Authentication System and Authentication Method

By authenticating users through device-specific operations, the system ensures that only legitimate users with the device can access cloud services, addressing security vulnerabilities in existing systems.

JP7709018B2Active Publication Date: 2025-07-16STAR MICRONICS CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2021085607
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-05-20
Publication Date
2025-07-16
Estimated Expiration
2041-05-20

AI Technical Summary

Technical Problem

Existing systems face security risks as unauthorized users can gain access to device-related cloud services due to improper management or attacks, particularly when device-specific information like serial numbers are compromised.

Method used

The system authenticates users by acquiring user account and device-specific information, instructing operations on the device, and verifying the performance of these operations based on device status, associating account and device information only upon successful operation execution.

Benefits of technology

Ensures that only legitimate users with the device can access the service, enhancing security by requiring actual possession and operation of the device for successful authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007709018000001
    Figure 0007709018000001
  • Figure 0007709018000002
    Figure 0007709018000002
  • Figure 0007709018000003
    Figure 0007709018000003
Patent Text Reader

Abstract

To enable a system, which provides service associated with a device, to give only a right user who has the device an authority to use.SOLUTION: An authentication system comprises: an authentication processing part 34 which instructs a user to operate a device and determines whether the operation is performed as instructed to make an authentication; and an authority setting part 36 which registers account information and device information associatively when the authentication is successful so as to impart an authority to use service. Only when a device corresponding to device information acquired by a device information acquisition part 32 is actually at a hand of a user corresponding to account information acquired by an account information acquisition part 31 and operated as instructed, an authentication is made successful so as to give only the right user who has the device an authority to use, thereby securing security.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an authentication system and an authentication method, and more particularly to an authentication system and an authentication method for authenticating a user who wishes to use a service related to a device.

Background Art

[0002] Generally, as a means of permitting only users with legitimate authority to use cloud services provided by a server on the Internet, a technique called authentication is used to confirm whether the user accessing for service use is the actual person. In many cases, authentication is performed using account information consisting of a combination of an ID and a password. In addition to the ID and password, an IC card or biometric information (biometric information such as fingerprints or retina) may be used.

[0003] Conventionally, for the purpose of achieving both security and usability improvement, a technique has been known in which a user is authenticated by a first authentication process that is an authentication process for authenticating a user and a second authentication process that authenticates the user more securely than the first authentication process (for example, Patent Document 1). In the device described in Patent Document 1, when the authority of the user authenticated by the first authentication process is a predetermined authority, the predetermined authority is given to the user authenticated by the first authentication process. On the other hand, when the authority of the user authenticated by the first authentication process is not a predetermined authority, the user is further authenticated by the second authentication process, and control is performed to give the authority when the authentication in the second authentication process is successful.

[0004] By the way, in a system that provides a cloud service related to a device to a user, when granting a specific user the authority to use the service, it is necessary to register the target device with the account information of the specific user. In this case, device-specific information such as a serial number is used for device registration. However, if the serial number or the like is stolen due to improper management or an attack, there is a risk that unauthorized acts such as impersonation may be committed by a third party who does not have the device.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] The present invention has been made to solve such problems, and in a system that provides a service related to a device to a user, it is an object to ensure security by enabling the use authority to be given only to a legitimate user having the device.

Means for Solving the Problems

[0007] To solve the above problems, in the present invention, user account information and device information unique to the device are acquired, an operation on the device is instructed to the user, and authentication is performed by determining whether or not the instructed operation has been performed based on status information indicating the state of the device. Then, when this authentication is successful, the account information and the device information are associated and registered, so as to grant the user corresponding to the account information the use authority for the service related to the device corresponding to the device information.

Effects of the Invention

[0008] According to the present invention configured as described above, authentication is successful only when the device corresponding to the acquired device information is actually in the hands of the user corresponding to the acquired account information and can perform the operation as instructed. Therefore, in a system that provides services related to the device to the user, the usage right can be given only to a legitimate user who has the device, and security can be ensured.

Brief Description of the Drawings

[0009]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Embodiments for Carrying Out the Invention

[0010] Hereinafter, an embodiment of the present invention will be described with reference to the drawings. FIG. 1 is a diagram showing an example of the overall configuration of the authentication system according to this embodiment. As shown in FIG. 1, the authentication system of this embodiment includes a user terminal 100, a printer 200 which is an example of a device, and a server device 300. The user terminal 100 and the server device 300, and the printer 200 and the server device 300 are connected via a communication network 500 such as the Internet or a mobile phone network. The user terminal 100 and the printer 200 are connected via a wired cable or wireless communication means.

[0011] The authentication system of this embodiment is a system that authenticates a user who wishes to use a cloud service related to a device (printer 200). The content of the cloud service related to the printer 200 is arbitrary. For example, the cloud service can be a service that monitors the state of the printer 200 by the server device 300 and notifies the user terminal 100 of the detected state of the printer 200. When starting to use this cloud service, the user undergoes authentication by the authentication system of this embodiment, and when the authentication is successful, the service can be used.

[0012] The user terminal 100 is, for example, a smartphone, a tablet, a notebook computer, or a desktop computer. The user terminal 100 has an application installed that has a function of executing printing using the printer 200, and can give a printing instruction to the printer 200 through the application. Further, the user terminal 100 has a web browser function, and can communicate with the server device 300 through the web browser function or the application function to use the cloud service.

[0013] The printer 200 executes printing in accordance with an instruction from the user terminal 100. Further, the printer 200 detects various states (details will be described later) and transmits status information indicating the states to the server device 300. The server device 300 provides the above-described cloud service to the user terminal 100 by using the status information transmitted from the printer 200, and performs an authentication process for determining whether a user who wishes to use the cloud service is a legitimate user.

[0014] In FIG. 1, a configuration is shown assuming that the provision of the cloud service and the authentication process are performed by the same server device 300, but the present invention is not limited to this. For example, a server device (not shown) that provides the cloud service may exist separately from the server device 300 that performs the authentication process.

[0015] Further, in FIG. 1, a configuration is shown assuming that the cloud service is used in the user terminal 100 that performs printing using the printer 200, but the present invention is not limited to this. For example, a terminal (not shown) that performs printing using the printer 200 may exist separately from the user terminal 100 that uses the cloud service. As a specific example, a form in which a POS terminal and the printer 200 are connected, printing is performed from the POS terminal to the printer 200, and the user terminal 100 uses the cloud service may be adopted.

[0016] FIG. 2 is a block diagram showing an example of the functional configuration of the user terminal 100. FIG. 3 is a block diagram showing an example of the functional configuration of the printer 200. FIG. 4 is a block diagram showing an example of the functional configuration of the server device 300. In FIGS. 2 to 4, the main part configurations related to the authentication process of the present embodiment are mainly shown, and the details of this authentication process will be described in detail below. The processes related to the provision and use of the cloud service are not the subject of the present invention, and thus will be briefly described.

[0017] As shown in FIG. 2, the user terminal 100 of the present embodiment includes, as functional components, an account information input unit 11, a device information input unit 12, an input information transmission unit 13, an operation instruction reception unit 14, and an instruction content display unit 15. Each of these functional blocks 11 to 15 can be configured by any of hardware, a DSP (Digital Signal Processor), and software. For example, when configured by software, each of the above functional blocks 11 to 15 is actually configured with a computer's CPU, RAM, ROM, etc., and is realized by the operation of a program stored in a recording medium such as RAM, ROM, a hard disk, or a semiconductor memory.

[0018] The account information input unit 11 inputs the user's account information according to the operation by the user on the user terminal 100. The account information is a user ID and a password. The user ID may be information that can uniquely identify an individual user. For example, it is possible to use the user's email address as the user ID. The password can use information arbitrarily set by the user.

[0019] The device information input unit 12 inputs the device information unique to the device (printer 200) according to the operation by the user on the user terminal 100. The device information may be information that can uniquely identify each printer 200. For example, it is possible to use the serial number of the printer 200 as the device information.

[0020] The input information transmission unit 13 transmits the account information input by the account information input unit 11 and the device information input by the device information input unit 12 to the server device 300 via the communication network 500. Here, when the input information transmission unit 13 transmits the account information to the server device 300, the server device 300 authenticates the user based on the account information as described later. And when the authentication is successful, this is notified from the server device 300 to the user terminal 100, and the device information can be input. The input information transmission unit 13 then transmits the subsequently input device information to the server device 300.

[0021] FIG. 5 is a diagram showing an example of an input screen of account information displayed on the user terminal 100. As shown in FIG. 5, the user inputs the user ID in the ID input field 51 and inputs the password in the password input field 52 to input the account information, and then presses the send button 53 to transmit the account information to the server device 300. That is, the account information input unit 11 inputs the account information according to the input operations by the user for the ID input field 51 and the password input field 52, and the input information transmission unit 13 transmits the input account information to the server device 300 in response to the pressing of the send button 53.

[0022] Note that in FIG. 5, an input example when the user already has account information is shown, but it is also possible to newly create and input the account information. In this case, for example, after inputting an email address as the user ID and transmitting it to the server device 300, the validity of the email address is confirmed by inputting the authentication code sent to the email address as a response and transmitting it to the server device 300. Then, by inputting an arbitrary password and transmitting it to the server device 300, the account information consisting of the combination of the user ID and the password is newly registered in the server device 300.

[0023] FIG. 6 is a diagram showing an example of an input screen for device information displayed on the user terminal 100. This input screen for device information is in a displayable state when the user authentication by account information is successful or when the new registration of account information is completed.

[0024] As shown in FIG. 6, the user activates the camera provided in the user terminal 100 and reads the barcode of the serial number printed on the product label attached to the housing of the printer 200, thereby transmitting the device information to the server device 300. That is, the device information input unit 12 inputs the device information according to the barcode reading operation by the user, and the input information transmission unit 13 transmits the input device information to the server device 300. Note that, similar to FIG. 5, after manually inputting the serial number in the serial number input field, the device information may be transmitted to the server device 300 in response to pressing the send button.

[0025] The operation instruction receiving unit 14 receives, from the server device 300 via the communication network 500, instruction information (details will be described later) on the operation that the user should perform on the printer 200. The instruction content display unit 15 causes the display of the user terminal 100 to display the instruction content of the operation that the user should perform on the printer 200 based on the instruction information received by the operation instruction receiving unit 14.

[0026] FIG. 7 is a diagram showing an example of an operation instruction screen displayed on the user terminal 100. In FIG. 7, an example is shown in which the instruction content of the operation of opening and closing the cover of the printer 200 twice is displayed by character information and video information (animation information). Note that the instruction content of the operation may be displayed by either the character information or the video information.

[0027] As shown in FIG. 3, the printer 200 includes, as functional components, a state detection unit 21, a status information generation unit 22, and a status information transmission unit 23. Each of these functional blocks 21 to 23 can be configured by any of hardware, DSP, and software. For example, when configured by software, each of the above functional blocks 21 to 23 is actually configured with a computer's CPU, RAM, ROM, etc., and is realized by the operation of a program stored in a recording medium such as RAM, ROM, hard disk, or semiconductor memory.

[0028] The state detection unit 21 detects the state of the printer 200. The state of the printer 200 to be detected is, for example, the opening and closing of the cover, paper discharge, presence or absence of paper, remaining amount of ink or toner, battery remaining amount, printing result (printing success / printing failure), printing setting information (paper setting, number of printed sheets, print quality, color / black and white selection, image processing method, etc.). The status information generation unit 22 generates status information indicating the state detected by the state detection unit 21. The status information transmission unit 23 transmits the status information generated by the status information generation unit 22 to the server device 300 via the communication network 500.

[0029] Note that the state detection unit 21 may detect the state of a device connected as an expansion device to a USB port or wireless port of the printer 200. Examples of expansion devices include a camera module, an acoustic device, and an electronic locking mechanism. Examples of the state to be detected include the presence or absence of a change in the image by the camera module, a change or recording of sound by the acoustic device, and a locking / unlocking operation of the lock by the electronic locking mechanism. It is better to let the server device 300 side recognize in advance the expansion devices connected to the printer 200.

[0030] Whenever the status detection unit 21 detects a change in the status of the printer 200, or whenever the status of the printer 200 meets a predetermined condition, the status information generation unit 22 generates status information. Then, when the status information is generated by the status information generation unit 22, the status information transmission unit 23 transmits it to the server device 300.

[0031] For example, when the status detection unit 21 detects that the cover has been opened, status information indicating that the cover is open is generated and transmitted to the server device 300. Conversely, when the status detection unit 21 detects that the cover has been closed, status information indicating that the cover is closed is generated and transmitted to the server device 300. Also, when the paper discharge is detected by the status detection unit 21, status information indicating that is generated and transmitted to the server device 300.

[0032] Also, when the status detection unit 21 detects that the remaining amount of paper has become less than a predetermined amount or has become zero, status information indicating that is generated and transmitted to the server device 300. Conversely, when the status detection unit 21 detects that the paper has been replenished and the remaining amount has changed from less than the predetermined amount to more than the predetermined amount, status information indicating that is generated and transmitted to the server device 300. The same applies to the remaining amount of ink or toner and the remaining battery level.

[0033] Also, when the status detection unit 21 detects that the printing instructed by the user terminal 100 has been successfully completed, status information indicating successful printing is generated and transmitted to the server device 300. Conversely, when the status detection unit 21 detects that some error has occurred during printing, status information indicating printing failure is generated and transmitted to the server device 300. Also, when the status detection unit 21 detects a change in the print setting information, status information indicating the changed content is generated and transmitted to the server device 300.

[0034] The status information transmitted to the server device 300 is used for a cloud service that notifies the user terminal 100 of the status of the printer 200. Further, the status information transmitted to the server device 300 is used for the authentication process of a user who wishes to use the cloud service. This authentication process is performed from the viewpoint of whether the user has operated the printer 200 as instructed by the instruction content transmitted from the server device 300 to the user terminal 100.

[0035] For example, as shown in FIG. 7, when an operation of opening and closing the cover of the printer 200 twice is instructed, if the user opens and closes the cover of the printer 200 twice accordingly, status information indicating that the cover is open and status information indicating that the cover is closed are each generated twice alternately and transmitted to the server device 300. As will be described later, the server device 300 performs an authentication process based on the status information sent from the printer 200 in this way.

[0036] As shown in FIG. 4, the server device 300 includes, as functional components, an account information acquisition unit 31, a device information acquisition unit 32, a status information acquisition unit 33, an authentication processing unit 34, an operation instruction transmission unit 35, and an authority setting unit 36. Further, the server device 300 includes, as a storage medium, a user management information storage unit 30. Each of the above functional blocks 31 to 36 can be configured by any of hardware, DSP, and software. For example, when configured by software, each of the above functional blocks 31 to 36 is actually configured with a computer's CPU, RAM, ROM, etc., and is realized by the operation of a program stored in a recording medium such as RAM, ROM, hard disk, or semiconductor memory.

[0037] The account information acquisition unit 31 acquires the user's account information transmitted by the input information transmission unit 13 of the user terminal 100. The device information acquisition unit 32 acquires the device information (serial number unique to the printer 200) transmitted by the input information transmission unit 13 of the user terminal 100. The status information acquisition unit 33 acquires the status information transmitted by the status information transmission unit 23 of the printer 200.

[0038] The authentication processing unit 34 performs authentication to confirm the legitimacy of the user by comparing the account information acquired by the account information acquisition unit 31 with the account information registered in the user management information storage unit 30. If this authentication is successful, the authentication processing unit 34 notifies the user terminal 100 to that effect. Then, when the device information acquisition unit 32 acquires the device information input at the user terminal 100 in response to this, the authentication processing unit 34 instructs the user to perform an operation on the printer 200, and determines whether the operation as instructed has been performed based on the status information acquired by the status information acquisition unit 33 to perform authentication.

[0039] That is, after the authentication processing unit 34 acquires the account information by the account information acquisition unit 31 and the authentication based on the account information is successful, when the device information acquisition unit 32 acquires the device information, the authentication processing unit 34 generates instruction information representing the content of the operation that the user should perform on the printer 200, and transmits it to the user terminal 100 via the operation instruction transmission unit 35. This instruction information includes at least one of character information and video information indicating the content of the operation instruction and information necessary to display it on the user terminal 100.

[0040] Thereafter, the authentication processing unit 34 determines whether the change in the state of the printer 200 indicated by a series of status information acquired by the status information acquisition unit 33 within a predetermined time after transmitting the instruction information matches the content of the operation instruction. If it matches, it determines that the authentication is successful. On the other hand, if the status information is not acquired within a predetermined time after transmitting the instruction information, or if the change in the state of the printer 200 indicated by the series of status information acquired within a predetermined time does not match the content of the operation instruction, it determines that the authentication is unsuccessful.

[0041] Here, the authentication processing unit 34 instructs an operation that commonly exists regardless of the model of the printer 200. For example, in the case where there are upper and lower models of the printer 200, an operation that commonly exists in both the upper and lower models, such as an operation related to opening and closing the cover, an operation related to paper discharge, an operation related to changing specific print setting information, etc., is instructed. By doing so, the types of instruction information issued from the server device 300 can be reduced.

[0042] Also, the authentication processing unit 34 may instruct an operation that commonly exists regardless of the model of the printer 200 by randomly changing the operation method. For example, regarding the operation related to opening and closing the cover, an operation method of opening and closing the cover n times (n is an arbitrary value of 1 or more), an operation method of opening the cover and then closing the cover after a predetermined time has elapsed, etc., are randomly changed each time the authentication process is performed and instructed. By doing so, since the user must actually confirm the instruction content and perform the operation of the printer 200 in order to succeed in authentication, the security level can be increased.

[0043] Also, in order to enhance the security level, the authentication processing unit 34 may instruct an operation specific to the device corresponding to the device information acquired by the device information acquisition unit 32. For example, in the case where there are upper and lower models in the printer 200, when the device corresponding to the device information acquired by the device information acquisition unit 32 corresponds to the upper model, an instruction corresponding to the device type is given so as to instruct an operation that exists only in the upper model. For example, functions based on device information are held and managed by the server device 300 for each model in advance, and by executing a confirmation function based on the same, it is possible to instruct a specific operation existing in the corresponding model.

[0044] When the authentication by the authentication processing unit 34 is successful, the authority setting unit 36 associates the account information acquired by the account information acquisition unit 31 with the device information acquired by the device information acquisition unit 32 and registers the same in the user management information storage unit 30, thereby granting the user corresponding to the account information the right to use the cloud service related to the device corresponding to the device information. The user to whom the use right is granted can then use the cloud service of the server device 300 simply by inputting the account information.

[0045] FIG. 8 is a flowchart showing an operation example of the server device 300 according to the present embodiment configured as described above. First, the account information acquisition unit 31 acquires the user's account information from the user terminal 100 (step S1). Next, the authentication processing unit 34 performs authentication to confirm the legitimacy of the user based on the acquired account information, and determines whether the authentication is successful (step S2).

[0046] Here, if the authentication of the user based on the account information is unsuccessful, the authentication process shown in FIG. 8 is terminated. On the other hand, when the authentication of the user based on the account information is successful, this is notified to the user terminal 100, and correspondingly, device information is transmitted from the user terminal 100, so the device information acquisition unit 32 acquires the device information (step S3).

[0047] In this way, when the account information and the device information are sequentially acquired, the authentication processing unit 34 generates instruction information representing the content of the operation that the user should perform on the printer 200, and transmits it to the user terminal 100 via the operation instruction transmission unit 35 (step S4). Then, the status information acquisition unit 33 determines whether or not status information has been acquired from the printer 200 (step S5).

[0048] When the status information acquisition unit 33 has not acquired the status information, it determines whether or not a predetermined time has elapsed since the authentication processing unit 34 transmitted the operation instruction information (step S6), and continues to determine whether or not status information has been acquired from the printer 200 until the predetermined time elapses (step S5). When the status information acquisition unit 33 acquires the status information, the authentication processing unit 34 determines whether or not the operation as instructed has been performed by the user based on the status information (step S7).

[0049] Here, when it is determined that the operation as instructed has been performed on the printer 200, the authentication processing unit 34 determines that the authentication is successful (step S8). In this case, the authority setting unit 36 associates the account information acquired in step S1 and the device information acquired in step S2 and registers them in the user management information storage unit 30, thereby granting the user corresponding to the account information the usage authority of the cloud service related to the device corresponding to the device information (step S9). Thereby, the authentication process shown in FIG. 8 is terminated.

[0050] In step S7 above, when it is determined that the operation as instructed has not been performed on the printer 200, the authentication processing unit 34 determines that the authentication is unsuccessful (step S10). Also, in step S6 above, when it is determined that the predetermined time has elapsed without the status information acquisition unit 33 acquiring the status information from the printer 200, the authentication processing unit 34 also determines that the authentication is unsuccessful (step S10). In this case, the authentication process shown in FIG. 8 is terminated without performing the process of step S9.

[0051] As described in detail above, in the present embodiment, after the server device 300 acquires the user's account information and the device information unique to the printer 200, it instructs the user to perform an operation on the printer 200, and determines whether the operation as instructed has been performed based on the status information of the printer 200, thereby performing authentication. When the authentication is successful, the account information and the device information are registered in association with each other, thereby granting the user corresponding to the account information the right to use the service related to the device corresponding to the device information.

[0052] According to the present embodiment configured as described above, the printer 200 corresponding to the device information acquired by the device information acquisition unit 32 is actually in the hands of the user corresponding to the account information acquired by the account information acquisition unit 31, and the authentication is successful only when the printer 200 can perform the operation as instructed. Therefore, in a system that provides a cloud service related to the printer 200 to the user, the use right can be granted only to a legitimate user who has the printer 200, and security can be ensured. Further, in the present embodiment, since the authentication is executed with a time limit from when the server device 300 instructs the user terminal 100 to operate the printer 200 until the status information is received, it is possible to enhance the security.

[0053] In the above embodiment, the configuration using the printer 200 as an example of the device has been described, but the device is not limited to the printer 200. For example, a cash drawer, a customer display, a scanner, a scale, a card reader / writer, a payment device, etc. may be used. When using a cash drawer, for example, it is possible to instruct operations such as opening and closing of the drawer in which money is stored, and opening and closing of the locking mechanism of the drawer. When using a customer display, for example, it is possible to instruct operations such as adjustment of the screen shading and brightness, and plugging and unplugging of a USB cable.

[0054] When using a scanner, for example, it is possible to instruct operations such as reading a bar code with an expiration date displayed on the screen of the user terminal 100 or pressing a trigger switch to instruct bar code reading. When using a scale, for example, it is possible to instruct operations such as placing a weight on the scale, applying pressure from above the mounting table, or pressing a reset button. When using a card reader / writer, for example, it is possible to instruct an operation such as reading a card. When using a payment device, for example, it is possible to instruct operations such as inputting predetermined information or swiping the screen.

[0055] In addition, in the above-described embodiment, an example in which the cloud service can be used only by inputting account information after authenticating the device operation once at the start of using the cloud service has been described, but the present invention is not limited to this. For example, authentication regarding the device operation may be performed each time the cloud service is used or each time a specific function in the cloud service is used. In this case, the authority setting unit 36 can be omitted. Whether such per-use authentication is required or not can be arbitrarily determined according to the content of the cloud service.

[0056] In addition, in the above-described embodiment, the service use authority granted when authentication is successful may be, in addition to the authority for using the cloud service, an administrative authority for making various settings when using the cloud service. For example, the service itself for notifying the user terminal 100 of the state of the printer 200 can be used without individual users undergoing authentication by account information or authentication by device operation, while authentication is performed when using the cloud service for making various settings regarding this service (for example, setting the types of states to be notified, setting the user terminal 100 to be the notification destination, etc.), and administrative authority is granted when the authentication is successful.

[0057] In addition, each of the above embodiments merely shows an example of implementation in carrying out the present invention, and thus the technical scope of the present invention should not be construed in a limited manner. That is, the present invention can be implemented in various forms without departing from its gist or main features.

Explanation of Reference Numerals

[0058] 31 Account information acquisition unit 32 Device information acquisition unit 33 Status information acquisition unit 34 Authentication processing unit 35 Operation instruction transmission unit 36 Authority setting unit 100 User terminal 200 Printer (device) 300 Server device

Claims

1. An authentication system for authenticating a user who wishes to use a service related to a device, comprising: an account information acquisition unit that acquires the account information of the user; a device information acquisition unit that acquires device information unique to the device; a status information acquisition unit that acquires status information indicating the status of the device; an authentication processing unit that authenticates by instructing the user to perform an operation on the device and determining whether the instructed operation has been performed based on the status information acquired by the status information acquisition unit; the device is a device that operates upon receiving an instruction from a POS terminal; the operation instructed by the authentication processing unit to the user is an operation directly performed on the device, which is different from the operation performed to instruct the device to operate from the POS terminal An authentication system characterized by the above.

2. An authentication system for authenticating a user who wishes to use a service related to a device, comprising: the server device for performing the authentication comprises: an account information acquisition unit that acquires the account information of the user; a device information acquisition unit that acquires device information unique to the device; a status information acquisition unit that acquires status information indicating the status of the device from the device; an authentication processing unit that authenticates by instructing the user to perform an operation on the device and determining whether the instructed operation has been performed based on the status information acquired by the status information acquisition unit; the device comprises: a status detection unit that detects the status of the device; a status information generation unit that generates the status information each time a change in the status of the device is detected by the status detection unit or each time the status of the device detected by the status detection unit meets a predetermined condition; a status information transmission unit that transmits the status information generated by the status information generation unit to the server device An authentication system characterized by the above.

3. The service related to the device is a service that monitors the status of the device and notifies the user of the detected status, using the status information acquired by the status information acquisition unit, the authentication processing unit performs authentication and provides the service after the authentication is successful The authentication system according to claim 2, characterized by the above.

4. When the authentication by the authentication processing unit is successful, by associating and registering the account information acquired by the account information acquisition unit and the device information acquired by the device information acquisition unit, the user corresponding to the account information is given the right to use the service related to the device corresponding to the device information. The authentication system according to any one of claims 1 to 3, further comprising an authority setting unit.

5. The authentication system according to any one of claims 1 to 4, wherein the device is a printer.

6. The service related to the device is a service that monitors the state of the device and notifies the user of the detected state. The operation instructed by the authentication processing unit to the user is an operation for setting the same state as the state of the device notified in the service. The authentication system according to claim 5.

7. The authentication system according to any one of claims 1 to 4, characterized in that there are separately an authentication-required terminal that uses the service and an authentication-unrequired terminal that instructs the device to operate.

8. The authentication system according to claim 4, wherein the service includes a service for which the use authority is granted by the authority setting unit when the authentication is successful and a service that can be used without performing the authentication.

9. The authentication system according to claim 8, wherein the use authority granted by the authority setting unit when the authentication is successful is an administrative authority for setting for using a service that can be used without performing the authentication.

10. The authentication processing unit instructs an operation specific to the device corresponding to the device information acquired by the device information acquisition unit. The authentication system according to any one of claims 1 to 4.

11. The authentication processing unit instructs an operation according to the model of the device corresponding to the device information acquired by the device information acquisition unit. The authentication system according to any one of claims 1 to 4.

12. An authentication method for authenticating a user who wishes to use a service related to a device, comprising: A first step in which an account information acquisition unit of a server device acquires the account information of the user from a user terminal. A second step in which a device information acquisition unit of the server apparatus acquires device information unique to the device from the user terminal; A third step of authentication in which, after an authentication processing unit of the server apparatus instructs the user to perform an operation on the device, the authentication is performed by determining whether or not the instructed operation has been performed based on status information indicating the status of the device acquired by a status information acquisition unit of the server apparatus from the device; The device is a device that operates upon receiving an instruction from a POS terminal; The operation instructed by the authentication processing unit to the user is an operation directly performed on the device, which is different from the operation performed to instruct the device to operate from the POS terminal; A authentication method characterized by the above. **Claim 13**: An authentication method for authenticating a user who wishes to use a service related to a device, A first step in which an account information acquisition unit of a server apparatus acquires account information of the user from a user terminal; A second step in which a device information acquisition unit of the server apparatus acquires device information unique to the device from the user terminal; A third step of authentication in which, after an authentication processing unit of the server apparatus instructs the user to perform an operation on the device, the authentication is performed by determining whether or not the instructed operation has been performed based on status information indicating the status of the device acquired by a status information acquisition unit of the server apparatus from the device; Regarding the processing of the status information, the device detects the status of the device, and each time a change in the status of the device is detected, or each time the status of the device meets a predetermined condition, the device generates the status information and transmits the generated status information to the server apparatus; A authentication method characterized by the above. **Claim 14** A fourth step in which, when the authentication by the authentication processing unit is successful, a privilege setting unit of the server apparatus associates and registers the account information acquired by the account information acquisition unit and the device information acquired by the device information acquisition unit, thereby granting a user corresponding to the account information the right to use a service related to the device corresponding to the device information, the authentication method according to claim 12 or 13, further characterized by having the above.

Citation Information

Patent Citations

  • Method and device for converting color image information

    JP1986084194A

  • Method for specifying owner of network apparatus

    JP2005173865A

  • Authentication method

    JP2017021413A

  • Pairing system for remote management of hot water use facility and communication adapter used in the same

    JP2018186452A