Information Processing Apparatus, Authentication System, Authentication Method, and Program

The system allows users to select and input different authentication factors, improving flexibility and convenience in multi-factor authentication by displaying appropriate screens based on the type of second attribute value.

JP7714000B2Active Publication Date: 2025-07-28CANON KK
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2023124708
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-07-31
Publication Date
2025-07-28
Estimated Expiration
2043-07-31

AI Technical Summary

Technical Problem

Existing multi-factor authentication systems in image forming apparatuses lack flexibility, as they do not allow users to select their preferred authentication method, reducing convenience.

Method used

Implementing user interface means and control means that enable users to select and input different authentication factors, such as IC card, password, or pattern, and display appropriate screens based on the type of second attribute value during multi-factor authentication.

Benefits of technology

Users can choose their preferred authentication method, enhancing flexibility and convenience in multi-factor authentication processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007714000000002
    Figure 0007714000000002
  • Figure 0007714000000003
    Figure 0007714000000003
  • Figure 0007714000000004
    Figure 0007714000000004
Patent Text Reader

Abstract

To allow a user as an authentication target to select an authentication method for authenticating a second factor from a plurality of authentication methods in multi-factor authentication.SOLUTION: An information processing apparatus has a user interface for display for a user and input by the user, and a control unit. The control unit performs first authentication of collating a first attribute value of a user to be authenticated as a first factor, which is in user information including a plurality of attributes for every user, with an input value from the user, and performing authentication, and second authentication of collating a second attribute value of the user succeeding the first authentication as a second factor, with the input value from the user, and performing authentication. In the second authentication, the control unit displays a user interface according to information included in the second attribute value and indicating the type of the second attribute value, and receives input according to the information indicating the type.SELECTED DRAWING: Figure 7
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, an authentication system, an authentication method, and a program.

Background Art

[0002] In the authentication means of an image forming apparatus, there is a server authentication function that executes authentication by accessing an authentication service provided by an on-premises server installed in a local network or an external cloud server. In conventional server authentication, user attributes included in user information registered on the server are specified in advance, and authentication is performed by referring to those attributes.

[0003] In addition, the registration of user attributes to the server is generally performed by the server administrator registering in advance, as the first user attribute, information such as the employee ID (IC card) information of the user who uses the image forming apparatus. On the other hand, for security improvement, a technique has been proposed in which a seed server different from the server that executes authentication is installed, and user information hashed using a different seed for each user is registered as the first user attribute (see Patent Document 1).

[0004] In addition, with the sophistication of cyberattacks in recent years, the number of companies introducing multi-factor authentication that executes authentication using an element different from the first element when executing server authentication is increasing. When using a combination of server authentication and multi-factor authentication, a second user attribute different from the first user attribute such as the above-mentioned IC card information, for example, a password or a pattern, is specified as the second element. Thereby, multi-factor authentication is realized by combining password authentication in which the user inputs a numeric sequence memorized by the user to execute authentication, pattern authentication in which the user traces the pattern displayed on the display device to execute authentication, etc. with IC card authentication.

Prior Art Documents

Patent Documents

[0005]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0006] As described above, there is a technique for realizing multi-factor authentication by referring to user attributes held by an authentication server. Here, when performing the second-factor authentication, there may be a plurality of second-factor authentication methods such as a password or pattern authentication as described above. In this case, when the image forming apparatus displays the second-factor authentication screen, it may not be able to determine which authentication method should be used for authentication. Therefore, when performing multi-factor authentication using an authentication server, the second-factor authentication method is set by the administrator, and the user to be authenticated performs the multi-factor authentication process only with the set authentication method. This has the problem of eliminating the flexibility of the authentication method and reducing the convenience.

[0007] The present invention has been made in view of the above problems, and an object thereof is to enable a user to be authenticated to select an authentication method for authenticating one authentication factor when performing multi-factor authentication.

Means for Solving the Problems

[0008] To achieve the above object, the present invention has the following configuration. According to one aspect of the present invention, there are provided user interface means for display to the user and input by the user, and control means, wherein the control means performs a first authentication in which, among user information including a plurality of attributes for each user, a first attribute value of the user to be authenticated is used as a first factor and compared with an input value by the user for authentication, performs a second authentication in which, when the first authentication is successful, a second attribute value of the user is used as a second factor and compared with an input value by the user for authentication, allows a user who has succeeded in the second authentication to use the service according to the authority as an authenticated user, When performing the second authentication, the control means displays, on the user interface means, a user interface screen corresponding to the information indicating the type of the second attribute value included in the second attribute value, and accepts an input corresponding to the information indicating the type. 、 In the second authentication, when the second attribute value does not include information indicating the type but can identify the type, the control means displays a user interface screen corresponding to the type of the identified second attribute value on the user interface means and accepts an input corresponding to the type. and An information processing apparatus is provided, which is characterized by the above.

Advantages of the Invention

[0009] According to the present invention, a user to be authenticated can select an authentication method for authenticating one authentication element when performing multi-factor authentication.

Brief Description of the Drawings

[0010]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9A

Figure 9B

Embodiments for Carrying Out the Invention

[0011] Hereinafter, embodiments will be described in detail with reference to the accompanying drawings. Note that the following embodiments do not limit the invention according to the claims. Although a plurality of features are described in the embodiments, not all of these plurality of features are essential to the invention, and the plurality of features may be arbitrarily combined. Further, in the accompanying drawings, the same or similar configurations are denoted by the same reference numerals, and redundant descriptions are omitted.

[0012] [First Embodiment] <System Configuration in this Embodiment> FIG. 1 is a schematic diagram showing the configuration of an authentication system according to this embodiment. The image forming apparatus 100 that requires user authentication for use is, for example, a multi-functional peripheral (MFP), and displays an authentication screen according to the authentication target and method. In FIG. 1, as the authentication screens, a card authentication screen 101, a password authentication screen 102, and a pattern authentication screen 103 are displayed on the operation unit of the image forming apparatus 100 according to the respective cases. The user inputs the information recorded on the card on the card authentication screen 101, inputs the password on the password authentication screen 102, and inputs by drawing a pattern on the touch panel on the pattern authentication screen 103. The image forming apparatus 100 is connected to an authentication server 104 for executing authentication. The authentication server 104 is provided with a database 1041 that records user information, and the users registered in the database 1041 include users to whom identification information such as "Alice" is assigned. The user information is information that collects information related to the user, that is, attributes (user attributes), and one record is configured for each user, and each individual field corresponds to each individual attribute.

[0013] In this embodiment, the description will be made on the assumption that the IC card authentication by the authentication server 104 is executed to identify the user of the image forming apparatus 100, and then the password authentication or the pattern authentication is executed.

[0014] Registered users of the impression server 104 have their IC card information registered in the authentication server 104, and a password or pattern is registered in association with the IC card information. After each user executes IC card authentication and inputs a password or pattern, user authentication of the image forming apparatus 100 is completed, and the functions of the MFP 100 can be used. The image forming apparatus 100 of the present embodiment includes a printer function, a copy function, and a scan function, and further includes an editing function that enables editing of the IC card information, password, or pattern registered in the authentication server on the authentication setting screen.

[0015] <Hardware Configuration of Image Forming Apparatus 100> FIG. 2 is a hardware configuration diagram of the image forming apparatus 100. The image forming apparatus 100 may also be referred to as an information processing apparatus focusing on its information processing function. In addition to a printer unit 207 and a scanner unit 209, the image forming apparatus 100 includes a document information reading unit 210 that reads information (barcode, QR code (registered trademark), watermark) embedded in the image data output from the scanner unit 209, and stores the read information in the HDD 205. Note that the document information reading unit 210 may be realized by executing a program with the CPU 206.

[0016] The printer unit 207 performs a process of forming and outputting an image corresponding to a print job received from, for example, a personal computer (PC) connected to the image forming apparatus 100 via the network 212 on a sheet. The scanner 209 optically reads a document image and outputs it as image data.

[0017] The document information reading unit 210 reads information (barcode, QR code (registered trademark), watermark) embedded in the image data output from the scanner unit 209, and stores the read information in the HDD 205. Note that the document information reading unit 210 may be realized by executing a program with the CPU 206.

[0018] The CPU 206 executes the programs stored in the ROM 203 and the RAM 204 to dynamically control various hardware components that make up the image forming apparatus 100. By doing so, it becomes possible to realize each function provided by the image forming apparatus 100. The CPU 206 sends signals to various hardware via the bus line and can perform data communication with other hardware. Since the CPU is a processor and is in charge of controlling the apparatus, it may also be called a control unit.

[0019] The operation unit 201 is a user interface for a user who uses the image forming apparatus 100 to make inputs such as operation instructions. In addition to including a display unit, the operation unit 201 can also be operated as a touch panel.

[0020] The wired LAN interface (I / F) 211 is a communication interface for connecting to a local network, such as a company internal network 212, which is, for example, composed of a LAN. The company internal network 212 is connected to a wide area network such as the Internet, and through these networks, the image forming apparatus 100 can connect to cloud services such as the authentication server 104 to receive services.

[0021] <Software Configuration in this Embodiment> Next, the software configuration in this embodiment will be described with reference to FIG. 3. <Software Configuration of the Image Forming Apparatus 100> Figure 3 is a software configuration diagram of the image forming apparatus 100. The image forming apparatus 100 in Figure 3 is controlled by an operating system (OS) 313, and on the OS 313, software that serves as a platform for executing applications, such as a language processing system program including a library, is executed. As applications operating on this platform, a copy application 301, a scan application 302, a print application 303, a user authentication setting application 304, and a user authentication application 305 are provided. In the following description, the "application" in each application name may be omitted. Also, the above-mentioned copy 301, scan 302, print 303, user authentication setting 304, and user authentication 305 provide a user interface operable by the user. Each application communicates with various control services used in the application via an application program interface (API).

[0022] The various control services are a module group including a scanner control service 306, a printer control service 307, an operation unit control service 308, a wired LAN control service 309, and an authentication control service 310. Each service provides services such as a scanner, a printer, an operation unit, a wired LAN, and user authentication to the application or to a web application. Also, a user DB 311 that holds user information and a RAM 312 for saving the login context of the logged-in user are provided. The user authentication 305 performs user authentication using the authentication server 104 or the authentication control service 310.

[0023] User authentication 305 provides functions for local authentication, server authentication, and remote authentication to log in to the image forming apparatus 100. In local authentication, user authentication is performed using the information in the user DB 311, and management of logged-in users such as new user registration and user information change is performed. When performing server authentication, an external authentication server 104 is accessed, and authentication processing is executed by referring to the user information registered in the authentication server 104. Management of user information is also performed for the user information registered in the authentication server 104. Settings related to management of these logged-in users and various authentications can be set after logging in to the image forming apparatus 100, from the user authentication setting application 304, or by remotely accessing user authentication 305 from the PC 314. In this case, user authentication 305 functions as a service for the PC 314. In remote authentication, for example, necessary information is input on an authentication screen displayed by a web browser for authentication.

[0024] Each function of the above-described embodiment can be realized by a program described in an assembly language, C, C++, Visual C++, Perl, Ruby, JAVA (registered trademark), JAVABeans, JAVABApplet, JAVAScript, or the like. Needless to say, other languages such as object-oriented programming languages may be used in addition to such legacy programming languages. These programs can be stored in a device-readable recording medium and distributed.

[0025] The user authentication processing supported by the image forming apparatus 100 of the present embodiment includes card authentication, user name + password authentication, PIN authentication (password authentication), pattern authentication, and combinations thereof. First, the authentication screens for these authentication processes will be described.

[0026] <Card authentication screen> Card authentication is a user authentication process performed by reading information such as card identification information (card ID) recorded electronically, magnetically, or optically on a card by a card reader 202 provided in the image forming apparatus 100. Fig. 4(a) shows a card authentication screen 401 which is the user interface screen. The user touches the card he / she possesses on the card reader 202 provided in the image forming apparatus 100. The image forming apparatus 100 reads the card ID from the card reader 202. The acquired card ID is inquired to the authentication server, and the card ID associated with the user account is searched. As a result of the search, if the card ID is registered, the authentication process is executed with the registered user account. If the card ID read by the card reader 202 is not registered, it is regarded as an authentication error, and the card authentication screen 401 is displayed again. Here, although it has been described as performing server authentication, when performing local authentication, it is the same as server authentication except that authentication is performed using the user DB 311 instead of the authentication server 104.

[0027] When using card authentication, the card ID needs to be registered in advance to the authentication server 104. The method of registering the card ID may be a method of directly inputting it to the operation unit 201 of the image forming apparatus 100, or a method of registering the card ID by having the card reader 202 read the card ID. When registering the card ID, the user name and password are input to the image forming apparatus 100 to execute the user confirmation process. By this user confirmation process (user authentication process), the user information (user name and password) registered in advance is specified, and the card ID is associated with the specified user information. Since the authentication information used in the user confirmation process uses the information registered in the authentication server 104, if the user information is not registered in the authentication server 104, a user confirmation error occurs. In that case, the user information needs to be registered in advance.

[0028] When the user authentication is successful, the user touches the card he / she wants to register on the card reader 202, and the association between the user account and the card ID is executed. After that, the user can perform the card authentication service.

[0029] <User Account Authentication> User account authentication is an authentication method in which the user is authenticated by having the user name (user identification information) and password input via the local UI of the image forming apparatus 100 or a remote UI such as a PC or a mobile terminal. The local UI is the UI displayed on the operation unit 201 of the image forming apparatus 100, and the remote UI is the UI provided from the HTTP server of the image forming apparatus 100 to the browser of the terminal and displayed, corresponding to the local UI. In either case, user information and the like can be input from the UI to perform user authentication and log in. In the following description, the case of logging in from the local UI and performing authentication by the authentication server 104 will be described. A user account authentication screen 402, which is a user interface screen for that purpose, is shown in Fig. 4(b).

[0030] The user who uses the image forming apparatus 100 inputs the user name 405 and password 406 on the user account authentication screen 402 displayed on the local UI, and presses the login button 407. Accordingly, the input user information is transmitted to the authentication server 104 and compared with the user name and password registered in the authentication server 104. If the corresponding user account and password information are registered, the authentication process is successful, and a response to that effect is returned to the image forming apparatus 100. As a result, the logged-in user can use the image forming apparatus 100.

[0031] If either the corresponding user name or password is not registered in the authentication server 104, the authentication server 104 regards it as an authentication error and responds to that effect to the image forming apparatus 100. After displaying the error on the image forming apparatus 100, the user account authentication screen 402 is displayed.

[0032] Also, when using user account authentication with the authentication server 104, authentication information including the user name and the password associated therewith is registered to the authentication server 104. At this time, it is assumed that the user who can register the authentication information is an administrator user granted with administrator authority.

[0033] <PIN authentication> PIN authentication is an authentication method for logging in to the image forming apparatus 100 by inputting a PIN when authenticating to the local UI of the image forming apparatus 100 and when authenticating to the remote UI from a PC or a mobile terminal. A PIN authentication screen 403 for that purpose is shown in Fig. 4(c).

[0034] The flow of the authentication process and the user registration process may be the same as those of the user account authentication. That is, the PIN is registered in association with the user name as part of the user information. In the present embodiment, PIN authentication is assumed to be used in combination with IC card authentication or user account authentication. When PIN authentication is set as multi-factor authentication after successful IC card authentication or user account authentication, the user is requested to input the PIN. The authentication server 104 collates the PIN registered in association with the user identified by card authentication or user account authentication with the input PIN to perform user authentication. The handling of the authentication result may be the same as that of the user account authentication.

[0035] <Pattern authentication service> The pattern authentication used in the present embodiment will be described. A pattern authentication screen 404 is shown in Fig. 4(d). In pattern authentication, the user registers in advance a pattern to be used in pattern authentication from the user authentication setting application 304. The user inputs the trajectory of the pattern on the pattern authentication screen 404 from the touch panel of the operation unit 201 of the image forming apparatus 100. The input pattern is transmitted to the authentication server 104 and collated with the registered pattern. If they match, a response to that effect is transmitted to the image forming apparatus 100 and the functions of the image forming apparatus 100 can be used.

[0036] If it does not match the registered pattern, it is regarded as an authentication error, and the pattern authentication screen 404 is displayed again. Note that the timing when the pattern authentication process starts is the timing when the user finishes the input process of the pattern and releases the finger from the touch panel.

[0037] Also, the pattern is composed of, for example, a sequence of points. Therefore, regarding the points constituting the pattern, numbers as exemplified on the pattern authentication screen 404 are internally associated with the points and held. Although numbers are shown in FIG. 4(d), the numbers do not have to be displayed on the screen. When transmitting the pattern to the authentication server 104, a sequence of numbers arranged along the trajectory, which are associated with the points through which the trajectory of the input pattern passes, is transmitted as the pattern. If the sequence of numbers registered as the pattern matches the sequence of input numbers, the pattern authentication may be determined to be successful. If they do not match, the pattern authentication fails.

[0038] <User information registered in the authentication server> Table 1 shows an example of user information registered in the authentication server 104. Note that the items included in the user information are the attributes of the corresponding user, and the values thereof may be referred to as attribute values.

[0039]

Table 1

[0040] The "user name" and "password" in Table 1 are referred to during the above-mentioned user account authentication and card authentication. The "first element (card ID)" in Table 1 is referred to during card authentication.

[0041] The "second factor (PIN or pattern)" is referred to when performing PIN authentication or pattern authentication. The PIN or pattern is held in the same area (field) of user information, and it is indicated by a prefix whether it is one or the other. In this embodiment, since the card ID attribute is used as the first factor of multi-factor authentication and the PIN or pattern attribute is used as the second factor, it is described as in Table 1. The PINs and patterns registered in the authentication server 104 via the image forming apparatus 100 are both converted into hash values using a hash function and stored in the format of "prefix:hash value". The prefix indicates the type of the registered information. For example, the prefix "PIN" means that the data is a PIN, and the prefix "PTN" means that the data is a pattern. When a PIN is directly input to the authentication server 104, it is registered without being hashed and without a prefix.

[0042] At the time of multi-factor authentication, when the image forming apparatus 100 succeeds in authenticating the first factor, it receives the response from the authentication server 104. Also, it acquires the prefix of the second factor together with the response. When referring to the acquired prefix and it is "PIN", it determines that the second factor is a PIN and displays the PIN authentication screen 403.

[0043] Also, when referring to the acquired prefix of the second factor and it is "PTN", it determines that the second factor is a pattern and displays the pattern authentication screen 404.

[0044] When registering the value of the "PIN or pattern" attribute from the image forming apparatus 100, it is registered after it is selected whether it is a PIN or a pattern. Therefore, the image forming apparatus 100 can also transmit information indicating which is the registration target to the authentication server 104 together with the PIN or pattern to be registered. Thus, the authentication server 104 may add a prefix corresponding to the information and register those PINs or patterns.

[0045] Also, when the administrator of the authentication server 104 directly inputs a value into the second factor instead of registering from the image forming apparatus 100, it is stored in a format without a prefix such as "7654321". The seed information required for the hash value is calculated from the user name described in Table 1, and the hash value is calculated using the value of the second factor to be hashed and the seed information.

[0046] The "Usage Authority of Image Forming Apparatus" in Table 1 is referred to when displaying the information that can be set in the user authentication information setting application 304. The user authority indicates the authority of the corresponding user.

[0047] <Function - specific Authentication> When in use, the image forming apparatus 100 displays an authentication screen as shown in FIG. 4 and provides the user with a device authentication mode for executing user authentication processing and a function - specific authentication mode. In the function - specific authentication mode, a user authentication screen is displayed when using the applications held by the image forming apparatus 100. Since authentication is executed for each application in the function - specific authentication mode, for example, the administrator user can set that the authentication process is executed when using the copy application 301, but the print application 303 can be used without executing the authentication process. Although the objects used by the authenticated users are different, user authentication may be performed in the same way in any mode. The server authentication described in this embodiment is assumed to be used in both the device authentication mode and the function - specific authentication mode.

[0048] <Authentication Setting Screen> The server authentication setting screen 501 displayed by the image forming apparatus 100 will be described with reference to FIG. 5. In the present embodiment, since the user authentication is described on the premise of multi-factor authentication, the setting using FIG. 5 is also based on multi-factor authentication, but other authentication methods may be selected. The server authentication setting screen 501 is displayed in response to the activation of the user authentication setting application 304 and the instruction of server authentication setting. Note that since the user authentication setting application 304 is also one of the applications of the image forming apparatus 100, it can be used by the authenticated user. For example, in the initial state of the image forming apparatus 100, it is possible to log in to the image forming apparatus 100 with user information that is predetermined and registered in the authentication server 104, and the user authentication setting application 304 can be used in the logged-in state.

[0049] The server authentication setting screen 501 includes items such as server information 502 regarding the server that executes server authentication, attribute settings 506 to be verified at the time of server authentication, and multi-factor authentication enforcement settings 509 for setting whether to forcibly perform multi-factor authentication at the time of server authentication. This setting is performed by a management user having administrator authority.

[0050] The server information 502 is an item for setting which domain's server to use when the image forming apparatus 100 uses the authentication server. The server information 502 specifies the target authentication server with the domain name 502 for setting the domain to which the server belongs and the host name 503 of the authentication server, and realizes access to the authentication server by performing network search. Also, at the time of access, the user name 504 and password 505, which are the user account information of the user who holds the administrator authority registered in the authentication server 104, are set. By doing so, when accessing the authentication server, the user account information is transmitted to execute the authentication process by the authentication server.

[0051] When accessing the authentication server 104, authentication processing based on the set values of the user name 504 and password 505 is first performed. After successful authentication, it becomes possible to perform the above-described card authentication, user account authentication, PIN authentication, and pattern authentication in the image forming apparatus 100 by using the authentication service provided by the authentication server 104. Also, registration of user information becomes possible.

[0052] For the attribute setting 506 to be collated at the time of authentication, when using each element in the authentication process, it is set which attribute value of the user information is to be referred to. When using user account authentication, server authentication is performed by referring to the value of the attribute set as the login name 506. When setting the user name and password as the user information to be the target of user account authentication, for the login name 506, information indicating the user name and password (for example, codes assigned to each item) may be set in the login name 506.

[0053] Also, when performing multi-factor authentication, the attributes of the user information to be used for the first factor 507 and the second factor 508 are set respectively. When using card authentication as the first factor, information indicating the "card ID" attribute, for example, the index of the card ID attribute in the user information, is set as the first factor 507. At the time of authentication, server authentication is performed by referring to the attribute value of the card ID. When using PIN or pattern authentication as the second factor, information indicating the "PIN or pattern" attribute is set as the second factor 508. Then, at the time of user authentication, server authentication is performed by referring to the input value and the value of the attribute set for the user to be authenticated. Also, the set attribute information is referred to not only at the time of server authentication but also when registering user information in the authentication server, and the value (attribute value) of the item set with the login name 506 is referred to when identifying the user to be registered. After the user identification is performed, when performing the update or registration process of other items of the user information, each attribute information set for each of the first factor 507 to the second factor 508 is referred to, and the registration process to the authentication server 104 is performed. If the user to be targeted is not registered in the user identification, it may be newly registered, and if it is already registered, it may be updated.

[0054] Note that referring to the server authentication settings set in Fig. 5(A) during the registration of user information may be the case when, on the user information setting screen, values of item names matching those on the server authentication setting screen, such as "login name", "first element", and "second element", are entered in the input item names. When displaying the names of the items in Table 1 and setting the values of each item, it is not necessary to refer to the server authentication settings set in Fig. 5(A) during the setting of user information.

[0055] The multi-factor authentication enforcement setting 509 is an item that can be set when the settings of the above-described first element 507 and second element 508 are valid. The settings being valid means that the attributes of the user information are set in their respective items. When the settings of the first element 507 and second element 508 are invalid, the multi-factor authentication enforcement setting 509 is masked. With this setting, an administrator can preset that multi-factor authentication is required during server authentication execution. When the multi-factor authentication enforcement 509 is valid, authentication of users who have not registered the attribute selected as the second element is not performed, and a screen prompting the second element attribute value registration process is displayed. For example, if the second element is "PIN or pattern", a screen prompting the registration process of that value is displayed during authentication execution. Also, if the multi-factor authentication enforcement setting 509 is off, user authentication may be performed using user account authentication.

[0056] Each setting of the PIN-only forced setting 510 and the pattern-only forced setting 511 can be set only when the multi-factor authentication forced setting 509 is valid. With these items, when setting the multi-factor authentication, it is possible to set the items that the user must input. When the PIN-only forced setting 510 is valid, authentication of users whose PIN is not registered and only the pattern is registered is prohibited, and a PIN registration screen is displayed at the time of user authentication. In this case, after the PIN registration is executed, the registered pattern is overwritten with the PIN. When the pattern-only forced setting 511 is valid, authentication of users whose pattern is not registered and only the PIN is registered is prohibited, and a pattern registration screen is displayed at the time of user authentication. After the pattern registration is executed, the registered PIN is overwritten with the pattern information indicating the pattern. In FIG. 5, the PIN-only forced setting 510 and the pattern-only forced setting 511 are check boxes, but these settings can be either only one of them on or both off, and in this embodiment, the setting of both on cannot be selected. Therefore, the user interface may be configured so that both cannot be selected at the same time.

[0057] The values of each item set on the user authentication setting screen 501 are stored in a non-volatile memory such as the HDD 205 or the ROM 203, for example, and are referred to as necessary for user authentication or the like. The stored information will be referred to as server authentication setting information. The server setting information may have a predetermined default setting even if the administrator does not set it. In the default setting, for example, the login name is the user name and password, the first element is the card ID, the second element is the PIN or pattern, etc., and the multi-factor authentication forced setting may be off.

[0058] <Registration of the Second Element> FIG. 5(B) is an example of the user setting screen 521 that is displayed when registering or updating user information. With the user setting screen 521, the administrative user can register the user information in Table 1 with the authentication server 104. When the administrative user activates the user authentication setting application 304 to instruct user settings and completes the authentication of the administrator authority, the user setting screen 521 in FIG. 5(B) is displayed.

[0059] On the user setting screen 521, values for the user name 522, password 523, card ID 524, PIN or pattern 525, and usage authority 526 can be set for each user. The set values are registered as the user information in Table 1 in response to the pressing of the registration button. Also, if the input card ID has already been registered, items other than the card ID of the user information may be updated with the newly set values.

[0060] Note that when inputting in FIG. 5(B), especially when inputting the PIN or pattern 525, the forced PIN only setting 510 and the forced pattern only setting 511 may be referred to. For example, if the forced PIN only setting 510 is on, the display of the second element registration screen 602 is skipped, the PIN registration screen 603 is displayed, and the PIN may be registered without any option. Similarly, if the forced pattern only setting 511 is on, the display of the second element registration screen 602 is skipped, the pattern registration screen 605 is displayed, and the pattern may be registered without any option.

[0061] Using FIG. 6, a method for registering the value of the second element, which is the second factor of multi-factor authentication and is the target of PIN or pattern authentication, will be described. Here, as an example, a case where the card ID is the first element and the PIN or pattern is the second element on the screen 501 in FIG. 5(A) displayed on the image forming apparatus 100 will be described. That is, the second element in FIG. 5(B) may be read as the password or pattern.

[0062] When the administrative user selects the recitation number or pattern 525 on screen 521, the card authentication screen 601 is displayed. The card authentication screen 601 displayed at that time includes a menu section 607. When the user presses the menu section 607, it transitions to the second element registration screen 602 for registering a PIN number or pattern. From the second element registration screen 602, the user selects the target to be registered as the second element from among the PIN number or pattern, and after the selection, presses the OK button 612. Although it is shown as being selected by a checkbox in the figure, it may also be a radio button for exclusive selection. By doing so, the registration process for the attribute value corresponding to the selected method is started. When the cancel button is pressed, it transitions to the card authentication screen 601.

[0063] When the PIN number setting 609 is selected on the second element registration screen 602, it transitions to the PIN number registration screen 603. After entering the PIN number to be registered and pressing the Next button 615, it transitions to the PIN number confirmation screen 604. When the cancel button 614 is pressed, it transitions to the card authentication screen 601. When the confirmation input is made on the PIN number confirmation screen 604 and the OK button 618 is pressed, the image forming apparatus compares the value input on the PIN number registration screen 603 with the value of the confirmation input. As a result of the comparison, if the values match, the image forming apparatus performs the registration process for the hash data with the PIN number prefix as shown in Table 1 for the authentication server 104. If the values do not match, an error screen is displayed and it transitions to the PIN number confirmation screen 604. Touching the cancel button 617 causes it to transition to the card authentication screen 601. At the time of registration, the user information of the authentication server 104 is searched using the read card ID, and if it is already registered, the PIN number of that user is rewritten with the newly set PIN number. If it is not registered, since it is the card ID of a newly registered user, a new record is added to the user information and the value set there is registered. In this case, if essential items such as the user name and user authority are not entered, registration is not performed, and registration may be performed after all these items are entered.

[0064] When pattern setting 610 is selected on the second element registration screen 602, the screen transitions to the pattern registration screen 605. After entering the pattern to be registered, the screen transitions to the pattern confirmation screen 606. When the cancel button 619 is pressed, the screen transitions to the card authentication screen 601. When a confirmation input is made on the pattern confirmation screen 606, the image forming apparatus compares the value input on the pattern registration screen 605 with the value of the confirmation input. As a result of the comparison, if the values match, the image forming apparatus performs a registration process of hash data with a pattern prefix as shown in Table 1 to the authentication server. If the values do not match, an error screen is displayed and the screen transitions to the pattern confirmation screen 606. Touching the cancel button 620 causes the screen to transition to the card authentication screen 601. At the time of registration, the user information of the authentication server 104 is searched using the read card ID. If it is already registered, the password of that user is rewritten with the newly set password. If it is not registered, since it is the card ID of a user to be newly registered, a new record is added to the user information and the value set there is registered. In this case, if essential items such as the user name and user authority are not input, registration is not performed, and registration may be performed after all these items are input.

[0065] If the registration or update of the password or pattern is completed, return to the screen 521 in Fig. 5(B).

[0066] Even if the user is not a management user, as long as it is the user's own information, a user without administrator privileges can edit the registered user information. However, the editable items may be limited. For example, the password attribute and the PIN or pattern attribute may be changed by the corresponding user even if the user is not a management user. If a user who logged in with a general user privilege without administrator privileges starts the user authentication setting application 304 and instructs the editing of user information, the user information of the logged-in user is obtained from the authentication server 104. It is the user authentication setting application 304 that obtains it. Then, the obtained value is displayed on the screen of FIG. 5(B). For items that cannot be changed, they are grayed out or otherwise made in a state where they cannot be changed. When the PIN or pattern attribute is selected, the second element registration screen 602 of FIG. 6 is displayed as described above. In this way, a non-administrative user can specify the information to be used as the second element of the multi-factor authentication of the user himself / herself. In the above example, it is possible to select from the PIN and the pattern. And the selected information can be registered in the user's own user information.

[0067] <Description of the flow according to the present invention> Next, using the flowchart of FIG. 7, the flow of the server authentication process in which the CPU 206 of the image forming apparatus shown in the present embodiment expands and executes the program stored in the ROM 203 in the RAM 204 will be described. Further, the flowchart of the present embodiment is a procedure of multi-factor authentication processing, and is a flowchart for executing the PIN or pattern authentication as the second element after executing the card authentication as the first element.

[0068] <Server authentication process flow when multi-factor authentication is enabled> The flow of multi-factor authentication using the authentication server 104 by a user registered in the authentication server 104 is shown below. At the time of user authentication, it is determined whether the multi-factor authentication forced setting 510 is on. If it is on, the process of FIG. 7 is executed. If it is off, user authentication is performed by a predetermined or specified authentication method such as user account authentication.

[0069] When performing multi-factor authentication, the image forming apparatus 100 displays an IC card authentication screen 401. This display may be triggered, for example, by an operation for login when the user is not logged in. When an IC card is read on this screen, if the card ID is sent to the authentication server 104 and there is corresponding user information, the authentication server 104 sends a successful response for IC card authentication to the image forming apparatus 100.

[0070] The image forming apparatus 100 receives a successful response for IC card authentication from the authentication server 104 (S700). Thereby, it is determined that the first authentication for the first factor of multi-factor authentication has been successful. Thereafter, or simultaneously therewith, the image forming apparatus 100 acquires the attribute value of the second factor of the logged-in user from the authentication server 104 (S701). The second factor to be acquired is the attribute set as the second factor setting 508 in the server authentication setting information. Here, it is the password or pattern information of the user corresponding to the card ID authenticated by IC card authentication. Information indicating which attribute the second factor is at the time of requesting IC card authentication may be sent to the authentication server 104, and the authentication server 104 may send the attribute value of the second factor corresponding to the card ID to the image forming apparatus 100 together with the successful response. After acquiring the attribute value registered in the second factor, first, confirmation of its prefix is performed (S702). In this example, the acquired password or pattern has a prefix indicating whether it is a password or a pattern added thereto. In S702, it suffices to determine which one it is.

[0071] As a result of prefix discrimination, if it is "PIN", the image forming apparatus 100 displays a PIN authentication screen 403 (S703). The image forming apparatus 100 accepts the input of the user's PIN from the displayed PIN authentication screen 403 (S704). If the input is made, the image forming apparatus 100 hashes the input PIN data (S705). The hashed PIN data is compared with the attribute value of the second factor, that is, the hash data registered in the user information obtained in S701, and it is determined whether the values match (S706). If it is determined that the values match, the second authentication for the second factor is successful, and since the multi-factor authentication is successful, the screen display after authentication execution is performed (S713). The authenticated user is permitted to use the image forming apparatus according to the authority. If it is determined that the values do not match, a login error (S707) occurs, and the screen before login is displayed.

[0072] On the other hand, as a result of prefix discrimination in S702, if it is "PTN", the image forming apparatus 100 displays a pattern authentication screen 404 (S708). The image forming apparatus 100 accepts the input of the user's pattern from the displayed pattern authentication screen 404 (S709). If the input is made, the image forming apparatus 100 hashes the input pattern data (S710). The hashed pattern data is compared with the attribute value of the second factor, that is, the hash data registered in the user information obtained in S701, and it is determined whether the values match (S711). If it is determined that the values match, the second authentication for the second factor is successful, and since the multi-factor authentication is successful, the screen display after authentication execution is performed (S713). If it is determined that the values do not match, a login error (S712) occurs, and the screen before login is displayed. Note that the hash data registered in the user information, which is the comparison target in S711, may be the data obtained in S701.

[0073] In the procedure as described above, the user can register whether to use a password or a pattern as one of the elements of multi-factor authentication. Also, at the time of registration to the authentication server 104, by attaching a prefix according to the selected information, it is possible to determine which information the registered information is at the time of authentication, and perform authentication in a method according to the determination result.

[0074] [Second Embodiment] <Authentication Flow When the Value of the Second Attribute Value Is Not Prefix-Added Hash Data> The above flow is a login flow when prefix-added hash data is already registered in the authentication server 104. In this embodiment, FIG. 8 describes a login flow in a case where a password or a pattern, which is the second element, is registered as raw data in the authentication server 104 by an administrator, or a case where no value is registered in the password or pattern, which is the second element. Note that the configurations and procedures other than that FIG. 7 of the first embodiment is replaced by FIG. 8 are the same as those of the first embodiment.

[0075] When executing authentication, the image forming apparatus 100 displays an IC card authentication screen 401. This display may be performed, for example, triggered by an operation for login when the user is not logged in. When an IC card is read on this screen, if the card ID is transmitted to the authentication server 104 and there is corresponding user information, the authentication server 104 transmits a successful response for IC card authentication to the image forming apparatus 100.

[0076] When receiving a successful response for IC card authentication from the authentication server 104 (S800), the image forming apparatus 100 acquires the second element of the logged-in user from the authentication server 104 (S801). This may be in the same manner as described in S701 of FIG. 7. It is determined whether the acquired attribute value as the second element is a value available for authentication of the second element (S802). Being available as the second element means that the attribute value specified as the second element has been acquired. For example, if all unconfigured attributes in the user information are set to 0, it can be determined that the acquired second element being all 0 is not available, and otherwise it can be determined to be available.

[0077] If it is determined that it is available in S802, it is determined whether the registered data is raw data (S803). Here, the raw data is data that has not been hashed. In the present embodiment, the second element is a password or a pattern attribute, and the raw data that is not hashed is limited to the password directly set from the authentication server 104. If the password that is not hashed is set as a numeric string, the value of the password or the pattern attribute is 0 if not set, and if set, the beginning is the text of the prefix or the text of the password. Therefore, if the password or the pattern attribute obtained as the second element is not 0 and has no prefix, its value can be determined as raw data that has not been hashed.

[0078] If it is determined in S803 that the registered data is raw data, the image forming apparatus 100 displays a password authentication screen 403 (S804). The image forming apparatus 100 receives a password input process of the user from the displayed password authentication screen 403 (S805). After the input, it is determined whether the value matches by comparing the input password data with the data obtained in S801 (S806). If it is determined that the values do not match, a login error (S808) occurs, and the screen before login is displayed.

[0079] If it is determined in S806 that the values match, the authentication is successful. However, in this case, in order to re-register the hash data including the prefix, a password or pattern registration screen 602 is displayed (S807). After the display of the password or pattern registration screen 602, the image forming apparatus 100 hashes the value used in the authentication method selected by the user and adds a prefix according to the selected authentication method (S809). The data is registered in the authentication server 104 as prefix-added hash data (S810). After the completion of the update registration of the second attribute value to the authentication server, the image forming apparatus 100 performs a screen display after the authentication execution (S811).

[0080] Note that the input of the PIN number in S807 may start from the PIN number described in FIG. 6 or the selection of the PIN number on the PIN or pattern registration screen 602, and may be performed through the PIN number registration screen 603 and the PIN number confirmation screen 604. Similarly, the input of the pattern in S807 may start from the PIN number described in FIG. 6 or the selection of the pattern on the PIN or pattern registration screen 602, and may be performed through the pattern registration screen 605 and the pattern confirmation screen 606.

[0081] When it is determined in S803 that the registered data is not raw data but prefixed hash data, the processes of S702 to S712 in FIG. 7 are performed. That is, the authentication of the second element is performed in the manner described in FIG. 7.

[0082] When it is determined in S802 that the acquired attribute value of the second element is not a value that can be used as the second element of multi-factor authentication, the process branches to S807. In this case, the authentication of the second element is not performed, but the user is allowed to register the attribute that becomes the second element. As a result, the user can register a PIN number or a pattern in the manner described above.

[0083] In the above procedure, when the PIN number, which is the second element, is registered as unprocessed raw data, after authenticating with the PIN number, the user can register the newly input PIN number or pattern again. Since the format at that time is hashed and prefixed, in subsequent authentication, multi-factor authentication using the PIN number or pattern registered by the user as the second element can be performed smoothly.

[0084] Also, when the PIN number or pattern, which is the second element, is not registered so as to be at least available as the second element of multi-factor authentication, the user can register the PIN number or pattern. In subsequent authentication, multi-factor authentication using the PIN number or pattern registered by the user as the second element can be performed smoothly.

[0085] [Third Embodiment] Next, when the multi-factor authentication enforcement setting is on, considering only PIN enforcement 510 and only pattern enforcement 511, the procedure for having the user set the enforced attribute value in the authentication procedure will be described with reference to FIGS. 9A and 9B.

[0086] FIG. 9A is different in that FIG. 8 and steps S807 to S810 of FIG. 8 are replaced with step S900, which will be described in detail in FIG. 9B, and after branching to S702, if authentication is successful, the post-authentication screen display is shown and the process ends, but here it branches to S900. In S900, according to the enforcement setting of the PIN or pattern and the value currently set in the "PIN or pattern" attribute of the user information, the user is prompted to register the value of the said attribute. Thereby, after authentication regarding the second factor, if an enforcement setting is made for either the PIN or the pattern, the input of the enforced attribute value can be made as necessary. Since FIG. 9A is common with FIG. 8 except for the above differences, the description will be omitted except for the description of S900.

[0087] FIG. 9B is a flowchart showing the details of step S900 in FIG. 9A. First, it is determined what the prefix of the attribute value obtained in S801, that is, the value of the PIN or pattern attribute of the user information of the logged-in user, is (S901). The prefix can be either a pattern (PTN) or a PIN, but it can also be the case where it is not set or it is raw data of a PIN. If it is determined that the prefix is PTN, then a pattern is set in the PIN or pattern attribute of the user information of the logged-in user. Therefore, it is determined whether only PIN enforcement 510 is set to on (S902).

[0088] If the only PIN forced setting 510 is not on, since the second factor of multi-factor authentication may be a pattern, the PIN or pattern registration process ends. If the only PIN forced setting 510 is on, since the second factor of multi-factor authentication must be a PIN instead of a pattern, a PIN is set instead of the pattern of the user information of the logged-in user. Therefore, the PIN registration screen 603 is displayed to allow the input of a PIN (S903), the PIN confirmation screen 604 is displayed to allow the re-entry of the PIN (S904), and if it can be confirmed, proceed to S905.

[0089] Therefore, the input and confirmed data is hashed (S905), a registration request is sent to the authentication server 104 as prefixed hash data, and it is registered in the authentication server 104 as the value of the PIN or pattern attribute (S906).

[0090] On the other hand, if it is determined in S901 that the prefix is not PTN, no pattern is set in the PIN or pattern attribute of the user information of the logged-in user. Therefore, it is determined whether the only pattern forced setting 511 is set to on (S907). If the only pattern forced setting 511 is not on, branch to S910. If the only pattern forced setting 511 is on, since the second factor of multi-factor authentication must be a pattern, a pattern is set instead of the data of the user information of the logged-in user. Therefore, the pattern registration screen 605 is displayed to allow the input of a pattern (S908), the pattern confirmation screen 606 is displayed to allow the re-entry of the pattern (S909), and if it can be confirmed, proceed to S905.

[0091] Therefore, the input and confirmed data is hashed (S905), a registration request is sent to the authentication server 104 as prefixed hash data, and it is registered in the authentication server 104 as the value of the PIN or pattern attribute (S906).

[0092] If it is determined in S907 that the pattern-only forced setting is not on, it is determined whether the attribute value of the second element has the prefix "PIN" (S910). If the prefix is "PIN", since the pattern-only forced setting 11 is not on and the PIN or the pattern attribute of the second element is set as the PIN, the PIN or pattern registration process ends.

[0093] If it is determined in S910 that the prefix is not "PIN", it is determined whether the value of the PIN or pattern attribute, which is the second element, is the raw data set by the authentication server 104 (S911). If it is determined that it is the raw data of the PIN, the process branches to S903 to re-set the PIN.

[0094] If it is determined in S911 that it is not the raw data of the PIN, or if it is determined that the raw data of the PIN is set, it can be determined that the PIN or pattern attribute is not set. In that case, the PIN or pattern is set. First, it is determined whether the PIN-only forced setting 510 is on (S912). If it is determined that the PIN forced setting 510 is on, the process branches to S903 to set the PIN. If it is determined that the PIN forced setting 510 is not on, the PIN or pattern registration screen 602 is displayed and any selection is accepted (S913). If the selected item is the PIN, the process branches to S903 to input the PIN and register it with the authentication server 104. If the selected item is the pattern, the process branches to S908 to input the pattern and register it with the authentication server 104.

[0095] According to the above procedures, when a hash-encrypted password is registered in user information as the second factor, when a hashed pattern is registered, when a plain-text password is registered, or when nothing is registered, re-registration can be performed as necessary. "As necessary" means according to settings where only the password is mandatory, only the pattern is mandatory, or neither is mandatory. This allows an authenticated user to appropriately reconfigure their own user information according to specified conditions. Also, particularly when there is no abnormality, it can be set according to the user's choice.

[0096] <Effect of the Embodiment> According to the above embodiment, when performing multi-factor authentication using an authentication server, even when there are multiple authentication methods for the second factor, it is possible to perform authentication using the authentication method selected by the user. This makes it possible to improve the convenience of the image forming apparatus.

[0097] Furthermore, when there is no room for user selection regarding the second factor, if there is a conflict between the current registered content and the forced authentication method, appropriate information can be registered during user authentication.

[0098] In the above embodiment, server authentication using an authentication server was described as an example, but the first to third embodiments can also be applied to a configuration in which the image forming apparatus holds user information without using a server.

[0099] Also, in the first to third embodiments above, it was assumed that user information is registered on the screens of FIGS. 5(B) and 6, but items may be selected on the screen of FIG. 5(A) and user information may be registered from the screen of FIG. 6 according to the selected items.

[0100] [Other Embodiments] The present invention can also be realized by supplying a program that realizes one or more functions of the above-described embodiments to a system or apparatus via a network or a storage medium, and having one or more processors in a computer of the system or apparatus read and execute the program. Further, it can also be realized by a circuit (for example, ASIC) that realizes one or more functions.

[0101] ● Summary of Embodiments Summarizing the above embodiments, the following inventions are included. (Item 1) User interface means for display to the user and input by the user, and control means, wherein the control means performs a first authentication in which, among user information including a plurality of attributes for each user, a first attribute value of the user to be authenticated is used as a first element and compared with an input value by the user for authentication, performs a second authentication in which, for a user who has succeeded in the first authentication, a second attribute value is used as a second element and compared with an input value by the user for authentication, allows a user who has succeeded in the second authentication to use according to the authority as an authenticated user, and in the second authentication, the control means displays, on the user interface means, a user interface screen corresponding to information indicating the type of the second attribute value included in the second attribute value, and accepts an input corresponding to the information indicating the type An information processing apparatus characterized by the above. (Item 2) The information processing apparatus according to Item 1, wherein in the second authentication, when the second attribute value does not include the information indicating the type but can specify the type, the control means displays, on the user interface means, a user interface screen corresponding to the specified type of the second attribute value, and accepts an input corresponding to the type An information processing apparatus characterized by the above. (Item 3) The information processing apparatus according to Item 1 or 2, If the second authentication is successful, a user interface screen corresponding to the type of the specified second attribute value is displayed on the user interface means, and an input corresponding to the information indicating the type is received. Based on the input, the second attribute value including the information indicating the type is re-registered. An information processing apparatus characterized by the above. (Item 4) The information processing apparatus according to any one of Items 1 to 3, In the second authentication, when the second attribute value is not set, the control means receives a selection of the type of the second attribute value by the user, displays a user interface screen corresponding to the selected type of the second attribute value on the user interface means, and receives an input corresponding to the information indicating the type. Based on the input, the second attribute value including the information indicating the type is re-registered. An information processing apparatus characterized by the above. (Item 5) The information processing apparatus according to any one of Items 1 to 4, When the second authentication is successful, if the type of the second attribute value is determined and the second attribute value of the user to be authenticated is not of the determined type, the control means displays a user interface screen corresponding to the determined type on the user interface means and receives an input corresponding to the type. Based on the input, the second attribute value including the information indicating the determined type is re-registered. An information processing apparatus characterized by the above. (Item 6) The information processing apparatus according to any one of Items 1 to 5, The first attribute value is card identification information read from a card, and the second attribute value is either a password or a pattern. An information processing apparatus characterized by the above. (Item 7) The information processing apparatus according to Item 6, The second attribute value is stored in the same area of the user information, The information indicating the type included in the second attribute value is information indicating whether the second attribute value stored in the area is either a password or a pattern. An information processing apparatus characterized by the above. (Item 8) An information processing apparatus according to any one of Items 1 to 7, Further comprising image forming means An information processing apparatus characterized by the above. (Item 9) An information processing apparatus according to any one of Items 1 to 8, Further comprising communication means, The user information is stored in an authentication server connected by the communication means, The control means, Sends an input value by the user to the authentication server to cause the authentication server to perform the first authentication, Obtains a second attribute value of the user for whom the first authentication has succeeded from the authentication server and performs the second authentication. An information processing apparatus characterized by the above. (Item 10) An information processing apparatus according to Item 9, Including an authentication server, An authentication system characterized by the above. (Item 11) A program for causing a computer to function as the information processing apparatus according to any one of Items 1 to 9. (Item 12) An authentication method executed by an information processing apparatus having user interface means for display to the user and input by the user and control means, The control means performs a first authentication in which, among user information including a plurality of attributes for each user, the first attribute value of the user to be authenticated is used as a first element and compared with an input value by the user for authentication, The control means performs a second authentication in which the second attribute value of the user who has succeeded in the first authentication is used as a second element and compared with the input value by the user for authentication. The control means permits use according to the authority of the user who has succeeded in the second authentication as an authenticated user. At the time of the second authentication, the control means displays on the user interface means a user interface screen corresponding to the information indicating the type of the second attribute value included in the second attribute value, and accepts an input corresponding to the information indicating the type. A authentication method characterized by the above.

[0102] The present invention is not limited to the above embodiments, and various changes and modifications can be made without departing from the spirit and scope of the invention. Therefore, claims are attached to disclose the scope of the invention.

Explanation of Signs

[0103] 100 Image forming apparatus, 104 Authentication server

Claims

1. user interface means for display to the user and input by the user, and control means, wherein the control means performs a first authentication by collating a first attribute value of the user to be authenticated, which is included in user information containing a plurality of attributes for each user, with an input value by the user using the first attribute value as a first element; performs a second authentication by collating a second attribute value of the user who has succeeded in the first authentication with an input value by the user using the second attribute value as a second element; allows use according to the authority for the user who has succeeded in the second authentication as an authenticated user; in the second authentication, the control means displays, on the user interface means, a user interface screen corresponding to information indicating the type of the second attribute value included in the second attribute value, and accepts an input corresponding to the information indicating the type; in the second authentication, when the second attribute value does not include the information indicating the type but the type can be specified, the control means displays, on the user interface means, a user interface screen corresponding to the specified type of the second attribute value, and accepts an input corresponding to the type An information processing apparatus characterized by the above.

2. The information processing apparatus according to claim 1, wherein if the second authentication is successful, a user interface screen corresponding to the specified type of the second attribute value is displayed on the user interface means, an input corresponding to the information indicating the type is accepted, and based on the input, the second attribute value including the information indicating the type is re-registered An information processing apparatus characterized by the above.

3. The information processing apparatus according to claim 1, wherein in the second authentication, when the second attribute value is not set, the control means accepts a selection of the type of the second attribute value by the user, displays, on the user interface means, a user interface screen corresponding to the selected type of the second attribute value, accepts an input corresponding to the information indicating the type, and based on the input, the second attribute value including the information indicating the type is re-registered An information processing apparatus characterized by the above.

4. The information processing apparatus according to claim 1, When the second authentication is successful, the control means determines the type of the second attribute value, and if the second attribute value of the user to be authenticated is not of the determined type, it displays a user interface screen corresponding to the determined type on the user interface means, accepts an input corresponding to the type, and re-registers the second attribute value including information indicating the determined type based on the input. An information processing apparatus characterized by the above.

5. The information processing apparatus according to claim 1, wherein the first attribute value is card identification information read from a card, and the second attribute value is either a password or a pattern. An information processing apparatus characterized by the above.

6. The information processing apparatus according to claim 5, wherein the second attribute value is held in the same area of the user information, and the information indicating the type included in the second attribute value is information indicating whether the second attribute value held in the area is either a password or a pattern. An information processing apparatus characterized by the above.

7. The information processing apparatus according to claim 1, further comprising an image forming means. An information processing apparatus characterized by the above.

8. The information processing apparatus according to claim 1, further comprising a communication means, wherein the user information is stored in an authentication server connected by the communication means, and the control means sends an input value by the user to the authentication server to cause the authentication server to perform the first authentication, and acquires the second attribute value of the user for whom the first authentication has been successful from the authentication server to perform the second authentication. An information processing apparatus characterized by the above.

9. An authentication system characterized by including the information processing apparatus according to claim 8 and an authentication server. An authentication system characterized by the above.

10. A program for causing a computer to function as the information processing apparatus according to any one of claims 1 to 8.

11. An authentication method executed by an information processing apparatus having a user interface means and a control means for display to the user and input by the user, wherein the control means performs a first authentication in which, among user information including a plurality of attributes for each user, the first attribute value of the user to be authenticated is used as a first element and compared with an input value by the user for authentication. The control means performs a second authentication by collating, as a second element, the second attribute value of the user who has successfully passed the first authentication with the input value by the user for authentication. The control means permits utilization according to the authority for the user who has successfully passed the second authentication as an authenticated user. At the time of the second authentication, the control means displays, on the user interface means, a user interface screen corresponding to the information indicating the type of the second attribute value included in the second attribute value, and accepts an input corresponding to the information indicating the type. In the second authentication, when the second attribute value does not include the information indicating the type but the type can be specified, the control means displays, on the user interface means, a user interface screen corresponding to the type of the specified second attribute value, and accepts an input corresponding to the type. A authentication method characterized by the above.

Citation Information

Patent Citations

  • Authentication system and authentication method

    JP2013020312A

  • System, electronic apparatus, authentication processing method, and program

    JP2018028874A

  • Information processing device with multi-factor authentication capability, control method, and program

    JP2023037169A