Information processing device and control method
The information processing device addresses the issue of non-compliant administrator settings by authenticating and enforcing security rules, ensuring secure import and management of user settings in multifunction peripherals.
Patent Information
- Application Number
- JP2022056218
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-30
- Publication Date
- 2025-09-22
- Estimated Expiration
- 2042-03-30
AI Technical Summary
Existing information processing devices, such as multifunction peripherals, fail to ensure that administrator or administrative authority setting values comply with security rules during import, leading to potential login failures and management issues.
An information processing device with an authentication unit to verify administrator setting values against security regulations, and a processing unit to interrupt import if they do not comply, while allowing other user settings to be imported as is.
Ensures secure import of user settings by preventing administrator login failures and maintaining device management capabilities by enforcing compliance with security rules.
Smart Images

Figure 0007742801000001 
Figure 0007742801000002 
Figure 0007742801000003
Abstract
Description
[Technical Field]
[0001] The present disclosure relates to an information processing device and the like. [Background technology]
[0002] Information processing devices such as multifunction peripherals have been widely used for some time. To facilitate the configuration of multifunction peripherals when multiple multifunction peripherals are installed or when a multifunction peripheral is replaced, some multifunction peripherals have a function for importing previously exported setting values (setting values specific to the user who uses the multifunction peripheral, also referred to as user data). Some such multifunction peripherals check the setting values when importing them, and import only those setting values that comply with regulations such as security rules, security policies, and password policies.
[0003] Techniques have also been proposed to make importing easier for multifunction peripherals that operate under security rules. For example, when the setting values to be imported correspond to individual settings for each user, a technique has been proposed that executes import processing of the setting values regardless of the security rules (see, for example, Patent Document 1). [Prior art documents] [Patent documents]
[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-180990 Summary of the Invention [Problem to be solved by the invention]
[0005] In the prior art such as Patent Document 1, it is possible to import setting values for individual user settings regardless of security rules, but it does not take into consideration whether the setting values are those of an administrator or a user with administrative authority. If setting values of an administrator or a user with administrative authority that do not satisfy the security rules are imported, the administrator or the user with administrative authority may not be able to log in to the multifunction device and may not be able to manage the multifunction device. If setting values of all administrators and all users with administrative authority are imported in an incompatible state that does not satisfy the security rules, there is a risk that a problem will occur in which none of the users who are able to manage the multifunction device will be able to log in.
[0006] In view of the above-described problems, the present disclosure has an object to provide an information processing device or the like that can appropriately retrieve user setting values. [Means for solving the problem]
[0007] In order to solve the above-mentioned problems, the information processing device of the present disclosure is characterized by comprising an authentication unit that authenticates a user according to a setting value; an acquisition unit that acquires the setting value; a judgment unit that judges whether an administrator's setting value among the setting values acquired by the acquisition unit satisfies regulations for authentication information; and a processing unit that, when importing the setting values acquired by the acquisition unit, imports the setting values of users other than the administrator as is, and performs processing to interrupt the import if the judgment unit judges that the administrator's setting value does not satisfy the regulations.
[0008] The control method of the present disclosure is characterized by including a step of acquiring setting values, a determination step of determining whether or not an administrator's setting values among the setting values satisfy the regulations for setting values, and a step of, when importing the setting values, importing the setting values of users other than the administrator as they are, and if the administrator's setting values do not satisfy the regulations, interrupting the import. [Effects of the Invention]
[0009] According to the present disclosure, it is possible to provide an information processing device or the like that is capable of appropriately acquiring user setting values. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is an external perspective view of a multifunction peripheral according to a first embodiment; [Figure 2] FIG. 2 is a diagram illustrating the functional configuration of the multifunction peripheral according to the first embodiment. [Figure 3] FIG. 3 is a diagram showing the data configuration of identification and authentication information in the first embodiment. [Figure 4] FIG. 4 is a diagram showing the data structure of unusable login name information in the first embodiment. [Figure 5] FIG. 3 is a diagram showing the data configuration of a system setting information table in the first embodiment. [Figure 6] FIG. 4 is a flowchart showing the flow of import processing in the first embodiment. [Figure 7] FIG. 10 is a flowchart showing the flow of an administrator password change process in the first embodiment. [Figure 8] FIG. 4 is a flowchart showing the flow of login processing in the first embodiment. [Figure 9] FIG. 10 is a flowchart showing the flow of a password change process in the first embodiment. [Figure 10] FIG. 4 is a diagram illustrating an example of operation in the first embodiment. [Figure 11] FIG. 4 is a diagram illustrating an example of operation in the first embodiment. [Figure 12] FIG. 4 is a diagram illustrating an example of operation in the first embodiment. [Figure 13] FIG. 10 is a flowchart showing the flow of a password change process in the second embodiment. [Figure 14] FIG. 10 is a diagram illustrating an example of operation in the second embodiment. [Figure 15] FIG. 10 is a diagram showing the overall configuration of a system according to a third embodiment. [Figure 16]FIG. 11 is a flowchart showing the flow of a password change process in the third embodiment. [Figure 17] FIG. 11 is a flowchart showing the flow of a password-linked change process in the third embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, an embodiment for carrying out the present disclosure will be described with reference to the drawings. Note that the following embodiment is an example for explaining the present disclosure, and the technical scope of the invention described in the claims is not limited to the following description.
[0012] [1. First embodiment] In the first embodiment, a case will be described in which an information processing device according to the present disclosure is applied to a multifunction peripheral 10. The multifunction peripheral 10 is an information processing device having a copy function, a scanner function, a printer function, etc., and is also called an MFP (Multi-Function Printer / Peripheral) or an image forming device.
[0013] [1.1 Functional Configuration] The functional configuration of the multifunction device 10 of this embodiment will be described below. Fig. 1 is an external perspective view of the multifunction device 10, and Fig. 2 is a block diagram showing the functional configuration of the multifunction device 10.
[0014] As shown in FIG. 2, the multifunction device 10 includes a control unit 100, an image input unit 120, an image forming unit 130, an operation panel 140, a storage unit 160, a device connection unit 180, and a communication unit 190.
[0015] The control unit 100 is a functional unit for controlling the entire multifunction device 10. The control unit 100 realizes various functions by reading and executing various programs stored in the storage unit 160, and is configured, for example, by one or more arithmetic devices (CPUs (Central Processing Units)). The control unit 100 may also be configured as an SoC (System on a Chip) having multiple functions among those described below.
[0016] In addition, the control unit 100 functions as an identification and authentication processing unit 102, an operation panel processing unit 104, a copy processing unit 106, a scanner processing unit 108, a printer processing unit 110, an import data processing unit 112, an identification and authentication information management unit 114, and an image processing unit 116 by executing programs stored in the memory unit 160.
[0017] The identification and authentication processing unit 102 identifies and authenticates the user who uses the multifunction device 10. For example, the identification and authentication processing unit 102 performs multifunction device standalone authentication (internal authentication). Internal authentication is a method in which identification and authentication information used for user identification and authentication is stored in advance, and if identification and authentication information that matches information input by the user when using the multifunction device 10 is stored, the identification and authentication processing unit 102 authenticates the user corresponding to the identification and authentication information. Note that the identification and authentication processing unit 102 may also transmit the identification and authentication information to a server device having an authentication function for authenticating users, and authenticate the user based on the authentication result by the server device (external authentication).
[0018] The operation panel processing unit 104 controls the display of the operation panel 140 and acquires the contents input by the user via the operation panel 140 .
[0019] The copy processing unit 106 realizes a copy function. For example, the copy processing unit 106 controls the image input unit 120 to input an image, and controls the image forming unit 130 to form (print) the image on a recording medium such as recording paper.
[0020] The scanner processing unit 108 realizes a scanner function. For example, the scanner processing unit 108 controls the image input unit 120 to input an image, and stores the image in the storage unit 160, stores the image in a device (recording medium) connected to the device connection unit 180, or transmits the image to another device via the communication unit 190.
[0021] The printer processing unit 110 realizes a printer function. For example, the printer processing unit 110 receives print data (e.g., PDL (Page Description Language) data) from an external device via the communication unit 190, and forms (prints) an image based on the print data on a recording medium such as recording paper by controlling the image forming unit 130.
[0022] The import data processing unit 112 performs import processing to acquire import data from other devices via the device connection unit 180 or the like and store the import data in the storage unit 160. The import data is, for example, setting values (user data) of personal information of the user of another multifunction device 10 that has been exported from the other multifunction device 10, and is data to be imported into the multifunction device 10. The import data may include setting values (user data) of multiple users. The import processing will be described later.
[0023] The identification and authentication information management unit 114 manages the identification and authentication information. For example, the identification and authentication information management unit 114 refers to a system setting information table 166 (described later) and, if there is a user who has not logged in for a certain period of time, deletes the identification and authentication information of the user. The identification and authentication information management unit 114 also renders the information included in the deleted identification and authentication information unusable. For example, if the identification and authentication information includes a login name used to identify the user, the identification and authentication information management unit 114 stores unusable login name information including the login name in the unusable login name information storage area 164 to render the login name unusable. Note that the identification and authentication information management unit 114 may make unusable information usable again if a certain period of time has passed since the information was made unusable. For example, the identification and authentication information management unit 114 stores, together with the unusable login name, information on the date (start date) when the unusable login name was made unusable as unusable login name information. Furthermore, the identification and authentication information management unit 114 deletes unusable login name information for which a predetermined period has elapsed since the start date from the unusable login name information storage area 164. This makes the unusable login name available again. Note that settings such as whether to delete the identification and authentication information, the period of no login after which it is determined that the identification and authentication information should be deleted, whether to prohibit reuse of the login name included in the deleted identification and authentication information, and the period during which reuse is permitted are stored, for example, in the system setting information table 166, which will be described later. In this case, the identification and authentication information management unit 114 refers to the system setting information table 166 to delete the identification and authentication information or store or delete the unusable login name information.
[0024] The image processing unit 116 performs various image-related processes. For example, the image processing unit 116 performs image processing such as sharpening and tone conversion on the image input by the image input unit 120.
[0025] The image input unit 120 reads an image of a document and inputs the image to the multifunction device 10. For example, the image input unit 120 is configured by a scanner device that reads a document placed on a document table. The scanner device is a device that converts an image into an electrical signal using an image sensor such as a CCD (Charge Coupled Device) or a CIS (Contact Image Sensor), and quantizes and encodes the electrical signal.
[0026] Image forming unit 130 forms (prints) an image on a recording medium such as recording paper. Image forming unit 130 is configured, for example, by a printing device such as a laser printer that uses an electrophotographic method. Image forming unit 130, for example, feeds recording paper from paper feed tray 132 in FIG. 1, forms an image on the surface of the recording paper, and discharges the recording paper from paper discharge tray 134.
[0027] The operation panel 140 inputs operations for the multifunction peripheral 10 and displays various information. The operation panel 140 is configured with an operation unit 142 and a display unit 144. The operation unit 142 is configured with input devices such as setting buttons and a numeric keypad for inputting operation modes and various settings of the multifunction peripheral 10. The display unit 144 is configured with a display device such as an LCD (Liquid Crystal Display), an organic EL (Electro-Luminescence) display, or a micro LED display. The operation panel 140 may be a touch panel in which the operation unit 142 and the display unit 144 are integrated into one unit. In this case, the method for detecting input to the touch panel may be any common detection method, such as a resistive film method, an infrared method, an electromagnetic induction method, or a capacitance method.
[0028] The multifunction device 10 may have an interface (operation I / F) that can be connected to an input device such as a keyboard or a display device such as a display, in addition to the operation panel 140. In this case, the multifunction device 10 may acquire information input via the input device and display information via the display device.
[0029] The storage unit 160 stores various programs and various data required for the operation of the multifunction peripheral 10. The storage unit 160 is configured by a storage device such as a semiconductor memory such as an SSD (Solid State Drive) or an HDD (Hard Disk Drive).
[0030] The storage unit 160 secures an identification / authentication information storage area 162 and an unusable login name information storage area 164 as storage areas, and further stores a system setting information table 166.
[0031] The identification and authentication information storage area 162 stores the identification and authentication information. For example, as shown in Fig. 3, the identification and authentication information includes a management number of the identification and authentication information (e.g., "3"), an ID that identifies the identification and authentication information (e.g., "0"), a login name (e.g., "USER001"), a password (e.g., "1234AAA+"), a display name (e.g., "User A"), contact information (e.g., "UserA@xxx.ccc.com"), a last logout date and time (e.g., "202005261030"), and an administrator user flag (e.g., "Yes").
[0032] 3, the identification and authentication information includes information used to identify the user (e.g., login name) and information used to authenticate the user (e.g., password). Furthermore, the identification and authentication information includes information specific to the user, such as a display name and contact information. In this way, the identification and authentication information is personalized settings for the user of the multifunction peripheral 10, and is also referred to as account information or authentication data.
[0033] The administrator user flag included in the identification and authentication information is information indicating whether or not the user has authority equivalent to that of an administrator, which will be described later. If the user has administrator authority, "Yes" is stored, and if the user does not have administrator authority, "No" is stored.
[0034] In this embodiment, the multifunction device 10 is assumed to have an administrator and a general user as users. The administrator is a user who has authority to manage the multifunction device 10, and is a device administrator or a service person. The device administrator is a special user designated by the manufacturer of the multifunction device 10. In this embodiment, the ID of the device administrator is "-2", and the ID of the service person is "-1".
[0035] A general user is a user other than the administrator. In this embodiment, the ID of a general user is an integer equal to or greater than 0. As mentioned above, the general users may include users who have the same authority as the administrator. A user who has the same authority as the administrator is also called an administrator user.
[0036] The identification and authentication information of the administrator is stored in advance in the identification and authentication information storage area 162. In addition, the administrator registers a general user by performing an operation to add a user to the multifunction device 10. As a result, the identification and authentication information of the general user is stored in the identification and authentication information storage area 162.
[0037] The unusable login name information storage area 164 stores unusable login name information, which is information relating to unusable login names. The unusable login name information includes, for example, as shown in Fig. 4, the management number of the unusable login name information (e.g., "1"), the unusable login name (e.g., "USER003"), and the start date of the unusable period (e.g., "20150331").
[0038] The system setting information table 166 is a table that stores information about the settings (system settings) of the multifunction device 10. For example, as shown in Fig. 5, the system setting information table 166 stores a table in which system setting item names indicating the names of system setting items, settable values indicating the ranges and types that can be set as setting values (system setting values) for the items, and system setting values set for the items are associated with each other.
[0039] The system setting information table 166 includes settings related to security rules to be applied to the multifunction device 10. The security rules are rules (regulations) for securely operating the multifunction device 10, and are settings for enhancing the security of the multifunction device 10 and improving the convenience of the multifunction device 10. The multifunction device 10 achieves predetermined functions in accordance with the security rules.
[0040] To enhance security, the multifunction device 10 implements, for example, a function for strengthening passwords at login and a function for strengthening account management.
[0041] By realizing the function of strengthening the password at the time of login, the multifunction device 10 behaves, for example, as follows. - Set a minimum password length and restrict (reject) the use of short passwords. - Increase the complexity of the characters used in passwords and restrict (reject) the use of passwords that do not contain the required characters. -When changing a password, restrict (reject) changing to a password that has been used in the past.
[0042] In this way, among the security rules, the settings related to the function for strengthening passwords used at login are regulations related to passwords included in the identification and authentication information. In other words, when the security rules related to passwords are enabled, the security rules are applied to passwords, and the password length and character types used in passwords become more complex, thereby improving the security level.
[0043] Furthermore, by implementing the function of strengthening account management, the multifunction device 10 behaves as follows, for example. · Automatically delete unused accounts. -Restrict (reject) the reuse of the same account (re-registration with the same account name) for a certain period of time.
[0044] Furthermore, in order to improve convenience, the multifunction device 10 detects an error that occurs during login (login error), for example, and notifies the administrator of the event that has occurred, thereby enabling the administrator to grasp the event that has occurred in real time.
[0045] In order to perform the above-described settings, in this embodiment, it is possible to individually set valid / invalid for the following setting items as settings for the individual rules included in the security rules. Minimum password length - Increase the complexity of the characters used in passwords (setting required character types) ·Restrict password reuse -Automatic deletion of unused accounts Account reuse restrictions -Error notification
[0046] A parent setting may be provided that can collectively control whether each of the above-mentioned settings is enabled or disabled. For example, as shown in FIG. 5, it is possible to set the "security rule" to be enabled or disabled. When the "security rule" is "enabled," the settings related to the security rule (D100 in FIG. 5) are enabled. In this case, when the "security rule" is "disabled," the settings related to the security rule (D100 in FIG. 5) are disabled. In other words, only when the parent setting is enabled, each child setting functions according to its own settings. Each child setting may be configurable only when the parent setting is enabled, or may be configurable regardless of whether the parent setting is enabled or disabled. Furthermore, when the parent setting is disabled, the child setting may be initialized, or the system setting value of the child setting may be retained.
[0047] Furthermore, some of the security rules may allow separate system setting values for administrators and general users, such as the minimum password length and required character type setting items in Figure 5. The system setting values for administrator users may depend on either the system setting values for administrators or the system setting values for general users. In this case, the system setting values for "all administrator users" may depend on either the system setting values for administrators or the system setting values for general users, or it may be possible for each "administrator user" to select whether the system setting values depend on the system setting values for administrators or the system setting values for general users.
[0048] As shown in D102 of Fig. 5, among the child settings of a security rule, there may be a setting that has a parent-child relationship. D102 of Fig. 5 indicates that "Delete user accounts that have not logged in for a certain period of time" is the parent setting, and "period" is the child setting.
[0049] The device connection unit 180 connects to another device directly or via a cable. The device connection unit 180 is configured as, for example, an interface (device I / F) that can connect to another device. The other device may be a storage device (storage medium) such as a USB (Universal Serial Bus) memory, or an information processing terminal such as a PC (Personal Computer).
[0050] The communication unit 190 connects other devices to the multifunction peripheral 10 via a network such as a LAN (Local Area Network) or a WAN (Wide Area Network). The communication unit 190 may be configured with a communication device or communication module such as a NIC (Network Interface Card) used in a wired / wireless LAN, and may have an interface (network I / F) connectable to a network. The communication unit 190 may also be connected to a communication network such as a public line network, a LAN, or the Internet, and may be capable of transmitting data to an external device via the communication network by a communication method such as facsimile or email. The other devices may also be PCs or server devices, or may be portable information processing terminals such as laptops, tablets, or smartphones.
[0051] [1.2 Processing flow] The processing executed by the multifunction device 10 will be described with reference to Figures 6 to 9. The processing shown in Figures 6 to 9 is executed by the control unit 100 reading out a program stored in the storage unit 160.
[0052] [1.2.1 Import process] 6 and 7 are flow diagrams showing the flow of the import process. The import process is executed by the import data processing unit 112 of the control unit 100 when an operation to import import data is performed by the administrator.
[0053] In the following description, the control unit 100 stores (imports) the setting values included in the import data as identification and authentication information. That is, the setting values included in the import data include at least information corresponding to an ID, a login name, and a password. Also, the system setting information table 166 stores information on security rule settings for passwords.
[0054] First, import data processing unit 112 acquires import data (step S100). For example, import data processing unit 112 reads import data stored in a USB memory or the like via device connection unit 180, or receives import data from another device via communication unit 190.
[0055] Next, the import data processing unit 112 acquires setting values for one user from the import data acquired in step S100 (step S102). The setting values for one user acquired in step S102 are also referred to as target setting values.
[0056] Next, the import data processing unit 112 analyzes the target setting value (step S104). For example, the import data processing unit 112 analyzes whether the target setting value can be stored as identification authentication information. Note that the import data processing unit 112 may analyze whether a login name included in the target setting value is included as a login name in the unusable login name information, or may perform other necessary analyses.
[0057] Next, the import data processing unit 112 determines whether the target setting value is a valid setting value (valid data type) based on the analysis result in step S104 (step S106). For example, if the target setting value does not contain information required for storage as identification and authentication information, or if the login name included in the target setting value is included in the login name of any of the unusable login name information, the import data processing unit 112 determines that the setting value is not valid.
[0058] If the target setting value is not a valid setting value (data type) in step S106, the import data processing unit 112 discards the target setting value and returns to step S102 (step S106; No → step S108 → step S102).
[0059] On the other hand, if the import data processing unit 112 determines in step S106 that the target setting value is a valid setting value, it determines whether the security rule is valid or not based on the system setting information table 166 (step S106; Yes → step S110).
[0060] If the security rule is invalid, the import data processing unit 112 stores the target setting value as identification and authentication information in the identification and authentication information storage area 162 (step S110; Yes→step S112).
[0061] Next, the import data processing unit 112 determines whether or not there are any setting values that have not been acquired in the import data acquired in step S100 (step S114). If there are any setting values that have not been acquired, the import data processing unit 112 returns to step S102 (step S114; Yes → step S102). On the other hand, if all setting values have been acquired, the import data processing unit 112 ends the processing shown in FIG. 6 (step S114; No).
[0062] Furthermore, if it is determined in step S110 that the security rule is valid, the import data processing unit 112 determines whether the target setting value is a setting value set by the administrator (step S110; No -> step S116). For example, when storing the target setting value as identification authentication information, the import data processing unit 112 determines whether the target setting value is a setting value set by the administrator based on whether the ID included in the identification authentication information is "-2" or "-1".
[0063] If the target setting value is not the administrator's setting value, the import data processing unit 112 stores the target setting value (step S116; No → step S112). On the other hand, if the import data processing unit 112 determines in step S116 that the target setting value is the administrator's setting value, it determines whether the target setting value matches (satisfies) the security rule (step S116; Yes → step S118).
[0064] If the target setting value matches the security rule (satisfies the security rule), the import data processing unit 112 stores the target setting value (step S118; Yes → step S112). On the other hand, if the target setting value does not match the security rule (does not satisfy the security rule), the import data processing unit 112 interrupts the import process and changes the target setting value so that it matches the security rule. In this embodiment, the import data processing unit 112 executes administrator password change processing to change the password included in the target setting value so that it matches the security rule for passwords (password policy) (step S118; No → step S120).
[0065] The administrator password change process will be described with reference to Fig. 7. Import data processing unit 112 displays a selection screen on display unit 144 that allows the user to select either password change or import cancellation (step S130).
[0066] Next, if a password change is selected based on the user's operation, the import data processing unit 112 acquires a new password (step S132; Yes → step S134). For example, the import data processing unit 112 displays a password input screen on the display unit 144, and acquires the character string entered via the input screen as the new password.
[0067] Next, the import data processing unit 112 determines whether the password acquired in step S134 conforms to the security rules (step S136). If the password acquired in step S134 conforms to the security rules, the import data processing unit 112 changes the password (step S136; Yes → step S138). That is, the import data processing unit 112 changes the administrator's setting value to the new setting value.
[0068] After executing the process in step S138, the import data processing unit 112 executes step S112 in Fig. 6. This allows the import data processing unit 112 to store the target setting values, including the password changed in step S138, as identification and authentication information.
[0069] If it is determined in step S132 that import cancellation has been selected, the import data processing unit 112 cancels and terminates the import process (step S32; No -> step S140). At this time, the import data processing unit 112 may restore the identification and authentication information stored in the identification and authentication information storage area 162 to the state it was in before the import process. After executing the process in step S140, the import data processing unit 112 returns to FIG. 6, and then terminates the process described in FIG. 6. As a result, the import data processing unit 112 cancels and terminates the import process without importing the import data.
[0070] In this way, by executing the processing shown in Figure 7, the import data processing unit 112 can have the administrator change the password on the spot if the administrator's setting value does not conform to the security rules regarding passwords.
[0071] 7, the import data processing unit 112 may require the user (administrator) to input the password twice. In this case, if the password input twice is the same, the control unit 100 determines whether the input password complies with the security rules (processing of step S136). On the other hand, if the input password is different between the first and second times, the import data processing unit 112 requires the user to start over from the first password input.
[0072] The above-described import process is a process in which the password can be changed when the administrator's setting value does not conform to the password security rules. Instead of the above-described process, the import data processing unit 112 may terminate the import process with an error if the administrator's setting value does not conform to the password security rules. In this case, when the import data processing unit 112 acquires a setting value that does not conform to the password security rules, it does not allow the administrator to change the password, restores the identification and authentication information stored in the identification and authentication information storage area 162 to the state before the import process, and terminates the import process.
[0073] Furthermore, in the above-described import process, the control unit 100 (import data processing unit 112) may also check whether the setting values of the administrator user conform to the security rules. In this case, the control unit 100 (import data processing unit 112) determines whether the target setting value is the setting value of the administrator or the setting value of the administrator user in step S116 of FIG. 6. If the target setting value is the setting value of the administrator or the setting value of the administrator user, the import data processing unit 112 further executes the process of step S118 of FIG. 6 to determine whether the target setting value conforms to the security rules. If the target setting value is the setting value of the administrator user and does not conform to the security rules (in the event of an error), the import data processing unit 112 may allow the setting value of the administrator user to be changed as is. Furthermore, even when the import data processing unit 112 allows the setting values of the administrator user to be changed, the import data processing unit 112 may allow the user to arbitrarily select whether or not to change the setting value of the administrator user. In this case, if the setting value of the administrator user is not to be changed, the import data processing unit 112 may skip importing the setting value of the administrator user. This allows the import data processing unit 112 to skip importing the setting values of the administrator user that do not conform to the security rules.
[0074] Furthermore, the import data processing unit 112 may set priorities for administrator users in advance based on the import data, etc., and determine whether only the setting values of administrator users with high priorities conform to the security rules. In this case, if the setting values of an administrator user with high priorities do not conform to the security rules, the import data processing unit 112 may make the setting values changeable or may skip importing the setting values. Note that the setting values of administrator users with low priorities are imported as is without being determined whether they conform to the security rules. In this way, the import data processing unit 112 can import the setting values of administrator users with high priorities after conforming to the security rules.
[0075] Although it is assumed that the import process is performed by an administrator, the import process may also be performed by an administrator user. In this case, some administrator users may be set as users who are permitted to change passwords during import, just like the administrator. If there are multiple administrator users, some administrator users may not be permitted to change passwords during import. In this case, setting information indicating whether or not an administrator user is permitted to change passwords may be set in the setting value (account setting).
[0076] [1.2.2 Login process] 8 and 9 are flow diagrams showing the flow of login processing. The login processing is executed when a user performs an operation to log in to the multifunction device 10. The user may perform the login operation by operating the multifunction device 10, or may perform the login operation via a device that the user owns and that is connected to the multifunction device 10.
[0077] First, the control unit 100 acquires login information (step S150). The login information is information necessary for logging in to the multifunction device 10, such as a login name and password. The control unit 100 displays a screen (login screen) for inputting the login name and password on the display unit 144, or causes the login screen to be displayed on a device used by the user, and acquires the login information input via the login screen.
[0078] Next, the control unit 100 determines whether the security rule is valid or not (step S152).
[0079] If the security rules are invalid, the control unit 100 (identification and authentication processing unit 102) identifies and authenticates the user based on the login information acquired in step S150 (step S152; Yes → step S154). The control unit 100 (identification and authentication processing unit 102) determines whether or not authentication has been successful (step S156). If authentication has been successful, the control unit 100 ends the processing shown in FIG. 8 (step S156; Yes). In this case, the control unit 100 executes post-login processing. The post-login processing may, for example, display buttons for selecting functions of the multifunction device 10 and a home screen displaying information about the multifunction device 10 on the display unit 144 or a device used by the user. In this way, if the security rules are invalid, the user can log in to the multifunction device 10 and use the multifunction device 10, regardless of whether the user's setting values match the security rules.
[0080] On the other hand, if the security rule is valid, the control unit 100 determines whether or not the login information acquired in step S150 matches the security rule (step S152; No→step S158).
[0081] If the security rule is met, the control unit 100 executes the process of step S154 (step S158; Yes→step S154).
[0082] On the other hand, if there is no conformance with the security rules, the control unit 100 determines whether or not the security rule error notification to the user is disabled for the error (security rule error) based on the non-conformance with the security rules (step S158; No -> step S160). For example, the control unit 100 refers to the system setting information table 166, and if the system setting value for the security rule error notification is "enabled" and the system setting value for notification by display (notification method (display)) is "enabled", the control unit 100 determines that the security rule error notification to the user is enabled. On the other hand, if either the system setting value for the security rule error notification or the system setting value for notification by display is "disabled", the control unit 100 determines that the security rule error notification to the user is disabled.
[0083] If the security rule error notification to the user is invalid, the control unit 100 sets the error condition to "identification and authentication error" (step S160; Yes → step S162). The error condition is information indicating the type of error that has occurred in the multifunction device 10. The control unit 100 also displays a message for each error condition (step S164). For example, if a login operation is performed via the multifunction device 10, the control unit 100 displays a message on the display unit 144. On the other hand, if a login operation is performed via a user's device, the control unit 100 causes the device to display a message by transmitting information for displaying a message on the device. In this way, even if the setting values of a user attempting to log in to the multifunction device 10 do not conform to the security rules, the control unit 100 displays a general error message such as a login error (an authentication error indicating that authentication has failed). This allows the control unit 100 to prevent the user from realizing that the security rules are not being met.
[0084] On the other hand, if the security rule error notification is enabled in step S160, the control unit 100 notifies the administrator of the security rule error (step S160; No → step S166). For example, the control unit 100 sends an email containing information indicating that a security rule error has occurred to an email address stored as the administrator's contact information or an email address stored in the system setting information table 166 as a destination for security error notifications. As a result, the control unit 100 notifies the administrator when an event occurs in which a user attempting to log in to the multifunction peripheral 10 is unable to log in because the user's settings do not conform to the security rules. This allows the administrator to confirm the occurrence of the event after the fact and to recognize when the event occurred. Furthermore, the administrator can recognize that a user whose password does not conform to the security rules is attempting to change their password, regardless of the notification sent to the user currently logged in to the multifunction peripheral 10. The control unit 100 may store the event in the storage unit 160. Furthermore, if the system setting value for security error notification is "disabled" or if the system setting value for security error notification by email is "disabled", control unit 100 may omit the process of step S166.
[0085] Next, the control unit 100 determines whether the password change at the time of the security rule error is valid or not (step S168). If the password change at the time of the security rule error is invalid, the control unit 100 sets the error condition to "security rule error" and displays a message according to the error condition (step S168; Yes → step S170 → step S164).
[0086] On the other hand, if the password change at the time of the security rule error is valid, the control unit 100 (identification and authentication processing unit 102) performs identification and authentication (step S168; No→step S172).
[0087] The control unit 100 determines whether or not the user has been authenticated (step S174). If the user has not been authenticated, the control unit 100 sets the error condition to "identification authentication error" and displays a message according to the error condition (step S174; No → step S176 → step S164).
[0088] On the other hand, if the authentication is successful, the control unit 100 executes a process for changing the password (password change process) (step S174; Yes→step S178).
[0089] The password change process will be described with reference to Fig. 9. In the following description, the operation for changing the password is performed via the multifunction device 10, but the password may also be edited (re-registered) in a device connected to the multifunction device.
[0090] First, the control unit 100 displays a password change screen on the display unit 144 or a device used by the user (step S190). Next, the control unit 100 acquires the password entered by the user via the password change screen (step S192).
[0091] Next, the control unit 100 determines whether the password acquired in step S192 complies with the security rules (step S194). If the password acquired in step S192 complies with the security rules, the control unit 100 changes the password (step S194; Yes → step S196). For example, the control unit 100 changes the password included in the identification and authentication information of the user authenticated in step S172 of FIG. 8 to the password acquired in step S192 (new password). That is, the control unit 100 changes the user's setting value to the new setting value. On the other hand, if the password does not complies with the security rules, the control unit 100 returns to step S190 (step S194; No → step S190).
[0092] Note that in step S192, control unit 100 may require the user to input the password twice. In this case, if the password input twice is the same, control unit 100 determines whether the input password complies with the security rules (processing of step S194). On the other hand, if the password input the first time is different from the password input the second time, control unit 100 causes the user to start over from the first password input.
[0093] In this way, when the security rules are enabled, if the user's setting values match the security rules, the user can log in to the multifunction device 10 and can use the multifunction device 10. On the other hand, if the user's setting values do not match the security rules, the user cannot log in to the multifunction device 10. If the user cannot log in, the control unit 100 displays a message in step S164 of FIG. 8. At this time, if notification of a security rule error to the user is disabled, the control unit 100 displays a general error message. This allows the control unit 100 to inform the user that the non-compliance with the security rules is a login error, without distinguishing it from an existing authentication error. Note that, if the security rule error notification is enabled, the control unit 100 can also inform the user that the reason for the inability to log in is non-compliance with the security rules.
[0094] [1.3 Example of operation] An example of the operation of the multifunction peripheral 10 of this embodiment will be described with reference to Figures 10 to 12. Figures 10 to 12 show examples of screens displayed on the display unit 144 of the operation panel 140.
[0095] 10 and 11 are diagrams showing screens that are displayed when the import process is executed. The administrator may perform the import operation when installing the multifunction device 10, or may perform the import operation as needed during operation of the multifunction device 10 (for example, when maintenance of the multifunction device 10 is completed).
[0096] 10(a) shows a screen E100 that is displayed when the administrator password does not conform to the security rules when importing the import data and the import process ends in an error. If the import process ends in an error, the administrator can use another multifunction device 10 or information processing device to change the import data so that it conforms to the security rules, and then import it again.
[0097] 10(b) shows a screen E110 (selection screen) that is displayed when the administrator password does not conform to the security rules and the user is prompted to select between changing the password and canceling the import. Screen E110 is displayed in step S130 of FIG. 7. Screen E110 includes a password reset button B110 for changing (updating, resetting) the password, and a cancel import button B112 for canceling the import process. When the cancel import button B112 is selected, the import process is canceled and terminated.
[0098] On the other hand, when the password reset button B110 is selected, screen E120 shown in Fig. 10(c) is displayed. Screen E120 is a password change screen that prompts the administrator to input a new password. Screen E120 is displayed in step S134 of Fig. 7. Screen E120 may also display a message M120 indicating security rules that must be met.
[0099] If the password needs to be entered twice, a screen E130 shown in Fig. 11(a) is displayed. Screen E130 is a screen for prompting the administrator to enter a new password again.
[0100] If the password entered by the administrator conforms to the security rules, screen E140 shown in FIG. 11(b) is displayed. Screen E140 is a screen for informing the administrator that the password has been successfully changed (updated). On the other hand, if the password needs to be entered twice and the password entered the first time is different from the password entered the second time, screen E150 shown in FIG. 11(c) is displayed. Screen E150 is a screen for informing the administrator that the password entered the first time and the password entered the second time must be the same. Screen E150 includes a button B150 that indicates that the contents of the displayed message have been confirmed. When button B150 is selected, screen E120 shown in FIG. 10(c) is displayed, and the administrator is prompted to enter the password the first time again.
[0101] 12A and 12B show screens that are displayed when login processing is performed. Fig. 12A shows screen E160 that is displayed when the error condition is an identification and authentication error (when an identification and authentication error occurs). Screen E160 is displayed when authentication is not possible or when the password does not conform to the security rules and the notification that the security rules do not conform is invalid.
[0102] 12(b) shows a screen E170 that is displayed when the error condition is a security rule error. In this case, the user cannot change the password and must inquire with the administrator.
[0103] On the other hand, if the password entered by the user at the time of logging in does not conform to the security rules but the user is authenticated using that password, the user is prompted to change the password. At this time, a screen similar to screen E120 shown in Fig. 10(c) or screen E130 shown in Fig. 11(a) is displayed, prompting the user to enter a password.
[0104] Fig. 12(c) shows screen E180 that is displayed when the password has been changed. By checking screen E180, the user can know that the password has been changed (updated). On the other hand, if the password needs to be entered twice and the password entered the first time is different from the password entered the second time, a screen similar to screen E150 shown in Fig. 11(c) is displayed.
[0105] In the above explanation, the import process is performed or the password is changed depending on whether the password included in the setting value conforms to the security rules for passwords. However, security rules for information other than passwords may be set, and whether the information other than passwords conforms to the security rules may be determined depending on the security rules, and the import process or the setting value may be changed.
[0106] In addition, the security rules have been described as being stored in the multifunction peripheral 10. However, when a user uses a plurality of multifunction peripherals 10 connected to a network or the like, the security rules may be set and operated individually for each multifunction peripheral 10, or may be shared among the plurality of multifunction peripherals 10. When the security rules are shared among the plurality of multifunction peripherals 10, each of the plurality of multifunction peripherals 10 is able to communicate with an external server that manages the security rules, and the multifunction peripherals 10 acquire the security rules from the external server by linking with the external server. Note that the security rule settings of one of the multifunction peripherals 10 may be adopted as the security rule settings of the other multifunction peripherals 10 without using an external server. When adopting security rules from the plurality of multifunction peripherals 10, for example, the strongest security rule settings are adopted in each multifunction peripheral 10. In addition, a parent-child relationship or a hierarchical relationship may be established between the multifunction devices 10, and the security rules of the prioritized multifunction device 10 (e.g., a parent or higher-level multifunction device 10) may be adopted by each multifunction device 10 (e.g., a child or lower-level multifunction device 10).
[0107] Alternatively, the multifunction peripheral 10 may determine whether or not the administrator's setting values conform to the security rules, without determining whether or not the general user's setting values conform to the security rules. The multifunction peripheral 10 may also exclude information to which the security rules apply from the authentication method (authentication mode). That is, if a password-free authentication method is available, the multifunction peripheral 10 may use the password-free authentication method as the authentication method for general users, and may not determine whether or not the user's setting values conform to the password-related security rules. Examples of password-free authentication methods include IC card authentication, user number authentication, fixed user login, and quick authentication (quick login). Since some authentication methods allow passwords to be set, when an authentication method that allows passwords to be set is used, the general user's setting values may also be determined to conform to the password-related security rules.
[0108] Furthermore, while the above description describes the process executed when importing import data, similar processes may be executed when the security level of the multifunction device 10 is raised. For example, if an administrator changes the system settings of the multifunction device 10, thereby changing the security rules of the multifunction device 10 itself and raising the security level, the multifunction device 10 may be configured to allow the administrator to change settings that do not conform to the security rules. Furthermore, when a general user logs in, the multifunction device 10 changes the user's settings to conform to the changed security rules. For example, the password length may be set to a value that is not longer than a certain value. In this way, the security rules may be forcibly enabled depending on the security level, making the multifunction device 10 more secure and allowing it to be operated with settings that are stronger than those at the normal security level. In this case, settings must be changed, but the multifunction device 10 can change the settings when the security rules are changed and when the user logs in.
[0109] As described above, the multifunction peripheral of this embodiment does not generally check the security rules when importing setting values such as identification and authentication information. Specifically, if the imported setting values are those of an administrator, the multifunction peripheral determines whether they conform to the security rules. However, if the imported setting values are those of a general user other than the administrator, the multifunction peripheral does not determine whether they conform to the security rules. For example, in order to improve the security of the multifunction peripheral, when an authentication function is used to restrict access to the multifunction peripheral, security rules regarding passwords may be strengthened to further enhance security. However, even in such a case, the multifunction peripheral of this embodiment imports setting values of a general user other than the administrator without checking the security rules. This prevents the multifunction peripheral from requiring a significant amount of time to resolve import errors and shortens the time it takes to import import data.
[0110] On the other hand, when importing setting values, if the setting values are those of an administrator, the multifunction device of this embodiment checks whether the setting values conform to the security rules. At this time, if the administrator's setting values conform to the security rules, the multifunction device executes the import process. If the administrator's setting values do not conform to the security rules, the multifunction device changes the setting values or cancels the import process. When an operation to change (reset) a setting value is performed, the multifunction device imports setting values that have adopted the reconfigured information (updated to the changed information) only if the setting values conform to the security rules. This allows the multifunction device of this embodiment to import at least the administrator's setting values in a state that is reliably in conformance with the security rules, thereby avoiding a situation in which all administrators are unable to log in.
[0111] In addition, in the past, user settings (user data) that did not conform to security rules were not imported, and the user was sometimes unable to use the multifunction device. In such cases, the user who could not use the multifunction device was required to register a new user, but this could result in security restrictions such as usage limitations, such as restrictions on user registration using the same login name as the user had previously used. In such cases, the user would need to register a different account using a different username and operate the device using that different account, which could result in a long time (downtime) before the device could be used. However, when importing a general user's settings, the multifunction device of this embodiment imports the settings without determining whether the imported data conforms to security rules. As a result, the multifunction device of this embodiment does not restrict the registration of the same account, thereby reducing the time (downtime) during which the user cannot use the multifunction device.
[0112] In this way, the multifunction device of this embodiment can provide a mechanism that takes security rules into consideration, avoids a situation where any administrator is unable to log in to the multifunction device, and reduces the management effort required for importing import data.
[0113] [2. Second Embodiment] Next, a second embodiment will be described. In addition to the processing described in the first embodiment, the second embodiment allows only the administrator to reset the setting values, or allows the user to reset the setting values only with the administrator's permission. In this embodiment, FIG. 9 of the first embodiment is replaced with FIG. 13. Note that the same processing is assigned the same reference numerals, and the description will be omitted.
[0114] [2.1 Functional Configuration] In this embodiment, the system setting information table 166 stores the following settings as settings for improving convenience. Password change denial This setting indicates whether or not the user is allowed to change the password. - Whether password changes require administrator approval This setting indicates whether an administrator must approve a password change when a user requests one, in cases where the user can change their password. If approval is required, the administrator can detect when a login failure occurs or check after the event has occurred. On the other hand, if approval is not required, the user can change their password immediately, improving convenience.
[0115] [2.2 Processing flow] The password change process in this embodiment will be described with reference to Fig. 13. First, the control unit 100 determines whether the password change made by the user is valid or not, based on the system setting values stored in the system setting information table 166 (step S200).
[0116] If the password change by the user is valid, the control unit 100 determines whether approval from the administrator is not required (step S200; Yes→step S202).
[0117] If approval from the administrator is not required (step S202; Yes), the process from step S190 to step S196 is executed to change the password.
[0118] On the other hand, if the control unit 100 determines in step S202 that approval from the administrator is required, it sends a request for approval of the password change (password change approval request) to the administrator (step S202; No → step S204). The administrator who can approve the password change may be a device administrator, an administrator set as the administrator who approves the password change (default administrator), or an administrator user. When the password change is approved by an administrator user, the administrator users who can approve the password change may be limited.
[0119] After transmitting the password change approval request, the control unit 100 displays on the display unit 144 a screen indicating that it is waiting for the result of approval by the administrator (step S206).
[0120] Next, the control unit 100 determines whether the administrator has approved the password change (step S208). For example, the control unit 100 determines that the administrator has approved the password change when the control unit 100 receives information indicating approval of the password change from the administrator to whom the password change approval request was sent, or when the control unit 100 performs an operation indicating approval of the password change. If the administrator has approved the password change, the control unit 100 executes the process in step S190 (step S208; Yes→step S190).
[0121] On the other hand, if the password change is not approved by the administrator, the control unit 100 sets the error condition to "Change denial from administrator" and displays a message according to the error condition (step S208; No → step S210 → step S212). The process in step S212 is the same as the process in step S164 in FIG. 8.
[0122] Furthermore, when the password change has been approved by the administrator and the user cancels the password change, the control unit 100 sets the error condition to "cancel waiting for administrator approval" (step S208; user cancel -> step S214). In this case, the control unit 100 executes the process in step S212 to display a message corresponding to the error condition, "cancel waiting for administrator approval." The control unit 100 may also notify the administrator to whom the password change approval request was sent that the password change has been canceled by the user.
[0123] If the user's password change is invalid in step S200, the control unit 100 sends a password change request to the administrator (step S200; No -> step S216). The administrator to whom the password change request is sent may be the device administrator, the default administrator, or the administrator user, as in step S204. The control unit 100 also sets the error condition to "waiting for contact from administrator" (step S218). In this case, the control unit 100 executes the process in step S212 to display a message corresponding to the error condition, "waiting for contact from administrator."
[0124] The administrator who receives the password change request changes (re-registers) the password. To allow the administrator to change the password, for example, when the control unit 100 acquires login name and password information from the administrator to whom the password change request was sent in step S216, the control unit 100 changes the password stored in the identification and authentication information including the login name to the password acquired from the administrator. This allows the password of the user whose password is to be changed to a password that complies with the password security rules. If the password acquired from the administrator does not comply with the password security rules, the control unit 100 may request the password from the administrator again. The administrator may notify the user who requested the password change of the changed password. The control unit 100 may notify the user whose password is to be changed that the password has been changed when the control unit 100 changes the identification and authentication information based on the password acquired from the administrator.
[0125] [2.3 Example of operation] The screens shown in Fig. 14 are diagrams showing screens displayed when executing login processing. Fig. 14(a) shows screen E200 displayed when waiting for the administrator approval result. Screen E200 is displayed in step S206 of Fig. 13.
[0126] 14(b) shows screen E210 that is displayed when a user cancels while waiting for administrator approval. Screen E210 is displayed by executing step S212 after step S214 in FIG.
[0127] 14(c) shows a screen E220 that is displayed when waiting for a response from the administrator. Screen E220 is displayed by executing step S212 after step S218 in FIG. 13 is executed.
[0128] In this way, in the multifunction peripheral of this embodiment, if a user's setting values do not conform to the security rules, an administrator can edit (re-register) the information to conform to the security rules, according to the system settings of the multifunction peripheral. Furthermore, in the multifunction peripheral of this embodiment, if a user edits (re-registers) information, according to the system settings of the multifunction peripheral, approval by an administrator is also required. In this way, in the multifunction peripheral of this embodiment, if a user's setting values do not conform to the security rules, the setting values can be changed via the administrator, thereby avoiding a situation in which the administrator is unaware of a password change by a general user.
[0129] 3. Third Embodiment Next, a third embodiment will be described. In addition to the processing described in the first embodiment, the third embodiment is an embodiment in which, when a password is changed in one multifunction device, the passwords of the identification and authentication information (account information) of the same user that are registered in other multifunction devices can be changed in conjunction with each other. In this embodiment, FIG. 9 of the first embodiment is replaced with FIG. 16. Note that the same processes are assigned the same reference numerals, and descriptions thereof will be omitted.
[0130] [3.1 Overall Structure] Fig. 15 is a diagram showing the overall configuration of a system 1 in this embodiment. In this embodiment, the system 1 has a plurality of multifunction peripherals 10 (in the example of Fig. 15, multifunction peripherals 10a, 10b, and 10c) connected via a network NW. The network NW is a network that connects the respective devices. For example, the network NW is realized by a LAN (Local Area Network) or a WAN (Wide Area Network), but a network other than a LAN or WAN may be used as long as the respective devices can exchange information with each other.
[0131] [3.2 Functional Configuration] In this embodiment, the system setting information table 166 stores the following settings as settings for improving convenience. · Sharing of setting information between multifunction devices (information sharing) This setting indicates whether or not multiple multifunction devices 10 work together to share setting values. For example, if the setting for sharing setting information between multifunction devices 10 is enabled, when a password is changed in one multifunction device 10, the passwords of the identification and authentication information (account information) of the same user registered in the other multifunction devices 10 are also changed (updated or reset).
[0132] [3.3 Processing flow] [3.3.1 Administrator password change process] The administrator password change process in this embodiment will be described with reference to Fig. 16. In this embodiment, after changing the password in step S196, the control unit 100 determines whether or not the password change linkage is enabled (step S300).
[0133] If the password change linkage is enabled, the control unit 100 acquires information about the multifunction peripheral 10 to be linked (step S300; Yes -> step S302). The information about the multifunction peripheral 10 to be linked is, for example, the address of the multifunction peripheral 10. For example, information about the multifunction peripheral 10 to be linked is stored in advance in the storage unit 160 or the system setting information table 166, and the control unit 100 acquires the information about the multifunction peripheral 10 to be linked from the storage unit 160. Note that a management server that manages the multifunction peripheral 10 may be provided in advance, and the control unit 100 may acquire the information about the multifunction peripheral 10 to be linked from the management server. Alternatively, the control unit 100 may broadcast communication to the network NW and acquire the information about the multifunction peripheral 10 to be linked in response to a response from the multifunction peripheral 10.
[0134] Next, the control unit 100 transmits a notification (coordination information) for coordinating the setting values to the multifunction peripheral 10 to be coordinated via the communication unit 190 (step S304). The coordination information includes, for example, the changed password (information on the changed setting values) and information (for example, login name) for identifying the user whose password is to be changed (the user who performed the password change operation). If the control unit 100 determines in step S300 that the password change coordination is invalid, it omits the processes in steps S302 and S304 (step S300; No).
[0135] [3.3.2 Password linkage change process] 17, a description will be given of a password-linked change process that is executed by the multifunction device 10 to change a password based on link information when the multifunction device 10 receives the link information from another multifunction device 10. The password-linked change process is executed by the control unit 100 reading out a program stored in the storage unit 160. The control unit 100 executes the password-linked change process in parallel with a process for implementing functions of the multifunction device 10, such as a login process.
[0136] First, the control unit 100 determines whether or not link information has been received from another multifunction device 10 via the communication unit 190 (step S350). If link information has been received, the control unit 100 determines, based on the link information, whether or not the user whose password is to be changed has not yet logged in to the multifunction device 10 (is not currently logged in) (step S352).
[0137] If the user whose password is to be changed is not currently logged in, control unit 100 changes the setting value based on the association information received in step S350 (step S352; Yes → step S354). For example, if the association information includes the changed password (information on the changed setting value) and information for identifying the user, control unit 100 changes the password stored in the identification and authentication information of the user identified based on the information for identifying the user to the changed password.
[0138] On the other hand, if the user whose password is to be changed is currently logged in to the device, the control unit 100 determines whether or not the user has completed logging out (step S352; No → step S356). If the user whose password is to be changed has not completed logging out, the control unit 100 repeats the process of step S356 (step S356; No). The control unit 100 waits for the user whose password is to be changed to log out, and changes the setting value after the user has completed logging out (step S356; Yes → step S354).
[0139] If the control unit 100 determines in step S350 that the cooperation information has not been received, it omits the processes from step S352 to step S356 (step S350; No).
[0140] Next, the control unit 100 determines whether or not an end operation has been performed (step S358). An end operation is, for example, an operation of selecting a button for turning off the power of the multifunction device 10. If an end operation has been performed, the control unit 100 ends the process shown in Fig. 17 (step S358; Yes). On the other hand, if an end operation has not been performed, the control unit 100 returns to step S350 (step S358; No).
[0141] The control unit 100 may have conditions for determining whether to change the password included in the identification and authentication information stored in the identification and authentication information storage area 162, and may determine whether to change the password in step S354 based on the conditions. For example, the system setting information table 166 may have a setting item for "Whether to change when link information is received." In this case, when the control unit 100 receives link information, it determines whether to change a setting value such as a password based on the system setting value of the setting item, and if the change made when link information is received is valid, it changes the setting value based on the link information. On the other hand, if the change made when link information is received is invalid, the control unit 100 does not change the setting value even when link information is received. Furthermore, a parent-child relationship or a hierarchical relationship may be set in each multifunction peripheral 10, and the control unit 100 may change the password when link information is received from a parent or higher-level multifunction peripheral 10, and not change the password when link information is received from a child or lower-level multifunction peripheral 10.
[0142] In this way, when multiple multifunction devices are used as in this embodiment, when information such as a password is changed in one multifunction device in accordance with the security rules, information such as passwords can also be changed in the other multifunction devices. As a result, the system in this embodiment can improve user convenience when multiple multifunction devices are used.
[0143] [4. Modifications] The present invention is not limited to the above-described embodiments and various modifications are possible. In other words, embodiments obtained by combining technical means that are appropriately modified within the scope of the present invention are also included in the technical scope of the present invention. Furthermore, although the above description has been given of the case where the information processing device of the present disclosure is applied to a multifunction peripheral, the present disclosure may also be applied to information processing devices other than a multifunction peripheral.
[0144] Although the above-described embodiments are described separately for convenience of explanation, they may be combined within the scope of technical feasibility. For example, the second and third embodiments may be combined. In this case, the multifunction device may require approval from an administrator when changing a password, and when a password is changed, it may be possible to have other multifunction devices change their passwords.
[0145] In addition, the programs that run on each device in the embodiments are programs that control the CPU, etc. (programs that make a computer function) so as to realize the functions of the above-described embodiments. Information handled by these devices is temporarily stored in a temporary storage device (e.g., RAM) during processing, and then stored in various storage devices such as ROMs (Read Only Memories) and HDDs, and is read, modified, and written by the CPU as needed.
[0146] Here, the recording medium for storing the program may be any of semiconductor media (e.g., ROM, non-volatile memory card, etc.), optical recording media / magneto-optical recording media (e.g., DVD (Digital Versatile Disc), MO (Magneto Optical Disc), MD (Mini Disc), CD (Compact Disc), BD (Blu-ray (registered trademark) Disc), etc.), magnetic recording media (e.g., magnetic tape, flexible disk, etc.), etc. Furthermore, not only are the functions of the above-described embodiments realized by executing the loaded program, but the functions of the present invention may also be realized by processing in cooperation with an operating system or other application programs, etc., based on instructions from the program.
[0147] Furthermore, when distributing the program on the market, the program can be stored on a portable recording medium and distributed, or transferred to a server computer connected via a network such as the Internet. In this case, the storage device of the server computer is of course included in the present invention. [Explanation of symbols]
[0148] 1 System 10 Multifunction device 100 control section 102 Identification and authentication processing unit 104 Operation panel processing section 106 Copy processing section 108 Scanner processing unit 110 Printer processing unit 112 Import data processing section 114 Identification and authentication information management unit 116 Image Processing Unit 120 Image input unit 130 Image forming unit 140 Operation Panel 142 Operation section 144 Display section 160 Storage section 162 Identification and authentication information storage area 164 Unavailable login name information storage area 166 System Settings Information Table 180 Device Connection 190 Communications Department
Claims
1. an authentication unit that authenticates a user according to a set value; an acquisition unit that acquires the setting value; a determination unit that determines whether or not a setting value of an administrator among the setting values acquired by the acquisition unit satisfies a rule for the setting value; a processing unit that, when importing the setting values acquired by the acquisition unit, imports the setting values of users other than the administrator as they are, and, if the determination unit determines that the setting values of the administrator do not satisfy the rule, interrupts the import; An information processing device comprising:
2. The information processing device according to claim 1, characterized in that, when an import is interrupted, the processing unit acquires a new setting value for the setting value of the administrator, and if the new setting value satisfies the regulations, changes the setting value to the new setting value and then performs the import.
3. 3. The information processing device according to claim 1, wherein, when the setting value corresponding to the user does not satisfy the regulation, the processing unit displays a message to the user indicating that authentication has failed when the authentication unit authenticates the user.
4. 3. The information processing apparatus according to claim 1, wherein the processing unit allows the user to change the setting value when the setting value corresponding to the user authenticated by the authentication unit does not satisfy the rule.
5. 5. The information processing apparatus according to claim 4, wherein the processing unit allows the user to change the setting value when the administrator gives permission to change the setting value.
6. The information processing device according to claim 1 or 2, characterized in that, when a setting value corresponding to a user authenticated by the authentication unit does not satisfy the regulation, when a new setting value is obtained from the administrator, the processing unit changes the setting value of the user to the new setting value obtained from the administrator.
7. a transmitting unit that transmits information about the changed setting value when the setting value is changed; a receiving unit that receives information about the changed setting value; Further provided with 7. The information processing device according to claim 1, wherein when the processing unit receives information about the changed setting value from the receiving unit, the processing unit changes the setting value before the change based on the information about the changed setting value.
8. obtaining a setting value; a determination step of determining whether or not the setting value of the administrator among the setting values satisfies a rule for the setting value; When importing the setting values, the setting values of users other than the administrator are imported as they are, and if the setting values of the administrator do not satisfy the regulations, the import is interrupted; A control method comprising:
Citation Information
Patent Citations
Image forming apparatus, control method of image forming apparatus, and program
JP2015180990A
Information processing device, method for controlling information processing device, and program
JP2016221951A
Image forming device, program, and information processing system
JP2021064088A