit 44 that manages the image forming apparatus 10C. The synchronous control unit 44 acquires data regarding the status of the image forming apparatus 10C by performing synchronous communication with the image forming apparatus 10C and stores it as synchronous data in the synchronous data storage unit 54.

[0083] Here, we will assume that locations A and B are set as groups permitted to supply authentication information, and location C is set as a group not permitted to supply authentication information.

[0084] Therefore, in Figure 12, the actions from steps (1) to (6) are the same as in Figure 9, but the action in step (7) is different from that in Figure 9.

[0085] In step (7) in Figure 12, the synchronization control unit 41 stores the transmitted authentication token and user ID only in the synchronization data storage units 52 and 53 of the group that is permitted to share the authentication status, and does not store them in the synchronization data storage unit 54 of the group that is not permitted to share the authentication status.

[0086] As a result, even if user A, who logged into the application from image forming apparatus 10A at site A, moves to site C and tries to log into the application from image forming apparatus 10C, user A will still need to enter their user ID and password.

[0087] [Differentiation 2] In the embodiment described above, the user ID and authentication token information were associated and stored in the synchronization data storage units 51-53 of the management server 40. However, there are cases where the user ID used to log in to the image forming apparatus 10 differs from one location to another, even for the same user. In such cases, even if the user ID and authentication token information are stored in association, if the same user moves to a different location, they cannot omit entering the user ID and password when logging into the application. Therefore, instead of using the user ID as user information that can identify a user, we will now describe a case where the user's email address is used as user information that can identify a user.

[0088] Figure 13 is a diagram illustrating the operation during the first login when the user IDs for logging into the image forming apparatus 10 are different at locations A and B.

[0089] In Figure 13, the actions from steps (1) to (4) are the same as in Figure 9, but the actions from step (5) onward differ from those in Figure 9, as shown below. In steps (5) to (7) in Figure 13, the following actions are performed.

[0090] (5) The image forming apparatus 10A sends the authentication token received from the application server 20 to the management server 40 along with the email address of user A.

[0091] (6) Then, the synchronization control unit 41 of the management server 40 associates the received authentication token with the email address of user A and stores it in the synchronization data storage unit 51.

[0092] (7) Furthermore, the synchronization control unit 41 associates the transmitted authentication token with user A's email address and stores it in the synchronization data storage units 52 and 53.

[0093] Figure 14 shows an example of how authentication token information is stored in the synchronous data storage units 51, 52, and 53. As shown in Figure 14, the authentication token information is stored in the synchronous data storage units 51, 52, and 53 in association with user A's email address.

[0094] Next, we will explain the operation of the second and subsequent logins when user A moves to site B and logs into the application from the image forming apparatus 10B1, referring to Figure 15.

[0095] In Figure 15, the operations other than steps (3) and (4) are the same as in Figure 11, but the operations in steps (3) and (4) are different from those in Figure 11, as shown below. In steps (3) and (4) in Figure 15, the following operations are performed.

[0096] (3) The image forming apparatus 10B1 sends the email address of user A, "ABCD@aaa.bbb.co.jp", to the management server 40.

[0097] (4) Then, in the management server 40, the synchronization control unit 42 retrieves the authentication token stored in association with the email address of user A that was sent, "ABCD@aaa.bbb.co.jp", from the synchronization data storage unit 52.

[0098] In Figure 15, the steps from step (5) onward are the same as in Figure 11, so the explanation is omitted.

[0099] In this modified case, when a user logs into the image forming apparatus 10 using a user ID and password, the control unit 35 obtains the user's email address from the registered information within the apparatus. Specifically, each user's information is registered in the image forming apparatuses 10A, 10B1, and 10B2, and each user's email address information is included in the registered user information. The control unit 35 then sends the obtained email address information along with the authentication token information to the management server 40.

[0100] Here, we have described the case where the email address information of the user who logged into the image forming apparatus 10 is used as user information that can identify the user. However, as shown in Figure 6, there are cases where the user's email address is used as the user ID for the application. In such cases, the email address information entered as the user's application ID is sent to the management server 40 along with the authentication token information and stored as synchronization data.

[0101] In each of the embodiments described above, the term "processor" refers to a processor in a broad sense, and includes general-purpose processors (e.g., CPU: Central Processing Unit, etc.) and dedicated processors (e.g., GPU: Graphics Processing Unit, ASIC: Application Specific Integrated Circuit, FPGA: Field Programmable Gate Array, programmable logic device, etc.).

[0102] Furthermore, the processor operations in each of the above embodiments may not be performed by a single processor, but may also be performed by multiple processors located in physically separate locations working together. Also, the order of the processor operations is not limited to the order described in each of the above embodiments, and may be changed as appropriate.

[0103] In this embodiment, "system" includes both systems composed of multiple devices and systems composed of a single device.

[0104] This disclosure is also applicable to programs and program products.

[0105] [Differentiation] The embodiments described above described a case where the information processing device used by installing and utilizing the application is an image forming apparatus 10. However, this disclosure is not limited to such a case, and is applicable to any information processing device such as a mobile terminal device or personal computer that can be used by installing and utilizing the application.

[0106] [Note] (((1))) An information processing system comprising multiple information processing devices and a management server that manages the multiple information processing devices, Each of the aforementioned plurality of information processing devices comprises a first processor, The aforementioned first processor, The system uses the first identification information and first password information entered by the user to perform the authentication process for that user, and if the authentication process is successful, it grants the user permission to use the device. When a user enters second identification information and second password information in order to use additional services available on their device, the second identification information and second password information are sent to an external server managing the service to request the execution of authentication processing. If the external server returns a message indicating successful authentication, the user is permitted to use the service, and the authentication token information sent from the external server when the message indicating successful authentication was returned is sent to the management server along with user information that can identify the user. The management server comprises a second processor and a memory unit, The second processor acquires data relating to the state of the plurality of information processing devices by performing synchronous communication with the plurality of information processing devices under management, and stores it in the storage unit as synchronous data. The authentication token information transmitted from the first processor is associated with user information and stored in the synchronization data of the information processing device that transmitted the authentication token information, as well as in the synchronization data of other information processing devices that perform authentication management in common with the said information processing device. When the first processor performs an authentication process using the first identification information and the first password information, it sends the user information of the logged-in user to the management server. If the authentication token information associated with the user information transmitted from the first processor is stored in the synchronization data of any of the multiple information processing devices that perform common authentication management, the second processor transmits the authentication token information to the information processing device that transmitted the user information. The first processor requests the external server to perform authentication processing using the authentication token information transmitted from the second processor, and if the external server returns a response indicating successful authentication, it grants the user permission to use the service. Information processing system.

[0107] (((2))) The user information is the first identification information necessary for logging in to the information processing device. The information processing system described in (((1))).

[0108] (((3))) When a user logs into the device using the first identification information and the first password information, the first processor retrieves the user's user information from the registration information within the device. The acquired user information is transmitted to the management server along with the authentication token information. The information processing system described in (((1))).

[0109] (((4))) The aforementioned user information is the email address information of the user who logged into the information processing device. The information processing system described in (((3))).

[0110] (((5))) The multiple information processing devices that perform common authentication management within the aforementioned management server are composed of multiple information processing devices that can be used by the same user. An information processing system described in any one of (((1))) through (((4))).

[0111] (((6))) Multiple information processing devices that can be used by the same user are multiple information processing devices that are commonly used within the same company, department, or group. The information processing system described in (((5))).

[0112] (((7))) A program for controlling the operation of an information processing system comprising multiple information processing devices and a management server that manages the multiple information processing devices, In the aforementioned plurality of information processing devices, the steps include: performing authentication processing for the user using first identification information and first password information entered by the user, and if the authentication process is successful, granting the user who has successfully been authenticated permission to use the device; In the aforementioned plurality of information processing devices, when a user enters second identification information and second password information in order to use additional services available on the device, the second identification information and second password information are sent to an external server managing the service to request the execution of authentication processing. In the aforementioned plurality of information processing devices, when a response indicating successful authentication is received from the external server, the user is permitted to use the service, and the authentication token information sent when the response indicating successful authentication was received from the external server is sent to the management server along with user information that can identify the user. The management server acquires data relating to the status of the multiple information processing devices by performing synchronous communication with the multiple information processing devices under management, and stores it as synchronous data. The steps include: associating authentication token information transmitted from one of the multiple information processing devices with user information, storing the authentication token information in the synchronization data of the information processing device that transmitted it, and also storing it in the synchronization data of other information processing devices that perform authentication management in common with that information processing device; In the aforementioned plurality of information processing devices, when a user performs authentication processing using the first identification information and the first password information, the user information of the logged-in user is transmitted to the management server. In the management server, if authentication token information associated with user information transmitted from one of the multiple information processing devices is stored in the synchronization data of one of the multiple information processing devices that perform common authentication management, the authentication token information is transmitted to the information processing device that transmitted the user information. In the aforementioned multiple information processing devices, the steps include: requesting the execution of authentication processing from the external server using the authentication token information transmitted from the management server, and if the external server returns a response indicating successful authentication, granting the user permission to use the service; A program that causes a computer to execute something.

[0113] According to the information processing system (((1))), a service function is added to each of the multiple information processing devices, and when a login operation is required for both the information processing device and its service, if a login operation is performed on one of the multiple information processing devices and then a login operation is performed for that service, then a login operation for that service will not be required when logging in to an information processing device other than the one on which the login operation was performed.

[0114] According to the information processing system of (((2))), it is possible to eliminate the need to pre-register user information that can identify a user in multiple information processing devices.

[0115] According to the information processing system of (((3))), even if the same user logs in to an information processing device using multiple different first identification pieces of information, it is possible to eliminate the need for a second or subsequent login operation to a service, even if the user logs in to an information processing device other than the one to which they first logged in.

[0116] According to the information processing system of (((4))), even when the same user logs in to an information processing device using multiple different first identification pieces of information, without having to specifically set user information that can identify the user, it is possible to eliminate the need for a second or subsequent login operation to a service, even if the user logs in to an information processing device other than the one to which they first logged in.

[0117] According to the information processing system (((5))), a user can log in to a service on any of the multiple information processing devices available to them without having to perform a second or subsequent login operation.

[0118] According to the information processing system in (((6))), a user can log in to a service without performing a second login operation on any of the multiple information processing devices used in common within the same company, department, or group.

[0119] According to the program in (((7))), a service function is added to each of the multiple information processing devices, and when a login operation is required for both the information processing device and its service, if a login operation is performed on one of the multiple information processing devices and then a login operation is performed for that service, then if a login operation is performed on an information processing device other than the one from which the login operation was performed, a login operation for that service will not be required. [Explanation of Symbols]

[0120] 10, 10A, 10B1, 10B2, 10C Image forming device 11 CPU 12 memory 13 Storage device 14. Communication Interface 15 UI device 16 scan units 17 Image forming unit 18 Control bus 20 Application Servers 21 CPU 22 memory 23 Storage device 24 Communication Interfaces 25 UI device 26 Control bus 30 Internet 31. Certification Department 32 Operation Input Section 33 Display section 34 Data transmission / reception unit 35 Control Unit 36 Image reading unit 37 Data Storage Unit 38 Image output section 40 Management Server 41-44 Synchronization Control Unit 51-54 Synchronized data storage unit 61 icons

Claims

1. An information processing system comprising multiple information processing devices and a management server that manages the multiple information processing devices, Each of the aforementioned plurality of information processing devices comprises a first processor, The first processor is, The system performs authentication of the user using the first identification information and first password information entered by the user, and if the authentication process is successful, it grants the user permission to use the device. When a user enters second identification information and second password information in order to use additional services available on their device, the second identification information and second password information are sent to an external server managing the service to request the execution of authentication processing. If the external server returns a message indicating successful authentication, the user is permitted to use the service, and the authentication token information sent from the external server when the message indicating successful authentication was returned is sent to the management server along with user information that can identify the user. The management server comprises a second processor and a memory unit, The second processor acquires data relating to the state of the plurality of information processing devices by performing synchronous communication with the plurality of information processing devices under management, and stores it in the storage unit as synchronous data. The authentication token information transmitted from the first processor is associated with user information and stored in the synchronization data of the information processing device that transmitted the authentication token information, as well as in the synchronization data of other information processing devices that perform authentication management in common with the said information processing device. When the first processor performs an authentication process using the first identification information and the first password information, it transmits the user information of the logged-in user to the management server. If the authentication token information associated with the user information transmitted from the first processor is stored in the synchronization data of any of the multiple information processing devices that perform common authentication management, the second processor transmits the authentication token information to the information processing device that transmitted the user information. The first processor requests the external server to perform authentication processing using the authentication token information transmitted from the second processor, and if the external server returns a response indicating successful authentication, it grants the user permission to use the service. Information processing system.

2. The user information is the first identification information necessary for logging in to the information processing device. The information processing system according to claim 1.

3. When a user logs into the device using the first identification information and the first password information, the first processor obtains the user's user information from the registration information within the device. The acquired user information is transmitted to the management server along with the authentication token information. The information processing system according to claim 1.

4. The aforementioned user information is the email address information of the user who logged into the information processing device. The information processing system according to claim 3.

5. The multiple information processing devices that perform common authentication management within the aforementioned management server are composed of multiple information processing devices that can be used by the same user. The information processing system according to claim 1.

6. Multiple information processing devices that can be used by the same user are multiple information processing devices that are commonly used within the same company, department, or group. The information processing system according to claim 5.

7. A program for controlling the operation of an information processing system comprising multiple information processing devices and a management server that manages the multiple information processing devices, In the aforementioned plurality of information processing devices, the steps include: executing an authentication process for the user using the first identification information and first password information entered by the user, and if the authentication process is successful, granting the user who has successfully been authenticated permission to use the device; In the aforementioned plurality of information processing devices, when a user enters second identification information and second password information in order to use additional services available on the device, the second identification information and second password information are sent to an external server managing the service to request the execution of authentication processing. In the aforementioned plurality of information processing devices, when a response indicating successful authentication is received from the external server, the user is permitted to use the service, and the authentication token information sent when the response indicating successful authentication was received from the external server is sent to the management server along with user information that can identify the user. The management server acquires data relating to the status of the multiple information processing devices by performing synchronous communication with the multiple information processing devices under management, and stores it as synchronous data. The steps include: associating authentication token information transmitted from one of the multiple information processing devices with user information, storing the authentication token information in the synchronization data of the information processing device that transmitted it, and also storing it in the synchronization data of other information processing devices that perform authentication management in common with that information processing device; In the aforementioned plurality of information processing devices, when a user performs an authentication process using the first identification information and the first password information, the user information of the logged-in user is transmitted to the management server. In the management server, if authentication token information associated with user information transmitted from one of the multiple information processing devices is stored in the synchronization data of one of the multiple information processing devices that perform common authentication management, the authentication token information is transmitted to the information processing device that transmitted the user information. In the aforementioned multiple information processing devices, the steps include: requesting the execution of authentication processing from the external server using the authentication token information transmitted from the management server, and if the external server returns a response indicating successful authentication, granting the user permission to use the service; A program that causes a computer to execute something.