Information processing apparatus, display method, program
The information processing apparatus addresses the issue of incomplete authentication screens by adjusting web browser settings based on external server authentication types, ensuring successful user operation and authentication through communication with an information processing system.
Patent Information
- Application Number
- JP2021135083
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-08-20
- Publication Date
- 2025-07-23
- Estimated Expiration
- 2041-08-20
AI Technical Summary
Conventional technologies face issues where devices cannot display specific screens for user operation due to default settings of local storage being turned off in web browsers, leading to incomplete authentication processes, particularly in multi-factor authentication scenarios.
An information processing apparatus that communicates with an information processing system to determine the type of external server used for authentication and adjusts the web browser settings accordingly, enabling the display of authentication screens by changing the local storage setting to 'ON' when necessary.
Enables the display of user operation screens, supports multiple authentication methods, and ensures successful user authentication by adjusting web browser settings based on the authentication method, thereby overcoming the limitations of default settings.
Smart Images

Figure 0007711483000001 
Figure 0007711483000002 
Figure 0007711483000003
Abstract
Description
Technical Field
[0001] The present invention relates to an information processing apparatus, a display method, and a program.
Background Art
[0002] When an authentication function of a device such as an image forming apparatus is inside the device, when modifying the authentication function such as customization or upgrade, an administrator needs to update each device individually. For this reason, there is a case where a method is used in which a device communicates with an information processing system on a network and the information processing system returns an authentication result to the device.
[0003] In addition, a technique for switching the display content of a login screen displayed by a device has been devised (see, for example, Patent Document 1). Patent Document 1 discloses a technique in which, when drawing a login screen, a device acquires a setting value of a login method set by an administrator from the cloud side, and switches the display content of the login screen according to the acquired setting value.
Summary of the Invention
Problems to be Solved by the Invention
[0004] However, the conventional technology has a problem that a screen for receiving an operation from a user may not be displayed. For example, depending on the OS installed in the device, the setting of local storage (a function of saving data in a web browser) is default OFF. However, when the device displays a specific screen, it may not be displayed unless the setting of local storage is ON. When the device cannot display a specific screen, the user cannot continue the operation.
[0005] An object of the present invention is to provide an information processing apparatus capable of displaying a screen for receiving an operation from a user in view of the above problems.
Means for Solving the Problems
[0006] In view of the above problems, the present invention is an information processing apparatus capable of communicating with an information processing system via a network, and from the information processing system Information including the type of external server used for authentication a communication unit that receives Based on the type of external server used for authentication, determine whether to change the settings of the web browser. If it is determined to make a change , a setting change unit that changes the settings of a web browser, and the The type of external server used for authentication received by the communication unit, an external server Received from , an operation reception Authentication screen The settings have been changed a display control unit that displays using the web browser, characterized by comprising.
Advantages of the Invention
[0007] An information processing apparatus capable of displaying a screen for receiving an operation from a user can be provided.
Brief Description of the Drawings
[0008]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Figure 11
Figure 12
Figure 13
Figure 14
Figure 15
Figure 16
Figure 17
Embodiments for Carrying Out the Invention
[0009] Hereinafter, as an example of an embodiment for carrying out the present invention, a device and a display method performed by the device will be described with reference to the drawings.
[0010] <Inconvenience of the login screen caused by the local storage setting> The device may be equipped with an OS called Android (registered trademark). Android has a module called WebView. WebView is a module used when creating an Android app and is for displaying web content within the app. WebView is incorporated into, for example, the functions of a web browser.
[0011] The WebView has the local storage setting turned off by default. When the local storage setting is on, the web browser can save data, and when it is off, it cannot. However, for certain screens provided by an external server for authentication, the WebView may not be able to display them if the external server does not enable the use of local storage. In this case, the device may display a blank screen or an error message, resulting in the inability to display a specific screen. This inconvenience will be explained in detail with reference to Figure 1.
[0012] Figure 1 is a diagram for explaining the inconvenience of the login screen caused by the local storage setting. Depending on the external server, it is possible to set up MFA authentication (Multi-Factor Authentication) for enhanced security. MFA authentication is an authentication method that requires additional information verification (user-owned items that are not easily replicable, such as a smartphone, or the user's unique biometric features, such as fingerprints) in addition to the email address and password when the user logs in.
[0013] Figure 1 shows the flow of MFA authentication through screen transitions. It should be noted that the screens in Figure 1 are displayed on a general-purpose information processing device owned by the user. Also, Figure 1 shows the screen transitions when the MFA authentication setting is valid and the user logs in to the external server with the MFA information of the logged-in user not registered. Therefore, the user registers the MFA information during the login process.
[0014] First, Figures 1(a) to (c) are normal login screens that are displayed regardless of MFA authentication. Figure 1(a) has a user ID field 201. Figure 1(a) transitions to Figure 1(b) when the Next button 202 is pressed.
[0015] Figure 1(b) has a password field 203. Figure 1(b) transitions to Figure 1(c) when the Next button 204 is pressed.
[0016] Figure 1(c) is displayed when MFA authentication is valid, and indicates that MFA authentication starts with the message 205 "Please cooperate in protecting your account." Figure 1(c) transitions to Figure 1(d) when the Next button 206 is pressed.
[0017] Figure 1(d) has the message 207 "First, obtain the app" and prompts the user to download the app for MFA authentication. Figure 1(d) transitions to Figure 1(e) when the Next button 208 is pressed.
[0018] Figure 1(e) has the message 209 "Account setup" and explains how to set up MFA authentication. Figure 1(e) transitions to Figure 1(f) when the Next button 210 is pressed.
[0019] Figure 1(f) has the message 211 "Scan the QR code (registered trademark)" and the QR code 212, and explains that the user's account is linked to the app. Figure 1(f) transitions to Figure 1(g) when the Next button 213 is pressed.
[0020] Figure 1(g) has the messages 214 "Let's try" and "Approve the notifications sent to the app" and explains that it prompts the user to approve the operation of notifications to the app. Figure 1(g) transitions to Figure 1(h) by an approval operation for the app installed in the information processing device.
[0021] Figure 1(h) has the message 215 "The notification has been approved" and explains that it can be confirmed that the user has approved the notification. Figure 1(h) transitions to Figure 1(i) when the Next button 216 is pressed.
[0022] Figure 1(i) has the message 217 "Success" and explains that the MFA information has been registered. Logging in is completed when the Finish button 218 is pressed.
[0023] However, for the screens in FIGS. 1(d) to 1(i), the local storage of the web browser (WebView in this embodiment) that displays them must be ON. This is a specification of the external server. On the other hand, since the local storage of WebView is OFF by default, even if the authentication application operating on the device attempts to display the screens in FIGS. 1(d) to 1(i) using WebView, it cannot be displayed.
[0024] <Outline of the operation> Therefore, the device utilization system of this embodiment operates as follows. (i) A device such as an image forming apparatus acquires the authentication method (an example of information related to the setting) set by the tenant administrator in the information processing system. (ii) When the authentication method is authentication using an external server, the device sets the local storage setting to ON.
[0025] By doing so, the device can display specific screens (FIGS. 1(d) to (i)) for authentication. Also, the number of authentication methods supported by the device increases, and it becomes possible to authenticate using the authentication method that the user wants to use.
[0026] <Regarding terms> Authentication refers to determining whether a user is a legitimate authorized person. In the case of this embodiment, it is whether the user has the right to use the device. Note that when authentication is successful, the user logs in to the device. Logging in refers to the authentication act of accessing the resources of the system using the account information registered in advance when using various services on a computer or the Internet. The account information includes a user ID, password, IC card number, biometric authentication information, etc. Logging in is sometimes referred to as signing in.
[0027] The login screen is a screen for the user to input this account information. The login screen may also be referred to as a sign-in screen or an authentication screen.
[0028] The settings of a web browser refer to the settings of the functions by which the web browser stores data. In this embodiment, local storage is taken as an example of the function by which the web browser stores data. As the function by which the web browser stores data, cookies may also be used.
[0029] The information regarding the settings may be any settings that affect the settings of the web browser. In this embodiment, the authentication method will be described as an example, but it may also be simply whether to use an external server or the web browser settings themselves.
[0030] The authentication method refers to the types of account information used for authentication and the method of processing the accompanying account information. In this embodiment, as an example, "email address - password", "tenant ID - user ID - password", "IC card", and "PIN (Personal Identification Number)" serve as account information.
[0031] The administrator is a system administrator on the customer side who uses the information processing system 10, etc., and is the person who makes settings related to the communication system for general users. The user is a general user on the customer side. Since a general user may perform the work of the administrator, it is not necessary to distinguish between the two.
[0032] <System configuration example> Referring to FIG. 2, the system configuration of the device utilization system 100 according to this embodiment will be described. FIG. 2 is a diagram showing an example of the system configuration of the device utilization system 100 according to this embodiment.
[0033] The device utilization system 100 shown in FIG. 2 includes an information processing system 10 and a device 20, and is communicably connected via a wide - area network N such as the Internet. Also, the information processing system 10 can communicate with various external servers 40 and terminal devices 60.
[0034] The information processing system 10 is implemented by one or more information processing devices, and provides various services to users by operating alone or in cooperation with an external server 40 via the network N. The services provided by the information processing system 10 according to this embodiment cover a wide range. For example, there are workflow services that execute a series of processes such as scanning of manuscripts, OCR of image data, and uploading of files. Also, as an example of a service, there is pull printing in which a device downloads a file from a storage service and prints it. In addition, the information processing system 10 can provide various services using the device 20.
[0035] The information processing system 10 has a function of authenticating users who use the device 20. Users can be authenticated by the information processing system 10 or by the external server 40. The administrator can set in advance which authentication method to use (including the setting of the authentication method).
[0036] The information processing system 10 may be implemented by cloud computing or by a single information processing device. Cloud computing refers to a form in which resources on a network are used without awareness of specific hardware resources. The information processing system 10 may exist on the Internet or on-premises.
[0037] The device 20 is various electronic devices used by users. The device 20 is, for example, an image forming device such as an MFP (Multifunction Peripheral), a projector, an electronic blackboard, a video conferencing terminal, a digital camera, etc. In addition, the device 20 may have a web browser or a function equivalent thereto. The device 20 can communicate with the information processing system 10 or the external server 40 via the network N. Users can use various services provided by the information processing system 10 or the external server 40 using the device 20.
[0038] There may be a plurality of external servers 40 according to their functions. "External" means a server different from the information processing system 10. For example, the external server 40 may have a different service operator from the information processing system 10. When distinguishing each external server 40, it is described as external servers 40A, 40B, etc., and any external server 40 is simply described as "external server 40". The external server 40 is one or more information processing devices.
[0039] Each external server 40 has a function of authenticating users. The external server 40 is, for example, compatible with OAUTH. OAUTH is a mechanism for operating multiple web services in cooperation. Usually, in order for a user to use a web service, it is necessary to individually input a user ID and password. However, by using OAUTH, the web services (information processing system 10 and external server 40) can be interlocked without the user individually inputting an ID or password. When OAUTH is used, the external server 40 authenticates the user of the device 20 in response to an authentication request from the information processing system 10.
[0040] The terminal device 60 is a general-purpose information processing device that communicates with the information processing system 10. A web browser operates on the terminal device 60, and various screens are displayed based on the screen information received from the information processing system 10. The administrator can set, for example, the authentication method from the screen.
[0041] The terminal device 60 is, for example, a PC (Personal Computer), a smartphone, a tablet terminal, a PDA (Personal Digital Assistant), etc., but it is sufficient that a web browser operates. Note that on the terminal device 60, not only a web browser but also a dedicated application for the information processing system 10 may operate.
[0042] <Hardware Configuration Example> With reference to FIGS. 3 and 4, the hardware configurations of the information processing system 10 and the device 20 included in the device utilization system 100 according to the present embodiment will be described.
[0043] <<Information Processing System, Terminal Device>> FIG. 3 is a diagram showing an example of the hardware configuration of the information processing system 10 and the terminal device 60 according to the present embodiment. It is assumed that the hardware configuration of the external server 40 is the same as or different from that in FIG. 3, and it does not interfere with the description of the present embodiment.
[0044] As shown in FIG. 3, the information processing system 10 and the terminal device 60 are constructed by a computer 500. The computer 500 includes a CPU 501, a ROM 502, a RAM 503, an HD (Hard Disk) 504, an HDD (Hard Disk Drive) controller 505, a display 506, an external device connection I / F (Interface) 508, a network I / F 509, a bus line 510, a keyboard 511, a pointing device 512, a DVD-RW (Digital Versatile Disk Rewritable) drive 514, and a media I / F 516.
[0045] Among these, the CPU 501 controls the operation of the entire computer 500. The ROM 502 stores programs used for driving the CPU 501 such as IPL. The RAM 503 is used as a work area for the CPU 501. The HD 504 stores various data such as programs. The HDD controller 505 controls the reading or writing of various data to and from the HD 504 according to the control of the CPU 501. The display 506 displays various information such as a cursor, a menu, a window, characters, or an image. The external device connection I / F 508 is an interface for connecting various external devices. The external devices in this case are, for example, a USB (Universal Serial Bus) memory, a printer, and the like. The network I / F 509 is an interface for performing data communication using the network N. The bus line 510 is an address bus, a data bus, etc. for electrically connecting the components such as the CPU 501 shown in FIG. 3.
[0046] Also, the keyboard 511 is a type of input means having a plurality of keys used for inputting characters, numerical values, or various instructions. The pointing device 512 is a type of input means for selecting and executing various instructions, selecting a processing target, moving a cursor, etc. The optical drive 514 controls reading or writing of various data with respect to the optical storage medium 513 as an example of a removable recording medium. Note that the optical storage medium is a CD, DVD, Blu-Ray (registered trademark), etc. The media I / F 516 controls reading or writing (storage) of data with respect to the recording medium 515 such as a flash memory.
[0047] <<Device>> FIG. 4 is a hardware configuration diagram of an image forming apparatus which is an example of the device 20. As shown in FIG. 4, the image forming apparatus includes a controller 910, a short-range communication circuit 920, an engine control unit 930, an operation panel 940, and a network I / F 950.
[0048] Among these, the controller 910 has a CPU 901 which is the main part of a computer, a system memory (MEM-P) 902, a north bridge (NB) 903, a south bridge (SB) 904, an ASIC (Application Specific Integrated Circuit) 906, a local memory (MEM-C) 907 which is a storage part, an HDD controller 908, and an HD 909 which is a storage part, and is configured to connect between the NB 903 and the ASIC 906 by an AGP (Accelerated Graphics Port) bus 921.
[0049] Among these, the CPU 901 is a control part that performs overall control of the image forming apparatus. The NB 903 is a bridge for connecting the CPU 901 with the MEM-P 902, the SB 904, and the AGP bus 921, and has a memory controller that controls reading and writing with respect to the MEM-P 902, and a PCI (Peripheral Component Interconnect) master and an AGP target.
[0050] MEM-P902 consists of a ROM902a which is a memory for storing programs and data for realizing each function of the controller 910, and a RAM902b which is used as a memory for developing programs and data, and a drawing memory during memory printing. Note that the program stored in the RAM902b may be configured to be recorded and provided on a computer-readable recording medium such as a CD-ROM, CD-R, or DVD in an installable format or an executable format file.
[0051] SB904 is a bridge for connecting the NB903 with PCI devices and peripheral devices. The ASIC906 is an IC (Integrated Circuit) for image processing applications having hardware elements for image processing, and has the role of a bridge for connecting the AGP bus 921, the PCI bus 922, the HDD controller 908, and the MEM-C907 respectively. This ASIC906 includes a PCI target and an AGP master, an arbiter (ARB) forming the core of the ASIC906, a memory controller for controlling the MEM-C907, a plurality of DMACs (Direct Memory Access Controllers) for performing operations such as rotation of image data by hardware logic, etc., and a PCI unit for performing data transfer via the PCI bus 922 between the scanner unit 931, the printer unit 932, and the facsimile unit. Note that the ASIC906 may have a USB (Universal Serial Bus) interface and an IEEE1394 (Institute of Electrical and Electronics Engineers 1394) interface.
[0052] MEM-C907 is local memory used as a copy image buffer and a code buffer. HD909 is storage for accumulating image data, font data used at the time of printing, and forms. HD909 controls the reading or writing of data to HD909 according to the control of CPU901. The AGP bus 921 is a bus interface for a graphics accelerator card proposed to speed up graphic processing. By directly accessing MEM-P902 with high throughput, the graphics accelerator card can be made faster.
[0053] In addition, the short-range communication circuit 920 is provided with an antenna 920a of the short-range communication circuit. The short-range communication circuit 920 is a communication circuit such as NFC or Bluetooth (registered trademark).
[0054] Furthermore, the engine control unit 930 has a scanner unit 931, a printer unit 932, and a facsimile unit 933. Also, the operation panel 940 includes a panel display unit 940a such as a touch panel that displays current setting values, selection screens, etc. and receives inputs from the operator, and a hard key 940b including a numeric keypad that receives setting values of conditions related to image formation such as density setting conditions and a start key that receives a copy start instruction. The controller 910 controls the entire image forming apparatus, for example, controls drawing, communication, inputs from the operation panel 940, etc. The scanner unit 931 or the printer unit 932 includes an image processing part such as error diffusion and gamma conversion.
[0055] Note that the image forming apparatus can sequentially switch and select the document box function, copy function, printer function, and facsimile function by the application switching key of the operation panel 940. When the user selects the document box function, the image forming apparatus enters the document box mode, the copy mode when the copy function is selected, the printer mode when the printer function is selected, and the facsimile mode when the facsimile mode is selected.
[0056] The network I / F 950 is an interface for data communication using the network N. The short-range communication circuit 920 and the network I / F 950 are electrically connected to the ASIC 906 via the PCI bus 922.
[0057] <Regarding the software configuration> FIG. 5 shows a configuration diagram of the software of the device 20. As shown in FIG. 5, the device 20 has an authentication application 71 that operates on the operation panel 940. The authentication application 71 operates on the OS 73. This OS 73 has the above-described WebView 72. The WebView 72 is a module for displaying a web page within the Android app as described above.
[0058] The authentication application 71 communicates with the information processing system 10, and the WebView 72 communicates with the external server 40. When the authentication method acquired by the device 20 from the information processing system 10 is set to "cooperation with external services", the authentication application 71 displays the login screen provided by the external server 40 via the WebView 72. The user can log in to the information processing system 10 through authentication by the external server 40, and after logging in, can use functions such as copy / print provided by the device 20 and the function of uploading files provided by the information processing system 10.
[0059] Note that the authentication application 71 is an app called a native app. A native app is an app that is executed after being installed on the terminal, and an app that runs on a web browser without being installed is called a web app. Therefore, the WebView 72 can implement a web app.
[0060] As the OS 73, for example, an operating system such as Android (registered trademark) is assumed, but it is not limited to this. The OS 73 may be, for example, Windows (registered trademark), iOS (registered trademark), Linux (registered trademark), MAC (registered trademark), Chrome (registered trademark), etc.
[0061] When the authentication method set by the administrator is an authentication method other than "authentication by an external server", the authentication application 71 displays a login screen using display components held in advance.
[0062] Whether it is a login screen displayed by the authentication application 71 without using the WebView or a login screen displayed using the WebView, the user can log in to the device 20.
[0063] <Regarding functions> Next, with reference to FIG. 6, the functional configuration of the device usage system 100 according to the present embodiment will be described. FIG. 6 is a diagram showing an example of the functional configuration of the device usage system 100 according to the present embodiment.
[0064] <<Device>> The device 20 includes a communication unit 21, a second display control unit 22, a setting change unit 23, a setting information storage unit 24, an operation reception unit 25, and a first display control unit 26. Each of these functional units included in the device 20 is a function or means realized by the CPU 901 executing instructions included in one or more programs installed in the device 20. Hereinafter, it will be described assuming that the second display control unit 22 and the setting change unit 23 are realized by the authentication application 71, and the first display control unit 26 is realized by the WebView 72.
[0065] The communication unit 21 transmits and receives various types of information to and from the information processing system 10 or the external server 40. In the present embodiment, the communication unit 21 transmits an authentication request to the information processing system 10. When the authentication method is "authentication by an external server", the communication unit 21 redirects to the external server 40 and performs communication related to authentication.
[0066] The second display control unit 22 uses the display components held in advance to display the login screen on the panel display unit 940a. Also, when the authentication method is "authentication by an external server", the second display control unit 22 synthesizes the web page drawn by the WebView 72 with the display components to display the login screen.
[0067] The setting change unit 23 changes the setting of local storage from OFF to ON according to the authentication method received from the information processing system 10. The default setting of local storage (immediately after the WebView is started) is OFF.
[0068] The operation reception unit 25 receives various operations of the user on various screens displayed on the panel display unit 940a.
[0069] The first display control unit 26 interprets and draws screen information such as the login screen transmitted from the external server 40. The content of the web page drawn by the first display control unit 26 (in this embodiment, mainly information for authentication) is passed to the second display control unit 22, and the second display control unit 22 displays it on the panel display unit 940a. Note that the screen information is a program described in HTML, XML, a script language, CSS (Cascading Style Sheet), etc. The structure of the web page is mainly defined by HTML, the operation of the web page is defined by the script language, and the style of the web page is defined by CSS.
[0070] Also, the device 20 has a setting information storage unit 24 realized by the HD909 or the like. In the setting information storage unit 24, the setting of local storage according to the type of the external server 40 is stored.
[0071] FIG. 7 shows the setting information stored in the setting information storage unit 24. The setting information registers the type of the external server 40 and the setting (ON, OFF) of local storage. Although the appropriate local storage setting for displaying the login screen varies depending on the external server 40, since the device 20 sets the local storage to ON according to the setting information, the device 20 can display the login screen.
[0072] Note that the information processing system 10 may have the setting information in FIG. 7. In this case, the information processing system 10 can send not only the authentication method but also the setting (ON, OFF) of local storage to the device 20. As a result, since each individual device 20 does not need to have the setting information, maintenance becomes easier.
[0073] <<Information Processing System>> Returning to FIG. 6 for explanation. The information processing system 10 includes a communication unit 11, an authentication unit 12, a screen generation unit 13, and a setting reception unit 14. Each of these functional units included in the information processing system 10 is a function or means realized by the CPU 501 executing instructions included in one or more programs installed in the information processing system 10.
[0074] The communication unit 11 transmits and receives various information to and from the device 20 and the external server 40. In the present embodiment, the communication unit 11 receives an authentication request together with account information from the device 20. When the authentication method is "authentication by an external server", the communication unit 11 transmits information for redirecting the device 20 to the external server 40 to the device 20.
[0075] When the authentication method is other than "authentication by an external server", the authentication unit 12 compares the account information ("email address · password", "tenant ID · user ID · password", "IC card", "PIN (Personal Identification Number)") transmitted by the device 20 with the preset account information to authenticate the user.
[0076] The screen generation unit 13 generates screen information for various settings displayed on the terminal device 60. The setting reception unit 14 stores the settings related to the authentication method transmitted from the terminal device 60 in the authentication method storage unit 191.
[0077] Also, the information processing system 10 has an authentication method storage unit 191 realized by the HD 504 or the like. In the authentication method storage unit 191, the authentication method is stored for each tenant.
[0078] FIG. 8(a) shows the authentication method information stored in the authentication method storage unit 191. In the authentication method information, the authentication method is registered in association with the tenant ID. A tenant is an enterprise, organization, etc. that has contracted to receive services from a service provider (in this embodiment, the information processing system 10). Although a user belongs to a tenant as an example, a user may subscribe to the service individually. The tenant ID is identification information of the tenant. Note that the device 20 is registered with the tenant, and when the device 20 transmits the device ID to the information processing system 10, the tenant to which the device 20 belongs is also specified.
[0079] The authentication method indicates by which information the information processing system 10 authenticates the user. Examples of the authentication method include authentication by an external server, email address - password, tenant ID - user ID - password, PIN, user selection, or an IC card.
[0080] When "authentication by an external server" is set, the information processing system 10 redirects the device 20 to the external server 40, and the external server 40 authenticates the user.
[0081] When "email address - password" is set, the information processing system 10 authenticates the user with the email address and password.
[0082] When "tenant ID - user ID - password" is set, the information processing system 10 authenticates the user with the tenant ID - user ID - password.
[0083] When set to the IC card, the information processing system 10 authenticates the user with the card number stored in the IC card.
[0084] When set to the PIN, the information processing system 10 authenticates the user with the PIN.
[0085] When set to user selection, the user can select another user on the device 20. The user logs in with the account information of this other user.
[0086] The authentication method as shown in Fig. 8(a) can be set in advance by the administrator from the authentication method setting screen described later.
[0087] Fig. 8(b) shows the connection destination URL corresponding to the external server 40. The connection destination URL is the URL to which the device 20 connects to receive authentication from the external server 40. When the authentication method is "authentication by external server", in addition to the authentication method, the information processing system 10 sends the connection destination URL to the device 20, so that the device 20 can connect to the external server 40.
[0088] <<External server>> Returning to Fig. 6 for explanation. The external server 40 has a communication unit 41 and an authentication unit 42. Each of these functional units of the external server 40 is a function or means realized by the CPU 501 executing instructions included in one or more programs installed in the external server 40.
[0089] The communication unit 41 transmits and receives various information with the device 20 and the information processing system 10. In the present embodiment, the communication unit 41 receives account information etc. (user ID, password, etc. in the external server 40) from the device 20 and transmits an access token etc.
[0090] The authentication unit 42 authenticates the user based on the OAUTH mechanism. It is assumed that the user's account information (such as user ID and password) in the external server 40 has been set in the external server 40 in advance.
[0091] <<Terminal device>> The terminal device 60 includes a communication unit 61, a display control unit 62, and an operation reception unit 63. These functional units are functions or means realized by the CPU 501 shown in FIG. 3 executing instructions included in one or more programs installed in the computer 500. Note that this program may be a web browser or dedicated software.
[0092] The communication unit 61 transmits and receives various types of information to and from the information processing system 10. In this embodiment, it receives various types of screen information and the like from the information processing system 10 and transmits the information set by the user to the information processing system 10.
[0093] The display control unit 62 interprets the screen information of various screens and displays it on the display 506. The operation reception unit 63 receives various operations of the user on various screens displayed on the display 506.
[0094] <Example of screen> First, with reference to FIG. 9, the authentication method setting screen 230 displayed by the terminal device 60 will be described. FIG. 9 is an example of the authentication method setting screen 230. The administrator can connect the terminal device 60 to the information processing system 10 and log in to set the authentication method for this tenant. Hereinafter, each item included in the authentication method setting screen 230 will be described.
[0095] In the valid method setting column 230A, the authentication method that the administrator wants to enable in the tenant is set. Note that for the email address / password and tenant ID / user ID / password, the administrator cannot disable them, so they are not displayed in the valid method setting column 230A.
[0096] As shown in FIG. 9, the authentication methods that can be enabled include an IC card 231, a PIN 233, authentication by an external service 237, and user selection 240. For each of the IC card 231, the PIN 233, the authentication by an external service 237, and the user selection 240, there are radio buttons 232, 234, 238, and 241 for enabled and disabled states.
[0097] Regarding the PIN 233, there are a digit number setting field 235 and a generation method selection field 236. Regarding the authentication by an external service 237, there is a setting field 239 for the type of the external service. The administrator can select the type of the external server 40 from a pull-down menu.
[0098] In the authentication method field 230B, the authentication methods set to be enabled in the enabled method setting field 230A are displayed in a pull-down menu 242. The authentication method set by the administrator in the authentication method field 230B is stored in the authentication method storage unit 191.
[0099] Next, with reference to FIGS. 10 to 14, the login screens displayed by the device 20 according to the authentication methods will be described.
[0100] FIG. 10 shows a login screen 250 displayed by the device 20 when the authentication method is an email address and password. The login screen 250 in FIG. 10 has an email address field 251 and a password field 252. The user enters an email address in the email address field 251, enters a password in the password field 252, and presses a login button 253.
[0101] FIG. 11 shows a login screen 260 displayed by the device 20 when the authentication method is a tenant ID, user ID, and password. The login screen 260 in FIG. 11 has a tenant ID field 261, a user ID field 262, and a password field 263. The user enters a tenant ID in the tenant ID field 261, enters a user ID in the user ID field 262, enters a password in the password field 263, and presses a login button 264.
[0102] Figure 12 shows the login screen 270 displayed by device 20 when the authentication method is PIN. The login screen 270 in Figure 12 has a PIN field 271. The user enters the PIN in the PIN field 271 and presses the login button 272.
[0103] Figure 13 shows the login screen 280 displayed by device 20 when the authentication method is user selection. The login screen 280 in Figure 13 displays a user list 281. The user selects another user from the user list 281. As a result, one of the screens in Figures 10 to 12 is displayed, and the user can log in with the account information of another user.
[0104] Note that the login screens 250, 260, 270, and 280 in Figures 10 to 13 are displayed by the second display control unit 22 of device 20 according to the authentication method received from the information processing system 10. In other words, the second display control unit 22 switches the login screens 250, 260, 270, and 280 according to the authentication method.
[0105] Figure 14 shows the login screen 290 displayed by device 20 when the authentication method is "authentication by external server". Note that Figure 14 is the same as Figure 1(a). The login screen 290 in Figure 14 has a user ID field 291. The user enters the user ID in the user ID field 291 and presses the next button 292. As a result, the login screen 290 displays a password field (see Figure 1(b)), so the user enters the password in the password field and presses the login button.
[0106] Note that the login screen 290 in Figure 14 is displayed by the first display control unit 26 of device 20 connecting to the external server 40 according to the authentication method, based on the content of the web page received from the external server 40 and the display components held by the second display control unit 22. Details will be described with reference to Figure 15.
[0107] <Configuration of the screen> A login screen 290 as shown in FIG. 14 is generated by combining a device screen generated by an authentication application 71 and a WebView area generated by a WebView 72. FIG. 15 schematically shows the ranges in which the authentication application 71 and the WebView 72 perform drawing respectively. The authentication application 71 (second display control unit 22) draws a device screen 301. The authentication application 71 secures a part of the device screen 301 as a WebView area 302 in which the WebView 72 draws the content of a web page. Although the authentication application 71 may draw something in the WebView area 302, it will be overwritten by the WebView 72.
[0108] The WebView 72 (second display control unit 22) forms a menu area 303 for displaying a menu of a web page or the like in the WebView area 302, or forms a content area 304 for displaying the content of a web page. In FIG. 15, a menu area 303 is prepared, but the menu area 303 can be made non-displayable. The WebView 72 displays a screen 305 based on the screen information received from an external server 40 in the content area 304.
[0109] To the user, the device screen 301 and the WebView area 302 including the screen 305 appear as one login screen, so that the authentication operation can be performed without a sense of discomfort.
[0110] <Operation Procedure> FIG. 16 is a sequence diagram in which the authentication application 71 displays a login screen in this embodiment.
[0111] S1: The administrator connects the terminal device 60 to the information processing system 10 in advance and displays an authentication method setting screen 230.
[0112] S2: The administrator sets the authentication method for the authentication method setting screen 230. The operation reception unit 63 of the terminal device 60 receives the operation, and the communication unit 61 transmits the authentication method to the information processing system 10. The communication unit 11 of the information processing system 10 receives the authentication method, and the setting reception unit 14 stores it in the authentication method storage unit 191.
[0113] S3: Next, the user inputs an operation to start logging in to the device 20. The operation reception unit 25 of the device 20 receives the operation.
[0114] S4: The authentication application 71 transmits an authentication method acquisition request to the information processing system 10 through the communication unit 21. Since the communication unit 21 transmits the device ID stored in the device 20, the information processing system 10 can identify the tenant.
[0115] S5: The communication unit 11 of the information processing system 10 receives the authentication method acquisition request, acquires the authentication method associated with the tenant from the authentication method storage unit 191, and transmits it to the authentication application 71. When the authentication method is "authentication by an external server", the communication unit 11 may also transmit the type of the external server and the connection destination URL to the device 20 and redirect it to the external server 40.
[0116] S6: When the authentication method is "authentication by an external server", steps S6 to S10 are executed. First, the setting change unit 23 refers to the setting information storage unit 24 to determine whether the local storage setting associated with the type of the external server 40 transmitted together with "authentication by an external server" is ON or OFF. When the local storage setting is ON, the setting change unit 23 sets the local storage setting to ON (because the default is OFF). The details of this process are shown in FIG. 17.
[0117] S7: If the setting of the local storage associated with the type of the external server 40 is OFF, the setting change unit 23 does nothing (because the default is OFF). However, for safety, the setting change unit 23 may set the local storage setting to OFF.
[0118] S8: Then, the authentication application 71 requests the WebView 72 to display the login screen (specifically, the drawing of the WebView area 302). The connection destination URL of the external server 40 is passed to the WebView 72.
[0119] S9: The WebView 72 requests the external server 40 for the login screen based on the specified connection destination URL through the communication unit 21. Note that a single sign-on mechanism such as OAUTH may be used for switching the connection from the information processing system 10 to the external server 40. Thus, the connection can also be switched from the external server 40 to the information processing system 10.
[0120] S10: The communication unit 41 of the external server 40 transmits the screen information of the login screen in response to the request for the login screen.
[0121] S11: The WebView 72 receives the screen information of the login screen of the external server 40 through the communication unit 21, and the first display control unit 26 draws the content of the web page based on this screen information. The first display control unit 26 draws the WebView area 302 by arranging the content of the web page in the content area 304. The second display control unit 22 synthesizes the device screen 301 generated by the authentication application 71 and the WebView area 302 drawn by the WebView 72 to display the login screen 290.
[0122] The communication unit 21 of the device 20 transmits the account information input on the login screen 290 to the external server 40, and the authentication unit 42 of the external server 40 determines authentication success or failure based on the account information. In the case of successful authentication, the communication unit 41 redirects the device 20 to the information processing system 10, and the information processing system 10 acquires an access token from the external server 40. The device 20 can be used by the user by receiving the access token from the information processing system 10.
[0123] S12: When the authentication method is other than "authentication by external server", step S12 is executed. Therefore, the second display control unit 22 displays one of the login screens in FIGS. 10 to 13 according to the authentication method. The communication unit 21 of the device 20 transmits the account information input on the login screen to the information processing system 10, and the authentication unit 12 of the information processing system 10 determines authentication success or failure based on the account information. When the communication unit 11 transmits authentication success to the device 20, the device 20 permits login and the user can use the device 20.
[0124] In this way, since the authentication application 71 can turn on the local storage according to the preset authentication method, even if the authentication method is "authentication by external server", the device 20 can display the login screen.
[0125] FIG. 17 is an example of a flowchart for explaining the process in which the setting change unit 23 changes the setting of the local storage to ON.
[0126] The setting change unit 23 determines whether the authentication method received from the information processing system 10 is "authentication by external server" (S101). If the determination in step S101 is No, the setting change unit 23 does nothing.
[0127] If the determination in step S101 is Yes, the setting change unit 23 determines whether the setting of the local storage associated with the type of the external server is ON (S102). If the determination in step S102 is No, the setting change unit 23 does nothing.
[0128] If the determination in step S102 is Yes, the setting change unit 23 changes the setting of the local storage to ON (S103).
[0129] <Main effects> As described above, since the device 20 of the present embodiment changes the setting of the local storage to ON according to the preset authentication method, even if the authentication method is "authentication by an external server", a specific screen can be displayed. In addition, the number of authentication methods supported by the device 20 increases, and it is possible to authenticate with the authentication method required by the user.
[0130] <Other application examples> As described above, the best mode for carrying out the present invention has been described using examples. However, the present invention is not limited to such examples, and various modifications and substitutions can be made without departing from the gist of the present invention.
[0131] For example, the division of the blocks in the functional block diagram shown in FIG. 6 is an example, and a plurality of blocks may be realized as one block, one block may be divided into a plurality of blocks, and / or some functions may be transferred to other blocks. In addition, the functions of a plurality of blocks having similar functions may be processed by a single piece of hardware or software in parallel or in time division.
[0132] Also, the device group described in the embodiments merely shows one of a plurality of computing environments for implementing the embodiments disclosed in this specification. In one embodiment, the information processing system 10 includes a plurality of computing devices such as a server cluster. The plurality of computing devices are configured to communicate with each other via any type of communication link including a network or a shared memory, and implement the processes disclosed in this specification.
[0133] Furthermore, the information processing system 10 can be configured to share the processing steps disclosed in this embodiment, such as FIG. 16 etc., in various combinations. For example, a process executed by a predetermined unit can be executed by a plurality of information processing devices included in the information processing system 10. Also, the information processing system 10 may be integrated into one server device or divided into a plurality of devices.
[0134] Also, each function of the embodiments described above can be realized by one or a plurality of processing circuits. Here, the "processing circuit" in this specification includes a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, and devices such as an ASIC (Application Specific Integrated Circuit), a DSP (digital signal processor), an FPGA (field programmable gate array), and conventional circuit modules designed to execute each function described above.
Explanation of Reference Numerals
[0135] 10 Information processing system 20 Device 40 External server 100 Device utilization system
Prior Art Documents
Patent Documents
[0136]
Patent Document 1
Claims
1. An information processing apparatus capable of communicating with an information processing system via a network, a communication unit that receives information including the type of an external server used for authentication from the information processing system, a setting change unit that determines whether to change the settings of a Web browser based on the type of the external server used for authentication received by the communication unit, and changes the settings of the Web browser if it is determined to make a change, a display control unit that displays, using the Web browser whose settings have been changed, an authentication screen for receiving an operation, which is received from an external server according to the type of the external server used for authentication received by the communication unit, An information processing apparatus characterized by comprising the above.
2. The information including the type of the external server used for authentication includes an authentication method, and the setting change unit changes the settings of the Web browser according to the authentication method received by the communication unit. The information processing apparatus according to claim 1.
3. When the authentication method received by the communication unit uses an external server, the setting change unit changes the settings of the Web browser. The information processing apparatus according to claim 2.
4. The communication unit receives the type of the external server together with the authentication method, When the authentication method received by the communication unit uses an external server, and further, when the type of the external server is set in the information processing apparatus to change the settings of the Web browser, the setting change unit changes the settings of the Web browser. The information processing apparatus according to claim 3.
5. Changing the settings of the Web browser is to change the setting for saving data in the Web browser from OFF to ON. The information processing apparatus according to any one of claims 2 to 4.
6. When the authentication method received by the communication unit is a mail address / password, a tenant ID / user ID / password, an IC card, or a PIN, the display control unit displays a login screen according to the authentication method. The information processing apparatus according to any one of claims 2 to 5.
7. An authentication application for authentication operates in the information processing apparatus, When the authentication method received by the communication unit uses an external server, the authentication application calls the Web browser, The information processing apparatus according to any one of claims 2 to 6, characterized in that a screen related to authentication drawn by the web browser is synthesized with a screen drawn by the authentication application and displayed.
8. It has a storage unit that stores in association with each other the type of the external server and the ON / OFF of the function of storing data of the web browser, The setting change unit determines whether to turn on the function of storing data of the web browser according to the ON / OFF of the function of storing data of the web browser associated with the type of the external server received by the communication unit, The information processing apparatus according to claim 4, characterized in that when it is determined that the function of storing data of the web browser is to be turned on, the function of storing data of the web browser is turned on.
9. A display method by an information processing apparatus capable of communicating with an information processing system via a network, A communication step of receiving information including the type of an external server used for authentication from the information processing system, Based on the type of the external server used for authentication received in the communication step, determining whether to change the settings of the web browser, and if it is determined to make a change, a step of changing the settings of the web browser, A display control step of displaying, using the web browser whose settings have been changed, an authentication screen that receives an operation and is received from the external server according to the type of the external server used for authentication received in the communication step, A display method characterized by comprising:
10. An information processing apparatus capable of communicating with an information processing system via a network, A communication unit that receives information including the type of an external server used for authentication from the information processing system, A setting change unit that determines whether to change the settings of the web browser based on the type of the external server used for authentication received by the communication unit, and if it is determined to make a change, changes the settings of the web browser, A display control unit that displays, using the web browser whose settings have been changed, an authentication screen that receives an operation and is received from the external server according to the type of the external server used for authentication received by the communication unit, A program for causing the apparatus to function as such.
Citation Information
Patent Citations
Network-corresponding peripheral device and control method therefor
JP2005149256A
Information processor, terminal device, information processing method, information processing program and recording medium
JP2005267448A
Web authentication method, web authentication server, program, and storage medium
JP2006195750A
Image forming system and user manager server device
JP2011192115A
Information processing program, information processor and information processing method
JP2017021575A