Function execution device, server, and communication system
The communication system employs FIDO authentication with a pair of keys to securely and efficiently execute functions on devices like MFPs by automating the authentication and authorization process, addressing the lack of efficient methods in existing systems.
Patent Information
- Application Number
- JP2021098961
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-06-14
- Publication Date
- 2025-07-23
- Estimated Expiration
- 2041-06-14
AI Technical Summary
Existing systems lack an efficient method for authenticating and authorizing the execution of specific functions on devices using a pair of keys, particularly in scenarios involving multifunction peripherals (MFPs) and terminal devices.
A communication system utilizing a FIDO authentication method with a pair of keys, where a function execution device outputs information to a terminal device, which accesses a server, generates and encrypts verification information, and transmits it back to the server for decryption and execution instruction, enabling the device to execute specific functions.
Enables secure and efficient execution of functions on devices like MFPs through FIDO authentication, enhancing user convenience and security by eliminating the need for manual URL input and improving authentication processes.
Smart Images

Figure 0007711443000001 
Figure 0007711443000002 
Figure 0007711443000003
Abstract
Description
Technical Field
[0001] This specification discloses a technique for causing a function execution device to execute a specific function according to a predetermined authentication method using a pair of keys.
Background Art
[0002] Patent Document 1 discloses a system including an image processing device, an external authenticator, and a service providing system. When the image processing device receives an operation for using a printing service, it transmits a service provision request to the service providing system, receives authentication of a biometric request including an Assertion Challenge from the service providing system, and transmits an assertion creation request including the Assertion Challenge to the external authenticator. When the biometric authentication is successful, the external authenticator encrypts the Assertion Challenge using a secret key to generate signature data. Then, the external authenticator transmits assertion information including the signature data to the image processing device, and the image processing device transmits an assertion verification request including the assertion information to the service providing system. The service providing system decrypts the signature data included in the assertion information using a public key, and determines that the user authentication is successful when the decrypted value matches the Assertion Challenge, and transmits a signal for providing the printing service to the image processing device.
Prior Art Documents
Patent Documents
[0003]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0004] This specification provides a novel technique for causing a function execution device to execute a specific function according to a predetermined authentication method using a pair of keys.
Means for Solving the Problem
[0005] The function execution device disclosed in this specification includes a first output unit, and when a specific instruction for causing the function execution device to execute a specific function is received from a target user, a first output control unit that causes the first output unit to output first output information including the position information of a server operable according to a predetermined authentication method using a pair of keys. The first output information is obtained by a terminal device operable according to the predetermined authentication method. When the first output information is obtained, the terminal device uses the position information included in the first output information to access the server, receives first verification information from the server, and when the first authentication of the target user executed by the terminal device is successful, generates signature information by encrypting the first verification information using the secret key of the pair of keys, and transmits the signature information to the server. When the server receives the signature information from the terminal device, the server decrypts the signature information using the public key of the pair of keys, and when the first verification information is obtained by decrypting the signature information, transmits an execution instruction for the specific function to the function execution device. The function execution device may further include a function execution unit that executes the specific function when the execution instruction is received from the server after the first output information is output.
[0006] According to the above configuration, when the function execution device receives a specific instruction from the target user, it causes the first output unit to output the first output information. When the terminal device acquires the first output information, it accesses the server using the location information, and accordingly receives the first verification information from the server. When the first authentication of the target user is successful, the terminal device generates signature information by encrypting the first verification information using the private key, and transmits the generated signature information to the server. When the server receives the signature information from the terminal device, it decrypts the signature information using the public key. When the first verification information can be obtained by decrypting the signature information, the server transmits an execution instruction to the function execution device. After outputting the first output information, when the function execution device receives an execution instruction from the server, it executes a specific function. Therefore, according to a predetermined authentication method using a pair of keys, the function execution device can be made to execute a specific function.
[0007] Also, the server disclosed by this specification may be operable according to a predetermined authentication method that utilizes a pair of keys. When the first output information output from the function execution device is acquired by the terminal device and the terminal device accesses the server using the position information of the server included in the first output information, the server is a verification information transmission unit that transmits first verification information to the terminal device. When the function execution device receives a specific instruction for executing a specific function from a target user, the function execution device outputs the first output information. After receiving the first verification information from the server, when the first authentication of the target user executed by the terminal device is successful, the terminal device generates signature information by encrypting the first verification information using the secret key of the pair of keys, and transmits the signature information to the server. The verification information transmission unit, a signature information reception unit that receives the signature information from the terminal device, and when the signature information is received from the terminal device, a decryption unit that decrypts the signature information using the public key of the pair of keys, and when the first verification information is obtained by decrypting the signature information, an execution instruction transmission unit that transmits an execution instruction for the specific function to the function execution device. When the function execution device receives the execution instruction from the server, the function execution device executes the specific function. The execution instruction transmission unit may be provided.
[0008] According to the above configuration, when the first output information output from the function execution device is acquired by the terminal device and the terminal device that has acquired the first output information accesses the server using the location information, the server transmits the first verification information to the terminal device. When the first authentication of the target user is successful, the terminal device generates signature information by encrypting the first verification information using the private key, and transmits the generated signature information to the server. When the server receives the signature information from the terminal device, the server decrypts the signature information using the public key. When the first verification information can be obtained by decrypting the signature information, the server transmits an execution instruction to the function execution device. When the function execution device receives the execution instruction from the server, the function execution device executes a specific function. Therefore, according to a predetermined authentication method using a pair of keys, the function execution device can be made to execute a specific function.
[0009] Further, the communication system disclosed by this specification may include a function execution device and a server operable according to a predetermined authentication method using a pair of keys. The function execution device includes a first output unit and a first output control unit that, when a specific instruction for causing the function execution device to execute a specific function is received from a target user, outputs first output information including the position information of the server to the first output unit, where the first output information is obtained by a terminal device operable according to the predetermined authentication method. The server is a verification information transmission unit that transmits first verification information to the terminal device when the terminal device accesses the server using the position information included in the first output information. After receiving the first verification information from the server, the terminal device generates signature information by encrypting the first verification information using a secret key of the pair of keys when the first authentication of the target user executed by the terminal device is successful, and transmits the signature information to the server. The server includes a signature information reception unit that receives the signature information from the terminal device, and a decryption unit that decrypts the signature information using a public key of the pair of keys when the signature information is received from the terminal device. When the first verification information is obtained by decrypting the signature information, the server includes an execution instruction transmission unit that transmits an execution instruction for the specific function to the function execution device. The function execution device may further include a function execution unit that executes the specific function when the execution instruction is received from the server after the first output information is output.
[0010] According to the above configuration, when the function execution device receives a specific instruction from the target user, it causes the first output unit to output the first output information. When the terminal device acquires the first output information, it accesses the server using the location information and receives the first verification information from the server accordingly. When the first authentication of the target user is successful, the terminal device generates signature information by encrypting the first verification information using the secret key and transmits the generated signature information to the server. When the server receives the signature information from the terminal device, it decrypts the signature information using the public key. When the first verification information can be obtained by decrypting the signature information, the server transmits an execution instruction to the function execution device. After outputting the first output information, when the function execution device receives an execution instruction from the server, it executes a specific function. Therefore, according to a predetermined authentication method using a pair of keys, the function execution device can be made to execute a specific function.
[0011] Also, the above method for controlling the function execution device, the computer program for the function execution device, and the storage medium storing the computer program are novel and useful. Further, the above method for controlling the server, the computer program for the server, and the storage medium storing the computer program are novel and useful.
Brief Description of the Drawings
[0012]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0013] (First Embodiment) (Configuration of Communication System 2; Fig. 1) As shown in Fig. 1, the communication system 2 includes an MFP (abbreviation for Multifunction Peripheral) 10, a terminal device 100, a PC 200, and a server 300. The MFP 10, the terminal device 100, and the PC 200 belong to the same LAN (abbreviation for Local Area Network) 4 and can communicate with each other via the LAN 4. The LAN 4 is connected to the Internet 6. The server 300 is connected to the Internet 6. The MFP 10, the terminal device 100, the PC 200, and the server 300 can communicate with each other via the Internet 6. In this embodiment, the terminal device 100 and the PC 200 are used by the same user.
[0014] (Configuration of MFP 10) The MFP 10 is a peripheral device (for example, a peripheral device of the terminal device 100) capable of executing functions such as a printing function, a scanning function, a copying function, and a web server function. The web server function is a function of transmitting web page data representing a web page to an external device in response to the external device accessing the web server in the MFP 10. A device ID "dv1" for identifying the MFP 10 is assigned to the MFP 10.
[0015] The MFP 10 includes an operation unit 12, a display unit 14, a print execution unit 16, a scan execution unit 18, a communication interface 20, and a control unit 30. Hereinafter, the interface is simply referred to as "I / F".
[0016] The operation unit 12 includes a plurality of keys. The user can input various instructions to the MFP 10 by operating the operation unit 12. The display unit 14 is a display for displaying various information. Note that the display unit 14 may function as a touch panel (i.e., the operation unit 12).
[0017] The printing execution unit 16 is equipped with a printing mechanism such as an inkjet method or a laser method. The scanning execution unit 18 is equipped with a scanning mechanism such as a CCD (abbreviation for Charge Coupled Device) image sensor or a CIS (abbreviation for Contact Image Sensor). The communication I / F 20 is connected to the LAN 4. The communication I / F 20 may be a wireless I / F or a wired I / F.
[0018] The control unit 30 includes a CPU 32 and a memory 34. The CPU 32 executes various processes according to a program 36 stored in the memory 34. The memory 34 is composed of a volatile memory, a non-volatile memory, etc. The memory 34 further stores a user table 38.
[0019] (Configuration of the terminal device 100) The terminal device 100 is a portable terminal device such as a mobile phone (e.g., a smartphone), a PDA, or a tablet PC. The terminal device 100 includes an operation unit 112, a display unit 114, a communication I / F 120, a camera 122, and a control unit 130.
[0020] The operation unit 112 is, for example, a touch panel. The operation unit 112 can receive various instructions. The operation unit 112 also functions as a fingerprint authentication unit. The display unit 114 is a display for displaying various information. The communication I / F 120 is connected to the LAN 4. The camera 122 is a device for photographing an object. In this embodiment, the camera 122 is used to photograph the QR code (registered trademark) displayed on the display unit 14 of the MFP 10.
[0021] The control unit 130 includes a CPU 132 and a memory 134. The CPU 132 executes various processes according to the OS (abbreviation for Operating System) program 136 stored in the memory 134. The terminal device 100 can operate according to the FIDO (abbreviation for Fast Identity Online) authentication method that uses a pair of keys. The FIDO authentication method is an authentication method that uses a pair of keys, namely, a private key and a public key. Also, the FIDO authentication method is an authentication method that performs user authentication using biometric authentication (e.g., fingerprint authentication, voiceprint impression, face authentication) instead of authentication using a password. In this embodiment, the terminal device 100 operates as a so-called authenticator in the FIDO authentication method. The memory 134 is composed of a volatile memory, a non-volatile memory, etc. The memory 134 further stores fingerprint information 138 and a private key SK1. The fingerprint information 138 is information regarding the fingerprint of the user who uses the terminal device 100. The private key SK1 is used when performing authentication according to the FIDO authentication method (hereinafter simply referred to as "FIDO authentication").
[0022] (Configuration of Server 300) The server 300 is a server installed on the Internet and is, for example, a server provided by the vendor of the MFP 10. In a modified example, the server 300 may be a server provided by a vendor different from the vendor of the MFP 10. The server 300 can operate according to the FIDO (abbreviation for Fast Identity Online) authentication method. In this embodiment, the server 300 operates as a so-called authentication server in the FIDO authentication method. The server 300 is configured to send an instruction to the MFP 10 to cause the MFP 10 to execute a function (e.g., a printing function) in response to the successful user authentication according to the FIDO authentication.
[0023] The server 300 includes a communication I / F 316 and a control unit 330. The communication I / F 316 is connected to the Internet 6. The control unit 330 includes a CPU 332 and a memory 334. The CPU 332 executes various processes according to a program 336 stored in the memory 334. The memory 334 further stores an authentication table 338.
[0024] (Contents of the user table 38 and the authentication table 338; FIG. 2) Subsequently, with reference to FIG. 2, the user table 38 in the MFP 10 and the authentication table 338 in the server 300 will be described.
[0025] In the user table 38 in the MFP 10, for each of one or more users who use the MFP 10, a user ID, restriction information, a job ID, and FIDO information are stored in association with each other. The restriction information is information that specifies one or more functions among the printing function, scanning function, and copying function that the MFP 10 can execute and that are permitted for the user. "OK" indicates that use is permitted, and "NG" indicates that use is not permitted. The FIDO information is information indicating whether the registration process for registering a pair of keys used for FIDO authentication has been completed. "Registered" indicates that the registration process has been completed, and "Unregistered" indicates that the registration process is incomplete. The job ID is information for identifying print data. Although not shown in the figure, print data is associated with the job ID.
[0026] In the authentication table 338 in the server 300, a user ID and a public key are stored in association with each other. The public key is used when executing FIDO authentication. The public key is registered in the authentication table 338 in the registration process described later.
[0027] (Registration process; FIG. 3) Next, with reference to FIG. 3, a registration process for registering information for executing FIDO authentication in each device will be described. In the following description, each device (e.g., MFP10) will be described without focusing on the CPU of each device (e.g., CPU 32 of MFP10). Also, the communication executed by each device is executed via the communication I / F of each device (e.g., communication I / F 20 of MFP10). For this reason, in the following description of the processes related to the communication via the communication I / F, the description "via the communication I / F" will be omitted.
[0028] In the initial state of FIG. 3, in the user table 38 of MFP10, the user ID "U1", printing "OK", scanning "OK", copying "NG", and FIDO information "unregistered" are stored in association. Also, fingerprint information 138 is stored in the memory 134 of the terminal device 100. Further, the authentication table 338 of the server 300 is in an empty state.
[0029] When the terminal device 100 receives the input of the IP address assigned to MFP10 at T10, it transmits a top screen data request to MFP10 at T12, receives the top screen data from MFP10 at T14, and displays the top screen on the display unit 114 at T16. On the top screen, an input field for inputting the user ID, a FIDO registration button for requesting to register information for executing FIDO authentication, etc. are displayed. When the terminal device 100 receives the input of the user ID "U1" and the selection of the FIDO registration button (i.e., registration instruction) at T20, it transmits a FIDO registration request including the user ID "U1" to MFP10 at T22.
[0030] When the MFP10 receives a FIDO registration request from the terminal device 100 at T22, it generates a URL (Uniform Resource Locator) 50 at T24. First, the MFP10 identifies a URL 50a (i.e., "https: / / server.com") pre-stored in the memory 34. The URL 50a is a URL for accessing the server 300. Then, the terminal device 100 generates the URL 50 by adding a query string 50b to the URL 50a. The query string 50b includes the user ID "U1" included in the received FIDO registration request and the device ID "dv1" of the MFP10 (i.e., "user=U1&device=dv1"). Next, at T26, the MFP10 sends a redirect instruction including the generated URL 50 to the terminal device 100. The redirect instruction is an instruction for causing the terminal device 100 to access the server 300 with the URL 50 in the redirect instruction as the destination URL.
[0031] When the terminal device 100 receives a redirect instruction from the MFP10 at T26, at T28, it sends a registration screen data request including the URL 50 in the redirect instruction as the destination URL to the server 300. Since a redirect instruction including the URL 50 is sent from the MFP10 to the terminal device 100, the user of the terminal device 100 does not have to perform an operation for accessing the server 300. Therefore, the convenience of the user can be improved.
[0032] When the server 300 receives a registration screen data request from the terminal device 100 at T28, it extracts the character string described before the mark "?" in the URL 50 included in the registration screen data request as the URL 50a, and extracts the character string described after the mark "?" as the query string 50b. The server 300 further extracts the user ID "U1" and the device ID "dv1" from the query string 50b. At T30, the server 300 associates the extracted user ID "U1" and device ID "dv1" and stores them in the memory 334. Then, at T32, the server 300 transmits the registration screen data to the terminal device 100.
[0033] When the terminal device 100 receives the registration screen data from the server 300 at T32, it displays the registration screen at T34. The registration screen is a screen for notifying the user that the registration process is being executed. Then, at T40, the terminal device 100 transmits a registration start request to the server 300 that requests registration of a pair of keys used for FIDO authentication.
[0034] When the server 300 receives the registration start request from the terminal device 100 at T40, it generates a verification code VC1 that is a unique character string at T42, and associates the generated verification code VC1 with the user ID "U1" and the device ID "dv1" and stores them in the memory 334 at T44. Then, at T46, the server 300 transmits an authentication request including the generated verification code VC1 to the terminal device 100.
[0035] When the terminal device 100 receives an authentication request from the server 300 at T46, it displays a fingerprint authentication screen at T48. A message requesting the execution of fingerprint authentication is displayed on the fingerprint authentication screen. The terminal device 100 receives a fingerprint authentication operation at T50. In this case, since the fingerprint information obtained by the fingerprint authentication operation matches the fingerprint information 138 in the memory 134, the terminal device 100 determines that the fingerprint authentication has succeeded. Next, the terminal device 100 generates a private key SK1 and a public key PK1 for use in FIDO authentication at T52, and stores the private key SK1 in the memory 134 at T54. Then, the terminal device 100 transmits an authentication response including the generated public key PK1 and the received verification code VC1 to the server 300 at T56.
[0036] When the server 300 receives an authentication response from the terminal device 100 at T56, it identifies the verification code VC1 in the response and identifies the user ID "U1" associated with the identified verification code VC1 in the memory 334. The server 300 determines that the identified verification code VC1 matches the verification code VC1 (see T44) associated with the identified user ID "U1" in the authentication table 338, and determines that the user authentication for the user ID "U1" has succeeded. In this case, at T58, the server 300 associates the public key PK1 in the received authentication response with the identified user ID "U1" and registers them in the authentication table 338 in the memory 334. Next, at T60, the server 300 transmits the first registration completion screen data to the terminal device 100. Also, the server 300 identifies the device ID "dv1" associated with the verification code VC1 in the memory 334, and at T70, transmits the second registration completion screen data including the user ID "U1" to the MFP10. Also, the server 300 deletes the device ID "dv1" and the verification code VC1 stored in the memory 334. As described above, the MFP10 transmits the URL 50 including the device ID "dv1" to the terminal device 100 via the communication I / F 20 (T24, T26 in FIG. 3) and the server 300 receives a registration screen data request including the device ID "dv1" from the terminal device 100 (T28). Therefore, even in an environment where there are multiple MFPs, the server 300 can appropriately determine the MFP to which the second registration completion screen data should be transmitted by using the device ID "dv1" received from the terminal device 100.
[0037] When the terminal device 100 receives the first registration completion screen data from the server 300 at T60, at T62, it displays a first registration completion screen including a message indicating that the registration process has been completed on the display unit 114. Thereby, the user can know that the registration of the pair of keys used for FIDO authentication has been completed.
[0038] When MFP10 receives the second registration completion screen data from server 300 at T70, at T72, it displays a second registration completion screen including a message indicating that the registration process has been completed on display unit 14. Next, at T74, MFP10 changes the FIDO information associated with user ID "U1" included in the received second registration completion screen data from "unregistered" to "registered" in user table 38. When the process at T74 ends, the registration process ends. As a result, the user of terminal device 100 can use FIDO authentication.
[0039] (Printing process; Figure 4) Subsequently, with reference to Figure 4, a printing process in which printing using MFP10 is executed will be described. Figure 4 shows the state after the registration process in Figure 3 has ended. That is, in user table 38 of MFP10, "registered" is stored in the FIDO information associated with user ID "U1". Also, private key SK1 is stored in memory 134 of terminal device 100. Further, in authentication table 338 of server 300, user ID "U1" and public key PK1 are stored in association with each other. Also, the user using PC200 transmits print data to MFP10 using PC200 after the registration process in Figure 3 has ended. For this reason, job ID "job1" corresponding to the print data received from PC200 is stored in user table 38 of MFP10 in association with user ID "U1".
[0040] When the MFP10 receives the input of the user ID "U1" at T110 and receives a print operation (i.e., a print instruction) at T112, it determines in the user table 38 that the FIDO authentication information associated with the input user ID "U1" is "registered". In this case, at T114, the MFP10 generates a URL 52 with a query string 52b added to the URL 52a. The URL 52a and the query string 52b are the same as the URL 50a (see FIG. 3) and the query string 50b (see FIG. 3), respectively. Note that when the MFP10 determines that the FIDO authentication information associated with the input user ID "U1" is "unregistered", it may display a message requesting the execution of the registration process on the display unit 14. Next, the MFP10 encodes the URL 52 to generate a QR code and displays the generated QR code on the display unit 14 at T116.
[0041] When the terminal device 100 receives an operation from the user to capture the QR code displayed on the display unit 14 of the MFP10 using the camera 122 at T120, it captures the QR code displayed on the display unit 14 of the MFP10. Next, at T122, the terminal device 100 decodes the captured QR code to obtain a URL 52 including the URL 52a and the query string 52b, and at T124, it sends an authentication screen data request including the obtained URL 52 as the destination URL to the server 300. Since the QR code encoded with the URL 52 including the URL 52a and the query string 52b is displayed on the display unit 14 of the MFP10, the user of the terminal device 100 does not need to perform an operation to input the URL 52a, the user ID "U1", and the device ID "dv1". Therefore, the convenience of the user can be improved.
[0042] When the server 300 receives an authentication screen data request from the terminal device 100 at T124, it extracts the string described before the mark "?" in the URL 52 as the URL 52a, and extracts the string described after the mark "?" as the query string 52b. The server 300 further extracts the user ID "U1" and the device ID "dv1" from the query string 52b. The server 300 determines in the authentication table 338 whether a user ID "U1" that matches the extracted user ID "U1" is stored. In this case, at T126, the server 300 stores the extracted device ID "dv1" in the authentication table 338 in association with the user ID "U1". Thereby, the user ID "U1", the public key PK1, and the device ID "dv1" are associated. Next, at T128, the server 300 transmits authentication screen data to the terminal device 100.
[0043] When the terminal device 100 receives authentication screen data from the server 300 at T128, it displays an authentication screen at T130. The authentication screen is a screen for notifying the user that a process for executing FIDO authentication is being executed. Next, at T140, the terminal device 100 transmits an authentication start request to the server 300.
[0044] When the server 300 receives an authentication start request from the terminal device 100 at T140, it generates a verification code VC2, which is a unique string, at T142, and stores the generated verification code VC2 in the authentication table 338 in association with the user ID "U1" at T144. Thereby, the user ID "U1", the public key PK1, the device ID "dv1", and the verification code VC2 are associated. Next, at T146, the server 300 transmits an authentication request including the generated verification code VC2 to the terminal device 100.
[0045] T148 and T150 are the same as T48 and T50 in FIG. 3, respectively. When the terminal device 100 determines that the fingerprint authentication is successful, at T152, it generates signature information SI1 by encrypting the received verification code VC2 using the secret key SK1 stored in the memory 134. Next, at T154, the terminal device 100 transmits an authentication response including the generated signature information SI1 to the server 300.
[0046] When the server 300 receives the authentication response from the terminal device 100 at T154, at T156, in the authentication table 338, it decrypts the signature information SI1 in the authentication response using the public key PK1 associated with the user ID "U1". In this embodiment, by decrypting the signature information SI1 using the public key PK1, the verification code VC2 is obtained. The server 300 determines that the decrypted signature information SI1 (i.e., the verification code VC2) matches the verification code VC2 (see T144) associated with the user ID "U1" in the authentication table 338, and determines that the user authentication of the user ID "U1" is successful. In this case, the server 300 identifies the device ID "dv1" associated with the user ID "U1" in the authentication table 338, and at T160, transmits an execution instruction to the MFP10. The execution instruction is information indicating that the user authentication of the user ID "U1" is successful, and is also information for instructing the execution of the function corresponding to the instruction received by the MFP10 (see T112). Further, after transmitting the execution instruction to the MFP10, the server 300 deletes the device ID "dv1" and the verification code VC2 associated with the user ID "U1" in the authentication table 338.
[0047] As described above, a QR code in which a URL 52 including the device ID "dv1" is encoded is displayed on the display unit 14 of the MFP 10 (see T114 and T116). Then, the server 300 receives an authentication screen data request including the device ID "dv1" from the terminal device 100 (T124). Therefore, even in an environment where there are a plurality of MFPs, the server 300 can appropriately determine the MFP to which an execution instruction should be sent by using the device ID "dv1" received from the terminal device 100. Also, as described above, a QR code in which a URL 52 including the user ID "U1" is encoded is displayed on the display unit 14 of the MFP 10 (see T114 and T116). Then, the server 300 receives an authentication screen data request including the user ID "U1" from the terminal device 100 (T124). Therefore, the server 300 can appropriately determine the public key to be used for decrypting the signature information SI1 by using the user ID "U1" received from the terminal device 100.
[0048] When the MFP 10 receives an execution instruction from the server 300 at T160, it erases the QR code displayed on the display unit 14 at T162. In a modified example, the MFP 10 may erase the QR code from the display unit 14 when a predetermined time has elapsed after the QR code is displayed on the display unit 14. Next, the MFP 10 identifies the job ID "job1" associated with the input user ID "U1" (see T110) in the user table 38, identifies the print data associated with the identified job ID "job1", and executes printing according to the identified print data at T164. When the process of T164 ends, the printing process ends. In this way, the user of the terminal device 100 can use FIDO authentication to cause the MFP 10 to execute the printing function.
[0049] (Effects of this embodiment) According to the above configuration, when the MFP 10 receives a printing instruction from the user (T112 in FIG. 4), it displays a QR code including the URL 52a of the server 300 on the display unit 14 (T116). When the terminal device 100 acquires the QR code (T120), in response to accessing the server 300 using the URL 52a (T124), it receives the verification code VC2 from the server 300 (T146). When the fingerprint authentication of the user by the terminal device 100 is successful, the terminal device 100 generates signature information SI1 by encrypting the verification code VC2 using the secret key SK1, and transmits the generated signature information SI1 to the server 300 (T154). When the server 300 receives the signature information SI1 from the terminal device 100 (T154), it decrypts the signature information SI1 using the public key PK1 (T156). When the server 300 can obtain the verification code VC2 by decrypting the signature information SI1, it transmits an execution instruction to the MFP 10 (T160). When the MFP 10 receives the execution instruction from the server 300 after displaying the QR code on the display unit 14 (T160), it executes the printing function (T164). Therefore, according to the FIDO authentication method using a pair of keys, the MFP 10 can be made to execute the printing function.
[0050] Also, in the registration process of FIG. 3, the MFP 10 transmits a URL 50 including the user ID "U1" to the terminal device 100 via the communication I / F 20 (T24, T26). Then, the server 300 receives a registration screen data request including the user ID "U1" from the terminal device 100 (T28), and registers the user ID "U1" and the public key PK1 in the authentication table 338 of the memory 334 in association with each other (T58). For this reason, in the printing process of FIG. 4, when the server 300 receives an authentication response including the signature information SI1 from the terminal device 100 (T154), it can decrypt the signature information SI1 using the appropriate public key PK1 associated with the user ID "U1" in the authentication table 338 (T156).
[0051] Also, when the QR code output from the MFP 10 is acquired by the terminal device 100 (T120 in FIG. 4), and the terminal device 100 that has acquired the QR code accesses the server 300 using the URL 52a (T124), the server 300 transmits the verification code VC2 to the terminal device 100 (T146). When the fingerprint authentication of the user is successful on the terminal device 100 (T150), the terminal device 100 generates the signature information SI1 by encrypting the verification code VC2 using the secret key SK1 (T152), and transmits the signature information SI1 to the server 300. When the server 300 receives the signature information SI1 from the terminal device 100 (T154), the server 300 decrypts the signature information SI1 using the public key PK1 (T156). When the server 300 can obtain the verification code VC2 by decrypting the signature information SI1, the server 300 transmits an execution instruction to the MFP 10 (T160). When the MFP 10 receives the execution instruction from the server 300, the MFP 10 executes the printing function (T164). Therefore, according to the FIDO authentication method using a pair of keys, the MFP 10 can be made to execute the printing function.
[0052] (Corresponding relationship) The MFP 10 is an example of the "function execution device". The user of the terminal device 100 is an example of the "target user". The printing function and the print instruction are examples of the "specific function" and the "specific instruction", respectively. The FIDO authentication method is an example of the "predetermined authentication method". The URL 52a is an example of the "server location information". The QR code of T116 in FIG. 4 is an example of the "first output information" and the "code image". The display unit 14 is an example of the "first output unit". The verification code VC2 is an example of the "first verification information". The fingerprint authentication that succeeds at T150 in FIG. 4 is an example of the "first authentication". The device ID "dv1" is an example of the "device identification information". The user ID "U1" is an example of the "user identification information". The redirect instruction including the URL 50 of T26 in FIG. 3 is an example of the "second output information". The communication I / F 20 is an example of the "second output unit". The verification code VC1 is an example of the "second verification information". The fingerprint authentication that succeeds at T50 in FIG. 3 is an example of the "second authentication". The second registration completion screen data of T70 in FIG. 3 is an example of the "registration completion notification".
[0053] Examples of the processes executed by the "first output control unit" and the "function execution unit" are the T116 and T164 in FIG. 4, respectively.
[0054] Examples of the processes executed by the "verification information transmission unit", the "signature information reception unit", the "decryption unit", and the "execution instruction transmission unit" are the T146, T154, T156, and T160 in FIG. 4, respectively.
[0055] (Second Embodiment) Subsequently, with reference to FIG. 5, the second embodiment will be described. In the second embodiment, the process executed by the MFP 10 in response to receiving a print instruction is different from the process executed by the MFP 10 in the first embodiment. The initial state of FIG. 5 is the same as the initial state of FIG. 4.
[0056] T210 and T212 in FIG. 5 are the same as T110 and T112 in FIG. 4, respectively. In T214, the MFP 10 transmits a token generation request including the input user ID "U1" and the device ID "dv1" to the server 300.
[0057] In T214, when the server 300 receives the token generation request from the MFP 10, in T220, it generates a unique token "tk1", and in T222, in the authentication table 338, it temporarily stores the device ID "dv1" and the token "tk1" in association with the user ID "U1" included in the token generation request. Next, in T224, the server 300 transmits the token "tk1" to the MFP 10.
[0058] When the MFP10 receives the token "tk1" from the server 300 at T224, at T226, it generates a URL54 in which a query string 54b is added to the URL54a. The URL54a is the same as the URL50a (see FIG. 3). The query string 54b includes the token "tk1" (i.e., "token=tk1"). Next, the MFP10 encodes the URL54 to generate a QR code, and at T228, it displays the generated QR code on the display unit 14.
[0059] T230 to T234 are the same as T120 to T124 in FIG. 4 except that the URL54 is used. When the server 300 receives an authentication screen data request from the terminal device 100 at T234, it extracts the character string described before the mark "?" in the URL54 as the URL54a, and extracts the character string described after the mark "?" as the query string 54b. The server 300 further extracts the token "tk1" from the query string 54b. The server 300 determines that a token "tk1" that matches the extracted token "tk1" is stored in the authentication table 338. Then, the server 300 identifies the user ID "U1", the public key PK1, and the device ID "dv1" associated with the token "tk1" in the authentication table 338 as the target information to be used in subsequent processing. Next, the server 300 deletes the token "tk1" from the authentication table 338 and transmits authentication screen data to the terminal device 100 at T236. T238 and T240 are the same as T130 and T140, respectively. The server 300 generates a verification code VC3, which is a unique character string, at T242, and stores the verification code VC3 in association with the user ID "U1", the public key PK1, and the device ID "dv1" in the authentication table 338 at T244. Next, the server 300 transmits an authentication request including the verification code VC3 to the terminal device 100 at T246.
[0060] T248 and T250 are the same as T148 and T150 in FIG. 4 respectively. At T252, the terminal device 100 generates signature information SI2 by encrypting the received verification code VC3 using the secret key SK1 stored in the memory 134. Next, at T254, the terminal device 100 transmits an authentication response including the generated signature information SI2 to the server 300.
[0061] When the server 300 receives the authentication response from the terminal device 100 at T254, at T256, it decrypts the signature information SI2 in the authentication response using the public key PK1 specified as the target information. In this embodiment, the verification code VC3 is obtained by decrypting the signature information SI2 using the public key PK1. The server 300 determines that the decrypted signature information SI2 (i.e., the verification code VC3) matches the verification code VC3 stored in the authentication table 338 (see T244), and determines that the user authentication of the user ID "U1" specified as the target information has succeeded. In this case, at T260, the server 300 transmits an execution instruction to the MFP10 identified by the device ID "dv1" specified as the target information. Also, after transmitting the execution instruction to the MFP10, the server 300 deletes the device ID "dv1" associated with the user ID "U1" and the verification code VC3 in the authentication table 338. T262 and T264 are the same as T162 and T164 respectively.
[0062] As described above, when the MFP 10 receives a print instruction from the user (T212 in FIG. 5), it transmits a token generation request including the device ID "dv1" to the server 300 (T214). When the server 300 receives the token generation request from the MFP 10 (T214), it generates a token "tk1" (T220), associates and stores the device ID "dv1" and the token "tk1" (T222), and transmits the token "tk1" to the MFP 10 (T224). The QR code generated by the MFP 10 is information including the URL 54 and the token "tk1" (T226). Then, the server 300 receives an authentication screen data request including the URL 54 and the token "tk1" from the terminal device 100 (T234). The server 300 can identify the device ID "dv1" stored in association with the token "tk1" by using the token "tk1" received from the terminal device 100. Therefore, even in an environment where there are multiple MFPs, the server 300 can appropriately determine the MFP to which the execution instruction should be transmitted by using the token "tk1" received from the terminal device 100.
[0063] Also, as described above, when the MFP 10 receives a print instruction from the user (T212 in FIG. 5), it transmits a token generation request including the user ID "U1" to the server 300 (T214). When the server 300 receives the token generation request from the MFP 10 (T214), it generates a token "tk1" (T220), associates and stores the user ID "U1" and the token "tk1" (T222), and transmits the token "tk1" to the MFP 10 (T224). The QR code generated by the MFP 10 is information including the URL 54 and the token "tk1" (T226). Then, the server 300 receives an authentication screen data request including the URL 54 and the token "tk1" from the terminal device 100 (T234). The server 300 can identify the user ID "U1" stored in association with the token "tk1" by using the token "tk1" received from the terminal device 100, and can identify the public key PK1 stored in association with the user ID "U1". In this way, the server 300 can appropriately determine the public key used for decrypting the signature information SI2 by using the token "tk1" received from the terminal device 100.
[0064] As described above, specific examples of the present invention have been described in detail, but these are merely examples and do not limit the scope of the claims. The technology described in the claims includes various modifications and changes of the specific examples exemplified above. Modifications of the above embodiments are listed below.
[0065] (First Modification Example) The "first output unit" is not limited to the display unit 14, and may be the print execution unit 16 or the communication I / F 20. When the print execution unit 16 is an example of the "first output unit", a code image (QR code, barcode, etc.) may be printed by the print execution unit 16, or a character string representing the URL 52 (see FIG. 4) may be printed. Also, when the communication I / F 20 is an example of the "first output unit", the URL 52 may be transmitted to the terminal device 100. In this modification example, the communication I / F 20 is an NFC I / F, a Wi-Fi I / F, or a Bluetooth (registered trademark) I / F.
[0066] (Second Modification Example) In the memory 134 of the terminal device 100, a password may be stored. In this modification example, the terminal device 100 displays, on the display unit 114, a screen for requesting input of a password at T148 in FIG. 4.
[0067] (Third Modification Example) When the MFP 10 acquires an instruction for causing the MFP 10 to execute a scanning function in response to a user operating the operation unit 12, or when the MFP 10 receives an instruction for logging in to the web server in the MFP 10 from the terminal device 100 in response to a user operating the terminal device 100, the MFP 10 may be configured to execute the processes after T114 in FIG. 4 and the processes after T214 in FIG. 5.
[0068] (Fourth Modification Example) The URL 52 at T114 in FIG. 4 may not include at least one of the user ID "U1" and the device ID "dv1". In this case, when the URL 52 is acquired, the terminal device 100 may display, on the display unit 114, a screen for requesting input of the user ID and / or the device ID. Further, in another modification example, the user ID "U1" and / or the device ID "dv1" is / are stored in advance in the memory 134 of the terminal device 100, and when a URL 52 that does not include at least one of the user ID "U1" and the device ID "dv1" is acquired, the terminal device 100 may transmit to the server 300 the information that is not included in the URL 52 among the user ID "U1" and the device ID "dv1".
[0069] (Fifth Modification Example) The token generation request at T214 in FIG. 5 may not include at least one of the user ID "U1" and the device ID "dv1". In this modification example, the user ID "U1" and / or the device ID "dv1" is / are stored in advance in the memory 334 of the server 300, and when the token generation request is received, the server 300 generates a token "tk1" and stores the token "tk1" in association with the user ID "U1" and / or the device ID "dv1" stored in the memory 334.
[0070] (Sixth Modification Example) The URL 50 of T24 in FIG. 3 may not include at least one of the user ID "U1" and the device ID "dv1". In this case, when the URL 50 is acquired, the terminal device 100 may display, on the display unit 114, a screen for requesting the input of the user ID and / or the device ID. Further, in another modification example, the user ID "U1" and / or the device ID "dv1" are stored in advance in the memory 134 of the terminal device 100, and when the URL 50 is acquired, the terminal device 100 may transmit to the server 300 the information that is not included in the URL 50 out of the user ID "U1" and the device ID "dv1".
[0071] (Seventh Modification Example) The signal transmitted by the MFP 10 in T26 of FIG. 3 may not be a redirection instruction. In this modification example, when the terminal device 100 receives the URL 50 from the MFP 10, the terminal device 100 may display, on the display unit 114, a screen for allowing the user to select whether to permit access to the server 300, or may display, on the display unit 114, a character string representing the URL 50.
[0072] (Eighth Modification Example) The "function execution device" is not limited to the MFP 10, and may be, for example, a terminal device such as a printer, a scanner, a PC, or the like.
[0073] (Ninth Modification Example) In the above embodiments, the processes in FIGS. 3 to 5 are realized by software (for example, programs 36 and 336), but at least one of these processes may be realized by hardware such as a logic circuit.
[0074] Further, the technical elements described in this specification or the drawings exhibit technical utility alone or in various combinations, and are not limited to the combinations described in the claims at the time of filing. Also, the technology illustrated in this specification or the drawings achieves a plurality of purposes simultaneously, and achieving one of these purposes itself has technical utility. The following is the description corresponding to the claims at the time of filing. (Item 1) A function execution device, a first output unit, a first output control unit that causes the first output unit to output first output information including position information of a server operable according to a predetermined authentication method using a pair of keys when a specific instruction for causing the function execution device to execute a specific function is received from a target user, the first output information is acquired by a terminal device operable according to the predetermined authentication method, the terminal device, when the first output information is acquired, in response to accessing the server using the position information included in the first output information, receives first verification information from the server, when the first authentication of the target user executed by the terminal device is successful, generates signature information by encrypting the first verification information using a secret key of the pair of keys, transmits the signature information to the server, the server, when the signature information is received from the terminal device, decrypts the signature information using a public key of the pair of keys, when the first verification information is obtained by decrypting the signature information, transmits an execution instruction of the specific function to the function execution device, the first output control unit, a function execution unit that executes the specific function when an execution instruction is received from the server after the first output information is output, A function execution device comprising: (Item 2) The function execution device is a device capable of executing at least one of a printing function and a scanning function, The specific function is the at least one function, and the function execution device according to Item 1. (Item 3) The predetermined authentication method is a FIDO (abbreviation for Fast Identity Online) authentication method, and the function execution device according to Item 1 or 2. (Item 4) The first output unit is a display unit, The first output information is a code image obtained by encoding the position information, and the function execution device according to any one of Items 1 to 3. (Item 5) The first output information is information including the position information and device identification information for identifying the function execution device. When the first output information is acquired, the terminal device accesses the server by transmitting the position information and the device identification information included in the first output information to the server. The server, when the first verification information is obtained by decrypting the signature information, transmits the execution instruction to the function execution device identified by the device identification information received from the terminal device, the function execution device according to any one of items 1 to 4. (Item 6) The server stores in association, for each of one or more users, user identification information for identifying the user and a key for the user. The first output information is information including the position information and target user identification information for identifying the target user. When the first output information is acquired, the terminal device accesses the server by transmitting the position information and the target user identification information included in the first output information to the server. The server, when the signature information is received from the terminal device, decrypts the signature information using the public key which is the key stored in association with the target user identification information received from the terminal device, the function execution device according to any one of items 1 to 5. (Item 7) The function execution device further includes a request transmission unit that, when the specific instruction is received from the target user, transmits a token generation request including device identification information for identifying the function execution device to the server. The server generates a token when the token generation request is received from the function execution device. stores in association the device identification information included in the token generation request and the generated token. transmits the token to the function execution device. The first output information is information including the position information and the token received from the server. When the first output information is acquired, the terminal device accesses the server by transmitting the position information and the token included in the first output information to the server. When the first verification information can be obtained by decrypting the signature information, the server transmits the execution instruction to the function execution device identified by the device identification information stored in association with the token received from the terminal device, according to any one of items 1 to 6. (Item 8) The server stores, in association with each other, user identification information for identifying each user and a key for the user. The function execution device further when the specific instruction is received from the target user, includes a request transmission unit that transmits a token generation request including target user identification information for identifying the target user to the server. The server when the token generation request is received from the function execution device, generates a token. stores, in association with each other, the target user identification information included in the token generation request and the generated token. transmits the token to the function execution device. The first output information is information including the position information and the token received from the server. When the first output information is acquired, the terminal device accesses the server by transmitting the position information and the token included in the first output information to the server. The server when the signature information is received from the terminal device, specifies the target user identification information stored in association with the token received from the terminal device, and decrypts the signature information using the public key that is the key stored in association with the target user identification information, according to any one of items 1 to 7. (Item 9) The function execution device further includes a second output unit and a second output control unit that causes the second output unit to output second output information including the position information when a registration instruction is received from the target user. The second output information is acquired by the terminal device. The terminal device when the second output information is acquired, accesses the server using the position information included in the second output information, and receives second verification information from the server. when the second authentication of the target user executed by the terminal device is successful, generates the pair of keys. Transmit the public key of the generated pair of keys and the second verification information received from the server to the server. When the server receives the public key and the second verification information from the terminal device, the server registers the public key. The functional execution device according to any one of Items 1 to 8, comprising the second output control unit. (Item 10) The second output information is information including the position information and device identification information for identifying the functional execution device. When the second output information is acquired, the terminal device accesses the server by transmitting the position information and the device identification information included in the second output information to the server. When the public key is registered, the server according to Item 9 transmits a registration completion notice to the functional execution device identified by the device identification information received from the terminal device. (Item 11) The second output information is information including the position information and target user identification information for identifying the target user. When the second output information is acquired, the terminal device accesses the server by transmitting the position information and the target user identification information included in the second output information to the server. When the server receives the public key and the second verification information from the terminal device, the server according to Item 9 or 10 associates and registers the target user identification information received from the terminal device and the public key. (Item 12) The second output unit is a communication interface. When the registration instruction is received by accessing, via the communication interface, a web server in the functional execution device from the terminal device, the second output control unit transmits, via the communication interface, the second output information, which is a redirect instruction including the position information, to the terminal device. The functional execution device according to any one of Items 9 to 11. (Item 13) A server operable according to a predetermined authentication method using a pair of keys, A verification information transmission unit that transmits first verification information to the terminal device when first output information output from a functional execution device is acquired by the terminal device and the terminal device accesses the server using the position information of the server included in the first output information. The functional execution device is When receiving a specific instruction from a target user to cause the function execution device to execute a specific function, output the first output information. The terminal device After receiving the first verification information from the server, when the first authentication of the target user executed by the terminal device is successful, generate signature information by encrypting the first verification information using the secret key of the pair of keys. Transmit the signature information to the server. The verification information transmission unit A signature information reception unit that receives the signature information from the terminal device When the signature information is received from the terminal device, a decryption unit that decrypts the signature information using the public key of the pair of keys An execution instruction transmission unit that transmits an execution instruction for the specific function to the function execution device when the first verification information is obtained by decrypting the signature information. When the function execution device receives the execution instruction from the server, the function execution device executes the specific function. The execution instruction transmission unit A server comprising the same. (Item 14) A communication system comprising a function execution device and a server operable according to a predetermined authentication method using a pair of keys. The function execution device A first output unit A first output control unit that causes the first output unit to output first output information including the position information of the server when a specific instruction for causing the function execution device to execute a specific function is received from a target user. The first output information is obtained by a terminal device operable according to the predetermined authentication method. The first output control unit The server A verification information transmission unit that transmits first verification information to the terminal device when the terminal device accesses the server using the position information included in the first output information. The terminal device After receiving the first verification information from the server, when the first authentication of the target user executed by the terminal device is successful, generate signature information by encrypting the first verification information using the secret key of the pair of keys. Transmit the signature information to the server. The verification information transmission unit A signature information reception unit that receives the signature information from the terminal device When the signature information is received from the terminal device, a decryption unit that decrypts the signature information using the public key of the pair of keys When the first verification information is obtained by decrypting the signature information, an execution instruction transmission unit that transmits an execution instruction for the specific function to the function execution device; The function execution device further includes: After the first output information is output, when the execution instruction is received from the server, a function execution unit that executes the specific function. Communication system.
Explanation of Symbols
[0075] 2: Communication system, 4: LAN, 6: Internet, 10: MFP, 12: Operation unit, 14: Display unit, 16: Printing execution unit, 18: Scanning execution unit, 20: Communication I / F, 30: Control unit, 32: CPU, 34: Memory, 36: Program, 38: User table, 50: URL, 50a: URL, 50b: Query string, 52: URL, 52a: URL, 52b: Query string, 54: URL, 54a: URL, 54b: Query string, 100: Terminal device, 112: Operation unit, 114: Display unit, 120: Communication I / F, 122: Camera, 130: Control unit, 132: CPU, 134: Memory, 138: Fingerprint information, 200: PC, 300: Server, 316: Communication I / F, 330: Control unit, 332: CPU, 334: Memory, 336: Program, 338: Authentication table
Claims
1. A communication system comprising a function execution device, a server operable according to a predetermined authentication method using a pair of keys, and a terminal device operable according to the predetermined authentication method, wherein the server includes a memory for storing, in association with each of one or more users, user identification information for identifying the user and a key for the user, the function execution device includes a first output unit, and a first output control unit that causes the first output unit to output first output information including position information of the server and target user identification information for identifying the target user when a specific instruction for causing the function execution device to execute a specific function is received from the target user, the terminal device includes a first output information acquisition unit that acquires the first output information, and a first access unit that accesses the server by transmitting the position information and the target user identification information included in the first output information to the server when the first output information is acquired, the server includes a first verification information transmission unit that transmits first verification information to the terminal device when the terminal device accesses the server using the position information and the target user identification information included in the first output information, the terminal device further includes a first verification information reception unit that receives the first verification information from the server in response to accessing the server, a signature information generation unit that generates signature information by encrypting the first verification information using a secret key of the pair of keys when the first authentication of the target user executed by the terminal device is successful after the first verification information is received from the server, and a signature information transmission unit that transmits the signature information to the server when the signature information is generated, the server further includes a signature information reception unit that receives the signature information from the terminal device, a decryption unit that decrypts the signature information using a public key of the pair of keys, which is a key stored in association with the target user identification information received from the terminal device, when the signature information is received from the terminal device, and an execution instruction transmission unit that transmits an execution instruction for the specific function to the function execution device when the first verification information is obtained by decrypting the signature information, the function execution device further includes A function execution unit that executes the specific function when the execution instruction is received from the server after the first output information is output. Communication system.
2. The function execution device is a device capable of executing at least one of a printing function and a scanning function. The communication system according to claim 1, wherein the specific function is at least one of the functions.
3. The communication system according to claim 1 or 2, wherein the predetermined authentication method is a FIDO (abbreviation for Fast Identity Online) authentication method.
4. The first output unit is a display unit. The communication system according to any one of claims 1 to 3, wherein the first output information is a code image obtained by encoding the position information and the target user identification information.
5. The first output information is information including the position information, the target user identification information, and device identification information for identifying the function execution device. When the first output information is acquired, the first access unit of the terminal device accesses the server by transmitting the position information, the target user identification information, and the device identification information included in the first output information to the server. The execution instruction transmission unit of the server transmits the execution instruction to the function execution device identified by the device identification information received from the terminal device when the first verification information is obtained by decrypting the signature information. The communication system according to any one of claims 1 to 4.
6. The function execution device further includes: A request transmission unit that transmits a token generation request including device identification information for identifying the function execution device to the server when the specific instruction is received from the target user. The server further includes: A request reception unit that receives the token generation request from the function execution device. A token generation unit that generates a token when the token generation request is received from the function execution device. A first storage control unit that stores the device identification information included in the token generation request and the generated token in association with each other in the memory. A token transmission unit that transmits the token to the function execution device. The first output information is information including the position information, the target user identification information, and the token received from the server. When the first access unit of the terminal device acquires the first output information, it accesses the server by transmitting the position information, the target user identification information, and the token included in the first output information to the server. The execution instruction transmission unit of the server transmits the execution instruction to the function execution device identified by the device identification information stored in association with the token received from the terminal device when the first verification information is obtained by decrypting the signature information. The communication system according to any one of claims 1 to 5. **Claim 7** When the specific instruction is received from the target user, the function execution device includes a request transmission unit that transmits a token generation request including the target user identification information to the server. The server further includes: A request reception unit that receives the token generation request from the function execution device; A token generation unit that generates a token when the token generation request is received from the function execution device; A second storage control unit that stores the target user identification information included in the token generation request and the generated token in the memory in association with each other; A token transmission unit that transmits the token to the function execution device. The first output information is information including the position information, the target user identification information, and the token received from the server. When the first output information is acquired, the access unit of the terminal device accesses the server by transmitting the position information, the target user identification information, and the token included in the first output information to the server. The decryption unit of the server: When the signature information is received from the terminal device, the target user identification information stored in association with the token received from the terminal device is specified, and the signature information is decrypted using the public key that is the key stored in association with the target user identification information. The communication system according to any one of claims 1 to 6. **Claim 8** The function execution device further includes: A second output unit; A second output control unit that causes the second output unit to output second output information including the position information when a registration instruction is received from the target user. The terminal device further includes: A second acquisition unit that acquires the second output information output from the function execution device; A second access unit that accesses the server using the position information included in the second output information when the second output information is acquired; The server further includes: A second verification information transmission unit that transmits second verification information to the terminal device when the terminal device accesses the server using the position information included in the second output information; The terminal device further includes: A second verification information reception unit that receives the second verification information from the server in response to accessing the server; A key generation unit that generates the pair of keys when the second authentication of the target user executed by the terminal device is successful after the second verification information is received from the server; A public key transmission unit that transmits the public key of the generated pair of keys and the second verification information received from the server to the server; The server further includes: A public key reception unit that receives the public key and the second verification information from the terminal device; A third storage control unit that stores the public key in the memory when the public key and the second verification information are received from the terminal device. The communication system according to any one of claims 1 to 7.
9. The second output information is information including the position information and device identification information for identifying the function execution device; When the second output information is acquired, the second access unit of the terminal device accesses the server by transmitting the position information and the device identification information included in the second output information to the server; The server further includes: A completion notification transmission unit that transmits a registration completion notification to the function execution device identified by the device identification information received from the terminal device when the public key is stored in the memory. The communication system according to claim 8.
10. The second output information is information including the position information and the target user identification information; When the second output information is acquired, the second access unit of the terminal device accesses the server by transmitting the position information and the target user identification information included in the second output information to the server; When the third storage control unit of the server receives the public key and the second verification information from the terminal device, it stores the target user identification information received from the terminal device and the public key in association with each other in the memory. The communication system according to claim 8 or 9.
11. The second output unit is a communication interface, The terminal device further includes a third access unit that accesses a web server in the function execution device. When the registration instruction is received in response to the terminal device accessing the web server in the function execution device via the communication interface, the second output control unit transmits, via the communication interface, the second output information, which is a redirect instruction including the position information, to the terminal device. The communication system according to any one of claims 8 to 10.
Citation Information
Patent Citations
Image management system and image management device
JP2015035208A
Image processing apparatus, method, program, and system
JP2018198400A
Image processing device, image processing device control method, program, system and system control method
JP2019086937A