System, information processing device and control method thereof
The system ensures authenticity of printed materials by embedding identification information in print data and registering it on a blockchain, addressing the lack of direct blockchain integration in image forming devices.
Patent Information
- Application Number
- JP2021150165
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-15
- Publication Date
- 2025-08-28
- Estimated Expiration
- 2041-09-15
AI Technical Summary
Image forming devices without direct blockchain linking functionality cannot guarantee the authenticity of printed materials.
A system comprising an information processing device with a virtual printer driver and a blockchain device that embeds identification information in print data and registers it on a blockchain, ensuring authenticity through a transaction process.
Guarantees the authenticity of printed materials even for devices lacking direct blockchain integration.
Smart Images

Figure 0007730701000005 
Figure 0007730701000006 
Figure 0007730701000007
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technology for ensuring the authenticity of printed materials using blockchain. [Background technology]
[0002] Blockchain technology is known as a technology with excellent tamper resistance, making it nearly impossible to delete or falsify registered data. It is known that the use of blockchain can prevent unauthorized changes to electronic data (see Patent Document 1). [Prior art documents] [Patent documents]
[0003] [Patent Document 1] Japanese Patent Application Publication No. 2018-128823 Summary of the Invention [Problem to be solved by the invention]
[0004] One possible service would be one in which an image forming device equipped with a scanner and printer works with a blockchain service to guarantee the authenticity of printed materials. In one example of such a service, the image forming device registers document identification information and evidence information for the printed material (such as when and who printed it) with the blockchain service. The image forming device embeds the document identification information in the print data and prints it. In this assumed service, the recipient of the printed document can extract the document identification information from the document and query the blockchain service to confirm the authenticity of the document.
[0005] In a service that uses blockchain to guarantee the authenticity of printed materials, image forming devices need the ability to embed information in print data and to link with blockchain services. However, some image forming devices already in use do not have these functions, and therefore cannot perform printing that guarantees authenticity.
[0006] The present invention aims to make it possible to guarantee the authenticity of data from an image forming device even if it does not have the function of directly linking with a blockchain service. [Means for solving the problem]
[0007] In order to solve the above problem, there is provided a system comprising an information processing device and a blockchain device, wherein the information processing device: The virtual driver includes a virtual printer driver. an embedding instruction means for instructing an external device to embed identification information in print data; a receiving means for receiving, from the external device, identification information relating to the print data and the print data in which the identification information is embedded; The identification information regarding the print data is registered in the block chain device as a transaction. do The information processing device is caused to execute a registration instruction means for issuing instructions, and a transmission means for transmitting a print job of print data embedded with the identification information received from the external device to an image forming device, and the blockchain device has a registration means for generating a transaction based on the identification information and registering it in a block, and the virtual driver and the printer driver work together so that a single print instruction from a user generates a printed material and registers a block related to the generated printed material. [Effects of the Invention]
[0008] It is possible to guarantee the authenticity of data from image forming devices even if they do not have the functionality to directly link with blockchain services. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram illustrating a system configuration. [Figure 2] FIG. 2 is a diagram illustrating a hardware configuration of an image forming apparatus. [Figure 3] FIG. 1 illustrates a hardware configuration of an information processing apparatus and a document management apparatus. [Figure 4] FIG. 2 is a diagram illustrating a software configuration of the information processing device. [Figure 5] FIG. 2 is a diagram illustrating a software configuration of the print data generating device. [Figure 6] FIG. 1 is a diagram illustrating the software configuration of a blockchain device. [Figure 7] FIG. 10 is a diagram illustrating the data structure of a blockchain device. [Figure 8] 10 is an example of a screen for installing a virtual driver that issues credentials. [Figure 9] FIG. 10 is a sequence diagram of credential issuance in the first embodiment. [Figure 10] 10 is a flowchart showing a credential issuing process of the print data generating device according to the first embodiment. [Figure 11] This is an example of a virtual driver and printing app screen. [Figure 12] FIG. 10 is a sequence diagram of printing to guarantee authenticity in the first embodiment. [Figure 13] 4 is a flowchart showing a print data generation process of the print data generating device according to the first embodiment. [Figure 14] 1 is a flowchart showing a transaction registration process of the block chain device according to the first embodiment. [Figure 15] This is an example of a verification app screen. [Figure 16] FIG. 10 is a sequence diagram of verification in the first embodiment. [Figure 17] 10 is a flowchart showing information extraction processing of the print data generating device. [Figure 18] 10 is a flowchart showing the ledger reference process of a blockchain device. [Figure 19] FIG. 10 is a sequence diagram of printing to guarantee authenticity in the second embodiment. [Figure 20] 10 is a flowchart showing a print data generation process of a print data generating device according to a second embodiment. [Figure 21] FIG. 11 is a sequence diagram of credential issuance in the third embodiment. [Figure 22] 11 is a flowchart showing a print data generation process of a print data generating device according to a third embodiment. [Figure 23] FIG. 11 is a sequence diagram of verification in the third embodiment. [Figure 24] 10 is a flowchart showing a transaction registration process of the block chain device according to the fourth embodiment. [Figure 25] 10 is a flowchart showing a verification process of the block chain device according to the fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0010] [Example 1] First, we will explain the service that guarantees the authenticity of data and printed materials. Guaranteeing authenticity in this service means proving that electronic data or printed materials are genuine based on information that uniquely identifies them. Information about electronic data or printed materials includes evidence of when, who, what, and how, as well as document content information when the evidence information was saved. Because information about electronic data and printed materials is used to prove authenticity, it must be highly tamper-resistant. Therefore, this service manages information about electronic data and printed materials using blockchain, which is known to be highly tamper-resistant. The benefit of this service is that a third party (this service) guarantees the information about electronic data and printed materials, allowing the owners of the electronic data and printed materials to prove their authenticity. Furthermore, users who receive electronic data or printed materials can confirm their authenticity.
[0011] An embodiment of the present invention will be described below with reference to the drawings. FIG. 1 is an overall view of a printing system in this embodiment. An image forming device 101, an information processing device 102, and a document management device 103 are connected to a LAN 100 and exist within an intranet, and communicate with a print data generation device 111 and a block chain device 112 via the Internet 110. The image forming device 101 is a device equipped with printing and scanning functions. The information processing device 102 is a device operated by a user, and receives instructions for authenticating printing (hereinafter referred to as authenticity-guaranteed printing) and verifying printed materials, requests processing from each device via the LAN 100, and provides functions for displaying results and errors to the user. The document management device 103 is a device that stores electronic data generated by the image forming device 101 and the information processing device 102, and provides document management services.
[0012] When a print data generation device (external device) 111 receives a request to generate print data, it issues document identification information to be registered in the blockchain device 112 and provides a service of embedding the document identification information into the print data. Also, when it receives a request to extract information (extraction instruction), it provides a service of extracting the embedded information from the electronic data.
[0013] The blockchain device 112 is a device that stores and provides document identification information (identification information) that uniquely identifies electronic data and printed materials in blockchain format, and provides a blockchain service to guarantee the authenticity of documents. The services provided by the blockchain device 112, document management device 103, and print data generation device 111 may be provided as a single device by virtualizing multiple computers. Therefore, when we refer to a blockchain system, document management system, or print data generation system, we mean a system made up of one or more devices.
[0014] In addition, in this embodiment, two types of network configurations, the Internet 110 and LAN 100, are used, but all devices may be connected to either one of the networks, and there are no restrictions on configurations using network types other than these.
[0015] 2 is a block diagram showing the hardware configuration of the image forming apparatus 101. A control unit 200 including a CPU 201, which is a central processing unit, controls the overall operation of the image forming apparatus 101. The CPU 201 reads control programs stored in a ROM 202, which is read-only memory, and performs various controls such as reading control and transmission control. A RAM 203, which is random access memory, is used as a temporary storage area such as the main memory and work area of the CPU 201. A HDD 204, which is a hard disk drive, stores image data, various programs, and various data described below. The image forming apparatus 101 has the hardware configuration of an information processing apparatus, but in addition to this, it also has the following hardware configuration.
[0016] An operation unit I / F 205 connects an operation unit 209 and the control unit 200. A printer I / F 206 connects a printer 210 and the control unit 200. Image data to be printed by the printer 210 is transferred from the control unit 200 via the printer I / F 206, and is printed on a recording medium by the printer 210. A scanner I / F 207 connects a scanner 211 and the control unit 200. The scanner 211 reads an image on a document, generates image data, and inputs the image data to the control unit 200 via the scanner I / F 207.
[0017] The network I / F 208 connects the control unit 200 (image forming apparatus 101) to the LAN 100. The network I / F 208 transmits image data and information to external devices on the LAN 100 and receives various types of information from external devices on the LAN 100.
[0018] FIG. 3 is a block diagram showing the hardware configuration of the information processing device 102, document management device 103, print data generation device 111, and block chain device 112. CPU 302 controls the entire device. CPU 302 executes application programs, OS, etc. stored in HDD 305, and controls temporary storage of information, files, etc. required for program execution in RAM 303. ROM 304 is a storage unit that stores various data such as basic I / O programs. RAM 303 is a temporary storage unit that functions as the main memory, work area, etc. of CPU 302. HDD 305 is one of the external storage units that functions as a large-capacity memory and stores applications, OS, related programs, etc.
[0019] A display 306 is a display means that displays commands entered from a keyboard / mouse 307, which is an instruction input unit. An interface 308 is an external device I / F that connects a printer, USB device, and peripheral devices. A system bus 301 controls the flow of data within the device. A network interface card (hereinafter referred to as NIC) 309 exchanges data with external devices via the LAN 100 and the Internet 110.
[0020] The configuration of each device is an example, and is not limited to the configuration examples shown in Figures 2 and 3. For example, the storage destination of data and programs can be changed to ROM 304, RAM 303, HDD 305, etc. depending on the characteristics. Unless otherwise specified in this embodiment, various processes are realized by loading programs stored in ROM 304, etc. into RAM 303, etc., and executing them by CPU 302.
[0021] 4 is a block diagram showing the software configuration related to the present invention in the information processing device 102. The communication unit 401 provides a function for communicating with other devices on the LAN 100. The print processing unit 402 uses the services of the print data generation device 111 and the block chain device 112 via the communication unit 401 and provides a function for issuing print instructions to the printer driver 403. The print processing unit 402 can be provided as a virtual printer driver (hereinafter referred to as a virtual driver) or a print application.
[0022] The printer driver 403 transmits a print job to the image forming apparatus 101 via the communication unit 401 in response to a print instruction. The verification processing unit 404 uses the services of the print data generation device 111 and the block chain device 112 via the communication unit 401 to provide a function for verifying the authenticity of electronic data. The verification processing unit 404 can be provided as a verification application. The verification processing unit 404 may be provided as one of the functions of the above-mentioned print application.
[0023] The credential DB 405 provides a function for managing credential information of the print data generation device 111 and the block chain device 112. When the print processing unit 402 and the verification processing unit 404 use their respective services, the information managed by the credential DB 405 is used for authentication. The credential DB 405 may be prepared as a DB managed by each of the print processing unit 402 and the verification processing unit 404.
[0024] In this embodiment, the print processing unit 402 and verification processing unit 404 are provided to the user as functions of a virtual driver or application, and issue credentials for using each service during installation or when using the print verification function. When issuing credentials, in order to authenticate the virtual driver or application as authentic, the credentials for each service are embedded in the virtual driver or application beforehand and provided to the user. This credential will be described as a credential common to the virtual driver and application (hereinafter referred to as a common credential). The common credential is managed in a credential DB 405.
[0025] Note that the common credential does not need to be common to all virtual drivers and applications. For example, a common credential may be issued and embedded for each version of the virtual driver, and the service side may perform processing to fail authentication if the credential version is too old.
[0026] The credential DB 405 manages not only common credentials but also credentials for using services obtained by issuing credentials (hereinafter referred to as service usage credentials). Service usage credentials are credentials issued by each service for each virtual driver or application, and each service registers user information when issuing them.
[0027] When issuing service usage credentials, the credentials possessed by the user (hereinafter referred to as user credentials) are used to register the user. The user credentials are issued when the user applies to use the service, and the user manages the user credentials using the information processing device 102 or an accessible file server (not shown). The application for use by the user to the service can be made in a general manner, so a description thereof will be omitted.
[0028] The credentials managed by the information processing device 102 have been described above, but the procedure for issuing service usage credentials using common credentials and user credentials will be described later.
[0029] An example of information stored in the credential DB 405 is shown in Table 1.
[0030] [Table 1]
[0031] The credential information table in Table 1 consists of "destination," "purpose," "ID," and "authentication information." In order to manage credentials for multiple services, the credentials for the service to be used are determined by the "destination."
[0032] As described above, the credential DB 405 holds common credentials used for issuing credentials and service use credentials for using services, and is used differently depending on the "purpose."
[0033] "ID" is information that allows a service to uniquely identify a user. "Authentication information" is information that allows a service to authenticate a user. "ID" and "authentication information" are information issued by each service and are used in the authentication process of each service. In this embodiment, they are managed in a single information table, but it is also possible to create and manage credential information tables divided by connection destination or purpose.
[0034] 5 is a block diagram showing the software configuration related to the present invention in the print data generating device 111. A communication unit 501 provides a function for communicating with other devices via the Internet 110. A processing control unit 502 provides a function for executing processing in each processing unit in response to a request received from an external device via the communication unit 501, and for transmitting the processing results to the external device via the communication unit 501.
[0035] The authentication unit 503 is composed of an authentication processing unit 504 and a user information DB 505. The authentication processing unit 504 provides a function for authenticating users who use the service. The user information DB 505 provides a function for storing user information, which is information about users who use the service. An example of user information stored in the user information DB 505 is shown in Table 2.
[0036] [Table 2]
[0037] The user information table in Table 2 consists of "ID," "authentication information," and "user." "ID" is information used to uniquely identify a user. "Authentication information" is information used to authenticate a user. "User" is information used to identify the user of "ID," and one user may be linked to multiple IDs. For example, the user credentials and service usage credentials mentioned above are registered as the same user.
[0038] The document identification information embedding unit 506 generates document identification information and provides a function for embedding the document identification information in print data. The document identification information is information for uniquely referencing registered content in the blockchain. The document identification information extraction unit 507 provides a function for extracting embedded information from electronic data.
[0039] 6 is a block diagram showing the software configuration related to the present invention in the blockchain device 111. The communication unit 601 provides a function for communicating with other devices via the Internet 110. The processing control unit 602 provides a function for executing processing in each processing unit in response to a request received from an external device via the communication unit 601, and for transmitting the processing results to the external device via the communication unit 601.
[0040] The authentication unit 603 is composed of an authentication processing unit 604 and a user information DB 605. The authentication processing unit 604 provides a function for authenticating users who use the service. The user information DB 605 provides a function for storing user information. An example of user information stored in the user information DB 605 is shown in Table 3.
[0041] [Table 3]
[0042] In this embodiment, the configuration of the user information table in Table 3 is the same as that in Table 2. The block data management unit 606 performs blockchain processing such as transaction generation, block generation, writing to the distributed ledger 607, and referencing the distributed ledger 607. The distributed ledger 607 provides the function of storing blocks. Generally, in a blockchain, the ledger is managed by multiple nodes (computers), and the block data management unit 606 may be composed of multiple units.
[0043] The information that may be included in the DB that manages the credential information and user information described in Tables 1, 2, and 3 is not limited to this. For example, the issuance date and expiration date of the credential may also be managed.
[0044] Furthermore, the credential information may be a digital certificate, a key pair of a private key and a public key, or a predetermined data value, and there are no restrictions on the actual form of the credential information. In this embodiment, the credentials of the print data generation device 111 and the block chain device 112 are the same, but they may be different for each device.
[0045] FIG. 7 is a block diagram showing blocks held by the distributed ledger 607 and transactions, which are components of blocks. In this embodiment, transaction 701 includes three pieces of information. As described above, document identification information 702 is information for uniquely referencing registered content in the blockchain. When registering printed matter, document identification information 702 is generated by hashing the electronic data to be printed, the registration date and time, and information about the registrant. In other words, even if the same electronic data is printed, document identification information 702 will be different each time it is printed. When registering electronic data, information obtained by hashing the electronic data is registered as document identification information 702. In other words, the same electronic data cannot be registered multiple times. By doing this, if the content of the electronic data is tampered with, the hash generated from the electronic data will be different, making it impossible to refer to the registered content before the tampering. Therefore, the authenticity of tampered electronic data cannot be proven.
[0046] In this embodiment, the document identification information 702 is generated differently for printed matter and electronic data, but it may be the same. Furthermore, there are no limitations on the method for generating the document identification information 702 as long as it is unique information. For example, it may be a list of date and time or registrant information that is not hashed, or it may be a combination of partially hashed information and a list.
[0047] The next two pieces of information are information about the trail of electronic data and printed matter. Registration date and time 703 is information indicating the time of registration. Registrant 704 is information about the user who made the registration, and for example, the user in Table 3 is entered.
[0048] Although the information included in the transaction in this embodiment has been described, the information that may be included is not limited to this. For example, information regarding the period for which the registered content is guaranteed, information regarding the number of pages to confirm that all pages of the printed material are included, and information regarding the electronic data that is the source of the printed material (hereinafter referred to as the original document) may also be included. Examples of information regarding the original document include a hashed value of the electronic data of the original document, and if it is registered as electronic data in the blockchain, its document identification information. Furthermore, the amount of information used when generating a transaction may be limited to only the document identification information and the registration date and time.
[0049] Next, the structure of a block that holds transactions 701 will be explained using block 705. This is a schematic representation of a general blockchain structure. Block 705 holds multiple transactions 701(a) to 701(c) and a block hash value 706 calculated from these transactions 701. Although the number of transactions 701 included in a block is three, this does not limit the number of transactions.
[0050] Additionally, block 705 holds a hash value 707 of the previous block to link blocks. The hash value of block 708 is stored in the hash value 707 of the previous block, indicating that the blocks are related. When the block next to block 705 is generated, the value of the hash value 706 of the block is set as the hash value of the previous block in the next block. By repeating this process, blocks are linked together, making it difficult to tamper with transaction data. In this embodiment, the hash value of the previous block is used, but it is also possible to manage the hash value of the subsequent block, or to manage the hash values of both the previous and subsequent blocks.
[0051] The procedure for issuing credentials will now be described. The print processing unit 402 uses the common credentials acquired from the credential DB 405 and the user credentials specified by the user to request each service to issue service usage credentials. The procedure for issuing credentials will now be described using as an example the installation of a virtual driver or application that has the functions of the print processing unit 402.
[0052] FIG. 8 is an example of an installation screen when issuing credentials. The installation screen 801 is an installer screen that provides the function of installing a virtual driver or app that has the functions of the print processing unit 402. The blockchain service credential selection field 802 is a field for selecting user credentials for the blockchain service. The print data generation service credential selection field 803 is a field for selecting user credentials for the print data generation service. The issue button 804 is a button for starting the credential issuance process.
[0053] 9 is a sequence diagram of credential issuance in Example 1. This sequence is started when the user presses the above-mentioned issue button 804, and the print processing unit 402, print data generation device 111, and block chain device 112 cooperate to perform processing to obtain service usage credentials for each device.
[0054] In step S901, the user issues an instruction to issue a service usage credential by pressing the issue button 804. Upon receiving the instruction to issue the service usage credential, the print processing unit 402 requests the print data generating device 111 to perform credential issuance processing in step S902. Upon receiving the issuance request, the print data generating device 111 performs service usage credential issuance processing and provides the generated service usage credential to the print processing unit 402. Details of the credential issuance processing in step S902 will be explained later using the flowchart in FIG. 10. Next, in step S903, the print processing unit 402 stores the service usage credential received from the print data generating device 111 in the credential DB 405.
[0055] Next, the print processing unit 402 requests the block chain device 112 to perform credential issuance processing in step S904. Upon receiving the issuance request, the block chain device 112 performs processing to issue a service usage credential and provides the generated service usage credential to the print processing unit 402. Details of the credential issuance processing in step S904 will be explained later using the flowchart in FIG. 10. Next, in step S905, the print processing unit 402 stores the service usage credential received from the block chain device 112 in the credential DB 405.
[0056] In step S906, the print processing unit 402 notifies the user of the result of the credential issuance, and then ends this sequence. To notify the user, a message indicating successful issuance and an error message received from the device (described later) are displayed in a dialog box. The dialog boxes used for these notifications are standard dialog boxes provided by the OS, and therefore a description thereof will be omitted.
[0057] 10 is a flowchart showing the credential issuance process of the print data generating device 111. This flowchart is started when the print data generating device 111 receives the credential issuance request described above. The process control unit 502 is executed on the CPU 301 via the communication unit 501. When this flowchart is started, the process control unit 502 receives the ID and authentication information of the common credential and the user credential from the print processing unit 402. The process control unit 502 passes the received credential to the authentication processing unit 504, which then executes the following process.
[0058] In step S1001, the ID and authentication information of the common credential received from the print processing unit 402 at startup are compared with the information in the user information DB 505 to determine whether the authentication is successful. In step S1002, if the authentication is successful, the process proceeds to step S1003, and if it is unsuccessful, the process passes an error message to the process control unit 502 and proceeds to step S1007.
[0059] In step S1003, the ID and authentication information of the user credentials received from the print processing unit 402 at startup are compared with the information in the user information DB 505 to determine whether the authentication was successful. In step S1004, if the authentication was successful, the process proceeds to step S1005, and if it was unsuccessful, an error message is passed to the process control unit 502 and the process proceeds to step S1007.
[0060] In step S1005, service usage credentials are issued. First, an ID and authentication information are generated. There are no restrictions on how the generated ID is generated, as long as it is unique in the user information table managed by the user information DB 505. There are also no restrictions on the authentication information generated. Next, the user is obtained from the user information DB 505 based on the ID in the user credentials. The generated ID, authentication information, and the obtained user are registered in the user information DB 505. The authentication processing unit 504 passes the issued service usage credential information to the processing control unit 502, and the process proceeds to step S1006.
[0061] In step S1006, the process control unit 502 transmits the issued credential information to the print processing unit 402 via the communication unit 501. If the process control unit 502 receives an error message, in step S1007 it transmits the error message to the print processing unit 402 via the communication unit 501. After the transmission process to the print processing unit 402 is completed in step S1006 or step S1007, this flowchart ends.
[0062] The flowchart of the credential issuance process of the block chain device 112 is also the same as that of the print data generation device 111. The communication unit 501, the process control unit 502, the authentication processing unit 504, and the user information DB 505 of the print data generation device 111 correspond to the communication unit 601, the process control unit 602, the authentication processing unit 604, and the user information DB 605 of the block chain device 112, respectively.
[0063] The procedure for issuing credentials has been described above, but this is merely an example and does not limit other procedures up to the time when the print processing unit 402 possesses the service usage credential. For example, it is possible not to embed a common credential in the print processing unit 402 in advance, but to specify a user credential in the print processing unit 402 and issue a new credential. It is also possible to embed a service usage credential in the print processing unit 402 in advance.
[0064] As described above, if the verification processing unit 404 is provided as a separate application (verification application) from the print processing unit 402 and credential information is managed separately, service usage credentials may be issued in a similar procedure when the verification application is installed.
[0065] Authenticated printing will now be described. In authenticated printing, printing is started by the user operating a screen provided by the print processing unit 402. An example screen when the print processing unit 402 is provided as a virtual driver or print application, and the process flow of authenticated printing will be described using figures.
[0066] Figure 11 shows example screens of a virtual driver and a printing application. Figure 11(a) is the print properties screen of the virtual driver. The user opens the electronic data they want to print using a general application that can display, edit, and print electronic data, and when executing printing, selects the virtual driver and prints, which displays the print properties shown in Figure 11(a). Applications that open electronic data, select a driver, and have printing functions are general, so they are not shown in the figure.
[0067] A function selection tab 1101 is a tab for selecting a function. At startup, "Basic Settings" is selected in the function selection tab 1101, and a screen for making basic settings related to printing is displayed.
[0068] The printer driver setting field 1102 is a field for selecting the printer driver to be used for printing. There are no restrictions on the printer driver that can be specified here, and the driver that is normally used for printing can be selected. When printing, the print job is sent to the image forming apparatus 101 via the printer driver selected here. The print properties button 1103 is a button that displays the print properties screen of the selected printer driver. The properties that are displayed when the print properties button 1103 is pressed are not shown in the figure because they are the properties screen of a general printer driver. The print button 1104 is a button for starting authenticity-assured printing. The cancel button 1105 is a button for canceling the print instruction and closing the print properties screen of the virtual driver.
[0069] The aforementioned service usage credentials can be issued from the virtual driver's property screen. Figure 11(b) shows the credential management screen for selecting the user credentials required to issue the service usage credentials. By selecting "Credential Management" in the function selection tab 1101, the credential management screen shown in Figure 11(b) is displayed.
[0070] The credential selection field 1106 for the blockchain service is a field for selecting user credentials for the blockchain service. The credential selection field 1107 for the print data generation service is a field for selecting user credentials for the print data generation service. After setting the necessary information in each field, when the print button 1104 is pressed, the credential issuance sequence shown in Figure 9 above is started before authenticity-assured printing begins. The use of the credential management screen in Figure 11(b) is not limited to issuing credentials. For example, functions for reissuing, updating, and deleting credentials may be added.
[0071] FIG. 11(c) is an example screen when the print processing unit 402 is provided as a print application. When the print application is started, a top menu screen 1108 in FIG. 11(c) is displayed. An authenticity assurance print selection button 1109 is a button for transitioning to a screen for authenticity assurance printing. A verification selection button 1110 is a button for transitioning to a screen for verification. The verification screen will be described later in FIG. 15. A credential management selection button 1111 is a button for transitioning to a credential management screen. In this embodiment, only the functions for authenticity assurance are shown on the top menu screen 1108, but the authenticity assurance function may be provided by adding it to the normal printing and image editing functions of a general print application.
[0072] Fig. 11(d) is an example of a screen for performing authenticity-guaranteed printing. Pressing the authenticity-guaranteed printing selection button 1109 displays an authenticity-guaranteed printing screen 1112. The back button 1113 is a button for returning to the top menu screen 1110. The preview 1114 displays a preview of the selected file. The file selection button 1115 is a button for transitioning to a screen for selecting electronic data for authenticity-guaranteed printing by referencing the storage within the device or external storage on a network, etc. The screen for selecting electronic data is not shown in the figure because it is a screen provided by a general printing application.
[0073] The printer selection button 1116 is a button that transitions to a screen for selecting the device to use for printing. Here, as with general printing applications, image forming devices are searched for using Bluetooth or Multicast DNS. When Bluetooth is used, image forming devices are searched for by receiving a Bluetooth beacon from an image forming device within the Bluetooth communication range. The received beacon contains the printer's IP information, and the obtained IP information is used to perform IPP (Internet Printing Protocol) communication or IPPS communication. Detailed information such as the device name is obtained from the printer using IPP or IPPS communication, and the obtained information is displayed in a list on the search results screen for the number of image forming devices that were found. If the image forming device supports TLS (Transport Layer Security), detailed information is obtained using IPPS communication. An image forming device can be selected from the list of image forming device search results and the print destination can be set. The image forming device search screen and selection screen are not shown because they are screens provided by general printing applications.
[0074] The print property setting button 1117 is a button for transitioning to a screen for setting the print properties of the printer selected with the printer selection button 1116. As described above, the print property screen is displayed based on detailed printer information acquired through IPP and IPPS communication. The printer property setting screen is not shown in the figure because it is a screen provided by a general printing application. The print button 1118 is a button for starting authenticity-guaranteed printing.
[0075] FIG. 11(e) is a credential management screen for selecting the user credentials required to issue service usage credentials. Pressing the credential management selection button 1111 displays a credential management screen 1119. The blockchain service credential selection button 1120 is a button that transitions to a screen for selecting user credentials for the blockchain service. The print data generation service credential selection button 1121 is a button that transitions to a screen for selecting user credentials for the print data generation service. The credential selection screen is not shown in the figure because it is a general screen that allows you to select a file by referencing the storage inside the device or external storage on the network, etc.
[0076] The Apply button 1122 is a button for saving the settings of the selected user credentials. When the Print button 1118 is pressed, the saved user credentials are used to start the credential issuance sequence shown in FIG. 9 before authenticity-assured printing begins. Alternatively, the Apply button 1122 may be used as a credential issuance button to start credential issuance. The use of the credential management screen in FIG. 11(e) is not limited to issuing credentials. For example, functions for reissuing, updating, or deleting credentials may be added.
[0077] Fig. 12 is a sequence diagram of authenticity-guaranteed printing in Example 1. Fig. 12(a) is a sequence diagram when the print processing unit 402 is provided as a virtual driver. This sequence is started when the user presses the print button 1104, and the print processing unit 402, printer driver 403, image forming device 101, print data generation device 111, and block chain device 112 cooperate to perform processing and perform authenticity-guaranteed printing.
[0078] In step S1201, the user presses the print button 1104 to send a print instruction to the print processing unit 402. Upon receiving the print instruction, the print processing unit 402 sends print data to the print data generating device 111 and requests print data generation processing. In step S1202, the print data generating device 111 performs print data generation processing and sends the generated document identification information and print data to the print processing unit 402. Details of the print data generation processing in step S1202 will be described later using the flowchart in FIG. 13.
[0079] Next, the print processing unit 402 transmits the document identification information and a registration instruction to the block chain device 112. Upon receiving the registration request, the block chain device 112 performs transaction registration processing in step S1203 and transmits the result to the print processing unit 402. Details of the transaction registration processing in step S1203 will be explained later using the flowchart in FIG.
[0080] Next, the print processing unit 402 instructs the printer driver 403 specified in the printer driver setting field 1102 to print the print data received from the print data generating device 111, ie, to generate a print job.
[0081] Upon receiving the print instruction, the printer driver 403 performs print job generation processing in step S1204 and transmits the print job to the image processing device 101. Upon receiving the print job, the image forming device 101 performs print processing in step S1205 and ends this sequence. The print job generation processing of the printer driver 403 and the print processing of the image forming device 101 are general printer driver and image forming device processing, so explanations will be omitted. If the print processing unit 402 receives an error message (described later) from the print data generation device 111 or the block chain device 112, it notifies the user using a dialog box that the OS is equipped with as standard (not shown).
[0082] 12(b) is a sequence diagram when the print processing unit 402 is provided as a print application. This sequence is started when the user presses the print button 1118 described above, and the print processing unit 402, image forming device 101, print data generation device 111, and block chain device 112 cooperate to perform processing and perform authenticity-guaranteed printing.
[0083] Steps S1211 to S1213 are the same as steps S1201 to S1203 described in the sequence of authenticity-guaranteed printing in the virtual driver in Figure 12(a). In step S1214, the print processing unit 402 instructs the image forming device 101 selected by the printer selection button 1116 to print the print data received from the print data generation device 111, i.e., to generate a print job. The image forming device 101, which has received the instruction to generate a print job from the print processing unit 402, generates a print job and performs printing processing. If the print processing unit 402 receives an error message (described later) from the print data generation device 111 or the block chain device 112, it notifies the user using a dialog box that the OS is equipped with as standard (not shown).
[0084] 13 is a flowchart showing the print data generation process of the print data generating device 111. This flowchart is started when the communication unit 501 receives the print data generation request described above in the print data generating device 111, and first the process control unit 502 is executed on the CPU 301. When this flowchart is started, the process control unit 502 receives the ID and authentication information of the service usage credentials and print data from the print processing unit 402. The process control unit 502 passes the received service usage credentials to the authentication processing unit 504, and the authentication processing unit 504 executes step S1301.
[0085] In step S1301, the authentication processing unit 504 checks the ID and authentication information of the service usage credentials against the information in the user information DB 505, and determines whether the authentication is successful. If the check is successful, the authentication processing unit 504 obtains information about the user of the service usage credentials from the user information DB 505 and temporarily stores it in the RAM 303.
[0086] In step S1302, the authentication result is confirmed, and if the authentication is successful, the process proceeds to step S1303. If the process proceeds to step S1303, the process is returned to the process control unit 502, which then passes the print data received from the print processing unit 402 to the document identification information embedding unit 506, which then executes the document identification information embedding unit 506. If the authentication is unsuccessful, an error message is passed to the process control unit 502, and the process proceeds to step S1306.
[0087] In step S1303, the document identification information embedding unit 506 generates document identification information by hashing three pieces of information: the print data received from the process control unit 502, the date and time information in the print data generating device 111, and the user information stored in RAM 303 in step S1301.
[0088] In step S1304, the document identification information embedding unit 506 embeds the document identification information issued in step S1303 into the print data received from the process control unit 502. In the embedding process, the document identification information is converted into a format (e.g., a barcode) that can be read by scanning or photographing during verification, as described below, and then embedded. The embedding method may be either visible information that the user can see or invisible information that the user cannot see, and any form of embedded information that can be embedded in printed matter is acceptable. If you want to explicitly indicate to the user that the document has been registered on the blockchain, it is best to embed the information as visible information; for example, a two-dimensional barcode may be used. Alternatively, if you do not want to impair the appearance of the document, it is best to embed the information as invisible information in the document. For example, it is possible to embed the information as invisible information in the document by printing a pattern of tiny dots of toner or ink that are invisible to the user. The document identification information embedding unit 506 passes the document identification information and the print data in which the information is embedded to the process control unit 502, and the process proceeds to step S1305.
[0089] In step S1305, the process control unit 502 transmits the generated document identification information and the print data in which that information is embedded to the print processing unit 402 via the communication unit 501. If the process control unit 502 receives an error message, in step S1306 it transmits the error message to the print processing unit 402 via the communication unit 501. After the transmission process to the print processing unit 402 is completed in step S1305 or step S1306, this flowchart ends.
[0090] 14 is a flowchart showing the transaction registration process of the blockchain device 112. This flowchart is started when the communication unit 601 receives the registration request for the document identification information described above in the blockchain device 112, and first the process control unit 602 is executed on the CPU 301. When this flowchart is started, the process control unit 602 receives the ID, authentication information, and document identification information of the service usage credentials from the print processing unit 402. The process control unit 602 passes the received service usage credentials to the authentication processing unit 604, and step S1401 is executed by the authentication processing unit 604.
[0091] In step S1401, the authentication processing unit 604 checks the ID and authentication information of the service usage credentials against the information in the user information DB 605, and determines whether the authentication is successful. If the check is successful, the authentication processing unit 604 obtains information about the user of the service usage credentials from the user information DB 605 and temporarily stores it in the RAM 303.
[0092] In step S1402, the authentication result is confirmed, and if the authentication is successful, the process proceeds to step S1403. If the process proceeds to step S1403, the process returns to the process control unit 602, which then passes the document identification information received from the print processing unit 402 to the block data management unit 606, which then executes the block data management unit 606. If the authentication is unsuccessful, an error message is passed to the process control unit 602, and the process proceeds to step S1408.
[0093] In step S1403, the block data management unit 606 determines whether the document identification information 702 passed from the process control unit 602 can be registered in the blockchain. In this embodiment, since document identification information is information that uniquely references the registration content, if the information has already been registered, it is deemed unregisterable. If it is determined that registration is possible, the process proceeds to step S1404; if it is determined that registration is not possible, the process passes an error message to the process control unit 602 and proceeds to step S1408.
[0094] In step S1404, a transaction 701 is generated. The document identification information received by the process control unit 602 from the print processing unit 402 is specified as document identification information 702. The date and time information in the blockchain device at the time of execution of step S1404 is specified as registration date and time 703. The information temporarily saved in RAM 303 in step S1401 is specified as registrant 704.
[0095] In step S1405, the block data management unit 606 generates a block and writes it to the distributed ledger 607. After the transaction is generated in step S1404, the block is not necessarily generated immediately, but is generated when the block generation conditions are met. For example, a block is generated by collecting all the transactions that are to be registered in the block when a certain number of transactions have been collected or after a certain amount of time has passed. The conditions for generating a block differ depending on the type of blockchain and its settings. After the block is generated, it is written to the distributed ledger 607. In this embodiment, the block is generated when the conditions are met, but this is merely an example of one form of blockchain and does not limit the method of generating blocks.
[0096] In step S1406, if block generation and writing to the distributed ledger 607 are successful, a completion notification is passed to the process control unit 602, and the process proceeds to step S1407. If not, an error message is passed to the process control unit 602, and the process proceeds to step S1408.
[0097] In step S1407, the process control unit 602 transmits a registration completion message to the print processing unit 402 via the communication unit 601. If the process control unit 602 receives an error message, in step S1408 it transmits the error message to the print processing unit 402 via the communication unit 601. After the transmission process to the print processing unit 402 is completed in step S1407 or step S1408, this flowchart ends.
[0098] The above has described authenticity guaranteed printing. The printed matter obtained by authenticity guaranteed printing can be scanned by the image forming device 101 or photographed using the camera function of the information processing device 102, document identification information extracted from the electronic data, and an inquiry made to the blockchain device 112 to confirm the registered content. Confirming the registered content of the printed matter in this way is called verification. The verification method will be described below.
[0099] Fig. 15 shows an example of a screen when the verification processing unit 404 is provided as a function of a verification application or a print application. Fig. 15(a) shows the screen of the verification application. When the verification application is started, a verification application screen 1501 is displayed. A verification file selection field 1502 is a field for selecting a file to be verified. A verification button 1503 is a button for starting verification of the specified file.
[0100] The verification result screen 1504 in Figure 15(b) is a screen that displays the verification results. Verification file 1505 displays the file name or path specified by the user in Figure 15(a). Verification result 1506 displays whether it is registered in the blockchain. In the example screen in Figure 15(b), OK is displayed as an example of a case where it is registered in the blockchain. If it is not registered, NG is displayed (not shown). If the verification result 1506 is OK, the information registered in the blockchain may be displayed. In Figure 15(b), the registration date and time 703 included in the transaction 701 is displayed as registration date and time 1507, and the registrant 704 is displayed as registrant 1508. By checking the verification results, the user who performed the verification can confirm the evidence of the printed materials they own, such as when and who printed them. The close button 1509 is a button that closes the verification result screen 1504.
[0101] 15(c) to 15(e) are example screens when the verification processing unit 404 is provided as one of the functions provided by the print application. By pressing the verification selection button 1110 on the top menu screen 1108 of the print application described above, a verification menu screen 1510 is displayed. A back button 1511 is a button for transitioning to the top menu screen 1108. A select file and verify button 1512 is a button for transitioning to a screen for selecting and verifying a file. A camera-photographed and verified button 1513 is a button for transitioning to a screen for setting up and verifying a file with a camera.
[0102] 15(d) is a screen for selecting and verifying a file. By selecting a file and pressing a verify button 1512, a verification screen 1514 is displayed. A back button 1515 is a button for transitioning to a verification menu screen 1510. A file selection button 1516 is a button for transitioning to a screen for referencing the storage within the device or external storage on a network, etc., and selecting electronic data to be verified. A verify button 1517 is a button for starting verification of a specified file.
[0103] FIG. 15(e) shows a screen for photographing and verifying a printed matter with a camera. Pressing the "Take a photo with a camera and verify" button 1513 displays a verification screen 1518. Camera image 1519 displays an image captured from a camera built into or connected to the device running the print app. Pressing the "Verify" button 1520 while the printed matter is visible in the camera image 1519 captures a still image, and verification of the captured data begins. When photographing and verifying a printed matter with a camera, the portion of the printed matter to be photographed differs depending on the embedding method of the document identification information. If the entire printed matter must be photographed to extract the embedded information, the entire matter must be photographed. However, if information such as a two-dimensional barcode is embedded, verification can be performed by photographing only that portion. In this embodiment, photographing and verification begins by pressing the "Verify" button 1520. However, the photographed data may be saved and then verified by selecting the photographed data using the "File Selection" button 1516 in FIG. 15(d).
[0104] The verification result in the print application can be notified to the user by displaying a verification result screen as a pop-up as shown in Fig. 15(b). When verifying by taking a photo with a camera, the information to be displayed in the verification file 1505 is the save destination if the captured image is to be automatically saved, and nothing is displayed in the verification file 1505 if the captured image is not to be saved.
[0105] 16 is a sequence diagram of verification in this embodiment. This sequence is started by pressing any of the verification buttons 1503, 1517, and 1520, and performs verification through cooperation between the verification processing unit 404, the print data generation device 111, and the block chain device 112.
[0106] In step S1601, pressing one of the verification buttons 1503, 1517, or 1520 instructs the verification processing unit 404 to perform verification. In step S1602, upon receiving the verification instruction, the verification processing unit 404 reads the specified file or a captured image. The electronic data obtained by reading it is passed to the print data generation device 111, and a request is made for information extraction processing.
[0107] In step S1603, the print data generating device 111 performs information extraction processing and transmits the extracted document identification information to the verification processing unit 404. Details of the information extraction processing will be described later with reference to FIG.
[0108] The verification processing unit 404, which has received the document identification information from the print data generation device 111, confirms the registered content of the document identification information with the blockchain device 112. In step S1604, the blockchain device 112, which has received an inquiry from the verification processing unit 404, references the distributed ledger 607 and transmits the reference result to the verification processing unit 404. Details of the ledger reference process will be explained later with reference to FIG. 18.
[0109] In step S1605, the verification processing unit 404 receives the result of the reference to the distributed ledger 607 from the blockchain device 112, displays a screen such as that shown in Figure 15(b) to the user as the verification result, and ends this sequence. Errors in this sequence are displayed using a dialog box that the OS provides as standard (not shown).
[0110] 17 is a flowchart showing the information extraction process of the print data generating device 111. This flowchart is started when the communication unit 501 receives a request to extract the embedded information described above in the print data generating device 111, and is first executed by the process control unit 502 on the CPU 301. When this flowchart is started, the process control unit 502 receives the ID and authentication information of the service usage credential and data to extract information from the verification processing unit 404 via the communication unit 501. The process control unit 502 passes the received service usage credential to the authentication processing unit 504, and the authentication processing unit 504 executes step S1701.
[0111] In step S1701, the authentication processing unit 504 compares the ID and authentication information of the service usage credentials with the information in the user information DB 505 and determines whether the authentication is successful. In step S1702, the authentication result is confirmed, and if the authentication is successful, the process proceeds to step S1703. If the process proceeds to step S1703, the process returns to the process control unit 502, and the process control unit passes the data received from the verification processing unit 404 to the document identification information extraction unit 507, which is then executed. If the authentication is unsuccessful, an error message is passed to the process control unit 502, and the process proceeds to step S1706.
[0112] In step S1703, the document identification information extraction unit 507 extracts the document identification information embedded in the data. In step S1704, it is confirmed whether the information extraction was successful. If the information extraction was successful, the document identification information extraction unit 507 passes the extracted document identification information to the process control unit 502, and the process proceeds to step S1705. If the information extraction failed, the document identification information extraction unit 507 passes an error message to the process control unit 502, and the process proceeds to step S1706.
[0113] In step S1705, the process control unit 502 transmits the document identification information received from the document identification information extraction unit 507 to the verification processing unit 404 via the communication unit 501. If the process control unit 502 receives an error message, in step S1706 it transmits the error message to the verification processing unit 404 via the communication unit 501. After the transmission process to the verification processing unit 404 is completed in step S1705 or step S1706, this flowchart ends.
[0114] 18 is a flowchart of the ledger reference process in the blockchain device 112. This flowchart is started when the communication unit 601 receives confirmation of the above-mentioned registration contents in the blockchain device 112, and is first executed by the process control unit 602 on the CPU 301. When this flowchart is started, the process control unit 602 receives the ID, authentication information, and document identification information of the service usage credentials from the verification processing unit 404 via the communication unit 601. The process control unit 602 passes the received service usage credentials to the authentication processing unit 604, and step S1801 is executed by the authentication processing unit 604.
[0115] In step S1801, the authentication processing unit 604 checks the ID and authentication information of the service use credentials against the information in the user information DB 605, and determines whether the authentication is successful.
[0116] In step S1802, the authentication result is confirmed, and if the authentication is successful, the process proceeds to step S1803. If the process proceeds to step S1803, the process returns to the process control unit 602, which then passes the document identification information received from the verification processing unit 404 to the block data management unit 606, which then executes the block data management unit 606. If the authentication is unsuccessful, an error message is passed to the process control unit 602, and the process proceeds to step S1805.
[0117] In step S1803, the block chain managed by the distributed ledger 607 is searched for transactions 701 that include the document identification information received from the process control unit 602. The search results indicate whether the transaction exists and, if it has been registered, the information included in the transaction 701. The processing in this step is a general block chain ledger reference process, so details will not be explained. The block data management unit 606 passes the search results to the process control unit 602 and proceeds to step S1804.
[0118] In step S1804, the process control unit 602 transmits the search result received from the block data management unit 606 to the verification processing unit 404 via the communication unit 601. If the process control unit 602 receives an error message, in step S1805 it transmits the error message to the verification processing unit 404 via the communication unit 601. After the transmission process to the verification processing unit 404 is completed in step S1804 or step S1805, this flowchart ends.
[0119] As described above, according to the first embodiment, the print processing unit 402 cooperates with the print data generation device 111 and the block chain device 112, thereby enabling authenticity-guaranteed printing by the image forming device 101. Furthermore, the verification processing unit 404 cooperates with the print data generation device 111 and the block chain device 112, thereby enabling verification of the printed matter obtained by authenticity-guaranteed printing.
[0120] [Example 2] In the first embodiment, the print processing unit 402 cooperates with the print data generation device 111 and the block chain device 112 to perform authenticity-guaranteed printing. Because the print processing unit 402 cooperates with two services, there may be a large amount of processing content involved in communicating with the services and in error handling. The print processing unit 402 operates in an environment prepared by the user, so there may be a need to reduce the amount of processing and minimize the load on the print processing unit 402. Therefore, it is conceivable that the print processing unit 402 communicates only with the print data generation device 111, and the print data generation device 111 communicates with the block chain device 112.
[0121] In this embodiment, when authenticity-guaranteed printing is performed, the print processing unit 402 provides service usage credentials to the print data generation device 111, and the print data generation device 111 requests the blockchain device 112 to register the transaction 701.
[0122] The credentials managed in the credential DB 405 are the same as those in the first embodiment, and the procedure for issuing the credentials is also the same.
[0123] Table 4 shows an example of a user information table managed by the user information DB 505 of the print data generating device 111 in this embodiment.
[0124] [Table 4]
[0125] The user information table in Table 4 consists of "ID," "authentication information," "user," "BC ID," and "BC authentication information." "ID," "authentication information," and "user" are the same as those explained in Table 2. "BC ID" is user identification information used for authentication when using the blockchain device 112. "BC authentication information" is authentication information used for authentication when using the blockchain device 112.
[0126] Next, authenticity-assured printing in this embodiment will be described. An example of a screen when the print processing unit 402 is provided to the user as a virtual driver or print application is the same as that shown in Fig. 11. In this embodiment, the sequence of authenticity-assured printing when the print processing unit 402 is provided as a virtual driver will be described.
[0127] 19 is a sequence diagram of authenticity-guaranteed printing in this embodiment. This sequence is started when the user presses the print button 1104, and the print processing unit 402, printer driver 403, image forming device 101, print data generation device 111, and block chain device 112 cooperate to perform processing to perform authenticity-guaranteed printing.
[0128] In step S1901, the user issues a print instruction to the print processing unit 402 by pressing the print button 1104. Upon receiving the print instruction, the print processing unit 402 requests the print data generation device 111 to perform print data generation processing in step S1902. Upon receiving the request for print data generation processing, the print data generation device 111 performs the print data generation processing and requests the block chain device 112 to register the transaction 701.
[0129] In step S1903, the block chain device 112 that has received the registration request performs transaction registration processing and notifies the print data generating device 111 of the result. Details of the transaction registration processing are the same as those in the flowchart described in FIG.
[0130] The print data generation device that receives the registration notification from the block chain device 112 transmits the document identification information and print data to the print processing unit 402. Detailed processing of the print data generation device 111 will be described later with reference to Fig. 20. Subsequent steps S1904 and S1905 are the same as steps S1204 and S1205 described with reference to Fig. 12 in the first embodiment.
[0131] 20 is a flowchart showing the print data generation process of the print data generation device 111 in this embodiment. This flowchart is started when the communication unit 501 receives the print data generation request described above in the print data generation device 111, and first the process control unit 502 is executed on the CPU 301. When this flowchart is started, the process control unit 502 receives the ID and authentication information of the service usage credentials of the print data generation device 111 and print data from the print processing unit 402 via the communication unit 501. Optionally, the process control unit 502 also receives the ID and authentication information of the service usage credentials of the block chain device 112 from the print processing unit 402. The process control unit 502 passes the information of the service usage credentials of the print data generation device 111 and, if received, the information of the service usage credentials of the block chain device 112 to the authentication processing unit 504, and the following process is executed by the authentication processing unit 504.
[0132] In step S2001, the ID and authentication information of the service usage credentials of the print data generating device 111 are compared with the information in the user information DB 505 to determine whether authentication is possible. In step S2002, if authentication is successful, the process proceeds to step S2003. If authentication is unsuccessful, an error message is passed to the process control unit 502, and the process proceeds to step S2011.
[0133] In step S2003, it is confirmed whether or not the service usage credentials of the block chain device 112 have been received. If they have been received, the process proceeds to step S2004; if they have not been received, the process proceeds to step S2005.
[0134] In step S2004, for the ID authenticated in step S2001, the ID and authentication information of the service usage credentials of the blockchain device 112 are registered as the information of the "BC ID" and "BC authentication information" described in Table 4. In addition, the "BC ID" and "BC authentication information" are temporarily stored in RAM 303.
[0135] In step S2005, it is confirmed whether the "BC ID" and "BC authentication information" are registered in the user information table for the ID authenticated in step S2001. If they are registered, the "BC ID" and "BC authentication information" are temporarily stored in RAM 303, and the process proceeds to step S2006. If they are not registered, an error message is passed to the process control unit 502, and the process proceeds to step S2011. If the process proceeds to step S2006, the process returns to the process control unit 502, and the process control unit 502 passes the print data received from the print processing unit 402 to the document identification information embedding unit 506, and the document identification information embedding unit 506 is executed.
[0136] The processing in steps S2006 and S2007 performed by the document identification information embedding unit 506 is the same as that in steps S1303 and S1304 described in Fig. 13. The document identification information embedding unit 506 passes the document identification information generated in steps S2006 and S2007 and the print data in which that information is embedded to the process control unit 502, and the process control unit 502 performs the following processing.
[0137] In step S2008, the document identification information is registered in the blockchain device 112. The "BC ID" and "BC authentication information" stored in RAM 303 in step S2004 or step S2005 are used as authentication information for the blockchain device 112. The processing in the blockchain device 112 in this step is the same as the flowchart explained in Figure 14. The explanation in Figure 14 describes a case where communication is performed with the print processing unit 402, but this can be replaced with the print data generation device 111. In step S2009, a result notification is received from the blockchain device 112, and if registration was successful, the process proceeds to step S2010, or if registration was unsuccessful, the process proceeds to step S2011.
[0138] In step S2010, the generated document identification information and the print data in which that information is embedded are sent to the print processing unit 402 via the communication unit 501. In step S2011, an error message is sent to the print processing unit 402 via the communication unit 501. After the transmission process to the print processing unit 402 is completed in step S2010 or step S2011, this flowchart ends.
[0139] Verification of the printed matter can be performed in the same manner as described in the first embodiment, or in the same manner as the verification in the third embodiment described below.
[0140] As described above, in this embodiment, the print processing unit 402 communicates only with the print data generating device 111. This enables authenticity-guaranteed printing with less processing by the print processing unit 402 than in the first embodiment.
[0141] [Example 3] In the second embodiment, the print processing unit 402 possessed service usage credentials for the blockchain device 112, but since the print processing unit 402 does not directly use the blockchain device 112, there may be cases where the print processing unit 402 does not possess service usage credentials for the blockchain device 112.
[0142] In this embodiment, when performing authenticity-guaranteed printing, the print data generation device 111 uses the service usage credentials of the blockchain device 112 that it manages to register a transaction 701 in the blockchain device 112.
[0143] In this embodiment, the credential DB 405 does not manage the service usage credentials of the block chain device 112, but manages the common credentials in the same manner as in embodiment 1. The credential information table of the credential DB 405 has the same configuration as Table 1.
[0144] The configuration of the user information table in the user information DB 505 of the print data generating device 111 is the same as Table 4. In this embodiment, unlike the second embodiment, the "BC ID" and "BC authentication information" are registered when the credential is issued.
[0145] Credential issuance in this embodiment will now be described. The screen displayed when issuing credentials is the same as that shown in FIG.
[0146] 21 is a sequence diagram of credential issuance in this embodiment. This sequence is started when the user presses the above-mentioned issue button 804, and the print processing unit 402, print data generation device 111, and block chain device 112 cooperate to perform processing, and the print processing unit 402 obtains service usage credentials.
[0147] In step S2101, the user instructs the issuance of service usage credentials by pressing the issue button 804. Upon receiving the issued service usage credentials, the print processing unit 402 requests the print data generating device 111 to perform credential issuance processing in step S2102.
[0148] In step S2102, the print data generation device 111 that has received the issuance request performs processing to issue the service usage credentials. In this step, the print data generation device 111 performs processing from step S1001 to step S1005 described in FIG. 10. Through this processing, the generated ID and authentication information, and the acquired user are registered in the user information table of Table 4. After that, a request is made to the block chain device 112 to perform credential issuance processing in step S2103.
[0149] In step S2103, the blockchain device 112 that has received the request for credential issuance processing issues a service usage credential and provides the issued credential to the print data generation device 111. Details of the processing in this step are the same as those in the flowchart described in FIG.
[0150] In step S2104, the print data generation device 111 that has received the service usage credential registers the ID and authentication information of the received credential as the "BC ID" and "BC authentication information" of the service usage credential issued in step S2102. Thereafter, the "ID" and "authentication information" of the service usage credential issued in step S2102 are transmitted to the print processing unit 402. In this embodiment, as described above, the print processing unit 402 does not communicate with the block chain device 112, and therefore the credential provided to the print processing unit 402 does not include the credential of the block chain device 112.
[0151] In step S2105, the print processing unit 402 stores the received service usage credentials in the credential DB 405. In step S2106, the print processing unit 402 notifies the user of the result of the credential issuance, and ends this sequence. To notify the user, a message indicating successful issuance and an error message received from the device are displayed in a dialog box. The dialog boxes used for these notifications are standard dialog boxes provided by the OS, so their explanation will be omitted.
[0152] Next, authenticity-guaranteed printing in this embodiment will be described. An example of a screen when the print processing unit 402 is provided to the user as a virtual driver or print application is the same as that shown in FIG. 11. The sequence of authenticity-guaranteed printing is the same as that shown in FIG. 19. The processing of the print data generation device 111 differs from the processing shown in FIG. 20 described in the second embodiment in that, as described above, credential registration in the block chain device 112 is completed when the credential is issued, and therefore, steps S2003 and S2004 are not performed. The processing of the print data generation device 111 in this embodiment will be described below using the figures.
[0153] 22 is a flowchart showing print data generation processing of the print data generating device 111 in this embodiment. This flowchart is started when the communication unit 501 receives a print data generation request in the print data generating device 111, and first the process control unit 502 is executed on the CPU 301. When this flowchart is started, the process control unit 502 receives the ID and authentication information of the service usage credentials of the print data generating device 111, and print data, from the print processing unit 402 via the communication unit 501. The process control unit 502 passes the information of the service usage credentials of the print data generating device 111 to the authentication processing unit 504, and the following processing is executed by the authentication processing unit 504.
[0154] In step S2201, the ID and authentication information of the service usage credentials of the print data generating device 111 are compared with the information in the user information DB 505 to determine whether authentication is possible. In step S2202, the authentication result is confirmed, and if authentication is successful, the process proceeds to step S2203, and if authentication is unsuccessful, an error message is passed to the process control unit 502 and the process proceeds to step S2209.
[0155] In step S2203, it is confirmed whether the "BC ID" and "BC authentication information" are registered in the user information table for the ID authenticated in step S2201. If they are registered, the "BC ID" and "BC authentication information" are temporarily stored in RAM 303 and the process proceeds to step S2204. If they are not registered, an error message is passed to the process control unit 502 and the process proceeds to step S2209.
[0156] The processing in steps S2204 to S2209 is the same as that in steps S2006 to S2011. To authenticate the block chain device 112 in step S2206, the "BC ID" and "BC authentication information" temporarily stored in the RAM 303 in step S2203 are used.
[0157] Next, the verification of the printed matter in this embodiment will be described. The screen used during verification is the same as that described in FIG.
[0158] 23 is a sequence diagram of verification in this embodiment. This sequence is started by pressing any of the verification buttons 1503, 1517, and 1520, and performs verification through cooperation between the verification processing unit 404, the print data generation device 111, and the block chain device 112.
[0159] In step S2301, pressing one of the verification buttons 1503, 1517, or 1520 instructs the verification processing unit 404 to perform verification. In step S2302, upon receiving the verification instruction, the verification processing unit 404 reads the specified file or a captured image. The electronic data obtained by reading it is passed to the print data generation device 111, and a request is made for information extraction processing.
[0160] In step S2303, the print data generation device 111 that has received the verification request performs information extraction processing and confirms the registered contents of the extracted document identification information with the block chain device 112. Details of the information extraction processing are the same as those described in FIG.
[0161] In step S2304, the blockchain device 112, having received confirmation of the registration contents from the verification processing unit 404, references the distributed ledger 607 and transmits the reference result to the print data generation device 111. Details of the ledger reference process are the same as those described in Fig. 18. The print data generation device 111, having received the reference result of the distributed ledger 607 from the blockchain device 112, transmits the presence or absence of registration and the registration contents to the verification processing unit 404 as the verification result.
[0162] In step S2305, the verification processing unit 404 receives the verification result from the print data generating device 111, displays the verification result to the user on a screen such as that shown in Fig. 15(b), and ends this sequence. Errors in this sequence are displayed using a dialog box that the OS normally provides (not shown).
[0163] As a result, the print processing unit 402 and the verification processing unit 404 can perform authenticity-guaranteed printing and verification without managing the service usage credentials of the blockchain device 112.
[0164] [Example 4] In Examples 1 to 3, the print data generation device 111 issues and extracts document identification information and embeds it in the print data, but it is possible to consider a case where the blockchain device 112 issues and extracts document identification information and embeds it in the print data.
[0165] In this embodiment, a case will be described in which the block chain device 112 issues and extracts document identification information and embeds it in print data, without providing a print data generation device 111. Since the print processing unit 402 and verification processing unit 404 communicate only with the block chain device 112, the credential DB 405 manages only the common credential and service usage credential issued by the block chain device 112.
[0166] Regarding the issuance of credentials, the same procedure as in the first embodiment is performed only for the block chain device 112. In this embodiment, the credential selection field 803 for the print data generation service is not required on the installer screen in FIG.
[0167] In authenticity-guaranteed printing in this embodiment, the processing by the print data generation device 111 described in step S1202 of FIG. 12 is not performed, and the print processing unit 402 requests the block chain device 112 to register the transaction 701. At this time, the print processing unit 402 transmits the print data and a registration instruction to the block chain device 112. Details of the processing in step S1203 by the block chain device 112 that has received the registration request will be explained later in FIG. 24. After the processing of step S1203, the block chain device 112 transmits the print data in which the document identification information is embedded to the print processing unit 402. The processing from then on, from the print instruction to the printer driver 403 onwards, is the same as in embodiment 1.
[0168] 24 is a flowchart showing the transaction registration process of the block chain device 112 in this embodiment. This flowchart is started when the communication unit 601 receives the above-mentioned registration request, and first the process control unit 602 is executed on the CPU 301. When this flowchart is started, the process control unit 602 receives the ID of the service usage credential, authentication information, and print data from the print processing unit 402 via the communication unit 601. The process control unit 602 passes the received service usage credential to the authentication processing unit 604, and the authentication processing unit 604 executes step S2401.
[0169] In step S2401, the authentication processing unit 604 checks the ID and authentication information of the service usage credential against the information in the user information DB 605, and determines whether the authentication is successful. If the check is successful, the authentication processing unit 604 obtains information about the user of the service usage credential from the user information DB 605 and temporarily stores it in the RAM 303.
[0170] In step S2402, the authentication result is confirmed, and if the authentication is successful, the process proceeds to step S2403. If the process proceeds to step S2403, the process returns to the process control unit 602, which then passes the print data received from the print processing unit 402 to the block data management unit 606, which then executes the block data management unit 606. If the authentication is unsuccessful, an error message is passed to the process control unit 602, and the process proceeds to step S2410.
[0171] In step S2403, document identification information is generated using the same method as the processing described in step S1303 of Fig. 13. In step S2404, if the generated document identification information has already been registered in the distributed ledger 607, it is determined that registration is not possible, and the process returns to the generation of document identification information in step S2403, where document identification information is generated again. If the generated document identification information has not been registered in the distributed ledger 607, it is determined that registration is possible, and the process proceeds to step S2405.
[0172] In step S2405, document identification information is embedded in the print data in the same manner as in step S1304 of Fig. 13. In steps S2406 and S2407, the same processes as in steps S1404 and S1405 of Fig. 14 are performed.
[0173] In step S2408, if block generation is successful, the process is passed to the process control unit 602 along with the print data in which information has been embedded in step S2405, and the process proceeds to step S2407. If not successful, an error message is passed to the process control unit 602, and the process proceeds to step S2410.
[0174] In step S2409, the process control unit 602 transmits the print data to the print processing unit 402 via the communication unit 601. If the process control unit 602 receives an error message, in step S2410 it transmits the error message to the print processing unit 402 via the communication unit 601. After the transmission process to the print processing unit 402 is completed in step S2409 or step S2410, this flowchart ends.
[0175] Next, verification of a printed matter in this embodiment will be described. As in the first embodiment, it is assumed that the printed matter has been converted into electronic data in advance. The verification screen is the same as that described in FIG. 15 in the first embodiment.
[0176] The verification sequence will be described, focusing on the differences from Example 1. The processing by the print data generating device 111 described in step S1603 of Fig. 16 is not performed, and the verification processing unit 404 requests verification from the block chain device 112. At this time, the verification processing unit 404 transmits the file data read in S1602 to the block chain device 112. The processing of the block chain device 112 that receives the verification request will be described with reference to Fig. 25.
[0177] 25 is a flowchart of verification in this embodiment. This flowchart is started when the communication unit 601 receives the above-mentioned verification request in the blockchain device 112, and first the processing control unit 602 is executed on the CPU 301. When this flowchart is started, the processing control unit 602 receives the ID of the service usage credential, authentication information, and data to be verified from the verification processing unit 404 via the communication unit 601. The processing control unit 602 passes the received service usage credential to the authentication processing unit 604, and step S2501 is executed in the authentication processing unit 604.
[0178] In step S2501, the authentication processing unit 604 checks the ID and authentication information of the service use credentials against the information in the user information DB 605, and determines whether the authentication is successful.
[0179] In step S2502, the authentication result is confirmed, and if the authentication is successful, the process proceeds to step S2503. If the process proceeds to step S2503, the process returns to the process control unit 602, which then passes the data received from the verification processing unit 404 to the block data management unit 606, which then executes the block data management unit 606. If the authentication is unsuccessful, an error message is passed to the process control unit 602, and the process proceeds to step S2507.
[0180] In step S2503, the block data management unit 606 extracts the document identification information embedded in the data. In step S2504, the success or failure of the information extraction is confirmed. If the information extraction is successful, the process proceeds to step S2505. If the information extraction is unsuccessful, the block data management unit 606 passes an error message to the process control unit 602 and the process proceeds to step S2507.
[0181] In step S2505, the blockchain managed by the distributed ledger 607 is searched for transactions 701 that include the document identification information extracted in step S2503. The search results indicate whether the transaction exists and, if so, the information included in the transaction 701. The processing in this step is a general blockchain ledger reference process, so details will not be explained. The block data management unit 606 passes the search results to the process control unit 602 and proceeds to step S2506.
[0182] In step S2506, the process control unit 602 transmits the search result received from the block data management unit 606 to the verification processing unit 404 via the communication unit 601. If the process control unit 602 receives an error message, in step S2507 it transmits the error message to the verification processing unit 404 via the communication unit 601. After the transmission process to the verification processing unit 404 is completed in step S2506 or step S2507, this flowchart ends.
[0183] As described above, the fourth embodiment has been described as an embodiment that can obtain the same effects as the first embodiment with a configuration that does not include the print data generating device 111.
[0184] [Other Examples] In the first to fourth embodiments, when the print processing unit 402 is provided as a virtual driver, the virtual driver instructs the printer driver 403 to print, and the printer driver 403 generates a print job and transmits the print job to the image forming apparatus 101. The present invention can also be realized by implementing the printer driver 403 so that it has the functions of the print processing unit 402, and distributing the printer driver 403 to the user as a new driver or as an update.
[0185] The present invention can also be realized by executing the following process. That is, software (programs) that realize the functions of the above-described embodiments are supplied to a system or device via a network or various storage media. Then, the computer (or CPU or MPU) of the system or device reads and executes the programs.
[0186] According to the embodiment described above, a service that provides the function of generating print data for authenticity assurance can be prepared, and an authenticity assurance service can be provided by an app or printer driver that works in conjunction with that service and the blockchain service.
Claims
1. A system comprising an information processing device and a blockchain device, the information processing device has a virtual driver and a printer driver, The virtual driver an embedding instruction means for instructing an external device to embed identification information in print data; a receiving means for receiving, from the external device, identification information relating to the print data and the print data in which the identification information is embedded; a registration instruction means for instructing the block chain device to register identification information related to the print data in a transaction, and causing the information processing device to execute the registration instruction means; The printer driver causing the information processing device to execute a transmission means for transmitting a print job of print data in which the identification information is embedded, received from the external device, to an image forming device; The blockchain device is a registration means for generating a transaction based on the identification information and registering it in a block; A system characterized in that the virtual driver and the printer driver work together to generate a printed material and register blocks related to the generated printed material with a single print instruction from the user.
2. The information processing device further comprises: The system described in claim 1, characterized in that it has an inquiry means for inquiring of the blockchain device whether identification information extracted from scanned data of a printed material is registered in a block.
3. The information processing device further comprises:
3. The system according to claim 2, further comprising extraction instruction means for instructing the external device to extract identification information from data obtained by scanning a printed material.
4. A system described in any one of claims 1 to 3, characterized in that after it is confirmed that the transaction has been registered in a block by instruction from the registration instruction means, the sending means, which receives instructions sent from the virtual driver, sends a print job of print data in which the identification information is embedded to the image forming device.
5. The information processing device further comprises: The system described in claim 4, characterized in that it has a management means for managing a first credential used to authenticate the external device and a second credential used to authenticate the blockchain device.
Citation Information
Patent Citations
Electronic file certification system
JP2018128823A
Provision device, processing system, and communication method
JP2020035041A
Image forming system, image forming apparatus, and image forming method
JP2020181573A
Image formation apparatus, control method and program
JP2021019271A