Image forming apparatus
Patent Information
- Application Number
- JP2025025742
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2026-09-01
AI Technical Summary
【0011】 本発明によれば、Kerberos認証等によりMFPをサーバとして使用し、印刷を行う場合においてジョブ認可を行うことができる。
Smart Images

Figure 2026139230000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a paper feeding device applicable to a user job authorization function in a multifunction peripheral (MFP) provided with user authentication.
Background Art
[0002] Conventionally, there has been disclosed an image forming apparatus that uses a job authorization function regarding authorization of whether a user can log in using network authentication and use printing functions such as printing, color printing, or monochrome printing.
[0003] For example, Patent Document 1 discloses a printing function restriction method for a printing system including a printing control device connected to a network, a printing right management server, and a printing device. In this printing function restriction method, the printing function is restricted by disabling selection of restricted printing functions in print settings of a print job.
[0004] Also, for example, Patent Document 2 discloses a printing system having a control means for operating a printing device under printing processing conditions based on paper attribute information. When allowing a user to select paper required for printing by the printing device, the printing system is configured to disable selection of paper whose attribute information has not been duplicated or modified by the user, and enable selection of paper whose attribute information has been duplicated or modified.
[0005] For example, Patent Document 3 discloses an information processing device characterized by having: association means for associating an object with a driver corresponding to the image processing device and a port related to communication with the image processing device when communication with the image processing device is established, and for releasing the association between the object and the driver corresponding to the image processing device and the port related to communication with the image processing device when communication with the image processing device is no longer established; and object control means for controlling whether the first object and the second object are displayed on the display device as the same object, in cases where communication with the first image processing device is established and the association means displays a first object associated with the driver corresponding to the first image processing device and the port related to communication with the first image processing device on the display device, and in cases where communication with a second image processing device different from the first image processing device is established and the association means displays a second object associated with the driver corresponding to the second image processing device and the port related to communication with the second image processing device on the display device.
[0006] For example, Patent Document 4 discloses an image forming apparatus terminal device that sends instructions to an image forming apparatus that performs user authentication using a predetermined authentication device and executes authenticated print printing. The terminal device accepts a choice between whether the print output processing of the selected document data file should be authenticated print output processing or not authenticated print output processing. [Prior art documents] [Patent Documents]
[0007] [Patent Document 1] Japanese Patent Publication No. 2007-272781 [Patent Document 2] Japanese Patent Publication No. 2007-301911 [Patent Document 3] Japanese Patent Publication No. 2008-52705 [Patent Document 4] Japanese Patent Publication No. 2009-146102 [Overview of the project] [Problems that the invention aims to solve]
[0008] Thus, when a user logs in using network authentication and performs job authorization, Kerberos authentication or NTLM (NT LAN Manager authentication) authentication may be used. In this case, when accessing a hot folder that automatically executes a pre-registered process when data (e.g., image data) is stored in the folder, the multifunction printer (MFP) can act as a server and grant access to the hot folder, but it cannot obtain user information, and therefore cannot obtain the job authorization information of that user.
[0009] In view of the above circumstances, the object of the present invention is to provide an image forming apparatus that can perform job authorization when printing using an MFP as a server via Kerberos authentication or the like. [Means for solving the problem]
[0010] To achieve the above objective, an image forming apparatus according to one embodiment of the present invention is an image forming apparatus connected to an authentication server via a network, and comprises a storage unit, a reception unit, and an authentication control unit. The storage unit stores at least one hot folder. The reception unit accepts the use of the image forming apparatus and access to the hot folder by the user, using user information that includes at least a user ID for identifying a predetermined user. The authentication control unit sends the user information used when accessing the hot folder is made to the authentication server to request authentication, and obtains job authorization information, including authorization for at least the printing function of the image forming apparatus, based on the authenticated user information. [Effects of the Invention]
[0011] According to the present invention, job authorization can be performed when performing printing by using an MFP as a server via Kerberos authentication or the like.
[0012] Note that the effects are not necessarily limited to those described herein, and may be any effect described in the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] [Figure 1] FIG. 1 is a block diagram showing an example of a configuration of an image forming apparatus. [Figure 2] FIG. 2 is a flowchart showing print control based on job authorization information in Method 1. [Figure 3] FIG. 3 is a flowchart showing print control based on job authorization information in (a). [Figure 4] FIG. 4 is a flowchart showing print control based on job authorization information in (b). [Figure 5] FIG. 5 is a flowchart showing print control based on job authorization information in (c). MODE FOR CARRYING OUT THE INVENTION
[0014] Hereinafter, embodiments according to the present invention will be described with reference to the drawings.
[0015] FIG. 1 is a block diagram showing an example of a configuration of an image forming apparatus 10 according to the present embodiment.
[0016] The image forming apparatus 10 prints print data received via a network on a sheet. For example, the image forming apparatus 10 is a multifunction peripheral or a printer. In the present embodiment, the image forming apparatus 10 includes a storage unit 12 that stores a hot folder holding image data. The image forming apparatus 10 authorizes a job for image data input to the hot folder based on job authorization information set for individual user information (e.g., a user ID), and executes printing based on the job authorization information.
[0017] For example, as shown in FIG. 1, the image forming apparatus 10 includes a communication unit 11, a storage unit 12, a reception unit 13, an authentication control unit 14, and an execution unit 15.
[0018] The communication unit 11 performs data communication with an external device including the authentication server 1 via a network. In the present embodiment, the authentication server 1 and the image forming apparatus 10 are connected to each other via a network. The communication method used by the communication unit 11 is not limited, and a known technique such as Ethernet (registered trademark) may be used.
[0019] The authentication server 1 stores job authorization information for users who use the image forming apparatus 10. Here, the job authorization information is information including authorization on whether a printing function of the image forming apparatus such as printing, color printing, monochrome printing, N-up printing, or double-sided printing can be used. For example, the job authorization information is set for each user such as user A who is only authorized for monochrome printing and user B who is not authorized for printing (cannot use the printing function). Note that the job authorization information is not limited to the above, and may include various types of information such as permission or restriction on use of a transmission function, a FAX function and the like, the number of printable sheets, paper types (thick paper, thin paper, color paper, etc.), paper sizes, copying, and the like.
[0020] The storage unit 12 stores at least one hot folder. A hot folder associates, with a shared folder, a function of executing a specific process on data (such as image data) in the folder, and can execute the specific process on data stored in the shared folder. The storage unit 12 may store various types of information in addition to the hot folder. For example, IDs of users who have accessed the hot folder, printing histories, various settings, and the like may be stored.
[0021] The reception unit 13 accepts user requests to use the image forming apparatus 10 and access to hot folders stored in the storage unit 12, using user information that includes at least a user ID for identifying a specific user. For example, the reception unit 13 is composed of a liquid crystal panel and a touch panel superimposed on it, and by entering a user ID via the reception unit 13, the user can use functions such as printing of the image forming apparatus.
[0022] User information may include various pieces of information such as passwords set for each user ID.
[0023] The authentication control unit 14 sends user information (e.g., user ID) used when accessing the hot folder to the authentication server 1 to request authentication, and obtains job authorization information authorized to the authenticated user.
[0024] For example, the authentication server 1 authenticates a user based on the user ID and password sent from the authentication control unit 14, and transmits job authorization information authorized to the authenticated user. The authentication method is not limited, and existing authentication methods such as Kerberos authentication or NTLM (NT LAN Manager authentication) authentication may be used. do.
[0025] The execution unit 15 prints files (image data, etc.) placed in the hot folder based on the job authorization information obtained by the authentication control unit 14. If job authorization information is not obtained, the execution unit 15 either prints the files in the hot folder or does not print them based on the system settings. Here, system settings refer to the authorization information settings for printing, copying, etc., associated with each group to which the user belongs on the MFP main unit.
[0026] The image forming apparatus 10 is not limited to the above configuration. For example, the communication unit 11 may be configured to communicate with a PC operated by the user, and may receive image data and operation instructions from the PC. It may also have, for example, a display unit for notifying the user of abnormal situations such as errors or malfunctions during printing.
[0027] Here, we will explain the conventional process in which a user logs into an image forming machine using network authentication and uses the job authorization function.
[0028] Users log in to the image forming apparatus through an authentication server. The authentication server performs authentication based on the entered user ID and password. The authentication methods used by the authentication server include Kerberos authentication and NTLM authentication.
[0029] If authentication is successful, the image forming machine retrieves user information from the authentication server (LDAP (Lightweight Directory Access Protocol)). The image forming machine uses the retrieved user information to authorize jobs based on job authorization information. The user then executes the authorized job (such as printing or copying).
[0030] In other words, when a user logs in using network authentication and authorizes a job, the image forming apparatus acts as a client, performing authentication with the authentication server, and then obtaining user information.
[0031] Next, we will show the case of a conventional hot folder.
[0032] In the case of Kerberos authentication, the image forming machine uses the administrator's user ID and password at startup to join the domain with the authentication server. The user logs in to the PC (Personal Computer) as a user of the network domain and obtains an authentication ticket.
[0033] Furthermore, when a user accesses the hot folder of the image forming machine, they obtain a service ticket by presenting the acquired authentication ticket to the authentication server, thereby gaining access. The image forming machine then grants access to the hot folder based on the acquired service ticket. The user places files (image data) in the hot folder. The image forming machine then prints the files placed in the hot folder.
[0034] In the case of NTLM authentication, the image forming machine uses the administrator's user ID and password at startup to join the domain with the authentication server. The user logs into the PC as a network domain user via NTLM authentication. The user also accesses the image forming machine's hot folder. At this time, the image forming machine delegates user authentication to the authentication server using NTLM pass-through authentication.
[0035] If user authentication is performed, the image forming apparatus grants the user access to the hot folder. The user places files in the hot folder. The image forming apparatus then prints the files placed in the hot folder.
[0036] In this type of hot folder scenario, the image forming apparatus acts as a server and grants access to the hot folder. However, while the image forming apparatus can obtain the user ID when a user accesses the hot folder, it cannot obtain the password or other user information, and therefore cannot obtain the user's job authorization information.
[0037] Therefore, in this embodiment, two methods are used to obtain job authorization information.
[0038] [Method 1] In Method 1, the user ID and password of the domain administrator user are used to obtain user information (job authorization information) and perform job authorization.
[0039] Figure 2 is a flowchart illustrating print control based on job authorization information in Method 1. In Figure 2, the user is able to access the hot folder.
[0040] As shown in Figure 2, since it is necessary to join a domain in order to perform authentication in the hot folder, the image forming apparatus 10 uses the admin's user ID and password to access the authentication server 1 using LDAP (step 101).
[0041] Furthermore, when a user accesses a hot folder, the user ID can be obtained from the authentication ticket. The authentication control unit 14 sends the admin user's ID and password to the authentication server 1 when the user accesses the hot folder, and determines whether or not the user information (job authorization information) for that user was successfully obtained (step 102).
[0042] If the execution unit 15 successfully obtains the job authorization information of the user accessing the hot folder (YES in step 102), the execution unit 15 prints the files placed in the hot folder by the user based on the user's job authorization information (steps 103 and 104).
[0043] Furthermore, if obtaining the user's job authorization information fails (NO in step 102), the execution unit 15 either prints or does not print the file placed in the hot folder by the user, based on the system settings (steps 105 and 106). For example, if a file that cannot be printed unless authorized according to the system settings is placed in the hot folder, printing of that file will not be performed.
[0044] [Method 2] In Method 2, the user information of a user who logged in using network authentication is copied locally to the image forming apparatus 10, and job authorization is performed using that user information.
[0045] For example, when a user logs in using network authentication from a panel or the like, the user information of that user is copied to the internal (local) storage of the image forming apparatus 10. The items to be copied vary depending on the authentication method. In this embodiment, the following three types are given as examples.
[0046] (a) User ID and job authorization information (i) User ID and password (c) User ID and authentication ticket
[0047] This information is retained inside the image forming apparatus 10 (for example, in the storage unit) only for a set retention period. The information retention period can be set arbitrarily. Furthermore, the items to be copied are not limited to (a), (b), and (c) above, and various items may be copied and stored.
[0048] [(a) User ID and job authorization information] In case (a), the user ID is obtained when the user accesses the hot folder. Specifically, in the case of Kerberos authentication, the user ID from the service ticket is obtained, or in the case of NTLM authentication, the user ID at the time of access is obtained. The copied job authorization information is then retrieved using this obtained user ID, and job authorization is performed.
[0049] Figure 3 is a flowchart illustrating print control based on job authorization information in (a). In Figure 3, the user has access to the hot folder, and the user's user information has been copied to the image forming apparatus 10.
[0050] As shown in Figure 3, the image forming apparatus 10 obtains job authorization information from the user ID of the service ticket and determines whether or not the acquisition of the user's job authorization information was successful (steps 201 and 202).
[0051] If the execution unit 15 successfully obtains the job authorization information of the user accessing the hot folder (YES in step 202), the execution unit 15 prints the files placed in the hot folder by the user based on the user's job authorization information (steps 203 and 204).
[0052] Furthermore, if obtaining the user's job authorization information fails (NO in step 202), the execution unit 15 either prints or does not print the file placed in the hot folder by the user, based on the system settings (steps 205 and 206).
[0053] [(i) User ID and password] In case (i), the user ID is obtained when the user accesses the hot folder. Specifically, in the case of Kerberos authentication, the user ID from the service ticket is obtained, or in the case of NTLM authentication, the user ID at the time of access is obtained. By obtaining the password from this obtained user ID, the authentication server is accessed and the job authorization information for that user is obtained.
[0054] Figure 4 is a flowchart showing print control based on job authorization information in (a). In Figure 4, the user has access to the hot folder, and the user's user information has been copied to the image forming apparatus 10.
[0055] As shown in Figure 4, the image forming apparatus 10 obtains the user's password from the user ID (step 301). The authentication control unit 14 sends the user ID and password to the authentication server 1 to request authentication, and if authentication is successful, it is determined whether or not the acquisition of the user's job authorization information was successful (step 302).
[0056] If the execution unit 15 successfully obtains the job authorization information of the user accessing the hot folder (YES in step 302), the execution unit 15 prints the files placed in the hot folder by the user based on the user's job authorization information (steps 303 and 304).
[0057] Furthermore, if obtaining the user's job authorization information fails (NO in step 302), the execution unit 15 either prints or does not print the file placed in the hot folder by the user, based on the system settings (steps 305 and 306).
[0058] [(c) User ID and authentication ticket] (c) Kerberos authentication is used, and the user ID is obtained from the authentication ticket when the user accesses the hot folder. An authentication ticket is obtained from the obtained user ID, and user information (job authorization information) is obtained using that authentication ticket.
[0059] Figure 5 is a flowchart showing print control based on job authorization information in (c). In Figure 5, the user has access to the hot folder via Kerberos authentication, and the user's user information has been copied to the image forming apparatus 10.
[0060] As shown in Figure 5, the image forming apparatus 10 obtains an authentication ticket from the user ID (step 401). The authentication control unit 14 determines whether the acquisition of job authorization information was successful by using the acquired authentication ticket to authenticate with the authentication server (step 402).
[0061] If the execution unit 15 successfully obtains the job authorization information of the user accessing the hot folder (YES in step 402), the execution unit 15 prints the files placed in the hot folder by the user based on the user's job authorization information (steps 403, 404).
[0062] Furthermore, if obtaining the user's job authorization information fails (NO in step 402), the execution unit either prints the file placed in the hot folder by the user, or does not print it, based on the system settings (steps 405, 406).
[0063] As described above, the image forming apparatus 10 according to this embodiment is connected to an authentication server 1 via a network and comprises a storage unit 12 that stores at least one hot folder, a reception unit 13 that accepts the use of the image forming apparatus 10 and access to the hot folder by a user using user information including a user ID for identifying at least a predetermined user, and an authentication control unit 14 that sends the user information used when accessing the hot folder is made to the authentication server 1 to request authentication and obtains job authorization information, including authorization for at least the printing function of the image forming apparatus 10, based on the authenticated user information. This makes it possible to perform job authorization when using the image forming apparatus 10 as a server and performing printing using Kerberos authentication or the like.
[0064] Traditionally, when users log in using network authentication and perform job authorization, Kerberos authentication or NTLM authentication may be used. In this case, when accessing the hot folder, the multifunction printer (MFP) can act as a server and grant access to the hot folder, but it cannot obtain user information, and therefore cannot obtain the user's job authorization information.
[0065] This technology performs job authorization in two ways: either by using the administrator user in the domain settings to obtain user information and perform job authorization, or by copying the network authentication user locally and performing job authorization using that copied user information. This makes it possible to perform job authorization when using an image forming machine as a server and performing printing using Kerberos authentication, etc. Furthermore, even if NTLM authentication is discontinued, this invention uses Kerberos authentication so that job authorization information can be obtained and file sending and receiving functions such as exchanging files placed in a hot folder can be used. [Explanation of Symbols]
[0066] 1… Authentication Server 10…Image forming apparatus 11… Communications Department 12...Storage section 13…Reception Department 14…Authentication Control Unit 15…Executive Department
Claims
1. An image forming apparatus connected to an authentication server via a network, A storage unit that stores at least one hot folder, A reception unit that accepts the use of the image forming apparatus and access to the hot folder by the user, using user information including a user ID for identifying a predetermined user, The authentication control unit sends the user information used when accessing the hot folder is made to the authentication server to request authentication, and obtains job authorization information, including authorization for at least the printing function of the image forming apparatus, based on the authenticated user information. An image forming apparatus comprising the following:
2. An image forming apparatus according to claim 1, The aforementioned user is an administrator, The authentication control unit sends the administrator's user information to the authentication server to request authentication and obtains the administrator's job authorization information. Image forming apparatus.
3. An image forming apparatus according to claim 1, The authentication control unit transmits the user information used to use the image forming apparatus to the authentication server to request authentication, and obtains the job authorization information of the user information. The storage unit stores the user information used to use the image forming apparatus and the acquired job authorization information. Image forming apparatus.
4. An image forming apparatus according to claim 1, The user information includes the user's password, The storage unit stores the user ID and password of the user used to use the image forming apparatus. The authentication control unit sends the stored user ID and password to the authentication server to request authentication and obtains the user's job authorization information. Image forming apparatus.
5. An image forming apparatus according to claim 1, The user information includes an authentication ticket that authorizes the use of the printing function of the image forming apparatus, The storage unit stores the user ID and authentication ticket of the user used to use the image forming apparatus. The authentication control unit sends the stored user ID and authentication ticket to the authentication server to request authentication and obtains the job authorization information. Image forming apparatus.
Citation Information
Patent Citations
Print function restriction method and print controller
JP2007272781A
Printing system, control method, storage medium, program, and printing device
JP2007301911A
Information processor and method for displaying object
JP2008052705A
Image forming device, image forming device terminal, imaging forming system, and program
JP2009146102A