Data processing device, information processing system, data processing method and program
The described system enhances security in shared printing environments by using a cloud gateway and edge devices to manage and enforce user permissions and device availability, preventing unauthorized access and exposure of confidential information.
Patent Information
- Application Number
- JP2021162398
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-30
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2041-09-30
AI Technical Summary
Existing printing systems in shared workspaces do not adequately ensure security when multiple users are using the same device simultaneously, potentially exposing confidential information to unauthorized individuals.
A data processing device and system that includes a cloud gateway, edge devices, and user terminals, which utilize job information and user authentication to determine and enforce security levels, ensuring that jobs are executed only when compatible with the current device usage status and user permissions.
Ensures secure printing by preventing unauthorized access and exposure of confidential information in shared device environments.
Smart Images

Figure 0007735768000001 
Figure 0007735768000002 
Figure 0007735768000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a data processing device, an information processing system, a data processing method, and a program. [Background technology]
[0002] In recent years, work style reform has been promoted, allowing people to choose from a variety of work styles according to their individual circumstances. As a result, coworking spaces and shared offices (hereinafter simply referred to as coworking spaces) are on the rise as places to work other than company offices or homes. A distinctive feature of such coworking spaces is that they share facilities. Therefore, since the facilities are shared with other companies, security becomes more important than in a regular office.
[0003] For example, if an MFP (Multifunction Peripheral) is installed as shared equipment in a shared space in a coworking space, users may send data from their own devices and output it to the MFP. Here, an MFP is an image forming device that has at least two of the following functions: copy, printer, scanner, and fax. In this case, if multiple people use the MFP at the same time, there is a possibility that people will gather around the MFP to obtain the output. If the output contains confidential company information, the content may be seen by someone from another company who happens to be present.
[0004] A printing system that outputs printed materials while ensuring security is disclosed that is composed of a server having an input means for assigning output conditions to print jobs, a user terminal, a collection means for collecting device information from image forming devices within the network, a search means for determining the collected information and output conditions of the print job and searching for an output destination, and multiple image forming devices that receive jobs output from the server and are capable of printing out, and the server switches the image forming device to output depending on the output destination search results (for example, Patent Document 1). Summary of the Invention [Problem to be solved by the invention]
[0005] However, while the system described in Patent Document 1 allows printing while taking into consideration the security of the output, it does not anticipate cases where multiple people will be using the same device at the same time, and so there is a problem in that security is not sufficiently ensured.
[0006] The present invention has been made in consideration of the above, and aims to provide a data processing device, an information processing system, a data processing method, and a program that can ensure security when using a device shared by multiple people. [Means for solving the problem]
[0007] In order to solve the above problems and achieve the object, the present invention provides: A data processing device connected to a user terminal and a first edge device, The user terminal from , the output target The first job consists of a reception unit that receives job information; a first edge device that receives the first job information from the reception unit and determines whether the first job can be executed by the first edge device; User Information whether there is another second job being executed by the first edge device; Based on judgment Determine a determining unit, when determining that the first edge device is executing the second job, determining whether the first job can be executed by the first edge device based on the first user information and security information indicating a security level included in second job information constituting the second job. a determination unit, No. 1 Job Information The first job is composed of If it is determined to be feasible, Execution of the first job configured by the first job information accepted by the accepting unit, To the first edge device Essential and a request unit for requesting the [Effects of the Invention]
[0008] According to the present invention, security can be ensured when a device shared by multiple people is used. [Brief explanation of the drawings]
[0009] [Figure 1] FIG. 1 is a diagram illustrating an example of the overall configuration of an information processing system according to the first embodiment. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of the cloud gateway, the cloud, and the user terminal according to the first embodiment. [Figure 3] FIG. 3 is a diagram illustrating an example of the hardware configuration of an MFP, which is an edge device according to the first embodiment. [Figure 4] FIG. 4 is a diagram illustrating an example of the configuration of functional blocks of the information processing system according to the first embodiment. [Figure 5] FIG. 5 is a diagram illustrating a case where a specific user uses an edge device in the information processing system according to the first embodiment. [Figure 6] FIG. 6 is a sequence diagram showing an example of the flow of operations when user A uses a specific edge device in the information processing system according to the first embodiment. [Figure 7] FIG. 7 is a diagram showing an example of the login screen. [Figure 8] FIG. 8 is a diagram showing an example of the job list screen. [Figure 9] FIG. 9 is a diagram showing an example of the job execution screen. [Figure 10] FIG. 10 is a diagram illustrating a case in which a person from the same company as user A and a person from a different company use the same edge device in the information processing system according to the first embodiment. [Figure 11A] FIG. 11A is a sequence diagram showing an example of the flow of operations in the information processing system according to the first embodiment when a user C, who is in a different company from a user A, uses the same edge device. [Figure 11B] FIG. 11B is a sequence diagram showing an example of the flow of operations in the information processing system according to the first embodiment when user A and user C, who are in a different company, use the same edge device. [Figure 12] FIG. 12 is a diagram showing an example of the use NG screen. [Figure 13A] FIG. 13A is a sequence diagram showing an example of the flow of operations in the information processing system according to the first embodiment when a user B who is in the same company as a user A uses the same edge device. [Figure 13B] FIG. 13B is a sequence diagram showing an example of the flow of operations in the information processing system according to the first embodiment when user B, who is in the same company as user A, uses the same edge device. [Figure 14] FIG. 14 is a diagram illustrating a case in which a user C, who is in a different company from the user A, is prompted to use a different edge device in the information processing system according to the second embodiment. [Figure 15A] FIG. 15A is a sequence diagram showing an example of the flow of operations in the information processing system according to the second embodiment when a user C, who is in a different company from a user A, uses the same edge device. [Figure 15B] FIG. 15B is a sequence diagram showing an example of the flow of operations in the information processing system according to the second embodiment when user A and user C, who are in a different company, use the same edge device. [Figure 16] FIG. 16 is a diagram illustrating a case where a person is present near an edge device used by a specific user in the information processing system according to the third embodiment. [Figure 17] FIG. 17 is a sequence diagram showing an example of the flow of operations in the case where there are people nearby when user A uses a specific edge device in the information processing system according to the third embodiment. [Figure 18] FIG. 18 is a diagram showing an example of the output security screen. DETAILED DESCRIPTION OF THE INVENTION
[0010] Hereinafter, with reference to the drawings, embodiments of a data processing device, an information processing system, a data processing method, and a program according to the present invention will be described in detail. Furthermore, the present invention is not limited to the following embodiments, and the components in the following embodiments include those that would be easily conceived by a person skilled in the art, those that are substantially the same, and those that are within the scope of what is called equivalents. Furthermore, various omissions, substitutions, modifications, and combinations of the components can be made without departing from the spirit of the following embodiments.
[0011] [First embodiment] (Overall configuration of information processing system) 1 is a diagram showing an example of the overall configuration of an information processing system according to the first embodiment. The overall configuration of the information processing system 1 according to this embodiment will be described with reference to FIG.
[0012] As shown in FIG. 1, the information processing system 1 includes a cloud gateway 10, a cloud 20, edge devices 30a to 30c, and user terminals 40a to 40c. Among these, the cloud gateway 10, the edge devices 30a to 30c, and the user terminals 40a to 40c are capable of data communication via a network N. The network N is a network configured by a LAN (Local Area Network) or the like. The network N may be either a wired network or a wireless network. The cloud gateway 10 is also capable of data communication with the cloud 20. The cloud gateway 10 and the cloud 20 may also perform data communication via a VPN (Virtual Private Network), the Internet, or the like.
[0013] The cloud gateway 10 is a device that relays data between the cloud 20 and edge devices 30a to 30c, which are various types of edge equipment, and is a data processing device that provides new value to each of the users who use the user terminals 40a to 40c. The cloud gateway 10 is configured, for example, by a single-board computer, a PC (Personal Computer), or dedicated equipment.
[0014] The cloud 20 is a cloud system that stores and manages data used by the user terminals 40a to 40c. The cloud 20 is realized by an information processing device such as a single server device, or an information processing system including multiple server devices.
[0015] The edge devices 30a to 30c are installed in a coworking space or a shared office, and are used by multiple users as shared facilities. The edge devices 30a to 30c are, for example, image forming devices such as an MFP, an inkjet printer, or an electrophotographic printer, an IWB (Interactive Whiteboard), or a projector. In the following description, the edge devices 30a to 30c are assumed to be image forming devices. Note that although FIG. 1 shows three edge devices, 30a to 30c, the number is not limited to three. Furthermore, when referring to any edge device or collectively referring to the edge devices 30a to 30c, they will be simply referred to as "edge device 30."
[0016] The user terminals 40a to 40c are information processing devices such as PCs or tablet terminals used by each user in a coworking space, a shared office, or the like. For example, the user terminals 40a to 40c specify print data stored in the cloud 20 and issue job execution requests to print out the data on the edge devices 30a to 30c in accordance with user operations. In this embodiment, the user terminal 40a is assumed to be user A, the user terminal 40b is assumed to be user B, and the user terminal 40c is assumed to be user C. Note that while FIG. 1 shows three user terminals, 40a to 40c, the number of user terminals is not limited to three. Furthermore, when referring to any user terminal or collectively referring to the user terminals 40a to 40c, the user terminals 40a to 40c will be simply referred to as "user terminal 40."
[0017] (Hardware configuration of cloud gateway, cloud, and user terminal) 2 is a diagram showing an example of the hardware configuration of the cloud gateway, cloud, and user terminal according to the first embodiment. The hardware configuration of the cloud gateway 10 according to this embodiment will be described with reference to FIG.
[0018] As shown in FIG. 2, the cloud gateway 10 includes a CPU (Central Processing Unit) 501, a ROM (Read Only Memory) 502, a RAM (Random Access Memory) 503, an auxiliary storage device 505, a media drive 507, a display 508, a network I / F 509, a keyboard 511, a mouse 512, and a DVD (Digital Versatile Disc) drive 514.
[0019] The CPU 501 is a computing device that controls the overall operation of the cloud gateway 10. The ROM 502 is a non-volatile storage device that stores programs such as an IPL (Initial Program Loader) that is initially executed by the CPU 501. The RAM 503 is a volatile storage device that is used as a work area for the CPU 501.
[0020] The auxiliary storage device 505 is a non-volatile storage device that stores various data such as programs, etc. The auxiliary storage device 505 is, for example, a hard disk drive (HDD) or a solid state drive (SSD).
[0021] The media drive 507 is a device that controls reading and writing of data from and to a recording medium 506 such as a flash memory.
[0022] The display 508 is a liquid crystal display (LCD) or an organic electroluminescence (EL) display that displays various types of information such as a cursor, menu, window, text, or image.
[0023] The network I / F 509 is an interface for data communication using the network N. The network I / F 509 is, for example, a network interface card (NIC) that enables communication using the TCP (Transmission Control Protocol) / IP (Internet Protocol) protocols. The network I / F 509 may also be a communication interface having a wireless communication function based on standards such as Wi-Fi (registered trademark). Furthermore, when performing protocol conversion of data from one network to another network using a different communication protocol as a gateway, the cloud gateway 10 may be provided with multiple network I / Fs 509 that enable data communication with each network.
[0024] The keyboard 511 is an example of an input device having multiple keys for inputting characters, numbers, various instructions, etc. The mouse 512 is a type of input device for selecting and executing various instructions, selecting a processing target, moving a cursor, etc.
[0025] The DVD drive 514 is a device that controls reading and writing of various data from and to a DVD 513, which is an example of a removable storage medium. The DVD 513 is, for example, a DVD-RW (Digital Versatile Disk Rewritable), a DVD-R (Digital Versatile Disk Recordable), a CD-RW (Compact Disc Rewritable), or a CD-R (Compact Disc Recordable).
[0026] The above-mentioned CPU 501, ROM 502, RAM 503, auxiliary storage device 505, media drive 507, display 508, network I / F 509, keyboard 511, mouse 512 and DVD drive 514 are connected to each other so that they can communicate with each other via bus lines 510 such as an address bus and a data bus.
[0027] 2 is an example, and it is not necessary to include all of the components, and other components may be included. The hardware configurations of the cloud 20 and the user terminal 40 also conform to the configuration shown in FIG.
[0028] (Edge device hardware configuration) Fig. 3 is a diagram showing an example of the hardware configuration of an MFP, which is an edge device according to the first embodiment. The hardware configuration of the edge device 30 as an image forming apparatus will be described with reference to Fig. 3. In Fig. 3, the edge device 30 will be described as an MFP in particular.
[0029] As shown in FIG. 3, the edge device 30 is configured such that a controller 600, an operation display unit 610, an FCU (Facsimile Control Unit) 620, a plotter 631, a scanner 632, and an imaging device 633 are connected via a PCI (Peripheral Component Interface) bus.
[0030] The controller 600 is a device that controls the entire edge device 30 , and controls drawing, communication, and input from the operation display unit 610 .
[0031] The operation display unit 610 is, for example, a touch panel, and is a device that accepts input to the controller 600 (input function) and displays the status of the edge device 30 (display function), and is directly connected to the ASIC (Application Specific Integrated Circuit) 606 described later.
[0032] The FCU 620 is a device that implements a fax function, and is connected to the ASIC 606 via, for example, a PCI bus.
[0033] The plotter 631 is a device that realizes a printing function and is connected to the ASIC 606 via, for example, a PCI bus. The scanner 632 is a function that realizes a scanner function and is connected to the ASIC 606 via, for example, a PCI bus. The imaging device 633 is a device that captures images of the periphery of the edge device 30 and is connected to the ASIC 606 via, for example, a PCI bus. The imaging device 633 may be connected as an external device to a Universal Serial Bus (USB) I / F 604c (described later) or the like. In addition to or instead of the imaging device 633, a human presence sensor that detects people present in the periphery of the edge device 30 may be connected to the sensor I / F 604e.
[0034] The controller 600 has a CPU 601, a system memory (MEM-P) 602, a north bridge (NB) 603, a south bridge (SB) 604a, a network I / F 604b, a USB I / F 604c, a Centronics I / F 604d, a sensor I / F 604e, an ASIC 606, a local memory (MEM-C) 607, and an auxiliary storage device 608.
[0035] The CPU 601 is a computing device that performs overall control of the edge device 30, and is connected to a chipset consisting of a system memory 602, a north bridge 603, and a south bridge 604a, and is connected to other devices via this chipset.
[0036] The system memory 602 is a memory used as a memory for storing programs and data, a memory for expanding programs and data, a memory for printer drawing, etc., and includes ROM and RAM. Of these, the ROM is a read-only memory used as a memory for storing programs and data, and the RAM is a writable and readable memory used as a memory for expanding programs and data, and a memory for printer drawing, etc.
[0037] The north bridge 603 is a bridge for connecting the CPU 601 with the system memory 602, south bridge 604a, and AGP (Accelerated Graphics Port) bus 605, and has a memory controller that controls reading and writing to the system memory 602, a PCI master, and an AGP target.
[0038] The southbridge 604a is a bridge for connecting the northbridge 603 with PCI devices and peripheral devices. The southbridge 604a is connected to the northbridge 603 via a PCI bus, and the network I / F 604b, USB I / F 604c, Centronics I / F 604d, sensor I / F 604e, etc. are connected to the PCI bus.
[0039] The AGP bus 605 is a bus interface for a graphics accelerator card proposed to accelerate graphics processing. The AGP bus 605 is a bus that speeds up the graphics accelerator card by directly accessing the system memory 502 at high throughput.
[0040] The ASIC 606 is an integrated circuit (IC) for image processing applications that has hardware elements for image processing and serves as a bridge connecting the AGP bus 605, PCI bus, auxiliary storage device 608, and local memory 607. The ASIC 606 is composed of a PCI target and AGP master, an arbiter (ARB) that forms the core of the ASIC 606, a memory controller that controls the local memory 607, multiple direct memory access controllers (DMACs) that perform image data rotation and the like using hardware logic, and a PCI unit that transfers data via the PCI bus between the ASIC 606 and the plotter 631, scanner 632, and image capture device 633. For example, the FCU 620, plotter 631, scanner 632, and image capture device 633 are connected to the ASIC 606 via the PCI bus.
[0041] The local memory 607 is a memory used as an image buffer for copying and a code buffer.
[0042] The auxiliary storage device 608 is a storage device such as an HDD (Hard Disk Drive), SSD (Solid State Drive), SD (Secure Digital) card, or flash memory, and is a storage for storing image data, programs, font data, and forms, etc.
[0043] 3 is an example, and the edge device 30 does not necessarily have to include all of the components, and may include other components. For example, the edge device 30 may include an ADF (Automatic Document Feeder) or the like.
[0044] (Configuration and operation of functional blocks of information processing systems) 4 is a diagram showing an example of the configuration of functional blocks of the information processing system according to the first embodiment. The configuration and operation of the functional blocks of the information processing system 1 according to the present embodiment will be described with reference to FIG.
[0045] As shown in FIG. 4, the cloud gateway 10 has a first communication unit 101 (first acquisition unit), a second communication unit 102 (second acquisition unit), an authentication unit 103, a job reception unit 104 (reception unit), a job management unit 105 (request unit), a judgment unit 106, and a display control unit 107 (first notification unit, second notification unit, third notification unit).
[0046] The first communication unit 101 is a functional unit that performs data communication with the cloud 20. The first communication unit 101 is realized, for example, by the network I / F 509 and the CPU 501 shown in FIG.
[0047] The second communication unit 102 is a functional unit that performs data communication with external devices such as the edge device 30 and the user terminal 40 via the network N. The second communication unit 102 is realized, for example, by the network I / F 509 shown in FIG. 2 and a program executed by the CPU 501. In this case, the network I / F 509 that realizes the second communication unit 102 may be a different interface from the network I / F 509 that realizes the first communication unit 101.
[0048] The authentication unit 103 is a functional unit that performs authentication processing using user information managed by the cloud 20. The user information includes a user ID, a password, and the company to which the user belongs (an example of the organization to which the user belongs), etc. The authentication unit 103 is realized, for example, by the CPU 501 shown in FIG. 2 executing a program.
[0049] The job receiving unit 104 is a functional unit that receives a job that a user of the user terminal 40 desires to output. Job information that constitutes a job includes a user ID, a security level (security information) selected by the user, and output data to be output. Note that the job information that a user desires to output on the edge device 30 is not limited to job information stored in the cloud 20, but may also be job information stored in the user terminal 40 used by the user. The job receiving unit 104 is realized, for example, by a program executed by the CPU 501 shown in FIG. 2.
[0050] The job management unit 105 is a functional unit that manages job information and is realized, for example, by a program executed by the CPU 501 shown in FIG.
[0051] The determination unit 106 is a functional unit that determines whether or not the job information can be executed in the specified edge device 30 based on the job information accepted by the job acceptance unit 104 and the user information of the user of the edge device 30. The determination unit 106 is realized, for example, by the CPU 501 shown in FIG. 2 executing a program.
[0052] The display control unit 107 is a functional unit that controls the display operation on the user terminal 40 using screen data managed by the cloud 20. The display control unit 107 is realized, for example, by a program being executed by the CPU 501 shown in FIG.
[0053] Note that the authentication unit 103, job reception unit 104, job management unit 105, determination unit 106, and display control unit 107 of the cloud gateway 10 shown in Fig. 4 are not limited to being realized by the CPU 501 in Fig. 2 executing a program. For example, they may be realized by hardware such as an integrated circuit, or may be realized by a combination of software and hardware.
[0054] Furthermore, the functions of each functional unit of the cloud gateway 10 shown in Fig. 4 are conceptually illustrated, and the configuration is not limited to this. For example, the multiple functional units illustrated as independent functional units in the cloud gateway 10 shown in Fig. 4 may be configured as a single functional unit. On the other hand, the function of a single functional unit in the cloud gateway 10 shown in Fig. 4 may be divided into multiple functional units and configured as multiple functional units.
[0055] As shown in FIG. 4, the cloud 20 includes a communication unit 201, a screen management unit 202, a user information management unit 203, and a user information registration unit 204.
[0056] The communication unit 201 is a functional unit that performs data communication with the cloud gateway 10. That is, when the user terminal 40 stores data in the cloud 20, the user terminal 40 transmits the data to the cloud 20 via the cloud gateway 10. The communication unit 201 is realized, for example, by the network I / F 509 and a program executed by the CPU 501 shown in FIG.
[0057] The screen management unit 202 is a functional unit that manages screen data displayed on the user terminal 40. The screen management unit 202 is realized, for example, by the CPU 501 shown in FIG.
[0058] The user information management unit 203 is a functional unit that manages user information of the user of the user terminal 40. The user information management unit 203 is realized, for example, by the CPU 501 shown in FIG.
[0059] The user information registration unit 204 is a functional unit that registers user information in accordance with operations on an administrator's PC or the like operated by an administrator. The user information registration unit 204 is realized, for example, by a program being executed by the CPU 501 shown in FIG.
[0060] Note that the screen management unit 202, user information management unit 203, and user information registration unit 204 of the cloud 20 shown in Fig. 4 are not limited to being realized by a program being executed by the CPU 501 in Fig. 2. For example, they may be realized by hardware such as an integrated circuit, or may be realized by a combination of software and hardware.
[0061] Furthermore, the functional units of the cloud 20 shown in Fig. 4 are conceptual representations of functions, and are not limited to such a configuration. For example, the multiple functional units illustrated as independent functional units in the cloud 20 shown in Fig. 4 may be configured as a single functional unit. On the other hand, the function of one functional unit in the cloud 20 shown in Fig. 4 may be divided into multiple units and configured as multiple functional units.
[0062] As shown in FIG. 4, the edge device 30 includes a communication unit 301 and a job execution unit 302.
[0063] The communication unit 301 is a functional unit that performs data communication with the cloud gateway 10 via the network N. The communication unit 301 is realized, for example, by the network I / F 604b and the CPU 601 shown in FIG.
[0064] The job execution unit 302 is a functional unit that executes job information in accordance with instructions from the job management unit 105 of the cloud gateway 10. Specifically, the job execution unit 302 causes the output data of the job information to be printed out by the plotter 631. The job execution unit 302 is realized, for example, by the CPU 601 shown in FIG. 3 executing a program.
[0065] Note that the functions of each functional unit of the edge device 30 shown in Fig. 4 are conceptually shown, and the configuration is not limited to this. For example, the multiple functional units shown as independent functional units in the edge device 30 shown in Fig. 4 may be configured as a single functional unit. On the other hand, the function of a single functional unit in the edge device 30 shown in Fig. 4 may be divided into multiple functional units, and configured as multiple functional units.
[0066] As shown in FIG. 4, the user terminal 40 includes a communication unit 401, an input unit 402, and a display control unit 403.
[0067] The communication unit 401 is a functional unit that performs data communication with the cloud gateway 10 via the network N. The communication unit 401 is realized, for example, by the network I / F 509 and the CPU 501 shown in FIG.
[0068] The input unit 402 is a functional unit that accepts operational inputs from the user and is realized by the keyboard 511 and mouse 512 shown in FIG.
[0069] The display control unit 403 is a functional unit that controls the display operation of the display 508. Furthermore, the display control unit 403 displays screen data on the display 508 in accordance with a command from the display control unit 107 of the cloud gateway 10. The display control unit 403 is realized, for example, by the CPU 501 shown in FIG. 2 executing a program.
[0070] Note that the display control unit 403 of the user terminal 40 shown in Fig. 4 is not limited to being realized by the CPU 501 in Fig. 2 executing a program. For example, it may be realized by hardware such as an integrated circuit, or may be realized by a combination of software and hardware.
[0071] Furthermore, the functional units of user terminal 40 shown in Fig. 4 are conceptual representations of functions, and are not limited to such configurations. For example, the multiple functional units shown as independent functional units in user terminal 40 shown in Fig. 4 may be configured as a single functional unit. On the other hand, the function of a single functional unit in user terminal 40 shown in Fig. 4 may be divided into multiple functional units, and configured as multiple functional units.
[0072] (Behavior when a specific user uses an edge device) FIG. 5 is a diagram illustrating a case where a specific user uses an edge device in the information processing system according to the first embodiment. FIG. 6 is a sequence diagram illustrating an example of the flow of operations when user A uses a specific edge device in the information processing system according to the first embodiment. FIG. 7 is a diagram illustrating an example of a login screen. FIG. 8 is a diagram illustrating an example of a job list screen. FIG. 9 is a diagram illustrating an example of a job execution screen. With reference to FIGS. 5 to 9, the operations when a specific user uses an edge device 30 in the information processing system 1 according to this embodiment will be described.
[0073] 5, assume that a specific user is user A of user terminal 40a, and consider a case where output data of user A managed in cloud 20 is printed out from edge device 30a. The flow of operations of information processing system 1 in this case will be described below with reference to FIG.
[0074] <Steps S11 and S12> It is assumed that the administrator has registered the user information of user A in the auxiliary storage device 505 of the cloud 20 from the administrator PC as a preliminary preparation.
[0075] <Steps S13 and S14> User A of user terminal 40a performs an operation to receive authentication to use edge devices 30a to 30c, which are shared facilities installed in a coworking space or the like. Specifically, user A of user terminal 40a operates input unit 402 on login screen 1000 shown in FIG. 7 to input his / her user ID and password and presses the login button. Then, communication unit 401 of user terminal 40a transmits a usage authentication request together with the input user ID and password to cloud gateway 10. When second communication unit 102 of cloud gateway 10 receives the usage authentication request, user ID, and password, authentication unit 103 transmits a user information acquisition request together with the user ID to cloud 20 via first communication unit 101.
[0076] <Steps S15 and S16> When the communication unit 201 of the cloud 20 receives a user information acquisition request and a user ID, the user information management unit 203 extracts user information that matches the user ID received by the communication unit 201 from the user information registered in the auxiliary storage device 505 of the cloud 20, and transmits the user information to the cloud gateway 10 via the communication unit 201. When the user information is received by the first communication unit 101 of the cloud gateway 10, the authentication unit 103 performs authentication processing to determine whether the password of the user ID received from the user terminal 40a matches the password included in the user information.
[0077] <Step S17> If the authentication process results in authentication success, the authentication unit 103 transmits a message indicating that the authentication has been successful to the user terminal 40a via the second communication unit 102. This allows the user terminal 40a to use the edge devices 30a to 30c, etc., which are shared facilities.
[0078] <Step S18> User A operates the input unit 402 to display the job list in order to print out his / her own data stored in the cloud 20 from the edge device 30a. When the second communication unit 102 of the cloud gateway 10 receives the job list display operation from the user terminal 40a, the job management unit 105 transmits a job information request to the cloud 20 via the first communication unit 101 to request job information of user A.
[0079] <Steps S19 and S20> When the communication unit 201 of the cloud 20 receives the job information request for user A, it extracts a list of job information including data of user A from the auxiliary storage device 505 and transmits it to the cloud gateway 10. When the list of job information is received by the first communication unit 101 of the cloud gateway 10, the job management unit 105 transmits the list of job information to the user terminal 40a via the second communication unit 102. When the list of job information of user A is received from the communication unit 401 of the user terminal 40a, the display control unit 403 causes the display 508 to display a job list screen 1100 shown in FIG. 8 for displaying the list of job information.
[0080] 8, the job list screen 1100 includes a job list display section 1101 and an execute job button 1102. The job list display section 1101 is a display area that displays a list of job information. The execute job button 1102 is a button for executing job information selected in the job list display section 1101.
[0081] <Step S21> User A operates the input unit 402 to select job information to be printed by the edge device 30a from the job information displayed on the job list screen 1100. At this time, user A sets the security level of the job information to be output in advance on a security type selection screen 1300 shown in FIG. 10 (described later). The security level may be set for each user or for each job information. In the following description, it is assumed that user A sets the security level of the job information to “confidential.” Here, “confidential” refers to a security level that should be kept secret from outsiders but is permitted to be disclosed to internal personnel. Furthermore, “top confidential” refers to a security level that should be kept secret from all others, regardless of whether they are internal or external personnel. When user A presses the job execution button 1102 on the job list screen 1100, the communication unit 401 of the user terminal 40a transmits the selected job information and a message indicating that the job execution button 1102 has been pressed to the cloud gateway 10.
[0082] <Steps S22 to S24> When the second communication unit 102 of the cloud gateway 10 receives a notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. Then, the determination unit 106 performs a usage permission determination to determine whether the job information can be executed in the edge device 30a (an example of a first edge device) based on the job information received by the job receiving unit 104 and the user information of user A, etc. If the result of the usage permission determination is usage permission, the determination unit 106 transmits a notification that usage is permission to the user terminal 40a via the second communication unit 102. For example, if there is no other job information being executed in the edge device 30a, the determination unit 106 determines usage permission. On the other hand, if the result of the usage permission determination is usage denial, the determination unit 106 transmits a notification that usage is denial to the user terminal 40a via the second communication unit 102.
[0083] <Steps S25 and S26> If the determination unit 106 determines that use is OK, the job management unit 105 transmits a job execution request together with the job information to the edge device 30a via the second communication unit 102. When the communication unit 301 of the edge device 30a receives the job execution request and the job information, the job execution unit 302 executes the job information. Furthermore, the display control unit 107 of the cloud gateway 10 receives screen data of a job execution screen 1200 shown in FIG. 9 from the screen management unit 202 of the cloud 20 and transmits it to the user terminal 40a via the second communication unit 102 to display it on the display 508 of the user terminal 40a. When the screen data of the job execution screen 1200 is received from the communication unit 401 of the user terminal 40a, the display control unit 403 displays the job execution screen 1200 on the display 508.
[0084] <Step S27> When the execution of the job information is completed, that is, when the plotter 631 has completed printing the output data of the job information, the job execution unit 302 of the edge device 30a transmits a notification of job completion to the cloud gateway 10 via the communication unit 301.
[0085] (Operation when users from different companies use the same edge device) FIG. 10 is a diagram illustrating a case where a person from the same company as user A and a person from a different company use the same edge device in the information processing system according to the first embodiment. FIGS. 11A and 11B are sequence diagrams illustrating an example of the flow of operations when user A and user C, who is from a different company, use the same edge device in the information processing system according to the first embodiment. FIG. 12 is a diagram illustrating an example of a usage NG screen. With reference to FIGS. 10 to 12, the operations when users from different companies use the same edge device 30 in the information processing system 1 according to this embodiment will be described.
[0086] As shown in Fig. 10, consider a case where user A using user terminal 40a causes user C, who is in a different company from user A, to print out output data of user C managed in cloud 20 from edge device 30a using user terminal 40c. In this case, it is assumed that user C uses edge device 30a on which user A is executing job information. The flow of operations of information processing system 1 in this case will be described below with reference to Figs. 11A and 11B.
[0087] <Steps S31 to S34> As a preliminary step, the administrator has registered the user information of user A and user C from the administrator PC to the auxiliary storage device 505 of the cloud 20. In this case, the user information of user A includes the fact that the company to which he belongs is company X, and the user information of user C includes the fact that the company to which he belongs is company Y.
[0088] <Steps S35 to S42> The processes in steps S35 to S42 are similar to the processes in steps S13 to S20 shown in FIG. 6 above.
[0089] <Step S43> User A operates the input unit 402 to select job information to be printed out by the edge device 30a from the job information displayed on the job list screen 1100. At this time, user A sets in advance the security level of the job information to be output on the security type selection screen 1300 shown in Fig. 10. Note that the security level may be set for each user or for each piece of job information.
[0090] 10 , the security type selection screen 1300 includes a confidential check box 1301 and a top confidential check box 1302. The confidential check box 1301 is a check box for selecting whether or not the security level of the job information is to be set to "confidential." The top confidential check box 1302 is a check box for selecting whether or not the security level of the job information is to be set to "top confidential." In the following description, it is assumed that the security level of the job information is set to "confidential." When user A presses the job execution button 1102 on the job list screen 1100, the communication unit 401 of the user terminal 40a transmits the selected job information (including the security level) and a message that the job execution button 1102 has been pressed to the cloud gateway 10.
[0091] <Steps S44 and S45> When the second communication unit 102 of the cloud gateway 10 receives a notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. Then, the determination unit 106 performs a usage permission determination to determine whether the job information can be executed in the edge device 30a (an example of a first edge device) based on the job information received by the job receiving unit 104 and the user information of user A, etc. For example, the determination unit 106 determines that usage is OK if there is no other job information currently being executed in the edge device 30a. Since the result of the usage permission determination indicates that usage is OK, the determination unit 106 transmits a notification that usage is OK to the user terminal 40a via the second communication unit 102.
[0092] <Steps S46 and S47> Because the determination unit 106 determines that use is OK, the job management unit 105 transmits a job execution request together with the job information to the edge device 30a via the second communication unit 102. When the communication unit 301 of the edge device 30a receives the job execution request and the job information, the job execution unit 302 executes the job information. Furthermore, the display control unit 107 of the cloud gateway 10 receives screen data for the job execution screen 1200 shown in FIG. 9 from the screen management unit 202 of the cloud 20 and transmits it to the user terminal 40a via the second communication unit 102 to display it on the display 508 of the user terminal 40a. When the screen data for the job execution screen 1200 is received from the communication unit 401 of the user terminal 40a, the display control unit 403 displays the job execution screen 1200 on the display 508.
[0093] <Steps S48 to S52> User C of user terminal 40c performs an operation to be authenticated to use edge devices 30a to 30c, etc., which are shared facilities installed in a coworking space, etc. The processing of steps S48 to S52 for this authentication is the same as the processing of steps S35 to S39 described above, respectively.
[0094] <Step S53> User C operates the input unit 402 of the user terminal 40c to display the job list in order to print out his / her own data stored in the cloud 20 from the edge device 30a. When the second communication unit 102 of the cloud gateway 10 receives the job list display operation from the user terminal 40c, the job management unit 105 transmits a job information request to the cloud 20 via the first communication unit 101 to request job information of user C.
[0095] <Steps S54 and S55> When the communication unit 201 of the cloud 20 receives the job information request for user C, it extracts a list of job information including data of user C from the auxiliary storage device 505 and transmits it to the cloud gateway 10. When the list of job information is received by the first communication unit 101 of the cloud gateway 10, the job management unit 105 transmits the list of job information to the user terminal 40c via the second communication unit 102. When the list of job information of user C is received from the communication unit 401 of the user terminal 40c, the display control unit 403 causes the display 508 to display a job list screen 1100 as shown in FIG. 8 described above for displaying the list of job information.
[0096] <Step S56> User C operates the input unit 402 to select job information to be printed out by the edge device 30a from the job information displayed on the job list screen 1100. When user C presses the job execution button 1102 on the job list screen 1100, the communication unit 401 of the user terminal 40c transmits to the cloud gateway 10 the selected job information and a message that the job execution button 1102 has been pressed.
[0097] <Step S57> When the second communication unit 102 of the cloud gateway 10 receives a notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. The determination unit 106 then determines whether or not the job information of user C can be executed on the edge device 30a, based on the job information of users A and C received by the job receiving unit 104 and the user information of users A and C. Specifically, the determination unit 106 determines that the job information of user A being executed on the edge device 30a is NG because the security level of the job information of user A being executed on the edge device 30a is "confidential" and the company to which user C belongs is different from the company to which user A belongs based on the company information of users A and C. As a result, even if the determination was NG, when user C goes to the edge device 30a to retrieve a printed copy of his / her output data, it is possible to avoid the risk of the user C viewing the contents of the printed copy of user A that was just printed out as "confidential" job information.
[0098] <Step S58> The determination unit 106 transmits a notice of denial of use to the user terminal 40c via the second communication unit 102. Furthermore, the display control unit 107 receives screen data of a use denial screen 1400, shown in FIG. 12 , indicating that the edge device 30a is not available, from the screen management unit 202 of the cloud 20, and transmits the screen data to the user terminal 40c via the second communication unit 102 to display the use denial screen 1400 on the display 508 of the user terminal 40c. When the communication unit 401 of the user terminal 40c receives the screen data of the use denial screen 1400, the display control unit 403 displays the use denial screen 1400 on the display 508. In other words, the display control unit 107 notifies the user terminal 40c that the job information cannot be executed on the edge device 30a. This allows user C to recognize that another user is executing job information that poses a security risk.
[0099] <Step S59> When the execution of user A's job information is completed, i.e., when the plotter 631 has completed printing of the output data of the job information, the job execution unit 302 of the edge device 30a sends a notification of job completion to the cloud gateway 10 via the communication unit 301.
[0100] <Step S60> Since the execution of the job information of user A in the edge device 30a has been completed, the determination unit 106 again determines whether the job information of user C can be executed in the edge device 30a based on the job information of user C accepted by the job acceptance unit 104 and the user information of user C. In this case, the determination unit 106 determines that the job information of user C is OK to be used because there is no other job information being executed in the edge device 30a.
[0101] <Step S61> As a result of the use permission determination, use is OK, so the determination unit 106 transmits information that use is OK to the user terminal 40c via the second communication unit 102. After this, for example, the job management unit 105 may transmit a job execution request together with the job information of user C to the edge device 30a via the second communication unit 102, or may once again have user C select job information and perform an execution operation.
[0102] As described above, when the edge device 30a is executing job information of user A, whose security level is set to "confidential," and receives job information of user C, who is in a different company from the user A related to the job information, the execution of the job information of user C is prohibited. This prevents user C from seeing the contents of the printout of user A's job information, which was just printed out as "confidential," when user C goes to the edge device 30a to obtain the printout of his / her own output data.
[0103] (Operation when users from the same company use the same edge device) 13A and 13B are sequence diagrams showing an example of the flow of operations when user A and user B of the same company use the same edge device in the information processing system according to the first embodiment. With reference to FIGS. 13A and 13B, the operations when users of the same company use the same edge device 30 in the information processing system 1 according to this embodiment will be described.
[0104] As shown in Fig. 10, consider a case where user A using user terminal 40a causes user B, who works in the same company as user A, to print out output data from user terminal 40b of user B, which is managed in cloud 20, from edge device 30a. In this case, it is assumed that user B uses edge device 30a on which user A is executing job information. The flow of operations of information processing system 1 in this case will be described below with reference to Figs. 13A and 13B.
[0105] <Steps S71 to S74> As a preliminary step, the administrator has registered the user information of user A and user B from the administrator PC to the auxiliary storage device 505 of the cloud 20. In this case, the user information of user A includes the fact that the company to which he belongs is company X, and the user information of user B also includes the fact that the company to which he belongs is company X.
[0106] <Steps S75 to S87> The processes in steps S75 to S87 are the same as the processes in steps S35 to S47 shown in FIG. 11, respectively.
[0107] <Steps S88 to S92> User B of user terminal 40b performs an operation to be authenticated to use edge devices 30a to 30c, etc., which are shared facilities installed in a coworking space, etc. The processing of steps S88 to S92 for this authentication is the same as the processing of steps S48 to S52 shown in FIG.
[0108] <Step S93> User B operates the input unit 402 of the user terminal 40b to display the job list in order to print out his / her own data stored in the cloud 20 from the edge device 30a. When the second communication unit 102 of the cloud gateway 10 receives the job list display operation from the user terminal 40b, the job management unit 105 transmits a job information request to the cloud 20 via the first communication unit 101 to request job information of user B.
[0109] <Steps S94 and S95> When the communication unit 201 of the cloud 20 receives the job information request for user B, it extracts a list of job information including data of user B from the auxiliary storage device 505 and transmits it to the cloud gateway 10. When the list of job information is received by the first communication unit 101 of the cloud gateway 10, the job management unit 105 transmits the list of job information to the user terminal 40b via the second communication unit 102. When the list of job information of user B is received by the communication unit 401 of the user terminal 40b, the display control unit 403 causes the display 508 to display a job list screen 1100 as shown in FIG. 8 described above for displaying the list of job information.
[0110] <Step S96> User B operates the input unit 402 to select job information to be printed out by the edge device 30a from the job information displayed on the job list screen 1100. When User B presses the job execution button 1102 on the job list screen 1100, the communication unit 401 of the user terminal 40b transmits to the cloud gateway 10 the selected job information and a message that the job execution button 1102 has been pressed.
[0111] <Step S97> When the second communication unit 102 of the cloud gateway 10 receives a notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. Then, the determination unit 106 determines whether the job information of user B can be executed on the edge device 30a based on the job information of user A and user B and the user information of user A and user B received by the job receiving unit 104. Specifically, the determination unit 106 determines that the job information of user A being executed on the edge device 30a is OK because the security level of the job information of user A being executed on the edge device 30a is "confidential" and the company to which user B belongs is the same as the company to which user A belongs based on the company to which user A belongs in the user information of user A and user B. In other words, although the security level of the job information of user A currently being executed is "confidential," user B, whose job information is about to be executed, belongs to the same company as user A. Therefore, there is no security problem when user B's job information is executed on edge device 30a that is executing user A's job information, and printing output on edge device 30a is permitted.
[0112] <Step S98> The determination unit 106 transmits to the user terminal 40b via the second communication unit 102 a message indicating that use is permitted.
[0113] <Steps S99 and S100> Because the determination unit 106 determines that use is OK, the job management unit 105 transmits a job execution request together with the job information to the edge device 30a via the second communication unit 102. When the communication unit 301 of the edge device 30a receives the job execution request and the job information, the job execution unit 302 executes the job information. Furthermore, the display control unit 107 of the cloud gateway 10 receives screen data for the job execution screen 1200 shown in FIG. 9 from the screen management unit 202 of the cloud 20 and transmits it to the user terminal 40b via the second communication unit 102 to display it on the display 508 of the user terminal 40b. When the communication unit 401 of the user terminal 40b receives the screen data for the job execution screen 1200, the display control unit 403 displays the job execution screen 1200 on the display 508.
[0114] <Step S101> When the execution of user A's job information is completed, i.e., when the plotter 631 has completed printing of the output data of the job information, the job execution unit 302 of the edge device 30a sends a notification of job completion to the cloud gateway 10 via the communication unit 301.
[0115] <Step S102> When the execution of the job information of User B is completed, that is, when the plotter 631 has completed printing the output data of the job information, the job execution unit 302 of the edge device 30a transmits a notice of job completion to the cloud gateway 10 via the communication unit 301. At this time, even if User B goes to the edge device 30a to obtain the printed matter, and the printed matter of User A printed out in step S101 is still there, and User B happens to see the contents of the printed matter, no security problem will arise because the printed matter is treated as "confidential" and both users belong to the same company.
[0116] As described above, in the information processing system 1 according to this embodiment, the first communication unit 101 acquires user information of the user of the user terminal 40 from the cloud 20, the job receiving unit 104 receives job information to be output in accordance with an operation on the user terminal 40, the determination unit 106 determines whether the job information is executable on the edge device 30 to which the job information is to be output, based on at least the security level and the user information included in the job information, and the job management unit 105 requests the edge device 30 to execute the job information if the determination unit 106 determines that the job information is executable. Furthermore, if the determination unit 106 determines that the job information is not executable, the display control unit 107 notifies the user terminal 40 that the job information is not executable. This ensures security when using an edge device 30 shared by multiple users.
[0117] [Second embodiment] The information processing system 1 according to the second embodiment will be described, focusing on the differences from the information processing system 1 according to the first embodiment. In the first embodiment, an operation of notifying a user terminal 40 that has been determined to be unusable in the usability determination that the terminal is unusable will be described. In this embodiment, an operation of sending a notification to a user terminal 40 that has been determined to be unusable in the usability determination to prompt the user terminal 40 to switch to using another alternative edge device 30 will be described. Note that the overall configuration of the information processing system 1 according to this embodiment, the hardware configuration of the cloud gateway 10, the cloud 20, the edge device 30, and the user terminal 40, and the configuration of the functional blocks of the information processing system 1 are the same as those described in the first embodiment.
[0118] (Operation when users from different companies use the same edge device) Fig. 14 is a diagram illustrating a case in which user C, who is in a different company from user A, is prompted to use a different edge device in the information processing system according to the second embodiment. Figs. 15A and 15B are sequence diagrams illustrating an example of the flow of operations when user A and user C, who is in a different company, use the same edge device in the information processing system according to the second embodiment. With reference to Figs. 14, 15A, and 15B, operations when users from different companies use the same edge device 30 in the information processing system 1 according to this embodiment will be described.
[0119] As shown in Fig. 14, consider a case where user A using user terminal 40a causes user C, who is in a different company from user A, to print out output data of user C managed in cloud 20 from edge device 30a using user terminal 40c. In this case, it is assumed that user C uses edge device 30a on which user A is executing job information. The flow of operations of information processing system 1 in this case will be described below with reference to Figs. 15A and 15B.
[0120] <Steps S111 to S114> As a preliminary step, the administrator has registered the user information of user A and user C from the administrator PC to the auxiliary storage device 505 of the cloud 20. In this case, the user information of user A includes the fact that the company to which he belongs is company X, and the user information of user C includes the fact that the company to which he belongs is company Y.
[0121] <Steps S115 to S122> The processes in steps S115 to S122 are similar to the processes in steps S35 to S42 shown in FIG. 11, respectively.
[0122] <Step S123> User A operates the input unit 402 to select job information to be printed out by the edge device 30a from the job information displayed on the job list screen 1100. At this time, user A sets in advance the security level of the job information to be output on a security type selection screen 1300 shown in FIG. 14. Note that the security level may be set for each user or for each piece of job information. In the following description, it is assumed that user A has set the security level of the job information to "confidential." Then, when user A presses the job execution button 1102 on the job list screen 1100, the communication unit 401 of the user terminal 40a transmits the selected job information (including the security level) and a message that the job execution button 1102 has been pressed to the cloud gateway 10.
[0123] <Steps S124 and S125> When the second communication unit 102 of the cloud gateway 10 receives a notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. Then, the determination unit 106 performs a usage permission determination to determine whether the job information can be executed in the edge device 30a based on the job information received by the job receiving unit 104 and the user information of user A, etc. For example, if there is no other job information being executed in the edge device 30a, the determination unit 106 determines that usage is OK. Since the result of the usage permission determination indicates that usage is OK, the determination unit 106 transmits a notification that usage is OK to the user terminal 40a via the second communication unit 102.
[0124] <Steps S126 and S127> Because the determination unit 106 determines that use is OK, the job management unit 105 transmits a job execution request together with the job information to the edge device 30a via the second communication unit 102. When the communication unit 301 of the edge device 30a receives the job execution request and the job information, the job execution unit 302 executes the job information. Furthermore, the display control unit 107 of the cloud gateway 10 receives screen data for the job execution screen 1200 shown in FIG. 9 from the screen management unit 202 of the cloud 20 and transmits it to the user terminal 40a via the second communication unit 102 to display it on the display 508 of the user terminal 40a. When the communication unit 401 of the user terminal 40a receives the screen data for the job execution screen 1200, the display control unit 403 displays the job execution screen 1200 on the display 508.
[0125] <Steps S128 to S136> The processing of steps S128 to S136 for this authentication is the same as the processing of steps S48 to S56 shown in FIG. 11 above, respectively.
[0126] <Step S137> When the second communication unit 102 of the cloud gateway 10 receives a notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. Then, the determination unit 106 determines whether the job information of user C can be executed on the edge device 30a based on the job information of users A and C and the user information of users A and C received by the job receiving unit 104. Specifically, the determination unit 106 determines that the job information of user A being executed on the edge device 30a is NG because the security level of the job information of user A being executed on the edge device 30a is "confidential" and the company to which user C belongs is different from the company to which user A belongs based on the company information of users A and C.
[0127] <Step S138> If it is determined that the edge device 30a is not usable, the determination unit 106 searches for another edge device 30 (second edge device) among the shared edge devices 30 installed in the coworking space that can execute the job information of user C on behalf of user C. For example, the determination unit 106 searches for another edge device 30 that is not currently executing the job information, or another edge device 30 that is currently executing the job information but that does not pose a security problem if it is allowed to execute the job information of user C based on its security level. Here, the description will be made assuming that the determination unit 106 has searched for edge device 30b (an example of a second edge device) as the edge device 30 that can execute the job information of user C on behalf of user C.
[0128] <Steps S139 and S140> 14, the display control unit 107 transmits a notification to the user terminal 40c via the second communication unit 102 indicating that the edge device 30a is unavailable and urging the user to switch to using the edge device 30b. In response to the notification displayed on the display 508 of the user terminal 40c, the user C operates the input unit 402 to accept the switch to using the edge device 30b. The communication unit 401 of the user terminal 40c then transmits a notification to the cloud gateway 10 indicating that the user C accepts the switch to using the edge device 30b.
[0129] <Steps S141 and S142> When the second communication unit 102 of the cloud gateway 10 receives a notice of consent to the change to use of the edge device 30b, the job management unit 105 sends a job execution request along with the job information of user C to the edge device 30b via the second communication unit 102. When the communication unit 301 of the edge device 30b receives the job execution request and the job information, the job execution unit 302 executes the job information. Furthermore, the display control unit 107 of the cloud gateway 10 receives screen data for the job execution screen 1200 shown in FIG. 9 from the screen management unit 202 of the cloud 20 and transmits it to the user terminal 40c via the second communication unit 102 to display it on the display 508 of the user terminal 40c. When the communication unit 401 of the user terminal 40c receives the screen data for the job execution screen 1200, the display control unit 403 displays the job execution screen 1200 on the display 508.
[0130] <Step S143> When the execution of user A's job information is completed, i.e., when the plotter 631 has completed printing of the output data of the job information, the job execution unit 302 of the edge device 30a sends a notification of job completion to the cloud gateway 10 via the communication unit 301.
[0131] <Step S144> When the execution of user C's job information is completed, i.e., when the plotter 631 has completed printing out the output data of the job information, the job execution unit 302 of edge device 30b transmits a notification of job completion to the cloud gateway 10 via the communication unit 301. In this way, user C's job information is executed by an edge device 30 (edge device 30b in this case) different from the edge device 30a where user A's job information is executed. Therefore, when user C goes to obtain a printout of his or her own output data, it is possible to avoid the risk of user C seeing the contents of user A's printout, which has been printed out as "confidential" job information.
[0132] As described above, in the information processing system 1 according to this embodiment, when the determination unit 106 determines that job information cannot be executed, it searches for another edge device 30 that can execute the job information, and the display control unit 107 notifies the user terminal 40 of a prompt to change to using the searched edge device 30. This achieves the same effect as the first embodiment described above, and also makes it possible to print out using the other edge device 30 that is prompted, thereby suppressing a decrease in convenience.
[0133] [Third embodiment] The information processing system 1 according to the third embodiment will be described, focusing on the differences from the information processing system 1 according to the first embodiment. In the first embodiment, an operation of notifying a user terminal 40 that has been determined to be unusable in the usage permission determination that the user terminal 40 is unusable will be described. In this embodiment, an operation of issuing a warning when a person is present near the edge device 30 that prints out, even if the usage permission determination determines that the user terminal 40 is usable, will be described. Note that the overall configuration of the information processing system 1 according to this embodiment, the hardware configuration of the cloud gateway 10, the cloud 20, the edge device 30, and the user terminal 40, and the configuration of the functional blocks of the information processing system 1 are the same as those described in the first embodiment.
[0134] (Operation when using an edge device and there are people nearby) FIG. 16 is a diagram illustrating a case where there is a person nearby an edge device used by a specific user in the information processing system according to the third embodiment. FIG. 17 is a sequence diagram illustrating an example of the flow of operations when there is a person nearby when user A uses a specific edge device in the information processing system according to the third embodiment. FIG. 18 is a diagram illustrating an example of an output security screen. With reference to FIGS. 16 to 18, operations when there is a person nearby when a user uses edge device 30 in the information processing system 1 according to this embodiment will be described.
[0135] 16, assume that the user is user A of user terminal 40a, and consider a case where output data of user A managed in cloud 20 is printed out from edge device 30a. The flow of operations of information processing system 1 in this case will be described below with reference to FIG.
[0136] <Steps S151 to S161> The processes in steps S151 to S161 are the same as the processes in steps S11 to S21 shown in FIG. 6 above.
[0137] <Step S162> When the second communication unit 102 of the cloud gateway 10 receives the notification that the job execution button 1102 has been pressed and the job information, the job receiving unit 104 receives the job information as job information to be executed. Then, the determination unit 106 determines whether the job information can be executed on the edge device 30a based on the job information received by the job receiving unit 104 and the user information of user A, etc. Here, the description will be given assuming that the determination unit 106 has determined that the job information is OK for use.
[0138] <Steps S163 and S164> The determination unit 106 transmits an edge device surrounding information request to the edge device 30a via the second communication unit 102 to request information about the presence or absence of people around the edge device 30a where job information of user A is being executed. When the communication unit 301 of the edge device 30a receives the edge device surrounding information request, the imaging device 633 of the edge device 30a obtains a captured image of the periphery of the edge device 30a. Note that a human presence sensor of the edge device 30a may be configured to detect people present around the edge device 30a. Then, the communication unit 301 transmits edge device surrounding information (periphery information) indicating the presence or absence of people around the edge device 30a to the cloud gateway 10. The edge device surrounding information includes, for example, a captured image, detection information by a human presence sensor, or information indicating whether a person is captured in the captured image.
[0139] <Step S165> When the second communication unit 102 of the cloud gateway 10 receives the edge device peripheral information, the determination unit 106 determines whether a person is present around the edge device 30a to which the edge device peripheral information is output. If the determination unit 106 determines that a person is present around the edge device 30a to which the edge device peripheral information is output, the display control unit 107 receives screen data of an output security warning screen 1500 (shown in FIG. 18 ) from the screen management unit 202 of the cloud 20 to warn that a person is present around the edge device 30a, and transmits the screen data to the user terminal 40a via the second communication unit 102 to display the screen data on the display 508 of the user terminal 40a. In other words, the display control unit 107 notifies the user terminal 40a of a warning that a person is present around the edge device 30a. When the communication unit 401 of the user terminal 40a receives the screen data of the output security warning screen 1500, the display control unit 403 displays the output security warning screen 1500 on the display 508.
[0140] 18, the output security warning screen 1500 includes a continue button 1501 and a cancel button 1502. The continue button 1501 is a button for executing the job information regardless of the warning. The cancel button 1502 is a button for canceling the execution of the job information in accordance with the warning.
[0141] When user A presses the continue button 1501, that is, when a notice to execute job information is received in response to a warning that a person is present near the edge device 30a, the job management unit 105 transmits the job information together with a job execution request to the edge device 30a via the second communication unit 102, and causes the job information to be executed. Also, when user A presses the cancel button 1502, the job management unit 105 cancels the processing of the job information.
[0142] This avoids the risk of the contents of User A's printed materials being seen by printing out the job information on the edge device 30a where there is a person nearby. Furthermore, even if there is a person nearby, if User A determines that there is no problem with the printout on the edge device 30a, the job information can be continued to be executed, thereby preventing a decrease in convenience due to uniformly canceling the job information.
[0143] As described above, in the information processing system 1 according to this embodiment, when the determination unit 106 determines that job information is executable, the second communication unit 102 acquires, from the edge device 30 to which output is to be made, edge device surrounding information indicating the presence or absence of a person around the edge device 30, and when the edge device surrounding information acquired by the second communication unit 102 indicates the presence of a person around the edge device 30, the display control unit 107 notifies the user terminal 40 of a warning that a person is around the edge device 30. This achieves the same effects as the first embodiment described above, and also allows the job information to continue to be executed if the user determines that there is no problem with the print output from the edge device 30, even if a person is around the edge device 30. This makes it possible to prevent a decrease in convenience that would be caused by uniformly canceling job information.
[0144] The above-described embodiments can also be combined with each other.
[0145] Furthermore, each function of each of the above-described embodiments can be realized by one or more processing circuits. Here, the term "processing circuit" includes a processor programmed to execute each function by software, such as a processor implemented by an electronic circuit, as well as devices such as an ASIC, a DSP (Digital Signal Processor), an FPGA (Field Programmable Gate Array), and conventional circuit modules designed to execute each of the above-described functions.
[0146] Furthermore, the programs executed by the cloud gateway 10, the cloud 20, and the edge device 30 in each of the above-described embodiments may be configured to be provided in a state that they are pre-installed in a ROM or the like.
[0147] In addition, the programs executed by the cloud gateway 10, cloud 20, and edge device 30 in each of the above-mentioned embodiments may be configured to be provided as a computer program product by being recorded in an installable or executable format on a computer-readable recording medium such as a CD-ROM (Compact Disc Read Only Memory), a flexible disk (FD), a CD-R (Compact Disk-Recordable), or a DVD (Digital Versatile Disk).
[0148] The programs executed by the cloud gateway 10, the cloud 20, and the edge device 30 in each of the above-described embodiments may be stored on a computer connected to a network such as the Internet and provided by being downloaded via the network. The programs executed by the cloud gateway 10, the cloud 20, and the edge device 30 in each of the above-described embodiments may be provided or distributed via a network such as the Internet.
[0149] In addition, the programs executed by the cloud gateway 10, cloud 20, and edge device 30 in each of the above-mentioned embodiments have a modular structure including each of the above-mentioned functional units, and in actual hardware, the CPU (processor) reads the program from the ROM and executes it, loading each of the above-mentioned functional units onto the main memory device, and each functional unit is generated on the main memory device. [Explanation of symbols]
[0150] 1. Information Processing Systems 10. Cloud Gateway 20. Cloud 30, 30a-30c Edge Devices 40, 40a-40c User terminal 101 First Communications Department 102 Second Communications Department 103 Authentication Department 104 Job Reception Department 105 Job Management Department 106 Judgment section 107 Display control unit 201 Communications Department 202 Screen management department 203 User Information Management Department 204 User Information Registration Department 301 Communications Department 302 Job Execution Unit 401 Communications Department 402 Input section 403 Display control unit 501 CPU 502 ROM 503 RAM 505 Auxiliary storage 506 Recording Media 507 Media Drive 508 Display 509 Network I / F 510 Bus Line 511 keyboard 512 Mouse 513 DVD 514 DVD drive 600 Controller 601 CPU 602 System Memory (MEM-P) 603 Northbridge (NB) 604a Southbridge (SB) 604b Network I / F 604c USB I / F 604d Centronics I / F 604e Sensor I / F 605 AGP 606 ASIC 607 Local Memory (MEM-C) 608 Auxiliary storage 610 Operation display section 620 FCU 631 Plotter 632 Scanner 633 Imaging Device 1000 Login Screen 1100 Job list screen 1101 Job list display section 1102 Job execution button 1200 Job execution screen 1300 Security type selection screen 1301 Confidential checkbox 1302 Confidential Checkbox 1400 Usage NG screen 1500 Output security warning screen 1501 Continue button 1502 Cancel button N Network [Prior art documents] [Patent documents]
[0151] [Patent Document 1] Japanese Patent Application Laid-Open No. 2014-016774
Claims
1. A data processing device connected to a user terminal and a first edge device, a receiving unit that receives, from the user terminal, first job information that constitutes a first job to be output; a determination unit that determines whether the first job constituted by the first job information accepted by the acceptance unit can be executed by the first edge device based on first user information of a user of the user terminal and whether or not there is another second job being executed by the first edge device, and when it is determined that the first edge device is executing the second job, the determination unit determines whether or not the first job can be executed by the first edge device based on the first user information and security information that indicates a security level and is included in the second job information that constitutes the second job; a request unit that, when the determination unit determines that the first job configured by the first job information is executable, requests the first edge device to execute the first job configured by the first job information accepted by the acceptance unit; A data processing device comprising:
2. A data processing device as described in Claim 1, wherein when the determination unit determines that the first edge device is not currently executing the second job, it determines that the first job constituted by the first job information accepted by the acceptance unit is executable by the first edge device.
3. The security level includes at least confidential, 3. The data processing device according to claim 1, wherein when the determination unit determines that the first edge device is currently executing a second job, if the security level indicated by the security information included in the second job information constituting the other second job is confidential, and if the company to which the user belongs included in the second user information of the second job information constituting the second job is different from the company to which the user belongs included in the first user information of the user of the user terminal is different, the determination unit determines that the first job constituted by the first job information cannot be executed by the first edge device.
4. A data processing device as described in any one of claims 1 to 3, further comprising a first notification unit that, when the judgment unit determines that the first job constituted by the first job information cannot be executed, notifies the user terminal that the first job cannot be executed.
5. When the determination unit determines that the first job configured by the first job information is not executable, the determination unit searches for a second edge device that is executable to execute the first job; 4. The data processing device according to claim 1, further comprising a second notification unit that notifies the user terminal of a prompt to change to use of the second edge device.
6. a second acquisition unit that acquires, when the determination unit determines that the first job configured by the first job information is executable, from the first edge device, surrounding information indicating the presence or absence of a person around the first edge device; a third notification unit that, when the surrounding information acquired by the second acquisition unit indicates that a person is present around the first edge device, issues a warning to the user terminal that a person is present around the first edge device; 6. The data processing device according to claim 1, further comprising:
7. 7. The data processing device according to claim 6, wherein the request unit, when receiving from the user terminal a request to execute the first job constituted by the first job information in response to the warning notified by the third notification unit, requests the first edge device to execute the first job.
8. 8. The data processing device according to claim 1, wherein the security level is set for each user or for each piece of job information.
9. An information processing system including a cloud system and a data processing device, the cloud system includes a management unit that manages user information of users; The data processing device includes: a first acquisition unit that acquires first user information of a user of the user terminal from the cloud system; a receiving unit that receives, from the user terminal, first job information that constitutes a first job to be output; a determination unit that determines whether the first job constituted by the first job information accepted by the acceptance unit can be executed by a first edge device based on first user information of a user of the user terminal and whether or not there is another second job being executed by the first edge device, and when it is determined that there is the second job being executed by the first edge device, the determination unit determines whether or not the first job can be executed by the first edge device based on the first user information and security information that indicates a security level and is included in the second job information that constitutes the second job; a request unit that, when the determination unit determines that the first job configured by the first job information is executable, requests the first edge device to execute the first job configured by the first job information accepted by the acceptance unit; An information processing system comprising:
10. A receiving step of receiving, from a user terminal, first job information constituting a first job to be output; a determination unit that determines whether the first job constituted by the first job information received in the receiving step can be executed by a first edge device based on first user information of a user of the user terminal and whether or not there is another second job being executed by the first edge device, and when it is determined that the first edge device is executing the second job, determines whether or not the first job can be executed by the first edge device based on the first user information and security information that indicates a security level and is included in the second job information that constitutes the second job; a request step of requesting the first edge device to execute the first job configured by the first job information received in the receiving step, when it is determined in the determining step that the first job configured by the first job information is executable; A data processing method comprising:
11. On the computer, a receiving step of receiving, from a user terminal, first job information constituting a first job to be output; a step of determining whether the first job constituted by the first job information received in the receiving step can be executed by a first edge device based on first user information of the user of the user terminal and whether or not there is another second job being executed by the first edge device, and when it is determined that there is the second job being executed by the first edge device, a determination step of determining whether or not the first job can be executed by the first edge device based on the first user information and security information indicating a security level included in the second job information that constitutes the second job; a request step of requesting the first edge device to execute the first job configured by the first job information received in the receiving step, when it is determined in the determining step that the first job configured by the first job information is executable; A program to execute.
Citation Information
Patent Citations
Printer
JP2008006778A
Printing system, server, and control program of server
JP2014016774A
Printer, terminal device and computer program
JP2015139990A
Information processing system and information processing method
JP2017182641A
Program and information processing apparatus
JP2020047287A