Information Processing Apparatus, Information Processing Method, and Program
The information processing apparatus addresses the limitation of requiring all necessary authorities for program installation by using a determination unit to authenticate secondary users with missing authorities, thereby enabling installation instructions from users with partial authorities.
Patent Information
- Application Number
- JP2021146918
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-09
- Publication Date
- 2025-06-11
- Estimated Expiration
- 2041-09-09
AI Technical Summary
Conventional information processing apparatuses restrict program installation to users with authority over all necessary functions, preventing users with partial authorities from giving installation instructions.
An information processing apparatus with a determination unit that assesses a user's authorities and, if lacking, authenticates a secondary user with necessary authorities to permit installation, enabling control units to make the program available.
This solution allows installation instructions from users without all required authorities, facilitating program installation by leveraging collective user permissions.
Smart Images

Figure 0007690825000001 
Figure 0007690825000002 
Figure 0007690825000003
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, an information processing method, and a program.
Background Art
[0002] Regarding an information processing apparatus shared by a plurality of people such as an image forming apparatus, there are cases where users who can install programs such as applications are limited to predetermined users. Specifically, a user who has the authority required for installing a program (for example, an administrator) can give an installation instruction, and there are cases where other users cannot give an installation instruction.
[0003] Also, a technique for granting users different authorities regarding the setting of a function for each function of an information processing apparatus is also known. For example, in the case of an image forming apparatus having a copy function, a scanner function, and a fax function, it is possible to give user A the authority regarding the copy function and give user B the scanner function and the fax function.
Summary of the Invention
Problems to be Solved by the Invention
[0004] Conventionally, when it is desired to install a program that uses a plurality of functions (for example, a copy function and a scanner function) of an information processing apparatus, an installation instruction cannot be given unless the user has the authority for all of the plurality of functions. In other words, a user who has the authority only for some of the plurality of functions cannot give an installation instruction for the program.
[0005] The present invention has been made in view of the above points, and an object thereof is to enable an installation instruction even for a user who does not have any of a plurality of authorities required for installation.
Means for Solving the Problems
[0006] Therefore, in order to solve the above problems, an information processing apparatus includes a determination unit that determines whether a first user related to an installation instruction has a plurality of authorities necessary for installing a certain program, and when the first user does not have any of the plurality of authorities, if a second user who has the authority that the first user does not have and permits the installation is authenticated, a control unit that performs control to make the program available.
Advantages of the Invention
[0007] It is possible to enable an installation instruction even for a user who does not have any of a plurality of authorities necessary for installation.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Embodiments for Carrying Out the Invention
[0009] Hereinafter, embodiments of the present invention will be described with reference to the drawings. FIG. 1 is a diagram showing a configuration example of an information processing system according to an embodiment of the present invention. In FIG. 1, an image forming apparatus 10 is connected to an application store server 20 via a network such as the Internet.
[0010] The image forming apparatus 10 is an image forming apparatus that realizes a plurality of functions such as copying, scanning, printing, and faxing in a single housing. By installing one or more applications that utilize the functions of the image forming apparatus 10 in the image forming apparatus 10, the convenience of the image forming apparatus 10 can be improved.
[0011] The application store server 20 is one or more computers that store and publish a plurality of applications developed for installation in the image forming apparatus 10.
[0012] FIG. 2 is a diagram showing a hardware configuration example of the image forming apparatus 10 according to an embodiment of the present invention. The image forming apparatus 10 in FIG. 2 includes a drive device 100, an auxiliary storage device 102, a memory device 103, a CPU 104, an interface device 105, a display device 106, and an input device 107, etc., which are mutually connected by a bus B.
[0013] A program for realizing processing in the image forming apparatus 10 is provided by a recording medium 101 such as an SD card. When the recording medium 101 storing the program is set in the drive device 100, the program is installed from the recording medium 101 to the auxiliary storage device 102 via the drive device 100. However, the installation of the program does not necessarily have to be performed from the recording medium 101, and it may be downloaded from another computer via a network. The auxiliary storage device 102 stores the installed program and also stores necessary files, data, etc.
[0014] When there is an instruction to start a program, the memory device 103 reads and stores the program from the auxiliary storage device 102. The CPU 104 realizes the functions related to the image forming apparatus 10 according to the program stored in the memory device 103. The interface device 105 is used as an interface for connecting to a network. The display device 106 displays a GUI (Graphical User Interface) or the like according to the program. The input device 107 is composed of buttons, a touch panel, etc., and is used to input various operation instructions.
[0015] Note that the display device 106 and the input device 107 constitute the operation panel of the image forming apparatus 10. Also, the drive device 100, the auxiliary storage device 102, the memory device 103, the CPU 104, and the interface device 105 may also be hardware that constitutes the operation panel of the image forming apparatus 10.
[0016] FIG. 3 is a diagram showing a functional configuration example of the image forming apparatus 10 according to an embodiment of the present invention. In FIG. 3, the image forming apparatus 10 includes a login control unit 11, a user management unit 12, an app management unit 13, and an installation unit 14. Each of these units is realized by processing that causes the CPU 104 to execute one or more programs installed in the image forming apparatus 10. The image forming apparatus 10 also uses a user information storage unit 15. The user information storage unit 15 can be realized, for example, using the auxiliary storage device 102 or a storage device that can be connected to the image forming apparatus 10 via a network.
[0017] The login control unit 11 controls the login of a user to the image forming apparatus 10. The user management unit 12 authenticates the user by referring to the user information storage unit 15. In the user information storage unit 15, for each user who can use the image forming apparatus 10, a user name, a password, and the like are stored. The application management unit 13 performs control to make an application designated as an installation target available (executable by the image forming apparatus 10) in the image forming apparatus 10. The state in which an application is available means an installed state. Or, even after installation, if it is possible to restrict the use, it means a state in which the restriction on the use has been released. The installation unit 14 executes the installation of an application designated as an installation target in accordance with an instruction from the application management unit 13.
[0018] Hereinafter, the processing procedure executed by the image forming apparatus 10 will be described. FIG. 4 is a sequence diagram for explaining an example of the processing procedure of the installation process of an application executed by the image forming apparatus 10. In FIG. 4, a scenario where user A attempts to install an application on the image forming apparatus 10 is assumed.
[0019] In step S101, the login control unit 11 receives from user A an input of a login request including the user name and password of user A via the login screen displayed on the display device 106. The user name and password of user A are input on the login screen. The login request is input by pressing a predetermined button on the login screen or the like.
[0020] Subsequently, the login control unit 11 requests the user management unit 12 to check (authenticate) the user name and password related to the login request (S102). The user management unit 12 authenticates user A by referring to the user information storage unit 15 and determining the validity of the user name and the password.
[0021] FIG. 5 is a diagram showing a configuration example of the user information storage unit 15. As shown in FIG. 5, the user information storage unit 15 stores a user name, a password, management authority, etc. for each user who can use the image forming apparatus 10. The user name is the name (account name) of the user. The password is the password of the user. The management authority is information indicating the authority given to the user regarding operations (such as settings and installations) for managing the image forming apparatus 10.
[0022] FIG. 6 is a diagram showing an example of management authorities that can be given to a user. As shown in FIG. 6, for a user, for example, management authorities such as "Copy", "Scanner", "Printer", "Fax", "Installation", and "Others" can be given.
[0023] "Copy" indicates the authority to perform settings (update of parameters) related to copying. "Scanner" indicates the authority to perform settings related to the scanner. "Printer" indicates the authority to perform settings related to the printer. "Fax" indicates the authority to perform settings related to the fax. "Installation" indicates the authority to install or uninstall an application. "Others" indicates the authority to perform settings other than the above.
[0024] In the user information storage unit 15 of FIG. 5, the management authority of user X is "All". "All" indicates having all the authorities shown in FIG. 6.
[0025] The user management unit 12 determines that the authentication is successful if a record including the user name and password requested for check from the login control unit 11 is stored in the user information storage unit 15, and determines that the authentication has failed otherwise. If the authentication fails, the processing after step S103 is not executed. If the authentication is successful, the user management unit 12 notifies the login control unit 11 of a response including the success of the authentication and the management authorities ("Installation", "Copy") of the authenticated user (here, user A) (S103).
[0026] When the login control unit 11 is notified of a response indicating successful authentication, it changes the login state of the image forming apparatus 10 from the non-logged-in state to the logged-in state (S104). At this time, the login control unit 11 stores, for example, the user name and management authority of the authenticated user A in the memory device 103 as the user name and management authority of the logged-in user.
[0027] Subsequently, the login control unit 11 notifies user A of the successful login (S105). The successful login may be performed, for example, by switching the display content of the display device 106 to a screen for receiving an operation from the user (hereinafter referred to as an "operation screen").
[0028] Subsequently, when user A inputs a display instruction for the application list via the operation screen (S106), the application management unit 13 acquires a list of application information of each application stored and published in the application store server 20 from the application store server 20 (S107, S108).
[0029] FIG. 7 is a diagram showing an example of application information. As shown in FIG. 7, the application information includes an application name and a type. The application name is the name of the application. The type is identification information of the function of the image forming apparatus 10 used by the application. In other words, the type is information indicating the management authority required for the installation of the application.
[0030] Subsequently, the application management unit 13 requests the login control unit 11 to acquire the management authority of the logged-in user (S109). The login control unit 11 notifies the application management unit 13 of the management authority of the logged-in user stored in the memory device 103, for example (S110).
[0031] Subsequently, the app management unit 13 selects, as the app information of the application to be displayed, the app information including the management authority of the logged-in user in the list of app information acquired from the application store server 20 (S111). According to the example of FIG. 5, the management authority of user A is "installation" and "copy". In this case, the app management unit 13 selects the app information including either one or both of "installation" and "copy". According to the example of FIG. 7, each of the copy app and the copy scan app includes "copy". Therefore, the app information of each of the copy app and the copy scan app is selected.
[0032] Subsequently, the app management unit 13 displays, on the operation screen, a list of applications related to each app information selected in step S111 (S112). In the list, each application is displayed as an option for installation target. Each application may be represented by, for example, an icon or the like.
[0033] Subsequently, when user A selects (designates as an installation target) any one of the applications in the list, the app management unit 13 stores the app information of the selected application (hereinafter referred to as "target app") (S113).
[0034] Subsequently, when user A inputs an installation instruction via the operation screen (S114), the app management unit 13 determines whether the logged-in user can install the target app alone (whether the logged-in user has the installation authority for the target app) (S115). Such determination is made by confirming (1) whether the logged-in user has the management authority of "installation", and (2) whether all of the types of the app information of the target app are included in the management authority of the logged-in user. If (1) is not satisfied (if the logged-in user does not have the management authority of "installation") in the first place, it is determined that installation is impossible. Therefore, (2) may be determined when (1) is satisfied.
[0035] Since User A has the management authority for "Installation", the determination in (2) is made. That is, if the app management unit 13 determines that all of the types of app information of the target app are included in the management authority of the logged-in user, it is determined that the logged-in user can install the target app alone. On the other hand, if the app management unit 13 determines that some of the types of app information of the target app are not included in the management authority of the logged-in user, it is determined that the logged-in user cannot install the target app alone. Therefore, if the target app is a copy app, it is determined that the logged-in user can install the target app alone. On the other hand, if the target app is a copy scan app, it is determined that the logged-in user cannot install the target app alone. This is because the management authority of User A does not include "Scanner" among the types of copy apps.
[0036] If it is determined that the logged-in user can install the target app alone, the process proceeds to step S123. If it is determined that the logged-in user cannot install the target app alone, after steps S116 to S122 are executed, steps S123 and subsequent steps are executed.
[0037] In step S116, the application management unit 13 displays an additional authentication request screen on the display device 106. The additional authentication request screen includes, for example, a message indicating that the logged-in user lacks sufficient management authority for the target application, and a message indicating that authentication of a user having insufficient management authority (in this embodiment, "scanner") is required. The additional authentication request screen further includes an area for inputting the username and password of a user having insufficient management authority ("scanner"). When displaying the additional authentication request screen, the application management unit 13 may inquire of the user management unit 12 about the username of a user having insufficient management authority ("scanner"). The user management unit 12 refers to the user information storage unit 15 (FIG. 5), identifies a list of usernames of users having the management authority, and responds to the application management unit 13 with the list of usernames. The application management unit 13 may include the list of usernames in the additional authentication request screen. By doing so, user A can easily grasp who the users with insufficient authority are.
[0038] According to FIG. 5, the users having insufficient management authority "scanner" are user B and user C. Thus, for example, user A requests authentication from user B for installing the target application. When user B permits the installation of the target application, user B inputs his / her username and password to the additional authentication request screen and instructs the authentication request (S117). Subsequently, the application management unit 13 requests the login control unit 11 to acquire the management authority of user B (S118). At this time, the application management unit 13 notifies the login control unit 11 of the username and password of user B input to the additional authentication request screen.
[0039] In response to a request from the Application Management Unit 13, the Login Control Unit 11 requests the User Management Unit 12 to check (authenticate) the user name and password of User B notified from the Application Management Unit 13 (S119). The User Management Unit 12 refers to the User Information Storage Unit 15 (Fig. 5) and authenticates User B by determining the validity of the user name and the password. Note that the method for determining the validity of authentication is the same as that for User A. If the authentication fails, the steps after S120 are not executed. If the authentication is successful, the User Management Unit 12 notifies the Login Control Unit 11 of a response indicating the success of the authentication and including the management authority (「Installation」, 「Scanner」) of the authenticated user (here, User B) (S120).
[0040] When the Login Control Unit 11 is notified of a response indicating the success of the authentication, it notifies the Application Management Unit 13 of the management authority of User B (S121).
[0041] Subsequently, the Application Management Unit 13 determines whether the management authority of the additionally authenticated User B satisfies the insufficient management authority (S122). That is, the Application Management Unit 13 determines that the management authority of User B satisfies the insufficient management authority if the management authority of User B includes all of the insufficient management authority, and otherwise determines that the management authority of User B does not satisfy the insufficient management authority. If the management authority of User B does not satisfy all of the insufficient management authority, the steps after S123 are not executed. In this case, steps S116 and subsequent steps may be repeated in order to request additional authentication for users including User A and User B who also have insufficient management authority. That is, the type of the target application may be satisfied by the management authorities of three or more users.
[0042] In this embodiment, the management authority of User B satisfies the insufficient management authority. Therefore, the process proceeds to step S123.
[0043] In step S123, the application management unit 13 displays an application download start screen on the display device 106. The application download start screen is a screen for notifying the user of the start of the download of the target application. Subsequently, the application management unit 13 downloads (acquires) the target application from the application store server 20 (S124, S125). Subsequently, the application management unit 13 requests the installation unit 14 to install the downloaded target application (S126).
[0044] In response to the request from the application management unit 13, the installation unit 14 installs the target application in the image forming apparatus 10. When the installation is completed, the installation unit 14 notifies the application management unit 13 of the completion of the installation (S127). In response to the notification of the completion of the installation, the application management unit 13 displays on the display device 106 a screen for notifying the user of the completion of the installation (S128).
[0045] Note that the application management unit 13 may put the installation of the target application on hold without authenticating user B who has insufficient management authority. Specifically, in response to the installation instruction in step S114, the application management unit 13 may not execute steps S116 and subsequent steps, and may store the insufficient management authority in the auxiliary storage device 102 or the like in association with the application name of the target application. Thereafter, when any user logs in to the image forming apparatus 10 again, if the user has insufficient management authority, the application management unit 13 may execute steps S116 and subsequent steps. At this time, if the user permits the installation of the target application, the user inputs his / her username and password to the additional authentication request screen. On the other hand, if the user does not permit the installation of the target application, the user does not input his / her username and password to the additional authentication request screen. However, in this case, since the user has already been authenticated at the time of login, the application management unit 13 may display a screen for inquiring whether to permit the installation of the target application instead of the additional authentication request screen. In this case, the user simply needs to select an option of permitting or not permitting the installation of the target application.
[0046] Alternatively, the application management unit 13 may execute the installation without authenticating a user who lacks the necessary management authority. That is, the application management unit 13 may execute steps S123 to S128 without executing steps S116 to S122. In this case, the application management unit 13 stores the target application and the lacking management authority in the auxiliary storage device 102 and keeps the target application in a state where it cannot be started. The state where the target application cannot be started means that, for example, the application management unit 13 may not include the target application in the options on the screen that displays the list of applications to be used by the user, so that the target application cannot be started. Or, the option may be displayed, and when the option is selected, the application management unit 13 may reject the start of the target application. Thereafter, when any user logs in to the image forming apparatus 10 again, if the user lacks the necessary management authority, the application management unit 13 may execute steps S116 to S122. At this time, when the user permits the installation of the target application, the user inputs his / her user name and password to the additional authentication request screen. On the other hand, when the user does not permit the installation of the target application, the user does not input his / her user name and password to the additional authentication request screen. However, in this case, since the user has already been authenticated at the time of login, the application management unit 13 may display a screen for inquiring whether to permit the installation of the target application instead of the additional authentication request screen. In this case, the user simply needs to select an option of whether to permit the installation of the target application. When the installation of the target application is permitted by the user, the application management unit 13 may change the target application to a state where it can be started.
[0047] As described above, according to the present embodiment, if the set of management authorities of a plurality of users can satisfy the authorities necessary for installation, the installation can be executed. Therefore, even a user who does not have any of the plurality of authorities necessary for installation can give an installation instruction.
[0048] In addition, each function of the embodiment described above can be realized by one or more processing circuits. Here, the "processing circuit" in this specification refers to a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, an ASIC (Application Specific Integrated Circuit) designed to execute each function described above, a DSP (digital signal processor), an FPGA (field programmable gate array), and devices such as conventional circuit modules.
[0049] Note that in this embodiment, the image forming apparatus 10 is an example of an information processing apparatus. However, the information processing apparatus is not limited to an image forming apparatus as long as it is a device shared by a plurality of users. The information processing apparatus may be, for example, an output device such as a PJ (Projector), an IWB (Interactive White Board: a whiteboard having an electronic blackboard function capable of mutual communication), a digital signage, a HUD (Head Up Display) device, an industrial machine, an imaging device, a sound collection device, a medical device, a network home appliance, a notebook PC (Personal Computer), a mobile phone, a smartphone, a tablet terminal, a game machine, a PDA (Personal Digital Assistant), a digital camera, a wearable PC, or a desktop PC.
[0050] In addition, the application management unit 13 is an example of a determination unit, a control unit, an authentication request unit, and an inquiry unit. The target application is an example of a certain program.
[0051] As described above, the embodiments of the present invention have been described in detail. However, the present invention is not limited to such specific embodiments, and various modifications and changes are possible within the scope of the gist of the present invention described in the claims.
Explanation of Reference Numerals
[0052] 10 Image forming apparatus 11 Login control unit 12 User management unit 13 Application management unit 14 Installation unit 15 User information storage unit 20 Application store server 100 Drive device 101 Recording medium 102 Auxiliary storage device 103 Memory device 104 CPU 105 Interface device 106 Display device 107 Input device B Bus
Prior art documents
Patent documents
[0053]
Patent Document 1
Claims
1. A determination unit that determines whether a first user related to an installation instruction has a plurality of permissions required for installing a certain program; When the first user does not have any of the plurality of permissions, if a second user who has the permission that the first user does not have and permits the installation is authenticated, a control unit that performs control to make the program available; An information processing apparatus, characterized by comprising the above.
2. When the first user does not have any of the plurality of permissions, for each of the plurality of permissions that the first user does not have, if a second user who has the permission and permits the installation is authenticated, the control unit performs control to make the program available. The information processing apparatus according to claim 1, characterized by the above.
3. An authentication request unit that requests input of authentication information of the second user when the first user does not have any of the plurality of permissions. The information processing apparatus according to claim 1 or 2, characterized by comprising the above.
4. An inquiry unit that inquires whether to permit the installation to the second user in response to the login of the second user. The information processing apparatus according to claim 1 or 2, characterized by comprising the above.
5. The determination unit refers to a storage unit that stores information indicating the permissions of each user, and determines whether the first user has the plurality of permissions. The information processing apparatus according to any one of claims 1 to 4, characterized by the above.
6. The plurality of permissions are permissions related to functions of the information processing apparatus used by the program. The information processing apparatus according to any one of claims 1 to 5, characterized by the above.
7. A determination procedure for determining whether a first user related to an installation instruction has a plurality of permissions required for installing a certain program; When the first user does not have any of the plurality of permissions, if a second user who has the permission that the first user does not have and permits the installation is authenticated, a control procedure for performing control to make the program available. An information processing method, characterized in that a computer executes the above.
8. A determination procedure for determining whether a first user related to an installation instruction has a plurality of permissions required for installing a certain program; When the first user does not have any of the plurality of authorities, if a second user who has the authority that the first user does not have and permits the installation is authenticated, a control procedure for performing control to make the program available; A program, characterized in that the program is caused to be executed by a computer.
Citation Information
Patent Citations
Information processor, information processing system, installation control method, installation control program and computer-readable recording medium
JP2008234235A
Peripheral device
JP2010108426A
Image formation apparatus, function expansion method, and user authentication system
JP2010218089A
Information processing system, management device, and program
JP2013030022A
Image forming apparatus, printing method using NFC communication, and program
JP2016029778A