Information processing system, image processing device, information processing device, and program
The system efficiently manages token updates across multiple image processing devices by identifying priority devices and enabling remote updates, reducing administrative workload and improving efficiency.
Patent Information
- Application Number
- JP2021174348
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-10-26
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2041-10-26
AI Technical Summary
In environments with multiple image processing devices, administrators face increased workload and reduced efficiency due to frequent notifications for refresh token updates, especially when working remotely.
An information processing system that identifies and prioritizes devices with short token expiration periods, notifying administrators and enabling remote updates through a centralized interface.
Reduces the frequency of token updates across multiple devices, enhancing administrative efficiency and allowing remote management.
Smart Images

Figure 0007718228000001 
Figure 0007718228000002 
Figure 0007718228000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing system, an image processing apparatus, an information processing apparatus, and a program, and more particularly to a technique for updating the expiration date of a token used to authenticate access rights. [Background technology]
[0002] Conventionally, image processing devices such as MFPs (Multifunction Peripherals) are known that set an expiration date for passwords used to authenticate users and are equipped with a notification means that notifies an administrator of the impending expiration of the password in the form of a warning message a certain period of time before the password expires (for example, Patent Document 1).
[0003] On the other hand, image processing devices such as MFPs are equipped with the function of sending and receiving e-mail. Therefore, the image processing device can send image data obtained by scanning a document to an external device via e-mail, and can also print document files received from an external device via e-mail using its printer function. Conventionally, this type of image processing device has employed an authentication method using an ID and password to authenticate access rights when sending and receiving e-mail.
[0004] However, in recent years, mail servers have begun to adopt authentication methods such as OAuth 2.0 as a more secure authentication method. For example, with OAuth 2.0, an image processing device accesses an authentication server and is authenticated, thereby obtaining an access token and a refresh token from the authentication server in advance. When sending or receiving e-mail, the image processing device sends the access token obtained from the authentication server to the mail server. The mail server then sends the access token to the authentication server, and after verifying that it is a valid access token, the mail server can send or receive e-mail in response to a request from the image processing device.
[0005] In OAuth2.0, the expiration date of an access token is set to a short period of time, ranging from a few minutes to a few tens of minutes, and the expired access token cannot be used. Therefore, when the access token expires, the image processing device sends a refresh token to the authentication server and reacquires an access token with a new expiration date issued by the authentication server. In other words, a refresh token is a token for refreshing an access token with a short expiration date. This refresh token also has an expiration date. However, the expiration date of the refresh token is set to be longer than the expiration date of the access token, for example, about six months. Therefore, the image processing device can refresh the access token using the same refresh token any number of times until the refresh token expires.
[0006] On the other hand, once the refresh token expires, the image processing device will no longer be able to send or receive emails. Therefore, the administrator needs to update the refresh token before it expires. Therefore, as in the conventional technology of Patent Document 1 mentioned above, if the administrator is notified a certain period of time before the refresh token held in the image processing device expires, the administrator will be able to notice that the expiration is approaching and operate the image processing device to update the refresh token. [Prior art documents] [Patent documents]
[0007] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-171914 Summary of the Invention [Problem to be solved by the invention]
[0008] However, multiple image processing devices are often installed in an office. Each of the multiple image processing devices has its own refresh token, and each has a different expiration date. Therefore, if the conventional technology of Patent Document 1 is applied to an environment where multiple image processing devices are installed, the multiple image processing devices will individually send notifications to the administrator indicating that the refresh token is about to expire, and the administrator will have to individually update the refresh token each time they receive a notification. In particular, the more image processing devices there are, the more frequently the administrator will receive notifications, which increases the frequency of the update work and reduces work efficiency.
[0009] Furthermore, as remote work has become more common in recent years, administrators may receive notifications from image processing devices while working remotely, which requires them to go to the office to operate the image processing device and update the refresh token, significantly reducing work efficiency.
[0010] The present invention has been made to solve the above-mentioned conventional problems, and aims to provide an information processing system, an image processing device, an information processing device, and a program that can reduce the workload of an administrator when updating tokens held by each of multiple devices. [Means for solving the problem]
[0011] In order to achieve the above-mentioned object, the invention of claim 1 is an information processing system that manages tokens held by each of a plurality of devices, and is characterized in that it comprises: a first identification means that identifies a first update target device among the plurality of devices, the first update target device having a remaining period until the expiration date of the token that is a first period or less; a second identification means that, when the first update target device is identified by the first identification means, identifies a second update target device among the plurality of devices, the second update target device having a remaining period until the expiration date of the token that is a second period or less that is longer than the first period; and a notification means that, when the first update target device is identified by the first identification means, notifies an administrator of the first update target device and the second update target device.
[0012] The invention of claim 2 is characterized in that, in the information processing system of claim 1, the notification means sends a notification to the administrator including address information for accessing the respective remote operation screens of the first update target device and the second update target device.
[0013] The invention of claim 3 is a configuration in which the information processing system of claim 2 further comprises an information terminal capable of communicating with each of the plurality of devices, and when the first update target device detects access from the information terminal based on the address information, it provides its own remote operation screen to the information terminal and updates the expiration date of the token based on operations performed by the information terminal.
[0014] The invention of claim 4 is characterized in that, in the information processing system of claim 3, the information terminal updates the expiration date of the token held in the first update target device, and then displays a remote operation screen of the second update target device based on operation by an administrator.
[0015] The invention of claim 5 is a configuration in which, in the information processing system of claim 2, it further comprises an information terminal capable of communicating with each of the plurality of devices, wherein each of the first update target device and the second update target device provides its respective remote operation screen to the information terminal when it detects access from the information terminal based on the address information, and the information terminal displays the plurality of remote operation screens obtained from each of the first update target device and the second update target device as a plurality of tab screens.
[0016] The invention of claim 6 is characterized in that, in the information processing system of claim 5, the multiple tab screens are arranged in a predetermined direction in order of the shortest remaining period until the expiration of the tokens held by each of the first update target device and the second update target device.
[0017] The invention of claim 7 is an information processing system of any one of claims 2 to 6, characterized in that the address information includes a path for directly reaching a remote control screen for updating the token.
[0018] The invention according to claim 8 is an information processing system according to any one of claims 1 to 7, characterized in that the token is authentication information used for authentication when sending and receiving e-mail.
[0019] The invention according to claim 9 is an information processing system according to any one of claims 1 to 8, characterized in that the token is a refresh token used to update an access token.
[0020] The invention according to claim 10 is an information processing system according to any one of claims 1 to 9, characterized in that each of the plurality of devices is an image processing device having an email sending and receiving function.
[0021] The invention of claim 11 is an information processing system according to any one of claims 1 to 10, characterized in that each of the plurality of devices is equipped with the first identification means, the second identification means, and the notification means.
[0022] The invention of claim 12 is an information processing system according to any one of claims 1 to 10, further comprising an information processing device capable of communicating with each of the plurality of devices, wherein the information processing device is equipped with the first identification means, the second identification means, and the notification means.
[0023] The invention of claim 13 is an image processing device that holds a token with an expiration date set, and is configured to include a first identification means that identifies the device itself as a first update target device when the remaining period until the expiration date of the token is a first period or less, a second identification means that, when the first identification means identifies the device itself as the first update target device, identifies, from other image processing devices with which it can communicate, a second update target device for which the remaining period until the expiration date of the token held by the other image processing device is a second period or less that is longer than the first period, and a notification means that, when the first identification means identifies the device itself as the first update target device, notifies an administrator of the first update target device and the second update target device.
[0024] The invention of claim 14 is an information processing device that is capable of communicating with each of a plurality of devices and manages tokens held by each of the plurality of devices, and is characterized in that it comprises: a first identification means that identifies a first update target device among the plurality of devices, the first update target device having a remaining period until the expiration date of the token that is a first period or less; a second identification means that, when the first update target device is identified by the first identification means, identifies a second update target device among the plurality of devices, the second update target device having a remaining period until the expiration date of the token that is a second period or less that is longer than the first period; and a notification means that, when the first update target device is identified by the first identification means, notifies an administrator of the first update target device and the second update target device.
[0025] The invention of claim 15 is a program executed on a computer that manages tokens held by each of a plurality of devices, and is configured to cause the computer to execute the following steps: a first identification step of identifying a first update target device among the plurality of devices, the first update target device having a remaining period until the expiration date of the token that is a first period or less; a second identification step of identifying a second update target device among the plurality of devices, the second update target device having a remaining period until the expiration date of the token that is a second period or less that is longer than the first period, when the first update target device is identified by the first identification step; and a notification step of notifying an administrator of the first update target device and the second update target device, when the first update target device is identified by the first identification step. [Effects of the Invention]
[0026] According to the present invention, it is possible to simultaneously perform a series of update operations on multiple devices whose tokens have a short remaining period until their expiration date, thereby reducing the workload on administrators when updating tokens held by multiple devices. [Brief explanation of the drawings]
[0027] [Figure 1] FIG. 1 is a diagram illustrating an example of the configuration of an information processing system according to a first embodiment. [Figure 2] FIG. 10 is a diagram illustrating the flow of an authentication process when an image processing apparatus sends and receives e-mails. [Figure 3] FIG. 1 illustrates a process for refreshing an access token using a refresh token. [Figure 4] FIG. 2 is a block diagram illustrating an example of a hardware configuration of the image processing apparatus. [Figure 5] FIG. 2 is a diagram illustrating an example of the functional configuration of a control unit in the image processing apparatus. [Figure 6] FIG. 10 is a diagram showing the remaining periods of refresh tokens in a first update target device and a second update target device. [Figure 7] 10 is a flowchart illustrating an example of a processing procedure performed by a token management unit. [Figure 8] 2 is a block diagram showing an example of a hardware configuration and a functional configuration of an information terminal; [Figure 9] FIG. 10 is a diagram showing an example of a screen displayed when an information terminal accesses a first update target device and a second update target device one by one in turn. [Figure 10] FIG. 10 is a diagram illustrating a process of updating a refresh token by remote operation from an information terminal. [Figure 11] FIG. 10 is a diagram illustrating an example of an update operation by an administrator. [Figure 12] FIG. 10 is a diagram showing an example of a screen displayed when an information terminal simultaneously accesses both a first update target device and a second update target device. [Figure 13] FIG. 10 is a diagram illustrating an example of the configuration of an information processing system according to a second embodiment. [Figure 14] FIG. 2 is a block diagram illustrating an example of a hardware configuration and a functional configuration of an information processing device. [Figure 15] FIG. 10 is a diagram illustrating an example of information collection by an information collection unit. [Figure 16] 10 is a flowchart illustrating an example of a processing procedure performed in an information processing device. DETAILED DESCRIPTION OF THE INVENTION
[0028] Hereinafter, preferred embodiments of the present invention will be described in detail with reference to the drawings. Elements common to the embodiments described below are designated by the same reference numerals, and redundant description thereof will be omitted.
[0029] (First embodiment) A first embodiment of the present invention will be described. FIG. 1 is a diagram showing an example of the configuration of an information processing system 1 according to the first embodiment of the present invention. The information processing system 1 includes multiple image processing devices 3a, 3b, and 3c, a mail server 7, an authentication server 8, and an information terminal 9. The multiple image processing devices 3a, 3b, and 3c are installed in, for example, an office 2 and connected to a local network 4, such as a local area network (LAN) established in the office 2. The local network 4 is connected to a cloud 6, which is an external network such as the Internet. For example, the mail server 7 and the authentication server 8 are installed on the cloud 6. The information terminal 9 is a terminal device configured as a personal computer (PC), tablet terminal, smartphone, or the like used by an administrator of the image processing devices 3a, 3b, and 3c. For example, by connecting the information terminal 9 to the cloud 6, the administrator can access the multiple image processing devices 3a, 3b, and 3c connected to the local network 4 from outside the office 2 via the cloud 6. Furthermore, when the administrator brings the information terminal 9 into the office 2, the administrator can directly connect the information terminal 9 to the local network 4 to access the multiple image processing devices 3a, 3b, and 3c.
[0030] The image processing devices 3a, 3b, and 3c are installed in different locations in, for example, an office 2. For example, the image processing devices 3a, 3b, and 3c are each an MFP equipped with scanning, printing, copying, faxing, and email sending / receiving functions. Each of the image processing devices 3a, 3b, and 3c includes an operation panel 14 serving as a user interface. The operation panel 14 displays various operation screens that users can operate and accepts user operations. For example, the operation panel 14 accepts user job setting operations and job execution instructions. The image processing devices 3a, 3b, and 3c are shared and used by multiple users working in the office 2. An administrator is, for example, a user selected from among the multiple users. The administrator manages and maintains the image processing devices 3a, 3b, and 3c used by the multiple users. While FIG. 1 illustrates an example in which three image processing devices 3a, 3b, and 3c are installed in the office 2, the number of image processing devices is not limited to three. In the following description, when the image processing devices 3a, 3b, and 3c are not distinguished from one another, they will be collectively referred to as the image processing device 3.
[0031] The mail server 7 is a type of resource server that provides resource services to each of the multiple image processing devices 3a, 3b, and 3c as clients. In this embodiment, the mail server 7 provides email transmission and reception services. Email accounts for multiple users working in the office 2 are pre-configured in the mail server 7. Email accounts corresponding to each of the multiple image processing devices 3a, 3b, and 3c are also pre-configured in the mail server 7. Therefore, each of the multiple image processing devices 3a, 3b, and 3c can send and receive emails by accessing the email account configured in the mail server 7. When the mail server 7 detects access to an email account, it authenticates the access authority. If the authentication is successful, the mail server 7 sends and receives emails in response to a processing request from the access source. The mail server 7 in this embodiment employs, for example, OAuth 2.0 authentication as its authentication method.
[0032] The authentication server 8 is a server that issues access tokens and refresh tokens used in an authentication method such as OAuth2.0.
[0033] FIG. 2 is a diagram illustrating the flow of the authentication process when the image processing device 3 sends and receives e-mail. First, an administrator accesses the authentication server 8 from the image processing device 3 by operating the operation panel 14 of the image processing device 3, and transmits an authorization request D10 from the image processing device 3 to the authentication server 8 (process P1). Upon receiving the authorization request D10, the authentication server 8 registers the image processing device 3, which is the sender of the authorization request D10, as an authorized device, and issues an access token TK1 and a refresh token TK2, which are transmitted to the image processing device 3 (process P2). At this time, for example, identification information capable of identifying the image processing device 3 registered as the authorized device is embedded in the access token TK1 and the refresh token TK2. Furthermore, an expiration date is set for each of the access token TK1 and the refresh token TK2. The expiration date of the access token TK1 is set to a short period of time, for example, several minutes to several tens of minutes. In contrast, the expiration date of the refresh token TK2 is set to a longer period than that of the access token TK1, for example, approximately six months. Upon receiving the access token TK1 and the refresh token TK2 from the authentication server 8, the image processing device 3 stores and holds them internally (process P3).
[0034] When the image processing device 3 detects, for example, by its email sending / receiving function, that it is time to receive an email, it sends a processing request D11 to the mail server 7 requesting that an email be received (process P4). This processing request D11 is accompanied by an access token TK1 held by the image processing device 3. The processing request D11 also includes information that can identify the email account of the image processing device 3.
[0035] When the mail server 7 receives the processing request D11 from the image processing device 3, it extracts the access token TK1 included in the processing request D11 and sends the access token TK1 to the authentication server 8 (process P5). When the authentication server 8 receives the access token TK1 from the mail server 7, it verifies whether the access token TK1 is identical to the access token TK1 already issued to the image processing device 3 and sends the verification result D12 to the mail server 7 (process P6). Based on the verification result D12, the mail server 7 determines whether the authentication server 8 has verified that the access token TK1 is valid. If the access token TK1 is valid, the mail server 7 executes processing based on the processing request D11 (process P7). Then, the mail server 7 sends the processing result D13 to the image processing device 3 (process P8). That is, the mail server 7 executes processing according to the processing request D11 by sending emails received in the email account of the image processing device 3 to the image processing device 3.
[0036] In the above authentication process, the access token TK1 sent from the image processing device 3 to the mail server 7 has a short expiration date, so even if the access token TK1 is stolen by a third party through wiretapping or the like, the risk of unauthorized access to the email account can be minimized, making it a highly secure authentication process.
[0037] On the other hand, when the access token TK1 expires, the image processing device 3 will no longer be able to access the mail server 7 and will therefore no longer be able to send or receive e-mails. To prevent this, the image processing device 3 refreshes the access token TK1 using the refresh token TK2.
[0038] 3 is a diagram illustrating the process of refreshing the access token TK1 using the refresh token TK2. The image processing device 3 transmits the refresh token TK2 to the authentication server 8 at a predetermined timing (process P10). The predetermined timing may be the timing immediately before the access token TK1 expires, the timing when the access token TK1 expires, the timing when it is discovered that the access token TK1 has expired after it has expired, or the timing when an email is sent or received using the email sending / receiving function.
[0039] When the authentication server 8 receives the refresh token TK2 from the image processing device 3, it issues an access token TK1 with a new expiration date and sends the access token TK1 to the image processing device 3 (process P11). Upon receiving the new access token TK1 from the authentication server 8, the image processing device 3 updates the access token TK1 stored therein.
[0040] The image processing device 3 can renew the access token TK1 any number of times by sending the refresh token TK2 to the authentication server 8 as described above until the refresh token TK2 expires. However, once the refresh token TK2 expires, the image processing device 3 will no longer be able to renew the access token TK1. Therefore, the administrator must renew the refresh token TK2 before the refresh token TK2 expires.
[0041] In the information processing system 1 of this embodiment, the frequency of updating the refresh tokens TK2 held by each of the image processing devices 3 a, 3 b, and 3 c is reduced, thereby reducing the workload of the administrator. Such an information processing system 1 will be described in detail below.
[0042] 4 is a block diagram showing an example of the hardware configuration of the image processing device 3. The image processing device 3 includes a control unit 10, a storage unit 13, an operation panel 14, a communication interface 17, a scanner unit 18, a printer unit 19, and a FAX unit 20.
[0043] The control unit 10 includes a CPU 11 and a memory 12, and controls the operation of each unit. The CPU 11 is a hardware processor that reads and executes a program 21 pre-stored in a storage unit 13. The memory 12 is a storage device that provides a work area when the CPU 11 executes the program 21. The storage unit 13 is a non-volatile storage device configured, for example, by a hard disk drive (HDD) or a solid state drive (SSD). In addition to the program 21, the storage unit 13 also stores an access token TK1 and a refresh token TK2 obtained from the authentication server 8.
[0044] The operation panel 14 includes a display unit 15 and an operation unit 16. The display unit 15 is a display device configured, for example, by a color LCD display, and displays various operation screens that can be operated by the user. The operation unit 16 is an operation device configured, for example, by touch panel keys arranged on the screen of the display unit 15 and push button keys arranged around the screen of the display unit 15, and accepts operations by the user. For example, the operation panel 14 displays a job setting screen on the display unit 15 and accepts job setting operations and job execution instructions by the user. When the image processing device 3 accesses the authentication server 8, the operation panel 14 also displays an operation screen provided by the authentication server 8 on the display unit 15 and accepts operations by the administrator. Therefore, by operating the operation panel 14, the administrator can register the image processing device 3 in the authentication server 8 as an authorized device and can also update the refresh token TK2.
[0045] The communication interface 17 connects the image processing device 3 to the local network 4 and communicates with external devices via the local network 4. For example, the control unit 10 communicates with external devices such as the mail server 7 and the authentication server 8 via this communication interface 17.
[0046] The scanner unit 18 optically reads an original document set by a user and generates image data. For example, the image processing device 3 can attach the image data generated by the scanner unit 18 to an email and send it to the outside.
[0047] The printer unit 19 prints and outputs an image based on the data to be printed on a sheet such as printing paper. For example, when data to be printed is attached to a received email, the image processing device 3 can print out based on the data to be printed.
[0048] The FAX unit 20 transmits and receives FAX data via, for example, a public telephone line. For example, the image processing device 3 can generate FAX data from image data generated by the scanner unit 18 and transmit the FAX data to an external device via the FAX unit 20. Furthermore, when the FAX unit 20 receives FAX data from an external device, the image processing device 3 can print out the FAX data using the printer unit 19.
[0049] Fig. 5 is a diagram illustrating an example of the functional configuration of the control unit 10 of the image processing device 3. The CPU 11 of the control unit 10 executes the program 21, causing the control unit 10 to function as multiple processing units shown in Fig. 5. That is, the control unit 10 functions as a job control unit 30, an email application 31, a panel control unit 32, a communication control unit 33, a remote operation reception unit 34, and a token management unit 35.
[0050] The job control unit 30 controls the execution of jobs in the image processing device 3. The job control unit 30 controls the operations of the scanner unit 18, printer unit 19, and FAX unit 20, and causes the jobs specified by the user to be executed. The job control unit 30 also acquires the job settings specified by the user via the panel control unit 32, and causes the jobs to be executed with the settings reflected.
[0051] The email application 31 is an application that sends and receives emails. The email application 31 sends emails to a destination specified by the user via the panel control unit 32. When an email is received, the email application 31 displays the received email on the operation panel 14 via the panel control unit 32. When the received email has data to be printed attached, the email application 31 outputs the data to be printed to the job control unit 30. When the job control unit 30 acquires the data to be printed from the email application 31, it drives the printer unit 19 and performs printing based on the data to be printed.
[0052] When the email application 31 accesses the mail server 7 to send or receive email, it obtains the access token TK1 stored in the storage unit 13 via the token management unit 35. Then, the email application 31 adds the access token TK1 to a processing request D11 and sends it to the mail server 7. The processing request D11 is a command that requests the mail server 7 to send or receive email.
[0053] The panel control unit 32 controls the operation panel 14. For example, the panel control unit 32 displays various operation screens on the display unit 15 of the operation panel 14. When the operation unit 16 detects a user operation, the panel control unit 32 performs processing in accordance with the user operation. For example, the panel control unit 32 updates the operation screen displayed on the display unit 15 based on the user operation. The panel control unit 32 manages multiple operation screens to be displayed on the display unit 15 and can switch the operation screen displayed on the display unit 15 based on the user operation. The multiple operation screens have, for example, a hierarchical structure. Therefore, the user can sequentially change the operation screen displayed on the display unit 15 from the top screen to a lower screen by repeatedly operating the operation unit 16. Furthermore, the panel control unit 32 outputs job settings to the job control unit 30 and instructs the job to be executed based on the user operation. Furthermore, the panel control unit 32 can instruct the email application 31 to send or receive email based on the user operation.
[0054] The panel control unit 32 includes a browser 32a. The browser 32a acquires screen information (web page) provided by a web server and displays a screen based on the screen information on the display unit 15. For example, when registering the image processing device 3 as an authorized device with the authentication server 8, an administrator operates the operation panel 14 to launch the browser 32a and access the authentication server 8. The browser 32a acquires screen information provided by the authentication server 8 and displays a screen based on the screen information on the display unit 15. Therefore, when the administrator operates the screen displayed on the display unit 15 by the browser 32a, an authorization request D10 is transmitted from the image processing device 3 to the authentication server 8, and the image processing device 3 is registered as an authorized device in the authentication server 8. The image processing device 3 then acquires an access token TK1 and a refresh token TK2 from the authentication server 8.
[0055] The communication control unit 33 controls communication with an external device via the communication interface 17. When each unit of the control unit 10 communicates with an external device via the communication interface 17, the communication control unit 33 controls the communication.
[0056] The remote operation reception unit 34 receives remote operations of the image processing device 3. For example, when the remote operation reception unit 34 detects access from an external device, it acquires the operation screen displayed on the display unit 15 by the panel control unit 32 and provides screen information corresponding to the operation screen to the external device. This allows the external device to display the same operation screen as that of the operation panel 14 as a remote operation screen. The remote operation reception unit 34 can also acquire an operation screen specified by the external device from the panel control unit 32. When the panel control unit 32 provides the operation screen to the remote operation reception unit 34, it displays a screen on the display unit 15 of the operation panel 14 indicating that remote operation is in progress, and sets the operation unit 16 to a state in which no operation is being received. This prevents overlapping operations on the operation panel 14 and remote operation by an external device.
[0057] When the remote operation reception unit 34 receives operation information indicating that an operation has been performed on the remote operation screen from an external device, it outputs the operation information to the panel control unit 32. The panel control unit 32 detects the operation performed by the user based on the operation information and performs processing according to the user's operation. In other words, the panel control unit 32 treats the operation information output from the remote operation reception unit 34 in the same way as an operation performed on the operation unit 16 of the operation panel 14. Such functions of the remote operation reception unit 34 enable the image processing device 3 to be remotely controlled by an external device. Therefore, an administrator can remotely control the image processing device 3 by accessing the remote operation reception unit 34 of the image processing device 3 using the information terminal 9.
[0058] The token management unit 35 stores and manages the access token TK1 and refresh token TK2 obtained from the authentication server 8 in the storage unit 13. Furthermore, when the email application 31 requests the access token TK1, the token management unit 35 reads the access token TK1 from the storage unit 13 and provides it to the email application 31. Furthermore, the token management unit 35 manages the expiration date of the access token TK1, and when it detects that a predetermined time has come to refresh the access token TK1, it reads the refresh token TK2 from the storage unit 13 and transmits it to the authentication server 8. Then, the token management unit 35 obtains a new access token TK1 from the authentication server 8 and updates the access token TK1 in the storage unit 13.
[0059] The token management unit 35 is configured to enable the administrator to update the refresh token TK2 at an appropriate time. That is, as shown in Fig. 5, the token management unit 35 includes an expiration date confirmation unit 36, a first identification unit 37, a second identification unit 38, and a notification unit 39, and notifies the administrator to perform an update operation for the refresh token TK2 before the expiration date of the refresh token TK2.
[0060] The expiration date confirmation unit 36 confirms the expiration date of the refresh token TK2 stored in the memory unit 13. For example, the expiration date confirmation unit 36 functions periodically at a predetermined cycle, such as once a day, reads out the refresh token TK2 stored in the memory unit 13, and calculates the remaining period until the expiration date of the refresh token TK2. When the expiration date confirmation unit 36 calculates the remaining period for which the refresh token TK2 is valid, it causes the first identification unit 37 to function.
[0061] The first identification unit 37 determines whether the remaining period of the refresh token TK2 calculated by the expiration date confirmation unit 36 is equal to or shorter than a first period (e.g., seven days). If the remaining period of the refresh token TK2 is equal to or shorter than the first period, the first identification unit 37 determines that the expiration date of the refresh token TK2 held by the image processing device 3 is approaching, and identifies the image processing device 3 as a first update target device. On the other hand, if the remaining period of the refresh token TK2 is longer than the first period, the first identification unit 37 does not identify the image processing device 3 as a first update target device.
[0062] The second identification unit 38 functions when the first identification unit 37 identifies the image processing device 3 as the first update target device. The second identification unit 38 communicates with other image processing devices 3 connected to the local network 4 and acquires the remaining period until the expiration date of the refresh token TK2 held by the other image processing device 3. The second identification unit 38 then determines whether the remaining period of the refresh token TK2 of the other image processing device 3 is equal to or shorter than a second period (e.g., 30 days) that is longer than the first period. If the remaining period of the refresh token TK2 of the other image processing device 3 is equal to or shorter than the second period, the second identification unit 38 identifies the other image processing device 3 as the second update target device. If there are multiple other image processing devices 3 on the local network 4, the second identification unit 38 determines whether each of the multiple other image processing devices 3 is the second update target device. Note that the second identification unit 38 may not identify the second update target device.
[0063] 6 is a diagram showing the remaining period of the refresh token TK2 in the first update target device and the second update target device. As shown in FIG. 6, the first update target device is a device that is identified when the remaining period until the expiration date of the refresh token TK2 is equal to or shorter than the first period T1. In contrast, the second update target device is a device that is identified when the remaining period until the expiration date of the refresh token TK2 is equal to or shorter than the second period T2.
[0064] 1, when multiple image processing devices 3a, 3b, and 3c are connected to the local network 4, the above-described process is performed in each of the multiple image processing devices 3a, 3b, and 3c. Therefore, when it is detected that the remaining time until the expiration date of the refresh token TK2 of one image processing device 3a among the multiple image processing devices 3a, 3b, and 3c is equal to or shorter than the first period T1, the image processing device 3a identifies itself as the first update target. Then, even if the remaining time until the expiration date of the refresh token TK2 of the other image processing devices 3b and 3c is longer than the first period T1, the image processing device 3a identifies the other image processing devices 3b and 3c as the second update target devices if the remaining time is equal to or shorter than the second period.
[0065] The notification unit 39 functions when the first identification unit 37 identifies the image processing device 3 as the first update target device. The notification unit 39 notifies the administrator of the first update target device identified by the first identification unit 37 and the second update target device identified by the second identification unit 38. When the second identification unit 38 does not identify the second update target device, the notification unit 39 notifies the administrator of the first update target device identified by the first identification unit 37. For example, the notification unit 39 starts the email application 31 and sends an email to the administrator to notify the administrator of the first update target device and the second update target device. However, the notification method by the notification unit 39 is not limited to email. For example, the notification unit 39 may send a notification to a server (not shown). In this case, the server sends a push notification to an application (e.g., a remote control application 50 described later) installed on the administrator's information terminal 9, and notifies the administrator of the first update target device and the second update target device via the application when the administrator starts the application. In this way, the notification unit 39 may be any unit that can send a message or the like to the information terminal 9 used by the administrator in some way.
[0066] When notifying the administrator, the notifying unit 39 collects information with which the first update target device can be identified (e.g., device name, installation location, IP address, etc.), address information for accessing the remote operation screen of the first update target device (e.g., URL for accessing the remote operation receiving unit 34), information with which the second update target device can be identified (e.g., device name, installation location, IP address, etc.), and address information for accessing the remote operation screen of the second update target device (e.g., URL for accessing the remote operation receiving unit 34).Then, the notifying unit 39 transmits a notification to the administrator, including the information with which the first update target device can be identified, the address information for accessing the remote operation screen of the first update target device, the information with which the second update target device can be identified, and the address information for accessing the remote operation screen of the second update target device.
[0067] Therefore, upon receiving the notification from the notification unit 39, the administrator can know that the refresh token TK2 held in the image processing device 3 identified as the first update target device is about to expire, and can perform the update work for the refresh token TK2 before the expiration date. Furthermore, if the notification from the notification unit 39 includes information about the second update target device, the administrator can know that the refresh token TK2 held in the image processing device 3 identified as the second update target device is also about to expire. Therefore, when performing the update work for the image processing device 3 identified as the first update target device, the administrator can also simultaneously perform the update work for the image processing device 3 identified as the second update target device. That is, the administrator can perform the update work for multiple image processing devices 3 at once. This reduces the frequency of the update work performed by the administrator, thereby reducing the administrator's workload.
[0068] Furthermore, the image processing device 3 of this embodiment includes the remote operation reception unit 34 as described above. Therefore, when the administrator receives a notification from the notification unit 39, the administrator can operate the information terminal 9 to access the remote operation reception unit 34 and display a remote operation screen on the information terminal 9, thereby updating the refresh token TK2, without having to go to the installation location of the image processing device 3. Therefore, even when the administrator is working remotely in a location different from the office 2, the administrator can update the refresh token TK2 remotely, thereby reducing the administrator's workload.
[0069] FIG. 7 is a flowchart showing an example of a processing procedure performed by the token management unit 35. The token management unit 35 executes the processing shown in FIG. 7 periodically at a predetermined cycle, such as once a day. When starting this processing, the token management unit 35 checks the expiration date of the refresh token TK2 stored in the storage unit 13 (step S10) and calculates the remaining period Tp (step S11). The token management unit 35 compares the remaining period Tp with the first period T1 and determines whether the remaining period Tp is equal to or shorter than the first period T1 (step S12). As a result, if the remaining period Tp is longer than the first period T1 (NO in step S12), the processing by the token management unit 35 ends.
[0070] If the remaining period Tp is equal to or shorter than the first period T1 (YES in step S12), the token management unit 35 identifies itself as a first update target device (step S13). Subsequently, the token management unit 35 communicates with the other image processing device 3, checks the expiration date of the refresh token TK2 held by the other image processing device 3 (step S14), and calculates the remaining period Tq (step S15). The token management unit 35 compares the remaining period Tq with the second period T2 and determines whether the remaining period Tq is equal to or shorter than the second period T2 (step S16). If the remaining period Tq is equal to or shorter than the second period T2 (YES in step S16), the token management unit 35 identifies the other image processing device 3 with which it has communicated as a second update target device (step S17). On the other hand, if the remaining period Tq is longer than the second period T2 (NO in step S16), the token management unit 35 does not identify the other image processing device 3 as a second update target device.
[0071] Next, the token management unit 35 determines whether or not another image processing device 3 exists on the local network 4 (step S18). If another image processing device 3 exists (YES in step S18), the processing by the token management unit 35 returns to step S14, and the above-described processing is repeated for the other image processing device 3.
[0072] If there is no other image processing device 3 with which communication is not being performed (NO in step S18), the token management unit 35 determines whether or not a second update target device has been identified (step S19). As a result, if a second update target device has been identified (YES in step S19), the token management unit 35 generates address information for accessing the remote operation screen of its own device, which is the first update target device, and address information for accessing the remote operation screen of the image processing device 3 identified as the second update target device (step S20). Then, the token management unit 35 notifies the administrator of the first update target device and the second update target device (step S21). This notification includes the address information generated in step S20.
[0073] On the other hand, if the second update target device has not been identified (NO in step S19), the token management unit 35 generates only address information for accessing the remote operation screen of its own device, which is the first update target device (step S22).The token management unit 35 then notifies the administrator of the first update target device (step S23).This notification includes the address information generated in step S22.
[0074] By periodically performing the above-described processing by the token management unit 35 of the image processing device 3, when the remaining period Tp of the refresh token TK2 held by the image processing device 3 becomes equal to or less than the first period T1, if there is another image processing device 3 whose remaining period Tq of the refresh token TK2 is equal to or less than the second period T2, the image processing device 3 and the other image processing device 3 whose remaining period Tq is equal to or less than the second period T2 will be notified to the administrator at the same time as the image processing device 3 itself as devices whose refresh token TK2 needs to be updated.
[0075] Next, FIG. 8 is a block diagram showing an example of the hardware configuration and functional configuration of the information terminal 9. The information terminal 9 includes a control unit 40, a storage unit 41, a display unit 42, an operation unit 43, and a communication interface 44. The control unit 40 includes a CPU and memory (not shown). The CPU reads and executes a program 45 stored in the storage unit 41, causing the control unit 40 to function as a remote control application 50. The storage unit 41 is a non-volatile storage device such as a hard disk drive (HDD) or a solid state drive (SSD), and stores the program 45 in advance. The display unit 42 is a display device such as a liquid crystal display. The operation unit 43 is configured with a keyboard, a mouse, or touch panel keys, and accepts operations by a user. The communication interface 44 connects the information terminal 9 to a network and enables communication with external devices such as the image processing device 3.
[0076] The remote control application 50 is an application that communicates with the image processing device 3 and remotely controls the image processing device 3. For example, the remote control application 50 may be a dedicated application for remotely controlling the image processing device 3, or may be a general-purpose application such as a browser. For example, the remote control application 50 is started in the control unit 40 when an administrator issues an instruction to start the application. When the image processing device 3 sends a notification to the administrator via email, the information terminal 9 receives the email using an email application (not shown) and displays it on the display unit 42. The email contains address information for accessing the remote control screens of the first and second update target devices. Therefore, when the administrator selects the address information and starts the remote control application 50, the remote control application 50 acquires the address information upon startup.
[0077] The remote control application 50 includes a screen acquisition unit 51, a display processing unit 52, and an operation information transmission unit 53. The screen acquisition unit 51 accesses the remote operation reception units 34 of the first update target device and the second update target device based on address information acquired when the remote control application 50 is started, and acquires a remote operation screen. The display processing unit 52 displays the remote operation screen acquired by the screen acquisition unit 51 on the display unit 42. Furthermore, when the operation information transmission unit 53 detects an operation by an administrator on the operation unit 43 while the remote operation screen is displayed on the display unit 42, it generates operation information based on the operation and transmits the operation information to the image processing device 3 that is the provider of the remote operation screen.
[0078] Here, when the notification unit 39 of the image processing device 3 notifies the administrator, it is preferable to generate address information including a path for directly reaching the remote operation screen for updating the refresh token TK2 of each of the first update target device and the second update target device. By including a path for directly reaching the remote operation screen for updating the refresh token TK2 in the address information, the screen acquisition unit 51 can directly acquire the remote operation screen for updating the refresh token TK2 from each of the first update target device and the second update target device. Therefore, the administrator does not need to perform operations in order from the top screen in the hierarchical structure, and can perform work efficiently.
[0079] Furthermore, when acquiring the remote control screen, the screen acquisition unit 51 may access the first update target device and the second update target device one by one in sequence, or may access the first update target device and the second update target device simultaneously.
[0080] FIG. 9 illustrates an example of a screen G1 displayed on the display unit 42 when the screen acquisition unit 51 sequentially accesses the first and second update target devices. The screen G1 includes a display area R1 displaying a remote operation screen acquired from one image processing device 3. The screen G1 also includes a button B1 for switching the remote operation screen displayed in the display area R1 to a remote operation screen acquired from another image processing device 3. For example, when the screen acquisition unit 51 directly acquires a remote operation screen for updating the refresh token TK2 from the image processing device 3 identified as the first update target device, the remote operation screen for updating the refresh token TK2 is displayed in the display area R1 of the screen G1. FIG. 9 illustrates an example in which the remote operation screen for updating the refresh token TK2 is an email setting screen. The email setting screen displays information indicating that the refresh token TK2 has already been acquired and the expiration date of the refresh token TK2. To the right of the expiration date, an update button 58 is displayed, which the administrator can operate to update the refresh token TK2.
[0081] FIG. 10 shows a process in which the administrator updates the refresh token TK2 by operating the information terminal 9. When the administrator operates the update button 58 displayed on the information terminal 9, operation information D15 corresponding to the operation is transmitted from the information terminal 9 to the image processing device 3, which is the first update target device (process P20). When the remote operation reception unit 34 of the image processing device 3 receives the operation information D15, the panel control unit 32 starts the browser 32a (process P21). Then, the browser 32a accesses the authentication server 8 (process P22). When the authentication server 8 detects the access from the browser 32a, it transmits an authentication screen D16 (process P23). The remote operation reception unit 34 generates a remote operation screen D17 based on the authentication screen D16 acquired by the browser 32a from the authentication server 8, and transmits the generated screen to the information terminal 9 (process P24). Therefore, the authentication screen provided by the authentication server 8 is displayed as the remote operation screen on the display unit 42 of the information terminal 9. When the administrator enters authentication information such as an ID and a password on the remote operation screen, authentication information D18 is sent from the information terminal 9 to the image processing device 3 (process P25). The remote operation reception unit 34 passes the authentication information D18 to the browser 32a of the panel control unit 32. The browser 32a then sends the authentication information D18 to the authentication server 8 (process P26). Upon receiving the authentication information D18, the authentication server 8 performs an authentication process to compare the received authentication information with the authentication information used when the image processing device was registered as an authorized device (process P27). If the authentication server 8 verifies that the request is from an authorized device in the authentication process, it issues a refresh token TK2 with a new expiration date set, and sends the refresh token TK2 to the image processing device 3 (process P28). Upon receiving the new refresh token TK2 from the authentication server 8, the image processing device 3 updates the refresh token TK2 stored in the storage unit 13 with the new refresh token TK2 (process P29).
[0082] When the expiration date of the refresh token TK2 is updated as described above, the expiration date of the refresh token TK2 displayed on the remote operation screen in the display area R1 of the screen G1 in FIG. 9 is updated to the new expiration date. Therefore, the administrator can remotely update the expiration date of the refresh token TK2 held in the image processing device 3. After completing the update of the refresh token TK2 for the image processing device 3 identified as the first update target device, the administrator operates the button B1 displayed on the screen G1. The screen acquisition unit 51 then accesses the image processing device 3 identified as the second update target device and acquires a remote operation screen for updating the refresh token TK2 from the image processing device 3. As a result, the remote operation screen for the image processing device 3 identified as the second update target device is displayed in the display area R1 of the screen G1. The administrator can also update the refresh token TK2 for the image processing device 3 identified as the second update target device by performing the same operation on the screen G1 as described above.
[0083] Furthermore, when multiple image processing devices 3 are identified as second update target devices, the administrator can operate button B1 to sequentially display in display area R1 remote operation screens acquired from the multiple image processing devices 3. Therefore, as shown in Fig. 11, the administrator can perform remote operations on the multiple image processing devices 3a, 3b, and 3c as a series of operations, and can simultaneously update the refresh tokens TK2 held by each of the multiple image processing devices 3a, 3b, and 3c in a single update operation.
[0084] Furthermore, when multiple image processing devices 3 are identified as second update target devices, the screen acquisition unit 51, in response to button B1 being operated while the remote operation screen of the first update target device is displayed, preferentially accesses the image processing device 3 with the shortest remaining period until the expiration date of the refresh token TK2 and acquires the remote operation screen. This allows the remote operation screens to be displayed in the display area R1 in order of the period remaining until the expiration date of the refresh token TK2. Therefore, by operating button B1, the administrator can perform the update work on the image processing device 3 in order of the period remaining until the expiration date of the refresh token TK2.
[0085] Next, FIG. 12 is a diagram illustrating an example of a screen G2 displayed on the display unit 42 when the screen acquisition unit 51 simultaneously accesses each of the first and second update target devices. This screen G2 has a display area R2 that displays multiple remote operation screens acquired simultaneously from multiple image processing devices 3 as tab screens. In FIG. 12, three tabs TB1, TB2, and TB3 are displayed. The administrator can switch the remote operation screen displayed in the display area R2 by selecting one of the three tabs TB1, TB2, and TB3. When displaying the screen G2 shown in FIG. 12, the display processing unit 52 arranges the tabs TB1, TB2, and TB3 in a predetermined direction (e.g., from left to right) in order of the shortest remaining period of the refresh token TK2, and displays the remote operation screen of the first update target device with the shortest remaining period in the display area R2. This allows the administrator to perform update work among the multiple remote operation screens in order of the shortest remaining period.
[0086] 12, similar to FIG. 9, illustrates an example in which the remote operation screen for updating the refresh token TK2 is an email setting screen. This remote operation screen displays an update button 58 that the administrator can operate to update the refresh token TK2. When the administrator operates this update button 58, the administrator can update the refresh token TK2 through the same process as described above.
[0087] For example, in screen G1 shown in Fig. 9, only one remote operation screen is displayed in display area R1, and the administrator can switch the remote operation screen each time he or she operates button B1. Therefore, when screen G1 is displayed on display unit 42 of information terminal 9, the administrator cannot grasp how many update target devices there are. In contrast, in screen G2 shown in Fig. 12, remote operation screens simultaneously acquired from the first update target device and the second update target device are displayed as tab screens. Therefore, when screen G2 is displayed, the administrator can grasp how many update target devices there are by checking the number of tabs TB1, TB2, and TB3, which is highly convenient in that the administrator can grasp the amount of work required before starting the update work.
[0088] As described above, the information processing system 1 of this embodiment has a configuration for managing the refresh token TK2 held in each of the multiple image processing devices 3 a, 3 b, and 3 c. Specifically, as described above, the information processing system 1 includes: a first identification unit 37 that identifies a first update target device among the multiple image processing devices 3 a, 3 b, and 3 c, whose remaining time until the expiration date of the refresh token TK2 is a first period or less; a second identification unit 38 that, when the first update target device is identified by the first identification unit 37, identifies a second update target device among the multiple image processing devices 3 a, 3 b, and 3 c, whose remaining time until the expiration date of the refresh token TK2 is a second period or less that is longer than the first period; and a notification unit 39 that, when the first update target device is identified by the first identification unit 37, notifies an administrator of the first update target device identified by the first identification unit 37 and the second update target device identified by the second identification unit 38.
[0089] With this configuration, the administrator does not need to check the expiration dates of the refresh tokens TK2 held by each of the image processing devices 3a, 3b, and 3c one by one. Furthermore, when the first identification unit 37 identifies a first update target device whose remaining period is equal to or shorter than the first period, the information processing system 1 notifies the administrator of the first update target device and simultaneously notifies the administrator of second update target devices whose remaining period is equal to or shorter than the second period, which is longer than the first period. Therefore, when the administrator updates a refresh token TK2 whose remaining period is equal to or shorter than the first period, the administrator can simultaneously update a refresh token TK2 whose remaining period is equal to or shorter than the second period. Therefore, the information processing system 1 of this embodiment can reduce the frequency of updating refresh tokens TK2, thereby reducing the administrator's workload.
[0090] Furthermore, the information processing system 1 of this embodiment is configured so that each of the multiple image processing devices 3a, 3b, and 3c can update the refresh token TK2 by remotely operating the image processing device 3a, 3b, and 3c. Therefore, even if the administrator receives a notification from one of the image processing devices 3a, 3b, and 3c while working remotely, the administrator can update the refresh token TK2 remotely without having to go to the office 2 to update the refresh token TK2. Furthermore, even if the administrator is working in the office 2, by connecting the information terminal 9 to the local network 4, the administrator can remotely update the refresh tokens TK2 of the multiple image processing devices 3a, 3b, and 3c from his or her own desk. Therefore, the administrator can update the refresh tokens TK2 without having to travel to the installation locations of the multiple image processing devices 3a, 3b, and 3c, significantly improving work efficiency.
[0091] (Second embodiment) Next, a second embodiment of the present invention will be described. Fig. 13 is a diagram showing an example of the configuration of an information processing system 1 in the second embodiment of the present invention. This information processing system 1 includes a plurality of image processing devices 3a, 3b, and 3c, an information processing device 5, a mail server 7, an authentication server 8, and an information terminal 9. This information processing system 1 differs from the first embodiment in that the information processing device 5 is connected to a local network 4 in an office 2.
[0092] The information processing device 5 is a device that manages the multiple image processing devices 3a, 3b, and 3c, and is configured by, for example, a server or a personal computer. The information processing device 5 can communicate with each of the multiple image processing devices 3a, 3b, and 3c via the local network 4, and manages the expiration dates of the refresh tokens TK2 held by each of the multiple image processing devices 3a, 3b, and 3c.
[0093] Fig. 14 is a block diagram showing an example of the hardware configuration and functional configuration of the information processing device 5. As shown in Fig. 14, the information processing device 5 includes a control unit 60, a storage unit 61, and a communication interface 62. The control unit 60 includes a CPU and a memory (not shown). The CPU reads and executes a program 63 stored in the storage unit 61, causing the control unit 60 to function as a token management unit 64. The storage unit 61 is a non-volatile storage device configured by a hard disk drive (HDD), a solid state drive (SSD), or the like, and stores the program 63 in advance. The communication interface 62 connects the information processing device 5 to the local network 4 and is used to communicate with external devices such as the image processing device 3.
[0094] The token management unit 64 has a configuration that enables an administrator to update the refresh token TK2 held in each of the multiple image processing devices 3a, 3b, and 3c at an appropriate timing. That is, as shown in Fig. 14, the token management unit 64 includes an information collection unit 65, a first identification unit 66, a second identification unit 67, and a notification unit 68, and notifies the administrator to perform an update operation for the refresh token TK2 before the expiration date of the refresh token TK2 held in the multiple image processing devices 3a, 3b, and 3c.
[0095] The information collection unit 65 collects expiration date information relating to the expiration date of the refresh token TK2 from each of the multiple image processing devices 3a, 3b, and 3c. FIG. 15 is a diagram showing an example of information collection by the information collection unit 65. For example, the information collection unit 65 functions periodically at a predetermined cycle, such as once a day, and collects expiration date information D21 for the refresh token TK2 held by each of the multiple image processing devices 3a, 3b, and 3c, as shown in FIG. 15. Then, based on the expiration date information D21, the information collection unit 65 calculates the remaining valid period for the refresh token TK2 held by each of the image processing devices 3a, 3b, and 3c.
[0096] The first identification unit 66 functions after the expiration date information D21 is collected by the information collection unit 65. The first identification unit 66 identifies a first update target device among the multiple image processing devices 3a, 3b, and 3c, whose remaining period until the expiration date of the refresh token TK2 is a first period (e.g., seven days) or less. If there is no device among the multiple image processing devices 3a, 3b, and 3c whose remaining period of the refresh token TK2 is the first period or less, the first identification unit 66 does not identify the first update target device.
[0097] The second identification unit 67 functions when the first identification unit 66 identifies a first update target device. The second identification unit 67 identifies a second update target device among the multiple image processing devices 3a, 3b, and 3c, for which the remaining period until the expiration date of the refresh token TK2 is longer than the first period and is equal to or shorter than a second period longer than the first period. Note that the second identification unit 38 may not identify the second update target device.
[0098] The notification unit 68 functions when the first identification unit 66 identifies the first update target device. The notification unit 68 then notifies the administrator of the first update target device identified by the first identification unit 66 and the second update target device identified by the second identification unit 67. The notification method by the notification unit 68 is the same as that described in the first embodiment. The information included in the notification by the notification unit 68 is also the same as that described in the first embodiment. Therefore, the administrator who has received the notification by the notification unit 68 can update the refresh token TK2 of the image processing device 3 identified as the first update target device and can simultaneously update the refresh token TK2 of the image processing device 3 identified as the second update target device in a series of operations by operating his or her own information terminal 9.
[0099] FIG. 16 is a flowchart showing an example of a processing procedure performed by the information processing device 5. The information processing device 5 executes the processing shown in FIG. 16 periodically at a predetermined cycle, such as once a day. When starting this processing, the information processing device 5 collects expiration date information D21 from each of the multiple image processing devices 3a, 3b, and 3c (step S30). Next, the information processing device 5 determines whether or not there is an image processing device 3 whose remaining period of the refresh token TK2 is equal to or shorter than the first period (step S31). If there is no image processing device 3 whose remaining period is equal to or shorter than the first period (NO in step S31), the processing by the information processing device 5 ends.
[0100] If there is an image processing device 3 whose remaining period is the first period or less (YES in step S31), the information processing device 5 identifies the image processing device 3 whose remaining period is the first period or less as a first update target device (step S32). Next, the information processing device 5 determines whether or not there is an image processing device 3 whose remaining period is the second period or less among the image processing devices 3 other than the first update target device (step S33).
[0101] If there is an image processing device 3 whose remaining period is the second period or less (YES in step S33), the information processing device 5 identifies the image processing device 3 whose remaining period is the second period or less as a second update target device (step S34). Next, the information processing device 5 generates address information for accessing the remote operation screen of its own device, which is the first update target device, and address information for accessing the remote operation screen of the image processing device 3 identified as the second update target device (step S35). Then, the information processing device 5 notifies the administrator of the first update target device and the second update target device (step S36). This notification includes the address information generated in step S35.
[0102] On the other hand, if there is no image processing device 3 whose remaining period is less than the second period (NO in step S33), the information processing device 5 generates only address information for accessing the remote operation screen of its own device, which is the first update target device (step S37).The information processing device 5 then notifies the administrator of the first update target device (step S38).This notification includes the address information generated in step S37.
[0103] By periodically performing the above-mentioned processing by the information processing device 5, when there is a first update target device among the multiple image processing devices 3 whose remaining period of the refresh token TK2 is less than the first period, and there is a second update target device among the other image processing devices 3 whose remaining period of the refresh token TK2 is less than the second period, the administrator will be notified of the second update target device whose remaining period is less than the second period together with the first update target device.
[0104] Therefore, the administrator can simultaneously perform a series of operations to update the refresh token TK2 of the first update target device whose remaining period is equal to or less than the first period and to update the refresh token TK2 of the second update target device whose remaining period is equal to or less than the second period. This reduces the frequency with which the administrator must perform update operations, thereby reducing the administrator's workload.
[0105] As described above, the information processing system 1 of this embodiment includes an information processing device 5 that manages the refresh token TK2 held in each of the multiple image processing devices 3 a, 3 b, and 3 c. The information processing device 5 includes a first identification unit 66 that identifies a first update target device among the multiple image processing devices 3 a, 3 b, and 3 c, whose remaining time until the expiration date of the refresh token TK2 is a first period or less, a second identification unit 67 that, when the first update target device is identified by the first identification unit 66, identifies a second update target device among the multiple image processing devices 3 a, 3 b, and 3 c, whose remaining time until the expiration date of the refresh token TK2 is a second period or less that is longer than the first period, and a notification unit 68 that, when the first update target device is identified by the first identification unit 66, notifies an administrator of the first update target device identified by the first identification unit 66 and the second update target device identified by the second identification unit 67.
[0106] With this configuration, the administrator does not need to check the expiration dates of the refresh tokens TK2 held by each of the image processing devices 3a, 3b, and 3c. Furthermore, when the first identification unit 66 identifies a first update target device whose remaining period is equal to or shorter than the first period, the information processing device 5 notifies the administrator of the first update target device and simultaneously notifies the administrator of second update target devices whose remaining period is equal to or shorter than the second period, which is longer than the first period. Therefore, when the administrator updates a refresh token TK2 whose remaining period is equal to or shorter than the first period, the administrator can simultaneously update a refresh token TK2 whose remaining period is equal to or shorter than the second period. Therefore, the information processing system 1 according to this embodiment can reduce the frequency of updating refresh tokens TK2, thereby reducing the administrator's workload.
[0107] Furthermore, similar to the first embodiment, the information processing system 1 of this embodiment is configured such that the refresh token TK2 can be updated by remotely operating each of the multiple image processing devices 3a, 3b, and 3c using the information terminal 9. Therefore, even if the administrator receives a notification from the information processing device 5 while working remotely, the administrator can remotely update the refresh token TK2 without having to go to the office 2 to update the refresh token TK2. Furthermore, even if the administrator is working in the office 2, by connecting the information terminal 9 to the local network 4, the administrator can remotely update the refresh tokens TK2 of the multiple image processing devices 3a, 3b, and 3c from his or her desk. Therefore, the administrator can update the refresh tokens TK2 without having to travel to the installation locations of the multiple image processing devices 3a, 3b, and 3c, significantly improving work efficiency.
[0108] The configuration and operation of this embodiment other than those described above are the same as those described in the first embodiment.
[0109] (Variation) Although several preferred embodiments of the present invention have been described above, the present invention is not limited to the above-described embodiments, and various modifications are possible.
[0110] For example, in the above embodiment, the image processing device 3 uses the access token TK1 and the refresh token TK2 to access the mail server 7 and send and receive e-mails. However, the image processing device 3 may use the access token TK1 and the refresh token TK2 not only for sending and receiving e-mails. In other words, the image processing device 3 may use the access token TK1 and the refresh token TK2 issued by the authentication server 8 to access a resource server other than the mail server 7 and enjoy resource services.
[0111] In the above embodiment, the case where the device that holds the access token TK1 and the refresh token TK2 is the image processing device 3 configured by an MFP has been exemplified. However, the device that holds the access token TK1 and the refresh token TK2 is not limited to the image processing device 3.
[0112] In the above embodiment, the administrator updates the refresh token TK2 used in the OAuth 2.0 authentication method. However, the above-described method for updating the refresh token TK2 can also be used to update tokens (authentication information) used in authentication methods other than OAuth 2.0.
[0113] In the above embodiment, an example has been described in which the administrator remotely updates the refresh token TK2 of the image processing device 3 using the information terminal 9. However, this is not limiting, and the administrator can also update the refresh token TK2 by operating the operation panel 14 mounted on the image processing device 3. The operation panel 14 may also be equipped with the functions of the information terminal 9 described above. By providing the operation panel 14 with the functions of the information terminal 9, the administrator can simultaneously perform update operations for each of multiple image processing devices 3 as a series of operations by operating the operation panel 14 of one image processing device 3.
[0114] In the second embodiment, an example configuration has been described in which the information processing device 5 includes the first identification unit 66, the second identification unit 67, and the notification unit 68. However, the information processing device 5 may be configured to include the first identification unit 66 and the second identification unit 67, and the function of the notification unit 68 may be installed in each of the multiple image processing devices 3a, 3b, and 3c. In this case, when the information processing device 5 identifies the first update target device using the first identification unit 66, the information processing device 5 may cause the notification unit 68 of the image processing device 3 identified as the first update target device to function and cause the notification unit 68 to perform processing to notify the administrator of the first update target device and the second update target device.
[0115] In the above embodiment, the programs 21, 45, and 63 are stored in advance in the storage units 13, 41, and 61. However, the programs 21, 45, and 63 may be installed in the image processing device 3, the information terminal 9, or the information processing device 5, for example, via the local network 4. In this case, the programs 21, 45, and 63 are provided in a downloadable form via the Internet or the like. However, the programs 21, 45, and 63 may be provided in a form recorded on a computer-readable recording medium such as a CD-ROM or a USB memory. [Explanation of symbols]
[0116] 1. Information Processing Systems 3(3a,3b,3c) Image processing device 5. Information processing equipment 21,45,63 Program 34 Remote Control Reception 35,64 Token Management Unit 36 Expiration date confirmation section 37,66 1st specific part 38,67 Second Specific Part 39,68 Notification Department 65 Information Gathering Department TK1 Access Token TK2 Refresh Token
Claims
1. An information processing system for managing tokens held by a plurality of devices, a first identification means for identifying a first update target device among the plurality of devices, the first update target device having a remaining period until the expiration date of the token that is equal to or shorter than a first period; a second identification means for, when the first identification means has identified the first update target device, identifying a second update target device among the plurality of devices, the second update target device having a remaining period until the expiration date of the token that is equal to or shorter than a second period that is longer than the first period; a notification unit that notifies an administrator of the first update target device and the second update target device when the first update target device is identified by the first identification unit; An information processing system comprising:
2. 2. The information processing system according to claim 1, wherein the notification means transmits a notification to an administrator, the notification including address information for accessing the remote operation screens of the first update target device and the second update target device.
3. further comprising an information terminal capable of communicating with each of the plurality of devices; The information processing system described in claim 2, characterized in that when the first update target device detects access from the information terminal based on the address information, it provides its own remote operation screen to the information terminal and updates the expiration date of the token based on operations performed by the information terminal.
4. The information processing system described in claim 3, characterized in that the information terminal displays a remote operation screen of the second update target device based on operation by an administrator after updating the expiration date of the token held in the first update target device.
5. further comprising an information terminal capable of communicating with each of the plurality of devices; each of the first update target device and the second update target device provides a respective remote operation screen to the information terminal when detecting access from the information terminal based on the address information; 3. The information processing system according to claim 2, wherein the information terminal displays a plurality of remote operation screens acquired from the first update target device and the second update target device as a plurality of tab screens.
6. 6. The information processing system according to claim 5, wherein the plurality of tab screens are arranged in a predetermined direction in order of the shortest remaining period until the expiration date of the tokens held by each of the first update target device and the second update target device.
7. 7. The information processing system according to claim 2, wherein the address information includes a path for directly reaching a remote operation screen for updating the token.
8. 8. The information processing system according to claim 1, wherein the token is authentication information used for authentication when sending and receiving e-mail.
9. 9. The information processing system according to claim 1, wherein the token is a refresh token used to update an access token.
10. 10. The information processing system according to claim 1, wherein each of the plurality of devices is an image processing device having an email sending / receiving function.
11. 11. The information processing system according to claim 1, wherein each of the plurality of devices comprises the first specifying means, the second specifying means, and the notifying means.
12. an information processing device capable of communicating with each of the plurality of devices; 11. The information processing system according to claim 1, wherein the information processing device comprises the first specifying unit, the second specifying unit, and the notifying unit.
13. An image processing device that holds a token with an expiration date set thereto, a first identification means for identifying the device itself as a first update target device when the remaining period until the expiration date of the token is equal to or shorter than a first period; a second identification means for, when the first identification means has identified the image processing device itself as the first update target device, identifying, from other image processing devices with which communication is possible, a second update target device for which the remaining period until the expiration date of a token held by the other image processing device is equal to or shorter than a second period that is longer than the first period; a notification means for notifying an administrator of the first update target device and the second update target device when the first identification means identifies the own device as the first update target device; An image processing device comprising:
14. An information processing device that can communicate with each of a plurality of devices and manages tokens held by each of the plurality of devices, a first identification means for identifying a first update target device among the plurality of devices, the first update target device having a remaining period until the expiration date of the token that is equal to or shorter than a first period; a second identification means for, when the first identification means has identified the first update target device, identifying a second update target device among the plurality of devices, the second update target device having a remaining period until the expiration date of the token that is equal to or shorter than a second period that is longer than the first period; a notification unit that notifies an administrator of the first update target device and the second update target device when the first update target device is identified by the first identification unit; An information processing device comprising:
15. A program executed on a computer that manages tokens held by each of a plurality of devices, the program comprising: a first identification step of identifying a first update target device from among the plurality of devices, the first update target device having a remaining period until the expiration date of the token that is equal to or shorter than a first period; a second identification step of identifying, when the first update target device is identified by the first identification step, a second update target device among the plurality of devices, the second update target device having a remaining period until the expiration date of the token that is equal to or shorter than a second period that is longer than the first period; a notification step of notifying an administrator of the first update target device and the second update target device when the first update target device is identified by the first identification step; A program characterized by executing the following.
Citation Information
Patent Citations
Network-compatible peripheral equipment, program and recording medium
JP2006171914A
Relay device, system, and program
JP2015176546A
System
JP2016143164A
Information processing device and information processing program
JP2019061324A